IP Library Granted Patent US 11,507,654
Granted Patent B2
US 11,507,654 · App. 16/994,484 · Granted Nov 22, 2022

Secure environment in a non-secure microcontroller

Inventors: Maurizio Gentili (Santa Clara, CA); Massimo Panzica (Biancavilla, IT)
Assignee: STMICROELECTRONICS, INC.
G06F21/53G06F13/24G06F13/28G06F21/575G06F21/74G06F21/79H04L63/061H04L63/0853G06F2213/24G06F2221/2143G06F2221/2149
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,507,654
App. No.
16/994,484
Granted
Nov 22, 2022
Kind
B2
Abstract

A secure engine method includes providing an embedded microcontroller in an embedded device, the embedded microcontroller having internal memory. The method also includes providing a secure environment in the internal memory. The secure environment method recognizes a boot sequence and restricts user-level access to the secure environment by taking control over the secure environment memory. Taking such control may include disabling DMA controllers, configuring at least one memory controller for access to the secure environment, preventing the execution of instructions fetched from outside the secure environment, and only permitting execution of instructions fetched from within the secure environment. Secure engine program instructions are then executed to disable interrupts, perform at least one secure operation, and re-enable interrupts after performing the at least one secure operation. Control over the secure environment memory is released, which can include clearing memory, re-enabling DMA controllers, and restoring memory controller parameters.

Claims (68)

1. A method, comprising:

providing a secure environment in an internal memory of a microcontroller, the secure environment having secure engine program instructions executable by a microprocessor of the microcontroller;

restricting user-level access to the secure environment;

recognizing a boot-sequence of the microcontroller; and

in response to recognizing the boot-sequence:

disabling all direct memory access (DMA) controllers of the microcontroller that are configured to access memory of the secure environment;

configuring at least one memory controller of the microcontroller for access to the secure environment;

permitting access to memory outside the secure environment based on access permissions defined in a memory map for addresses of the internal memory, wherein the memory map for addresses of the internal memory has a configurable granularity at page, word and byte granularity levels;

preventing the microprocessor of the microcontroller from executing instructions fetched from outside the secure environment;

executing various ones of the secure engine program instructions as a state machine, said executing including:

disabling interrupts;

performing at least one secure operation after interrupts are disabled; and

enabling interrupts after performing the at least one secure operation;

clearing the internal memory;

restoring an enabled/disabled status of each DMA controller disabled after recognizing the boot-sequence; and

performing user-level operations.

2. The method of claim 1 wherein the secure engine program instructions executable by the microprocessor of the microcontroller are stored in a non-volatile memory.

3. The method of claim 1 wherein the microcontroller is an embedded microcontroller in an embedded device, and wherein the at least one secure operation includes a secure boot of the embedded device.

4. The method of claim 1 wherein the microcontroller is an embedded microcontroller in an embedded device, and wherein the at least one secure operation includes an update to firmware of the embedded device.

5. The method of claim 1 wherein the at least one secure operation includes a signature verification function.

6. The method of claim 1 wherein the act of performing at least one secure operation includes accessing protected cryptic values.

7. The method of claim 1 , comprising:

after recognizing the boot-sequence, enabling a firewall to protect the secure environment, wherein executing various ones of the secure engine program instructions as the state machine includes executing a call gate function to open an area of access within the secure environment.

8. The method of claim 7 , comprising:

after performing at least one secure operation, executing a second call gate function to close the area of access within the secure environment.

9. A device, comprising:

a microcontroller having a microprocessor and an internal memory, the internal memory having a secure environment, the secure environment having secure environment configuration instructions executable by the microprocessor and secure engine program instructions executable by the microprocessor, wherein the microprocessor, in operation:

restricts user-level access to the secure environment;

recognizes a boot sequence of the microcontroller;

in response to recognizing the boot sequence and via the secure environment configuration instructions:

disables each direct memory access (DMA) controller that is configured to access memory of the secure environment;

configures at least one memory controller for access to the secure environment;

permits access to memory outside the secure environment based on access permissions defined in a memory map for addresses of the internal memory, wherein the memory map for addresses of the internal memory has a configurable granularity at page, word and byte granularity levels; and

prevents the microprocessor from executing instructions fetched from outside the secure environment;

via the secure engine program instructions executed as a state machine:

disables interrupts;

performs at least one secure operation after interrupts are disabled; and

enables interrupts after performing the at least one secure operation; and

via the secure environment configuration instructions:

clears the internal memory;

restores an enable/disable status of each DMA controller disabled after recognizing the boot-sequence; and

performs user-level operations.

10. The device of claim 9 wherein the at least one secure operation is a cryptographic operation.

11. The device of claim 9 wherein the at least one secure operation is a secure key operation.

12. A system, comprising:

a communications interface; and

a microcontroller coupled to the communications interface and having a microprocessor and an internal memory, the internal memory having a secure environment, the secure environment having secure environment configuration instructions executable by the microprocessor and secure engine program instructions executable by the microprocessor, wherein the microprocessor, in operation:

restricts user-level access to the secure environment;

recognizes a boot sequence of the microcontroller;

in response to recognizing the boot sequence and via the secure environment configuration instructions:

disables each direct memory access (DMA) controller that is configured to access memory of the secure environment;

configures at least one memory controller for access to the secure environment;

permits access to memory outside the secure environment based on access permissions defined in a memory map for addresses of the internal memory, wherein the memory map for addresses of the internal memory has a configurable granularity at page, word and byte granularity levels; and

prevents the microprocessor from executing instructions fetched from outside the secure environment;

via the secure engine program instructions executed as a state machine:

disables interrupts;

performs at least one secure operation after interrupts are disabled; and

enables interrupts after performing the at least one secure operation; and

via the secure environment configuration instructions:

clears the internal memory;

restores an enable/disable status of each DMA controller disabled after recognizing the boot-sequence; and

performs user-level operations.

13. The system of claim 12 , comprising:

at least one sensor, the at least one sensor arranged to provide sensor data to the microcontroller via the communication interface.

14. The system of claim 12 wherein the at least one secure operation is a cryptographic operation.

15. The system of claim 12 wherein the at least one secure operation is a secure key operation.

16. The system of claim 12 wherein the secure environment of the internal memory comprises a plurality of portions of the internal memory having respective sets of addresses, the respective sets of addresses being non-contiguous.

17. The system of claim 12 , wherein the internal memory includes non-volatile and volatile memory, and access to a portion of the internal non-volatile memory and access to a portion of the internal volatile memory is restricted.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 18, 2024
From: STMICROELECTRONICS, INC.
To: STMICROELECTRONICS INTERNATIONAL N.V.
Reel/Frame 068433/0816 →
Continuity (2)
Continuation 15721362 · Sep 29, 2017
Related Publication 20200380116A1 · Dec 3, 2020