A method, system, device, and medium for chip operation
By integrating key storage, secure booting and encryption and decryption functions into one chip, the security risks and inefficiency of independent use of multiple chips in high-security applications are solved, and higher security and work efficiency are achieved.
Patent Information
- Application Number
- CN202210094973.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-01-26
- Publication Date
- 2025-08-01
- Estimated Expiration
- 2042-01-26
AI Technical Summary
In high-security applications, when the key memory chip, secure boot chip and encrypted and decrypted chip are used independently, excessive exposure of external pin signals leads to security risks and inefficiency.
The key storage chip, secure start chip and encryption and decryption chip functions are integrated into one chip, and implemented through a fusion architecture, including register configuration module, security function control module, encryption and decryption module and OTP storage module, to realize hash calculation, key management and secure startup of system data.
It improves the chip's safety performance and working efficiency, reduces the exposure of external pin signals, and enhances the system's safety and operating efficiency.
Smart Images

Figure CN114491556B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of chips, and particularly to a chip working method, system, device, and storage medium. Background Art
[0002] Currently, due to the need for information security, key secure storage chips, secure boot chips, and encryption and decryption chips have been widely studied and applied. Usually, these three types of chips are completely independent. However, in applications with higher security requirements, the three functions of key secure storage, secure boot, and encryption and decryption may be used simultaneously. When the key storage chip, secure boot chip, and encryption and decryption chip are used simultaneously in high-security applications, the excessive exposure of the external pin signals of the three independent chips will bring certain security risks. On the other hand, the application working efficiency is also relatively low. Summary of the Invention
[0003] In view of this, in order to overcome at least one aspect of the above problems, an embodiment of the present invention provides a chip working method, including the following steps:
[0004] In response to receiving a first start signal and the value of the status register being a first preset value, obtain a status identification bit in a first memory;
[0005] In response to the status identification bit being a first preset value, read a system data key number, system data, and digital signature in a second storage unit;
[0006] Obtain a corresponding key from the first memory according to the system data key number;
[0007] Perform a hash calculation on the system data to obtain a first hash value and decrypt the digital signature with the key to generate a second hash value;
[0008] In response to the first hash value and the second hash value being equal, generate a second start signal and load an operating system from the second storage unit to complete a secure boot;
[0009] In response to detecting that the value of the status register is a second preset value or a third preset value, obtain data to be encrypted and an encryption key for encryption, or obtain data to be decrypted and a decryption key for decryption.
[0010] In some embodiments, it further includes:
[0011] In response to the status identification bit being a second preset value, generate a second start signal and load an operating system from a second storage unit;
[0012] Modify the value of the status register from the first preset value to a second preset value;
[0013] Obtain key data including multiple groups of key numbers and keys and write them into the first memory to complete secure key storage and generate a first startup signal to complete system restart.
[0014] In some embodiments, in response to the status identification bit being a second preset value, generating a second startup signal and loading an operating system from a second storage unit, further including:
[0015] In response to the status identification bit being a second preset value, generating a first action signal;
[0016] Enabling the first memory according to the first action signal and generating a second action signal based on the status identification bit with a value of the second preset value in the first memory;
[0017] Outputting the second startup signal according to the second action signal.
[0018] In some embodiments, obtaining key data including multiple groups of key numbers and keys and writing them into the first memory to complete secure key storage and generate a first startup signal to complete system restart, further including:
[0019] In response to the key data being written into the first memory, generating a write completion signal;
[0020] Generating a third action signal based on the write completion signal to generate the first startup signal based on the third action signal.
[0021] Based on the same inventive concept, according to another aspect of the present invention, an embodiment of the present invention further provides a chip operating system, including:
[0022] A first acquisition module, configured to acquire a status identification bit in a first memory in response to receiving a first startup signal and the value of a status register being a first preset value;
[0023] A first reading module, configured to read a system data key number, system data, and digital signature in a second storage unit in response to the status identification bit being a first preset value;
[0024] A second acquisition module, configured to acquire a corresponding key from the first memory according to the system data key number;
[0025] A calculation module, configured to perform a hash calculation on the system data to obtain a first hash value and decrypt the digital signature using the key to generate a second hash value;
[0026] A startup module, configured to generate a second startup signal and load an operating system from the second storage unit to complete secure startup in response to the first hash value and the second hash value being equal;
[0027] An encryption / decryption module, configured to, in response to detecting that the value of the status register is the second preset value or the third preset value, obtain the data to be encrypted and an encryption key for encryption, or obtain the data to be decrypted and a decryption key for decryption.
[0028] In some embodiments, it further includes a restart module, configured to:
[0029] In response to the status identification bit being the second preset value, generate a second start signal and load an operating system from a second storage unit;
[0030] Modify the value of the status register from the first preset value to the second preset value;
[0031] Obtain key data including multiple groups of key numbers and keys, write the key data into the first memory to complete secure key storage, and generate a first start signal to complete system restart.
[0032] In some embodiments, the restart module is further configured to:
[0033] In response to the status identification bit being the second preset value, generate a first action signal;
[0034] Enable the first memory according to the first action signal, and generate a second action signal based on the status identification bit with a value of the second preset value in the first memory;
[0035] Output the second start signal according to the second action signal.
[0036] In some embodiments, the restart module is further configured to:
[0037] In response to the key data being written into the first memory, generate a write completion signal;
[0038] Generate a third action signal based on the write completion signal to generate the first start signal based on the third action signal.
[0039] Based on the same inventive concept, according to another aspect of the present invention, embodiments of the present invention further provide a computer device, including:
[0040] At least one processor; and
[0041] A memory, where the memory stores a computer program that can run on the processor, and is characterized in that when the processor executes the program, it executes the steps of any of the above-mentioned chip working methods.
[0042] Based on the same inventive concept, according to another aspect of the present invention, an embodiment of the present invention further provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, it executes the steps of any one of the above-mentioned chip working methods.
[0043] One of the beneficial technical effects of the present invention is as follows: The solution proposed by the present invention can improve the security performance and working efficiency of the chip. BRIEF DESCRIPTION OF THE DRAWINGS
[0044] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other embodiments can be obtained based on these drawings.
[0045] Figure 1 It is a flowchart of the chip working method provided by the embodiment of the present invention;
[0046] Figure 2 It is a structural diagram of the chip working system provided by the embodiment of the present invention;
[0047] Figure 3 It is a structural diagram of the computer device provided by the embodiment of the present invention;
[0048] Figure 4 It is a structural diagram of the computer-readable storage medium provided by the embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0049] To make the objectives, technical solutions, and advantages of the present invention clearer, the following further elaborates on the embodiments of the present invention in detail with reference to specific embodiments and the accompanying drawings.
[0050] It should be noted that all the expressions using "first" and "second" in the embodiments of the present invention are used to distinguish two entities or parameters with the same name but different. It can be seen that "first" and "second" are only for the convenience of expression and should not be construed as a limitation on the embodiments of the present invention. This will not be elaborated one by one in the subsequent embodiments.
[0051] According to one aspect of the present invention, an embodiment of the present invention proposes a chip working method, as Figure 1 shown, which may include the steps:
[0052] S1, in response to receiving a first start signal and the value of the status register being a first preset value, obtain the status identification bit in the first memory;
[0053] S2, in response to the status identification bit being the first preset value, read the system data key number, system data, and digital signature in the second storage unit;
[0054] S3, obtain the corresponding key from the first memory according to the system data key number;
[0055] S4, perform a hash calculation on the system data to obtain a first hash value and decrypt the digital signature using the key to generate a second hash value;
[0056] S5, in response to the first hash value and the second hash value being equal, generate a second start signal and load the operating system from the second storage unit to complete a secure start;
[0057] S6, in response to detecting that the value of the status register is the second preset value or the third preset value, obtain the data to be encrypted and the encryption key for encryption, or obtain the data to be decrypted and the decryption key for decryption.
[0058] The solution proposed by the present invention can improve the security performance and working efficiency of the chip.
[0059] In some embodiments, the functions of a key storage chip, a secure boot chip, and an encryption / decryption chip can be integrated into one chip, that is, the functions of the above three chips are implemented through a fusion architecture. For example, the subsystem fusion architecture includes four modules, namely a register configuration module, a security function control module, an encryption / decryption module, and an OTP (One Time Password) storage module (the first memory). The register configuration module includes a bus data read / write unit, an action control unit, and a data cache transfer unit. The bus data read / write unit is used to interact with an external bus, facilitating direct attachment to a certain type of protocol bus, such as the AXI (Advanced eXtensible Interface) bus (a bus protocol proposed by ARM Corporation); the action control unit contains function registers. When the status of the function registers changes, this unit can output different action signals according to the register values. Additionally, the action control unit can also read the data in the data cache transfer unit and output corresponding action signals according to the data values; the data cache transfer unit, when continuous data needs to be input from the outside into the architecture, this unit first obtains the bus data from the bus data read / write unit and caches it, and then outputs the data to the encryption / decryption module or the OTP storage module according to the action signals of the action control unit. When continuous data needs to be output from the architecture to the outside, this unit first reads the data from the encryption / decryption module or the OTP storage module according to the action signals of the action control unit, caches the data, and then transfers the cached data to the bus data read / write unit for output. The OTP storage module includes an OTP read / write logic generation unit and an OTP physical memory. The OTP read / write logic generation unit is used to convert the read / write signals transmitted by the register configuration module into logic signals recognizable by the OTP physical memory. The OTP physical memory is a one-time programmable memory that can store encryption / decryption key numbers and corresponding keys. The encryption / decryption module includes a hash calculation unit, an RSA (a cryptographic system proposed by Ron Rivest, Adi Shamir, and Leonard Adleman) encryption unit, and an RSA decryption unit. The security function control module includes an enable control unit and a control signal output unit. Among them, the enable control unit can enable and disable the hash calculation unit, RSA encryption unit, RSA decryption unit in the encryption / decryption module, and the OTP read / write logic generation unit and OTP physical memory in the OTP storage module; the control signal output unit can correspondingly output a system reset signal, a system start signal, a hash calculation status signal, an encryption calculation status signal, a decryption calculation status signal, and a system data digital signature verification status signal according to the action signals output by the action control unit in the register configuration module.
[0060] In some embodiments, in step S1, in response to receiving a first start signal and the value of the status register being a first preset value, obtain the status identification bit in the first memory. Specifically, when the system starts, the value of the status indication register in the action control unit of the register configuration module is 0x00; the action control unit in the register configuration module outputs an OTP data judgment action signal (the first start signal) according to 0x00; the security function control module enables the OTP read / write logic generation unit and the OTP physical memory according to this action signal; the data cache transfer unit of the register configuration module reads the status identification bit in the OTP memory according to the OTP data judgment action signal. When the key number and the key have not been written into the OTP, this status identification bit is 0, and when the key number and the key have been written, this status identification bit is 1.
[0061] In some embodiments, in step S2, in response to the status identification bit being the first preset value, read the system data key number, system data, and digital signature in the second storage unit. Specifically, when the status identification bit in the OTP memory is 1, the action control unit outputs a secure start key number read signal; then the data cache transfer unit reads the system data key number in the Flash (the second storage unit) through the bus data read / write unit according to this action signal (the system data key number, system data, digital signature, and the key number written into the OTP are in one-to-one correspondence in the Flash, and the digital signature is obtained by encrypting the hash value of the system data with the private key of a certain number).
[0062] In some embodiments, in step S3, obtain the corresponding key from the first memory according to the system data key number. Specifically, when the action control unit obtains this key number, it generates an OTP key read action signal; the enable control unit of the security function control module enables the hash calculation unit and the RSA decryption unit. The data cache transfer unit reads the key with the corresponding number from the OTP according to this action signal and transmits the key value to the RSA decryption unit, and the action control unit generates a secure start data verification action signal.
[0063] In some embodiments, in step S4, a hash calculation is performed on the system data to obtain a first hash value, and the digital signature is decrypted using the key to generate a second hash value. Specifically, the data cache transmission unit reads the system data and the system data digital signature in the Flash through the bus data reading and writing unit, and transmits them to the hash calculation unit and the RSA decryption unit respectively. The hash calculation unit performs a hash calculation on the system data to obtain a hash value H1, and the RSA decryption unit decrypts the system digital signature using the read key to generate a hash value H2, and compares whether H1 is equal to H2, and transmits the comparison result to the action control unit through the control signal data cache transmission unit. If the two are equal, the action control unit outputs a system start action signal. If they are not equal, the action control unit outputs a system reset action signal
[0064] In some embodiments, in step S5, in response to the first hash value and the second hash value being equal, a second start signal is generated and the operating system is loaded from the second storage unit to complete the secure start. Specifically, if the security function control module receives the system reset action signal, it outputs a system reset signal (second start signal), and the system restarts. If the security function control module receives the system start action signal, it outputs a system start signal. After receiving the system start signal, the CPU core loads the operating system from the Flash and starts normally. At this time, the secure start function has been completed.
[0065] In some embodiments, in step S6, in response to detecting that the value of the status register is the second preset value or the third preset value, the data to be encrypted and the encryption key are obtained for encryption, or the data to be decrypted and the decryption key are obtained for decryption. Specifically, when the CPU writes the value of the status indication register to 0x02, that is, the continuous encryption state, through the bus data reading and writing unit of the register configuration module, the action control unit outputs a continuous encryption action signal; then the data cache transmission unit reads the encryption key and the data to be encrypted on the bus through the bus data reading and writing unit, and transmits them to the RSA encryption unit; then the RSA encryption unit performs a continuous encryption calculation using the key and outputs an encryption calculation status signal to the data cache transmission unit; finally, the action control unit obtains the encryption calculation status signal from the data cache transmission unit and outputs an encryption status indication action signal, and the control signal output unit of the security function control module outputs a corresponding encryption status signal.
[0066] For the decryption calculation, only write the status register to 0x03 and perform similar steps as above.
[0067] In some embodiments, it further includes:
[0068] In response to the status identification bit being the second preset value, a second start signal is generated and the operating system is loaded from the second storage unit;
[0069] Modify the value of the status register from the first preset value to the second preset value;
[0070] Obtain key data including multiple groups of key numbers and keys, write it into the first memory to complete secure key storage, and generate a first startup signal to complete system restart.
[0071] In some embodiments, in response to the status identification bit being the second preset value, generating a second startup signal and loading an operating system from a second storage unit, further comprising:
[0072] In response to the status identification bit being the second preset value, generating a first action signal;
[0073] Enable the first memory according to the first action signal, and generate a second action signal based on the status identification bit with a value of the second preset value in the first memory;
[0074] Output the second startup signal according to the second action signal.
[0075] In some embodiments, obtaining key data including multiple groups of key numbers and keys, writing it into the first memory to complete secure key storage, and generating a first startup signal to complete system restart, further comprising:
[0076] In response to the key data being written into the first memory, generating a write completion signal;
[0077] Generate a third action signal based on the write completion signal to generate the first startup signal based on the third action signal.
[0078] Specifically, when the system is started for the first time, the value of the status indication register in the action control unit of the register configuration module is 0x00; the action control unit in the register configuration module outputs an OTP data judgment action signal (the first action signal) according to 0x00; the security function control module enables the OTP read / write logic generation unit and the OTP physical memory according to this action signal; since the key number and the key have not been written into the OTP yet, the status identification bit is 0. After the action control unit reads that this bit is 0, it outputs a system start action signal (the second action signal); at this time, the control signal output unit of the security function control module outputs a system start signal (the second start signal) according to this action signal; when the CPU core receives the system start signal, it loads the operating system from the Flash and starts normally, and then writes the value of the status indication register as 0x01 through the bus data read / write unit of the register configuration module. This status is the key write status, and the action control unit outputs an OTP write data action signal; finally, the data cache transfer unit transmits the key data received by the bus data read / write unit from the CPU to the OTP storage module according to this action signal, writes N groups of key numbers and keys into the OTP physical memory. After the writing is completed, the OTP storage module sends a writing completion signal to the data cache transfer unit. After the action control unit reads this signal, it outputs a system reset action signal (the third action signal). At this time, the key security storage function has been completed. The control signal output unit of the security function control module outputs a system reset signal (the first start signal) according to this action signal.
[0079] The solution proposed by the present invention can improve the security performance and working efficiency of the chip by integrating the key storage chip, the secure boot chip, and the encryption / decryption chip into one chip.
[0080] Based on the same inventive concept, according to another aspect of the present invention, an embodiment of the present invention further provides a chip operating system 400, as Figure 2 shown, including:
[0081] A first acquisition module 401, configured to acquire a status identification bit in the first memory in response to receiving a first start signal and the value of the status register being a first preset value;
[0082] A first reading module 402, configured to read the system data key number, the system data, and the digital signature in the second storage unit in response to the status identification bit being a first preset value;
[0083] A second acquisition module 403, configured to acquire a corresponding key from the first memory according to the system data key number;
[0084] A computing module 404, configured to perform a hash calculation on the system data to obtain a first hash value and decrypt the digital signature using the key to generate a second hash value;
[0085] A startup module 405, configured to generate a second startup signal and load an operating system from the second storage unit to complete a secure startup in response to the first hash value being equal to the second hash value;
[0086] An encryption / decryption module 406, configured to encrypt the data to be encrypted and an encryption key or decrypt the data to be decrypted and a decryption key in response to detecting that the value of the status register is a second preset value or a third preset value.
[0087] In some embodiments, it further includes a restart module, configured to:
[0088] Generate a second startup signal and load an operating system from a second storage unit in response to the status identification bit being a second preset value;
[0089] Modify the value of the status register from the first preset value to the second preset value;
[0090] Obtain key data including multiple groups of key numbers and keys and write them into the first memory to complete secure key storage and generate a first startup signal to complete system restart.
[0091] In some embodiments, the restart module is further configured to:
[0092] Generate a first action signal in response to the status identification bit being a second preset value;
[0093] Enable the first memory according to the first action signal and generate a second action signal based on the status identification bit with a value of the second preset value in the first memory;
[0094] Output the second startup signal according to the second action signal.
[0095] In some embodiments, the restart module is further configured to:
[0096] Generate a completion write signal in response to the key data being written into the first memory;
[0097] Generate a third action signal based on the completion write signal to generate the first startup signal based on the third action signal.
[0098] Based on the same inventive concept, according to another aspect of the present invention, as Figure 3 shown, an embodiment of the present invention further provides a computer device 501, including:
[0099] at least one processor 520; and
[0100] a memory 510 storing a computer program 511 executable on the processor, and when the processor 520 executes the program, it performs the steps of any of the above chip working methods.
[0101] Based on the same inventive concept, according to another aspect of the present invention, as Figure 4 shown, an embodiment of the present invention further provides a computer-readable storage medium 601 storing computer program instructions 610, and when the computer program instructions 610 are executed by a processor, they perform the steps of any of the above chip working methods.
[0102] Finally, it should be noted that those of ordinary skill in the art can understand that all or part of the processes of implementing the above method embodiments can be completed by instructing relevant hardware through a computer program. The program can be stored in a computer-readable storage medium, and when the program is executed, it can include the processes of the embodiments of the above methods.
[0103] In addition, it should be understood that the computer-readable storage medium herein (e.g., memory) can be a volatile memory or a non-volatile memory, or can include both volatile memory and non-volatile memory.
[0104] Those skilled in the art will also understand that the various exemplary logical blocks, modules, circuits, and algorithm steps described in connection with the disclosure herein can be implemented as electronic hardware, computer software, or a combination of both. To clearly illustrate this interchangeability of hardware and software, the functions of the various illustrative components, blocks, modules, circuits, and steps have been generally described. Whether this function is implemented as software or as hardware depends on the specific application and the design constraints imposed on the overall system. The functions that those skilled in the art can implement in various ways for each specific application, but this implementation decision should not be construed as causing a departure from the scope of the disclosure of the embodiments of the present invention.
[0105] The above are the exemplary embodiments disclosed by the present invention. However, it should be noted that various changes and modifications can be made without departing from the scope of the disclosure of the embodiments of the present invention defined by the claims. The functions, steps, and / or actions of the method claims according to the disclosed embodiments herein do not need to be performed in any specific order. In addition, although the elements disclosed in the embodiments of the present invention can be described or claimed in an individual form, they can also be understood as plural unless explicitly limited to the singular.
[0106] It should be understood that, as used herein, unless the context clearly supports the exception, the singular form "a" is intended to also include the plural form. It should also be understood that the "and / or" used herein refers to any and all possible combinations of one or more of the associated listed items.
[0107] The serial numbers of the disclosed embodiments of the present invention above are only for description and do not represent the superiority or inferiority of the embodiments.
[0108] Those of ordinary skill in the art can understand that all or part of the steps to implement the above embodiments can be completed by hardware, or can be completed by instructing relevant hardware through a program. The program can be stored in a computer-readable storage medium, and the above-mentioned storage medium can be a read-only memory, a magnetic disk or an optical disc, etc.
[0109] Those of ordinary skill in the art should understand that: the discussion of any of the above embodiments is only exemplary and is not intended to imply that the scope of the disclosure of the embodiments of the present invention (including the claims) is limited to these examples; under the idea of the embodiments of the present invention, the technical features between the above embodiments or different embodiments can also be combined, and there are many other variations in different aspects of the above embodiments of the present invention, which are not provided in detail for the sake of brevity. Therefore, any omission, modification, equivalent replacement, improvement, etc. made within the spirit and principle of the embodiments of the present invention shall be included in the protection scope of the embodiments of the present invention.
Claims
1. A method for a chip to work, characterized in that, Integrate the functions of a key storage chip, a secure boot chip, and an encryption / decryption chip into one chip, including the following steps: In response to receiving an OTP data judgment action signal and the value of the status register being a first preset value, obtain the status identification bit in the OTP memory; In response to the status identification bit being a first preset value, read the system data key number, system data, and digital signature in the Flash; Obtain the corresponding key from the OTP memory according to the system data key number; Perform a hash calculation on the system data to obtain a first hash value and decrypt the digital signature using the key to generate a second hash value; In response to the first hash value and the second hash value being equal, generate a system reset signal and load the operating system from the Flash to complete a secure boot; In response to the status identification bit being a second preset value, generate a system reset signal and load the operating system from the Flash; Modify the value of the status register from the first preset value to the second preset value; Obtain key data including multiple groups of key numbers and keys and write it into the OTP memory to complete secure key storage and generate a system reset signal to complete a system restart; In response to detecting that the value of the status register is the second preset value or the third preset value, obtain the data to be encrypted and an encryption key for encryption, or, obtain the data to be decrypted and a decryption key for decryption.
2. The method according to claim 1, characterized in that, In response to the status identification bit being a second preset value, generate a system reset signal and load the operating system from the Flash, further including: In response to the status identification bit being a second preset value, generate a first action signal; Enable the OTP memory according to the first action signal and generate a second action signal based on the status identification bit with a value of the second preset value in the OTP memory; Output the system reset signal according to the second action signal.
3. The method according to claim 1, wherein Obtain key data including multiple groups of key numbers and keys and write it into the OTP memory to complete secure key storage and generate a system reset signal to complete a system restart, further including: In response to the key data being written into the OTP memory, generate a write completion signal; Generate a third action signal based on the write completion signal to generate the system reset signal based on the third action signal.
4. A chip operating system, characterized in that, Integrate the functions of a key storage chip, a secure boot chip, and an encryption / decryption chip into one chip, including: A first acquisition module configured to obtain the status identification bit in the OTP memory in response to receiving an OTP data judgment action signal and the value of the status register being a first preset value; A first reading module configured to read the system data key number, system data, and digital signature in the Flash in response to the status identification bit being a first preset value; A second acquisition module configured to obtain the corresponding key from the OTP memory according to the system data key number; A calculation module configured to perform a hash calculation on the system data to obtain a first hash value and decrypt the digital signature using the key to generate a second hash value; The startup module is configured to generate a system reset signal and load an operating system from the Flash to complete a secure startup in response to the equality of the first hash value and the second hash value; The encryption / decryption module is configured to encrypt the data to be encrypted and an encryption key or decrypt the data to be decrypted and a decryption key in response to detecting that the value of the status register is a second preset value or a third preset value; It further includes a restart module configured to: Generate a system reset signal and load an operating system from the Flash in response to the status identification bit being a second preset value; Modify the value of the status register from the first preset value to the second preset value; Obtain key data including multiple groups of key numbers and keys, write the key data into the OTP memory to complete secure key storage, and generate a system reset signal to complete system restart.
5. The system according to claim 4, wherein The restart module is further configured to: Generate a first action signal in response to the status identification bit being a second preset value; Enable the OTP memory according to the first action signal and generate a second action signal based on the status identification bit with a value of the second preset value in the OTP memory; Output the system reset signal according to the second action signal.
6. The system according to claim 4, wherein The restart module is further configured to: Generate a write completion signal in response to the key data being written into the OTP memory; Generate a third action signal based on the write completion signal to generate the system reset signal based on the third action signal.
7. A computer device, comprising: At least one processor; And A memory storing a computer program that can run on the processor, wherein when the processor executes the program, it performs the steps of the method according to any one of claims 1-3.
8. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by the processor, it performs the steps of the method according to any one of claims 1-3.
Citation Information
Patent Citations
Set top box chip and digital signature implementation method applied to same
CN103974122A
System on chip to perform a secure boot, an image forming apparatus using the same, and method thereof
CN104871169A