Bus hardware security monitoring equipment and monitoring method based on embedded system

By introducing bus hardware security monitoring equipment into the embedded SoC system and using the L-HASH algorithm and dedicated DMA for data movement, the security and integrity issues of the embedded SoC system during key data transmission are solved, and efficient data monitoring and security protection are achieved.

CN120653505APending Publication Date: 2025-09-16SHAOXING YANGYU INTELLIGENT CHIP CO LTD

Patent Information

Application Number
CN202510575281.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-06
Publication Date
2025-09-16

AI Technical Summary

Technical Problem

Existing embedded SoC systems are vulnerable to attacks during critical data transmission, and existing bus monitors cannot effectively monitor bus access behavior and data integrity, resulting in insufficient system security.

Method used

A bus hardware security monitoring device is designed. It uses L-HASH security summary calculation and dedicated DMA to replace the CPU for data movement. By monitoring bus access operations and performing data integrity verification, combined with an optimized L-HASH algorithm, it improves security and throughput.

Benefits of technology

Without affecting the bus efficiency, it improves the security and operating speed of the embedded SoC system, ensures the integrity and privacy of key data, and reduces the CPU computing burden.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120653505A_ABST
    Figure CN120653505A_ABST
Patent Text Reader

Abstract

The invention provides bus hardware security monitoring equipment and a monitoring method based on an embedded system, master control equipment and slave equipment on a bus are connected with an intermediate control module, a bus monitoring module comprises a lightweight hash algorithm module and a DM module, all the master control equipment and slave equipment on the bus are connected with the input end of each channel, and the input end of each channel is connected with the corresponding channel. The outputs of all the channels are summarized to the interrupt management unit, the interrupt management unit serves as the output end of the bus monitoring module and is connected with the DMA, each channel comprises a monitoring selection unit, an access selection unit and a counting comparison unit, and an address range is set for each channel. Corresponding interrupt information is generated by monitoring the integrity abnormal behavior of a specific bus access sequence occurring in a system bus in the SoC security program running process. In a low-power-consumption application scene, the security of the embedded SoC can be improved, and key information is protected from being stolen and damaged.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of embedded system security, and more particularly to a hardware security monitoring method based on a multi-stage pipeline structure. A lightweight, low-power hash algorithm (L-HASH) generation circuit is provided. Without affecting the normal operation of the Advanced High Performance Bus (AHB) high-performance bus or reducing bus efficiency, the circuit monitors the integrity of specific bus access sequences occurring on the system bus during the execution of a SoC (System on Chip) security program, generating corresponding interrupt information. This method can improve the security of embedded SoCs in low-power application scenarios, protecting critical information from theft and destruction. Background Art

[0002] The rapid development and advancement of microelectronics technology has led to widespread adoption of embedded systems. Due to the large scale and complex application scenarios of embedded systems, their applications in defense, aerospace, finance, and other fields place high security demands, making embedded system security a hot topic of research. Therefore, secure SoC chips offer broad advantages in the information security field. Embedded SoC systems are generally designed based on a general system architecture. Whether operating general data or transferring critical data, the system bus is a crucial bridge for these transmission processes. Consequently, attackers often exploit side-channel attacks and injection attacks to obtain critical information transmitted on the system bus during power-up initialization of embedded SoC chips, thereby gaining insight into the embedded system's operating behavior and potentially compromising the entire secure information system.

[0003] Embedded SoC chips often include a large number of external storage devices, such as SDRAM (synchronous dynamic random-access memory) and Flash. To improve system efficiency, data often needs to be moved to the chip's internal memory. This transfer process, accomplished via the system bus, can become a target for attackers. This is because embedded system chips often have strong access restrictions, prohibiting unauthorized users from accessing key chip information through their integrated CPU cores. Therefore, directly interfering with bus behavior can be a very effective attack method. If an attack, such as tampering or theft, occurs during the execution of critical programs or the transmission of important data on an embedded SoC chip, the system's normal operation mechanism may fail, resulting in immeasurable losses.

[0004] The AMBA (Advanced Microcontroller Bus Architectural) bus is an open, efficient SoC bus standard proposed by ARM. Independent of processors and process technologies, it boasts high speed, low power consumption, and strong reusability. The AMBA bus has become the bus standard for embedded SoCs. AHB, defined by the AMBA bus protocol, is a high-speed, high-performance system bus standard. Embedded SoC platforms built on AHB have become a key development direction for embedded SoCs. To improve the security and integrity of critical data in embedded SoC chips, the present invention fully considers the entire data transmission system consisting of DMA (Direct Memory Access), the system bus, and the on-chip storage system. Without affecting the operation of the AHB bus, this invention incorporates a lightweight hashing algorithm to provide integrity for critical data and programs while significantly reducing the performance loss of the embedded system.

[0005] SoC chips are typically based on a bus architecture. Master devices like the processor and DMA access slave devices like memory and communication modules through the bus, enabling general-purpose computing and real-time control. The bus serves as the interface between the master and slave devices. Analyzing the bus's operating status and efficiency can provide insights and a basis for debugging and optimizing the entire chip.

[0006] In existing SoC system signature authentication systems, the internal memory SRAM is used to store the data content that requires signature authentication, including the message and digital signature. The central processing unit (CPU) is responsible for executing the signature authentication algorithm: first, it needs to read the original data from the SRAM and execute the SHA256 algorithm to obtain the digest of the original data, Digest_M. Then, it reads the digital signature R from the SRAM and executes the confidentiality algorithm to obtain the decrypted result of the signature, Digest_S. Finally, the authenticity of the original data is determined by comparing Digest_M and Digest_S. The CPU needs to frequently access the SRAM to obtain data while also sequentially executing complex confidentiality and integrity algorithms. The high complexity of the confidentiality algorithm makes software design very difficult. In addition, the CPU's excessive access to the SRAM makes the real-time performance of the authentication scheme poor.

[0007] The patent application "System-on-Chip Bus Priority Dynamic Configuration Device Based on Bus Monitor" (CN201010562898.3) provides a bus monitor that monitors memory access conflicts among multiple master devices and adjusts their access priorities. This bus monitor cannot meet the need to monitor bus access behavior in different address ranges of the same device.

[0008] Patent application "A Bus Monitoring Module and Monitoring Method for the AHB Protocol" (CN113190400A) provides a bus monitoring module and monitoring method for the AHB protocol. The bus monitoring module includes multiple channels, with multiple master and slave devices on the bus connected to the input of each channel. The outputs of all channels are aggregated to an interrupt management unit. This monitoring method directly controls the monitoring module circuitry through the CPU and does not use security algorithms to protect data. This fails to meet security monitoring requirements. Summary of the Invention

[0009] This paper proposes an embedded system-based bus hardware security monitoring device. This device, mounted on the bus, primarily performs L-HASH security digest calculations and uses a dedicated DMA to replace the CPU for data movement. The bus monitor primarily consists of a bus slave interface module, a decoder module, a monitoring timeout module, a data capture module, an L-HASH algorithm calculation module, and a dedicated DMA. Among them, the bus slave interface module is connected to the bus, indicating the bus monitor slave device identity and receiving the signal from the master device; the decoder module is connected to the slave interface module and is responsible for generating chip select signals according to different access addresses, thereby configuring different register groups; the data capture module is also directly connected to the bus signal, sampling the data blocks and address information transmitted on the bus, and performing calculation format preprocessing on the information, and outputting it to the dedicated DMA; the L-HASH algorithm calculation module is responsible for performing summary calculations on the monitoring information and is interconnected with the dedicated DMA; the monitoring timeout module is also connected to the bus transmission signal, responsible for calculating the bus access delay, and the timeout interrupt signal output is connected to the CPU; the dedicated DMA receives the sampled preprocessed data of the data capture module and the configuration information of the user register, and is interconnected with the on-chip memory and the input and output of the L-HASH algorithm calculation module, and is responsible for transporting data. The dedicated DMA also includes a bus host interface module, a DMA control module, a data channel and cache FIFO module, a response synchronization module, and an interrupt control module. The bus host interface is directly connected to the bus and is used for data movement of the dedicated DMA; the DMA control module includes various control logics and register groups to control the dedicated DMA to move data; the data channel and cache FIFO module, the data moved by the dedicated DMA can be cached in the FIFO, and the data will be output after an output request. The data channel includes a write port and a read port, which are used to write and read data respectively. The number of data channels in the DMA can be configured according to the bus transmission characteristics, and it contains at least one data channel; the response synchronization module is responsible for synchronizing the signals of other clock domains input to the dedicated DMA to the DMA clock domain; the interrupt control module is responsible for information exchange with the CPU, receiving the empty signal of the data channel, and outputting the CPU interrupt request.

[0010] When configuring the data channel of the dedicated DMA inside the bus monitoring device, each channel selects one of the master and slave devices on the AHB bus as a monitoring device according to the DMA configuration; when the selected monitoring device is the master device, the channel monitors all bus access operations initiated by the master device and selects the operations of interest for counting, such as changes in the address phase and data phase. The L-HASH module performs a HASH calculation on the count value generated by the monitored bus operation and stores the generated calculation result in RAM as a comparison value. When the slave device on the bus initiates a bus access operation, the corresponding operation is selected for counting, including changes in the address phase and data phase, and the calculation result is calculated by the L-HASH module. When the count value equals the comparison value, a channel trigger signal is generated.

[0011] When the channel selects to monitor the master device, some of the connection signals between the master device and the AHB bus, including HADDR, HTRANS, and HWDATA, are sent to the access selection unit; when the channel selects to monitor the slave device, some of the connection signals between the slave device and the AHB bus, including HADDR, HTRANS, and HWDATA, are sent to the L-HASH module for integrity marking.

[0012] The data capture module uses the signal HADDR to determine whether the device is within the set address range; uses the signal HWDATA to determine whether the read and write operations conform to the set values; and uses the signal HTRANS to determine whether the device access is a single transfer or a continuous transfer. Accesses that meet all conditions are considered countable accesses to the device.

[0013] The counting comparison module accumulates the countable number of accesses through the access selection unit, and generates a channel trigger signal when the accumulated value is equal to the configured comparison value. If the comparison value configured by the counting comparison unit is 0, a channel trigger signal is generated when the counter overflows.

[0014] The timeout determination module determines the access address range, number of times the address is accessed, and the time of access to the address of the monitored device based on the trigger signal generated by the channel. It outputs an interrupt signal to the DMA according to the configuration, inserts a breakpoint in the interrupt function executed by the user register unit, and pauses the system for online debugging.

[0015] The L-HASH algorithm module designs and optimizes a bus security monitoring algorithm based on the L-HASH algorithm and implements the algorithm module in hardware. The algorithm also optimizes the internal round transformation function structure of the L-HASH algorithm, increasing the fixed round transformation length to 256, retaining a 16-bit round constant, and increasing the number of round transformation iterations to 16, thereby improving the security redundancy of the L-HASH algorithm. The L-HASH algorithm with an increased round transformation length of 256 has eight 32-bit registers to store initialization digests. The values ​​stored in six of these registers are directly determined by the results of the previous round transformation, that is, they are directly assigned to the registers storing the previous round transformation results. The values ​​of the other two registers are dependent on the results of the previous round transformation and the external input of the current round permutation, requiring an additional addition calculation. The result of a round transformation is normally stored by the registers of the previous first and second rounds, and the three rounds of registers rotate in storage. However, based on the characteristics of the calculation structure, the present invention eliminates the storage of the intermediate round registers in the three-round transformation structure. The value directly determined by the results of the previous second round calculation is directly assigned to the registers of the current round, and the value derived from the input data is added in the intermediate round. Therefore, the calculation process of the values ​​stored in these two registers is the critical path of the optimized L-HASH algorithm, that is, the path with the greatest delay that affects the computational throughput of the round-trip transformation. This invention replaces the conventional adder within the original round-trip transformation function structure with a carry-lookahead adder (CSA), reducing the impact of this maximum delay path on throughput and minimizing latency. Ultimately, two round-trip transformations are completed per clock cycle. In other words, after each permutation operation, the values ​​of the two registers are updated in parallel. The cycle time after each round-trip transformation is shortened to half of the original, significantly improving the computational speed and throughput of the L-HASH algorithm module.

[0016] The hardware implementation of the L-HASH algorithm mainly includes two parts: the data flow control state machine and the data channel module. The control logic circuit controls the input data and output data. The data channel module mainly consists of a first-in-first-out dedicated DMA module FIFO (First in First out) and two stages of sponge structure.

[0017] The data block with a specific bit width in the bus is used as the message input of the L-HASH algorithm. In the dedicated DMA module, the data received by the algorithm module is merged and converted, and then transferred to the initialization register through the FIFO multiplexer with the basic operation bit width. These register arrays mainly act as buffers for the input and output of the cache algorithm module. After the summary calculation is completed, the dedicated DMA can also store the HASH value generated at the current moment.

[0018] The hash function digest calculation process based on the sponge structure can be specifically divided into two stages: the absorption stage when the message is input, and the process of outputting the digest is called the compression stage. In the absorption stage, the input message first needs to be padded and divided into blocks. The blocks are padded into 96, 128, or 256-bit data blocks according to the message length. The specific size depends on the size of the input message. Taking L-Hash96 as an example, its input message length is 96 bits, so the message blocks are marked as m1, m2, m3, ... m n , message blocks m1, m2, m3, ...m n Both are 96 bits. If the length of the last block of messages is less than 32 bits and greater than 0 bits, the last message block needs to be padded to 32 bits. If the length of the last message block is greater than 32 bits but less than 96 bits, the last message block needs to be padded to 96 bits, following the rule that the most significant bit of the padded bit string is 1 and the rest are padded with 0s. In the design of the sponge structure, r represents the length of the input message block, c represents the portion that will not be XORed with the input message block during the round operation, b is the sum of r and c, representing the fixed round transformation bit length, and r* is the bit length of each output digest. The XOR calculation result is used as the input of the next round of compression function T, and the permutation continues until all padded and grouped message blocks are completely absorbed. During the compression phase of the sponge structure, compression function T takes the output of the last round of XOR calculations in the absorption phase as input. It then extracts subdigests from the outputs of each compression function and concatenates them to achieve the required output digest length.

[0019] A three-stage state machine is used to describe the finite state machine in the L-HASH control module, which properly controls the absorption, compression, and input and output caching processes of the L-HASH function. The four main states of the control state machine include: idle state (IDLE0), message write state (WRITE_L), signature verification state (SIGN), and digest read state (READ_L).

[0020] The present invention also proposes a bus hardware security monitoring method based on an embedded system. The method is implemented on the bus hardware security monitoring device proposed above and specifically includes the following steps:

[0021] Step 1: The embedded system CPU completes the initialization of the L-HASH security calculation module, and the L-HASH module is ready to receive data;

[0022] Step 2: The embedded system CPU configures the digest length into the internal register of the L-HASH calculation module;

[0023] Step 3: The CPU enables the DMA module and moves the data to be calculated for signature authentication (including address phase and data phase) in the SRAM to the L-HASH calculation module; the CPU determines whether the data transfer is completed through interruption or active query.

[0024] Step 4: The DMA controller selects one of the master and slave devices on the AHB bus as the monitoring device based on the DMA configuration. It then selects the bus operation of the monitored device to monitor and counts the corresponding bus access operations.

[0025] Step 5: During the DMA transfer process, the L-HASH calculation module starts L-HASH calculation upon receiving the address phase, data phase, and bus access operation count value of the monitored device.

[0026] Step 6: After the L-HASH calculation module completes the operation, the DMA transfers the calculation result to the counting and comparison module for data integrity verification.

[0027] Step 7: The CPU determines whether the data integrity check is completed through the timeout determination unit or active query. After the integrity check is completed, the CPU obtains the check result and can choose whether to read the L-HASH algorithm calculation result.

[0028] The advantages and beneficial effects of the present invention are:

[0029] 1. The L-HASH security algorithm circuit used in the embedded system bus hardware security monitoring device is improved, the round transformation function circuit structure of the L-HASH algorithm is optimized, the round transformation iteration number is increased, and the anti-image security is provided to 96 bits, with more sufficient security redundancy. The L-HASH round transformation generation circuit structure is optimized, and each three-layer round transformation circuit is compressed into two layers, so that each clock cycle can be upgraded from only performing one round transformation to performing two round substitutions, completing the fast round transformation of messages of the same length. A carry look-ahead adder is used to replace the ordinary adder, shortening the maximum delay path of the L-HASH round transformation generation circuit, reducing delay, and improving throughput and operation speed. Compared with the original circuit of the improved L-HASH algorithm circuit of the present invention, while improving security and throughput, the area is not significantly increased, and the integrity of embedded system bus transmission can be guaranteed under limited resources.

[0030] 2. A bus hardware security monitoring device for an embedded system that moves data through DMA is proposed. A dedicated DMA is designed in the bus hardware security monitoring device and mounted on the bus to replace the CPU for data movement and bus data read and write operations; at the same time, a DMA controller is designed in the bus monitor to control the operation of the dedicated DMA through register configuration and control logic signals. The dedicated DMA is enabled by the CPU, and the internal registers are configured by the CPU to move the monitored data to the L-HASH algorithm module through the internal data channel of the DMA, thereby greatly improving the operating speed of the embedded system. The bus hardware security monitoring device proposed in the present invention can minimize the impact and occupation of the L-HASH algorithm module on the CPU computing resources and scheduling, configure multiple data paths inside the DMA to replace the CPU for read and write control and data movement of the embedded system bus data, and realize real-time data transmission while ensuring the security of bus transmission data. It can efficiently control the data interaction between the various modules inside the embedded system, thereby improving the operating speed of the embedded system. BRIEF DESCRIPTION OF THE DRAWINGS

[0031] Figure 1 This is a flow chart of the AHB bus hardware security monitoring method.

[0032] Figure 2 This is a structural diagram of the dedicated DMA module provided by the present invention.

[0033] Figure 3 This is a hardware implementation structure diagram of the L-HASH calculation module provided by the present invention.

[0034] Figure 4 This is a structural block diagram of the AHB bus monitor in the bus hardware security monitoring device provided by the present invention.

[0035] Figure 5 The present invention is a SoC system embodiment that applies the bus monitoring device and method provided by the present invention. DETAILED DESCRIPTION

[0036] The technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, rather than all the embodiments.

[0037] Based on the proposed embedded system bus hardware security monitoring device, the present invention also proposes a set of embedded system bus hardware security monitoring methods. The monitoring method will be specifically implemented in Figure 5 The flowchart of the bus complete monitoring method on the AHB bus hardware security monitoring device system-level platform is as follows: Figure 1 The specific monitoring methods are as follows:

[0038] In step 1, the CPU of the E906 processor completes the initialization of the L-Hash algorithm module, and the L-Hash module is in the state of receiving plaintext data.

[0039] Step 2: The user register module of the embedded system configures the digest length value into the internal register of the L-Hash calculation module through a dedicated DMA.

[0040] Step 3: The CPU enables the dedicated DMA module to move the data to be calculated (including address phase information and data phase information) in the SRAM to the dedicated DMAFIFO of the L-Hash algorithm module; the CPU determines whether the data transfer is completed through interruption or active query.

[0041] In step 4, the DMA controller selects one of the master and slave devices on the AHB bus as the monitoring device based on the DMA configuration, monitors the bus behavior of the monitored data, and counts the bus access operations.

[0042] Step 5: During the DMA transfer process, after receiving the address phase and data phase, the L-Hash algorithm module starts digest calculation while counting the bus access operations of the monitored device.

[0043] Step 6: After the L-Hash algorithm module completes the calculation, the DMA transfers the calculation results to the calculation and comparison module for data integrity verification.

[0044] Step 7: The CPU determines whether the data integrity check is completed by timeout determination or active query. After the integrity check is completed, the CPU obtains the check result and can choose whether to read the L-Hash algorithm calculation result.

[0045] Figure 2This diagram illustrates the overall architecture of a dedicated AHB bus DMA within an embedded system bus hardware security monitoring device. Based on functional requirements, the dedicated DMA in this invention comprises four data channels, four FIFO data buffers, four multiplexers, an arbiter, and two bus interfaces. Each multiplexer can receive transfer requests from up to four peripheral devices, such as signals req0-req3, and simultaneously select a peripheral device as the transfer target for the corresponding data channel. The select outputs of the four multiplexers are connected to the arbiter. When one or more data channels issue a transfer request, the arbiter round-robinly arbitrates the requesting channels according to a preset priority algorithm. It then determines the order of transmission for the two AHB master ports based on the burst size. Software priority has four levels of priority, while hardware priority is determined by the data stream channel number, with lower numbers receiving higher priority. When transferring data between source and destination, the data stream is first stored in the DMA's internal FIFO, also known as the data buffer. Each of the four FIFOs is connected to the memory port and the peripheral port, allowing data flow exchange between the memory and the peripheral device through any path. When a peripheral generates a DMA transfer task, it sends a transfer request to the DMA controller in the AHB bus monitor and configures the relevant registers in the controller. The arbiter in the dedicated DMA will receive the register information and arbitrate the peripheral request according to the channel priority. If the dedicated DMA responds to the request, the DMA controller will send a handshake confirmation signal to the corresponding peripheral and start data transmission according to the transfer configuration. The channel transfers the data corresponding to the peripheral address to the FIFO. After reaching the FIFO threshold limit, the memory port transfers the FIFO data to the corresponding address of the memory target, completing a data transfer. The peripheral request signal is released and the DMA controller confirmation signal becomes invalid immediately.

[0046] The main features of the dedicated DMA in the present invention include the following:

[0047] 1. The dedicated DMA adopts a dual AHB master bus structure and is designed with two AHB bus master ports, one for memory access and the other for peripheral access; the register configuration interface only supports 32-bit programming; it supports 4 independent channels, each of which can respond to 4 peripheral requests, allowing up to 16 peripherals to initiate transfer requests simultaneously; because data transfer requires a cache FIFO, 4 independent FIFO buffers are set up corresponding to the 4 independent channels, each channel has an independent four-word deep FIFO buffer, which can be used in FIFO mode or direct mode; the transmission information of each channel can be configured independently, supporting memory to peripheral, peripheral to memory, and memory to memory transfers; in order to improve system efficiency and flexibility, it is also necessary to design an arbitration module for channel priority control, and a large number of channel configuration registers are designed as internal registers to indicate data transmission information.

[0048] 2. The priority of the dedicated DMA channel supports software configuration and is divided into four levels: very high, high, medium, and low. If the software-configured priorities are the same, the priority is determined by hardware, and the low channel has a higher priority. The number of data items to be transmitted on the channel is determined by the DMA controller or peripheral. If the DMA controller is used as the data flow controller, the number of transmitted data items is configured by software, up to 0xFFFF. If the peripheral is used as the data flow controller, the number of transmitted data items is uncertain, and the channel transmission is terminated by sending a transmission end signal through the peripheral. It supports incremental and non-incremental addressing of memory or peripheral addresses. It supports incremental burst transmission of single, 4, 8, and 16 beats, and the burst size is configured by software. It has five error interrupt flags (FIFO error, half transmission, transmission completion, transmission error, direct mode error, etc.), and performs logical OR operation on all error interrupts to generate interrupt signals for each channel.

[0049] DMA is mounted on the AHB system bus as a slave device and completes data transmission and caching by configuring multiple data channels. The DMA controller is located inside the AHB bus monitor and accurately transfers the monitored data through control logic and register configuration. The dedicated DMA mounted on the AHB bus has the following design indicators to match the transmission characteristics of the AHB bus:

[0050] 1. The AHB_Master interface and AHB_Slave interface are designed. The DMA needs to act as an AHB slave device when communicating with the CPU, and act as a master device when transferring data between the L-HASH algorithm module and SRAM.

[0051] 2. Because the burst data width of the AHB-Lite bus protocol in the E906 processor is 32 bits, and the input message width of the L-Hash256 algorithm module is also 32 bits, the internal FIFO cache of the DMA needs to support 32 bits of dedicated DMA space.

[0052] 3. In order to flexibly meet the incremental, wraparound and other transmission modes in the AHB bus protocol, at least four data transmission channels need to be designed internally.

[0053] 4. Since the burst transfer operation of the AHB protocol cannot cross the 1KB boundary, the minimum address space of the slave in the AHB-based embedded system is 1KB. Therefore, in order to avoid incorrect access to other slave device spaces and cause system errors, the burst transfer is limited to 1KB. Therefore, according to this design, the DMA module supports a maximum of 1KB of data per transfer.

[0054] 5. Supports three data bit widths: byte, half word, and word at the transmitter / receiver. Supports multiple burst transmission modes: SINGLE, INCR, WRAP4, and INCR4 at the transmitter / receiver.

[0055] 6. Use asynchronous clock control in DMA data register and status register.

[0056] 7. The data transmission bit width and Burst transmission mode of the sender and receiver can be configured separately.

[0057] The present invention is deployed in Figure 5 The specific steps for completing the transfer of dedicated DMA on the system-level platform of the AHB bus hardware security monitoring device are as follows:

[0058] In step 1, the E906 embedded processor first controls the DMA controller through the CPU write port. When the interface control logic between the L-Hash algorithm module and the AHB bus has data input requirements for summary calculation, the algorithm module will send a data transfer request signal to the DMA controller as a slave device. The processor interrupts the running program and then executes several IO instructions to detect the status of the memory, bus, and DMA. After the DMA receives the transfer request signal for the data to be monitored, the CPU will enable the DMA at this time, configure the DMA controller by enabling the transfer, and write the data address to be monitored, the source address and destination address, and the number of bytes to be transferred to the DMA controller.

[0059] In step 2, before the AHB_Slave interface initiates DMA data transfers, the embedded system's CPU addresses the various register groups in the DMA engine based on the address bus information. It then configures the DMA engine's register information using the data bus information. Because DMA and the L-Hash algorithm require different clocks for control, an asynchronous clock synchronous reset design approach is employed. A synchronous reset module is designed to enable cross-clock domain signaling of data transfer request signals. This module's primary function is to synchronize register information generated during the CPU configuration process after DMA transfers are initiated. This includes the DMA control module's enable signal, DMA_Start, and interrupt signals that the DMA engine needs to send to the CPU.

[0060] Step three: When DMA starts to move data, DMA sends a read / write request to AHB. After receiving the read / write request, the bus authorizes DMA to access the bus read / write port to obtain the corresponding data and address information. The data to be monitored read from the sending end can be cached in FIFO. When the data output request signal of the receiving end is pulled high, the FIFO cache will then control the state of the DMA state machine to select the message or summary to be moved to the receiving end to complete the data transmission.

[0061] Step 4: After the transfer is complete, the DMA controller sends another interrupt request to the CPU. Finally, after the current instruction is executed, the processor responds to the interrupt request sent by the DMA, verifies the integrity of the transferred data through the data comparison module and the L-Hash algorithm module, and then enables the bus to cancel the DMA's authorized access.

[0062] The hardware implementation of the L-HASH256 algorithm mainly includes two parts: the algorithm control state machine and the data channel module. The control logic circuit controls the input and output data. The data channel module mainly consists of a data cache module, a multiplexer, a buffer register group, and two stages in the sponge structure: the absorption stage and the compression stage. The hardware implementation structure diagram is shown in the figure below. Figure 3 As shown. Since the AHB bus uses 32-bit burst transmission (Burst) as the transmission unit and is also the unit for data monitoring, the 32-bit wide data block of the AHB system bus is used as the message input of the L-HASH256 algorithm. In the data cache module, the data received by the algorithm module is merged and converted, stored in the FIFO inside the data cache module, and then transmitted to the initialization register through the FIFO multiplexer with a basic operation bit width of 32 bits. These register arrays mainly serve as buffers for the input and output of the cache algorithm module. After the summary calculation is completed, the FIFO can also store the hash value generated at the current moment. The specific implementation steps are as follows:

[0063] In step 1, the algorithm control module enters the IDLE state after completing initialization, and then samples the rising edge of the clock to wait for the flag signal Ready to receive input data to be pulled high. When Ready is pulled high to 1, it means that the module is ready to write input messages to the dedicated DMA FIFO.

[0064] Step 2: In the write state, input data is accepted and when the write enable signal Start=1, data is started to be written from the dedicated DMAFIFO. When a group of data blocks are completely received and the L-Hash signature authentication calculation is started, the Start enable signal is set to 0.

[0065] Step 3: The hash function summary calculation process based on the sponge structure can be specifically divided into two stages: the absorption stage when the message is input, and the compression stage when the summary is output. In the absorption stage, the input message first needs to be padded and divided into blocks. The blocks are padded into 256-bit data blocks according to the message length. Because the L-HASH256 function structure is used, the input message length is 256 bits. After the input, the message is quickly subjected to multiple rounds of exclusive OR (XOR) operations. The XOR calculation result will be used as the new round of compression function T 256The input of () is permuted until all padded and grouped message blocks are completely absorbed. The compression function T used by L-Hash256 256 (), considering that the Burst transmission of AHB bus is transmitted in 32-bit data blocks, the input message of L-Hash256 uses the 32-bit data stream provided by the three signals HRDATA[31:0], HWDATA[31:0] and HADDR[31:0] of the AHB bus read and write interface, and there is no need to fill the message block. The internal permutation length b = 256, the message packet length r is 32 bits, and the part c that will not be XORed with the input message block during the round-robin transformation is 224 bits. The output of each round of transformation takes the most significant 16 bits of the internal permutation output, and the left and right inputs and outputs are 128 bits each. The entire permutation module uses 8 compression functions T 256 ().

[0066] Step 4: During the compression phase of the sponge structure, the compression function T 256 () will take the output of the last round of XOR calculation results in the absorption phase as input, and then extract sub-digests from the output results of each compression function respectively, and splice each sub-digest to achieve the required output length digest.

[0067] Step 5: After the digest calculation is completed, the system enters the read state. When the Hash_valid signal is pulled high, it indicates that the L-Hash tag value has been calculated and the state returns to IDLE.

[0068] This embodiment deploys the embedded system bus hardware security monitoring device and monitoring method of the present invention to the open source Smart_Run SoC platform of the Pingtou Ge Xuantie E906 processor, and is specifically applied to the system bus in the SoC. The system bus uses the AHB bus protocol and is responsible for the information interaction between the CPU inside the SoC and other slave devices. The CPU controls the operation of the system as the only master device in the system. After the bus hardware security monitoring device is deployed, the dedicated DMA and bus monitor are directly mounted on the AHB system bus. The two modules together constitute the AHB bus hardware security monitoring device, and the monitoring object is the instruction data transmitted between the CPU and the SRAM as a slave device through the system bus. The E906 CPU adopts the Harvard structure to store instructions and data separately. The SoC structure diagram after the bus hardware security monitoring device is deployed is as follows: Figure 5 shown.

[0069] Figure 4This is the overall architecture of a bus monitor within an embedded system bus hardware security monitoring device. The bus monitor primarily consists of an AHB slave interface module, decoder module, multiplexer module, register access interface module, memory, monitoring timeout module, data capture module, DMA control module, and L-HASH algorithm module. Together, they perform tasks such as bus access analysis, data capture, preprocessing, digest calculation, and integrity comparison. The memory access interface module and RAM management unit primarily provide direct bus access to memory. When the bus monitor is operating, memory data transfer is controlled by the DMA controller and is not utilized by these two modules.

[0070] Other specific implementation steps are as follows:

[0071] Step 1: The AHB slave interface is responsible for receiving AHB bus data, address, and various control signals, such as HWDATA, HADDR, HSEL, etc. This interface module indicates that the AHB bus monitor is mounted on the AHB bus as a slave.

[0072] Step 2: After receiving the AHB bus transmission information, the decoder generates different chip select signals according to the access address and other information, thereby selecting the corresponding register group through the signal and configuring the register information; after decoding the access object, the user register in the bus monitor is configured through the register access interface, such as Figure 4 As indicated by arrow ①;.

[0073] Step 3: The bus monitor starts after monitoring the bus transmission and samples the data blocks and address information transmitted on the bus in real time. Because the AHB bus transmits information jointly by the data phase and the address phase, the data on the address bus and the data bus are both sampling objects of the bus monitor. The data capture module can filter the corresponding bus transmission sequence, and left-align the data and address transmitted by the bus and cut them into the input format of the algorithm module. The bus input signal of this module is the same as the input of the monitoring timeout module. At the same time, the data capture module will also configure the user register information according to the capture process, such as Figure 4 As shown by arrow ②, the data capture module outputs the pre-processed data to the dedicated DMA data cache according to the DMA controller's call, such as Figure 4 As indicated by arrow ③.

[0074] Step 4: When the bus monitor is monitoring, the DMA control module can transfer the data cut by the data capture module to the on-chip memory in real time, such as Figure 4 As shown by arrow ④, the data on the on-chip memory is pre-processed by the integrity verification algorithm such as filling and blocking, and then it is transmitted in a 32-bit wide data format from the on-chip memory to the L-HASH algorithm module in order according to the address information for label calculation, as shown in FIG. Figure 4 As shown by arrows ⑤ and ⑥, after L-HASH completes the calculation of the digest value of a 32-bit data block, it requests bus authorization again through the configuration register, and the user register outputs the information through the register access interface, such as Figure 4 As shown by arrows ⑧ and ⑨, after authorization, the same transport process is restarted, such as Figure 4 As shown by arrow ⑦, after the entire data sequence stored in the on-chip memory is completely transferred, the DMA control module sends an interrupt request to the CPU, ends the bus access authorization and stops transferring data.

[0075] In step five, the L-HASH calculation module is first parameterized according to the contents of the register, and three different modes of integrity verification algorithms are selected. They are divided into L-HASH96, L-HASH128, and L-HASH256 according to the number of round transformations of the compression function. The main function of its submodule L-HASH-CTRL is to use the dedicated DMA controller to interact with the dedicated direct memory access controller to complete the integrity verification calculation of the plaintext data in the plaintext register. After the ciphertext calculation is completed, the calculation result is cached in the output cache and then handed over to the dedicated DMA to be transferred to the off-chip memory. The L-HASH algorithm is a one-way encryption algorithm with strong uniqueness and irreversibility. When the bit value of any data bit is tampered with, a completely different summary tag will be generated.

[0076] Step 6: The summary value calculated by the L-HASH algorithm module is transferred to the comparison module through the DMA controller for comparison with the summary value calculated and stored before bus transmission. If the comparison fails, an alarm is issued.

[0077] Combine Figure 5After deploying the bus hardware security monitoring device, the E906 Smart_run SoC was used to build a system-level test and execution platform based on the embedded system bus hardware security monitoring device. In this SoC system, the E906 CPU serves as the master device, controlling the entire chip's operation. The CPU is surrounded by several subsystem devices, such as the instruction cache and data cache, which store the instructions and data required for CPU operations. The CPU's only external interface is the AHB system bus, which connects to peripherals such as the APB bus control flash memory and directly controls slave devices such as SRAM, DMA, and the AHB bus monitor. A dedicated DMA, acting as both a CPU slave and a SoC master, is mounted on the AHB system bus and connected to the DMA controller within the AHB bus monitor via a separate channel. SRAM and flash memory serve as slave devices, with instruction data stored in the SRAM. The dedicated DMA transfers AHB bus data to be monitored to the bus monitor. The AHB bus monitor has both an AHB host interface and a slave interface. The host interface connects to the dedicated DMA, while the slave interface provides the monitor with a system bus connection. The specific steps for implementing the system-level platform test and execution are as follows:

[0078] Step 1: Load the E906 CPU executable binary file into the off-chip Flash memory before the system is powered on. After the system is powered on, the CPU reads the executable code and starts controlling the SoC operation.

[0079] Step 2: The bus monitor is waiting for the monitoring signal input. When the interface control logic between the L-Hash algorithm module and the AHB bus has a signature-calculated data input requirement, the algorithm module will send a data transfer request signal to the DMA controller as a slave device.

[0080] Step 3: After the DMA receives the transfer request signal for the data being monitored, the CPU suspends the currently executing task and sends a bus access authorization signal to the dedicated DMA control module, enabling the DMA and configuring the DMA controller by enabling the transfer. A wait timeout counter is also set at this point. If the wait time exceeds the counter value, the wait timeout flag is raised. When the flag is raised, a time_out_warning wait timeout warning signal is immediately fed back to the CPU, informing the embedded system that the data to be signed and authenticated is lost or that the dedicated DMA bus access authorization is abnormal.

[0081] Step 4: DMA sends a read / write request to the AHB system bus. After receiving the read / write request, the bus authorizes DMA to perform the read / write operation. Then, DMA starts data transmission and moves the instruction data block stored in SRAM to the internal cache FIFO of the L-HASH algorithm module.

[0082] In step 5, the DMA controller selects one of the master and slave devices on the AHB bus as a monitoring device based on the DMA configuration, monitors the bus behavior of the monitored data, and counts bus access operations.

[0083] Step 6: After receiving the address and data information transferred by DMA, the L-HASH algorithm module starts to calculate the summary of the monitored data and count the bus access operations of the monitored device.

[0084] Step 7: After the L-HASH algorithm module completes the digest calculation, the DMA transfers the calculation result to the calculation comparison module and compares it with the pre-stored standard digest value. If the comparison is unsuccessful, an alarm is issued to complete the data integrity check.

[0085] Step 8: After the dedicated DMA transfer is complete, the L-HASH algorithm module is checked for readiness. l_hash_done is the algorithm ready signal, active low. The start_read flag is pulled high to begin inputting the already filled message blocks into the algorithm buffer FIFO. When all monitored data has been transferred and verified, the DMA controller sends a transfer completion signal to the CPU, causing the CPU to generate an interrupt.

Claims

1. A hardware security monitoring device based on an embedded system bus. This device is mounted on the bus and performs L-HASH security digest calculation and dedicated DMA to replace the CPU to move data. It is characterized by: The bus monitor consists of a bus slave interface module, a decoder module, a monitoring timeout module, a data capture module, an L-HASH algorithm calculation module, and a dedicated DMA. The bus slave interface module is connected to the bus, identifies the bus monitor as a slave device, and receives signals from the master device; The decoder module is connected to the bus slave interface module and is responsible for generating chip select signals according to different access addresses to configure different register groups; The data capture module is also directly connected to the bus, sampling the data blocks and address information transmitted on the bus, and pre-processing the information into calculation format and outputting it to the dedicated DMA; The L-HASH algorithm calculation module is responsible for performing summary calculations on monitoring information and is interconnected with the dedicated DMA; The monitoring timeout module is also connected to the bus and transmits signals. It is responsible for calculating the bus access delay, and the timeout interrupt signal output is connected to the CPU. The dedicated DMA receives the pre-processed data sampled by the data capture module and the configuration information of the user register. It is also interconnected with the on-chip memory and the input and output of the L-HASH algorithm calculation module, and is responsible for transporting data.

2. The embedded system bus hardware security monitoring device according to claim 1, characterized in that: The dedicated DMA includes a bus host interface module, a DMA control module, a data channel and cache FIFO module, a response synchronization module and an interrupt control module; among them, the bus host interface is directly connected to the bus and is used for data movement of the dedicated DMA; the DMA control module includes various control logics and register groups to control the dedicated DMA to move data; the data channel and cache FIFO module, the data moved by the dedicated DMA is cached in the FIFO, and the data is output after an output request. The data channel includes a write port and a read port, which are used to write and read data respectively. The number of data channels in the DMA is configured according to the bus transmission characteristics, and it contains at least one data channel; the response synchronization module is responsible for synchronizing the signals of other clock domains input to the dedicated DMA to the DMA clock domain; the interrupt control module is responsible for information exchange with the CPU, receiving the empty signal of the data channel, and outputting the CPU interrupt request.

3. The embedded system bus hardware security monitoring device according to claim 1 or 2, characterized in that: The dedicated DMA also includes four data channels, four FIFO data buffers, four multiplexers, an arbiter, and two bus interface parts; each multiplexer receives up to four peripheral transfer requests and selects one peripheral as the transfer object of the corresponding data channel; the selection outputs of the four multiplexers are connected to the arbiter. When one or more data channels issue a transfer request, the arbiter will poll the transfer channel for arbitration authorization according to the preset priority algorithm, and determine the transmission order for the two AHB master ports according to the burst transfer size; the four FIFO data buffers are connected to the memory port and the peripheral port, and any channel can complete the transfer between the memory and the peripheral. Data flow interaction; when a peripheral generates a DMA transfer task, it will send a transfer request to the DMA controller in the AHB bus monitor and configure the relevant registers in the controller. The arbiter in the dedicated DMA will receive the register information and arbitrate the peripheral request according to the channel priority. If the dedicated DMA responds to the request, the DMA controller will send a handshake confirmation signal to the corresponding peripheral and start data transmission according to the transfer configuration. The channel transfers the data corresponding to the peripheral address to the FIFO. After reaching the FIFO threshold limit, the memory port transfers the FIFO data to the corresponding address of the memory target, completing a data transfer, the peripheral request signal is released, and the DMA controller confirmation signal is immediately invalid.

4. The embedded system bus hardware security monitoring device according to claim 1 or 2, characterized in that: When configuring the data channel of the dedicated DMA inside the bus monitoring device, each channel selects one of the master and slave devices on the AHB bus as a monitoring device based on the DMA configuration. When the selected monitoring device is the master device, the channel monitors all bus access operations initiated by the master device and selects the operations of interest for counting. The L-HASH algorithm calculation module performs a HASH calculation on the count value generated by the monitored bus operations and stores the generated calculation result in RAM as a comparison value. When the slave device on the bus initiates a bus access operation, the corresponding operation is selected for counting, including the changes in the address phase and data phase, and the calculation result is generated by the L-HASH algorithm calculation module. When the count value equals the comparison value, a channel trigger signal is generated.

5. The embedded system bus hardware security monitoring device according to claim 4, characterized in that: When the channel selects the monitoring master device, some connection signals between the master device and the AHB bus, including HADDR, HTRANS, and HWDATA, are sent to the access selection unit; When a slave device is selected for monitoring, some connection signals between the slave device and the AHB bus, including HADDR, HTRANS, and HWDATA, are sent to the L-HASH algorithm calculation module for integrity marking.

6. The embedded system bus hardware security monitoring device according to claim 1, characterized in that: The data capture module uses the signal HADDR to determine whether the device is within the set address range; uses the signal HWDATA to determine whether the read and write operations conform to the set values; and uses the signal HTRANS to determine whether the device access is a single transfer or a continuous transfer. Accesses that meet all conditions are considered countable accesses to the device.

7. The embedded system bus hardware security monitoring device according to claim 1, characterized in that: The monitoring timeout module determines the access address range, number of times the address is accessed, and the time of access to the address of the monitored device based on the trigger signal generated by the channel. It outputs an interrupt signal to the DMA according to the configuration and inserts a breakpoint in the interrupt function executed by the user register unit to pause the system for online debugging.

8. The embedded system bus hardware security monitoring device according to claim 1, characterized in that: The data block with a specific bit width in the bus is used as the message input of the L-HASH algorithm. In the dedicated DMA module, the data received by the algorithm module is merged and converted, and then transferred to the initialization register through the FIFO multiplexer. These register arrays act as a buffer for the input and output of the cache algorithm module. After the summary calculation is completed, the dedicated DMA stores the HASH value generated at the current moment.

9. A monitoring method for implementing the embedded system bus hardware security monitoring device according to claim 1, comprising the following steps: Step 1: The embedded system CPU completes the initialization of the L-HASH algorithm calculation module, and the L-HASH algorithm calculation module is in a state of preparing to receive data; Step 2: The embedded system CPU configures the digest length into the internal register of the L-HASH calculation module; Step 3: Move the data to be signed and authenticated in SRAM to the L-HASH algorithm calculation module; The CPU determines whether the data movement is completed through interruption or active query; Step 4: The DMA controller selects one of the master and slave devices on the AHB bus as the monitoring device according to the DMA configuration; and selecting the bus operation of the monitored device to monitor, and counting the corresponding bus access operations; Step 5: During the DMA transfer process, the L-HASH algorithm calculation module starts L-HASH calculation when receiving the address phase, data phase, and bus access operation count value of the monitored device; Step 6: After the L-HASH algorithm calculation module completes the calculation, the DMA transfers the calculation result to the counting and comparison module for data integrity verification; Step 7: The CPU determines whether the data integrity check is completed through the timeout determination unit or active query. After the integrity check is completed, the CPU obtains the check result and chooses whether to read the L-HASH algorithm calculation result.

10. The monitoring method according to claim 9, characterized in that: The AHB bus transmit data integrity monitoring process is as follows: Step 1. AHB configures the user register through the user register interface; Step 2. The user register transmits the bus information conditions to be monitored to the data capture module; Step 3. DMA reads the data read by the data capture module and writes the data to SRAM; Step 4. The DMA controller writes the read data into the message register of L-HASH; Step 5. After each operation is completed, the L-HASH module returns a completion signal to the DMA controller, and then the above data flow is repeated between the DMA controller, SRAM, and L-HASH; Step 6. L-HASH transmits the calculation completion signal and message digest to the user register; Step 7. The AHB reads the message digest and status information through DMA to determine whether to send an interrupt enable signal to the processor.

Citation Information

Patent Citations

  • Bus monitor-based system chip bus priority dynamic configuration device

    CN102012881B

  • Bus monitoring module and monitoring method suitable for AHB protocol

    CN113190400A

Cited By

  • Chip and method for writing data into FLASH memory

    CN122284931A

  • An embedded multimedia memory card and a monitoring system and method for data transmission thereof

    CN122450727A