Chip card with integrated circuit
Claim Score by NHIP
Abstract
Chip cards comprising a microprocessor and a memory are used for various applications. It is also desirable that such chip cards can be used for different applications. This requires a strict and reliable separation of the various user programs so that mutual accessing is not possible. This is achieved notably by subdivision into a system mode, in which all access rights are free, and a user mode which is adjusted by way of a given bit in the program status word. This mode bit controls inter alia a separation in the bus for the special function registers so that given registers are not accessible in the user mode. These registers may contain information enabling the access to given memory sections only, so that this access cannot be modified in the user mode. Furthermore, each memory word may contain respective test information which is individually associated with a user program and is compared with the appropriate test information upon reading out, the information read out not being internally transported further in the case of lack of correspondence.

Term
Term ended
Projected expiry passed 16 April 2023, 3.4 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
5 claims: 2 independent, 3 dependent
- 1A device comprising:a program status word register in a microprocessor, the register containing a program status word in which a value of at least one predetermined mode bit is representative of a user mode or a system mode and the at least one predetermined bit is not comprised in an address word, and, wherein, access to at least a part of the program status word register and at least a specific register that is used only in the system mode is inhibited when the at least one predetermined mode bit indicates the user mode.
- 5Broadest claimClaim Score 70, broad(NHIP)A software application for conditionally inhibiting access to a specific register of a microprocessor comprising a program status word register, the software application comprising at least one instruction to carry out the following steps:modifying at least one predetermined bit representative of a user mode or a system mode and the at least one predetermined bit is not comprised in an address word;enabling to inhibit access to the specific register and part of the program status word register when the at least one predetermined bit indicates the user mode.
Independent claims2
35 paragraphs in 6 sections, as filed
CROSS REFERENCE TO RELATED APPLICATIONS
[0001] This is a continuation of application Ser. No. 09/246,662, filed Feb. 05, 1999.
FIELD OF THE INVENTION
[0002] The invention relates to a chip card which includes an integrated circuit provided with a control unit in the form of a microprocessor and memories.
BACKGROUND OF THE INVENTION
[0003] Chip cards of this kind are generally known and are used for various purposes. Such chip cards are often used for applications where the card contains security-relevant information. This is so, for example in the case of bank cards which contain a balance or credit lines and also personal secret numbers, or in the case of patient cards which contain confidential information concerning the patient which should be readable, for example only after entry of a personal secret number. Furthermore, such cards are used for controlling the access to given rooms or buildings. It is also desirable that a chip card is suitable for a plurality of applications in that separate user programs are contained in the memory but only the desired program may be addressable. In such cases it is particularly important that data and parts of a user program cannot be accessed by another user program.
SUMMARY OF THE INVENTION
[0004] It is an object of the invention to provide a chip card with a microprocessor and memories which precludes as reliably as possible the unauthorized, i.e. undesirable, accessing of data, notably of a user program, by another user program or by other manipulations for the purpose of reading out or modification.
[0005] This object is achieved according to the invention mainly in that the program status word register (PSW register) contains at least one mode bit whose value indicates a user mode or a system mode. In the user mode, the corresponding bit value of the mode bit inhibits the access to at least parts of the PSW register as well as to all register and memory segments which are used only in the system mode. Consequently, all such registers and memories, containing security-relevant information, can be accessed only in the system mode. The system mode operates with a permanently stored program which, evidently, cannot be read out or modified from the outside. This program is independent of the relevant applications.
[0006] This offers the advantage that such a system program need be tested only once in respect of its security-relevant functions so as to be released. The user programs, generated and loaded onto the cards by the appropriate institutions such as banks or health insurance companies, need not be specially tested in that case. Each access to secret data in the framework of an application program takes place exclusively via the system program. This is also particularly important for chip cards which serve for more than one application. The system program ensures that all different user programs are unambiguously and reliably separated from one another and that no user program can access any other user program or data used therein.
[0007] For the authorized accessing of secret data used in a user program a given jump is always triggered in the system program so as to switch over the mode bit. All registers and all memory locations are accessible in the system mode. On the other hand, however, it can be reliably checked in the system mode whether the requested access is indeed permissible. This test cannot be deactivated by a fraudulent user. Every data input operation and every output operation is also equivalent to an access to secret data.
[0008] The inhibition of memory locations and the release of given memory location segments for a respective user program are simply realized in that the memory is subdivided into given zones, also referred to as segments, different user programs then being effectively associated with different segments. The segments are determined by the content of one or more corresponding registers which can be modified only in the system mode. Consequently, memory zones of different user programs are reliably isolated from one another.
[0009] Moreover, within a segment the access to only a part of the segment can be enabled in that additional registers are provided for indicating a limit address within a segment. Each address, i.e. the less significant bits, is automatically compared with the content of such a register. These registers can again be read and written only in the system mode.
[0010] Furthermore, the segment register preferably stores a bit group whose value is written into the memory location together with the data written. Upon reading out it is then checked whether the content of the corresponding zone of the memory location corresponds to this bit group. If this is not the case, reading out is inhibited.
[0011] If a user program wishes to access a register or a memory location in the user mode without such access being permissible according to this user program, it is possible to output, instead of a special system message, merely a value which corresponds to an empty memory cell, i.e. a cell which has not been written after the manufacture of the card. Thus, a fraudulent user cannot recognize whether he or she actually accessed an empty memory location or an inhibited memory location. Moreover, such a value corresponds to an unconditional jump in the system mode.
[0012] The inhibition of all inadmissible memory zones thus takes place via registers which can be modified only in the system mode. These registers form at least a part of the special function or SF registers. These registers are interconnected via a bus within the registers. Moreover, this internal register bus has an interface to the internal data bus via which the data can be written into the registers from the data bus or via which the registers can be read out to the data bus. Preferably, the register bus is subdivided by a switch which is closed only in the system mode. This constitutes a very simply possibility for inhibiting the relevant registers and hence indirectly also all non-accessible memory locations.
BRIEF DESCRIPTION OF THE DRAWINGS
[0013] Embodiments of the invention will be described in detail hereinafter with reference to the drawing. Therein:
[0014]FIG. 1 shows a block diagram with the essential parts of a microprocessor for a chip card,
[0015]FIG. 2 is a detailed representation of a part thereof,
[0016]FIG. 3 shows a block diagram for the testing of address limits,
[0017]FIG. 4 shows a block diagram for testing the content of memory locations,
[0018]FIG. 5 symbolically represents the subdivision into the protected system zone and the non-protected user zone,
[0019]FIG. 6 shows an example of the composition of a program status word in two separate registers.
DETAILED DESCRIPTION
[0020]FIG. 1 shows diagrammatically the parts of a microprocessor which are of essential importance to the invention. A program counter <b>10</b>, which can be set to a given address via the data bus and otherwise counts autonomously, is connected to an internal bus <b>11</b> which includes a number of data leads and control leads. For the sake of clarity, the necessary control signals are shown neither for the program counter nor for the other elements in this Figure and the other Figures.
[0021] The program counter <b>10</b> delivers its content to a memory management unit MMU <b>14</b> which supplies a memory <b>20</b> with address signals and control signals via a connection <b>15</b>. The memory <b>20</b> effectively consists of a plurality of memory units, i.e. specifically a ROM for the system program or essential parts thereof, an EEPROM for user programs and given fixed data such as secret numbers, and a volatile RAM which serves notably for the storage of intermediate results during individual processing steps. The individual memories are selected by way of control signals via the connection <b>15</b>. Data read out from addressed memory locations is output and data to be written into writable memory locations is supplied via a connection <b>29</b>.
[0022] Furthermore, the MMU <b>14</b> is connected directly to the bus <b>11</b> in order to apply data from the bus <b>11</b> as addresses to the memory <b>20</b>. Moreover, the MMU <b>14</b> is connected to registers <b>18</b> which are represented as one block for the sake of simplicity and which contain indications as to which memory unit in the memory <b>20</b> is to be selected and, additionally, as to which memory zone or address zone in the selected memory unit is addressed. To this end, notably the EEPROM memory unit is subdivided into zones which are generally referred to as segments. Each user program is assigned one or more given segments for program information and data which are defined when the relevant user program is written. These assignments can be modified exclusively by the system program as will be explained in detail hereinafter.
[0023] An input of an arithmetic and logic unit ALU <b>12</b> is connected to the bus <b>11</b>. The internal construction of this unit, including notably an arithmetic unit and an accumulator as well as further registers, is known per se and hence is not shown in detail. The results of the unit <b>12</b> are applied to the bus <b>11</b> again. Moreover, some signals occurring during the execution of the calculations, such as carry signals, overflow signals or zero values, are applied, via a connection <b>13</b>, to a register <b>26</b> which contains a part of the so-called program status word. The second part of the program status word is stored in a register <b>28</b>.
[0024] For the input or output of data, for example from outside the chip card or from a co-processor in the chip card or on the same chip as the microprocessor, there are provided registers <b>24</b> which can be loaded, via a connection <b>25</b>, from outside the microprocessor and can also output data to the environment.
[0025] The registers <b>18</b>, <b>28</b> and <b>24</b> are interconnected via a special bus <b>23</b> which leads to a connection unit <b>30</b>. Further registers may also be connected to the bus <b>23</b> as denoted by the dashed line extending to the connection unit <b>30</b>. The connection unit <b>30</b> is also connected to an internal bus <b>21</b> which leads to the register <b>26</b> for the one part of the program status word as well as to a coupling unit <b>22</b> which connects the bus <b>21</b> to the bus <b>11</b> when appropriately driven via control leads which are not separately shown. The buses <b>21</b> and <b>23</b> constitute the customary internal bus for the special function registers in microprocessors. These two parts constitute a unitary bus when the connection unit <b>30</b> interconnects the two bus segments by control via the lead <b>27</b>.
[0026] The control lead <b>27</b> is connected to a given part of the register <b>28</b> which contains a mode bit. The value of this bit determines whether the microprocessor operates in the system mode or in the user mode. When the value of this bit indicates the system mode, the connection unit <b>30</b> is driven so as to interconnect the two bus segments <b>21</b> and <b>23</b>, thus forming a unitary bus via which all special function registers, such as the registers <b>18</b>, <b>24</b>, <b>26</b> and <b>28</b> shown as well as possibly further registers which are not shown, are interconnected. Thus, all registers can be accessed in the system mode. Because of the corresponding other value of the mode bit in the user mode, the connection unit <b>30</b> is driven, via the control lead <b>27</b>, so as to separate the two bus segments <b>21</b> and <b>23</b> from one another. The registers <b>18</b>, <b>28</b> and <b>24</b> as well as further registers connected to the bus <b>23</b> can then no longer be accessed, i.e. neither for writing nor for reading out.
[0027] The transition from the user mode to the system mode is made under the control of a special jump instruction whereby the mode bit in the register <b>28</b> is switched to the system mode. At the same time the start of the system program is called whose essential content is fixed so that it cannot be modified. In the system program, for example the register <b>18</b> can be modified so as to enable the addressing of other memory units or other segments in a memory unit during the subsequent user program. At the end of the system program, the mode bit in the register <b>28</b> is switched back again and hence the connection to the bus <b>23</b> is interrupted again in the connection unit <b>30</b>, via the control lead <b>27</b>, so that the registers connected thereto can no longer be accessed.
[0028]FIG. 2 is a more detailed representation of the construction of the connection unit <b>30</b>. The transfer of data from the bus <b>21</b> to the bus <b>23</b> takes place via a switch <b>302</b> whereas the data to be transferred from the bus <b>23</b> to the bus <b>21</b> is conducted via a switch <b>304</b>. The switches <b>302</b> and <b>304</b> are driven together via the control lead <b>27</b>. In the position of the switches <b>302</b> and <b>304</b> shown in FIG. 2, the connection is interrupted and data originating from a lead <b>306</b> with a fixed data value is transferred to the bus <b>21</b>. This data value corresponds, for example to the value of the jump instruction whereby a jump to the system mode is made. Therefore, should an inadmissible register be accessed in an inhibited manner in a user program, a value corresponding to the jump instruction is read out. If this value is to be interpreted as an instruction, such an inhibited access always triggers ajump to the system mode in which only fixed instruction sequences which cannot be modified by a user are executed.
[0029]FIG. 3 is a more detailed representation of some parts of the MMU <b>14</b>. The connection to the bus <b>11</b> leads to an address calculator <b>140</b> in which the data from the bus <b>11</b> is combined, as an address, with a more significant address part, arriving from the register <b>18</b> in FIG. 1, via the connection <b>19</b>, so as to be output via the connection <b>141</b>. The connection <b>141</b> leads to a blocking unit <b>144</b> and a comparator <b>142</b>. A second input of the comparator <b>142</b> is connected to the output of a register <b>32</b> which is also connected, as a special function register, to the bus <b>23</b> and is accessible only in the system mode and can be loaded with a value for an address limit in the system mode. The address limit is preferably compared with parts of the address on the connection <b>141</b> and, if the address is situated within the predetermined limit, the comparator <b>142</b> enables the blocking unit <b>144</b>, via the lead <b>141</b>, and the address is applied to the memory <b>20</b> of FIG. 1 via the connection <b>15</b>. The access to a part of a segment associated with the relevant user program can thus be inhibited in the user mode.
[0030] A further protection against the accessing of inhibited data is diagrammatically shown in FIG. 4. When the content of a memory location of the memory <b>20</b> of FIG. 1 is read out and the corresponding data is output via the connection <b>29</b>, the data is applied to a comparator <b>42</b> and to a further blocking unit <b>40</b>. A further input of the comparator <b>42</b> receives data from the register <b>18</b> which has been loaded via the bus <b>23</b>. The comparator <b>42</b> checks given parts of the data word on the connection <b>29</b> for correspondence to the data supplied by the register <b>18</b>. The blocking unit <b>40</b> is released, via the lead <b>43</b>, only in the case of correspondence and the data is then output via the connection <b>45</b>. This data is written into a data register <b>44</b> in dependence on appropriate control signals on control leads which are not separately shown, said data register <b>44</b> applying the data to the bus <b>11</b>, or into an instruction register <b>46</b> which applies this data as an instruction to an instruction decoder (not shown).
[0031] If data is to be written into the memory <b>20</b> of FIG. 1 from the bus <b>11</b>, via the data register <b>44</b>, this data is again conducted to the blocking unit <b>40</b> in which it is supplemented by data in conformity with the content of the register <b>18</b> after which it is written into the memory <b>20</b> via the connection <b>29</b>. As a result, when this data is read during the associated user program the necessary correspondence to the content of the register <b>18</b> is detected. During another user program, in which this test data has a different value, therefore, data of a different user program cannot be accessed.
[0032]FIG. 5 shows symbolically the subdivision into a protected system zone <b>50</b> and a non-protected user zone <b>60</b>. In the user zone <b>60</b> the access to a stack memory <b>62</b> and the program counter <b>64</b> is enabled. Moreover, one half of the register <b>59</b> for the program status word is available to the user zone. The other part of the register <b>59</b> is available only to the system zone <b>50</b>. Therein, the system stack memory <b>570</b>, <b>571</b> can be accessed via the register <b>57</b>; moreover, via an interface <b>52</b> to the bus for the special function registers, such as a register <b>56</b> for controlling the write enable in the memory and the register <b>55</b> for the accessing of memories as well as the register <b>54</b> for input/output operations and a register <b>53</b> for a co-processor which is preferably provided on the same chip, can also be accessed. Other registers of this kind (not shown) may also be provided.
[0033] The units indicated in the system zone <b>50</b> can be accessed only when the mode bit has been set. In the user zone the units <b>62</b> and <b>64</b> shown therein can be accessed, but the units shown in the system section <b>50</b> cannot be accessed.
[0034]FIG. 6 shows an example of the composition of a program status word <b>70</b>. The section <b>71</b> contains the mode bit. The section <b>72</b> contains a bit which can be used to check the program execution; this is important notably for the formation of programs. The content of the section <b>73</b> serves for register selection. The content of the section <b>74</b> serves to mask interrupt requests. These sections belong to the half of the program status word which can be modified only in the system mode.
[0035] The part behind the double stroke can also be read and modified in the user mode and comprises two sections <b>75</b> and <b>76</b> in which carry signals, arising in the ALU <b>12</b> of FIG. 1, are stored. The section <b>77</b> can be defined substantially independently of the user program. The section <b>78</b> stores the message that an overflow has occurred in the ALU <b>12</b> of FIG. 1. The section <b>79</b> indicates that a negative result has occurred in the ALU <b>12</b> and the section <b>80</b> indicates that the value zero has occurred during calculation. Because these are only signals of the ALU <b>12</b> of FIG. 1, the accessing of these sections must also be possible in the user mode.
Contents6
4 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US2005060540A1 | Cited by | United States of America | Pre-grant |
| US6820203B1 | Cited by | United States of America | Search report |
| US8639946B2 | Cited by | United States of America | Applicant |
| GB2427720B | Cited by | United Kingdom | Search report |
| US2006294397A1 | Cited by | United States of America | Pre-grant |
| US7124436B2 | Cited by | United States of America | Applicant |
| GB2427720A | Cited by | United Kingdom | Search report |
| US5491827A | Cites | United States of America | Pre-grant |
| US5600818A | Cites | United States of America | Pre-grant |
| US5701493A | Cites | United States of America | Pre-grant |
| US5754762A | Cites | United States of America | Pre-grant |
| US5963980A | Cites | United States of America | Pre-grant |
| US6003134A | Cites | United States of America | Pre-grant |
| US6034889A | Cites | United States of America | Pre-grant |
| US6594746B2 | Cites | United States of America | Pre-grant |
11 members in 4 offices
Priority claims8
| Document | Office | Kind | Date |
|---|---|---|---|
| 19804784 | Germany | A | |
| 24666299 | United States of America | A | |
| 41491503 | United States of America | A | |
| 09246662 | – | – | – |
| 198047843 | – | – | – |
| DE1998104784 | – | – | – |
| US19990246662 | – | – | – |
| US20030414915 | – | – | – |
Members11
| Document | Office | Kind | |
|---|---|---|---|
| EP0935214A2 | European Patent Office (EPO) | A2 | |
| DE19804784A1 | Germany | A1 | |
| JPH11272828A | Japan | A | |
| EP0935214A3 | European Patent Office (EPO) | A3 | |
| US2002169943A1 | United States of America | A1 | |
| US6594746B2 | United States of America | B2 | |
| US2003196054A1 | United States of America | A1 | |
| US6754794B2 | United States of America | B2 | |
| EP0935214B1 | European Patent Office (EPO) | B1 | |
| DE59914917D1 | Germany | D1 | |
| JP4559552B2 | Japan | B2 |
9 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| Fee paymentFPAY | FPAY | |
| Fee paymentFPAY | FPAY | |
| Fee paymentFPAY | FPAY | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| Information on status: patent grantGrantedPATENTED CASESTCF | STCF |
Numbers
- Publication, DOCDB
- 2003196054
- Publication, EPODOC
- US2003196054
- Application
- 10414915
- Application, DOCDB
- 41491503
- Application, EPODOC
- US20030414915
Titles
- English
- Chip card with integrated circuit
Classification
- CPC, 5
- G07F7/1008
- G06F21/74
- G06F21/79
- G06Q20/341
- G06Q20/3576
- IPC, 4
- G06K19 073
- G06F21 74
- G06F21 79
- G07F7 10
- USPC, 2
- 711163000
- 711156000