A processor chip supporting multi-source trusted authentication and its manufacturing and usage methods
By implanting multiple sets of public keys into the processor chip and combining Boot ROM and eFuse memory technology, the security risks and high cost of a single key pair in the prior art are solved, and authentication of multiple trusted sources and flexible trusted source management are achieved.
Patent Information
- Application Number
- CN202210951944.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-08-09
- Publication Date
- 2025-06-17
- Estimated Expiration
- 2042-08-09
AI Technical Summary
Existing processor chips use a single key pair in trusted verification, which leads to third-party chip manufacturers need to publicize private keys when using them, which poses security risks and is costly to produce different chips for third parties with high cost.
Multiple sets of public keys are implanted inside the chip, and the authentication operations of multiple trusted sources are realized through the cooperation of the startup code in the Boot ROM and the eFuse memory.
The same chip is certified to multiple trusted sources, reducing security risks in chip production and use, and flexibly adjusting the number of trusted sources by adjusting the number of public keys.
Smart Images

Figure CN115329339B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the application technical field of processor chips, and particularly relates to a processor chip supporting multi-source trusted authentication and a manufacturing and usage method thereof. Background Art
[0002] Boot ROM is a read-only ROM embedded in a processor chip, which contains the first piece of code executed when the processor is powered on or reset. These codes can determine where to load the next part of the code to be executed and how or whether to verify its correctness or validity.
[0003] The asymmetric cryptosystem is also called public key encryption technology, which is proposed in view of the defects of the private key cryptosystem (symmetric encryption algorithm). Different from the symmetric cryptosystem, in the public key encryption system, encryption and decryption are relatively independent, and two different keys are used for encryption and decryption. The encryption key (public key) is publicly available and can be used by anyone. The decryption key (secret key) is only known to the decryptor himself. Illegal users cannot deduce the decryption key based on the publicly available encryption key, thus greatly enhancing the strength of information protection.
[0004] After the processor chip is powered on or reset, it fetches and executes instructions from a fixed storage space address. Chip designers generally store the first piece of code to be executed in a non-volatile memory inside the chip (Boot ROM). These codes are solidified inside the chip after the chip is produced, and neither third parties nor chip designers can modify them anymore.
[0005] The code stored in Boot ROM is the first piece of code executed after the processor chip is powered on or reset. This part of the code usually performs the initialization work inside the chip, moves the next part of the code to be executed from an external mass storage to the system memory, verifies its correctness and then jumps to execute it.
[0006] To ensure the correctness of the next piece of code to be executed, the Boot ROM code will verify the correctness of the imported code before jumping to execute the next piece of code imported from the outside. (See Figure 1 )
[0007] The correctness check of the next execution code includes two steps. The first step is to verify whether there is any error in the code transmission; the second step is to verify that the code is credible, that is, provided by a trusted source. Among them, the first step of verification can be implemented through channel coding such as CRC. The second step of credible verification is usually implemented using an asymmetric encryption algorithm. Taking the A series chip of Apple's iPhone as an example, a public key is stored inside the chip. When the Boot ROM moves the external code to be executed to the memory, it will use the public key to verify the signature of the code. Only after the signature is verified correctly, the Boot ROM will guide the processor to jump to the code segment for execution. Therefore, only code signed with Apple's private key can run on the A series processor, thereby ensuring the credibility of the executed code.
[0008] The biggest problem with the above trusted verification process is that the key pair for trusted verification is single. For example, if Apple wants to allow third-party mobile phone manufacturers to use Apple chips, Apple needs to make its private key public, which poses a great threat to the security of Apple's own code. And if a chip with a different public key is produced for a third-party customer, the cost is huge. Summary of the invention
[0009] The present invention proposes a method for solving the above technical problems. By implanting multiple sets of public keys inside the chip, one chip can authenticate multiple trusted sources. The present invention consists of the following parts:
[0010] 1. The Boot ROM read-only non-volatile memory (memory A) located in the chip. This memory stores the first-stage startup code of the chip, which is responsible for loading the next-stage code into the chip memory and performing trustworthy authentication on the next-stage code before execution.
[0011] 2. The ROM read-only non-volatile memory (memory B) in the chip stores several fixed public keys. Taking the RSA2048 algorithm as an example, each public key occupies 256 bytes, so if 256 public keys need to be stored, 64K bytes of capacity are required.
[0012] 3. The eFuse one-time programmable memory (memory C) located in the chip is used to record the effective public key index number. Therefore, the value stored in this memory corresponds to the number of public key entries in memory B. Taking 256 public keys as an example, memory C needs to be able to store at least 8 bits to represent (0 to 255). After the chip is produced, eFuse allows one-time burning. After the burning is completed, the index value cannot be changed.
[0013] 4. The eFuse one-time programmable memory (memory D) located in the chip is used to record the chip ID number, which is used for secondary identification of the chip's purpose.
[0014] The specific usage is as follows:
[0015] 1. During the chip design process, asymmetric public-private key pairs are generated in batches, with the public key being stored in the ROM in the chip (memory B). The private key is properly stored.
[0016] 2. After the chip is produced, the public key stored in memory B can be selected for different application scenarios or users. Once the public key to be used is determined, its index number is burned into memory C.
[0017] 3. Burn the chip ID number into memory D. The ID number can be different for each chip, or the same ID number can be used for the same usage scenario and user.
[0018] 4. After generating the second-stage execution code, the chip developer needs to concatenate the execution code with the chip ID number, obtain the summary using the summary algorithm, and sign the summary using the private key corresponding to the selected public key. The obtained signature is attached to the executable code.
[0019] 5. The first stage startup code in the Boot ROM moves the second stage execution code to the memory and then verifies it in the following order:
[0020] a) Check whether the chip ID data segment of the code is consistent with the chip's own ID number. If not, terminate the execution. If consistent, proceed to the next step:
[0021] b) Use the same digest algorithm as in step 4 to digest the data in the code segment except the signature.
[0022] c) Use the index in memory C to find the corresponding public key in memory B, and use the public key to verify the signature data and the summary data obtained in step b. If the verification passes, the processor is guided to jump to the second stage of code execution. If not, the execution is terminated.
[0023] The present invention provides a processor startup method that can be solidified in the Boot ROM, which supports trusted authentication of the next execution code of the processor and supports multiple authentication combinations. The present invention achieves the following beneficial effects:
[0024] 1. The same chip supports authentication of multiple trusted sources.
[0025] 2. The number of trusted sources can be adjusted by adjusting the number of public keys stored in the chip.
[0026] 3. Trusted sources are isolated from each other and do not affect each other.
[0027] Through the present invention, the same chip can execute different codes according to different users, and the codes executed by each user cannot be executed on the chips of other users. BRIEF DESCRIPTION OF THE DRAWINGS
[0028] Figure 1 It is a schematic diagram of the execution process of the Boot ROM code in the background art.
[0029] Figure 2 It is a schematic diagram of the composition of the processor chip according to an embodiment of the present invention.
[0030] Figure 3 It is a schematic diagram of the second-stage code signing process according to an embodiment of the present invention.
[0031] Figure 4 It is a schematic diagram of the Boot ROM signature verification process according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0032] In order to more clearly understand the purpose, technical solution and advantages of the present invention, the present invention will be further described in detail below in conjunction with the accompanying drawings and the preferred embodiments of the present invention. The illustrative embodiments and descriptions of the present invention are only used to explain the present invention and are not intended to limit the present invention. The implementation of the present invention is divided into three stages, including:
[0033] 1. Chip design and production stage. In this stage, a key pair is generated and the public key is solidified inside the chip.
[0034] 2. Chip factory and second-stage code generation stage. In this stage, the generated second-stage execution code is signed using the private key.
[0035] 3. Chip usage stage. In this stage, the second-stage execution code is verified using the public key and executed after confirmation of trust. This part of the signature verification function is implemented by the startup code stored in the Boot ROM inside the chip, and this part of the startup code is solidified inside the chip during chip design and production. The implementation solutions of the three stages will be described separately below.
[0036] Chip design and production stage. During the chip design process, the following steps need to be executed:
[0037] 1. Use the RSA2048 algorithm to generate 256 pairs of public and private keys. Among them, 256 private keys are properly stored. These private keys will be used for the code signing of the second stage.
[0038] 2. The 256 public keys are sequentially solidified in the ROM inside the chip. Since the length of each public key is 256 Byte, the capacity of the entire ROM is 64 KB (memory B).
[0039] 3. Add an 8-bit eFuse memory (Memory C) to the chip to record the index number of the public key determined to be used before the chip is delivered to the customer. The eFuse memory is a one-time programmable memory that can only be programmed once after the chip production is completed and cannot be changed after programming.
[0040] 4. Add a 128-bit eFuse memory (Memory D) to the chip to store the chip ID. The chip ID number is set before the chip leaves the factory and cannot be changed after one-time programming. The ID number can be different for each chip or the same ID number can be used for the same usage scenario and user.
[0041] 5. In the chip design and production stage, the initial startup code in the Boot ROM also needs to be solidified in the chip. The function of this part of the code will be described in detail in the third stage.
[0042] Chip factory and second-stage code generation stage. Before the chip is delivered to the customer, perform the following steps:
[0043] 1. Confirm the public and private key pairs used for trusted authentication and burn the number of the key pair into Memory C. For example, when it is confirmed that the 127th public key pair is used for trusted authentication, write the 8 bits of binary 01111111 (representing decimal 127) into Memory C.
[0044] 2. Generate a 128-bit chip ID number, which can be randomly generated. Burn the chip ID number into Memory D. This ID number will be used for code verification in the second stage.
[0045] 3. Sign the second-stage startup code. The specific process is as follows:
[0046] a) Concatenate the second-stage execution code with the chip ID number and obtain a digest using the SHA256 algorithm. The length of the digest is 32 bytes.
[0047] b) Sign the digest using the corresponding private key (taking the above example, the 127th private key) to obtain 32-byte signature data.
[0048] c) The chip ID number, the second-stage execution code, and the 32-byte signature constitute the complete second-stage startup data.
[0049] d) The second-stage startup data can be distributed to the corresponding users. The verification process in step three can ensure that this section of startup data can only be executed on chips that have burned the corresponding public key index and chip ID.
[0050] Chip usage phase. When the chip is in use, the second-stage startup data needs to be stored in the external memory of the chip. The Boot ROM will copy this code to the chip's memory and perform a trusted authentication on the code. The specific operation process of the code in the Boot ROM is as follows:
[0051] 1. Copy the second-stage startup data from the external memory to the chip's memory.
[0052] 2. Check whether the first 128-bit data of the startup data is consistent with the chip's own ID number. If not, terminate the execution.
[0053] 3. Use the SHA256 algorithm to digest the data of the code segment except the last 256-bit signature.
[0054] 4. Use the index in Memory C to find the corresponding public key (taking the above example, the 127th public key) in Memory B, and use this public key to perform a signature verification operation on the last 256-bit signature data of the code segment and the digest data obtained in step 3. If it passes, guide the processor to jump to the second stage to execute the code. If it fails, terminate the execution.
Claims
1. A method for manufacturing and using a processor chip that supports multi-source trusted authentication, characterized in that, The processor chip includes: Boot ROM read-only non-volatile memory A, which stores the first-stage startup code of the chip. This code is responsible for loading the next-stage code into the chip memory and performing trustworthy authentication on the next-stage code before execution; ROM read-only non-volatile memory B, which stores the solidified public key; The first eFuse one-time programmable memory C is used to record the effective public key index number. The value stored in the memory corresponds to the number of public key entries in the memory B. After the chip is produced, the eFuse allows one-time programming. After the programming is completed, the index value cannot be changed; The second eFuse one-time programmable memory D is used to record the chip ID number, and the chip ID number is used for secondary identification of the chip purpose; The following steps are involved: During the chip design process, asymmetric public-private key pairs are generated in batches, where the public key is stored in the memory B in the chip; After the chip is produced, the public key stored in memory B is selected according to different application scenarios or different user needs. After the public key to be used is determined, its index number is burned into memory C; the chip ID number is burned into memory D; After generating the second-stage execution code, the chip developer needs to concatenate the execution code with the chip ID number, obtain the digest using the digest algorithm, and sign the digest using the private key corresponding to the selected public key. The obtained signature is attached to the second-stage executable code. The first stage boot code in memory A moves the second stage execution code to memory and then verifies it in the following order: a) Check whether the chip ID data segment of the second-stage executable code is consistent with the chip's own ID number. If not, terminate the execution; if consistent, proceed to the next step: b) Using a digest algorithm consistent with the above digest algorithm, perform digest calculation on the data in the code segment except the signature; c) Use the index in memory C to find the corresponding public key in memory B, and use the public key to verify the signature data and the summary data obtained in step b). If the verification passes, the processor is guided to jump to the second stage execution code to run. If not, the execution is terminated.
2. A processor chip that supports multi-source trusted authentication manufactured by the manufacturing method according to claim 1, characterized in that, The processor chip includes: Boot ROM read-only non-volatile memory A, which stores the first-stage startup code of the chip. This code is responsible for loading the next-stage code into the chip memory and performing trustworthy authentication on the next-stage code before execution; ROM read-only non-volatile memory B, which stores the solidified public key; The first eFuse one-time programmable memory C is used to record the effective public key index number. The value stored in the memory corresponds to the number of public key entries in the memory B. After the chip is produced, the eFuse allows one-time programming. After the programming is completed, the index value cannot be changed; The second eFuse one-time programmable memory D is used to record the chip ID number, and the chip ID number is used for secondary identification of the chip purpose.
Citation Information
Patent Citations
Multi-core neural network processor chip of RISC-V architecture
CN114239806A
Testing and operating a multiprocessor chip with processor redundancy
US20130031418A1