SOC Chip and Data Processing Methods Applied to SOC Chip
By introducing peripheral interface modules and data processing modules into the SOC chip, the raw data with a high level of security is processed securely before being sent to the processor, which solves the problem of poor data processing security in SOC chips and achieves secure data isolation and improved processing efficiency.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- GUANGDONG LEAPFIVE TECH CO LTD
- Filing Date
- 2021-03-29
- Publication Date
- 2026-05-26
Smart Images

Figure CN115130144B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of semiconductor integrated circuit technology, and in particular to a SOC chip and a data processing method applied to the SOC chip. Background Technology
[0002] With the rapid development of very large-scale integrated circuits (VLSI), the semiconductor industry has entered the deep submicron era. Device feature sizes are getting smaller and smaller, and chip sizes are getting larger and larger, allowing millions to hundreds of millions of transistors to be integrated on a single chip. This high degree of integration allows us to integrate the functions that were previously achieved by several chips, such as CPUs and I / O interfaces, onto a small chip. Powerful and complete systems can be constructed from a single integrated circuit. This is what we usually call a System-on-Chip (SOC) peripheral system, which can be widely used in industries such as power, rail transportation, petrochemicals, high-tech electronics, aerospace, nuclear industry, pharmaceuticals, and food manufacturing. Many critical infrastructure projects related to national economy and people's livelihood also rely on SOC peripheral systems to achieve automated operations.
[0003] A System-on-a-Chip (SoC) typically integrates a processor, data processing module, and memory (or off-chip memory control interface) onto a single chip. It can make full use of existing design experience, significantly improve the design capabilities of integrated circuits, and narrow the gap between design capabilities and integrated circuit process capabilities. SoC system design technology has become one of the hot topics in design.
[0004] However, current data processing methods for SOC chips suffer from poor security. Summary of the Invention
[0005] The problem solved by the embodiments of the present invention is to provide a SOC chip and a data processing method applied to the SOC chip, thereby reducing the risk of original data being leaked and tampered with, and improving data security.
[0006] To address the aforementioned problems, this invention provides a data processing method for SOC chips. The data processing method includes: receiving raw data, including first raw data and second raw data, wherein the security level of the first raw data is higher than that of the second raw data; performing security processing on the first raw data to obtain processed data; and sending the processed data and the second raw data to a processor for further processing.
[0007] Optionally, the data processing method further includes sending at least one of the processed data and the processing result of the processor on the processed data to a peripheral device.
[0008] Optionally, the security processing of the first raw data includes encryption.
[0009] Optionally, the data processing method further includes: before sending the processed data to the processor for corresponding processing, performing specified mode processing on the first original data after security processing, wherein the specified mode processing includes any one or more of preprocessing, routing processing and hardware acceleration processing; and using the processing result of the first original data after security processing and specified mode processing as the processed data.
[0010] Accordingly, this embodiment of the invention also provides a SOC chip, including: a peripheral interface module, including a first peripheral interface and a second peripheral interface, wherein the first peripheral interface is used to receive first raw data, the second peripheral interface is used to receive second raw data, and the security level of the first raw data is higher than that of the second raw data; a data processing module, used to perform security processing on the first raw data to obtain processed data; and a processor, used to perform corresponding processing on the processed data and the second raw data.
[0011] Optionally, the SOC chip further includes: an interconnect bus for forwarding data between the peripheral interface module and the processor, and between the data processing module and the processor; the interconnect bus is disconnected from the first peripheral interface and connected to the second peripheral interface; the interconnect bus is also used to forward at least one of the processed data and the processor's processing result of the processed data to the peripheral interface module.
[0012] Optionally, the peripheral interface module includes multiple peripheral interfaces for transmitting data; the SOC chip further includes: a configuration module, configured to configure a specified peripheral interface as the first peripheral interface based on the security level of the original data, and configured to disconnect the interconnect bus from the first peripheral interface; the configuration module is also configured to configure the data processing module to perform secure processing on the first original data.
[0013] Optionally, the configuration module is a programmable storage module used to store configuration information.
[0014] Optionally, the programmable storage module is a ROM; the ROM includes OTP, EPROM, EEPROM, antifuse memory, electrically programmable fuse memory, or flash memory.
[0015] Optionally, the interconnect bus is physically disconnected from the first peripheral interface.
[0016] Optionally, the data processing module includes a data security module for encrypting the first raw data.
[0017] Optionally, the configuration module is further configured to configure the data processing module to perform specified mode processing on the first raw data after security processing; the processing result of the data processing module after performing security processing and specified mode processing on the first raw data is used as the processed data.
[0018] Optionally, the data processing module further includes: a preprocessing module, a routing module, and a hardware acceleration module; wherein, the preprocessing module is used to preprocess the first raw data after security processing, so that the first raw data after security processing carries interactive identification information; the routing module is used to perform routing processing on the first raw data after security processing; the hardware acceleration module is used to perform hardware acceleration processing on the first raw data after security processing; the configuration module configures the data processing module to perform specified mode processing on the first raw data after security processing, including: any one or more of the preprocessing, routing processing, and hardware acceleration processing.
[0019] Optionally, the data security module is a hardware module.
[0020] Compared with the prior art, the technical solution of the embodiments of the present invention has the following advantages:
[0021] In the data processing method for SOC chips provided in this embodiment of the invention, raw data is received, including first raw data and second raw data. The security level of the first raw data is higher than that of the second raw data. Then, the first raw data is subjected to security processing to obtain processed data. The processed data and the second raw data are then sent to the processor for further processing. The first raw data has a high security requirement. In this embodiment of the invention, the first raw data is first subjected to security processing to obtain processed data. Therefore, the processor cannot directly process the first raw data, but processes the processed data after security processing. This avoids the risk of data tampering and leakage caused by the processor obtaining the first raw data first, meets the security protection requirements for the first raw data, and thus improves data security.
[0022] In the SOC chip provided in this embodiment of the invention, the peripheral interface module includes a first peripheral interface for receiving first raw data and a second peripheral interface for receiving second raw data. The security level of the first raw data is higher than that of the second raw data. The data processing module is used to perform security processing on the first raw data to obtain processed data. The processor is used to perform corresponding processing on the processed data and the second raw data. The first raw data has a high security requirement. In this embodiment of the invention, the first raw data is first sent to the data processing module for security processing, so that the processor only performs corresponding processing on the processed data. This avoids the risk of data tampering and leakage caused by the processor obtaining the data first, meets the security protection requirements for the first raw data, and thus improves data security.
[0023] Furthermore, the data processing module can securely process the first raw data transmitted through the first peripheral interface without requiring processor forwarding, which also helps to improve the efficiency of data processing.
[0024] In an optional embodiment, the SOC chip further includes an interconnect bus for data forwarding between the peripheral interface module and the processor, and between the data processing module and the processor. The interconnect bus is disconnected from the first peripheral interface and connected to the second peripheral interface. Disconnection of the interconnect bus from the first peripheral interface breaks the transmission path of the first raw data from the first peripheral interface to the processor via the interconnect bus. The processor cannot access the first raw data transmitted from the first peripheral interface via the interconnect bus, effectively isolating the processor from direct contact with the first raw data, significantly reducing the risk of leakage and tampering of the first raw data, and improving data security. Attached Figure Description
[0025] Figure 1 This is a schematic diagram of the composition structure of an embodiment of the SOC chip of the present invention;
[0026] Figure 2 This is a flowchart illustrating an embodiment of the data processing method of the present invention. Detailed Implementation
[0027] As can be seen from the background technology, the current data processing methods of SOC chips have poor security issues.
[0028] Specifically, in traditional SoC chip architectures, the processor core is typically the central element, with all peripherals and hardware acceleration modules connected to the internal interconnect bus and communicating with it. External raw data sources connect to peripheral interfaces for raw data exchange, and the raw data is then sent from the peripheral interfaces to the processor core via the internal interconnect bus for processing.
[0029] Currently, there are generally two ways to protect data in traditional SoC chip architectures: one is processor software encryption; the other is hardware encryption, where the processor transmits the raw data to a hardware encryption module for encryption.
[0030] However, both of these traditional protection methods, whether software encryption or hardware encryption, allow the processor core to directly access the plaintext raw data. Once the SoC chip software is compromised or breached, there is a risk that the raw data will be leaked and tampered with, resulting in poor data security.
[0031] In particular, the core of IoT terminal node devices is "SoC chip + sensor". The sensor is connected to the SoC peripheral interface to exchange raw data. When the node SoC chip software is compromised, the risk of raw data being leaked and tampered with is high, resulting in poor security of IoT node chips, weak data security protection capabilities of IoT, and prominent information security issues.
[0032] To address the aforementioned technical problem, embodiments of the present invention provide a data processing method applied to a SOC chip, comprising: receiving raw data, including first raw data and second raw data, wherein the security level of the first raw data is higher than that of the second raw data; performing security processing on the first raw data to obtain processed data; and sending the processed data and the second raw data to a processor for corresponding processing.
[0033] In the data processing method for SOC chips provided in this embodiment of the invention, since the first original data has high security requirements, the first original data is first subjected to security processing to obtain processed data. Therefore, the processor cannot directly process the first original data, but processes the processed data after security processing. This avoids the risk of data tampering and leakage caused by the processor obtaining the first original data first, meets the security protection requirements for the first original data, and improves data security.
[0034] This invention provides a SOC chip, comprising: a peripheral interface module, including a first peripheral interface and a second peripheral interface, wherein the first peripheral interface is used to receive first raw data, and the second peripheral interface is used to receive second raw data, wherein the security level of the first raw data is higher than the security level of the second raw data; a data processing module, used to perform security processing on the first raw data to obtain processed data; and a processor, used to perform corresponding processing on the processed data and the second raw data.
[0035] In the SOC chip provided in this embodiment of the invention, the peripheral interface module includes a first peripheral interface for receiving first raw data and a second peripheral interface for receiving second raw data. The security level of the first raw data is higher than that of the second raw data. The data processing module is used to perform security processing on the first raw data to obtain processed data. The processor is used to perform corresponding processing on the processed data and the second raw data. The first raw data has a high security requirement. In this embodiment of the invention, the first raw data is first sent to the data processing module for security processing, so that the processor only performs corresponding processing on the processed data. This avoids the risk of data tampering and leakage caused by the processor obtaining the data first, meets the security protection requirements for the first raw data, and thus improves data security.
[0036] Furthermore, the data processing module can securely process the first raw data transmitted through the first peripheral interface without requiring processor forwarding, which also helps to improve the efficiency of data processing.
[0037] In an optional embodiment, the SOC chip further includes an interconnect bus for data forwarding between the peripheral interface module and the processor, and between the data processing module and the processor. The interconnect bus is disconnected from the first peripheral interface and connected to the second peripheral interface. Disconnection of the interconnect bus from the first peripheral interface breaks the transmission path of the first raw data from the first peripheral interface to the processor via the interconnect bus. The processor cannot access the first raw data transmitted from the first peripheral interface via the interconnect bus, effectively isolating the processor from direct contact with the first raw data, significantly reducing the risk of leakage and tampering of the first raw data, and improving data security.
[0038] To make the above-mentioned objects, features and advantages of the embodiments of the present invention more apparent and understandable, the specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings.
[0039] To facilitate understanding, the structure of the SOC chip in the embodiments of the present invention will be described first below.
[0040] refer to Figure 1 The diagram shows a schematic representation of the structure of an embodiment of the SOC chip of the present invention.
[0041] In this embodiment, the SOC chip 100 includes:
[0042] The peripheral interface module 102 includes a first peripheral interface 106 and a second peripheral interface 107. The first peripheral interface 106 is used to receive first raw data, and the second peripheral interface 107 is used to receive second raw data. The security level of the first raw data is higher than that of the second raw data.
[0043] The data processing module 103 is used to perform security processing on the first raw data to obtain processed data; the processor 105 is used to perform corresponding processing on the processed data and the second raw data.
[0044] It should be noted that, in this embodiment, the SOC chip 100 further includes an interconnect bus 104, used for data forwarding between the peripheral interface module 102 and the processor 105, and between the data processing module 103 and the processor 105. The interconnect bus 104 is disconnected from the first peripheral interface 106 and connected to the second peripheral interface 107.
[0045] In this embodiment, the peripheral interface module 102 is coupled to a peripheral device (not shown) to obtain the corresponding raw data, so that the SOC chip 100 and the peripheral device can interact with each other.
[0046] It should be noted that the coupling in the embodiments of the present invention can be a direct connection or an indirect connection, and can be a wireless connection or a wired connection, etc.
[0047] In this embodiment, the peripheral device interface 106 includes multiple peripheral interfaces (such as... Figure 1 Peripheral interfaces 1 to n (as shown in the diagram) are used for data transmission. The specific number of peripheral interfaces can be set by those skilled in the art according to actual needs, and no limit is imposed here.
[0048] In specific implementation, the peripheral device is used to collect any object or process that needs to be monitored, connected, or interacted with, and to collect various required information such as sound, light, heat, electricity, mechanics, chemistry, biology, and location. Thus, the peripheral interface module 102 can transmit the information collected by the peripheral device to the SOC chip 100 for corresponding data processing.
[0049] In practical implementation, based on actual application scenarios, peripheral devices can be information sensors, such as GPS, infrared sensors, laser scanners, etc.; they can also be computer information storage devices, such as disks, optical discs, magnetic tapes, etc.; or they can be human-computer interaction devices, such as printers, monitors, plotters, speech synthesizers, keyboards, etc.
[0050] It should be noted that the peripheral device can be a peripheral device set within the SOC chip 100 or a peripheral device set independently of the SOC chip 100. Those skilled in the art can set it according to actual needs, and no limitation is made here.
[0051] The peripheral interface type of the peripheral interface module 102 can be USB interface, UART (Universal Asynchronous Receiver / Transmitter) interface, I2C (Inter-Integrated Circuit) interface, SPI (Serial Peripheral Interface), GPIO (General-purpose input / output) interface, I2S (Inter-IC Sound) interface, SAI (Serial Audio Interface), CAN (Controller Area Network) bus interface, etc. Those skilled in the art can configure it according to actual needs, and there are no restrictions here.
[0052] The first peripheral interface 106 is used to receive the first raw data, and the second peripheral interface 107 is used to receive the second raw data. The security level of the first raw data is higher than that of the second raw data.
[0053] Specifically, the first raw data has a high security level requirement. The first peripheral interface 106 is a pre-configured designated peripheral interface. Based on user needs, it is connected to an external raw data source with a high security level, thereby transmitting the first raw data to the data processing module 103 for secure processing. This avoids the problem that the processor 105 may obtain the first raw data first, which could lead to the data being easily tampered with and leaked.
[0054] Furthermore, the first peripheral interface 106 is disconnected from the interconnect bus 104, thereby isolating the processor 105 from direct contact with the first raw data, effectively reducing the risk of the first raw data being leaked or tampered with, and thus significantly improving data security.
[0055] Compared to the security level of the first raw data, the security level of the second raw data is lower, so that the second peripheral interface 107 is connected to the interconnect bus 104, so that the second raw data can interact with the processor 105 through the second peripheral interface 107 and the interconnect bus 104.
[0056] In specific implementation, based on the actual application scenario, as well as the data security requirements and user needs in the corresponding application scenario, the first raw data and the first peripheral interface 106 for receiving the first raw data, and the second raw data and the second peripheral interface 107 for receiving the second raw data are determined.
[0057] Specifically, based on the actual application scenario, the peripheral devices connected to the peripheral interface, and the information collected by the peripheral devices, the types of the first raw data and the second raw data are determined.
[0058] As one embodiment, when applied to a smart home scenario, peripheral devices may include biometric sensors (e.g., fingerprint sensors) and humidity sensors. The biometric sensors are used to obtain the user's biometric information for authentication and other operations, specifically including fingerprint information, iris information, etc. The humidity sensors are used to obtain the humidity information of the environment. In this scenario, the biometric information can be used as the first raw data, and the humidity information can be used as the second raw data. Accordingly, the peripheral interface connected to the biometric sensor serves as the first peripheral interface 106, and the peripheral interface connected to the humidity sensor serves as the second peripheral interface 107.
[0059] As one embodiment, when applied to a vehicle-to-everything (V2X) scenario, peripheral devices may include a vehicle speed sensor, a GPS sensor, and an air flow sensor, etc. The vehicle speed sensor is used to obtain vehicle speed information, the GPS sensor is used to obtain vehicle location information, and the air flow sensor is used to detect engine intake airflow information. In this scenario, the vehicle speed information and location information can be used as first raw data, and the engine intake airflow information can be used as second raw data. Accordingly, the peripheral interface connected to the vehicle speed sensor and the peripheral interface connected to the GPS sensor are used as the first peripheral interface 106, and the peripheral interface connected to the air flow sensor is used as the second peripheral interface 107.
[0060] As one embodiment, when applied to wearable device scenarios, peripheral devices may include gyroscopes, accelerometers, barometers, etc. The gyroscope is primarily used to detect the angular velocity between the device's axes, i.e., rotational speed, to analyze the user's actual movements. The accelerometer measures the degree of acceleration between the device's axes to determine the device's motion state. The barometer measures air pressure data. In this scenario, the angular velocity and acceleration can be used as the first raw data, and the air pressure data can be used as the second raw data. Accordingly, the peripheral interfaces connected to the gyroscope and accelerometer serve as the first peripheral interface 106, and the peripheral interface connected to the barometer serves as the second peripheral interface 107.
[0061] As an example, in the peripheral interface module 102, peripheral interface 1 is configured as the first peripheral interface 106, and peripheral interface 2 is configured as the second peripheral interface 107.
[0062] The number of the first peripheral interface 106 can be one or more, and the number of the second peripheral interface 107 can be one or more. In specific implementations, those skilled in the art can set specific peripheral interfaces as the first peripheral interface 106 and the second peripheral interface 107 according to actual needs, without limitation. Those skilled in the art can also set the specific number of the first peripheral interface 106 and the second peripheral interface 107 according to actual needs, without limitation.
[0063] In specific implementations, in addition to the first peripheral interface 106 and the second peripheral interface 107, the peripheral interface module 102 may also include a third peripheral interface 112 for data transmission. For example, the third peripheral interface 112 may be a network peripheral interface used to transmit data processed by the SOC chip 100 to an external network; or, for example, the third peripheral interface 112 may be an input / output interface used to connect to input / output devices (I / O devices), such as connecting the third peripheral interface 112 to a display or keyboard. The type of the third peripheral interface 112 is not limited to these, and those skilled in the art can configure it according to actual needs.
[0064] As an example, the first peripheral interface 106 is coupled to the data processing module 103 via a preset first internal bus (not shown). Thus, raw data collected by peripheral devices connected to the first peripheral interface 106 can be sent to the data processing module 103 sequentially via the first peripheral interface 106 and the first internal bus. The data processing module 103 can also sequentially return processed data to the corresponding peripheral device via the first internal bus and the first peripheral interface 106.
[0065] In specific implementations, the first internal bus can be a data transmission bus based on different standards, such as the I2C bus, the Serial Communication Interface (SCI) bus, etc. Those skilled in the art can choose according to actual needs, and no limitation is made here.
[0066] In this embodiment, the SOC chip 100 further includes: a configuration module 101, coupled to the peripheral interface module 102, for configuring a specified peripheral interface as the first peripheral interface 106 based on the security level of the original data; the configuration module 101 is also coupled to the interconnect bus 104, for configuring the interconnect bus 104 to disconnect from the first peripheral interface 106.
[0067] Based on the security level of the original data, the configuration module 101 configures a specified peripheral interface as the first peripheral interface 106, and configures the interconnect bus 104 to disconnect from the first peripheral interface 106.
[0068] In other words, when the raw data sent by the peripheral device has a high security level, the raw data is sent to the data processing module 103 for security processing through the first peripheral interface 106. This allows the first peripheral interface 106 and the data processing module 103 to directly interact with each other without needing to go through the processor 105 for data forwarding. Therefore, the risk of data tampering and leakage caused by the processor 105 first obtaining the raw data with a high security level can be avoided, thereby improving data security and data processing efficiency.
[0069] Furthermore, the configuration module 101 configures the interconnect bus 104 to disconnect from the first peripheral interface 106, thereby disconnecting the transmission path of the first raw data from the first peripheral interface 106 to the processor 105 through the interconnect bus 104. This prevents the processor 105 from obtaining the first raw data transmitted from the first peripheral interface 106 through the interconnect bus 104, thus isolating the processor 105 from direct contact with the first raw data. This effectively reduces the risk of the raw data being leaked or tampered with, and improves data security.
[0070] In this embodiment, the configuration module 101 is also coupled to the data processing module 103 and is used to configure the data processing module 103 to perform secure processing on the first raw data.
[0071] As an example, the configuration module 101 is a programmable storage module used to store configuration information. The configuration information includes at least: information specifying a first peripheral interface 106 for receiving the first raw data, information specifying a first peripheral interface 106 that the interconnect bus 104 needs to disconnect, and processing information setting the data processing module 103 to perform secure processing on the first raw data.
[0072] Specifically, the configuration information can be stored in the configuration module 101 by burning the SOC chip 100 before it leaves the factory, according to predefined application scenarios and user needs.
[0073] As an example, the programmable storage module is a ROM (Read Only Memory). A ROM is characterized by the fact that during normal operation, it can only read and use pre-stored information and cannot write new content; that is, once information is written, it cannot be changed. This also reduces the risk of the configuration information in the configuration module 101 being tampered with, thereby improving data security and reliability.
[0074] Specifically, the ROM can be an OTP (One Time Programmable) module, an EPROM (Erasable Programmable Read Only Memory), an antifuse, an eFuse, an EEPROM (Electrically Erasable Programmable ROM), or a FLASH ROM.
[0075] As one embodiment, the programmable storage module is an OTP (One-Time Programmable) module. The storage units in an OTP module can only be programmed once; the data after programming cannot be changed or erased again. It has good anti-reverse engineering characteristics, which helps reduce the risk of the configuration information in the configuration module 101 being changed or erased, further improving data security and reliability. In addition, the OTP module also has excellent characteristics such as non-volatility, high reliability, strong stability, and strong anti-interference ability.
[0076] In other embodiments, the programmable storage module may also be other types of storage modules.
[0077] In other embodiments, the configuration module is not limited to the storage module, but can also be other types of modules, which can be configured by those skilled in the art according to actual needs.
[0078] In this embodiment, the data processing module 103 is coupled to the peripheral interface module 102, enabling the data processing module 103 to interact with peripheral devices through the peripheral interface module 102.
[0079] Specifically, the data processing module 103 performs secure processing on the first raw data transmitted from the first peripheral interface 106 to obtain processed data. As a result, the first raw data transmitted from the first peripheral interface 106 can be directly sent to the data processing module 103. In this way, the interactive data between the first peripheral interface 106 and the data processing module 103 does not need to be forwarded by the processor 105 in advance, which can avoid the risk of the first raw data being tampered with and leaked.
[0080] As one embodiment, the data processing module 103 may perform security processing on the first raw data, including encryption processing, thereby converting the first raw data into encrypted data. Accordingly, the processed data is encrypted data.
[0081] In a specific implementation, the data processing module 103 includes a data security module 108, which is used to encrypt the first original data so as to process the first original data into encrypted data.
[0082] As an example, the configuration module 101 configures the data processing module 103 to perform secure processing on the first raw data. Specifically, the configuration module 101 can configure the specific content of the encryption processing performed by the data security module 108, such as encryption parameters, encryption mode, etc. Accordingly, the data security module 108 performs encryption processing on the first raw data based on the configuration information of the configuration module 101.
[0083] Specifically, the data security module 108 can be a data encryption module or a data encryption / decryption module. When the data security module 108 is a data encryption / decryption module, in addition to the encryption function, it also has the decryption function.
[0084] It should be noted that in this embodiment, the data security module 108 is a hardware module, that is, the data security module 108 implements its functions in hardware, which helps to avoid the problem of the first original data being called by the processor 105. Accordingly, the data processing module 103 has the function of data isolation and protection to resist the intrusion of external programs, prevent data from being tampered with and leaked, and improve data security. Moreover, compared with software modules, the use of hardware modules helps to improve the efficiency and speed of data processing.
[0085] In a specific implementation, the data processing module 103 may further include a preprocessing module 109, a routing processing module 110, and a hardware acceleration module 111.
[0086] The preprocessing module 109 is used to preprocess the first raw data after security processing, so that the first raw data after security processing carries interactive identification information. Specifically, the preprocessing module 109 can be a tagging module, used to add tags to the first raw data. As an embodiment, the preprocessing module 109 can preprocess the first raw data after it has been encrypted by the data security module 108.
[0087] The routing processing module 110 is used to perform routing processing on the first raw data after security processing to determine the forwarding direction of the data. As an example, the routing processing module 110 may perform routing processing on the first raw data after security processing by the data security module 108 and preprocessing by the preprocessing module 109.
[0088] The hardware acceleration module 111 is used to perform hardware acceleration processing on the first raw data after security processing, so as to improve the efficiency of data processing. As an embodiment, the hardware acceleration module can be a Physical Unclonable Functions (PUF) hardware acceleration module, etc. As an example, the hardware acceleration module 111 can perform hardware acceleration processing on the first raw data after security processing by the data security module 108, preprocessing by the preprocessing module 109, and routing processing by the routing processing module 110.
[0089] It should be noted that the hardware acceleration module 111, the preprocessing module 109, and the routing processing module 110 in the data processing module 103 can be implemented in software or in hardware. Those skilled in the art can set them according to actual needs.
[0090] It should also be noted that, apart from the data security module 108, the other functional modules included in the data processing module 103 are only examples. In specific implementations, those skilled in the art can set them according to actual needs.
[0091] In this embodiment, the configuration module 101 is further configured to configure the data processing module 103 to perform specified mode processing on the first raw data after security processing.
[0092] Specifically, based on the application scenario of the SOC chip 100 and user needs, the data processing module 103 is configured to process the first raw data after security processing in a specified mode.
[0093] Accordingly, the configuration information stored in the configuration module 101 may also include: specific information on how the data processing module 103 processes the first raw data after security processing in a specified mode.
[0094] In this embodiment, the configuration module 101 configures the data processing module 103 to perform specified mode processing on the first raw data after security processing, including any one or more of the preprocessing, routing processing and hardware acceleration processing.
[0095] In other embodiments, based on the types of modules included in the data processing module, the configuration module may configure the data processing module to perform specified mode processing on the first raw data after security processing, and may also include other processing types.
[0096] It should be noted that when the data processing module 103 performs specified mode processing on the first raw data after security processing based on the configuration information of the configuration module 101, the processing result of the data processing module 103 after security processing and specified mode processing on the first raw data is used as the processed data, so that the processing result of the data processing module 103 on the first raw data can be sent to the processor 105 for corresponding processing.
[0097] The processor 105 is used to process the processed data and the second original data accordingly. Specifically, the processor 105 is coupled to the data processing module 103 so that data interaction can be realized between the processor 105 and the data processing module 103.
[0098] More specifically, the interconnect bus 104 is coupled to the data processing module 103 and the processor 105 respectively, thereby realizing data interaction between the processor 105 and the data processing module 103, and data interaction between the processor 105 and peripheral devices through the interconnect bus 104.
[0099] In a specific implementation, the processor 105 is responsible for data processing and control scheduling. As one embodiment, the processor 105 can be a CPU (central processing unit).
[0100] The processor 105 can be a single-core processor or a multi-core processor. If the processor 105 is a multi-core processor, it can be a specific processor core in the multi-core processor, or any one or more processor cores in the multi-core processor.
[0101] The interconnect bus 104 is coupled to the peripheral interface module 102, the data processing module 103 and the processor 105 respectively, and is used as a data communication bus between the various component modules in the SOC chip 100. For example, the interconnect bus 104 can be used for communication between the data processing module 103 and the processor 105, and between the peripheral interface module 102 and the processor 105.
[0102] The interconnect bus 104 is disconnected from the first peripheral interface 106, thereby cutting off the transmission path of the first raw data from the first peripheral interface 106 to the processor 105 via the interconnect bus 104, thus isolating the processor 105 from direct contact with the first raw data and effectively ensuring the security of the first raw data.
[0103] In a specific implementation, the interconnect bus 104 is physically disconnected from the first peripheral interface 106, thereby disabling the channel between the interconnect bus 104 and the first peripheral interface 106, so as to ensure that the first raw data can be directly sent to the data processing module 103 for secure processing.
[0104] In this embodiment, the interconnect bus 104 is also coupled to the configuration module 101, so that the interconnect bus 104 is disconnected from the first peripheral interface 106 based on the configuration of the configuration module 101.
[0105] Specifically, the configuration information stored in the configuration module 101 includes information about the first peripheral interface 106 that needs to be disconnected from the interconnect bus 104. The interconnect bus 104 is coupled to the configuration module 101, so that based on the configuration information in the configuration module 101, the second peripheral interface 107 that needs to be connected is selected, and correspondingly, the interconnect bus 104 is disconnected from the first peripheral interface 106.
[0106] As an example, a second internal bus (not shown) is also provided between the interconnect bus 104 and the peripheral interface module 102, and a third internal bus (not shown) is provided between the interconnect bus 104 and the processor 105, so that the peripheral interface module 102 and the processor 105 can interact with each other through the second internal bus, the interconnect bus 104 and the third internal bus.
[0107] Specifically, a second internal bus is provided between the interconnect bus 104 and the second peripheral interface 107.
[0108] Furthermore, as an example, a fourth internal bus (not shown) is provided between the interconnect bus 104 and the data processing module 103, and a third internal bus is provided between the interconnect bus 104 and the processor 105, thereby enabling the processor 105 and the data processing module 103 to interact with each other through the fourth internal bus, the interconnect bus 104 and the third internal bus.
[0109] In specific implementation, the second internal bus, the third internal bus and the fourth internal bus can refer to the description of the first internal bus, and will not be repeated here.
[0110] In this embodiment, the interconnect bus 104 is also used to forward at least one of the processed data and the corresponding processing result of the processor 105 to the peripheral interface module 102, so that at least one of the processed data and the processing result of the processor 105 on the processed data can be returned to the peripheral device through the peripheral interface module 102.
[0111] Specifically, in addition to the first peripheral interface 106 and the second peripheral interface 107, the peripheral interface module 102 may also include the third peripheral interface 112, for example, a network peripheral interface. Correspondingly, at least one of the processed data and the processing result of the processor 105 on the processed data can be sent to the corresponding peripheral device through the third peripheral interface to achieve communication with the peripheral device. In other embodiments, at least one of the processed data and the processing result of the processor on the processed data can also be sent to the corresponding peripheral device through the second peripheral interface or other peripheral interfaces.
[0112] It should be noted that, in specific implementations, the SOC chip 100 may further include an encryption module (not shown) for encrypting the second raw data, thereby enabling the scheme of this embodiment to be flexibly combined with traditional encryption modules. Specifically, the processor 105's processing of the second raw data includes forwarding the second raw data to the encryption module.
[0113] In this embodiment, the SOC chip 100 can be applied to devices capable of data processing, such as mobile phones, computers, wearable devices, smart home devices, and in-vehicle electronic devices.
[0114] As one embodiment, the SOC chip 100 is an IoT node chip. In the IoT node chip, the privacy and security of the first raw data received by the first peripheral interface 106 are highly critical. This embodiment isolates the processor 105 from direct contact with the first raw data, thereby effectively reducing the risk of leakage and tampering of the raw data of the IoT node chip. Consequently, it effectively protects the security of the raw data of the IoT node chip, and thus significantly improves the data security and reliability of the IoT node chip.
[0115] Accordingly, the present invention also provides a data processing method applied to a SOC chip. Figure 2 This is a flowchart illustrating an embodiment of the data processing method of the present invention. For ease of understanding and explanation, the data processing method of this embodiment will be described in detail below with reference to the SOC chip provided in this embodiment.
[0116] refer to Figure 2 In this embodiment, the data processing method may include the following steps:
[0117] Step S1: Receive raw data, including first raw data and second raw data, wherein the security level of the first raw data is higher than that of the second raw data.
[0118] As one embodiment, first raw data is received through a first peripheral interface, and second raw data is received through a second peripheral interface. The first and second peripheral interfaces are connected to corresponding peripheral devices.
[0119] In practice, the first and second raw data are distinguished based on the actual application scenario and the data security requirements and usage needs in the corresponding application scenario.
[0120] Specifically, based on the actual application scenario, the peripheral devices connected to the peripheral interface, and the information collected by the peripheral devices, the types of the first raw data and the second raw data are determined.
[0121] As one embodiment, when applied to a smart home scenario, peripheral devices may include biosensors (e.g., fingerprint sensors) and humidity sensors. The biosensors are used to obtain the user's biometric information for authentication and other operations, specifically including fingerprint information, iris information, etc. The humidity sensor is used to obtain the humidity information of the environment. In this scenario, the biometric information can be used as the first raw data, and the humidity information can be used as the second raw data. Accordingly, the peripheral interface connected to the biosensor serves as the first peripheral interface, and the peripheral interface connected to the humidity sensor serves as the second peripheral interface.
[0122] As one embodiment, when applied to a vehicle-to-everything (V2X) scenario, peripheral devices may include vehicle speed sensors, GPS sensors, and air flow sensors. The vehicle speed sensor obtains vehicle speed information, the GPS sensor obtains vehicle location information, and the air flow sensor detects engine intake airflow information. In this scenario, the vehicle speed information and location information can be used as first raw data, and the engine intake airflow information can be used as second raw data. Accordingly, the peripheral interface connected to the vehicle speed sensor and the peripheral interface connected to the GPS sensor are designated as first peripheral interfaces, and the peripheral interface connected to the air flow sensor is designated as a second peripheral interface.
[0123] As one embodiment, when applied to wearable device scenarios, peripheral devices may include gyroscopes, accelerometers, barometers, etc. The gyroscope is primarily used to detect the angular velocity (rotation speed) between the device's axes to analyze the user's actual movements. The accelerometer measures the degree of acceleration between the device's axes to determine the device's motion state. The barometer measures air pressure data. In this scenario, the angular velocity and acceleration can be used as the first raw data, and the air pressure data can be used as the second raw data. Accordingly, the peripheral interfaces connected to the gyroscope and accelerometer serve as the first peripheral interface, and the peripheral interface connected to the barometer serves as the second peripheral interface.
[0124] Step S2: Perform security processing on the first raw data to obtain processed data.
[0125] The first raw data is subjected to security processing, and the resulting processed data is non-plaintext data. This process ensures data security when the processed data is sent to the processor.
[0126] Specifically, the security processing of the first original data includes: encryption processing, thereby processing the first original data into encrypted data.
[0127] As one embodiment, the first raw data is processed securely by a data processing module. Accordingly, the first peripheral interface and the data processing module can directly interact with each other without the need for data forwarding through the processor. This avoids the risk of data tampering and leakage caused by the processor acquiring the data first, thereby improving data security and data processing efficiency.
[0128] As one embodiment, the data processing module includes a data security module, which encrypts the first raw data.
[0129] It should be noted that, in specific implementations, based on application scenarios and user needs, the data processing method further includes: before sending the processed data to the processor for corresponding processing, performing specified mode processing on the first raw data after security processing.
[0130] As one embodiment, processing the first raw data after security processing in a specified mode may include any one or more of the following: preprocessing, routing processing, and hardware acceleration processing.
[0131] The process of preprocessing the first raw data after security processing is suitable for imbuing the first raw data with interactive identification information. Specifically, preprocessing may include adding tags to the first raw data after security processing. As one embodiment, the preprocessing may be performed on the first raw data after encryption processing.
[0132] The first raw data, after security processing, is then routed to determine the forwarding direction. As an example, this could involve routed data that has undergone security processing and preprocessing.
[0133] Hardware acceleration is applied to the first raw data after security processing to improve data processing efficiency. As one embodiment, the first raw data undergoes hardware acceleration processing using Physical Unclonable Functions (PUFs). As an example, hardware acceleration processing could be applied to the first raw data after security processing, preprocessing, and routing processing.
[0134] As one embodiment, the data processing module may further include: a preprocessing module, a routing processing module, and a hardware acceleration module; wherein, the preprocessing module is used to preprocess the first raw data after security processing; the routing processing module is used to perform routing processing on the first raw data after security processing; and the hardware acceleration module is used to perform hardware acceleration processing on the first raw data after security processing.
[0135] Accordingly, when the first original data after security processing is further processed using the specified mode, the processing result of the first original data after security processing and specified mode processing is used as the processed data.
[0136] As one embodiment, the first raw data is forwarded to the data processing module via an interconnect bus for secure processing and specified mode processing. The interconnect bus is disconnected from the first peripheral interface but connected to the second peripheral interface, thereby preventing the processor from acquiring the first raw data first through the first peripheral interface and the interconnect bus.
[0137] In practice, the connection between the interconnect bus and the first peripheral interface can be physically disconnected to disable the channel between the interconnect bus and the first peripheral interface.
[0138] Step S3: Send the processed data and the second original data to the processor for corresponding processing.
[0139] In this embodiment, the security level of the first original data is required to be high. By first performing security processing on the first original data to obtain processed data, the processor cannot directly process the first original data. Instead, it processes the processed data after security processing. This avoids the risk of data tampering and leakage caused by the processor first obtaining the first original data, meets the security protection requirements for the first original data, and thus improves the security of the data.
[0140] As an example, the processor performs at least the following processes: data processing and control scheduling.
[0141] As one embodiment, the processed data and the second original data are forwarded to the processor for corresponding processing via an interconnect bus.
[0142] As an example, since the first peripheral interface is disconnected from the interconnect bus, after the first raw data is processed to obtain the processed data, the processor obtains the processed data forwarded by the interconnect bus. The processor then comes into contact with non-plaintext data, thereby effectively isolating the processor from direct contact with the first raw data and reducing the risk of the raw data being leaked or tampered with.
[0143] Step S4: In this embodiment, the data processing method further includes sending at least one of the processed data and the processing result of the processor on the processed data to a peripheral device.
[0144] At least one of the processed data and the processing result of the processor on the processed data is sent to the peripheral device, thereby realizing data interaction with the peripheral device.
[0145] As one embodiment, at least one of the processed data and the processing result of the processor on the processed data is sent to a peripheral device via an interconnect bus through a peripheral interface module.
[0146] Specifically, in addition to the first peripheral interface and the second peripheral interface, the peripheral interface module also includes a third peripheral interface, such as a network peripheral interface or an input / output interface. Accordingly, at least one of the processed data and the processor's processing result of the processed data can be sent to the corresponding peripheral device through the third peripheral interface to realize communication with the peripheral device.
[0147] It should be noted that, in specific implementations, the data processing method may further include: encrypting the second original data, thereby enabling the scheme of this embodiment to be flexibly combined with traditional data encryption methods. Specifically, the processor's processing of the second original data may include: forwarding the second original data to the encryption module for encryption.
[0148] In this embodiment, the data processing method is described using the SOC chip described in the foregoing embodiments as an example. However, the implementation of the data processing method is not limited to this. The implementation of the data processing method can be achieved by various other means, such as hardware, firmware, software, or combinations thereof. Those skilled in the art can adopt appropriate implementation methods according to actual needs, and no limitation is made here.
[0149] The embodiments of the present invention described above are combinations of elements and features of the present invention. Unless otherwise stated, the elements or features described are optional. Individual elements or features may be practiced without combination with other elements or features. Furthermore, embodiments of the present invention may be constructed by combining some elements and / or features. The order of operations described in the embodiments of the present invention may be rearranged. Some constructions of any embodiment may be included in another embodiment and may be replaced by corresponding constructions of another embodiment. It will be apparent to those skilled in the art that claims in the appended claims that are not expressly referenced to each other may be combined to form embodiments of the present invention, or may be included as new claims in amendments made after the filing of this application.
[0150] Embodiments of the present invention can be implemented by various means, such as hardware, firmware, software, or combinations thereof. In a hardware configuration, the method according to an exemplary embodiment of the present invention can be implemented by one or more application-specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field-programmable gate arrays (FPGAs), processors, controllers, microcontrollers, microprocessors, etc.
[0151] In firmware or software configuration, embodiments of the present invention can be implemented in the form of modules, processes, functions, etc. Software code can be stored in a memory unit and executed by a processor. The memory unit is located inside or outside the processor and can send data to and receive data from the processor via various known means.
[0152] While the present invention has been disclosed above, it is not limited thereto. Any person skilled in the art can make various modifications and alterations without departing from the spirit and scope of the invention; therefore, the scope of protection of the present invention should be determined by the scope defined in the claims.
Claims
1. A data processing method applied to a SOC chip, characterized in that, include: The system receives raw data, including first raw data and second raw data. The security level of the first raw data is higher than that of the second raw data. The first raw data is received through a first peripheral interface. The interconnect bus of the SOC chip is disconnected from the first peripheral interface and connected to a second peripheral interface. The second peripheral interface is used to receive the second raw data. The first raw data is subjected to security processing to obtain processed data; The processed data and the second original data are sent to the processor for corresponding processing. The processor cannot access the first original data transmitted through the first peripheral interface via the interconnect bus.
2. The data processing method as described in claim 1, characterized in that, The data processing method further includes sending at least one of the processed data and the processing result of the processor on the processed data to a peripheral device.
3. The data processing method as described in claim 1, characterized in that, The security processing of the first raw data includes at least encryption.
4. The data processing method as described in claim 1 or 3, characterized in that, The data processing method further includes: before sending the processed data to the processor for corresponding processing, performing specified mode processing on the first original data after security processing, wherein the specified mode processing includes any one or more of preprocessing, routing processing and hardware acceleration processing; The processing result of the first original data after security processing and specified mode processing is used as the processed data.
5. A SOC chip, characterized in that, include: The peripheral interface module includes a first peripheral interface and a second peripheral interface. The first peripheral interface is used to receive first raw data, and the second peripheral interface is used to receive second raw data. The security level of the first raw data is higher than that of the second raw data. The data processing module is used to perform security processing on the first raw data to obtain processed data; The processor is used to process the processed data and the second original data accordingly. The processor cannot access the first original data transmitted through the first peripheral interface via the interconnect bus. The SOC chip further includes an interconnect bus for forwarding data between the peripheral interface module and the processor, and between the data processing module and the processor. The interconnect bus is disconnected from the first peripheral interface and connected to the second peripheral interface. The interconnect bus is also used to forward at least one of the processed data and the processor's processing result of the processed data to the peripheral interface module.
6. The SOC chip as described in claim 5, characterized in that, The peripheral interface module includes multiple peripheral interfaces for transmitting data; The SOC chip further includes: a configuration module, configured to configure a specified peripheral interface as the first peripheral interface based on the security level of the original data, and configured to disconnect the interconnect bus from the first peripheral interface; the configuration module is also configured to configure the data processing module to perform security processing on the first original data.
7. The SOC chip as described in claim 6, characterized in that, The configuration module is a programmable storage module used to store configuration information.
8. The SOC chip as described in claim 7, characterized in that, The programmable storage module is an OTP.
9. The SOC chip as described in claim 5, characterized in that, The interconnect bus is physically disconnected from the first peripheral interface.
10. The SOC chip as described in claim 5, characterized in that, The data processing module includes a data security module, which is used to encrypt the first raw data.
11. The SOC chip as described in claim 6, characterized in that, The configuration module is also used to configure the data processing module to process the first raw data after security processing in a specified mode. The data processing module performs security processing and specified mode processing on the first raw data, and the resulting processing is used as the processed data.
12. The SOC chip as described in claim 11, characterized in that, The data processing module further includes: a preprocessing module, a routing module, and a hardware acceleration module; wherein, the preprocessing module is used to preprocess the first original data after security processing, so that the first original data after security processing carries interactive identification information; the routing module is used to perform routing processing on the first original data after security processing; and the hardware acceleration module is used to perform hardware acceleration processing on the first original data after security processing. The configuration module configures the data processing module to perform specified mode processing on the first raw data after security processing, including any one or more of the preprocessing, routing processing, and hardware acceleration processing.
13. The SOC chip as described in claim 10, characterized in that, The data security module is a hardware module.