IP Library Granted Patent US 12,585,758
Granted Patent B2
US 12,585,758 · App. 17/055,434 · Granted Mar 24, 2026

Electronic system and method for preventing malicious actions on a processing system of the electronic system

Inventor: Yannick Teglia (Meudon, FR)
Assignee: THALES DIS FRANCE SAS
G06F21/554G06F21/54G06F21/566G06F21/575G06F21/86
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,585,758
App. No.
17/055,434
Granted
Mar 24, 2026
Kind
B2
Abstract

An electronic system having a processing system with a hardware processor and at least one additional unit the hardware processor having a CPU register and the additional unit having a processing system memory. A secure enclave of the system is configured to monitor the behavior of the processing system and detect a compromise of the processing system. A protection system of the electronic system is configured, upon detection of a compromise of the processing system by the secure enclave, to perform at least one dedicated action on at least one additional unit among the additional units for raising an alert or for applying countermeasures, or on the hardware processor modifying a CPU register of the hardware processor, the protection system and the secure enclave being connected to the additional units.

Claims (17)

1 . A system on a chip wherein components of the system are co-located on the chip, the system on the chip comprising:

a processing system located on the chip and comprising a hardware processor and at least one additional unit, wherein said hardware processor comprises at least one CPU register and said at least one additional unit comprises a processing system memory,

a secure enclave co-located with the processing system on the chip configured to continuously monitor and verify behavior of a software program run by the processing system to detect compromise of the processing system,

a protection system co-located with the processing system on the chip, directly connected to the processing system, and external to the processing system and configured, upon the detection of the compromise of the processing system by the secure enclave, to send to a reset unit of said at least one additional unit a reset command triggering a reset of the processing system, or to erase an area of the processing system memory,

said protection system and said secure enclave being connected to said at least one additional unit.

2 . The system on the chip of claim 1 , wherein the protection system is configured, upon detection of compromise of the processing system by the secure enclave, to erase said area of the processing system memory, and said area comprises the whole processing system memory.

3 . The system on the chip of claim 1 , wherein said protection system is a dedicated integrated circuit external to said secure enclave and connected to the secure enclave.

4 . The system on the chip of claim 1 , wherein said secure enclave is external to said processing system and said protection system is included in the secure enclave.

5 . The system on the chip of claim 1 , wherein the secure enclave is a secure mode or secure area of the hardware processor.

6 . The system on the chip of claim 1 , wherein the secure enclave is a dedicated tamper proof integrated circuit.

7 . The system on the chip of claim 6 , wherein the secure enclave is an integrated Secure Element.

8 . The system on the chip of claim 1 wherein to monitor behavior of the processing system and to detect compromise of the processing system, said secure enclave acts as a redundant CPU performing same operations equivalent to operations performed by the hardware processor of said processing system and performs consistency checks between outputs from the secure enclave and outputs of the hardware processor.

9 . The system on the chip of claim 1 wherein said secure enclave is configured to verify integrity of a selected memory selected from the processing system memory and a random access memory of the processing system by storing, in the secure enclave, a reference hash value of content of the selected memory.

10 . The system on the chip of claim 1 wherein the secure enclave performs redundant execution of the software program and performs consistency checks between outputs from the execution of the software program by the secure enclave and outputs of the processing system.

11 . A method for preventing malicious actions on a processing system of a system on a chip, the processing system located on the chip and having a hardware processor and at least one additional unit, the system on the chip further having a secure enclave located on the chip and a protection system located on the chip, directly connected to the processing system, and external to the processing system, the method performed by said system on the chip, the method comprising:

continuously monitoring and verifying, by the secure enclave, behavior of a software program run by the processing system to detect, by the secure enclave of the system on the chip, compromise of the processing system, and upon the detection of the compromise, triggering the protection system to perform at least one dedicated action on at least one of said at least one additional unit for applying countermeasures;

performing, by the protection system of the system on the chip, via said direct connection, upon the triggering by the secure enclave, the at least one dedicated action on at least one of said at least one additional unit for applying the countermeasures by sending to a reset unit of said at least one additional unit a reset command triggering a reset of the processing system, or erasing an area of a memory of the processing system of the system on the chip.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 8, 2025
From: TEGLIA, YANNICK
To: THALES DIS FRANCE SA
Reel/Frame 073146/0757 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 23, 2023
From: THALES DIS FRANCE SA
To: THALES DIS FRANCE SAS
Reel/Frame 064674/0941 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 13, 2020
From: TEGLIA, YANNICK
To: THALES DIS FRANCE SA
Reel/Frame 054363/0808 →
Priority Claims (1)
EP 18305602 · May 16, 2018 · regional
Continuity (1)
Related Publication 20210224386A1 · Jul 22, 2021
References Cited (22)
US 9727726B1 · Allen · 2017 [cited by examiner]
US 9941880B1 · Lesea · 2018 [cited by examiner]
US 10657265B1 · Poolla · 2020 [cited by examiner]
US 20080238612A1 · Carpenter · 2008 [cited by examiner]
US 20100107246A1 · Ohta · 2010 [cited by examiner]
US 20100182147A1 · Rueping · 2010 [cited by examiner]
US 20110004771A1 · Matsushima · 2011 [cited by examiner]
US 20140089650A1 · Polzin · 2014 [cited by examiner]
US 20140359239A1 · Hiremane · 2014 [cited by applicant]
US 20160283937A1 · Reese · 2016 [cited by examiner]
US 20170076116A1 · Chen · 2017 [cited by examiner]
US 20170262352A1 · Jeansonne · 2017 [cited by examiner]
US 20180157572A1 · Grieco · 2018 [cited by examiner]
US 20180239905A1 · Liu · 2018 [cited by examiner]
US 20190042802A1 · Trikalinou · 2019 [cited by examiner]
US 20190172047A1 · Tan · 2019 [cited by examiner]
US 20190277912A1 · Panesar · 2019 [cited by examiner]
US 20190303585A1 · Ofek · 2019 [cited by examiner]
US 20200242276A1 · Klein · 2020 [cited by examiner]
WO WO2016182650A1 · 2016 [cited by applicant]
PCT/EP2019/061290, Written Opinion of the International Searching Authority, May 16, 2019, European Patent Office, D-80298 Munich. [cited by applicant]
PCT/EP2019/061290, International Search Report, May 16, 2019, European Patent Office, P.B. 5818 Patentlaan 2 NL—2280 HV Rijswijk. [cited by applicant]