IP Library Granted Patent US 10,459,848
Granted Patent B2
US 10,459,848 · App. 15/497,763 · Granted Oct 29, 2019

Method for optimising memory writing in a device

Inventors: Guillaume Dabosville (Issy les Moulineaux, FR); Philippe Gislard (Issy les Moulineaux, FR); Victor Servant (Issy les Moulineaux, FR)
Assignee: SAFRAN IDENTITY & SECURITY
G06F12/1408G06F3/065G06F3/0619G06F3/0685G06F12/0223G06F12/1425G06F12/1433G06Q20/35765G06F2212/1052G06F2212/177G06F2212/2532
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,459,848
App. No.
15/497,763
Granted
Oct 29, 2019
Kind
B2
Abstract

Provided is a method for optimising memory writing in a device implementing a cryptography module and a client module calling functions implemented by the cryptography module. The device includes a random access memory including a first memory zone that is secured and dedicated to the cryptography module and a second memory zone dedicated to the client module. When the client module calls a series of functions implemented by the cryptography module including a first function and at least one second function, with each second function executed following the first function or from a further second function and providing a runtime result added to a runtime result of the preceding series function, each runtime result is added to a value contained in a buffer memory allocated in the first memory. The buffer memory value is copied to the second memory zone following the execution of the last function of the series.

Claims (15)

1. A method for optimizing memory writing in a device implementing a plurality of software modules, a first software module comprising functions handling confidential data, a third software module allowing functions, called client functions, of a second software module to call functions, called cryptography functions, of the first software module, each software function being stored in a non-volatile memory of said device, and being executed in a runtime environment comprising an interpreter stored in a read only memory of said device, said device comprising a random access memory divided into a plurality of memory zones, a first memory zone of the plurality being secured and being able to be used exclusively by the first and third software modules, a second memory zone being able to be used exclusively by the second and third software modules, wherein the method comprises:

obtaining a series of client functions comprising a first client function and at least one second client function, each second client function having to be executed following the first client function or a further second client function and providing a runtime result that must be added to a runtime result of the client function preceding it in the series, each client function of the series calling a cryptography function;

allocating a buffer memory in the first memory zone and setting this buffer memory to a value equal to a predefined value;

launching a sequenced execution of each client function of the series, each execution of one of said client functions comprising a call, through the third software module, to the cryptography function affected by said client function, causing said cryptography function to be executed in the first memory zone, the runtime result of said cryptography function being added to the value contained in the buffer memory; and

copying, in the second memory zone, the value contained in the buffer memory following the execution of the last client function of the series.

2. The method according to claim 1 , wherein the first memory zone is read and write blocked by default and is only unblocked when a cryptography function is executed, the second memory zone being read and write blocked each time a cryptography function is executed.

3. The method according to claim 1 , wherein the random access memory comprises a third memory zone, through which each data item passes that is exchanged between the first and second software modules from the first memory zone to the second memory zone or from the second memory zone to the first memory zone.

4. The method according to claim 1 , wherein each data item exchanged between the first and second software modules is copied from the first memory zone to the second memory zone or from the second memory zone to the first memory zone and, prior to each copying operation, a check is implemented that ensures that the first memory zone does not contain any confidential data and, if the first memory zone contains confidential data, said confidential data is deleted.

5. A non-transitory computer readable storage medium storing a computer program product comprising instructions causing the implementation of the method according to claim 1 when the instructions are executed by the device implementing a plurality of software modules after having been loaded by said device.

6. A device implementing a plurality of software modules, a first software module comprising functions handling confidential data, a third software module allowing functions, called client functions, of a second software module to call functions, called cryptography functions, of the first software module, each software function being stored in a non-volatile memory of said device, and being executed in a runtime environment comprising an interpreter stored in a read only memory of said device, said device comprising a random access memory divided into a plurality of memory zones, a first memory zone of the plurality being secured and being able to be used exclusively by the first and third software modules, a second memory zone being able to be used exclusively by the second and third software modules, wherein the device comprises electronic circuitry adapted for:

obtaining a series of client functions comprising a first client function and at least one second client function, each second client function having to be executed following the first client function or a further second client function and providing a runtime result that must be added to a runtime result of the client function preceding it in the series, each client function of the series calling a cryptography function;

allocating a buffer memory in the first memory zone and setting this buffer memory to a value equal to a predefined value;

launching a sequenced execution of each client function of the series, each execution of one of said client functions comprising a call, through the third software module, to the cryptography function affected by said client function, causing said cryptography function to be executed in the first memory zone, the runtime result of said cryptography function being added to the value contained in the buffer memory; and

copying, in the second memory zone, the value contained in the buffer memory following the execution of the last client function of the series.

7. The method according to claim 6 , wherein the device is chip card.

Assignments (10)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 26, 2025
From: IDEMIA IDENTITY & SECURITY FRANCE
To: IDEMIA FRANCE
Reel/Frame 070632/0157 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ERRONEOUSLY NAMED PROPERTIES 14/366,087 AND 15/001,534 PREVIOUSLY RECORDED ON REEL 048039 FRAME 0605. ASSIGNOR(S) HEREBY CONFIRMS THE CHANGE OF NAME. Recorded Jan 17, 2024
From: MORPHO
To: SAFRAN IDENTITY & SECURITY
Reel/Frame 066343/0143 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ERRONEOUSLY NAMED PROPERTIES 14/366,087 AND 15/001,534 PREVIOUSLY RECORDED ON REEL 047529 FRAME 0948. ASSIGNOR(S) HEREBY CONFIRMS THE CHANGE OF NAME. Recorded Jan 17, 2024
From: SAFRAN IDENTITY & SECURITY
To: IDEMIA IDENTITY & SECURITY
Reel/Frame 066343/0232 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE ERRONEOUSLY NAME PROPERTIES/APPLICATION NUMBERS PREVIOUSLY RECORDED AT REEL: 055108 FRAME: 0009. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 17, 2024
From: SAFRAN IDENTITY & SECURITY
To: IDEMIA IDENTITY & SECURITY FRANCE
Reel/Frame 066365/0151 →
CORRECTIVE ASSIGNMENT TO CORRECT THE THE REMOVE PROPERTY NUMBER 15001534 PREVIOUSLY RECORDED AT REEL: 055314 FRAME: 0930. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 17, 2024
From: SAFRAN IDENTITY & SECURITY
To: IDEMIA IDENTITY & SECURITY FRANCE
Reel/Frame 066629/0638 →
CORRECTIVE ASSIGNMENT TO CORRECT THE APPLICATION NUMBER PREVIOUSLY RECORDED AT REEL: 055108 FRAME: 0009. ASSIGNOR(S) HEREBY CONFIRMS THE CHANGE OF NAME. Recorded Feb 17, 2021
From: SAFRAN IDENTITY AND SECURITY
To: IDEMIA IDENTITY & SECURITY FRANCE
Reel/Frame 055314/0930 →
CORRECTIVE ASSIGNMENT TO CORRECT THE THE RECEIVING PARTY DATA PREVIOUSLY RECORDED ON REEL 047529 FRAME 0948. ASSIGNOR(S) HEREBY CONFIRMS THE CHANGE OF NAME. Recorded Oct 29, 2020
From: SAFRAN IDENTITY AND SECURITY
To: IDEMIA IDENTITY & SECURITY FRANCE
Reel/Frame 055108/0009 →
CHANGE OF NAME Recorded Jan 9, 2019
From: MORPHO
To: SAFRAN IDENTITY & SECURITY
Reel/Frame 048039/0605 →
CHANGE OF NAME Recorded Aug 30, 2018
From: SAFRAN IDENTITY & SECURITY
To: IDEMIA IDENTITY & SECURITY
Reel/Frame 047529/0948 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 6, 2017
From: DABOSVILLE, GUILLAUME; GISLARD, PHILIPPE; SERVANT, VICTOR
To: SAFRAN IDENTITY & SECURITY
Reel/Frame 043804/0816 →
Priority Claims (1)
FR 16 53944 · May 2, 2016 · national
Continuity (1)
Related Publication 20170315933A1 · Nov 2, 2017