IP Library › Granted Patent US 11,983,420
Granted Patent B2
US 11,983,420 · App. 17/843,046 · Granted May 14, 2024

Method and system for protecting data in external memory based on isolated execution environment

Inventor: Zong-Min Lin (Kaohsiung, TW)
Assignee: NUVOTON TECHNOLOGY CORPORATION
G06F3/0622G06F3/0659G06F3/0679
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,983,420
App. No.
17/843,046
Granted
May 14, 2024
Kind
B2
Abstract

A method for protecting data in an external memory based on an isolated execution environment is provided. The method is used in a processor in the isolated execution environment of a system-on-a-chip. The method includes: accessing an output command of a main system processor in a main system of the system-on-a-chip; reading first data from a shared memory in the main system according to the output command; encrypting the first data with a private key and generating encrypted first data; and outputting the encrypted first data to the external memory.

Claims (54)

1. A method for protecting data in an external memory based on an isolated execution environment, used in a processor located in the isolated execution environment of a system-on-a-chip, comprising:

accessing an output command of a main system processor in a main system of the system-on-a-chip;

reading first data from a shared memory in the main system according to the output command;

encrypting the first data with a private key and generating encrypted first data; and

outputting the encrypted first data to the external memory;

wherein the method further comprises:

accessing a read command in the main system processor;

reading encrypted second data from the external memory according to the read command;

decrypting the encrypted second data using the private key to generate second data;

sending the second data to the shared memory in the main system;

calculating a second hash value of the second data;

comparing the second hash value with a third hash value corresponding to the second data recorded in the random access memory, and generating a comparison result; and

when the comparison result is incorrect, invaliding the second data and reporting an error message to the main system processor.

2. The method as claimed in claim 1 , further comprising:

calculating a first hash value of the first data; and

recording the first hash value in the random access memory of the isolated execution environment.

3. The method as claimed in claim 1 , wherein before the processor accesses the output command, the method further comprises:

accessing an initialization command issued by the main system processor;

accessing at least one true random number generator (TRNG) located in the isolated execution environment according to the initialization command to generate a random number;

generating the private key according to the random number;

storing the private key in the random access memory in the isolated execution environment; and

reporting a completion message to the main system processor.

4. The method as claimed in claim 1 , further comprising:

accessing a program load command in the main system processor;

loading a program from the host system into the random access memory of the isolated execution environment according to the program load command;

authenticating the program using an authentication key and generating an authentication result; and

loading and executing the program when the authentication result matches a program signature.

5. A system for protecting data in an external memory based on an isolated execution environment, comprising:

a main system, comprising:

a main system processor; and

a shared memory, coupled to the main system processor; and

an isolated execution environment, coupled to the main system, comprising:

a processor;

wherein the processor executes the following steps:

accessing an output command of the main system processor;

reading first data from a shared memory in the main system according to the output encrypting the first data with a private key and generating encrypted first data; and

outputting the encrypted first data to the external memory;

wherein the processor further executes the following steps:

accessing a read command in the main system processor;

reading encrypted second data from the external memory according to the read command;

decrypting the encrypted second data using the private key to generate second data;

sending the second data to the shared memory in the main system;

calculating a second hash value of the second data;

comparing the second hash value with a third hash value corresponding to the second data recorded in the random access memory, and generating a comparison result; and

when the comparison result is incorrect, invaliding the second data and reporting an error message to the main system processor.

6. The system as claimed in claim 5 , wherein the processor further executes the following steps:

calculating a first hash value of the first data; and

recording the first hash value in the random access memory of the isolated execution environment.

7. The system as claimed in claim 5 , wherein before the processor accesses the output command, the processor further executes the following steps:

accessing an initialization command issued by the main system processor;

accessing at least one true random number generator (TRNG) located in the isolated execution environment according to the initialization command to generate a random number;

generating the private key according to the random number;

storing the private key in the random access memory in the isolated execution environment; and

reporting a completion message to the main system processor.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 29, 2022
From: LIN, ZONG-MIN
To: NUVOTON TECHNOLOGY CORPORATION
Reel/Frame 060357/0715 →
Continuity (1)
Related Publication 20230409211A1 · Dec 21, 2023