A method, device, equipment and storage medium for preventing chip from being cracked
By partitioning the program of development mode and security mode in the security chip, and using random timing interrupts and life cycle judgment, the problem of mode error switching caused by non-invasive attacks of the chip is solved, achieving a more efficient protection effect.
Patent Information
- Application Number
- CN202111202349.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-10-15
- Publication Date
- 2025-08-19
- Estimated Expiration
- 2041-10-15
AI Technical Summary
The existing security chips are easily attacked by "fault generation technology" of non-invasive attacks, resulting in error mode switching, and then cracking or tampering with the chip content.
Store the programs in development mode and security mode in different address intervals respectively, and use random timing interrupts and life cycle judgments to ensure that the program running address is within the correct interval, increase the number of judgments and unpredictability, and prevent wrong mode switching.
Effectively prevent the chip from being cracked by external attacks, reduce the probability of chip content being acquired or tampered with, improve protection capabilities, and increase cracking difficulty.
Smart Images

Figure CN114036512B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of information security technology, and in particular to a method, apparatus, device, and storage medium for preventing a chip from being cracked. Background Art
[0002] With the increasing popularity of security chips, a variety of cracking methods have emerged. These methods fall into two main categories: invasive attacks and non-invasive attacks. Invasive attacks require breaking the package and using sophisticated instruments. Non-invasive attacks do not physically damage the chip, but instead use external means, such as "fault generation techniques," which use voltage or clock surges to force the processor to perform incorrect operations, potentially affecting instruction decoding and execution. Furthermore, the equipment required for non-invasive attacks can often be homemade and upgraded, making them very inexpensive and low-cost. In some situations, non-invasive attacks can be particularly dangerous.
[0003] Current security chip mode switching methods typically utilize flags stored in the EFUSE module. This involves running the boot program, checking the flags at the beginning, and then jumping to the appropriate program for the desired mode. This method can be vulnerable to external attacks, leading to misjudgment and entry into the wrong mode, potentially cracking the chip and obtaining or tampering with its internal information.
[0004] Regarding the above-mentioned related technologies, the inventor believes that there is a defect in that the existing chips are easily cracked after a technical attack caused by an error, and the program returns from the security mode to the development mode, resulting in the chip content being obtained or tampered with. Summary of the Invention
[0005] In order to reduce the possibility of chip contents being obtained or tampered with, the present application provides a method, apparatus, device, and storage medium for preventing a chip from being cracked.
[0006] On the first aspect, the present application provides a method for preventing a chip from being cracked, which has the characteristic of reducing the possibility of the chip content being obtained or tampered with.
[0007] This application is achieved through the following technical solutions:
[0008] A method for preventing a chip from being cracked comprises the following steps:
[0009] The development mode program and the security mode program are stored in different address ranges;
[0010] During program execution, the current life cycle is randomly judged to obtain the current mode information of the chip and determine whether the address of the currently running program is within the address range corresponding to the current mode;
[0011] If the address of the currently running program is outside the address range corresponding to the current mode, the program will stop running.
[0012] For the existing solutions, since there is no clear boundary between the security mode program and the development mode program, and many common functions are used during operation, such as delay functions, printing functions, opening and closing functions of certain modules, etc., it is difficult to determine which mode the currently executed program is in. Once the chip is attacked and enters the wrong mode and runs the wrong program, the chip cannot self-detect the problem and handle it, which makes it easy to make mistakes. Then the chip enters the development mode from the security mode, and the chip content is obtained or tampered with. Therefore, this solution makes the development mode part of the program and the security mode part of the program store in different address ranges respectively, and during the program running process, randomly judges the current life cycle and program running address, and distinguishes the development mode program and the security mode program with clear address boundaries, which is conducive to accurately judging which mode the currently executed program is in, and when the chip is attacked, the chip can self-check to determine the current running mode. Whether the address of the running program conforms to the address range corresponding to the current mode, so as to more quickly discover that the chip has been attacked and take timely measures; during the running of the program, the current life cycle and program running address are randomly judged. Because the number of judgments is increased, the probability of the chip being successfully cracked is greatly reduced, and it can effectively prevent attackers from predicting and accurately attacking each judgment. When using the "fault generation technology" to attack the chip, it is not only necessary to bypass the general practice: judging the life cycle at the beginning of the program, but also to randomly attack and bypass the check operations of the life cycle and address range later, which greatly increases the difficulty of cracking; if the address of the currently running program is outside the address range corresponding to the current mode, the program is stopped to take measures to protect the program content entering the development mode in time, which can effectively prevent the chip content from being obtained or tampered with in a timely manner, prevent the chip from being cracked by external attacks, and improve the protection capability of the chip content.
[0013] In a preferred example, the present application can be further configured as follows: during program execution, the steps of randomly determining the current life cycle, obtaining the current mode information of the chip, and determining whether the address of the currently running program is within the address range corresponding to the current mode include:
[0014] Set a timer interrupt based on a true random number;
[0015] When the timing interrupt is generated, the current life cycle of the chip and the program running address are judged.
[0016] By adopting the above technical solution, a timer interrupt is set based on a true random number. When the timer interrupt occurs, the current life cycle of the chip is judged; if it is judged to be development mode, it is then judged whether the program running address at this time is in the ROM address range where the development mode program is located; if it is judged to be security mode, it is then judged whether the program running address at this time is in the ROM address range where the security mode program is located; if it is consistent with the ROM address range of the current mode program, the program continues to run; otherwise, the relevant data is cleared and the program stops running.
[0017] In a preferred example, the present application may be further configured as follows: when the timing interrupt is generated, the following steps are further included:
[0018] Generate a true random number again, and reset a new timer interrupt based on the new true random number to replace the original timer interrupt.
[0019] By adopting the above technical solution, a true random number is generated again at the same time as the timer interrupt is generated, and a new timer interrupt is reset based on the new true random number to replace the original timer interrupt, so as to achieve the purpose of judging the current life cycle and program running address by an unpredictable random timer interrupt.
[0020] In a preferred example, the present application can be further configured as follows: the program of the development mode part and the program of the security mode part are stored in a ROM area inside the chip.
[0021] By adopting the above technical solution, the development mode program and the security mode program are stored in the ROM area inside the chip, that is, the development mode program and the security mode program are stored in different ROM address ranges respectively.
[0022] In a preferred example, the present application can be further configured as follows: the life cycle is stored in the EFUSE module inside the chip in the form of a life cycle identification bit, and the life cycle identification bit is used to indicate that the chip is in development mode or security mode.
[0023] By adopting the above technical solution, the life cycle is stored in the EFUSE module inside the chip in the form of a life cycle identification bit to indicate whether the chip is in development mode or security mode. The EFUSE module is OTP (One Time Programmable) and is burned after the chip is produced. After burning, it cannot be changed or cleared again, ensuring the security of the life cycle information.
[0024] In a preferred example, the present application can be further configured to include the following steps:
[0025] Preset sensitive operations;
[0026] Before executing sensitive operations, the subroutine must determine the current life cycle, obtain the current mode of the chip, and determine whether the address of the currently running program is within the address range corresponding to the current mode.
[0027] If the address of the currently running program is outside the address range corresponding to the current mode, the program will stop running.
[0028] By adopting the above technical solution, sensitive operations are preset, and before the program executes the sensitive operations, the current life cycle of the chip and the address corresponding to the program operation are fixedly checked again, ensuring that the life cycle and program operation address are rechecked before each execution of the sensitive area of the program. This is beneficial to improving the protection capability of the chip. When the attacker performs sensitive operations on the chip, the chip can conduct self-inspection in time, and then use the "fault generation technology" to attack the chip. It is necessary not only to bypass the general practice: judging the life cycle at the beginning of the program, but also to perform precise attack bypass on the life cycle and address range check operations before executing sensitive operations later. This is beneficial to quickly obtain the warning information that the program erroneously enters the development mode from the safe mode, so as to discover the chip being attacked more quickly and take timely measures, further increasing the difficulty of cracking the chip.
[0029] In a preferred example, the present application may be further configured as follows: the sensitive operations include operations that may threaten chip security.
[0030] By adopting the above technical solution, the sensitive operations of the program can be any operations that may threaten the security of the chip, so as to cover more sensitive operations of the program. Before the program executes sensitive operations, timely detection can be performed, which provides more comprehensive protection for the chip and further increases the difficulty of cracking the chip.
[0031] On the second aspect, the present application provides a device for preventing a chip from being cracked, which has the characteristic of reducing the possibility of the chip content being obtained or tampered with.
[0032] This application is achieved through the following technical solutions:
[0033] A device for preventing a chip from being cracked, comprising:
[0034] A preset module is used to store the development mode program and the security mode program in different address ranges;
[0035] The second judgment module is used to randomly judge the current life cycle during the program running process, obtain the current mode information of the chip, and judge whether the address of the currently running program is within the address range corresponding to the current mode;
[0036] The execution module is used to stop the program from running when the address of the currently running program is outside the address range corresponding to the current mode.
[0037] On the third aspect, the present application provides a computer device that has the characteristic of reducing the acquisition or tampering of chip contents.
[0038] This application is achieved through the following technical solutions:
[0039] A computer device includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the steps of the above-mentioned method for preventing a chip from being cracked are implemented.
[0040] Fourthly, the present application provides a computer-readable storage medium that reduces the possibility of chip contents being obtained or tampered with.
[0041] This application is achieved through the following technical solutions:
[0042] A computer-readable storage medium stores a computer program, which, when executed by a processor, implements the steps of the above-mentioned method for preventing a chip from being cracked.
[0043] In summary, this application includes at least one of the following beneficial technical effects:
[0044] 1. A method for preventing chip cracking by storing development mode programs and security mode programs in different address ranges. This method uses clear address boundaries to distinguish development mode programs from security mode programs. This helps accurately determine which mode the currently executed program is in and quickly receives warning messages when a program mistakenly enters development mode from security mode. This allows for faster detection of chip attacks and timely implementation of measures. This method greatly increases the difficulty of cracking, reduces the possibility of chip content being obtained or tampered with, and prevents the chip from being cracked by external attacks.
[0045] 2. Set a timer interrupt based on a true random number, and use the timer interrupt to judge the current life cycle of the chip and the program running address to increase the number of judgments, greatly reducing the probability of successful chip cracking. At the same time, when the timer interrupt is generated, a new true random number is generated again, and a new timer interrupt is reset based on the new true random number to achieve unpredictable random timer interrupts. This can effectively prevent attackers from predicting and accurately attacking each judgment, greatly increasing the difficulty of cracking.
[0046] 3. Before each sensitive operation is performed, the chip's current life cycle and program execution address will be rechecked, which helps improve the chip's protection capabilities. When an attacker performs sensitive operations on the chip, the chip can self-check in time to detect the attack more quickly and take timely measures, further increasing the difficulty of cracking the chip.
[0047] 4. The sensitive operations of the program can be any operations that may threaten the security of the chip, so as to cover more sensitive operations of the program. Before the program executes sensitive operations, timely detection can be performed, which provides more comprehensive protection for the chip and further increases the difficulty of cracking the chip. BRIEF DESCRIPTION OF THE DRAWINGS
[0048] Figure 1 This is an overall flow chart of a method for preventing a chip from being cracked according to one embodiment of the present application.
[0049] Figure 2 It is a flowchart of the steps for randomly judging the current life cycle and program running address.
[0050] Figure 3 This is a structural block diagram of a device for preventing a chip from being cracked according to one embodiment of the present application. DETAILED DESCRIPTION
[0051] This specific embodiment is merely an explanation of the present application and is not a limitation of the present application. After reading this specification, those skilled in the art may make non-creative modifications to the present embodiment as needed, but as long as they are within the scope of the claims of the present application, they are protected by the patent law.
[0052] To make the purpose, technical solutions, and advantages of the embodiments of this application more clear, the technical solutions in the embodiments of this application will be clearly and completely described below in conjunction with the drawings in the embodiments of this application. Obviously, the described embodiments are part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.
[0053] In this document, the term "and / or" simply describes a relationship between related objects, indicating that three possible relationships exist. For example, "A and / or B" can represent: A exists alone, A and B exist simultaneously, or B exists alone. Furthermore, the character " / " in this document, unless otherwise specified, generally indicates an "or" relationship between the related objects.
[0054] Currently, security chips generally have at least two modes: development mode and secure mode. In development mode, security identifiers such as keys and unique IDs are not yet burned into the security chip. The test interface can be opened freely, and the application is in plain text, requiring no decryption at runtime. In secure mode, security identifiers such as keys, unique IDs, and lifecycle are burned into the security chip. The test interface is closed, and the application is in ciphertext, requiring decryption at runtime. Development mode is used by chip application manufacturers to debug programs and burn keys. Once the program is debugged and stabilized and finally released as a product, the lifecycle is also burned into secure mode during program burning on the mass production line.
[0055] With existing solutions, there is no clear boundary between safe mode programs and development mode programs, and many common functions are used during runtime, such as delay functions, printing functions, and functions for opening and closing certain modules, making it difficult to determine which mode the currently executing program is in.
[0056] The non-invasive attack "fault generation technology" can easily cause the security chip to return from security mode to development mode in the following two places, obtain or tamper with the chip content, and thus crack the chip.
[0057] 1. When the boot program executes the statement that determines the life cycle, the "fault generation technology" is used to cause the chip to fail, so that the program runs into the development mode branch;
[0058] 2. When the boot program executes a jump instruction, use the "fault generation technology" to cause the chip to fail, so that the program jumps to the development mode branch.
[0059] Therefore, this application proposes a method for preventing a chip from being cracked, so as to effectively protect the chip from being cracked by "fault generation technology".
[0060] The embodiments of the present application are described in further detail below with reference to the accompanying drawings.
[0061] Reference Figure 1 , an embodiment of the present application provides a method for preventing a chip from being cracked, and the main steps of the method are described as follows.
[0062] S1: Store the development mode program and the security mode program in different address ranges.
[0063] S31: During program execution, the current life cycle is randomly determined to obtain the current mode information of the chip, and to determine whether the address of the currently running program is within the address range corresponding to the current mode;
[0064] S4: If the address of the currently running program is outside the address range corresponding to the current mode, the program is stopped.
[0065] Specifically, the development mode program and the security mode program are stored in the ROM area within the chip. Because the Boot program splits into two branches during execution, the development mode branch and the security mode branch, S1: The development mode program and the security mode program are stored in different address ranges. That is, the two branches are stored in different ROM address ranges. Furthermore, the programs in the two branches are compiled into different runtime ranges. This intentionally keeps the programs used in security mode and development mode completely independent, each occupying an independent address space. This facilitates accurate determination of which mode the currently executing program is in. If the chip is attacked, the chip can self-check to determine whether the address of the currently running program matches the address range corresponding to the current mode, allowing for faster detection and timely action. For example, the development mode branch program is compiled in the range 0x70001000 to 0x70001fff; the security mode branch program is compiled in the range 0x70002000 to 0x70002fff.
[0066] Next, the chip is powered on and the Boot program is run.
[0067] S2: Before the program starts, determine the life cycle and select the corresponding mode of program operation.
[0068] Specifically, when the program starts running, it will first determine the life cycle and select the corresponding mode of program running.
[0069] The lifecycle is stored in the chip's internal EFUSE module as a lifecycle identifier. This identifier indicates whether the chip is in development mode or secure mode. This lifecycle information is stored in the EFUSE module, ensuring that it remains intact during power outages and cannot be modified once fixed, ensuring the security of the lifecycle information.
[0070] In this embodiment, the length of the life cycle is one byte. When the life cycle is 0x5a, the mode corresponding to the program is the development mode, and other values are the security mode.
[0071] When it is determined to be development mode, the PC pointer jumps to the development mode program to run; when it is determined to be safe mode, the PC pointer jumps to the safe mode program to run.
[0072] The address pointed to by the PC pointer is the address where the current program is running. Before executing sensitive operations, the life cycle and program running address are checked. The program running address at this time can be obtained from the PC pointer.
[0073] The address pointed to by the return pointer is the address where the current program is interrupted, that is, the life cycle and program running address are checked in the timer interrupt, and the program running address at this time can be obtained from the return pointer.
[0074] S31: During program execution, the current life cycle is randomly judged to obtain the current mode information of the chip, and to determine whether the address of the currently running program is within the address range corresponding to the current mode.
[0075] Reference Figure 2 , wherein, during the program running process, the steps of randomly judging the current life cycle, obtaining the current mode information of the chip, and judging whether the address of the currently running program is in the current mode include:
[0076] S311: Setting a timer interrupt based on a true random number;
[0077] S312: When a timer interrupt is generated, the current life cycle of the chip and the program running address are judged;
[0078] S313: At the same time, when the timer interrupt is generated, a true random number is generated again, and a new timer interrupt is reset based on the new true random number to replace the original timer interrupt.
[0079] Specifically, the interrupt handling function is used to re-judge the program's life cycle. If the program is judged to be in development mode, the program's running address is then determined to be within the ROM address range of the development mode program. If the program is judged to be in safe mode, the program's running address is then determined to be within the ROM address range of the safe mode program to determine whether the program's running address is within the ROM address range of the current mode program. This allows the program's current life cycle and program running address to be judged using unpredictable, random, and timed interrupts.
[0080] In this embodiment, when the life cycle is judged to be development mode, the program running address is read to determine whether the running address at this time is within the range of 0x70001000 to 0x70001fff; when the life cycle is judged to be security mode, the program running address is read to determine whether the running address at this time is within the range of 0x70002000 to 0x70002fff.
[0081] Therefore, each time the life cycle is checked, the program running address is also checked. By judging whether the life cycle and the program running address match, it is determined whether the current Boot program running mode is legal.
[0082] S4: If the address of the currently running program is outside the address range corresponding to the current mode, the program stops running; otherwise, the program runs normally.
[0083] Specifically, when the obtained program running address is outside the address range of the corresponding mode, the program is stopped; when the obtained program running address is within the address range of the corresponding mode, the program is run normally.
[0084] For example, if the running address of a program in development mode is outside the range of 0x70001000 to 0x70001fff, the intermediate data of some operations will be cleared and the program will stop running; if the running address of a program in safe mode is outside the range of 0x70002000 to 0x70002fff, the data will be cleared and the program will stop running.
[0085] When the running address of the program in development mode is within the range of 0x70001000 to 0x70001fff or the running address of the program in safe mode is within the range of 0x70002000 to 0x70002fff, the interrupt processing is completed, and the program returns to the address corresponding to the running interrupt to continue execution.
[0086] Furthermore, a method for preventing a chip from being cracked further includes the following steps:
[0087] S321: Preset sensitive operations;
[0088] S322: Before executing the preset sensitive operation, the subroutine that performs the sensitive operation judges the current life cycle, obtains the current mode information of the chip, and judges whether the address of the currently running program is within the address range corresponding to the current mode.
[0089] The preset sensitive operations include operations that may threaten chip security. In this embodiment, sensitive operations may include operations such as opening a test interface and reading an internal key. Sensitive operations may be any operations that may threaten chip security, covering more program-sensitive operations.
[0090] Before executing sensitive operations, the subroutine that performs sensitive operations will judge the current life cycle, obtain the current mode information of the chip, and determine whether the address of the currently running program is within the address range corresponding to the current mode; thus, timely detection can be performed before executing sensitive operations, which provides more comprehensive protection for the chip and further increases the difficulty of cracking the chip.
[0091] If the address of the currently running program is outside the address range corresponding to the current mode, the program will be stopped; in this way, timely defensive measures can be taken when the chip is attacked, further increasing the difficulty of cracking the chip.
[0092] If the address of the currently running program is within the address range corresponding to the current mode, the program will return to the address corresponding to the interruption to continue execution.
[0093] Existing chip defense methods only check the life cycle at the beginning of the program. Once an external attack bypasses this check, the chip will be easily cracked. In addition, the life cycle of existing chips is not deliberately segmented into independent address spaces, making it impossible to determine which mode the currently running program is in. Once the security chip is attacked by an external attack and returns to development mode, there is a great deal of freedom in chip operation in development mode, and important information inside the chip, such as keys and identity identifiers, can be obtained.
[0094] This application not only judges the life cycle at the beginning, but also checks the life cycle and program running address at any time during program running. It even rechecks the life cycle and program running address before executing sensitive areas of the program.
[0095] This is equivalent to using the "fault generation technology" attack, which not only needs to bypass the program's initial judgment of the life cycle, but also needs to perform precise attack bypasses on all subsequent checks on the life cycle and program running address. This greatly increases the difficulty of cracking the chip, preventing the security chip from being attacked from the outside and returning from the security mode to the development mode, so that the chip content can be obtained or tampered with. In order to detect the attack as soon as possible and take timely measures to protect the chip content, reduce the situation of the chip content being obtained or tampered with, and prevent the chip from being cracked by external attacks, thereby achieving the purpose of protection.
[0096] At the same time, the present application is simple to implement, and does not require additional hardware costs for the chip or the cost of peripheral devices.
[0097] It should be understood that the size of the serial numbers of the steps in the above embodiments does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.
[0098] Reference Figure 3 The present application also provides a device for preventing a chip from being cracked. The device for preventing a chip from being cracked corresponds one-to-one with the method for preventing a chip from being cracked in the above embodiment. The device for preventing a chip from being cracked includes:
[0099] A preset module is used to store the development mode program and the security mode program in different address ranges;
[0100] The first judgment module is used to judge the life cycle before the program starts and select the program running in the corresponding mode;
[0101] The second judgment module is used to randomly judge the current life cycle during the program running process, obtain the current mode information of the chip, and judge whether the address of the currently running program is within the address range corresponding to the current mode;
[0102] The third judgment module is used for the subroutine that performs sensitive operations to judge the current life cycle before performing sensitive operations, obtain the current mode information of the chip, and determine whether the address of the currently running program is within the address range corresponding to the current mode;
[0103] The execution module is used to stop the program from running when the address of the currently running program is outside the address range corresponding to the current mode.
[0104] Furthermore, the second judgment module includes:
[0105] True random number submodule, used to generate true random numbers;
[0106] The time interrupt submodule is used to set a timer interrupt based on a true random number, and to judge the current life cycle of the chip and the program running address when the timer interrupt occurs.
[0107] For the specific definition of a device for preventing a chip from being cracked, please refer to the definition of a method for preventing a chip from being cracked above, and will not be repeated here. Each module in the above-mentioned device for preventing a chip from being cracked can be implemented in whole or in part by software, hardware, or a combination thereof. The above-mentioned modules can be embedded in or independent of the processor in the computer device in the form of hardware, or can be stored in the memory of the computer device in the form of software, so that the processor can call and execute the operations corresponding to the above modules.
[0108] In one embodiment, a computer device is provided, which may be a server. The computer device includes a processor, memory, a network interface, and a database connected via a system bus. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and computer program in the non-volatile storage medium. The network interface of the computer device is used to communicate with an external terminal via a network connection. When executed by the processor, the computer program implements a method for preventing chip cracking.
[0109] In one embodiment, a computer-readable storage medium is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the following steps are implemented:
[0110] The development mode program and the security mode program are stored in different address ranges;
[0111] During program execution, the current life cycle is randomly judged to obtain the current mode information of the chip and determine whether the address of the currently running program is within the address range corresponding to the current mode;
[0112] If the address of the currently running program is outside the address range corresponding to the current mode, the program will stop running.
[0113] Those skilled in the art will appreciate that all or part of the processes in the above-described embodiments can be implemented by instructing the relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-described methods. In particular, any reference to memory, storage, database, or other media used in the embodiments provided in this application can include non-volatile and / or volatile memory.
[0114] Those skilled in the art will clearly understand that for the sake of convenience and brevity in description, only the division of the above-mentioned functional units and modules is used as an example. In actual applications, the above-mentioned functions can be distributed and completed by different functional units and modules as needed, that is, the internal structure of the system can be divided into different functional units or modules to complete all or part of the functions described above.
Claims
1. A method for preventing a chip from being cracked, characterized in that: The following steps are included: The development mode program and the security mode program are stored in different address ranges; During program execution, a timer interrupt is set based on a true random number; when the timer interrupt is generated, the current life cycle of the chip and the program execution address are judged to obtain the current mode information of the chip, and whether the address of the currently executing program is within the address range corresponding to the current mode; If the address of the currently running program is outside the address range corresponding to the current mode, the program will stop running.
2. The method for preventing a chip from being cracked according to claim 1, characterized in that: When the timing interrupt is generated, the method further comprises the following steps: Generate a true random number again, and reset a new timer interrupt based on the new true random number to replace the original timer interrupt.
3. The method for preventing a chip from being cracked according to claim 1, wherein: The program of the development mode part and the program of the security mode part are stored in a ROM area inside the chip.
4. The method for preventing a chip from being cracked according to claim 1, wherein: The life cycle is stored in the EFUSE module inside the chip in the form of a life cycle identification bit, and the life cycle identification bit is used to indicate whether the chip is in development mode or security mode.
5. The method for preventing a chip from being cracked according to any one of claims 1 to 4, characterized in that: The following steps are also included: Preset sensitive operations; Before executing sensitive operations, the subroutine must determine the current life cycle, obtain the current mode of the chip, and determine whether the address of the currently running program is within the address range corresponding to the current mode. If the address of the currently running program is outside the address range corresponding to the current mode, the program will stop running.
6. The method for preventing a chip from being cracked according to claim 5, characterized in that: The sensitive operations include operations that may threaten chip security.
7. A device for preventing a chip from being cracked, characterized in that: include: A preset module is used to store the development mode program and the security mode program in different address ranges; The second judgment module is used to randomly judge the current life cycle during the program running process, obtain the current mode information of the chip, and judge whether the address of the currently running program is within the address range corresponding to the current mode; The execution module is used to stop the program from running when the address of the currently running program is outside the address range corresponding to the current mode.
8. A computer device, characterized in that: The method comprises a memory, a processor and a computer program stored in the memory, wherein the processor executes the computer program to implement the steps of the method according to any one of claims 1 to 6.
9. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.
Citation Information
Patent Citations
Microcomputer chip for game machine control
JP2002000885A
Single-chip microcomputer
JP2002041494A