IP Library Granted Patent US 8,689,338
Granted Patent B2
US 8,689,338 · App. 11/997,214 · Granted Apr 1, 2014

Secure terminal, a routine and a method of protecting a secret key

Inventors: Jean-Philippe Perrin (Seoul, KR); Harald Norbert Bauer (Nuremberg, DE); Patrick Fulcheri (Antibes, FR)
Assignee: ST-Ericsson SA
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,689,338
App. No.
11/997,214
Granted
Apr 1, 2014
Kind
B2
Abstract

The method of protecting a secret key from being read by a non-secure software application, comprises a step ( 94 ) of recording the secret key as a routine stored in an executable-only memory. The routine having: load instructions to load the secret key into a memory readable by a secure and a non-secure software application, if the routine is called by the secure software application, and control instructions to leave only dummy data instead of the secret key in the readable memory if the software application calling the executable-only routine is the non-secure software application.

Claims (28)

1. A method of protecting a secret key from being read by a non-secure software application, the method comprising:

recording the secret key in a read-only once memory;

reading the secret key after the reset of a processor; and

generating from the secret key an executable-only routine which is stored in a write-once and executable-only memory, the executable-only routine being embedded with constants respectively corresponding to bits of said secret key and further having:

load instructions to load said constants in a memory readable by a secure and a non-secure software application in the case that the executable-only routine is called by the secure software application, and

control instructions to leave only dummy data instead of said constants in a readable memory in the case that the executable-only routine is called by the non-secure software application.

2. The method of claim 1 , wherein the load instructions are instructions to load constants, the value of each constant being embedded in the executable-only routine code and representing at least one bit of the secret key.

3. The method according to claim 1 , wherein the method comprises the steps of disabling any IRQ (Interrupt Request) before the load instructions are executed and re-enabling the IRQ only after the secret key loaded in the readable memory has been deleted.

4. The method according to claim 3 , wherein the executable-only routine returns systematically to the secure software application and any secure software application deletes the loaded secret key before executing the IRQ re-enabling step.

5. The method according to claim 4 , wherein the secure software application to which the executable-only routine returns immediately deletes the loaded secret key if the secure software application was not called by the executable-only routine.

6. An executable-only routine contained in a method of protecting a secret key from being read by a non-secure software application, the method comprising the steps of (1) recording the secret key in a read-only once memory, (2) reading the secret key after the reset of a processor and (3) generating from the secret key the executable-only routine stored in a write-once and executable-only memory, wherein the executable-only routine is embedded with constants respectively corresponding to bits of said secret key and further comprises:

load instructions to load said constants in a memory readable by a secure and a non-secure software application, in the case that the executable-only routine is called by the secure software application, and

control instructions to leave only dummy data instead of said constants in a readable memory in the case that the executable-only routine is called by the non-secure software application.

7. The executable-only routine according to claim 6 , wherein the load instructions are instructions to load constants, the value of each constant being embedded in the executable-only routine code and representing at least one bit of the secret key.

8. The executable-only routine according to claim 6 , wherein the executable-only routine has instructions to disable any IRQ at the beginning of the execution of the executable-only routine.

9. The executable-only routine according to claim 8 , wherein the executable-only routine has an instruction to systematically return to the secure software application at the end of the execution of the executable-only routine.

10. A secure terminal comprising:

a processor to execute software applications and routines called by the software applications, and

at least one secret key stored in a read-only once memory, said secret key being read after the reset of said processor, and from which is generated an executable-only routine stored in a write-once and executable-only memory, the executable-only routine being embedded with constants respectively corresponding to bits of said secret key and further comprising:

load instructions to load said constants into a memory readable by a secure and a non-secure software application, in the case that the executable-only routine is called by the secure software application, and

control instructions to leave only dummy data instead of said constants in the readable memory in the case that the executable-only routine is called by the non-secure software application.

11. The secure terminal according to claim 10 , wherein the load instructions are instructions to load constants, the value of each constant being embedded in the executable-only routine code and representing at least one bit of the secret key.

12. The secure terminal according to claim 10 , wherein the terminal comprises a read only memory (ROM) comprising at least one instruction code of the secure software application, the instruction code having an instruction to delete the loaded secure key from the readable memory.

13. The secure terminal according to claim 10 , wherein the secure terminal comprises:

a read once memory readable only one time after reset of the terminal, the read once memory recording the secret key,

a read only memory having a secure initializing routine to create an instruction code of the executable-only routine from the secret key written in the read once memory, and to load the instruction code of the executable-only routine into the executable-only memory.

14. The secure terminal according to claim 13 , wherein the executable-only memory has a transaction decoder to authorize only instruction read operations and inhibit data read operations.

15. The secure terminal according to claim 10 , wherein the secure terminal is a mobile phone.

Assignments (14)
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION 12298143 PREVIOUSLY RECORDED ON REEL 039361 FRAME 0212. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY AGREEMENT SUPPLEMENT. Recorded Oct 22, 2019
From: NXP B.V.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 051029/0387 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION 12298143 PREVIOUSLY RECORDED ON REEL 042985 FRAME 0001. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY AGREEMENT SUPPLEMENT. Recorded Oct 22, 2019
From: NXP B.V.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 051029/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION 12298143 PREVIOUSLY RECORDED ON REEL 038017 FRAME 0058. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY AGREEMENT SUPPLEMENT. Recorded Oct 22, 2019
From: NXP B.V.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 051030/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION 12298143 PREVIOUSLY RECORDED ON REEL 042762 FRAME 0145. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY AGREEMENT SUPPLEMENT. Recorded Oct 22, 2019
From: NXP B.V.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 051145/0184 →
RELEASE OF SECURITY INTEREST Recorded Sep 10, 2019
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: NXP B.V.
Reel/Frame 050745/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION 12681366 PREVIOUSLY RECORDED ON REEL 038017 FRAME 0058. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY AGREEMENT SUPPLEMENT. Recorded May 9, 2017
From: NXP B.V.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 042985/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION 12681366 PREVIOUSLY RECORDED ON REEL 039361 FRAME 0212. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY AGREEMENT SUPPLEMENT. Recorded May 9, 2017
From: NXP B.V.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 042762/0145 →
PATENT RELEASE Recorded Aug 17, 2016
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: NXP B.V.
Reel/Frame 039707/0471 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION 12092129 PREVIOUSLY RECORDED ON REEL 038017 FRAME 0058. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY AGREEMENT SUPPLEMENT. Recorded Jul 14, 2016
From: NXP B.V.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 039361/0212 →
SECURITY AGREEMENT SUPPLEMENT Recorded Mar 7, 2016
From: NXP B.V.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 038017/0058 →
STATUS CHANGE-ENTITY IN LIQUIDATION Recorded Feb 2, 2016
From: ST-ERICSSON SA
To: ST-ERICSSON SA, EN LIQUIDATION
Reel/Frame 037739/0493 →
CHANGE OF NAME Recorded Feb 7, 2014
From: ST WIRELESS SA
To: ST-ERICSSON SA
Reel/Frame 032176/0550 →
DEED OF TRANSFER Recorded Feb 6, 2014
From: NXP B.V.
To: ST WIRELESS SA
Reel/Frame 032166/0163 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 6, 2008
From: PERRIN, JEAN-PHILIPPE; BAUER, HARALD NORBERT; FULCHERI, PATRICK
To: NXP B.V.
Reel/Frame 020470/0519 →
Priority Claims (1)
EP 05300649 · Aug 3, 2005 · regional
Continuity (1)
Related Publication 20080229425A1 · Sep 18, 2008