EP2873021A1 - Procédé pour protéger une carte à puce contre une attaque physique destinée à modifier le comportement logique d'un programme fonctionnel - Google Patents
Procédé pour protéger une carte à puce contre une attaque physique destinée à modifier le comportement logique d'un programme fonctionnelInfo
- Publication number
- EP2873021A1 EP2873021A1 EP13735012.0A EP13735012A EP2873021A1 EP 2873021 A1 EP2873021 A1 EP 2873021A1 EP 13735012 A EP13735012 A EP 13735012A EP 2873021 A1 EP2873021 A1 EP 2873021A1
- Authority
- EP
- European Patent Office
- Prior art keywords
- program
- memory
- stored
- codes
- functional
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Withdrawn
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/52—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems during program execution, e.g. stack integrity ; Preventing unwanted data erasure; Buffer overflow
- G06F21/54—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems during program execution, e.g. stack integrity ; Preventing unwanted data erasure; Buffer overflow by adding security routines or objects to programs
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/70—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer
- G06F21/71—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure computing or processing of information
- G06F21/77—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure computing or processing of information in smart cards
Definitions
- the present invention relates to the implementation of countermeasures for protecting a functional program stored in a memory zone of an electronic card against an electrical disturbance attack intended to modify at least one logic state of at least one code of this program.
- An electronic card includes components, such as memory blocks that may contain codes of a so-called functional program.
- a functional program is here considered to be a program whose logical state of at least one of its codes can be modified by an electrical disturbance attack applied to a particular point of memory on which memorized the codes of this program. Subsequently and for reasons of brevity, the expression attack will be understood as equivalent to the expression attack by electrical disturbance.
- a disturbance of electrical origin is usually defined by parameters such as the electrical power, the duration of application of the disturbance or the point of attack on the map that is to say the point of the map where this disturbance is applied.
- An attack can modify logic states of program codes by physically disrupting the components of that card. These modifications will lead to errors in the execution of the program codes that may jeopardize the security of the data on the card.
- an attack is to inject energy on a specific point of the chip at a specific time, via for example a laser.
- the attack point and the time of the attack are determined by the attacker so that the energy applied during this attack modifies the logical state of at least one code of a functional program stored in a zone particular memory of the chip.
- An attack causes, for example, a modification of certain logic states of the chip or the value of a stored data item used by or resulting from the execution of at least one code of this functional program.
- An attack can also disturb the sequencing of the steps of a functional program so that a function of the program is not executed for example.
- Such a memory zone may thus be, for example, a memory plane or a set of memory planes connected by a bus. This example is given here for illustrative purposes and does not limit the scope of the process.
- a control program checks the logical behavior of the functional program. It can, for example, check the coherence of the logic states of the card or validate tests or verify that a function that was to be called by a functional program has been or that a logical state has a value expected . In case of anomaly (fault), the control program then forces, for example, the card to be silent or to hang.
- This type of countermeasure is not effective against spatial or space-time attacks because repeated tests can all give the same false results if the repetition of the attacks is timed with the repetition of the tests.
- the problem solved by the present invention is to overcome the drawbacks raised.
- the invention consists in storing the codes of the control program in a memory zone formed by addresses which are defined so that an attack by electrical disturbance does not have any influence on the control program. the logical states of this program.
- the present invention relates to a method for protecting a functional program stored in a memory zone of an electronic card against an electrical disturbance attack intended to modify at least one logic state of at least one a code of this program, said method comprising:
- the control program codes are stored in a memory zone formed of addresses which are defined so that the electrical disturbance attack has no influence on the logical states of this program.
- the codes of the functional program are stored in a first memory zone and duplicated in a third memory zone and the codes of the control program are stored in a second zone and duplicated in a fourth memory zone, said first, second third and fourth memory zones being each formed by addresses which are defined so that an electrical disturbance attack on one of these other memory zones has no influence on the logic states of the codes of a program stored in another of these memory zones, and the step of executing at least one code of the functional program is then preceded by a memory zone selection step during which, on the one hand, is randomly selected a functional program among those stored in the first and third memory areas, the control program executes during the verification step then being that stored in the second memory zone if the functional program chosen is the one memorized in the first memory zone, or that stored in the fourth memory zone if the functional program chosen is
- the first and fourth memory areas are one and the same memory area and the third and second memory areas are also one and the same memory area, said two unique memory areas then being each formed of addresses. which are defined so that a disturbance attack of electrical origin on one of these memory zones has no influence on the logic states of the codes of a program stored in the other of these two memory zones.
- the codes of the control program are also stored in a third memory zone, said first, second and third memory zones then being each formed of addresses which are defined so that a disturbance attack of electrical origin on one of these memory zones has no influence on the logic states of the codes of one program stored in another of these memory zones, the verification step (3 ) is then preceded by a memory block selection step during which, it is randomly selected a control program among those stored in the second and third memory areas.
- said trap program which is defined to fill a register of the electronic card as soon as it undergoes an attack by electrical disturbance
- control program chosen is that of the second memory zone
- step of checking the coherence of said logic states is followed by a step of execution of the trap program stored in the third memory zone and,
- control program chosen is that of the third memory zone
- step of checking the coherence of said logic states is preceded by a step of execution of the trap program stored in the second memory zone.
- the present invention relates to a device for protecting a functional program stored in a memory of an electronic card against an electrical disturbance attack intended to modify at least one logic state of at least a code of this program, said device comprising:
- the means for storing the codes is configured so that the codes of the control program are stored in a memory zone formed by addresses which are defined so that the electrical disturbance attack does not have influence on the logical states of this program.
- the present invention relates to a computer program product characterized in that it comprises instructions for implementing, by a device above, the method also mentioned above when said program is executed by a device processor.
- the present invention relates to computer readable storage means characterized in that they store a computer program comprising instructions for implementing, by a suitable device, the above method when said program is executed by a processor of the above device.
- Fig. 1 represents a diagram of the steps of the method according to the present invention.
- Fig. 2 illustrates an example of a first embodiment according to the present invention.
- Fig. 3 illustrates an example of a second embodiment according to the present invention.
- Fig. 4 illustrates an example of a variant of the second embodiment according to the present invention.
- Fig. 5 illustrates an example of a third embodiment according to the present invention.
- Fig. 6 illustrates an example of a variant of the third embodiment according to the present invention.
- Figs. 2-5 provide illustrations of embodiments of the method according to the present invention in which a functional program SP, a program P and a control program CP are stored.
- the program SP is said to be functional because the logic state of at least one of its codes can be modified by an electrical disturbance attack applied to a particular point of the memory on which the codes of this program are stored.
- the program P is a program that is not functional that is to say not sensitive to this attack.
- the term program is used here to designate both an instruction and a set of instructions.
- the SP and P programs can be parts of the same program.
- the CP control program is used as a countermeasure to protect the SP program against attacks.
- the method comprises a storage step 1 during which codes of the functional program SP and the codes of the control program CP are stored in the memory of the card, a step 2 of execution of at least one code of the functional program SP followed by a step 3 of checking the logic states of the functional program SP by execution of the control program CP.
- the process can be continued by running the P program. But this is not an essential step in the process according to the present invention.
- the method is particular because during the storage step, the codes of the control program CP are stored in a memory zone formed by addresses which are defined so that the electrical disturbance attack does not have a problem. influence on the logical states of this program.
- Fig. 2 illustrates a first embodiment of this method.
- the functional program SP is stored in a first memory zone ZI and the control program CP is stored in a second memory zone Z2.
- the zones Z1 and Z2 are represented here by disjoint rectangles to indicate that the memory zone Z2 is formed by addresses which are defined, within the meaning of the invention, so that an attack by electrical disturbance has not for influencing the logic states of the codes of the control program CP while the memory zone ZI is formed by addresses relating to program codes (here SP and P) whose logic states can be modified by such an attack.
- This embodiment makes it possible to protect the memory of an electronic card against temporal attacks. Indeed, if the zone ZI undergoes an attack, the zone Z2 will not be affected and the control program will act on the card following the detection of a fault. On the other hand, if zone Z2 is attacked, the logical behavior of the SP program will not be affected.
- Fig. 3 illustrates a second embodiment of this method.
- the codes of the functional program SP are stored in a first memory zone ZI and duplicated in a third memory zone Z3 and the codes of the control program CP are stored in a memory.
- the memory zones Z1, Z2, Z3 and Z4 are each formed by addresses which are defined, within the meaning of the invention, so that an electrical disturbance attack on one of these other memory zones has not occurred. no influence on the logic states of the codes of one program stored in another of these memory zones,
- the method then comprises, according to this embodiment, a memory zone selection step 4 which precedes step 2 of execution of the functional program.
- This step 4 is illustrated in FIG. 3 by a function block A stored in the zone ZI. It may be noted that this functional block A can be stored on other memory areas without departing from the scope of this embodiment.
- step 4 on the one hand, a functional program SP of those memorized on the memory zones Z1 and Z3 is randomly chosen.
- the control program CP executed during step 3 is then either that stored in the memory zone Z2 if the functional program CP chosen is the one memorized in the memory zone ZI, or that memorized in the memory zone Z4 if the functional program chosen is the one stored in the memory zone Z3.
- This embodiment makes it possible to protect the memory of the electronic card against temporal attacks because both the functional program and the control program are duplicated on two memory zones (defined in the sense of the invention) and the choice to use randomly stored programs either in one or in the other memory area can be robust to repeated attacks because the probability will be low that different successive attacks choose the programs stored on the same memory areas.
- the failure rate of an attack is a function of the number of duplication programs on memory areas defined in the sense of the invention. Thus, by duplicating them once, the failure rate is 50%.
- the memory zones Z1 and Z4 are one and the same memory zone Z14 and the memory zones Z2 and Z3 are one and the same memory zone Z23, the memory zones Z14 and Z23 are then each formed of addresses which are defined at within the meaning of the invention, so that an electrical disturbance attack on one of these memory zones has no influence on the logic states of the codes of one program stored in the other of these two memory areas.
- Fig. 5 illustrates a third embodiment of the method.
- the codes of the control program CP are stored in a second memory zone Z2 and duplicated in a third memory zone Z3 while the codes of the functional program SP are not memorized. only in a first memory zone ZI.
- the memory zones Z1, Z2 and Z3 are then each formed of addresses which are defined, within the meaning of the invention, so that an attack by electrical disturbance on one of these memory zones has no problem. influence on the logic states of the codes of one program stored in another of these memory areas.
- the method then comprises, according to this embodiment, a memory zone selection step 4 which precedes step 3 of execution of the functional program.
- This step 4 is illustrated in FIG. 5 by a function block A stored in the zone ZI. It may be noted that this functional block A can be stored on other memory areas without departing from the scope of this embodiment.
- a control program CP is randomly selected from among those stored in the memory zones Z2 and Z3.
- This embodiment makes it possible to obtain failure rates of an attack similar to those obtained with the second embodiment.
- this mode is advantageous because only the control program is duplicated which limits the impact on the cost in size of this program.
- Fig. 6 illustrates a variant of the third embodiment of the method according to the present invention.
- the step 1 of storage it is also stored in the memory zone Z2 the codes of a program PP, said trap program, which is defined to detect an attack on the memory area in which it is stored.
- This trap program is duplicated in the memory zone Z3.
- step 3 is followed by a step 5 of execution of the trap program stored in the memory zone Z3 and, if the control program CP chosen is the one of the memory zone Z3, then step 3 is preceded by a step 5 of execution of the trap program stored in the memory zone Z2.
- This variant is also illustrated in FIG. 1 by the circles in italics.
- This variant makes it possible to protect the memory of the electronic card against spatio-temporal attacks because both the functional program and the trap program are duplicated on two memory zones formed by addresses that are defined, within the meaning of the invention, for that a disturbance attack of electrical origin on one of these memory zones has no influence on the logic states of the codes of one program stored in the other of these two memory zones, and the choice of randomly using the programs stored either in one or in the other memory area makes it possible to be robust to repeated attacks because the probability will be low that the different successive attacks choose the programs stored on the same memory areas.
- the functional program SP is not duplicated here, but the control program CP is duplicated in two memory areas as in the embodiment of FIG. 5.
- a trap program PP is introduced that does not check anything by default, but that makes it possible to detect that an attack has been applied to the memory zone where it is stored if it is disturbed.
- the trap program PP then makes it possible to apply a security policy of the card.
- All or part of the methods described above can be implemented in software form by executing a set of instructions by a programmable machine, such as a DSP (Digital Signal Processor in English or Digital Signal Processing Unit in French). or a microcontroller or be implemented in hardware form by a machine or a dedicated component, such as an FPGA (Field Programmable Gate Array) or an ASIC (Application-Specific Integrated Circuit). English or Integrated Circuit Specific to an Application in French).
- a programmable machine such as a DSP (Digital Signal Processor in English or Digital Signal Processing Unit in French).
- a microcontroller or be implemented in hardware form by a machine or a dedicated component, such as an FPGA (Field Programmable Gate Array) or an ASIC (Application-Specific Integrated Circuit). English or Integrated Circuit Specific to an Application in French).
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Theoretical Computer Science (AREA)
- Software Systems (AREA)
- Computer Hardware Design (AREA)
- Physics & Mathematics (AREA)
- General Engineering & Computer Science (AREA)
- General Physics & Mathematics (AREA)
- Mathematical Physics (AREA)
- Computing Systems (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Storage Device Security (AREA)
Abstract
Description
Claims
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| FR1256618A FR2993380B1 (fr) | 2012-07-10 | 2012-07-10 | Procede pour proteger une carte a puce contre une attaque physique destinee a modifier le comportement logique d'un programme fonctionnel |
| PCT/EP2013/064368 WO2014009307A1 (fr) | 2012-07-10 | 2013-07-08 | Procédé pour protéger une carte à puce contre une attaque physique destinée à modifier le comportement logique d'un programme fonctionnel |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| EP2873021A1 true EP2873021A1 (fr) | 2015-05-20 |
Family
ID=47624180
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP13735012.0A Withdrawn EP2873021A1 (fr) | 2012-07-10 | 2013-07-08 | Procédé pour protéger une carte à puce contre une attaque physique destinée à modifier le comportement logique d'un programme fonctionnel |
Country Status (4)
| Country | Link |
|---|---|
| US (1) | US10148671B2 (fr) |
| EP (1) | EP2873021A1 (fr) |
| FR (1) | FR2993380B1 (fr) |
| WO (1) | WO2014009307A1 (fr) |
Families Citing this family (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| FR3098319A1 (fr) * | 2019-07-05 | 2021-01-08 | Commissariat à l'énergie atomique et aux énergies alternatives | Procédé d'exécution d'un code binaire d'une fonction sécurisée par un microprocesseur |
| US12418559B2 (en) * | 2020-04-10 | 2025-09-16 | AttackIQ, Inc. | Method for emulating an attack on an asset within a target network |
| US11563765B2 (en) * | 2020-04-10 | 2023-01-24 | AttackIQ, Inc. | Method for emulating a known attack on a target computer network |
| US12547704B2 (en) * | 2023-05-17 | 2026-02-10 | Arm Limited | Automated deployment of relocatable code blocks as an attack countermeasure in software |
| CN118158679B (zh) * | 2024-03-25 | 2024-11-29 | 中国人民解放军61660部队 | 基于基带攻击的无线信号侦听方法 |
Family Cites Families (10)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP3950589B2 (ja) * | 1998-08-28 | 2007-08-01 | キヤノン株式会社 | 情報処理装置、プログラム更新方法および記憶媒体 |
| FR2785422B1 (fr) * | 1998-10-29 | 2000-12-15 | Schlumberger Ind Sa | Dispositif et procede pour la securisation d'un circuit integre |
| US6591393B1 (en) * | 2000-02-18 | 2003-07-08 | Hewlett-Packard Development Company, L.P. | Masking error detection/correction latency in multilevel cache transfers |
| JP3653449B2 (ja) * | 2000-06-15 | 2005-05-25 | シャープ株式会社 | 不揮発性半導体記憶装置 |
| FR2841015A1 (fr) * | 2002-06-18 | 2003-12-19 | St Microelectronics Sa | Controle d'execution d'un programme |
| EP1383047A1 (fr) * | 2002-07-18 | 2004-01-21 | Cp8 | Procédé de sécurisation de l'exécution d'un programme contre des attaques par rayonnement ou autres |
| NO324607B1 (no) * | 2003-11-24 | 2007-11-26 | Thin Film Electronics Asa | Fremgangsmate for a betjene et datalagringsapparat som benytter passiv matriseadressering |
| US7945958B2 (en) * | 2005-06-07 | 2011-05-17 | Vmware, Inc. | Constraint injection system for immunizing software programs against vulnerabilities and attacks |
| US7646636B2 (en) * | 2007-02-16 | 2010-01-12 | Mosaid Technologies Incorporated | Non-volatile memory with dynamic multi-mode operation |
| US10360143B2 (en) * | 2010-07-01 | 2019-07-23 | Qualcomm Incorporated | Parallel use of integrated non-volatile memory and main volatile memory within a mobile device |
-
2012
- 2012-07-10 FR FR1256618A patent/FR2993380B1/fr active Active
-
2013
- 2013-07-08 EP EP13735012.0A patent/EP2873021A1/fr not_active Withdrawn
- 2013-07-08 US US14/413,860 patent/US10148671B2/en active Active
- 2013-07-08 WO PCT/EP2013/064368 patent/WO2014009307A1/fr not_active Ceased
Non-Patent Citations (2)
| Title |
|---|
| None * |
| See also references of WO2014009307A1 * |
Also Published As
| Publication number | Publication date |
|---|---|
| WO2014009307A1 (fr) | 2014-01-16 |
| US20150180882A1 (en) | 2015-06-25 |
| FR2993380A1 (fr) | 2014-01-17 |
| FR2993380B1 (fr) | 2020-05-15 |
| US10148671B2 (en) | 2018-12-04 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| JP7157222B2 (ja) | セッションセキュリティ分割およびアプリケーションプロファイラ | |
| US9998482B2 (en) | Automated network interface attack response | |
| CN107659583B (zh) | 一种检测事中攻击的方法及系统 | |
| US20170111391A1 (en) | Enhanced intrusion prevention system | |
| CN104519032A (zh) | 一种互联网账号的安全策略及系统 | |
| EP2873021A1 (fr) | Procédé pour protéger une carte à puce contre une attaque physique destinée à modifier le comportement logique d'un programme fonctionnel | |
| CN115396202B (zh) | 一种暴力破解的识别方法及相关组件 | |
| WO2015063405A1 (fr) | Systeme de detection d'intrusion dans un dispositif comprenant un premier systeme d'exploitation et un deuxieme systeme d'exploitation | |
| Snyder et al. | {Pool-Party}: Exploiting browser resource pools for web tracking | |
| US11240268B1 (en) | Dynamic honeypots for computer program execution environments | |
| Netto et al. | An integrated approach for detecting ransomware using static and dynamic analysis | |
| CA2575143C (fr) | Procede et dispositif de traitement de donnees | |
| Thangavel et al. | Review on machine and deep learning applications for cyber security | |
| CN120012098B (zh) | 勒索病毒加密行为防护能力的无害化验证方法及装置 | |
| KR20190020523A (ko) | 로그 분석을 이용한 공격 탐지 장치 및 방법 | |
| EP1442556B1 (fr) | Procédé securisé de mise en oeuvre d'un algorithme de cryptographie et composant correspondant | |
| Talukder et al. | SPARE: Securing Progressive Web Applications Against Unauthorized Replications | |
| FR3089321A1 (fr) | Procédés et programmes d’ordinateur de défense contre les attaques informatiques | |
| CN112637217B (zh) | 基于诱饵生成的云计算系统的主动防御方法及装置 | |
| EP2630605B1 (fr) | Procede de securisation de l'execution d'un code informatique par redondance dynamique | |
| Locasto et al. | Bloodhound: Searching Out Malicious Input in Network Flows for Automatic Repair Validation | |
| WO2011073301A1 (fr) | Procede de protection polymorphe d'un code executable | |
| JP2026512929A (ja) | モバイルプラットフォームのための積層されたマルウェア検出器 | |
| CN119788289A (zh) | 基于WebGL指纹技术的登录环境检测与安全增强方法及装置 | |
| CN120632879A (zh) | 函数篡改检测方法、装置、存储介质以及终端 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| 17P | Request for examination filed |
Effective date: 20150128 |
|
| AK | Designated contracting states |
Kind code of ref document: A1 Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC MK MT NL NO PL PT RO RS SE SI SK SM TR |
|
| AX | Request for extension of the european patent |
Extension state: BA ME |
|
| DAX | Request for extension of the european patent (deleted) | ||
| RAP1 | Party data changed (applicant data changed or rights of an application transferred) |
Owner name: IDEMIA IDENTITY & SECURITY FRANCE |
|
| 17Q | First examination report despatched |
Effective date: 20191022 |
|
| GRAP | Despatch of communication of intention to grant a patent |
Free format text: ORIGINAL CODE: EPIDOSNIGR1 |
|
| INTG | Intention to grant announced |
Effective date: 20200323 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE APPLICATION IS DEEMED TO BE WITHDRAWN |
|
| 18D | Application deemed to be withdrawn |
Effective date: 20200804 |