A SoC system and a real-time encryption and decryption method based on PRINCE algorithm

By adopting a real-time encryption and decryption method based on PRINCE algorithm in the SoC system, combined with the 32-bit bus design and width adaptive unit, the problem of insufficient running speed and hardware cost of the encryption and decryption algorithm in the embedded system is solved, and efficient and secure real-time encryption and decryption effect is achieved.

CN114139188BActive Publication Date: 2025-06-06HANGZHOU VANGO TECH
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202111490265.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-12-08
Publication Date
2025-06-06
Estimated Expiration
2041-12-08

AI Technical Summary

Technical Problem

The existing encryption and decryption algorithms have shortcomings in operating speed and hardware cost, especially in SoC systems running in embedded systems, which are difficult to meet the encryption and decryption requirements of real-time programs.

Method used

The real-time encryption and decryption method based on the PRINCE algorithm is adopted, combined with the design of the SoC system, through the design of the bus width of 32 bits and the width adaptive unit, it supports access methods of different data widths such as bytes, half words, and words, and configures the key and initial vector through registers to achieve real-time encryption and decryption.

Benefits of technology

It realizes efficient real-time encryption and decryption in embedded system SoC, reduces the consumption of system computing resources, improves data security, and is suitable for high-clock frequency systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114139188B_ABST
    Figure CN114139188B_ABST
Patent Text Reader

Abstract

The present invention discloses a SoC system and a real-time encryption and decryption method based on the PRINCE algorithm. The SoC system includes a kernel, a bus, a peripheral bus module and an external memory. The peripheral bus module performs real-time encryption and decryption on important programs and data in the process of the kernel executing user software; the external memory is a peripheral of the kernel, which is accessed through the peripheral bus and is used to store important programs and data that have been encrypted. The SoC system and the real-time encryption and decryption method provided by the present invention apply the 64-bit PRINCE algorithm to an embedded system with a bus width of 32 bits, realize real-time data encryption and decryption for the external memory, the encryption and decryption process does not require software intervention, and is automatically completed by hardware, which well meets the real-time requirements, adopts a data encryption and decryption method based on an access address to support discrete access to the program, and the adaptive width design can flexibly support different data width access methods such as bytes, half words, and words, continuing the advantages of the PRINCE encryption algorithm in real time, low latency, and low cost.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of encryption and decryption of SoC systems, and in particular relates to a SoC system and a real-time encryption and decryption method based on a PRINCE algorithm. Background Art

[0002] When integrating external memory into SoC (System on Chip), the real-time confidentiality of the external memory is very high. Effective real-time encryption and decryption can prevent the user's identification or data from being read, and also prevent important program data from being changed.

[0003] Mainstream encryption and decryption algorithms are divided into two categories: symmetric and asymmetric. Common encryption and decryption algorithms include DES (Data Encryption Standard), RSA (Rivest-Shamir-Adleman), SHA1 (Secure Hash Algorithm 1), AES (Advanced Encryption Standard), MD5 (Message Digest Algorithm 5), etc. Symmetric algorithms have advantages over asymmetric algorithms, such as short keys, the same encryption and decryption hardware, and fast encryption speed, and are suitable for encryption and decryption of large amounts of data. However, in order to improve security, many encryption and decryption algorithms are currently becoming more complex and have too many rounds of operations. This makes it difficult for systems with high requirements for running speed to run real-time programs on encrypted storage.

[0004] Therefore, lightweight encryption and decryption algorithms are considered. The so-called lightweight means that the key data is short, the number of calculation rounds is small, and the authentication efficiency is high. It can achieve the premise of adding security without affecting its own cost and real-time performance, so as to meet the application requirements. Among them, the lightweight symmetric encryption algorithm PRINCE is considered to be used. The algorithm can well meet the requirements of dynamic encryption, low latency and low hardware cost. In the process of implementing the present invention, the inventor found that the PRINCE algorithm has at least the following problems:

[0005] 1. The algorithm data width is 64 bits. Too large a bit width will easily consume system computing resources and is not suitable for most embedded systems with a system bus width of 32 bits.

[0006] 2. The code program is stored in the external memory, and is accessed discretely after running. The data address and data width are not certain. The PRINCE algorithm cannot support discrete data access well. Summary of the invention

[0007] Purpose of the invention: The technical problem to be solved by the present invention is to provide a SoC system and a real-time encryption and decryption method based on the PRINCE algorithm in view of the deficiencies in the prior art.

[0008] In order to solve the above technical problems, in a first aspect, a SoC system is disclosed, including a core, a bus, a peripheral bus module and an external memory.

[0009] The kernel is the central processing unit of the SoC system, in which user software is executed and the peripheral bus module is accessed through the bus;

[0010] The bus is part of the bus architecture in the SoC system, and after the bus matrix arbitrates the access request, a bus command is issued to access the peripheral bus module;

[0011] The peripheral bus module includes a peripheral bus control module and a peripheral bus. The peripheral bus is the interface between the kernel and the external memory. The peripheral bus control module is used to control the peripheral bus driver and perform real-time encryption and decryption of important programs and stored data in the kernel during the execution of user software through the peripheral bus interface. The peripheral bus is used to connect external devices, generally standard protocols such as SPI (Serial Peripheral Interface), UART (Universal Asynchronous Receiver / Transmitter) or IIC (Inter-Integrated Circuit).

[0012] The external memory, as a peripheral of the core, is accessed through a peripheral bus and is used to store important programs and storage data that have been encrypted.

[0013] In combination with the first aspect, in one implementation, the bus width is 32 bits, and the bus includes an instruction channel, an address channel, and a data channel.

[0014] The instruction channel is used for the kernel to send access instructions to the peripheral bus control module, and the access instructions can realize the kernel's byte, half-word and word data access mode to the peripheral bus control module register, and can also realize the byte, half-word and word data access mode to the external memory in the XIP (eXecute In Place) mode; the XIP mode provides direct access from the system bus to the external memory, and the access request is converted into an access on the peripheral bus interface. If the peripheral bus receives read data, it is directly returned to the system bus interface;

[0015] The address channel is used for the kernel to send the peripheral bus control module register address to be operated by the kernel and the external memory address in XIP mode to the peripheral bus control module;

[0016] The data channel is used for reading and writing data from the kernel to the register of the peripheral bus control module, and for sending plaintext data to be encrypted to the external memory in XIP mode, or for the peripheral bus module to send decrypted plaintext data to the kernel.

[0017] In combination with the first aspect, in one implementation, the peripheral bus control module includes a register and an encryption and decryption control module;

[0018] The register is used to control the peripheral bus timing and store the initial vector and key used by the encryption and decryption algorithm unit;

[0019] The encryption and decryption control module is used for real-time encryption and decryption of external storage data, and includes a mode selection unit, an encryption and decryption algorithm unit and a width adaptation unit; the mode selection unit is used to select XIP mode or non-XIP mode, and obtain corresponding instruction information, address information and data information according to the selected mode, and enable XIP mode by register configuration; in XIP mode, instruction, address and data information are directly determined by the system bus; in non-XIP mode, instruction, address and data information are directly determined by register configuration.

[0020] The encryption and decryption algorithm unit is used to encrypt the plaintext data input by the kernel through the data channel to obtain ciphertext data, and save the ciphertext data to the external memory; and decrypt the ciphertext data stored in the external memory to obtain plaintext data, and transmit the plaintext data to the kernel through the data channel;

[0021] The width adaptive unit is used to implement the data access mode of the core to the external memory byte, half word and word through the access instruction input by the instruction channel.

[0022] In combination with the first aspect, in one implementation, the register width is consistent with the bus width, including a peripheral bus control part register and an encryption and decryption part register, the peripheral bus control part register is used to control the peripheral bus timing; the encryption and decryption part register is used to store the first initial vector iv0 and the second initial vector iv1 used by the encryption and decryption algorithm unit, as well as the first key key0, the second key key1, the third key key2 and the fourth key key3; the first initial vector iv0, the second initial vector iv1, the first key key0, the second key key1, the third key key2 and the fourth key key3 are all 32 bits wide. The initial vectors and keys in the encryption and decryption part register are configurable, flexible to use, and not easily cracked or stolen by the outside.

[0023] In combination with the first aspect, in one implementation, the width adaptation unit stores the data in a binary variable byte_map through an access instruction, the length of the binary variable byte_map is 4 bits, and the kernel implements the data access mode of the external memory byte, half word and word according to the following mapping relationship:

[0024] When the variable byte_map is 0001, the data access mode is byte operation, operating the 31st:24th bits of the data;

[0025] When the variable byte_map is 0010, the data access mode is byte operation, operating the 23:16th bit of the data;

[0026] When the variable byte_map is 0100, the data access mode is byte operation, operating the 15th:8th bit of the data;

[0027] When the variable byte_map is 1000, the data access mode is byte operation, operating the 7th:0th bit of the data;

[0028] When the variable byte_map is 1100, the data access mode is half-word operation, operating the 15:0th bit of the data;

[0029] When the variable byte_map is 0011, the data access mode is half-word operation, operating the 31st:16th bits of the data;

[0030] When the variable byte_map is 1111, the data access mode is word operation, and the 31st:0th bit of the operation data.

[0031] In response to different bit width requirements for accessing data, the width adaptation unit operates on the corresponding bits of ciphertext data or plaintext data through the access instructions input through the instruction channel, flexibly supporting the embedded system's random access operations on bytes, half words, and words of external memory.

[0032] In the second aspect, a real-time encryption and decryption method based on the PRINCE algorithm is disclosed, including an encryption algorithm and a decryption algorithm.

[0033] In conjunction with the second aspect, in one implementation, the encryption algorithm includes:

[0034] Step 1, convert the address passed to the encryption and decryption algorithm unit after mode selection into address ciphertext;

[0035] Step 2, performing XOR processing on the address ciphertext and the input plaintext data to obtain first XOR data;

[0036] Step 3, inputting the access instruction and the first XOR data into the width adaptive unit, and operating the corresponding bits in the first XOR data according to the access instruction to obtain the ciphertext data;

[0037] Step 4: Save the encrypted data to an external storage device.

[0038] The encryption of important data written to the external memory area is realized according to the address parameters, that is, after the address is encrypted into ciphertext, the specific data is encrypted according to the address ciphertext, which can support the discrete storage of data. No software intervention is required in the entire encryption process, which improves security.

[0039] In conjunction with the second aspect, in one implementation, the decryption algorithm includes:

[0040] Step 1', convert the address passed into the encryption and decryption algorithm unit after mode selection into address ciphertext;

[0041] Step 2', performing XOR processing on the address ciphertext and the ciphertext data obtained from the external memory to obtain second XOR data;

[0042] Step 3', inputting the access instruction and the second XOR data into the width adaptive unit, and operating the corresponding bits in the second XOR data according to the access instruction to obtain the plaintext data;

[0043] Step 4', transmit the plaintext data to the kernel through the data channel.

[0044] Decryption of ciphertext data read from external memory is realized according to address parameters, that is, after encrypting the address into ciphertext, the ciphertext data stored in external memory is decrypted according to the address ciphertext, which can support discrete reading of data. No software intervention is required in the entire decryption process, which improves security.

[0045] In conjunction with the second aspect, in one implementation, step 1 and step 1' respectively include the following steps:

[0046] Step a, adding the address passed into the encryption and decryption algorithm unit after mode selection to the third initial vector iv to obtain first operation data; the third initial vector iv is formed by concatenating the first initial vector iv0 and the second initial vector iv1, that is, iv = {iv0, iv1};

[0047] Step b, performing an XOR operation on the first operation data and the fifth key k0 to obtain third XOR data; the fifth key k0 is formed by concatenating the first key key0 and the second key key1, that is, k0 = {key0, key1};

[0048] Step c, encrypting the third XOR data using the PRINCE algorithm to obtain first encrypted data;

[0049] Step d, performing an XOR operation on the first encrypted data and the sixth key k0' to obtain a 64-bit address ciphertext, and intercepting the lower 32 bits; the sixth key k0'={k0[0], k0[63:2], (k0[1]^k0

[63] )}.

[0050] In view of the fact that the data width of the PRINCE algorithm is too wide and inconsistent with the actual bus data width, step 1 and step 1' add the 32-bit address parameter and the 64-bit third initial vector to form a 64-bit original plaintext. After the PRINCE algorithm, a 64-bit ciphertext is obtained, and the lower 32 bits are intercepted. The 32-bit plaintext data in step 1 and step 2 or the 32-bit ciphertext data in step 1' and step 2' are XORed, which not only realizes the encryption and decryption of 32-bit data, but also reduces the consumption of system computing resources.

[0051] The code implementation of step 2 and step 3 is shown in the following table:

[0052] Binary variable byte_map Code Implementation 4’b0001 Ciphertext = plaintext[7:0]^address ciphertext[31:24] 4’b0010 Ciphertext = plaintext[7:0]^address ciphertext[23:16] 4’b0100 Ciphertext = plaintext[7:0]^address ciphertext[15:8] 4’b1000 Ciphertext = plaintext[7:0]^address ciphertext[7:0] 4’b1100 Ciphertext = plaintext[15:0]^address ciphertext[15:0] 4’b0011 Ciphertext = plaintext[15:0]^address ciphertext[31:16] 4’b1111 Ciphertext = plaintext[31:0]^address ciphertext[31:0]

[0053] The code implementation of step 2' and step 3' is shown in the following table:

[0054]

[0055]

[0056] In combination with the second aspect, in one implementation, the PRINCE algorithm in step c includes a seventh key k1, and the seventh key k1 is composed of a third key key2 and a fourth key key3, that is, k1 = {key2, key3}.

[0057] Beneficial effects:

[0058] In addition, the real-time encryption and decryption method based on the PRINCE algorithm provided in the present application continues the advantages of the PRINCE encryption algorithm in real time, low latency, and low cost, with fewer operation cycles, low hardware cost, dynamic encryption, and real-time operation to complete encryption and decryption, thereby improving data security; the ciphertext is calculated within one clock cycle, with low latency, and is suitable for high clock frequency systems; the hardware cost is low, the area is small, and the same hardware code is used for encryption and decryption.

[0059] The SoC system and the real-time encryption and decryption method based on the PRINCE algorithm provided by the present application apply the 64-bit PRINCE algorithm to an embedded system with a bus width of 32 bits to realize real-time data encryption and decryption of an external memory. Among them, in order to support discrete access to the program, a data encryption and decryption method based on the access address is adopted, and an adaptive width design is added to flexibly support different data width access methods such as bytes, half words, and words. Among them, the key and the initial vector can be configured by registers before encryption, which has high flexibility. At the same time, no software intervention is required during the encryption and decryption process, which improves security. BRIEF DESCRIPTION OF THE DRAWINGS

[0060] The present invention will be further described in detail below in conjunction with the accompanying drawings and specific embodiments, and the above and / or other advantages of the present invention will become more clear.

[0061] Figure 1 A schematic diagram of a SoC system structure provided in an embodiment of the present application.

[0062] Figure 2 A real-time encryption algorithm provided in the embodiment of the present application Figure 1 .

[0063] Figure 3 A real-time decryption algorithm provided in the embodiment of the present application Figure 1 .

[0064] Figure 4 A real-time encryption algorithm provided in the embodiment of the present application Figure 2 .

[0065] Figure 5 A real-time decryption algorithm provided in the embodiment of the present application Figure 2 .

[0066] Figure 6 Schematic diagram of the PRINCE algorithm flow. DETAILED DESCRIPTION

[0067] The embodiments of the present invention will be described below in conjunction with the accompanying drawings.

[0068] The SoC system and the real-time encryption and decryption method based on the PRINCE algorithm provided in the present application can be applied to high clock frequency systems, and are particularly suitable for scenarios where user programs need to be executed in real time in an encrypted external memory.

[0069] Real-time encryption and decryption technology is similar to the codec between the kernel and the external memory, such as Figure 1As shown, one end is the plaintext area, which is connected to the user software (also called the application). The data must be in plaintext when flowing to the application so that the application can obtain the correct runtime data. The other end is the ciphertext end, which is connected to the external storage to ensure the security of the data.

[0070] like Figure 1 As shown, the first embodiment of the present application discloses a SoC system, including a core, a bus, a peripheral bus module and an external memory.

[0071] Kernel: It is the central processing unit of the entire SoC system. User software is executed in the kernel, and the registers of the peripheral bus module are accessed through the bus, thereby driving the peripheral bus to access the external memory. It can also drive the register configuration key and initial vector parameters of the peripheral bus module.

[0072] Bus: The bus is part of the bus architecture in the SoC system. The bus matrix arbitrates access requests and issues bus commands to access the peripheral bus modules in the SoC system.

[0073] Peripheral bus module: includes a peripheral bus control module and a peripheral bus. The peripheral bus is the interface between the kernel and the external memory. The peripheral bus control module is used to control the peripheral bus driver and perform real-time encryption and decryption of important programs and stored data in the kernel's execution of user software through the peripheral bus interface. That is, the application side performs real-time encryption and decryption on the access to the external memory, but it is completely "transparent" to the application side and there is no need to change the existing operating method.

[0074] External memory: As a peripheral of the kernel, it needs to be accessed through the peripheral bus and is used to store important encrypted programs and data.

[0075] In the first embodiment, the bus width is 32 bits, and the bus includes an instruction channel, an address channel, and a data channel.

[0076] The instruction channel is used for the kernel to send access instructions to the peripheral bus control module. The access instructions can realize the kernel's byte, half-word and word data access mode to the peripheral bus control module register, and can also realize the byte, half-word and word data access mode to the external memory in the XIP mode; the XIP mode provides a function to directly access the external memory from the system bus, and the access request is converted into an access on the peripheral bus interface. If the peripheral bus receives read data, it is directly returned to the system bus interface;

[0077] The address channel is used for the kernel to send the peripheral bus control module register address to be operated by the kernel and the external memory address in XIP mode to the peripheral bus control module;

[0078] The data channel is used for reading and writing data from the kernel to the register of the peripheral bus control module, and for sending plaintext data to be encrypted to the external memory in XIP mode, or for the peripheral bus module to send decrypted plaintext data to the kernel.

[0079] In the first embodiment, the peripheral bus control module includes a register and an encryption and decryption control module;

[0080] The register is used to control the peripheral bus timing and store the initial vector and key used by the encryption and decryption algorithm unit; the register width is consistent with the bus width, including the peripheral bus control part register and the encryption and decryption part register, the peripheral bus control part register is used to control the peripheral bus timing; the encryption and decryption part register is used to store the first initial vector iv0 and the second initial vector iv1 used by the encryption and decryption algorithm unit, as well as the first key key0, the second key key1, the third key key2 and the fourth key key3; the first initial vector iv0, the second initial vector iv1, the first key key0, the second key key1, the third key key2 and the fourth key key3 are all 32 bits wide. The initial vector and key in the encryption and decryption part register are both configurable and configured by software before encryption and decryption start. The value of the variable can be specified by the user program or generated by a random number. The process does not support software intervention and cannot be modified. Encryption and decryption need to be configured the same, otherwise the reverse operation cannot be performed to complete the decryption.

[0081] The encryption and decryption control module is used for real-time encryption and decryption of external storage data, and includes a mode selection unit, an encryption and decryption algorithm unit, and a width adaptation unit;

[0082] The mode selection unit is used to select XIP mode or non-XIP mode, and obtain corresponding instruction information, address information and data information according to the selected mode, and enable XIP mode by register configuration; in XIP mode, instruction, address and data information are directly determined by the system bus; in non-XIP mode, instruction, address and data information are directly determined by register configuration.

[0083] The encryption and decryption algorithm unit is used to encrypt the plaintext data input by the kernel through the data channel, obtain the ciphertext data, and save the ciphertext data in the external memory; and decrypt the ciphertext data stored in the external memory to obtain the plaintext data, and transmit the plaintext data to the kernel through the data channel; the core of encryption and decryption is to convert the address transmitted by the address channel into ciphertext, and then XOR the data of the data channel with the ciphertext to realize the encryption and decryption of the data.

[0084] The width adaptive unit is used to implement the flexible data access mode of the kernel to the bytes, half words and words of the external memory through the access instruction input through the instruction channel. The access instruction sent through the instruction channel is stored in the binary variable byte_map. The length of the binary variable byte_map is 4 bits. The data access mode of the kernel to the bytes, half words and words of the external memory is implemented according to the following mapping relationship:

[0085] Binary variable byte_map Operation Type 4’b0001 Byte Operation: [31:24] 4’b0010 Byte Operation: [23:16] 4’b0100 Byte operation: [15:8] 4’b1000 Byte operation: [7:0] 4’b1100 Half-word operation: [15:0] 4’b0011 Byte Half-word Operation: [31:16] 4’b1111 Word operation: [31:0]

[0086] The second embodiment of the present application discloses a real-time encryption and decryption method based on the PRINCE algorithm, including an encryption algorithm and a decryption algorithm.

[0087] In the second embodiment, if Figure 2 As shown, the encryption algorithm includes:

[0088] Step 1, convert the address passed into the encryption and decryption algorithm unit after mode selection into address ciphertext;

[0089] Step 2, performing XOR processing on the address ciphertext and the input plaintext data to obtain first XOR data;

[0090] Step 3, inputting the access instruction and the first XOR data into the width adaptive unit, and operating the corresponding bits in the first XOR data according to the access instruction to obtain the ciphertext data;

[0091] Step 4: Save the encrypted data to an external storage device.

[0092] In the second embodiment, if Figure 3 As shown, the decryption algorithm includes:

[0093] Step 1', convert the address passed into the encryption and decryption algorithm unit after mode selection into address ciphertext;

[0094] Step 2', performing XOR processing on the address ciphertext and the ciphertext data obtained from the external memory to obtain second XOR data;

[0095] Step 3', inputting the access instruction and the second XOR data into the width adaptive unit, and operating the corresponding bits in the second XOR data according to the access instruction to obtain the plaintext data;

[0096] Step 4', transmit the plaintext data to the kernel through the data channel.

[0097] In the second embodiment, if Figure 4 and Figure 5 As shown, the step 1 and step 1' respectively include the following steps:

[0098] Step a, adding the address passed into the encryption and decryption algorithm unit after mode selection to the third initial vector iv to obtain first operation data; the third initial vector iv is formed by concatenating the first initial vector iv0 and the second initial vector iv1, that is, iv = {iv0, iv1};

[0099] Step b, performing an XOR operation on the first operation data and the fifth key k0 to obtain third XOR data; the fifth key k0 is formed by concatenating the first key key0 and the second key key1, that is, k0 = {key0, key1};

[0100] Step c, encrypting the third XOR data using the PRINCE algorithm to obtain first encrypted data;

[0101] Step d, performing an XOR operation on the first encrypted data and the sixth key k0' to obtain a 64-bit address ciphertext, and intercepting the lower 32 bits; the sixth key k0'={k0[0], k0[63:2], (k0[1]^k0

[63] )}.

[0102] The code implementation of step 2 and step 3 is shown in the following table:

[0103] Binary variable byte_map Code Implementation 4’b0001 Ciphertext = plaintext[7:0]^address ciphertext[31:24] 4’b0010 Ciphertext = plaintext[7:0]^address ciphertext[23:16] 4’b0100 Ciphertext = plaintext[7:0]^address ciphertext[15:8] 4’b1000 Ciphertext = plaintext[7:0]^address ciphertext[7:0] 4’b1100 Ciphertext = plaintext[15:0]^address ciphertext[15:0] 4’b0011 Ciphertext = plaintext[15:0]^address ciphertext[31:16] 4’b1111 Ciphertext = plaintext[31:0]^address ciphertext[31:0]

[0104] The code implementation of step 2' and step 3' is shown in the following table:

[0105] Binary variable byte_map Code Implementation 4’b0001 Plain text = ciphertext[7:0]^address ciphertext[31:24] 4’b0010 Plain text = ciphertext[7:0]^address ciphertext[23:16] 4’b0100 Plain text = ciphertext[7:0]^address ciphertext[15:8] 4’b1000 Plain text = ciphertext[7:0]^address ciphertext[7:0] 4’b1100 Plain text = ciphertext[15:0]^address ciphertext[15:0] 4’b0011 Plain text = ciphertext[15:0]^address ciphertext[31:16] 4’b1111 Plain text = ciphertext[31:0]^address ciphertext[31:0]

[0106] In the second embodiment, if Figure 6 As shown, the PRINCE algorithm in step c includes a seventh key k1, and the seventh key k1 is composed of the third key key2 and the fourth key key3, that is, k1 = {key2, key3}.

[0107] The PRINCE algorithm is suitable for 64-bit data operations, and certain processing is required for bus data width of 32 bits. The following table shows Figure 4 , Figure 5 and Figure 6 The input variables are:

[0108]

[0109] The encryption algorithm is completely consistent with step 1 and step 1' of the decryption algorithm. The main purpose is to encrypt the 32-bit operation address into ciphertext. In order to be applicable to the 64-bit PRINCE algorithm and increase randomness, step a is first performed: address (32 bits) + third initial vector iv (64 bits), and after obtaining the 64-bit first operation data related to the address, the 64-bit ciphertext is obtained by the encryption PRINCE algorithm (step b to step d). Since the data width is 32 bits, the output after step d is intercepted and the lower 32 bits are sent to the subsequent calculation.

[0110] Step 2 of the encryption algorithm is the reverse operation of step 2' of the decryption algorithm. The core idea is that the data on the kernel side is plain text, and the data on the external memory side is cipher text. Therefore, encryption requires encrypting the data written by the kernel to the external memory, converting the plain text in the kernel into cipher text and then writing it to the external memory. The specific method is to XOR the 32-bit cipher text after step 1 with the 32-bit write data (plain text). Decryption is to decrypt the cipher text returned by the external memory to the kernel. The specific method is to XOR the 32-bit read data (cipher text) with the 32-bit cipher text after step 1'.

[0111] Step 3 of the encryption algorithm and step 3' of the decryption algorithm are implemented by the width adaptation unit, which is designed to adapt the access mode of the core to the external memory. After this step, the core's byte, double-byte, and word access operations can be flexibly supported.

[0112] Real-time encryption example:

[0113] Take the XIP mode as an example:

[0114] Before encryption and decryption, the encryption and decryption registers are configured by software:

[0115] iv0=32'h76543210

[0116] iv1=32'hfedcba98

[0117] key0=32'h1111_1111

[0118] key1=32'h2222_2222

[0119] key2=32'h3333_3333

[0120] key3=32'h4444_4444

[0121] therefore,

[0122] iv=64'h7654_3210_fedc_ba98

[0123] k0=64'h1111_1111_2222_2222

[0124] k0'=64'h0888_8888_9111_1111

[0125] k1=64'h3333_3333_4444_4444

[0126] The system bus is AHB, send a write instruction: address 0 writes data 32'hd85d_17a0, the access mode is word.

[0127] The complete encryption steps are as follows:

[0128] Step b, obtain the third XOR data = (32'h0+iv)^k0 = 64'h6745_2301_dcfe_98ba

[0129] Step c, obtain the first encrypted data = 64'h4de1_b40a_7d72_4a66

[0130] Step d, obtain the address ciphertext = 64'h4569_3c82_ec63_5b77, and intercept the lower 32 bits for subsequent operations.

[0131] Step 2, obtain the first XOR data = 32-bit address ciphertext ^ 32-bit data = 32'h343e_4cd7.

[0132] Step 3, obtain the ciphertext data, and the word access method retains all 32 bits of data.

[0133] Finally, the encrypted data written to the external memory is 32'h343e_4cd7.

[0134] Real-time decryption example:

[0135] Let's take XIP mode as an example:

[0136] The configuration register must be exactly the same as the encryption register, otherwise the reverse operation cannot be performed to decrypt the data.

[0137] The system bus is AHB, and a read instruction is sent: the access address is 0, and the access mode is half-word.

[0138] The complete decryption steps are as follows:

[0139] Step d is the same as encryption, and the address ciphertext 32'hec63_5b77 is obtained. At the same time, the data returned from reading the external memory address 0 is 32'h343e_4cd7.

[0140] Step 2', obtain the second XOR data = 32'hec63_5b77^32'h343e_4cd7 = 32'hd85d_17a0.

[0141] Step 3', half-word read, then byte_map is 4'b1100, and the read data obtained after passing through the width adaptive unit is 16'h17a0, which is successfully returned to the AHB bus, completing the decryption operation.

[0142] Through the above encryption and decryption examples in XIP mode, we can see that the read data is consistent with the written data. And the plaintext transmitted on the system bus is converted into ciphertext after encryption and decryption and stored in the external memory, which well implements the isolation of plaintext and ciphertext, and plays a good role in protecting important programs and stored data in the external memory.

[0143] This embodiment provides a real-time encryption and decryption algorithm for external memory. During use, no software intervention is required. The hardware automatically encrypts and decrypts data. It flexibly supports discrete random access of address and data width, and can effectively protect important programs and data in the external memory in real time. The encryption algorithm has the advantages of real-time, low latency and low cost.

[0144] The present invention provides a SoC system and a real-time encryption and decryption method based on the PRINCE algorithm. There are many methods and ways to implement the technical solution. The above is only a specific implementation of the present invention. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principle of the present invention. These improvements and modifications should also be regarded as the protection scope of the present invention. All components not specified in this embodiment can be implemented by existing technologies.

Claims

1. A SoC system, It is characterized in that Including the core, bus, peripheral bus module and external memory, The kernel is the central processing unit of the SoC system, in which user software is executed and the peripheral bus module is accessed through the bus; The bus is part of the bus architecture in the SoC system, and after the bus matrix arbitrates the access request, a bus command is issued to access the peripheral bus module; The peripheral bus module includes a peripheral bus control module and a peripheral bus, and the peripheral bus is an interface between the kernel and the external memory; The peripheral bus control module is used to control the peripheral bus driver and perform real-time encryption and decryption of important programs and stored data during the kernel execution of user software through the peripheral bus interface; The external memory, as a peripheral of the kernel, is accessed through a peripheral bus and is used to store important encrypted programs and storage data; The peripheral bus control module includes a register and an encryption and decryption control module; The register is used to control the peripheral bus timing and store the initial vector and key used by the encryption and decryption algorithm unit; The encryption and decryption control module is used for real-time encryption and decryption of external storage data, and includes a mode selection unit, an encryption and decryption algorithm unit, and a width adaptation unit; the mode selection unit is used to select XIP mode or non-XIP mode, and obtain corresponding instruction information, address information, and data information according to the selected mode, and enable the XIP mode by register configuration; in the XIP mode, the instruction, address, and data information are directly determined by the system bus; in the non-XIP mode, the instruction, address, and data information are directly determined by the register configuration; The encryption and decryption algorithm unit is used to encrypt the plaintext data input by the kernel through the data channel to obtain ciphertext data, and save the ciphertext data to the external memory; and decrypting the ciphertext data stored in the external memory to obtain the plaintext data, and transmitting the plaintext data to the kernel through the data channel; The width adaptive unit is used to implement the data access mode of the core to the external memory byte, half word and word through the access instruction input by the instruction channel.

2. A SoC system according to claim 1, It is characterized in that The bus width is 32 bits, and the bus includes an instruction channel, an address channel, and a data channel. The instruction channel is used for the kernel to send access instructions to the peripheral bus control module, and the access instructions can realize the kernel's byte, half-word and word data access mode to the peripheral bus control module register, and can also realize the byte, half-word and word data access mode to the external memory in the XIP mode; the XIP mode provides direct access from the system bus to the external memory, and the access request is converted into an access on the peripheral bus interface. If the peripheral bus receives read data, it is directly returned to the system bus interface; The address channel is used for the kernel to send the peripheral bus control module register address to be operated by the kernel and the external memory address in XIP mode to the peripheral bus control module; The data channel is used for reading and writing data from the kernel to the register of the peripheral bus control module, and for sending plaintext data to be encrypted to the external memory in XIP mode, or for the peripheral bus module to send decrypted plaintext data to the kernel.

3. A SoC system according to claim 1, It is characterized in that The register width is consistent with the bus width, including peripheral bus control part registers and encryption and decryption part registers. The peripheral bus control part registers are used to control the peripheral bus timing; the encryption and decryption part registers are used to store the first initial vector iv0 and the second initial vector iv1 used by the encryption and decryption algorithm unit, as well as the first key key0, the second key key1, the third key key2 and the fourth key key3; the width of the first initial vector iv0, the second initial vector iv1, the first key key0, the second key key1, the third key key2 and the fourth key key3 are all 32 bits.

4. A SoC system according to claim 1, It is characterized in that The access instruction input through the instruction channel in the width adaptive unit is stored in the binary variable byte_map. The length of the binary variable byte_map is 4 bits. The kernel implements the data access mode of the external memory byte, half word and word according to the following mapping relationship: When the variable byte_map is 0001, the data access mode is byte operation, operating the 31st:24th bits of the data; When the variable byte_map is 0010, the data access mode is byte operation, operating the 23:16th bit of the data; When the variable byte_map is 0100, the data access mode is byte operation, operating the 15th:8th bit of the data; When the variable byte_map is 1000, the data access mode is byte operation, operating the 7th:0th bit of the data; When the variable byte_map is 1100, the data access mode is half-word operation, operating the 15:0th bit of the data; When the variable byte_map is 0011, the data access mode is half-word operation, operating the 31st:16th bits of the data; When the variable byte_map is 1111, the data access mode is word operation, operating the 31st:0th bit of the data.

5. A real-time encryption and decryption method based on the PRINCE algorithm, applied to the SoC system according to any one of claims 1 to 4, It is characterized in that Includes encryption algorithm and decryption algorithm.

6. A real-time encryption and decryption method based on PRINCE algorithm according to claim 5, It is characterized in that The encryption algorithm includes: Step 1, convert the address passed into the encryption and decryption algorithm unit after mode selection into address ciphertext; Step 2, performing XOR processing on the address ciphertext and the input plaintext data to obtain first XOR data; Step 3, inputting the access instruction and the first XOR data into the width adaptive unit, and operating the corresponding bits in the first XOR data according to the access instruction to obtain the ciphertext data; Step 4: Save the encrypted data to an external storage device.

7. A real-time encryption and decryption method based on PRINCE algorithm according to claim 5, It is characterized in that The decryption algorithm includes: Step 1', convert the address passed to the encryption and decryption algorithm unit after mode selection into address ciphertext; Step 2', performing XOR processing on the address ciphertext and the ciphertext data obtained from the external memory to obtain second XOR data; Step 3', inputting the access instruction and the second XOR data into the width adaptive unit, and operating the corresponding bits in the second XOR data according to the access instruction to obtain the plaintext data; Step 4', transmit the plaintext data to the kernel through the data channel.

8. A real-time encryption and decryption method based on PRINCE algorithm according to claim 6, It is characterized in that The step 1 comprises the following steps: Step a, adding the address passed into the encryption and decryption algorithm unit after mode selection to the third initial vector iv to obtain first operation data; the third initial vector iv is formed by concatenating the first initial vector iv0 and the second initial vector iv1, that is, iv = {iv0, iv1}; Step b, performing an XOR operation on the first operation data and the fifth key k0 to obtain third XOR data; the fifth key k0 is formed by concatenating the first key key0 and the second key key1, that is, k0 = {key0, key1}; Step c, encrypting the third XOR data using the PRINCE algorithm to obtain first encrypted data; Step d, performing an XOR operation on the first encrypted data and the sixth key k0' to obtain a 64-bit address ciphertext, and intercepting the lower 32 bits; the sixth key k0'={k0[0], k0[63:2], (k0[1]^k0[63])}.

9. A real-time encryption and decryption method based on PRINCE algorithm according to claim 7, It is characterized in that The step 1' comprises the following steps: Step a, adding the address passed into the encryption and decryption algorithm unit after mode selection to the third initial vector iv to obtain first operation data; the third initial vector iv is formed by concatenating the first initial vector iv0 and the second initial vector iv1, that is, iv = {iv0, iv1}; Step b, performing an XOR operation on the first operation data and the fifth key k0 to obtain third XOR data; the fifth key k0 is formed by concatenating the first key key0 and the second key key1, that is, k0 = {key0, key1}; Step c, encrypting the third XOR data using the PRINCE algorithm to obtain first encrypted data; Step d, performing an XOR operation on the first encrypted data and the sixth key k0' to obtain a 64-bit address ciphertext, and intercepting the lower 32 bits; the sixth key k0'={k0[0], k0[63:2], (k0[1]^k0[63])}.

10. A real-time encryption and decryption method based on PRINCE algorithm according to claim 8 or 9, It is characterized in that The PRINCE algorithm in step c includes a seventh key k1, and the seventh key k1 is composed of the third key key2 and the fourth key key3, that is, k1 = {key2, key3}.

Citation Information

Patent Citations

  • Controller and method for protecting NorFlash core data outside universal sheet

    CN102436423A