US2016140057A1PendingUtilityA1

Semiconductor device and encryption key writing method

Assignee: RENESAS ELECTRONICS CORPPriority: Oct 31, 2012Filed: Jan 26, 2016Published: May 19, 2016
Est. expiryOct 31, 2032(~6.3 yrs left)· nominal 20-yr term from priority
G06F 21/74G06F 2212/1052G06F 12/1408H04L 9/14H04L 2209/24G06F 21/602
45
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A semiconductor device includes a central processing unit (CPU), a first memory which stores a plurality of split keys, a second memory which stores an encryption code as at least one of an encrypted instruction and encrypted data, the plurality of split keys including an encryption key for decrypting the encryption code, and a decrypter which reads the encryption code from the second memory, decrypts the encryption code with the use of the encryption key, and supplies the decrypted encryption code to the CPU. The second memory stores an encryption key reading program which is executed by the CPU to restore the encryption key and to supply the encryption key to the decrypter, by reading and reconfiguring the split keys stored in the first memory in a distributed manner.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A semiconductor device comprising:
 a central processing unit (CPU);   a first memory which stores a plurality of split keys;   a second memory which stores an encryption code as at least one of an encrypted instruction and encrypted data, the plurality of split keys comprising an encryption key for decrypting the encryption code; and   a decrypter which reads the encryption code from the second memory, decrypts the encryption code with the use of the encryption key, and supplies the decrypted encryption code to the CPU,   wherein the second memory stores an encryption key reading program which is executed by the CPU to restore the encryption key and to supply the encryption key to the decrypter, by reading and reconfiguring the split keys stored in the first memory in a distributed manner.   
     
     
         2 . The semiconductor device of  claim 1 , wherein the CPU includes a first operation mode and a second operation mode. 
     
     
         3 . The semiconductor device of  claim 2 , wherein the first memory comprises an electrically rewritable nonvolatile memory including a first region and a second region, the first region being forbidden access from the CPU in the second operation mode. 
     
     
         4 . The semiconductor device of  claim 3 , wherein the first memory includes a plurality of distributed address areas in the first region, for storing the plurality of split keys. 
     
     
         5 . The semiconductor device of  claim 4 , wherein the second memory comprises an electrically non-rewritable nonvolatile memory including a third region and a fourth region, the third region storing the encryption code. 
     
     
         6 . The semiconductor device of  claim 5 , wherein the second memory stores the encryption key reading program in the fourth region. 
     
     
         7 . The semiconductor device of  claim 5 , wherein the decrypter stores the encryption key, and in the second operation mode the decrypter decrypts the encryption code read from the third region of the second memory. 
     
     
         8 . The semiconductor device of  claim 5 , further comprising:
 a communication interface,   wherein the second memory stores an encryption key writing program in the fourth region, the encryption key writing program being executed by the CPU to:
 input the encryption key from an exterior through the communication interface; and 
 write the encryption key in the distributed address area in the first region of the first memory, in a state where the encryption key is divided into the split keys. 
   
     
     
         9 . The semiconductor device of  claim 8 , wherein the encryption key writing program executes an authentication, before the split keys are written in the first memory. 
     
     
         10 . The semiconductor device of  claim 9 , wherein, before the split keys are written in the first memory, the encryption key writing program determines that the operation mode to be operated by the CPU is the first operation mode, and determines whether the split keys are already written in the first memory, and
 wherein, when the operation mode to be operated by the CPU is the first operation mode and when the split keys are not yet written in, the encryption key writing program advances to the authentication.   
     
     
         11 . The semiconductor device of  claim 10 , wherein the first memory includes a region for storing data indicative of whether the split keys have already been written in the first region. 
     
     
         12 . The semiconductor device of  claim 11 , wherein the data indicative of whether the split keys have already been written comprises a plurality of bits. 
     
     
         13 . The semiconductor device of  claim 5 , wherein the distributed address areas in the first region of the first memory are discontinuous with respect to a physical address in the first memory, and discontinuous with respect to a logical address for accessing by the CPU. 
     
     
         14 . The semiconductor device of  claim 13 , wherein at least one of an interval of the physical addresses corresponding to the distributed address areas in the first region of the first memory and an interval of the logical addresses corresponding to the distributed address areas, is unequal. 
     
     
         15 . The semiconductor device of  claim 1 , further comprising:
 an address bus and a data bus; and   a universal asynchronous receiver transmitter (UART) which is coupled to the CPU, the first memory, the second memory and the decrypter, by the address bus and the data bus.   
     
     
         16 . An encryption key writing method for writing an encryption key to a semiconductor device, the method comprising:
 providing a semiconductor device comprising:
 a central processing unit (CPU); 
 a first memory which stores a plurality of split keys; 
 a second memory which stores an encryption code as at least one of an encrypted instruction and encrypted data, the plurality of split keys comprising an encryption key for decrypting the encryption code; 
 a decrypter which reads the encryption code from the second memory, decrypts the encryption code with the use of the encryption key, and supplies the decrypted encryption code to the CPU; and 
 a communication interface; 
   inputting the encryption key from an exterior through the communication interface; and   writing the inputted encryption key in a plurality of distributed address areas in a first region of the first memory, in the state where the encryption key is divided into a plurality of split keys.   
     
     
         17 . The encryption key writing method of  claim 16 , further comprising before the writing of the inputted encryption key:
 confirming that an operation mode to be operated by the CPU is a first operation mode;   confirming that the split keys are not written in the plurality of distributed address areas of the first memory, and   authenticating the writing of the inputted encryption key.   
     
     
         18 . The encryption key writing method of  claim 17 , further comprising:
 restoring the encryption key and supplying the encryption key to the decrypter in the first operation mode, by reading and reconfiguring the split keys stored in the first memory in a distributed manner, when it is determined that an operation mode to be operated by the CPU is a second operation mode, and   shifting the operation mode of the CPU to the second operation mode.

Join the waitlist — get patent alerts

Track US2016140057A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.