IP Library Granted Patent US 8,006,058
Granted Patent B2
US 8,006,058 · App. 10/416,754 · Granted Aug 23, 2011

Method and securing electronic device data processing

Assignee: Gemalto SA
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,006,058
App. No.
10/416,754
Granted
Aug 23, 2011
Kind
B2
Abstract

A method for securing electronic device processes against attacks (e.g. side channel attacks) during the processing of sensitive and/or confidential data by a Central Processing Unit (CPU) to the volatile memory (e.g. RAM) of an electronic device such as, for example, a smart card, a PDA or a cellular phone is described herein. The method involves the storage of the confidential data to a dynamically and randomly assigned memory location, thereby rendering more difficult the analysis and subsequently the attacks (e.g. side channel attacks).

Claims (22)

1. A method for securing data storage in a volatile memory of an electronic device, said method comprising:

defining a dedicated area in the volatile memory, the length of the dedicated area being equal to the length of the data to be stored;

randomly defining an offset from the beginning of the dedicated area;

transferring a first part of the data to the dedicated data area at a memory location determined by the offset, wherein the length of the first part corresponds to the difference between the end of the dedicated area and the offset; and

transferring a second part of said data to a memory location corresponding to the beginning of the dedicated area.

2. A device for securing data storage in a volatile memory of an electronic device, comprising:

means for defining a dedicated area in the volatile memory, the length of the dedicated area being equal to the length of the data to be stored;

means for randomly defining an offset from the beginning of the dedicated area; and

means for transferring an initial portion of the data to the dedicated data area at a memory location determined by the offset,

wherein said initial portion has a length corresponding to the difference between the end of the dedicated area and said offset, and thereafter transferring the remaining portion of said data to a memory location corresponding to the beginning of the dedicated area.

3. The device according to claim 2 , wherein the means for randomly defining an offset comprises means for preventing the transferred data from exceeding the dedicated area.

4. The device according to claim 3 , wherein the means for preventing the transferred data from exceeding the dedicated area comprises means for choosing as the offset a number located between zero and the difference between the length of the dedicated area and the length of the confidential data minus one.

5. A secure electronic device for processing data received from an input/output device, said device comprising:

an Electrically-Erasable Programmable Read-Only Memory (EEPROM) for receiving the data from the input/output device;

an input/output port for transferring the data from the input/output device to the EEPROM;

a volatile memory for transferring the data during processing, said volatile memory including a dedicated area, the length of the dedicated area being at least equal to the length of the data to be transferred; and

a data processing CPU comprising a random offset determining means and a data transfer means responsive to the random offset,

wherein the data transfer means is adapted to:

transfer a first part of the data to the dedicated data area at a memory location of the dedicated area determined by the offset, said length of the first part corresponding to the difference between the end of the dedicated area and the offset, and

transfer a second part of said data to a memory location corresponding to the beginning of the dedicated area.

6. A device according to claim 5 , wherein said volatile memory is selected from the group consisting of Random Access Memory (RAM), Internal Register and Cache Memory.

7. A device according to claim 5 , wherein the electronic device is selected from the group consisting of a smart card, a Personal Digital Assistant (PDA) and a cellular phone.

Assignments (2)
MERGER Recorded Jul 12, 2011
From: GEMPLUS
To: GEMALTO SA
Reel/Frame 026578/0442 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 20, 2003
From: BENOIT, OLIVIER
To: GEMPLUS
Reel/Frame 014795/0006 →
Priority Claims (1)
CA 2326036 · Nov 16, 2000 · national
Continuity (1)
Related Publication 20040093306A1 · May 13, 2004