IP Library Granted Patent US 11,816,466
Granted Patent B2
US 11,816,466 · App. 16/936,224 · Granted Nov 14, 2023

Electronic device with firmware, and method of operating thereof

Inventor: Fabien Arrive (Chasné-sur-illet, FR)
Assignee: STMICROELECTRONICS (GRAND OUEST) SAS
G06F8/65G06F21/572G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,816,466
App. No.
16/936,224
Granted
Nov 14, 2023
Kind
B2
Abstract

An embodiment electronic device includes a memory containing a plurality of copies of firmware of the device.

Claims (56)

1. An electronic component comprising:

a package having external electrically-conductive pins;

a non-transitory, non-volatile memory disposed on an integrated circuit chip in the package, the memory storing:

a plurality of copies of at least one version of a same firmware of the component; and

for each copy of the at least one version of the same firmware, an integrity signature for checking a validity of the copy; and

a central processing unit disposed on the integrated circuit chip in the package and communicatively coupled to the memory, wherein each of the copies of the same firmware is configured to cause the central processing unit to execute an operation of the component according to a trusted platform module (TPM) standard, and wherein the central processing unit is configured to:

receive an additional copy of the same firmware, wherein values depending on a future position of the additional copy in the memory are replaced with a same predefined value;

receive dependent values for each position of the copies in the memory;

replace at least one of the copies with the additional copy; and

restore the dependent values corresponding to the position of the additional copy.

2. The component of claim 1 , wherein the memory further comprises a program for starting the component, and wherein the program is configured to cause the central processing unit to execute a verification of a validity and execution of at least one of the copies.

3. The component of claim 1 , wherein the memory comprises a value indicating a copy selected from among the copies.

4. The component of claim 3 , wherein the selected copy corresponds to a most recent version of the firmware.

5. The component of claim 1 , wherein the memory further comprises a common file system accessible to each of the copies.

6. A method of operating an electronic component comprising a package having external electrically-conductive pins, a central processing unit disposed on a first integrated circuit chip in the package, and a non-volatile memory disposed on a second integrated circuit chip in the package and different from the first integrated circuit chip, the non-volatile memory containing a plurality of copies of at least one version of a same firmware of the component, the method comprising:

storing, by the central processing unit in the package in the non-volatile memory in the package, for each copy of the at least one version of the same firmware, an integrity signature for checking a validity of the copy;

receiving, by the component, an additional copy of the same firmware, wherein values depending on a future position of the additional copy in the memory are replaced with a same predefined value;

receiving, by the component, dependent values for each position of the copies in the memory;

replacing at least one of the copies with the additional copy;

restoring the dependent values corresponding to the position of the additional copy;

determining, by the central processing unit in the package, that a first copy of the copies of the same firmware is valid and corresponds to a most recent version of valid copies; and

executing, by the central processing unit in the package, the first copy of the copies to cause an operation of the component according to a trusted platform module (TPM) standard.

7. The electronic component of claim 1 , wherein the non-transitory, non-volatile memory is a flash memory.

8. The method of claim 6 , wherein each of the valid copies is capable of causing, when executed by the component, the operation of the component according to the TPM standard.

9. The method of claim 6 , comprising replacing a copy which, among the copies, is non-valid, with another copy which, among the copies, is valid.

10. The method of claim 6 , comprising replacing one of the copies with another one of the copies corresponding to a more recent version than that of the replaced copy.

11. The method of claim 6 , further comprising:

receiving the additional copy in compressed form; and

decompressing the additional copy.

12. The method of claim 6 , wherein the predefined value has all of its bits equal to a memory erase value.

13. An electronic component comprising:

a package having external electrically-conductive pins;

a central processing unit disposed on a first integrated circuit chip in the package;

a non-volatile memory disposed on at least one second integrated circuit chip in the package, wherein the at least one second integrated circuit chip is different from the first integrated circuit chip, and wherein the non-volatile memory is communicatively coupled to the central processing unit;

a plurality of copies of at least one version of a same firmware of the component, stored in the non-volatile memory, wherein each of the copies of the same firmware is configured to cause the central processing unit to execute an operation of the electronic component according to a trusted platform module (TPM) standard; and

for each copy of the at least one version of the same firmware, an integrity signature, stored in the non-volatile memory, for checking a validity of the copy;

wherein the central processing unit is configured to:

receive an additional copy of the same firmware, wherein values depending on a future position of the additional copy in the memory are replaced with a same predefined value;

receive dependent values for each position of the copies in the memory;

replace at least one of the copies with the additional copy; and

restore the dependent values corresponding to the position of the additional copy.

14. The electronic component of claim 13 , wherein the memory further comprises a program for starting the electronic component, the program configured to cause the central processing unit to execute a verification of a validity and execution of at least one of the copies.

15. The electronic component of claim 13 , wherein the memory comprises a value indicating a copy selected from among the copies.

16. The electronic component of claim 15 , wherein the selected copy corresponds to a most recent version of the firmware.

17. The electronic component of claim 13 , wherein the memory further comprises a common file system accessible to each of the copies.

18. A method of operating an electronic component comprising a package having external electrically-conductive pins, a central processing unit disposed on an integrated circuit chip in the package, and a non-volatile memory disposed on the integrated circuit chip and containing a plurality of copies of at least one version of a same firmware of the component, the method comprising:

storing, by the central processing unit on the integrated circuit chip in the non-volatile memory on the integrated circuit chip, for each copy of the at least one version of the same firmware, an integrity signature for checking a validity of the copy;

receiving, by the component, an additional copy of the same firmware, wherein values depending on a future position of the additional copy in the memory are replaced with a same predefined value;

receiving, by the component, dependent values for each position of the copies in the memory;

replacing at least one of the copies with the additional copy;

restoring the dependent values corresponding to the position of the additional copy;

determining, by the central processing unit on the integrated circuit chip, that a first copy of the copies of the same firmware is valid and corresponds to a most recent version of valid copies; and

executing, by the central processing unit on the integrated circuit chip, the first copy of the copies to cause an operation of the component according to a trusted platform module (TPM) standard.

19. The method of claim 18 , further comprising:

receiving the dependent values in compressed form; and

decompressing the dependent values.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2020
From: ARRIVE, FABIEN
To: STMICROELECTRONICS (GRAND OUEST) SAS
Reel/Frame 053285/0021 →
Priority Claims (1)
FR 1908696 · Jul 30, 2019 · national
Continuity (1)
Related Publication 20210034352A1 · Feb 4, 2021