A cipher module, a cipher operation method, a CPU chip and an electronic device
By integrating a security processor and a cryptographic coprocessor into the CPU chip, the problems of high cost and poor security of external cryptographic cards are solved, achieving the effect of reducing costs and enhancing security.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- HYGON YUNXIN INTEGRATED CIRCUIT DESIGN (SHANGHAI) CO LTD
- Filing Date
- 2022-04-13
- Publication Date
- 2026-05-05
AI Technical Summary
Existing dedicated external cryptographic cards for cryptographic modules suffer from high hardware costs and poor security, especially since they are vulnerable to physical attacks when connected to the CPU via an external bus.
The CPU chip integrates a security processor and a cryptographic coprocessor. The security processor is responsible for key management and cryptographic operations, while the running code and data are stored in secure memory outside the CPU and protected by hardware encryption and consistency to reduce external exposure.
It reduces system hardware costs, enhances security, reduces the risk of physical attacks, and achieves efficient cryptographic computation capabilities.
Smart Images

Figure CN114722410B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of information security technology, and in particular to a cryptographic module, a cryptographic operation method, a CPU chip, and an electronic device. Background Technology
[0002] In cryptographic applications such as cryptographic machines, dedicated cryptographic modules are often required. In addition to providing efficient cryptographic computing capabilities, these modules also need to provide key management functions to ensure key security.
[0003] Currently, the commonly used cryptographic modules are dedicated cryptographic cards, such as... Figure 1 As shown. The password card is inserted into the system motherboard and connected to the CPU via the PCIe bus, thus implementing the functions of the aforementioned password module. However, external dedicated password cards typically have the following main drawbacks:
[0004] In terms of cost, the password card requires additional hardware, which increases hardware costs;
[0005] In terms of security, the password card is connected to the CPU entirely through an external bus, which increases the exposure surface and makes it vulnerable to bus-based physical attacks. Summary of the Invention
[0006] In view of this, embodiments of the present invention provide a cryptographic module, a cryptographic operation method, a CPU chip, and an electronic device to reduce the cost of cryptographic module design and enhance its security.
[0007] In a first aspect, embodiments of the present invention provide a cryptographic module, the cryptographic module being built into a CPU and isolated from the CPU processing core, the cryptographic module comprising:
[0008] The security processor is used to receive cryptographic service requests sent by the CPU processing core, obtain the internal key, and send the internal key to the cryptographic coprocessor.
[0009] The cryptographic coprocessor is used to read the source data corresponding to the cryptographic service request from the system memory, respond to the cryptographic service based on the internal key and the source data, and store the response result in the system memory.
[0010] The code and data stored during the operation of the security processor are stored in secure memory outside the CPU. When the security processor accesses secure memory, the accessed content is encrypted and protected for consistency by hardware.
[0011] Optionally, the security processor is used to obtain the internal key, specifically including:
[0012] The security processor reads the internal key from a secure non-volatile memory outside the CPU, whereby the security processor encrypts and protects the accessed content when accessing the secure non-volatile memory.
[0013] Optionally, the security processor is used to obtain the internal key, specifically including:
[0014] The security processor reads the key image from system memory, decrypts the key image, and uses it as the internal key after passing a consistency check.
[0015] The key image in the system memory is pre-read from the hard disk file system by the CPU processing core.
[0016] Optional, the security processor is also used for:
[0017] It communicates with the CPU core via a management interface for internal key management.
[0018] Based on the CPU core's internal key management operations, manage the internal keys in the secure non-volatile memory outside the CPU; or...
[0019] Based on the internal key management operations of the CPU core, manage the internal key image in system memory; when the internal key image is updated, instruct the CPU core to update the updated internal key image to the hard disk file system.
[0020] Optionally, when the internal key management operation is an export / import internal key operation, the security processor is specifically used for:
[0021] A protection key is generated by combining confidential information within the chip with the internal key management operation password;
[0022] Use a protection key to encrypt and protect the consistency of the internal key that needs to be exported;
[0023] Alternatively, a protection key can be used to decrypt and verify the consistency of the internal key that needs to be imported.
[0024] Optionally, the security processor is also used to: negotiate communication keys with user applications on the CPU core through a business interface and establish a secure session;
[0025] Within the context of this secure session, user applications on the secure processor and CPU core use communication keys to encrypt and decrypt cryptographic service communication data.
[0026] Secondly, embodiments of the present invention provide a cryptographic operation method applied to a security processor, the method comprising:
[0027] Receive cryptographic service requests sent by the CPU processing core;
[0028] Obtain the internal key;
[0029] Send the internal key to the cryptographic coprocessor, instructing the cryptographic coprocessor to: read the source data corresponding to the cryptographic service request from the system memory, respond to the cryptographic service based on the internal key and the source data, and store the response result in the system memory;
[0030] The code and data stored during the operation of the security processor are stored in secure memory outside the CPU. When the security processor accesses secure memory, the accessed content is encrypted and protected for consistency by hardware.
[0031] Optionally, obtain the internal key, specifically including:
[0032] The internal key is read from a secure non-volatile memory outside the CPU, where the accessed content is encrypted and protected for consistency.
[0033] Optionally, obtain the internal key, specifically including:
[0034] Read the key image from system memory, decrypt the key image and use it as the internal key after passing the consistency check;
[0035] The key image in the system memory is pre-read from the hard disk file system by the CPU processing core.
[0036] Optionally, the method further includes:
[0037] It communicates with the CPU core via a management interface for internal key management.
[0038] Based on the CPU core's internal key management operations, manage the internal keys in the secure non-volatile memory outside the CPU; or...
[0039] Based on the internal key management operations of the CPU core, manage the internal key image in system memory; when the internal key image is updated, instruct the CPU core to update the updated internal key image to the hard disk file system.
[0040] Optionally, when the internal key management operation is an export / import internal key operation, the internal key management includes:
[0041] A protection key is generated by combining confidential information within the chip with the internal key management operation password;
[0042] Use a protection key to encrypt and protect the consistency of the internal key that needs to be exported;
[0043] Alternatively, a protection key can be used to decrypt and verify the consistency of the internal key that needs to be imported.
[0044] Optionally, the method further includes negotiating a communication key with the user application on the CPU core through a business interface to establish a secure session;
[0045] Within the context of this secure session, user applications on the secure processor and CPU core use communication keys to encrypt and decrypt cryptographic service communication data.
[0046] Thirdly, embodiments of the present invention provide a central processing unit (CPU) chip, comprising: a CPU processing core; and a cryptographic module as described in the first aspect above.
[0047] Fourthly, embodiments of the present invention provide an electronic device, the electronic device comprising: a housing, a processor, a memory, a circuit board, and a power supply circuit, wherein the circuit board is disposed within the space enclosed by the housing, and the processor and the memory are disposed on the circuit board; the power supply circuit is used to supply power to various circuits or devices of the electronic device; the memory is used to store executable program code; the processor runs a program corresponding to the executable program code by reading the executable program code stored in the memory, for executing the method described in the second aspect above.
[0048] The technical solution provided by the embodiments of the present invention makes full use of the cost-effectiveness advantage of integrated circuits. By integrating a security processor and a dedicated cryptographic coprocessor inside the CPU chip, the function of a general cryptographic module is realized. On the one hand, the system hardware cost and complexity are reduced. On the other hand, the security processor and the dedicated cryptographic coprocessor are both located inside the CPU chip and isolated from the CPU processing core, reducing the external exposure and enhancing security. Attached Figure Description
[0049] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0050] Figure 1 This is a schematic diagram of the hardware structure of an external cryptographic card for CPU in the prior art;
[0051] Figure 2 A schematic diagram of an overall hardware architecture applicable to an embodiment of the present invention;
[0052] Figure 3 A schematic diagram of a hardware architecture for storing internal keys in off-chip non-volatile memory, provided for an embodiment of the present invention;
[0053] Figure 4 A schematic diagram of a hardware architecture for storing internal keys on a hard disk, provided for an embodiment of the present invention;
[0054] Figure 5 A schematic diagram of a software architecture for implementing cryptographic service and key management on an SP, provided in an embodiment of the present invention;
[0055] Figure 6 This is a schematic diagram of an internal key import / export protection scheme provided by an embodiment of the present invention;
[0056] Figure 7 A schematic diagram of secure session access provided in an embodiment of the present invention;
[0057] Figure 8 This is a schematic diagram of a cryptographic operation method provided in an embodiment of the present invention;
[0058] Figure 9 This is a schematic diagram of an electronic device structure provided in an embodiment of the present invention. Detailed Implementation
[0059] The embodiments of the present invention will now be described in detail with reference to the accompanying drawings.
[0060] It should be understood that the described embodiments are merely some, not all, of the embodiments of the present invention. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without inventive effort are within the scope of protection of the present invention.
[0061] First, a brief explanation of some of the terms used in the embodiments of this invention will be given.
[0062] CCP: CryptoCo-Processor, a cryptographic coprocessor integrated within a CPU chip;
[0063] CEK: Chip Endorsement Key. The private key is located inside the chip and contains confidential information. The public key has a public key certificate issued by the manufacturer or an authoritative third party to prove the authenticity of the chip's identity.
[0064] SP: Secure Processor, a security processor integrated within the CPU chip, primarily responsible for handling CPU security-related tasks.
[0065] The technical solution of the present invention will be described in detail below through various embodiments.
[0066] Example 1
[0067] This embodiment provides a cryptographic module suitable for, for example, Figure 2The overall hardware architecture is shown. In this hardware architecture, in addition to the original computing core (taking the x86 core as an example in the figure) 200 inside the CPU chip, a cryptographic module (security processor SP 201 and cryptographic coprocessor CCP 202) is also integrated. Outside the CPU chip, there are system memory 203 and security memory 204.
[0068] SP receives cryptographic service requests sent by the CPU core, obtains the internal key, and sends the internal key to the cryptographic coprocessor.
[0069] CCP reads the source data corresponding to the cryptographic service request from the system memory, responds to the cryptographic service based on the internal key and the source data, and stores the response result in the system memory.
[0070] The SP's runtime code and data are stored in secure memory outside the CPU. This secure memory belongs to the SP and is inaccessible to the CPU core. To prevent memory-related physical attacks, hardware encrypts and protects the accessed content when the SP accesses the secure memory. The cryptographic service can perform cryptographic operations. The CCP is primarily responsible for implementing various cryptographic algorithms, providing efficient cryptographic operation capabilities. The CCP can directly read source data from system memory, and after completing the operation, put the result data back into system memory, ensuring efficient cryptographic operations. The process of generating the cryptographic service response result is existing technology and will not be elaborated here.
[0071] The cryptographic module's internal keys include internal keys, which are maintained by the administrator and assigned to specific users. These internal keys have the following attributes:
[0072] The internal key has access control checks and is further divided into device key and user key;
[0073] The device key is bound to the device and is unique to each device, representing the device's identity information;
[0074] User keys can include symmetric keys and asymmetric keys. Symmetric keys and asymmetric keys can typically be used to encrypt or decrypt user-generated or imported session keys. Asymmetric keys are also used to sign and verify user data.
[0075] User keys use a fixed key index, and users can access their assigned user keys by specifying the index.
[0076] The session key is a key that is temporarily generated during a user's session or imported from an external source. It can be of any type (symmetric or asymmetric), and the user uses it to perform any desired key operations (encryption, decryption, signature verification, etc.). The session key is automatically destroyed once the session ends. Users can access their own session key within a session using either an index or a handle.
[0077] Internal keys must be persistent and not lost when power is off, thus requiring persistent storage, i.e., non-volatile storage. Typically, the non-volatile storage space inside a CPU chip is very limited; when on-chip non-volatile storage cannot meet the requirements, off-chip storage is necessary. As a specific implementation method, such as... Figure 3 As shown, a dedicated secure non-volatile memory (SRAM) connected to the SP is deployed outside the CPU chip. Figure 3 Specifically, this refers to secure flash memory, where the internal key is stored. The SP can directly read or write the internal key from this dedicated secure non-volatile memory. To prevent physical attacks on the dedicated secure non-volatile memory, the internal key stored therein requires encryption and consistency protection.
[0078] Considering that using off-chip secure non-volatile memory would lead to additional hardware requirements and potentially limited storage space, this embodiment proposes another implementation method. The internal key is stored in the hard disk file system via the CPU core. The SP obtains the internal key by: the SP reading the key image from system memory, decrypting the key image, and using it as the internal key after passing a consistency check. The key image in system memory is pre-read by the CPU core from the hard disk file system. The key image contains all internal keys that need persistent storage and is encrypted and protected for consistency both on the hard disk and in system memory. The confidential information of the required keys is generated internally by the SP and cannot be known externally. In specific implementations, such as... Figure 4 As shown:
[0079] ① When the system starts up, the CPU core reads the saved key image from the hard disk file system;
[0080] ②The CPU processing core loads the key image into system memory and notifies the SP of the relevant address information;
[0081] ③SP has direct access to system memory. When needed, it can directly read the required key from system memory in the required format, and then use it after decryption and verification of consistency within SP.
[0082] Example 2
[0083] This embodiment optimizes the SP's interface division, key management, and secure session functions based on the technical solution provided in Embodiment 1. For example... Figure 5As shown in this embodiment, the interfaces provided by the SP can be divided into two categories: "business" interfaces and "management" interfaces. The business interfaces are used by upper-layer users and mainly provide functions related to cryptographic business service processing and session key management, such as encryption / decryption, signature verification, HMAC (Hash-based Message Authentication Code) verification, generation of symmetric or asymmetric session keys, and importing or exporting session keys. The management interfaces are used by device administrators and mainly provide internal key and device management functions. The following details the SP's internal key management and cryptographic business service functions.
[0084] 1. Internal Key Management
[0085] SP and CPU core communicate through a management interface for internal key management.
[0086] SP manages the internal keys in the secure non-volatile memory outside the CPU based on the CPU's internal key management operations; or...
[0087] SP manages the internal key image in system memory based on the internal key management operation of the CPU core; when the internal key image is updated, it instructs the CPU core to update the updated internal key image to the hard disk file system.
[0088] Internal key management operations can include adding, deleting, or updating internal keys, modifying access passwords for internal keys, importing or exporting internal keys, and setting management access permissions.
[0089] For example, such as Figure 4 As shown, ④ when the internal key needs to be updated, the SP will write the encrypted and consistency-protected internal key into the key image in the system memory; ⑤ when needed, if the internal key in the system memory has been updated, the CPU processing core will read the key image in the system memory and write it to the hard disk file system.
[0090] For example, when the internal key management operation is an export / import internal key operation, the SP is specifically used for:
[0091] A protection key is generated by combining confidential information within the chip with the internal key management operation password;
[0092] Use a protection key to encrypt and protect the consistency of the internal key that needs to be exported;
[0093] Alternatively, a protection key can be used to decrypt and verify the consistency of the internal key that needs to be imported.
[0094] In practical applications, cryptographic modules often have requirements for key backup and recovery. These requirements cause internal keys to leave the trusted SP (Secure Provider) area, thus necessitating protection. To address this, this embodiment provides a joint protection scheme based on on-chip confidential information and off-chip administrator passwords, such as... Figure 6 As shown, a unified on-chip confidential information is set within the CPU chip. This confidential information is the same across different CPU chips (which can be from the same product series). When an administrator exports the internal key, they enter a password. The SP then combines the on-chip confidential information and the password entered by the administrator to generate the required protection key. This protection key is used to encrypt and protect the exported internal key. The process of importing a key from the outside is similar to the export process. The same protection key is generated, and then the imported key is decrypted and its consistency is verified using the protection key. This key protection scheme ensures that the exported internal key must be recovered by a legitimate administrator within the actual SP cryptographic module, preventing the risk of plaintext password exposure and unauthorized use. For example, after encrypting and protecting the internal key to be exported, an internal key image is generated. This image contains the internal key as a file and exists outside the SP. Correspondingly, when importing an internal key, the internal key image existing outside the SP is imported, and the internal key contained in the image is decrypted and protected for consistency.
[0095] 2. Cryptographic Service Processing
[0096] In this embodiment, the user application on the CPU core accesses the cryptographic service of the cryptographic module through the business interface. To ensure the security of the access process, such as... Figure 7 As shown, the SP and the user application on the CPU core negotiate a communication key through a business interface to establish a secure session. Subsequently, within this secure session, the SP and the user application on the CPU core communicate via cryptographic services. During this communication: the user application on the CPU core requests the SP to open and obtain access to its internal key; the SP provides cryptographic computation services to the user application on the CPU core based on the internal key; and the SP returns the results of the cryptographic computation services to the CPU core. During communication, the cryptographic service communication data exchanged between the SP and the user application on the CPU core uses the communication key for encryption and decryption. In other words, the communication key of the secure session is used to protect the communication between the user application and the SP; generally, the communication key is a symmetric key. After the cryptographic computation service access is completed, the internal key is closed, the secure session is destroyed, and all confidential information generated during the access process is also destroyed.
[0097] This embodiment uses a secure session-based access method, ensuring that accessed content is not stolen or tampered with externally, and that external parties cannot forge access to the cryptographic module. After access ends, the secure session is destroyed, and all confidential information generated during the access process is also destroyed. Furthermore, as an optional solution, the SP has its own CEK public key certificate to prove its identity. When a user application needs to access key-based service services, such as... Figure 7 As shown, before establishing a secure session, user applications can verify the authenticity of the other party's identity by verifying the CEK public key certificate, thus preventing the risks associated with using fake cryptographic modules.
[0098] In this embodiment, the SP module is mainly responsible for the management of confidential information such as keys and the implementation of related interfaces of the cryptographic module, and has the following characteristics:
[0099] It has its own dedicated hardware resources and is a reliable execution environment in itself, whose operation is not affected by the CPU's computing core;
[0100] All software running on the SP module is verified by relevant security mechanisms (such as digital signatures) to ensure that it is trustworthy;
[0101] The CPU core communicates with the SP through an internal hardware interface. The CPU core can only call the functions pre-defined by the SP. Calling non-pre-defined functions will be directly rejected by the SP.
[0102] SP has a built-in chip endorsement key CEK. The CEK private key is the chip's confidential information and cannot be known to outsiders. Each CEK has a public CEK public key certificate to prove its authenticity.
[0103] Example 3
[0104] This embodiment provides a cryptographic operation method, applicable to, for example... Figure 2 The security processor SP in the cryptographic module shown. See also Figure 8 Cryptographic operations include:
[0105] Step 801: Receive the cryptographic service request sent by the CPU processing core;
[0106] Step 802: Obtain the internal key;
[0107] Step 803: Send the internal key to the cryptographic coprocessor, instructing the cryptographic coprocessor to: read the source data corresponding to the cryptographic service request from the system memory, respond to the cryptographic service based on the internal key and the source data, and store the response result in the system memory;
[0108] The code and data stored during the operation of the security processor are stored in secure memory outside the CPU. When the security processor accesses secure memory, the accessed content is encrypted and protected for consistency by hardware.
[0109] As one specific implementation, obtaining the internal key includes: reading the internal key from a secure non-volatile memory outside the CPU, wherein the accessed content is encrypted and protected for consistency when accessing the secure non-volatile memory.
[0110] Accordingly, the cryptographic operation method in this embodiment may also include the following steps: communicating with the CPU core through a management interface for internal key management; and managing the internal key in the secure non-volatile memory outside the CPU according to the internal key management operation of the CPU core.
[0111] As another specific implementation method, obtaining the internal key specifically includes: reading the key image from the system memory, decrypting the key image and using it as the internal key after passing the consistency check; wherein, the key image in the system memory is pre-read by the CPU processing core from the hard disk file system.
[0112] Accordingly, the cryptographic operation method in this embodiment may also include the following steps: communicating with the CPU core through a management interface for internal key management; managing the internal key image in system memory according to the internal key management operation of the CPU core; and instructing the CPU core to update the updated internal key image to the hard disk file system when the internal key image is updated.
[0113] For example, when the internal key management operation is an export / import internal key operation, the internal key management may include the following steps:
[0114] A protection key is generated by combining confidential information within the chip with the internal key management operation password;
[0115] Use a protection key to encrypt and protect the consistency of the internal key that needs to be exported;
[0116] Alternatively, a protection key can be used to decrypt and verify the consistency of the internal key that needs to be imported.
[0117] For example, the method further includes: negotiating a communication key with a user application on the CPU core through a business interface to establish a secure session;
[0118] Within the context of this secure session, user applications on the CPU core use communication keys to encrypt and decrypt cryptographic service communication data.
[0119] The cryptographic operation method provided in this embodiment belongs to the same inventive concept as the aforementioned cryptographic module embodiment. Technical details not described in this embodiment can be found in the relevant descriptions in the aforementioned method embodiments, and will not be repeated here.
[0120] In addition, this embodiment of the invention also provides a CPU chip, which includes: a CPU processing core, and the cryptographic module provided in the above embodiment one or embodiment two.
[0121] The technical solution provided by the embodiments of the present invention makes full use of the cost-effectiveness advantage of integrated circuits. By integrating the security processor SP module and the cryptographic coprocessor CCP module into the CPU chip, and with the relevant software support, the function of the cryptographic card can be directly provided in the CPU, and the two disadvantages of the cryptographic card scheme in terms of cost and security can be solved.
[0122] Figure 9 This is a schematic diagram of the structure of an embodiment of the electronic device of the present invention, which can realize the present invention. Figure 8 The process of the illustrated embodiment is as follows: Figure 9 As shown, the aforementioned electronic device may include: a housing 91, a processor 92, a memory 93, a circuit board 94, and a power supply circuit 95. The circuit board 94 is disposed inside the space enclosed by the housing 91, and the processor 92 and the memory 93 are disposed on the circuit board 94. The power supply circuit 95 is used to supply power to the various circuits or devices of the aforementioned electronic device. The memory 93 is used to store executable program code. The processor 92 runs a program corresponding to the executable program code by reading the executable program code stored in the memory 93, for executing the image decoding test method described in any of the foregoing embodiments.
[0123] For details on the specific execution process of the above steps by processor 92, and the steps further executed by processor 92 through running executable program code, please refer to the present invention. Figure 8 The description of the illustrated embodiments will not be repeated here.
[0124] This electronic device exists in various forms, including but not limited to:
[0125] (1) Mobile communication devices: These devices are characterized by their mobile communication capabilities and primarily aim to provide voice and data communication. These terminals include: smartphones (e.g., iPhones), multimedia phones, feature phones, and low-end phones, etc.
[0126] (2) Ultra-mobile personal computer devices: These devices fall under the category of personal computers, possessing computing and processing capabilities, and generally also have mobile internet access features. These terminals include PDAs, MIDs, and UMPCs, such as the iPad.
[0127] (3) Portable entertainment devices: These devices can display and play multimedia content. This category includes: audio and video players (such as iPods), handheld game consoles, e-books, as well as smart toys and portable car navigation devices.
[0128] (4) Server: A device that provides computing services. The components of a server include a processor, hard disk, memory, system bus, etc. Servers are similar to general computer architectures, but because they need to provide highly reliable services, they have higher requirements in terms of processing power, stability, reliability, security, scalability, and manageability.
[0129] (5) Other electronic devices with data processing functions.
[0130] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
[0131] In this embodiment of the invention, the term "and / or" describes the relationship between associated objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone. The character " / " generally indicates that the preceding and following associated objects have an "or" relationship.
[0132] The various embodiments in this specification are described in a related manner. The same or similar parts between the various embodiments can be referred to each other. Each embodiment focuses on describing the differences from other embodiments.
[0133] In particular, the device embodiment is basically similar to the method embodiment, so the description is relatively simple. For relevant details, please refer to the description of the method embodiment.
[0134] For ease of description, the above apparatus is described by dividing it into various functional units / modules. Of course, in implementing this invention, the functions of each unit / module can be implemented in one or more software and / or hardware.
[0135] Those skilled in the art will understand that all or part of the processes in the above embodiments can be implemented by a computer program instructing related hardware. The program can be stored in a computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. The storage medium can be a magnetic disk, optical disk, read-only memory (ROM), or random access memory (RAM), etc.
[0136] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in the present invention should be included within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be determined by the scope of the claims.
Claims
1. A cryptographic module, characterized in that, The cryptographic module is built into the central processing unit (CPU) and isolated from the CPU's processing core. The cryptographic module includes: The security processor receives cryptographic service requests from the CPU core, obtains the internal key, and sends the internal key to the cryptographic coprocessor. Obtaining the internal key involves: the security processor reading the internal key from a secure non-volatile memory outside the CPU, wherein the security processor encrypts and protects the accessed content when accessing this secure non-volatile memory; and the security processor reading a key image from system memory, decrypting the key image, and using it as the internal key after passing a consistency check. The key image in system memory is pre-obtained by the CPU core from the hard disk file system. The cryptographic coprocessor is used to read the source data corresponding to the cryptographic service request from the system memory, respond to the cryptographic service based on the internal key and the source data, and store the response result in the system memory. The internal key is divided into a device key and a user key; the device key is bound to a device, each bound device is unique, and the device key represents the device's identity information; The code and data stored during the operation of the security processor are stored in secure memory outside the CPU. When the security processor accesses secure memory, the accessed content is encrypted and protected for consistency by hardware.
2. The cryptographic module according to claim 1, characterized in that, The security processor is also used for: It communicates with the CPU core via a management interface for internal key management. Based on the CPU core's internal key management operations, manage the internal keys in the secure non-volatile memory outside the CPU; or... Based on the internal key management operations of the CPU core, manage the internal key image in system memory; when the internal key image is updated, instruct the CPU core to update the updated internal key image to the hard disk file system.
3. The cryptographic module according to claim 2, characterized in that, When the internal key management operation is an export / import internal key operation, the security processor is specifically used for: A protection key is generated by combining confidential information within the chip with the internal key management operation password; Use a protection key to encrypt and protect the consistency of the internal key that needs to be exported; Alternatively, a protection key can be used to decrypt and verify the consistency of the internal key that needs to be imported.
4. The cryptographic module according to claim 1, characterized in that, The security processor is also used to: negotiate communication keys with user applications on the CPU core through a business interface and establish a secure session; Within the context of this secure session, user applications on the secure processor and CPU core use communication keys to encrypt and decrypt cryptographic service communication data.
5. A cryptographic operation method, characterized in that, Applied to a security processor, the method includes: Receive cryptographic service requests sent by the CPU processing core; Obtaining the internal key; specifically, obtaining the internal key includes: reading the internal key from a secure non-volatile memory outside the CPU, wherein the accessed content is encrypted and protected for consistency when accessing the secure non-volatile memory; reading the key image from system memory, decrypting the key image and using it as the internal key after passing the consistency check; wherein the key image in system memory is pre-read by the CPU processing core from the hard disk file system; The internal key is sent to the cryptographic coprocessor, which is instructed to: read the source data corresponding to the cryptographic service request from the system memory, respond to the cryptographic service based on the internal key and the source data, and store the response result in the system memory; the internal key is divided into a device key and a user key; the device key is bound to a device, each bound device is unique, and the device key represents the device's identity information; The code and data stored during the operation of the security processor are stored in secure memory outside the CPU. When the security processor accesses secure memory, the accessed content is encrypted and protected for consistency by hardware.
6. The cryptographic operation method according to claim 5, characterized in that, The method further includes: It communicates with the CPU core via a management interface for internal key management. Based on the CPU core's internal key management operations, manage the internal keys in the secure non-volatile memory outside the CPU; or... Based on the internal key management operations of the CPU core, manage the internal key image in system memory; when the internal key image is updated, instruct the CPU core to update the updated internal key image to the hard disk file system.
7. The cryptographic operation method according to claim 6, characterized in that, When the internal key management operation is an export / import internal key operation, the internal key management includes: A protection key is generated by combining confidential information within the chip with the internal key management operation password; Use a protection key to encrypt and protect the consistency of the internal key that needs to be exported; Alternatively, a protection key can be used to decrypt and verify the consistency of the internal key that needs to be imported.
8. The cryptographic operation method according to claim 5, characterized in that, The method further includes: negotiating a communication key with the user application on the CPU core through a business interface to establish a secure session; Within the context of this secure session, user applications on the CPU core use communication keys to encrypt and decrypt cryptographic service communication data.
9. A central processing unit (CPU) chip, characterized in that, include: The CPU processing core; and the cryptographic module as described in any one of claims 1-4 above.
10. An electronic device, characterized in that, The electronic device includes: a housing, a processor, a memory, a circuit board, and a power supply circuit, wherein the circuit board is disposed inside the space enclosed by the housing, and the processor and the memory are disposed on the circuit board; the power supply circuit is used to supply power to various circuits or devices of the electronic device; the memory is used to store executable program code; the processor runs a program corresponding to the executable program code by reading the executable program code stored in the memory, for executing the method described in any one of claims 5-8 above.
Citation Information
Patent Citations
Key management method, key calling method and cipher machine
CN109768862A
Code protection system, authentication method and device, chip and electronic equipment
CN110348204A
Data encryption method, processor and computer equipment
CN111090869A