IP Library Granted Patent US 9,582,675
Granted Patent B2
US 9,582,675 · App. 14/871,873 · Granted Feb 28, 2017

Protection of memory areas

Inventors: Albert Martinez (Bouc Bel Air, FR); William Orlando (Peynier, FR)
Assignee: STMicroelectronics S.A.
G06F21/62G06F12/1408G06F12/1483G06F21/52G06F21/602G06F21/79G06F2212/1052G06F2221/033G06F2221/2105
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,582,675
App. No.
14/871,873
Granted
Feb 28, 2017
Kind
B2
Abstract

A method for loading a program, contained in at least a first memory, into a second memory accessible by an execution unit, in which the program is in a cyphered form in the first memory, a circuit for controlling the access to the second memory is configured from program initialization data, instructions of the program, and at least initialization data being decyphered to be transferred into the second memory after configuration of the circuit.

Claims (25)

1. A method to load a program from a first memory where the program is stored in a ciphered form, into a second memory accessible by an execution unit, the method comprising:

at initialization, before the program is ciphered, configuring a circuit with the program, the circuit then configured to control access to the second memory;

ciphering at least a first portion of the program with a ciphering key to create configuration data associated with the program, the configuration data used with at least header information of the program, wherein the header information is not ciphered;

providing a cryptographic signature to the remaining portions of the program that are not ciphered; and

controlling access to the second memory using the configured circuit.

2. The method of claim 1 , further comprising

a third memory and transferring the program to the first memory from the third memory.

3. The method of claim 2 , wherein the first and second memories are each separate memory portions contained within a single memory.

4. A method to load an application from an external first memory where the application is stored into an internal second memory accessible by an execution unit, the method comprising:

at initialization, when the application is not ciphered, configuring a control circuit to control access to the internal second memory;

receiving a header portion of the application, a program code portion of the application, and an initialization data portion of the application;

in a trusted external environment, executing a function to cypher with a cyphering key the program code portion of the application and the initialization data portion of the application;

storing the cyphered program code portion of the application and the cyphered initialization data portion of the application in the internal second memory;

in the trusted external environment, generating configuration data having a cryptographic signature, the configuration data associated with the cyphered program code portion and the cyphered initialization data portion;

storing the configuration data in the internal second memory; and

storing the header portion of the application in the internal second memory.

5. The method of claim 4 , wherein receiving the header portion, the program code portion, and the initialization data portion includes receiving said portions from an Internet accessible server device.

6. The method of claim 4 , wherein receiving the header portion, the program code portion, and the initialization data portion includes receiving said portions from a hard disk.

7. The method of claim 4 , wherein receiving the header portion, the program code portion, and the initialization data portion includes receiving said portions from an EEPROM.

8. The method of claim 4 , wherein storing the configuration data in the internal second memory includes storing un-cyphered configuration data.

9. The method of claim 4 , wherein the trusted external environment includes a secondary processor.

10. The method of claim 4 , comprising:

retrieving, via the control circuit, the program code portion and the initialization data portion from the second memory; and

using the cryptographic signature to authenticate the program code portion and the initialization data portion.

11. The method of claim 10 , wherein the retrieving is performed when the execution unit is operating in a supervisor mode and wherein the application is executed by the execution unit when the execution unit is operating in a mode that is not the supervisor mode.

Assignments (1)
CHANGE OF NAME Recorded Apr 9, 2024
From: STMICROELECTRONICS SA
To: STMICROELECTRONICS FRANCE
Reel/Frame 067055/0481 →
Priority Claims (1)
FR 06 55692 · Dec 20, 2006 · national
Continuity (3)
Division 13751628 · Jan 28, 2013
Division 11958989 · Dec 18, 2007
Related Publication 20160026811A1 · Jan 28, 2016