EP2104893A2 - Gesicherte elektronische systeme, sicherungsverfahren und verwendung solcher systeme - Google Patents
Gesicherte elektronische systeme, sicherungsverfahren und verwendung solcher systemeInfo
- Publication number
- EP2104893A2 EP2104893A2 EP07872435A EP07872435A EP2104893A2 EP 2104893 A2 EP2104893 A2 EP 2104893A2 EP 07872435 A EP07872435 A EP 07872435A EP 07872435 A EP07872435 A EP 07872435A EP 2104893 A2 EP2104893 A2 EP 2104893A2
- Authority
- EP
- European Patent Office
- Prior art keywords
- variant
- memory
- module
- heuristic
- systems
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Withdrawn
Links
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F12/00—Accessing, addressing or allocating within memory systems or architectures
- G06F12/14—Protection against unauthorised use of memory or access to memory
- G06F12/1408—Protection against unauthorised use of memory or access to memory by using cryptography
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/70—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer
- G06F21/71—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure computing or processing of information
- G06F21/72—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure computing or processing of information in cryptographic circuits
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/70—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer
- G06F21/71—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure computing or processing of information
- G06F21/77—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure computing or processing of information in smart cards
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/70—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer
- G06F21/78—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure storage of data
- G06F21/79—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure storage of data in semiconductor storage media, e.g. directly-addressable memories
Definitions
- the invention relates to embedded electronic systems including a processor and a computer data storage memory, security methods and uses of such systems.
- the systems of the invention are more particularly portable on-board systems manufactured in large series of identical systems. These include, for example, smart cards, including subscriber identification modules (SIMs), or electronic platforms for mobile phones or other small electronic devices.
- SIMs subscriber identification modules
- the electronic systems of the state of the art and, in particular, the on-board electronic systems, are likely to be attacked both at the software level and at the hardware level.
- a problem to be solved by the invention is to provide an electronic system, which has increased security against software and hardware attacks, including increased security against the reproducibility of such attacks, likely to be carried out on a large scale.
- the solution of the invention to this problem has for its first object an electronic system provided with a processor and a computer data storage memory, characterized in that it comprises a module for allocating physical write addresses. such data in said memory, said module being able to allocate said addresses according to a heuristic diversified by a variant.
- its second object is a method of securing an electronic system provided with a processor and a computer data storage memory, characterized in that said system comprises a physical address allocation module of writing such data in said memory and in that said module allocates said addresses according to a heuristic diversified by a variant.
- its third object is to use a method as defined above for securing an electronic system against software and hardware attacks.
- an attacker can not in any case expect to find computer data in a specific physical location within the memory of a secure system according to the invention. It must take into account that the location of these targeted data is different on each system, even if it is a system of an identical model.
- the physical location of the data to be protected is important information, both to target an attack on silicon, but also to determine the consequences of taking these data into account during the attack. system operation, the electromagnetic signature of the use of a data generally dependent on its physical position in silicon.
- the location of the data to be protected is also important because, depending on this location, an attacker does not have access to the same data on the stack, on the heap, or is not in executable space.
- the system further comprises a data access management module contained in the memory and said access management module is correlated to the allocation module; - the system is produced in series of identical systems; - the variant is a data unique to each system of a series of identical systems; the variant is a chip identifier; - the variant is a variable datum in the system; the variant is the current value of a monotone counter or the current time of a clock internal to the system or provided by an external clock signal; the variant is random or pseudo-random; - the variant is not modifiable in the system or the integrity of the variant is protected; - the variant is encrypted content in the system; the address allocation heuristic is further varied according to one or a plurality of behavioral factors of the system; - behavioral factors are states of the life cycle of the system; - the behavioral factors are derived from external information transmitted to the system; the address allocation heuristic is varied by a variant only in one or a plurality of specific persistent or transient states of the system; the address allocation heuristic is varied
- FIG. 1 is a schematic representation of a system according to the invention.
- the secure systems according to the invention are electronic systems, for example of the embedded type, provided with a processor and a computer data storage memory. Such systems are in particular portable systems manufactured in large series such as smart cards, including subscriber identification modules (SIMs), or such as electronic platforms for mobile phones or other electronic devices of reduced size.
- the processor is a microprocessor or a microcontroller.
- the storage memory is advantageously a read-only (ROM) persistent memory, for example of the PROM (programmable) type, NVRAM (non-volatile random access memory) for example of the EEPROM (electrically erasable programmable) or Flash type, or else, optionally, a random access memory (RAM), for example SRAM (static) or DRAM (dynamic).
- ROM read-only
- PROM programmable
- NVRAM non-volatile random access memory
- EEPROM electrically erasable programmable
- Flash or else, optionally, a random access memory (RAM), for example SRAM (static) or DRAM (dynamic
- the systems according to the invention also comprise a module for allocating the write addresses of the computer data in the storage memory.
- This module is invoked whenever it is necessary to allocate a memory area, and consequently one or more physical addresses, for writing new data, that is to say for programming the memory.
- This module is a hardware or software entity. It is correlated to a memory access management module intended to manage the accesses, in particular for reading the written data, and whose physical locations in the memory have been allocated by the allocation module.
- This memory access management module makes it possible, where appropriate, to associate the logical locations of the data with their physical locations.
- the memory access management module forms a hardware or software entity. In the case where it forms a physical entity, it is the MMU
- the MAA memory access and memory allocation module
- the MAA is able to allocate addresses and, in particular, physical addresses of this memory, according to a heuristic diversified by a variant.
- the allocation heuristic applies to pages or memory areas that belong to a specific process, or to all pages in the memory. It is therefore a local allocation or a global allocation.
- the allocated addresses are actually physical addresses corresponding to physical locations in persistent memory of the system according to the invention.
- the variant is a variable datum of a system considered with respect to other identical systems of the same series and / or a variable datum in the same system considered, over time.
- identical systems are understood to mean systems which have comparable characteristics and functionalities and intended for similar uses, for example the same model of a mobile phone platform.
- the variant is a unique data to the system, including a chip identifier.
- the memory allocation heuristic is then specific of a system considered in a series of identical systems.
- the variant is the current value of a monotone counter or the current time of a clock internal to the system or provided by an external clock signal.
- the allocation heuristic varies over time for the same system.
- the variant is a random or pseudo-random number generated by the system, preferably according to a secure algorithm. This number can be generated once and for all in a system considered or generated at different times. In the case where it is generated once and for all, the memory allocation heuristic will then be different in identical systems of the same series but it will always be identical in the same system. In the case where this number is not generated once and for all in a given system, the memory allocation heuristic will vary in this system over time.
- the variant according to the invention may be a complex variable data function of several unit variants. It may be, for example, a variable data function of both a chip identifier according to the first example above and a clock signal according to the second example above.
- the degree of security of a system according to the invention is proportional to the variability of the variant, especially when faced with the risk of cloning of this system.
- this identifier can effectively be used alone as a variant.
- this choice has the disadvantage of being, to a certain extent, predictable.
- variants with greater variability such as random or pseudo-random numbers, will be favorably selected or combined.
- the variant is advantageously secured in the system.
- it is non-modifiable or integrity protected.
- it is made confidential.
- the variant is entered in the ROM of the system during its production, or else in programmable memory type PROM or EPROM write once, or in a programmable memory of type with multiple writes. In this latter embodiment, it is then checked in integrity at each memory access or on certain occasions.
- the variant is made confidential, it is advantageously encrypted in the system and kept secret by it, or else transmitted to the system through a secure channel preserving confidentiality and kept secret.
- the MAA is able to allocate physical addresses of this memory according to a diversified heuristic according to factors behavioral characteristics of the system, these factors defining different behaviors of the MAA: behavior 1, behavior 2, ..., behavior n.
- the behavioral factors are known internal conditions of the systems.
- the memory allocation heuristic used by the MAA may or may not involve a variant depending on whether the system is in a specific state. This specific state can be a persistent state of the system.
- a specific state of the life cycle of the system such as a customization phase, a phase of production or normal use of the system, for example in a degraded or non-functional state, a threshold state or a debugging state.
- This specific state may be a transient state of the system. This is for example the opening of a secure section of a program implemented by the system or critical phases of its operation such as restarting or shutdown.
- the behavioral factors are derived from external information transmitted to the systems.
- the memory allocation heuristic used by the MAA may or may not involve the variant when this is explicitly requested by an external user of the system - man or machine - through indications transmitted to the system.
- the behavioral factors derive from the type of memory concerned by the allocation.
- the memory allocation heuristic used by the MAA may or may not involve the variant depending on the type of programmable memory targeted by the allocation.
- the behavioral factors are temporal data.
- the memory allocation heuristic used by the MAA may or may not involve the next variant whether or not one is at a specific time in time.
- the following exemplary embodiments relate to the heuristics implemented by the MAA, for the writing of data diversified by a variant and, possibly, by behavioral factors, and for access to said written data.
- the MAA uses a memory allocation heuristic where the physical address of the next memory block to be allocated is calculated from a deterministic algorithm dependent on a variant. We then have a function that associates with logical address and given variant, one and the same physical address of allocation. For the sake of the security of the system, it may be interesting to use, as an algorithm, a function called "one-way", that is to say a function of which it is deemed very difficult, in the current state knowledge, to calculate the input values from the output values. By making this choice, it makes it very difficult to calculate a logical address from a physical address.
- the heuristic for allocating the physical addresses of the memory blocks for storing the data is diversified by a variant and according to a behavioral factor.
- the MAA implements a traditional allocation heuristic, which is not diversified by a variant.
- the MAA implements a heuristic diversified by a variant according to which the MAA performs a reworking of all or part of the memory blocks previously allocated, and according to an algorithm dependent on this variant. After these revisions, the MAA switches back to normal mode.
- the performance of the system is absolutely not degraded in the normal operating mode.
- Performance is degraded only in the transient state that is of course triggered at times in which system performance is not required.
- the reworking of the blocks can be performed on memory blocks by size groups. fixed or variable and that it is likely to be limited to subsets of the programmable memory.
- the systems according to the invention manipulate logical addresses
- the MAA then accesses, for the translation of these logical addresses into physical addresses, an address table, or implements a variant-dependent algorithm, or else, uses a combination of such a table and such an algorithm.
- the use of an address table does not significantly degrade the performance of the system. However, this table requires memory resources.
- the use of an algorithm is likely to significantly degrade system performance, since a computation is necessary each time it is necessary to convert a logical address into a physical address. Nevertheless, the implementation of this algorithm does not require or little additional memory space.
- the variant is not necessary that the variant is preserved.
- the variant is variable such as, in particular, the case of a variant formed of a random number generated several times or if necessary, and in the case where an address table is maintained, then the variant is simply disposable.
- the address of the address table may itself depend on an initial variant or another variant which, it will be retained.
- the systems according to the invention are secured against the reproducibility of hardware attacks by simple analysis of the power consumption (SPA) of the system or by electromagnetic analysis.
- SPA power consumption
- the power consumption of a given system is generally a function of the physical address of the data to be accessed.
- the invention makes it possible to vary the physical address of the same information on two identical systems. Attacks, which could be carried out on systems identical to a first system will be as difficult to conduct as the first system attacked, which is not the case for systems of the state of the art.
- the invention harms the reproducibility of attacks proceeding by time analysis (timing attacks).
- timing attacks the access time to a given physical address is normally dependent on the physical address to access.
- this physical address varies from one system to another identical system.
- the access time to the same information varies from one system to another and the attack is not reproducible.
- the invention impairs the reproducibility of visualization-based or physical modification-based attacks, in particular using a laser or carrying out chemical etching. Indeed, for these attacks to be carried out, it is necessary to identify the physical locations to attack. However, the invention makes it possible to vary the spatial location of the same information on two identical systems. The implementation of this identification is thus more difficult.
- the invention is detrimental to the reproducibility of fault injection attacks. These attacks consist in operating systems under particular conditions, for example, at low frequencies, at high temperatures, or by means of a desynchronized clock, or else to operate these systems after a physical damage generated in particular by a laser, then to analyze the behavior of the material under these conditions. If, under the chosen conditions, the current consumption or the access time to a data vary on two identical systems according to the invention, it is necessary to inject a different fault on each system. In addition, the temporal synchronization of these attacks being very often based on an electromagnetic analysis itself disturbed by the invention, the difficulty of reproducing the attack is further increased. The invention is detrimental to attempts at cloning.
- the content of a first system can not, in this case, be correctly interpreted by the MAA of a second system, making all copy of the contents of the first system on the second useless system.
- the invention complicates software attacks that exploit particular memory configurations. For example, a virus that uses a stack overflow with a specific coding will not have the same data in the stack and it will be much more complicated for it to be grafted to a program by directly accessing the memory, the position of that last being variable from one copy to another of the system.
Landscapes
- Engineering & Computer Science (AREA)
- Theoretical Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Physics & Mathematics (AREA)
- Computer Hardware Design (AREA)
- General Engineering & Computer Science (AREA)
- General Physics & Mathematics (AREA)
- Software Systems (AREA)
- Mathematical Physics (AREA)
- Storage Device Security (AREA)
- Multi Processors (AREA)
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| FR0611283A FR2910658B1 (fr) | 2006-12-22 | 2006-12-22 | Systemes electroniques securises,procedes de securisation et utilisations de tels systemes |
| PCT/FR2007/002152 WO2008096076A2 (fr) | 2006-12-22 | 2007-12-21 | Systemes electroniques securises, procedes de securisation et utilisations de tels systemes |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| EP2104893A2 true EP2104893A2 (de) | 2009-09-30 |
Family
ID=38318668
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP07872435A Withdrawn EP2104893A2 (de) | 2006-12-22 | 2007-12-21 | Gesicherte elektronische systeme, sicherungsverfahren und verwendung solcher systeme |
Country Status (5)
| Country | Link |
|---|---|
| EP (1) | EP2104893A2 (de) |
| JP (1) | JP2010514039A (de) |
| BR (1) | BRPI0721042A2 (de) |
| FR (1) | FR2910658B1 (de) |
| WO (1) | WO2008096076A2 (de) |
Families Citing this family (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2020226054A1 (ja) * | 2019-05-07 | 2020-11-12 | 株式会社日立製作所 | 情報処理方法、情報処理装置及び記憶媒体 |
Family Cites Families (6)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JPS63157365A (ja) * | 1986-12-19 | 1988-06-30 | Fuji Xerox Co Ltd | 物理アドレス変換装置 |
| FR2745924B1 (fr) * | 1996-03-07 | 1998-12-11 | Bull Cp8 | Circuit integre perfectionne et procede d'utilisation d'un tel circuit integre |
| TW494306B (en) * | 1998-10-27 | 2002-07-11 | Winbond Electronics Corp | Secret code protection circuit capable of protecting read only memory data |
| JP3936630B2 (ja) * | 2002-06-20 | 2007-06-27 | 株式会社日立製作所 | 半導体試験装置または半導体装置の検査方法または半導体装置の製造方法 |
| TWI258658B (en) * | 2003-07-07 | 2006-07-21 | Sunplus Technology Co Ltd | Device in CPU using address line to proceed scrambling processing and method thereof |
| US7506178B2 (en) * | 2004-05-04 | 2009-03-17 | International Business Machines Corporation | Tamper-resistant re-writable data storage media |
-
2006
- 2006-12-22 FR FR0611283A patent/FR2910658B1/fr not_active Expired - Fee Related
-
2007
- 2007-12-21 EP EP07872435A patent/EP2104893A2/de not_active Withdrawn
- 2007-12-21 JP JP2009542142A patent/JP2010514039A/ja active Pending
- 2007-12-21 WO PCT/FR2007/002152 patent/WO2008096076A2/fr not_active Ceased
- 2007-12-21 BR BRPI0721042-6A patent/BRPI0721042A2/pt not_active IP Right Cessation
Non-Patent Citations (1)
| Title |
|---|
| See references of WO2008096076A3 * |
Also Published As
| Publication number | Publication date |
|---|---|
| FR2910658B1 (fr) | 2009-02-20 |
| WO2008096076A2 (fr) | 2008-08-14 |
| FR2910658A1 (fr) | 2008-06-27 |
| WO2008096076A3 (fr) | 2008-10-02 |
| JP2010514039A (ja) | 2010-04-30 |
| BRPI0721042A2 (pt) | 2014-07-29 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| EP1616242B1 (de) | Verfahren und einrichtung zur steuerung eines zugriffs auf peripheriegeräte | |
| FR2977694A1 (fr) | Microprocesseur protege contre un debordement de pile | |
| FR2935823A1 (fr) | Procede et dispositif de protection d'un microcircuit contre les attaques. | |
| WO2012085482A1 (fr) | Protection des applets contre les analyses par canaux caches | |
| EP2565810A1 (de) | Mikroprozessor, der gegen Speicherabzug geschützt ist | |
| EP1904946B1 (de) | Entdeckung eines fehlers durch eine lange störung | |
| EP2104893A2 (de) | Gesicherte elektronische systeme, sicherungsverfahren und verwendung solcher systeme | |
| FR2923923A1 (fr) | Verification de donnees lues en memoire | |
| EP3392791B1 (de) | Verfahren zur ausführung eines programms, das zur interpretation durch eine virtuelle maschine bestimmt ist, die gegen angriffe durch fehler-injektion geschützt ist | |
| WO2005101725A1 (fr) | Procede d'authentification dynamique de programmes par un objet portable electronique | |
| EP3042334B1 (de) | Verfahren zur installation einer sicherheitsvorrichtung in abhängigkeit einen vertrauensindex in einer elektronischen vorrichtung mit speicher und vorrichtung zur durchführung des verfahrens | |
| EP2860660A1 (de) | Gesichertes Ladesystem und -verfahren von Daten in einen mit einem gesicherten Prozessor verbundenen Cache-Speicher | |
| Gravellier | Remote hardware attacks on connected devices | |
| EP2860669B1 (de) | Verfahren in einem Mikroschaltkreis durgeführt und entsprechende Vorrichtung | |
| FR3120717A1 (fr) | Procédé d'exécution d'un code binaire d'un programme d'ordinateur par un microprocesseur | |
| FR2974648A1 (fr) | Protection d'une memoire vive contre des attaques par injection de fautes | |
| EP1715436A2 (de) | Schutz des Ablaufs eines von einem integrierten Schaltkreis ausgeführten Programms oder von Daten, die in diesem Schaltkreis enthalten sind | |
| EP4632579A1 (de) | Verfahren zum schutz eines mikrokontrollers | |
| FR3011656A1 (fr) | Procede et dispositif de realisation de fonction par un microcircuit | |
| FR3105484A1 (fr) | Méthode de vérification dynamique de l’intégrité d’un code machine | |
| EP4307143A1 (de) | Verfahren und schaltungsanordnung zur überprüfung der integrität von software | |
| EP3203405B1 (de) | Verfahren zur ausführung von objektorientierten anwendungsanweisungen durch einen dolmetscher | |
| FR2933791A1 (fr) | Procede de verification de l'integralite d'une memoire eeprom | |
| EP3179400B1 (de) | Verfahren zum hochladen einer it-ressource in einem elektronischen gerät, elektronisches modul und entsprechendes computerprogramm | |
| WO2007051770A1 (fr) | Procede securise de manipulations de donnees lors de l'execution d'algorithmes cryptographiques sur systemes embarques |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| 17P | Request for examination filed |
Effective date: 20090716 |
|
| AK | Designated contracting states |
Kind code of ref document: A2 Designated state(s): AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HU IE IS IT LI LT LU LV MC MT NL PL PT RO SE SI SK TR |
|
| 17Q | First examination report despatched |
Effective date: 20091022 |
|
| DAX | Request for extension of the european patent (deleted) | ||
| RAP1 | Party data changed (applicant data changed or rights of an application transferred) |
Owner name: TRUSTED LOGIC |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE APPLICATION IS DEEMED TO BE WITHDRAWN |
|
| 18D | Application deemed to be withdrawn |
Effective date: 20130702 |