Cryptography module and method for operating same

US11657165B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-11657165-B2
Application numberUS-201917055035-A
CountryUS
Kind codeB2
Filing dateMay 22, 2019
Priority dateJun 20, 2018
Publication dateMay 23, 2023
Grant dateMay 23, 2023

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A cryptography module for a computing device. The cryptography module is designed to check at least one memory area of a memory device which the computing device may access, as the result of which a result of the check is obtained, and to store the result at least temporarily.

First claim

Opening claim text (preview).

What is claimed is: 1. A cryptography module for a computing device, the cryptography module configured to: perform a check operation that produces a result, the checking operation checking at least one memory area of a memory device which is accessible by the computing device; and store the result at least temporarily, wherein the result indicates whether a change has occurred in a content of the at least one memory area on account of a manipulation or an error, and wherein the cryptography module checks multiple memory areas of the memory device, the cryptography module checking the multiple memory areas at least occasionally in a random or pseudorandom sequence, and wherein the cryptography module is configured to carry out the check of the at least one memory area using a cypher-based message authentication code (CMAC). 2. The cryptography module as recited in claim 1 , wherein the cryptography module is configured to periodically check multiple memory areas of the memory device. 3. The cryptography module as recited in claim 1 , wherein the cryptography module is configured to store at least temporarily the result of the check in a volatile and/or nonvolatile manner. 4. The cryptography module as recited in claim 1 , wherein the result of the check of a memory area of the at least one memory area includes at least one truth value that characterizes the result of the check. 5. The cryptography module claim 4 , wherein the cryptography module is configured to periodically check multiple memory areas of the memory device, wherein the result of the check of a memory area of the multiple memory areas includes at least one truth value that characterizes the result of the check, and wherein multiple truth values that are associated in each case with checked memory areas of the memory device as the result undergo an OR link in order to ascertain an overall result, the overall result characterizing whether at least one result of the multiple checked memory areas of the memory device is negative. 6. The cryptography module as recited in claim 5 , wherein the cryptography module is configured to store at least temporarily the overall result in a volatile and/or nonvolatile manner. 7. The cryptography module as recited in claim 5 , wherein the cryptography module is configured to initiate an error response when the overall result is negative, the error response including at least one of the following measures: a) resetting the computing device, and/or resetting the computing device and the cryptography module, b) transmitting an interrupt request to the computing device, c) blocking an access of the computing device to cryptographic keys that are stored in the cryptography module or providable by the cryptography module and/or to other first data, d) preventing the execution of a bootloader of the computing device by holding in a reset state the computing device, e) providing the overall result for the computing device and/or transmitting the overall result to the computing device. 8. The cryptography module as recited in claim 1 , wherein the cryptography module includes a memory unit integrated into the cryptography module, for storing at least one reference value and/or a reference layout for the at least one memory area. 9. The cryptography module as recited in claim 8 , wherein the cryptography module is configured to carry out the check as a function of the reference value. 10. The cryptography module as recited in claim 1 , wherein the cryptography module is configured to establish within the scope of the check whether the content of the at least one memory area corresponds to a predefinable memory content. 11. The cryptography module as recited in claim 1 , wherein the at least one memory area includes a bootloader for the computing device for execution on the computing device. 12. The cryptography module as recited in claim 1 , wherein the cryptography module is configured to provide the computing device with first data, the first data being cryptographic keys, the cryptography module being configured to provide the computing device with the first data only partially, or not at all, as a function of the check. 13. A method for operating a cryptography module for a computing device, the method comprising the following steps: performing, by the cryptography module, a checking operation that produces a result, the checking operation checking at least one memory area of a memory device accessible by the computing device to obtain a result of the check; and at least temporarily storing the result, wherein the result indicates whether a change has occurred in a content of the at least one memory area on account of a manipulation or an error, and wherein the cryptography module checks multiple memory areas of the memory device, the cryptography module checking the multiple memory areas at least occasionally in a random or pseudorandom sequence, and wherein the cryptography module is configured to carry out the check of the at least one memory area using a cypher-based message authentication code (CMAC). 14. The method as recited in claim 13 , wherein the cryptography module stores the result of the check, at least temporarily, in a volatile and/or nonvolatile manner.

Assignees

Inventors

Classifications

  • Protecting data integrity, e.g. using checksums, certificates or signatures · CPC title

  • at application loading time, e.g. accepting, rejecting, starting or inhibiting executable software based on integrity or source reliability · CPC title

  • Bootstrapping (security arrangements therefor G06F21/57) · CPC title

  • by using cryptography (for digital transmission H04L9/00) · CPC title

  • Secure boot · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US11657165B2 cover?
A cryptography module for a computing device. The cryptography module is designed to check at least one memory area of a memory device which the computing device may access, as the result of which a result of the check is obtained, and to store the result at least temporarily.
Who is the assignee on this patent?
Bosch Gmbh Robert
What technology area does this patent fall under?
Primary CPC classification G06F21/57. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue May 23 2023 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 4 related publications on this page (citations in our corpus or others sharing the same primary CPC).