IP Library › Granted Patent US 10,509,568
Granted Patent B2
US 10,509,568 · App. 15/254,480 · Granted Dec 17, 2019

Efficient secure boot carried out in information processing apparatus

Inventors: Mikio Hashimoto (Tokyo, JP); Kentaro Umesawa (Kanagawa, JP); Yoshiyuki Amanuma (Tokyo, JP)
Assignee: KABUSHIKI KAISHA TOSHIBA
G06F3/061G06F3/062G06F3/0637G06F3/0665G06F3/0673G06F9/4401G06F21/575G11C14/00G11C16/3459G11C16/22
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,509,568
App. No.
15/254,480
Granted
Dec 17, 2019
Kind
B2
Abstract

An information processing apparatus includes a nonvolatile memory, a flag settable to a first value indicating that a program stored in a memory region of the nonvolatile memory has not been verified, and to a second value indicating that the program has been verified, a switching circuit configured to set the flag to the first value, in response to a request for permission to modify the program stored in the memory region, and a verification circuit that sets the flag to the second value upon verification of the program stored in the memory region, and upon restart of the information processing apparatus, carries out a verification process of the program prior to execution of the program if the first value is set in the flag, and executes the program without the verification process if the second value is set in the flag.

Claims (56)

1. An information processing apparatus, comprising:

a processor;

a rewritable nonvolatile memory that stores a first flag settable to a first value indicating that a program stored in a first memory region of the nonvolatile memory has not been verified, and to a second value indicating that the program has been verified, the first memory region of the nonvolatile memory being an execute-in-place (XIP) region;

a switching circuit comprising a control register that stores a second flag settable either to a third value indicating that data writing to the first memory region is prohibited or to a fourth value indicating that the data writing to the first memory region is allowed, and configured to, upon receipt of a request for permission to set the first memory region from non-writable to writable, set the first flag to the first value, and thereafter set the second flag from the third value to the fourth value; and

a verification circuit configured to

set the second flag to the third value before the start of a verification process of the program stored in the first memory region, and set the first flag to the second value after the verification process finished successfully, and

upon restart of the information processing apparatus, carry out the verification process of the program prior to execution of the program if the first value is set in the first flag, and execute the program without carrying out the verification process if the second value is set in the first flag,

wherein the information processing apparatus is a microcontroller implemented as a single chip or a single package that includes the processor, the rewritable nonvolatile memory, the switching circuit, and the verification circuit.

2. The information processing apparatus according to claim 1 , wherein

the first flag is stored in a second memory region of the nonvolatile memory that is different from the first memory region of the nonvolatile memory.

3. The information processing apparatus according to claim 1 , wherein

the first memory region is non-writable when the third value is set in the second flag, and the first memory region is writable when the fourth value is set in the second flag.

4. The information processing apparatus according to claim 1 , wherein

the program is executable when the verification process is successful, and not executable when the verification process fails.

5. The information processing apparatus according to claim 1 , wherein

during the verification process, the verification circuit calculates a hash value of the program stored in the first memory region, extracts a hash value from a public key signature of the program, and compares the hash values.

6. The information processing apparatus according to claim 1 , wherein

a hash value extracted from a public key signature of the program is stored in another memory region of the nonvolatile memory, and

during the verification process, the verification circuit calculates a hash value of the program stored in the first memory region, and compares the stored hash value and the calculated hash value.

7. The information processing apparatus according to claim 1 , wherein

the verification circuit is configured to carry out the verification process in response to a verification request from the processor.

8. The information processing apparatus according to claim 1 , further comprising:

a non-rewritable nonvolatile memory that stores a verification program, wherein

the verification circuit carries out the verification process in accordance with the verification program.

9. The information processing apparatus according to claim 1 , further comprising:

a network interface, wherein

the processor stores the program downloaded through the network interface onto the rewritable nonvolatile memory before the program is verified.

10. The information processing apparatus according to claim 1 , wherein

the processor stores the program onto the rewritable nonvolatile memory while performing the download.

11. A method for operating an information processing apparatus including a processor, a rewritable nonvolatile memory that stores a first flag settable to a first value indicating that a program stored in a first memory region of the nonvolatile memory has not been verified, and to a second value indicating that the program has been verified, the first memory region of the nonvolatile memory being an XIP region, and a switching circuit comprising a control register that stores a second flag settable either to a third value indicating that data writing to the first memory region is prohibited or to a fourth value indicating that the data writing to the first memory region is allowed, the method comprising:

upon receipt of a request for permission to set the first memory region from non-writable to writable, setting, by the switching circuit, the first flag to the first value, and thereafter set the second flag from the third value to the fourth value;

before the start of a verification process of the program stored in the first memory region, setting, by a verification circuit, the second flag to the third value;

upon restart of the information processing apparatus, carrying out, by the verification circuit, the verification process of the program prior to execution of the program if the first value is set in the first flag, and executing the program without carrying out the verification process if the second value is set in the first flag; and

after the verification process finished successfully, setting, by the verification circuit, the first flag to the second value,

wherein the information processing apparatus is a microcontroller implemented as a single chip or a single package that includes the processor, the rewritable nonvolatile memory, the switching circuit, and the verification circuit.

12. The method according to claim 11 , wherein

the first flag is stored in a second memory region of the nonvolatile memory that is different from the first memory region of the nonvolatile memory.

13. The method according to claim 11 , wherein

the first memory region is non-writable when the third value is set in the second flag, and the first memory region is writable when the fourth value is set in the second flag.

14. The method according to claim 11 , wherein

the program is executable when the verification process is successful, and not executable when the verification process fails.

15. The method according to claim 11 , wherein the verification process comprises:

calculating a hash value of the program stored in the first memory region;

extracting a hash value from a public key signature of the program; and

comparing the hash values.

16. The method according to claim 11 , wherein

a hash value extracted from a public key signature of the program is stored in another memory region of the nonvolatile memory, and

the verification process comprising:

calculating a hash value of the program stored in the first memory region; and

comparing the stored hash value and the calculated hash value.

17. The method according to claim 11 , further comprising:

issuing a verification request from the processor, wherein

the verification process is carried out in response to the verification request by the verification circuit that is provided separately from the processing unit.

18. The method according to claim 11 , wherein

the information processing apparatus further includes a non-rewritable nonvolatile memory that stores a verification program, and

the verification process is carried out in accordance with the verification program.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 15, 2016
From: HASHIMOTO, MIKIO; UMESAWA, KENTARO; AMANUMA, YOSHIYUKI
To: KABUSHIKI KAISHA TOSHIBA
Reel/Frame 040330/0030 →
Priority Claims (1)
JP 2016-038991 · Mar 1, 2016 · national
Continuity (1)
Related Publication 20170255384A1 · Sep 7, 2017