TWI474257B

Microprocessor, method of protection and method of revoking first password

Abstract

The invention provides a microprocessor, which includes a key, a special module register, a plurality of fuses, and a microcode. The key is manufactured inside the microprocessor. The special module register has an address specified by instructions executed by the microprocessor. The microcode is used to receive commands that require access to the special module register, where the commands are used to specify the address of the special module register; execute the address and read of the specified special module register A functional operation of the value of the fuse to generate a first result; encrypt the first result with a key to generate a second result; compare the second result with the password specified by the command; and only have the second result Only when the result matches the password, the command is allowed to access the special module register.

TWI474257B, drawing sheet 1
Sheet 1 of 7

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Granted
  4. Today

16 claims: 16 independent, 0 dependent

  1. 1
    A microprocessor includes:a secret key manufactured inside the above-mentioned microprocessor;a special module register with an address designated by an instruction that can be executed by the above-mentioned microprocessor;a plurality of fuses;and a Microcode for: receiving the above command requesting access to the above special module register, wherein the above command is used to specify the address of the above special module register;using the designated special module for temporary storage The address of the device and a value read from the fuse perform a function operation to generate a first result;use the key to encrypt the first result to generate a second result;compare the second result The result matches one of the passwords specified by the above command;and if the second result matches the above password, the above command is allowed to access the above special module register, otherwise the above command is rejected to store the above special module register Pick. 一種微處理器,包括:一密鑰,製造於上述微處理器的內部;一特別模組暫存器,具有可由上述微處理器執行之一指令所指定之一位址;複數保險絲;以及一微碼,用以:接收要求對上述特別模組暫存器進行存取之上述指令,其中上述指令用以指定上述特別模組暫存器之位址;利用所指定之上述特別模組暫存器之位址與讀取自上述保險絲之一數值執行一函數運算,用以產生一第一結果;使用上述密鑰對上述第一結果進行加密,用以產生一第二結果;比較上述第二結果與上述指令所指定之一密碼;以及若上述第二結果與上述密碼匹配,允許上述指令對上述特別模組暫存器進行存取,否則拒絕上述指令對上述特別模組暫存器進行存取。
  2. 2
    The microprocessor as described in item 1 of the scope of patent application, in which the specified address of the above-mentioned special module register and the function calculation of the value read from the above-mentioned fuse, including the designated above-mentioned special module register The address of the device and the Boolean operation of the value read from the fuse mentioned above are mutually exclusive. 如申請專利範圍第1項所述之微處理器,其中所指定之上述特別模組暫存器之位址與讀取自上述保險絲之數值的函數運算,包括所指定之上述特別模組暫存器之位址與讀取自上述保險絲之數值的布林互斥或運算。
  3. 3
    The microprocessor described in item 1 of the scope of patent application, wherein Function calculation between the address of the specified special module register and the value read from the fuse, including the sequence of the address of the specified special module register and the value read from the fuse Concatenation. 如申請專利範圍第1項所述之微處理器,其中所 指定之上述特別模組暫存器之位址與讀取自上述保險絲之數值的函數運算,包括所指定之上述特別模組暫存器之位址與讀取自上述保險絲之上述數值的一序連串接(concatenation)。
  4. 4
    In the microprocessor described in item 1 of the scope of the patent application, the above-mentioned key cannot be observed by the outside of the above-mentioned microprocessor. 如申請專利範圍第1項所述之微處理器,其中上述密鑰係無法由上述微處理器的外部所觀視的。
  5. 5
    The microprocessor described in item 1 of the scope of patent application, wherein the microprocessor uses the key to encrypt the first result according to an Advanced Encryption Standard (AES) to generate the second result. 如申請專利範圍第1項所述之微處理器,其中上述微處理器根據一先進加密標準(AES),使用上述密鑰對上述第一結果進行加密,用以產生上述第二結果。
  6. 6
    A security method suitable for a microprocessor to provide selective access to a special module register of the microprocessor. The method includes:receiving a request to store the special module register Take an instruction, where the instruction is used to specify the address of the special module register;use the address of the special module register specified by the microprocessor and read the plural fuses from the processor Perform a function operation on a value to generate a first result;encrypt the first result with a key made in the microprocessor to generate a second result;compare the second result A password specified by the above command;and if the second result matches the password, the command is allowed to access the special module register, otherwise the command is denied to access the special module register . 一種保密方法,適用於一微處理器,用以提供具選擇性之存取至上述微處理器之一特別模組暫存器,上述方法包括:接收要求對上述特別模組暫存器進行存取之一指令,其中上述指令用以指定上述特別模組暫存器之位址;利用上述微處理器所指定之上述特別模組暫存器之位址以及讀取自上述處理器之複數保險絲之一數值執行一函數運算,用以產生一第一結果;使用製造於上述微處理器的內部之一密鑰對上述第一結果進行加密,用以產生一第二結果;比較上述第二結果與上述指令所指定之一密碼;以及若上述第二結果與上述密碼匹配,允許上述指令對上述特別模組暫存器進行存取,否則拒絕上述指令對上述特別模組暫存器進行存取。
  7. 7
    As the security method described in item 6 of the scope of patent application, the specified address of the above-mentioned special module register is the same as the one read from the above-mentioned fuse Numerical function operations include the Bollinger mutual exclusive OR operation of the specified address of the special module register and the value read from the fuse. 如申請專利範圍第6項所述之保密方法,其中所指定之上述特別模組暫存器之位址與讀取自上述保險絲之 數值的函數運算,包括所指定之上述特別模組暫存器之位址與讀取自上述保險絲之數值的布林互斥或運算。
  8. 8
    The security method described in item 6 of the scope of patent application, in which the specified above-mentioned special module register address and the above-mentioned function calculation of the value read from the above-mentioned fuse include the specified above-mentioned special module temporary storage The address of the device is connected in series with the above-mentioned value read from the above-mentioned fuse. 如申請專利範圍第6項所述之保密方法,其中所指定之上述特別模組暫存器之位址與讀取自上述保險絲之數值的上述函數運算,包括所指定之上述特別模組暫存器之位址與讀取自上述保險絲之上述數值的一序連串接。
  9. 9
    The security method described in item 6 of the scope of patent application, wherein the above-mentioned key cannot be observed by the outside of the above-mentioned microprocessor. 如申請專利範圍第6項所述之保密方法,其中上述密鑰係無法由上述微處理器的外部所觀視的。
  10. 10
    The security method described in item 6 of the scope of patent application, wherein the encryption step includes the use of advanced encryption standards for encryption. 如申請專利範圍第6項所述之保密方法,其中上述加密步驟包括使用先進加密標準進行加密。
  11. 11
    A security method comprising:manufacturing a first version of a microprocessor, the plurality of fuses of the first version of the microprocessor have a first value, and the first version of the microprocessor is used to prohibit an instruction To access a special module register, unless the instruction provides a first password, and the first password uses a key manufactured in the first version of the microprocessor to pair the first value with The address of the special module register is generated by a function operation;the key is used to perform a function operation on the first value and the address of the special module register to generate the first password And provide the above-mentioned first password to users of the above-mentioned first version of the above-mentioned microprocessor;and manufacture a second version of the above-mentioned microprocessor, and the fuse in the second version of the above-mentioned microprocessor has a second value , Wherein the above second version of the above microprocessor is used to prohibit (prohibit) the above instruction to the above special The module register is accessed unless the command provides a second password, and the second password uses the key to pair the second value and the address of the special module register to perform a function operation. produced. 一種保密方法,包括:製造一微處理器之一第一版本,上述微處理器之上述第一版本之複數保險絲具有一第一數值,其中上述微處理器之上述第一版本用以禁止一指令對一特別模組暫存器進行存取,除非上述指令提供一第一密碼,而上述第一密碼係使用製造於上述微處理器之上述第一版本內部的一密鑰對上述第一數值與上述特別模組暫存器之位址進行一函數運算所產生的;使用上述密鑰對上述第一數值與上述特別模組暫存器之位址以執行函數運算,用以產生上述第一密碼,並且提供上述第一密碼給上述微處理器之上述第一版本的使用者;以及製造上述微處理器之一第二版本,上述微處理器之第二版本中之上述保險絲具有一第二數值,其中上述微處理器之上述第二版本用以禁止(prohibit)上述指令對上述特別 模組暫存器進行存取,除非上述指令提供一第二密碼,而上述第二密碼係使用上述密鑰對上述第二數值與上述特別模組暫存器之位址以執行一函數運算所產生的。
  12. 12
    According to the security method described in item 11 of the scope of patent application, the above-mentioned function operation includes performing a Bollinger exclusive OR (XOR) operation between the above-mentioned first/second value and the address of the above-mentioned special module register. 如申請專利範圍第11項所述之保密方法,其中上述函數運算包括執行在上述第一/第二數值與上述特別模組暫存器之位址的一布林互斥或(XOR)運算。
  13. 13
    According to the security method described in item 11 of the scope of patent application, the above-mentioned function operation includes performing a sequential concatenation of the above-mentioned first/second value and the address of the above-mentioned special module register. 如申請專利範圍第11項所述之保密方法,其中上述函數運算包括執行在上述第一/第二數值與上述特別模組暫存器之位址的一序連串接(concatenation)。
  14. 14
    As for the security method described in item 11 of the scope of patent application, the above-mentioned key cannot be observed by the outside of the above-mentioned microprocessor. 如申請專利範圍第11項所述之保密方法,其中上述密鑰係無法由上述微處理器的外部所觀視的。
  15. 15
    The security method described in item 11 of the scope of patent application, wherein the above-mentioned encryption step uses an advanced encryption standard (AES). 如申請專利範圍第11項所述之保密方法,其中上述加密步驟係使用一先進加密標準(AES)。
  16. 16
    A security method, suitable for a microprocessor, provides a method for selectively accessing a special module register of the microprocessor. The method includes:receiving a request for access to the special module register A command, wherein the special module register has an address designated by the command, and the command is used to designate a password;the address of the designated special module register is read from the above A value of the plural fuses of the microprocessor performs a function operation to generate a first result;the password is decrypted using a key made in the microprocessor to generate a second result;compare The above-mentioned first result and the above-mentioned second result;and When the first result matches the second result, the command is allowed to access the special module register, otherwise the command is denied to the special module register. 一種保密方法,適用於一微處理器,提供具有選擇性存取上述微處理器之一特別模組暫存器之方法,上述方法包括:接收要求對上述特別模組暫存器進行存取之一指令,其中上述特別模組暫存器具有被上述指令所指定之一位址,並且上述指令用以指定一密碼;對所指定之上述特別模組暫存器之位址與讀取自上述微處理器之複數保險絲之一數值執行一函數運算,用以產生一第一結果;使用製造於上述微處理器的內部之一密鑰對上述密碼進行解密,用以產生一第二結果;比較上述第一結果以及上述第二結果;以及 當上述第一結果與上述第二結果匹配,允許上述指令對上述特別模組暫存器進行存取,否則拒絕上述指令對上述特別模組暫存器進行。
Independent claims16