Semiconductor device and data processing method
Abstract
A semiconductor device has: as security states to which the nonvolatile memory device can transition, an unprotected state in which, when secret information is not set in the nonvolatile memory device, rewriting the nonvolatile memory device is permitted, and reading the stored information is permitted; a protection unlocked state in which, when the secret information is set in the nonvolatile memory device, rewriting the nonvolatile memory device is permitted on condition that a result of authentication using the secret information is correct, and reading the stored information is permitted; and a protection locked state in which, when the secret information is set in the nonvolatile memory device, rewriting the nonvolatile memory device is inhibited until correctness as a result of authentication using the secret information is confirmed, and reading the stored information is inhibited under a predetermined condition.
Claims
exact text as granted — not AI-modified1 - 24 . (canceled)
25 . An electronic control system for an automotive vehicle, comprising:
a microcomputer which includes:
an internal bus,
an electrically erasable programmable nonvolatile memory device coupled to the internal bus,
a central processing unit coupled to the internal bus and for executing an instruction,
an external interface circuit coupled to the internal bus, and
an external bus circuit coupled to the internal bus; and
a memory device coupled to the external bus circuit, the microcomputer having, as security states to which the nonvolatile memory device can transition: a first security state in which, when secret information is not set in the nonvolatile memory device, reading from the nonvolatile memory device is permitted, rewriting the nonvolatile memory device is permitted, and external output from the external interface circuit is permitted; a second security state in which, when the secret information is set in the nonvolatile memory device, reading from the nonvolatile memory device is permitted, rewriting the nonvolatile memory device is permitted on condition that a result of authentication using the secret information is correct, and external output from the external interface circuit is permitted; and a third security state in which, when the secret information is set in the nonvolatile memory device, rewriting the nonvolatile memory device is inhibited until correctness as a result of authentication using the secret information is confirmed, reading from the nonvolatile memory device is inhibited under a predetermined condition, and external output from the external interface circuit is permitted.
26 . The electronic control system according to claim 25 ,
wherein the nonvolatile memory device has: a nonvolatile memory circuit having an array of nonvolatile memory cells and a memory control circuit for controlling erase, write, and read operation procedures for a memory cell of the nonvolatile memory circuit, and wherein the memory control circuit further controls the first to third security states.
27 . The electronic control system according to claim 26 ,
wherein in a reset operation of the microcomputer instructed in the second security state or the third security state, the memory control circuit causes an initial security state of the nonvolatile memory device to be the third security state.
28 . The electronic control system according to claim 26 ,
wherein the memory control circuit has a set command, a reset command, and an authentication command, as a command set for controlling the first to third security states, the set command is a command for writing the secret information inputted from the external interface circuit to a predetermined memory area in the nonvolatile memory circuit, the reset command is a command for disabling information in the predetermined memory area, and the authentication command is a command for controlling transition of the security state by comparing the secret information stored in the predetermined memory area with information provided from the external interface circuit and determining authentication correctness by a comparison match and authentication incorrectness by a comparison mismatch.
29 . The electronic control system according to claim 28 ,
wherein the memory control circuit causes the security state to transition to the first security state by execution of the reset command in the second security state or by a reset operation of the microcomputer in a state in which the information in the predetermined memory area is disabled, causes the security state to transition to the second security state by execution of the set command in the first security state or by authentication correctness as an authentication result of executing the authentication command in the third security state, and causes the security state to transition to the third security state by authentication incorrectness as an authentication result of executing the authentication command in the second security state or by a reset operation of the microcomputer in a state in which the secret information is set in the predetermined memory area.
30 . The electronic control system according to claim 28 ,
wherein the microcomputer further comprises: a control mode register having a security control mode bit, wherein setting the security control mode bit to a first value enables execution of the set command, the reset command, and the authentication command, and setting the security control mode bit to a second value disables change of the security state by execution of the set command, the reset command, and the authentication command.
31 . The electronic control system according to claim 30 ,
wherein the microcomputer further comprises: a security control status register indicating the current security state in the security control mode.
32 . The electronic control system according to claim 25 ,
wherein read inhibit under the predetermined condition refers to that after detection of an instruction fetch in external address space via the external bus circuit by the central processing unit, and external output inhibit in the third security state is performed by outputting, from the nonvolatile memory device which responds to a read request, a predetermined value independent of reading from the memory or a random value different from output data of the nonvolatile memory device.
33 . The electronic control system according to claim 25 ,
wherein the memory control circuit disables a request for read access to an area for storing the secret information provided via the internal bus.
34 . The electronic control system according to claim 25 ,
wherein the electronic control system is a powertrain control system.
35 . An electronic control system for an automotive vehicle, comprising:
a microcomputer which includes:
an internal bus,
an electrically erasable programmable nonvolatile memory device coupled to the internal bus,
a central processing unit coupled to the internal bus and for executing an instruction,
a first external interface circuit which is coupled to the internal bus and which is assigned as a debug-specific external interface,
a second external interface circuit which is coupled to the internal bus and which is assigned as another external interface, and
an external bus circuit which is coupled to the internal bus; and
a memory device coupled to the external bus circuit, the microcomputer having, as security states to which the nonvolatile memory device can transition: a first security state in which, when first secret information and second secret information are not set in the nonvolatile memory device, reading from the nonvolatile memory device is permitted, rewriting the nonvolatile memory device is permitted, and external output from the first external interface circuit and the second external interface circuit is permitted; a second security state in which, when the first secret information is set in the nonvolatile memory device, reading from the nonvolatile memory device is permitted, rewriting the nonvolatile memory device is permitted on condition that a result of authentication using the secret information is correct, and external output from the first external interface circuit and the second external interface circuit is permitted; a third security state in which, when the first secret information is set in the nonvolatile memory device, rewriting the nonvolatile memory device is inhibited until correctness as a result of authentication using the secret information is confirmed, reading from the nonvolatile memory device is inhibited under a predetermined condition, and external output from the first external interface circuit and the second external interface circuit is permitted; a fourth security state in which, when the second secret information is set in the nonvolatile memory device, reading from the nonvolatile memory device is permitted, rewriting the nonvolatile memory device is permitted on condition that a result of authentication using the secret information is correct, and external output from the first external interface circuit and the second external interface circuit is permitted; and a fifth security state in which, when the second secret information is set in the nonvolatile memory device, rewriting the nonvolatile memory device is inhibited until correctness as a result of authentication using the secret information is confirmed, reading from the nonvolatile memory device is inhibited under the predetermined condition, an interface operation of the first external interface circuit is disabled, and external output from the second external interface circuit is permitted.
36 . The electronic control system according to claim 35 ,
wherein the nonvolatile memory device has a nonvolatile memory circuit having an array of nonvolatile memory cells and a memory control circuit for controlling erase, write, and read operation procedures for a memory cell of the nonvolatile memory circuit, and the memory control circuit further controls the first to fifth security states.
37 . The electronic control system according to claim 36 ,
wherein in a reset operation of the microcomputer instructed in the second security state or the third security state, the memory control circuit causes an initial security state of the nonvolatile memory device to be the third security state, and in a reset operation of the microcomputer instructed in the fourth security state or the fifth security state, the memory control circuit causes an initial security state of the nonvolatile memory device to be the fifth security state.
38 . The electronic control system according to claim 36 ,
wherein the nonvolatile memory circuit has a first memory area assigned to store the first secret information and a second memory area assigned to store the second secret information individually.
39 . The electronic control system according to claim 38 ,
wherein the memory control circuit has a set command, a reset command, and an authentication command, as a command set for controlling the first to fifth security states, the set command is a command for writing information inputted from the first external interface circuit or the second external interface circuit to the first memory area or the second memory area by specifying the first memory area or the second memory area, the reset command is a command for disabling the information in the first memory area and the second memory area, and the authentication command is a command for controlling transition of the security state by comparing the information inputted by specifying the first memory area or the second memory area with information in the specified first or second memory area and determining authentication correctness of the secret information in the specified memory area by a comparison match as to the information in the specified memory area and authentication incorrectness by a comparison mismatch as to the information in the specified memory area.
40 . The electronic control system according to claim 37 ,
wherein the memory control circuit causes the security state to transition to the first security state by execution of the reset command in the second security state, by execution of the reset command in the fourth security state, or by a reset operation of the microcomputer in a state in which the information in the first memory area and the second memory area is disabled, causes the security state to transition to the second security state by execution of the set command specifying the first memory area in the first security state or by authentication correctness as an authentication result of executing the authentication command specifying the first memory area in the third security state, causes the security state to transition to the third security state by authentication incorrectness as an authentication result of executing the authentication command specifying the first memory area in the second security state or by a reset operation of the semiconductor device in a state in which the secret information is set in the first memory, causes the security state to transition to the fourth security state by execution of the set command specifying the second memory area in the first security state, by authentication correctness as an authentication result of executing the authentication command specifying the second memory area in the fifth security state, or by execution of the set command specifying the second memory area in the second security state, and causes the security state to transition to the fifth security state by authentication incorrectness as an authentication result of executing the authentication command specifying the second memory area in the fourth security state or by a reset operation of the semiconductor device in a state in which the secret information is set in the second memory.
41 . The electronic control system according to claim 39 ,
wherein the microcomputer further comprises: a control mode register having a security control mode bit, wherein setting the security control mode bit to a first value enables execution of the set command, the reset command, and the authentication command, and setting the security control mode bit to a second value disables change of the security state by execution of the set command, the reset command, and the authentication command.
42 . The electronic control system according to claim 40 ,
wherein the microcomputer further comprises: a security control status register indicating the current security state in the security control mode.
43 . The electronic control system according to claim 34 ,
wherein read inhibit under the predetermined condition refers to that after detection of an instruction fetch in external address space via the external bus circuit by the central processing unit, and external output inhibit in the third security state and the fifth security state is performed by outputting, from the nonvolatile memory device which responds to a read request, a predetermined value independent of reading from the memory or a random value different from output data of the nonvolatile memory device.
44 . The electronic control system according to claim 35 ,
wherein the memory control circuit disables a request for read access to an area for storing the secret information provided via the internal bus.
45 . The electronic control system according to claim 35 ,
wherein the electronic control system is a powertrain control system.Join the waitlist — get patent alerts
Track US2015317258A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.