IP Library Granted Patent US 11,157,658
Granted Patent B2
US 11,157,658 · App. 16/315,105 · Granted Oct 26, 2021

Secure loading of secret data to non-protected hardware registers

Inventors: Nicholas Xing Long Eu (Gemenos, FR); Annus Bin Khalid Syed (Gemenos, FR); Juan Manolo Alcasabas (Gemenos, FR)
Assignee: THALES DIS FRANCE SA
G06F21/72G06F21/602H04L9/003G06F2207/7223G06F2207/7257H04L2209/08H04L2209/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,157,658
App. No.
16/315,105
Granted
Oct 26, 2021
Kind
B2
Abstract

The present invention relates to a method to securely load set of sensitive data hardware registers with sensitive data on a chip supporting hardware cryptography operations, said method comprising the following steps monitored by software instructions, at each run of a software: select a set of available hardware registers listed in a predefined list listing, in the chip architecture, the unused hardware registers and other relevant hardware registers not handling sensitive data and not disrupting chip functionality when loaded, establish an indexible register list of the address of the sensitive data hardware registers and of the hardware registers in the set of available hardware registers, in a loop, write each hardware register in this register list with random data, a random number of times, in random order except the last writing in each of the sensitive data hardware registers where a part of the sensitive data is written.

Claims (37)

1. A method to securely load set of sensitive data hardware registers with sensitive data on a chip supporting hardware cryptography operations, said method comprising the following steps monitored by software instructions, at each run of a software:

select a set of available hardware registers listed in a predefined list listing, in the chip architecture, the unused hardware registers and other relevant hardware registers not handling sensitive data and not disrupting chip functionality when loaded,

establish an indexable register list of the addresses of the sensitive data hardware registers and of the hardware registers in the set of available hardware registers,

in a loop, write each hardware register in this register list with random data, a random number of times, in random order except the last writing in each of the sensitive data hardware registers where a part of the sensitive data is written.

2. The method according to claim 1 , comprising a step of further selecting key registers of other cryptographic hardware.

3. The method according to claim 1 , the write step comprises the following steps:

associating a number of load times to each hardware register in the indexable register list,

establishing a register write sequence listing the register address as many times as the associated load times,

shuffling the register write sequence to determine a processing order in a shuffled register write sequence,

identifying the last occurrence for the sensitive data registers in the shuffled register write sequence,

for the whole set of addresses in the shuffled register write sequence, writing each hardware register with random data.

4. A chip comprising:

a set of data hardware registers and supporting hardware cryptography operations, and

a computer program directing the chip to:

identify available hardware register, unused hardware registers, and other relevant hardware registers not handling sensitive data and not disrupting chip functionality when loaded;

establish an indexible register list of addresses of the sensitive data hardware registers, and of the hardware registers in the set of available hardware registers; and

in a loop, write each hardware register in this register list with random data, a random number of times, in random order except the last writing in each of the sensitive data hardware registers where a part of the sensitive data is written.

5. The chip of claim 4 , wherein the computer program further comprises instructions directing the chip to:

select key registers of other cryptographic hardware.

6. The chip of claim 4 , wherein the computer program further comprises instructions directing the chip to:

associate a number of load times to each hardware register in the indexable register list,

establish a register write sequence listing the register address as many times as the associated load times,

shuffle the register write sequence to determine a processing order in a shuffled register write sequence,

identify the last occurrence for the sensitive data registers in the shuffled register write sequence,

for the whole set of addresses in the shuffled register write sequence, write each hardware register with random data.

7. A computer readable device having instruction directing a chip, having a set of data hardware registers and supporting hardware cryptography, to:

identify available hardware register, unused hardware registers, and other relevant hardware registers not handling sensitive data and not disrupting chip functionality when loaded;

establish an indexable register list of addresses of the sensitive data hardware registers, and of the hardware registers in the set of available hardware registers; and

in a loop, write each hardware register in this register list with random data, a random number of times, in random order except the last writing in each of the sensitive data hardware registers where a part of the sensitive data is written.

8. The computer readable device of claim 7 , further comprising instructions directing the chip to:

select key registers of other cryptographic hardware.

9. The computer readable device of claim 7 , further comprising instructions directing the chip to:

associate a number of load times to each hardware register in the indexable register list,

establish a register write sequence listing the register address as many times as the associated load times,

shuffle the register write sequence to determine a processing order in a shuffled register write sequence,

identify the last occurrence for the sensitive data registers in the shuffled register write sequence,

for the whole set of addresses in the shuffled register write sequence, write each hardware register with random data.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 1, 2023
From: THALES DIS FRANCE SA
To: THALES DIS FRANCE SAS
Reel/Frame 064792/0714 →
CHANGE OF NAME Recorded Aug 25, 2023
From: GEMALTO SA
To: THALES DIS FRANCE SA
Reel/Frame 064716/0634 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 20, 2021
From: EU, NICHOLAS XING LONG
To: GEMALTO SA
Reel/Frame 057241/0288 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 29, 2019
From: EU, XING LONG NICHOLAS; SYED, ANNUS BIN KHALID; ALCASABAS, JUAN MANOLO
To: GEMALTO SA
Reel/Frame 048167/0234 →
Priority Claims (1)
EP 16305841 · Jul 4, 2016 · regional
Continuity (1)
Related Publication 20190311154A1 · Oct 10, 2019