Chip authorization and verification method, device and electronic device
By encrypting authorization data through a certification server and deploying it securely to the chip, the method addresses vulnerabilities in existing chip authorization methods, ensuring secure and efficient chip use verification.
Patent Information
- Application Number
- CN202111463404.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-03
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2041-12-03
AI Technical Summary
The existing chip licensing solutions are very labor-intensive, and the certification work is easily cracked in non-secure areas, which cannot effectively constrain the chip usage range.
The authorization request information and authorization list information are encrypted through the authentication server to form authorization ciphertext information, and deployed to the secure partition of the chip under the secure path. After decryption, verify whether the authorization plaintext information has been tampered with.
Perform authorization deployment under a secure path to reduce additional processes on the chip production side, ensure that chip usage meets the manufacturer's intentions, and improve the security of authorization.
Smart Images

Figure CN114154443B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of chip design, and particularly to a chip authorization and verification method, device, and electronic device. Background Art
[0002] In order to meet the differentiated needs of different industry customer groups, chip manufacturers will make differentiated designs on the same chip. Due to different resources invested in these designs, different authorizations are required to restrict the scope of use and different selling prices are given.
[0003] At present, most of the implementation solutions for chip authorization are to find a key path in the chip usage scenario, encrypt it in its necessary components, and hide the authorization data in another component, and compare the authorization data when the necessary component is started. The defect of this solution is that the workload is large, and the authentication work is all in the non-secure area and is easy to be cracked. Summary of the Invention
[0004] Embodiments of the present invention provide a chip authorization and verification method, device, and electronic device. The authorization request information and authorization list information are encrypted by an authentication server to form authorization ciphertext information and deployed to the chip, and then the authorization ciphertext information of the chip is decrypted to obtain authorization plaintext information and verify whether the authorization plaintext information is tampered with. Authorization deployment can be carried out under a secure path to query whether the user uses the chip according to the intention authorized by the chip manufacturer, and authorization deployment can be carried out at the production end to reduce the additional processes at the chip production end.
[0005] In a first aspect, an embodiment of the present invention provides a chip authorization method, including:
[0006] Receiving first authorization request information sent by a chip authorization tool, where the first authorization request information includes chip identification information, project information, and customer identity authentication information of a first chip;
[0007] Generating authorization ciphertext information of the first chip according to the chip identification information, the project information, and the customer identity authentication information;
[0008] Sending the authorization ciphertext information to the chip authorization tool, so that the chip authorization tool deploys the authorized ciphertext information to a secure partition of a first terminal device.
[0009] In a possible implementation manner, generating the authorization ciphertext information of the first chip according to the chip identification information, the project information, and the customer identity authentication information includes:
[0010] Determine the authorization list information of the first chip according to a combination of one or more of the chip identification information, the project information, and the customer identity authentication information, where the authorization list information includes the functions obtained by the first chip;
[0011] Perform at least one encryption on the authorization list information to obtain the authorization ciphertext information.
[0012] In a possible implementation, determining the authorization list information of the first chip according to a combination of one or more of the chip identification information, the project information, and the customer identity authentication information includes:
[0013] Determine the chip authorization balance according to the customer identity authentication information;
[0014] If the chip authorization balance is not zero, determine the authorization list information of the first chip according to the chip identification information, and decrement the chip authorization balance by one.
[0015] In a possible implementation, determining the authorization list information of the first chip according to a combination of one or more of the chip identification information, the project information, and the customer identity authentication information includes:
[0016] Determine the chip authorization balance according to the customer identity authentication information;
[0017] If the chip authorization balance is not zero, determine the authorization list information of the first chip according to the chip identification information and the project information, and decrement the chip authorization balance by one.
[0018] In a possible implementation, performing at least one encryption on the authorization list information to obtain the authorization ciphertext information includes:
[0019] Generate first verification information based on the chip identification information, the project information, the customer identity authentication information, and the authorization list information;
[0020] Obtain an encryption secret key according to the project information;
[0021] Encrypt the chip identification information, the project information, the customer identity authentication information, and the authorization list information through the encryption secret key to form the authorization ciphertext information.
[0022] In a second aspect, an embodiment of the present invention provides a chip verification method, including:
[0023] After the first chip restarts, read the authorization ciphertext information of the first chip from the secure partition;
[0024] Decrypt the authorized ciphertext information with the decryption key to obtain authorized plaintext information;
[0025] Determine chip identification information, project information, customer identity authentication information, authorization list information, and first verification information from the authorized plaintext information;
[0026] Verify the chip identification information, the project information, the customer identity authentication information, and the authorization list information according to the first verification information; if the verification passes, start the first chip, otherwise the first chip startup fails and enters the flashing process.
[0027] In a possible implementation, verifying the chip identification information, the project information, the customer identity authentication information, and the authorization list information according to the first verification information includes:
[0028] Generate second verification information according to the chip identification information, the project information, the customer identity authentication information, and the authorization list information;
[0029] If the second verification information and the first verification information match, confirm that the chip identification information, the project information, the customer identity authentication information, and the authorization list information have not been tampered with.
[0030] In a possible implementation, in addition to verifying the chip identification information, the project information, the customer identity authentication information, and the authorization list information according to the first verification information, the method further includes:
[0031] Verify whether the authorized plaintext information is authorized by the authentication server according to the arrangement format of the chip identification information, the project information, the customer identity authentication information, the authorization list information, and the first verification information, or according to the authentication identifier in the authorized plaintext information;
[0032] Verify whether the authorized plaintext information is authorized by the manufacturer through the secure boot process.
[0033] In the embodiments of the present invention, first, the authentication server encrypts the authorization request information and the authorization list information to form authorized ciphertext information and deploys it to the chip, and then decrypts the authorized ciphertext information of the chip to obtain authorized plaintext information and verify whether the authorized plaintext information is tampered with. Authorized deployment is carried out under a secure path, which can query whether the user uses the chip according to the intention authorized by the chip manufacturer, and authorized deployment at the production end can reduce the additional processes at the chip production end.
[0034] In a third aspect, embodiments of the present invention provide a chip authorization device, including:
[0035] A receiving module, configured to receive first authorization request information sent by a chip authorization tool, where the first authorization request information includes chip identification information, project information, and customer identity authentication information of a first chip;
[0036] A generating module, configured to generate authorization ciphertext information of the first chip according to the chip identification information, the project information, and the customer identity authentication information;
[0037] A sending module, configured to send the authorization ciphertext information to the chip authorization tool, so that the chip authorization tool deploys the authorized ciphertext information to the first chip.
[0038] Fourthly, an embodiment of the present invention provides a chip verification device, including:
[0039] A reading module, configured to read authorization ciphertext information of the first chip from a secure area of the first chip after the first chip restarts;
[0040] A decrypting module, configured to decrypt the authorization ciphertext information by using a decryption key to obtain authorization plaintext information;
[0041] A confirming module, configured to determine chip identification information, project information, customer identity authentication information, an authorization list information, and a first verification information from the authorization plaintext information;
[0042] A verifying module, configured to verify the chip identification information, the project information, the customer identity authentication information, and the authorization list information according to the first verification information;
[0043] A driving module, configured to, if the verification is passed, start the first chip; otherwise, the start of the first chip fails and enters a flashing process.
[0044] Fifthly, an embodiment of the present invention provides an electronic device, including:
[0045] At least one processor; and
[0046] At least one memory communicatively connected to the processor, where:
[0047] The memory stores program instructions executable by the processor, and the processor can execute the method of the first aspect or the second aspect by invoking the program instructions.
[0048] Sixthly, an embodiment of the present invention provides a computer-readable storage medium, characterized in that the computer-readable storage medium stores computer instructions, and the computer instructions cause the computer to execute the method of the first aspect or the second aspect. Description of the Drawings
[0049] To more clearly illustrate the technical solutions in the embodiments of the present invention or in the prior art, the following will briefly introduce the accompanying drawings required for the description of the embodiments or the prior art. Obviously, the accompanying drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0050] Figure 1 It is a schematic structural diagram of a chip authorization device provided by an embodiment of the present invention;
[0051] Figure 2 It is a flowchart of a chip authorization method provided by an embodiment of the present invention;
[0052] Figure 3 It is a flowchart of a chip verification method provided by an embodiment of the present invention;
[0053] Figure 4 It is a schematic structural diagram of a chip authorization device provided by an embodiment of the present invention;
[0054] Figure 5 It is a schematic structural diagram of a chip verification device provided by an embodiment of the present invention;
[0055] Figure 6 It is a schematic structural diagram of an electronic device provided by an embodiment of the present invention. Detailed Embodiments
[0056] To better understand the technical solutions of this specification, the following will describe the embodiments of the present invention in detail with reference to the accompanying drawings.
[0057] It should be clear that the described embodiments are only a part of the embodiments of this specification, rather than all of the embodiments. Based on the embodiments in this specification, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope protected by this specification.
[0058] The terms used in the embodiments of the present invention are only for the purpose of describing specific embodiments, and are not intended to limit this specification. The singular forms of "a", "the", and "said" used in the embodiments of the present invention and the appended claims are also intended to include the plural forms, unless the context clearly indicates otherwise.
[0059] Figure 1 It is a schematic structural diagram of a chip authorization device provided by an embodiment of the present invention. As Figure 1 shown, it may include: an authentication server 110, a chip authorization tool 120, a terminal device 130, a first chip 140, and a security partition 150.
[0060] During the production process of the terminal device 130, the authentication server 110 needs to perform an authorization operation on the first chip 140. The chip authorization tool 120 sends the first authorization request information of the first chip 140 to the authentication server 110. After receiving the first authorization request information, the authentication server 110 encrypts it to form authorization ciphertext information. Then, the authentication server 110 sends the authorization ciphertext information to the chip authorization tool 120, and the chip authorization tool 120 stores the authorization ciphertext information in the secure partition 150.
[0061] When the above chip authorization device authorizes the first chip, the chip authorization tool can establish a secure connection with the authentication server, and the encrypted authorization ciphertext information is finally stored in the secure partition, which can ensure that the chip manufacturer queries the usage information of the first chip; and the chip authorization deployment work is executed during the production of the terminal device, reducing the additional processes on the chip production side.
[0062] Figure 2 The flowchart of a chip authorization method provided by an embodiment of the present invention. As Figure 2 shown, this method is applied to the authentication server and may include:
[0063] Step 201, receive the first authorization request information sent by the chip authorization tool, where the first authorization request information includes the chip identification information, project information, and customer identity authentication information of the first chip.
[0064] Specifically, the chip identification information is the serial number written into the one-time programmable memory EFUSE area after the chip leaves the factory, and the EFUSE area cannot be changed once written. Each chip has a different and unique chip identification information from other chips, which is used to distinguish the identity of the chip.
[0065] In one implementation, when authorizing and deploying the chip, the chip authorization tool sends an application and the first authorization request information to the authentication server through a unique encrypted channel. The chip authorization tool needs to establish communication with the authentication server based on the customer identity authentication information.
[0066] Step 202, generate the authorization ciphertext information of the first chip according to the chip identification information, project information, and customer identity authentication information.
[0067] In one implementation, the authentication server can determine the chip authorization balance according to the customer identity authentication information. If the chip authorization balance is not zero, it can determine the authorization list information of the first chip according to the chip identification information. After determining the authorization list information of the first chip, the authentication server will subtract one from the chip authorization balance of the first chip. Among them, the authorization list information includes the functions obtained by the first chip.
[0068] In one implementation, after the authentication server determines that the chip authorization balance is not zero based on the customer identity authentication information, it can also determine the authorization list information of the first chip according to the chip identification information and the project information.
[0069] In one implementation, the authentication server generates first verification information based on the chip identification information, the project information, the customer identity authentication information, and the authorization list information, then obtains an encryption key according to the project information of the first chip, and encrypts the chip identification information, the project information, the customer identity authentication information, and the authorization list information of the first chip through the encryption key to form the authorized ciphertext information of the first chip.
[0070] Specifically, the authentication server stores an encryption key for encrypting the above information to form authorized ciphertext information, and the encryption key on the authentication server side is a public key.
[0071] Step 203: Send the authorized ciphertext information to the chip authorization tool so that the chip authorization tool deploys the authorized ciphertext information to the secure partition of the first terminal device.
[0072] In one implementation, the authentication server sends the authorized ciphertext information of the first chip to the chip authorization tool through an encrypted channel, and the chip authorization tool writes the authorized ciphertext information into the secure partition of the first terminal device. The secure partition may include a Replay Protected Memory Block (RPMB). The authorized ciphertext information is stored in the secure partition of the first terminal device, and if the first terminal device has operations such as system upgrade or factory reset, the authorized ciphertext information will not be cleared.
[0073] Figure 3 It is a flowchart of a chip verification method provided by an embodiment of the present invention. As Figure 3 shown, this method is used for a terminal device and may include:
[0074] Step 301: After the first chip restarts, read the authorized ciphertext information of the first chip from the secure partition.
[0075] In one implementation, after the first chip restarts, the diskless boot ROM interface bootrom inside the first chip loads the Second Program Loader (SPL) into the Static Random-Access Memory (SRAM). After the SPL completes the initialization of the memory and related devices, it reads the authorization ciphertext information License in the secure partition.
[0076] Step 302: Decrypt the authorized ciphertext information through a decryption key to obtain the authorized plaintext information.
[0077] In one implementation, the first terminal device stores a decryption key, which is used to decrypt the authorized ciphertext information to obtain authorized plaintext information, and the decryption key is a private key.
[0078] Step 303: Determine chip identification information, project information, customer identity authentication information, authorization list information, and first verification information from the authorized plaintext information.
[0079] Step 304: Verify the chip identification information, the project information, the customer identity authentication information, and the authorization list information according to the first verification information.
[0080] In one implementation, the terminal device first verifies whether the authorized plaintext information is authorized by the authentication server. The information that is not authorized by the authentication server is in its original state. It is possible to verify whether the authorized plaintext information is authorized by the authentication server according to the arrangement format of the chip identification information, the project information, the customer identity authentication information, the authorization list information, and the first verification information, or according to the authentication identifier in the authorized plaintext information. Then, second verification information is generated according to the chip identification information, the project information, the customer identity authentication information, and the authorization list information. If the second verification information matches the first verification information, it is confirmed that the chip identification information, the project information, the customer identity authentication information, and the authorization list information have not been tampered with. Finally, through the secure boot process, it is verified whether the authorized plaintext information is authorized by the manufacturer to prevent consumers from performing high-privilege operations such as reading, writing, and debugging some key systems of the chip at the software and hardware levels.
[0081] Step 305: If the verification is passed, start the first chip; otherwise, the startup of the first chip fails and enters the flashing process.
[0082] If all of the above three verifications are successful, the verification is passed and the first chip is started. If there is one or more verification failures, the terminal device enters the flashing process.
[0083] In the embodiments of the present invention, first, the authentication server encrypts the authorization request information and the authorization list information to form authorized ciphertext information and deploys it to the chip, and then decrypts the authorized ciphertext information of the chip to obtain authorized plaintext information and verify whether the authorized plaintext information has been tampered with. Authorized deployment is performed under a secure path, and it is possible to query whether the user uses the chip according to the intention authorized by the chip manufacturer. Moreover, authorized deployment by the production side of the terminal device can reduce additional processes on the chip production side.
[0084] Figure 4Schematic diagram of a chip authorization device provided by an embodiment of the present invention. The chip authorization device in the embodiment of the present invention can be used as a chip authorization device to implement the chip authorization method provided by the embodiment of the present invention. As Figure 4 shown, the above chip authorization device may include: a receiving module 410, a generating module 420, and a sending module 430.
[0085] The receiving module 410 is configured to receive first authorization request information sent by a chip authorization tool, where the first authorization request information includes chip identification information, project information, and customer identity authentication information of a first chip.
[0086] The generating module 420 is configured to generate authorization ciphertext information of the first chip according to the chip identification information, the project information, and the customer identity authentication information.
[0087] The sending module 430 is configured to send the authorization ciphertext information to the chip authorization tool, so that the chip authorization tool deploys the authorization ciphertext information to a secure partition of a first terminal device.
[0088] Figure 5 Schematic diagram of a chip verification device provided by an embodiment of the present invention. The chip verification device in the embodiment of the present invention can be used as a chip verification device to implement the chip verification method provided by the embodiment of the present invention. As Figure 5 shown, the above chip verification device may include: a reading module 510, a decryption module 520, a determination module 530, a verification module 540, and a driving module 550.
[0089] The reading module 510 is configured to read authorization ciphertext information of the first chip from a secure partition after the first chip restarts.
[0090] The decryption module 520 is configured to decrypt the authorization ciphertext information with a decryption key to obtain authorization plaintext information.
[0091] The determination module 530 determines chip identification information, project information, customer identity authentication information, authorization list information, and first verification information from the authorization plaintext information.
[0092] The verification module 530 is configured to verify the chip identification information, the project information, the customer identity authentication information, and the authorization list information according to the first verification information.
[0093] The driving module 540 is configured to, if the verification is passed, start the first chip; otherwise, the start of the first chip fails and enters a flashing process.
[0094] Figure 6 Schematic diagram of an electronic device provided by an embodiment of the present invention, asFigure 6 As shown, the electronic device is presented in the form of a general-purpose computing device. The components of the electronic device may include, but are not limited to: one or more processors 610, a memory 630, and a communication bus 640 connecting different system components (including the memory 630 and the processing unit 610).
[0095] The communication bus 640 represents one or more of several types of bus structures, including a memory bus or a memory controller, a peripheral bus, a graphics acceleration port, a processor, or a local bus using any of the various bus structures. For example, these architectures include, but are not limited to, an Industry Standard Architecture (ISA) bus, a Micro Channel Architecture (MAC) bus, an Enhanced ISA bus, a Video Electronics Standards Association (VESA) local bus, and a Peripheral Component Interconnection (PCI) bus.
[0096] The electronic device typically includes a variety of computer system-readable media. These media can be any available media that can be accessed by the electronic device, including volatile and non-volatile media, removable and non-removable media.
[0097] The memory 630 may include computer system-readable media in the form of volatile memory, such as Random Access Memory (RAM) and / or cache memory. The electronic device may further include other removable / non-removable, volatile / non-volatile computer system storage media. Although Figure 6 not shown, a disk drive for reading and writing a removable non-volatile disk (such as a "floppy disk") and an optical disk drive for reading and writing a removable non-volatile optical disk (such as a Compact Disc Read Only Memory (CD-ROM), a Digital Video Disc Read Only Memory (DVD-ROM), or other optical media) may be provided. In these cases, each drive may be connected to the communication bus 640 through one or more data media interfaces. The memory 630 may include at least one program product having a set of (e.g., at least one) program modules configured to perform the functions of the embodiments of the present invention.
[0098] A program / util utility having a set (at least one) of program modules can be stored in the memory 630. Such program modules include—but are not limited to—an operating system, one or more application programs, other program modules, and program data. Each or some combination of these examples may include the implementation of a network environment. The program modules generally perform the functions and / or methods in the embodiments described in the present invention.
[0099] The electronic device can also communicate with one or more external devices, communicate with one or more devices that enable a user to interact with the electronic device, and / or communicate with any device that enables the electronic device to communicate with one or more other computing devices (such as a network card, a modem, etc.). Such communication can be carried out through the communication interface 620. And, the electronic device can also communicate with one or more networks (such as a Local Area Network (LAN), a Wide Area Network (WAN), and / or a public network, such as the Internet) through a network adapter ( Figure 6 not shown in the figure). The above network adapter can communicate with other modules of the electronic device through the communication bus 640. It should be understood that although Figure 6 not shown in the figure, other hardware and / or software modules can be used in combination with the electronic device, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, Redundant Arrays of Independent Drives (RAID) systems, magnetic tape drives, and data backup storage systems, etc.
[0100] The processor 610 executes various functional applications and data processing by running the programs stored in the memory 630, such as implementing the chip authorization method or the chip verification method provided by the embodiments of the present invention.
[0101] The embodiments of the present invention also provide a computer-readable storage medium. The above computer-readable storage medium stores computer instructions, and the above computer instructions cause the above computer to execute the chip authorization method or the chip verification method provided by the embodiments of the present invention.
[0102] The above computer-readable storage medium may adopt any combination of one or more computer-readable media. The computer-readable media may be a computer-readable signal medium or a computer-readable storage medium. The computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples (a non-exhaustive list) of the computer-readable storage medium include: an electrical connection having one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (hereinafter referred to as: ROM), an erasable programmable read-only memory (hereinafter referred to as: EPROM), or a flash memory, an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In this document, the computer-readable storage medium may be any tangible medium that contains or stores a program, and the program can be used by or in combination with an instruction execution system, apparatus, or device.
[0103] The computer-readable signal medium may include a data signal propagated in a baseband or as part of a carrier wave, which carries the computer-readable program code. Such a propagated data signal may take various forms, including - but not limited to - an electromagnetic signal, an optical signal, or any suitable combination of the above. The computer-readable signal medium may also be any computer-readable medium other than the computer-readable storage medium, and the computer-readable medium can send, propagate, or transmit a program for use by or in combination with an instruction execution system, apparatus, or device.
[0104] The program code contained on the computer-readable medium can be transmitted by any suitable medium, including - but not limited to - wireless, wire, optical cable, RF, etc., or any suitable combination of the above.
[0105] In the description of this specification, the description with reference to terms such as "an embodiment", "some embodiments", "an example", "a specific example", or "some examples", etc. means that the specific features, structures, materials, or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic expressions of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described can be combined in a suitable manner in any one or more embodiments or examples. In addition, without contradiction, those skilled in the art can combine and combine the different embodiments or examples described in this specification and the features of different embodiments or examples.
[0106] In addition, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, features defined with "first" and "second" may explicitly or implicitly include at least one such feature. In the description of the present invention, "a plurality of" means at least two, such as two, three, etc., unless otherwise specifically defined.
[0107] Any process or method description in a flowchart or otherwise described herein can be understood to represent a module, segment, or portion of code including one or more executable instructions for implementing a customized logical function or process, and the scope of the preferred embodiments of the present invention includes additional implementations, where the functions may be executed in a substantially simultaneous manner or in a reverse order according to the functions involved, rather than in the order shown or discussed, which should be understood by those skilled in the art to which the embodiments of the present invention pertain.
[0108] In several embodiments provided by the present invention, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division, and there may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections between each other can be through some interfaces, and the indirect couplings or communication connections of the devices or units can be in electrical, mechanical, or other forms.
[0109] In addition, each functional unit in various embodiments of the present invention can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above-mentioned integrated units can be implemented in the form of hardware or in the form of a combination of hardware and software functional units.
[0110] The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present invention shall be included within the scope of protection of the present invention.
Claims
1. A chip authorization method, characterized in that, The method includes: Receiving first authorization request information sent by a chip authorization tool, where the first authorization request information includes chip identification information, project information, and customer identity authentication information of a first chip; Generating authorization ciphertext information of the first chip according to the chip identification information, the project information, and the customer identity authentication information; Sending the authorization ciphertext information to the chip authorization tool, so that the chip authorization tool deploys the authorization ciphertext information to a secure partition of a first terminal device; Generating authorization ciphertext information of the first chip according to the chip identification information, the project information, and the customer identity authentication information includes: Determining authorization list information of the first chip according to a combination of one or more of the chip identification information, the project information, and the customer identity authentication information, where the authorization list information includes functions obtained by the first chip; Performing at least one encryption on the authorization list information to obtain the authorization ciphertext information; Performing at least one encryption on the authorization list information to obtain the authorization ciphertext information includes: generating first verification information based on the chip identification information, the project information, the customer identity authentication information, and the authorization list information; obtaining an encryption key according to the project information; encrypting the chip identification information, the project information, the customer identity authentication information, and the authorization list information through the encryption key to form the authorization ciphertext information.
2. The method according to claim 1, wherein Determining authorization list information of the first chip according to a combination of one or more of the chip identification information, the project information, and the customer identity authentication information includes: Determining the chip authorization balance according to the customer identity authentication information; If the chip authorization balance is not zero, determining the authorization list information of the first chip according to the chip identification information, and decrementing the chip authorization balance by one.
3. The method according to claim 1, wherein Determining authorization list information of the first chip according to a combination of one or more of the chip identification information, the project information, and the customer identity authentication information includes: Determining the chip authorization balance according to the customer identity authentication information; If the chip authorization balance is not zero, determining the authorization list information of the first chip according to the chip identification information and the project information, and decrementing the chip authorization balance by one.
4. A chip verification method, characterized in that, The method is applied to a terminal device and includes: After the first chip restarts, reading the authorization ciphertext information of the first chip from the secure partition; Decrypting the authorization ciphertext information through a decryption key to obtain authorization plaintext information; Determining chip identification information, project information, customer identity authentication information, authorization list information, and first verification information from the authorization plaintext information; Verifying the chip identification information, the project information, the customer identity authentication information, and the authorization list information according to the first verification information; If the verification passes, starting the first chip; otherwise, the first chip startup fails and enters a flashing process; Verify the chip identification information, the project information, the customer identity authentication information, and the authorization list information according to the first verification information, including: Generate second verification information according to the chip identification information, the project information, the customer identity authentication information, and the authorization list information; If the second verification information is consistent with the first verification information, confirm that the chip identification information, the project information, the customer identity authentication information, and the authorization list information have not been tampered with.
5. The method according to claim 4, wherein In addition to verifying the chip identification information, the project information, the customer identity authentication information, and the authorization list information according to the first verification information, the method further includes: Verify whether the authorized plaintext information has been authorized by the authentication server according to the arrangement format of the chip identification information, the project information, the customer identity authentication information, the authorization list information, and the first verification information, or according to the authentication identifier in the authorized plaintext information; Verify whether the authorized plaintext information has been authorized by the manufacturer through the secure boot process.
6. A chip authorization device, characterized in that, Including: A receiving module, configured to receive first authorization request information sent by a chip authorization tool, where the first authorization request information includes chip identification information, project information, and customer identity authentication information of a first chip; A generating module, configured to generate authorized ciphertext information of the first chip according to the chip identification information, the project information, and the customer identity authentication information; A sending module, configured to send the authorized ciphertext information to the chip authorization tool, so that the chip authorization tool deploys the authorized ciphertext information to a secure partition of a first terminal device; Generating the authorized ciphertext information of the first chip according to the chip identification information, the project information, and the customer identity authentication information includes: Determine the authorization list information of the first chip according to a combination of one or more of the chip identification information, the project information, and the customer identity authentication information, where the authorization list information includes functions obtained by the first chip; Perform at least one encryption on the authorization list information to obtain the authorized ciphertext information; The performing at least one encryption on the authorization list information to obtain the authorized ciphertext information includes: generating first verification information based on the chip identification information, the project information, the customer identity authentication information, and the authorization list information; obtaining an encryption key according to the project information; and encrypting the chip identification information, the project information, the customer identity authentication information, and the authorization list information through the encryption key to form the authorized ciphertext information.
7. A chip verification device, characterized in that, The device is applied to a terminal device and includes: A reading module, configured to read the authorized ciphertext information of the first chip from a secure area after the first chip restarts; A decrypting module, configured to decrypt the authorized ciphertext information through a decryption key to obtain authorized plaintext information; A determining module, configured to determine chip identification information, project information, customer identity authentication information, authorization list information, and first verification information from the authorized plaintext information; A verification module, configured to verify the chip identification information, the project information, the customer identity authentication information, and the authorization list information according to the first verification information; A driving module, configured to, if the verification is passed, start the first chip; otherwise, if the start of the first chip fails, enter the flashing process; Specifically, the verification module is configured to generate second verification information according to the chip identification information, the project information, the customer identity authentication information, and the authorization list information; If the second verification information is consistent with the first verification information after comparison, it is confirmed that the chip identification information, the project information, the customer identity authentication information, and the authorization list information have not been tampered with.
8. An electronic device, characterized in that, Comprising: At least one processor; And At least one memory communicatively connected to the processor, wherein: The memory stores program instructions executable by the processor, and the processor can execute the method according to any one of claims 1 to 3 or any one of claims 4 to 5 by invoking the program instructions.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions, and the computer instructions cause the computer to execute the method according to any one of claims 1 to 3 or any one of claims 4 to 5.
Citation Information
Patent Citations
Method and device for presenting plaintext information by user
CN103780390A
Chip authorization encryption and decryption method and system
CN110602140A
Embedded device, legality identification method, controller and encryption chip
CN112585608A
Cryptographic key management based on identity information
US20200313875A1
KR20190069763A