Processing system, related integrated circuit, device and method
By introducing a cryptographic coprocessor and SIPI communication interface in the processing system, combined with DMA channel reconfiguration, the data encryption delay and bandwidth problems in the prior art are solved, and efficient data transmission and encryption operations are achieved.
Patent Information
- Application Number
- CN202210583662.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2022-05-18
- Filing Date
- 2022-05-25
- Publication Date
- 2025-09-02
- Estimated Expiration
- 2042-05-25
AI Technical Summary
Existing processing systems have problems with delay and available bandwidth when encrypting data and sending it through the SIPI communication interface, especially when large amounts of data are transmitted.
Using cryptographic coprocessor and SIPI communication interface, the DMA channel reconfiguration supports sending and receiving modes, implementing data encryption and decryption operations, and using DMA transmission technology to optimize the data transmission process.
Reduces the dependence of the data encryption process on the processing core, improves the efficiency and bandwidth of data transmission, and reduces the delay.
Smart Images

Figure CN115408313B_ABST
Abstract
Description
[0001] CROSS-REFERENCE TO RELATED APPLICATIONS
[0002] This application claims priority from Italian patent application No. 102021000013727, filed on May 26, 2021, entitled “Processing System, Related Integrated Circuit, Device and Method”, which is incorporated herein by reference. Technical Field
[0003] The present disclosure relates generally to electronic systems and methods, and in specific embodiments, to processing systems, related integrated circuits, devices, and methods. Background Art
[0004] Figure 1 A typical electronic system, such as that of a vehicle, is shown including a plurality of processing systems 10, such as embedded systems or integrated circuits, eg, field programmable gate arrays (FPGAs), digital signal processors (DSPs), or microcontrollers (eg, specific for the automotive market).
[0005] For example, in Figure 1 1 , three processing systems 101, 102, and 103 are shown, which are connected via a suitable communication system 20. For example, the communication system may include a vehicle control bus (such as a controller area network (CAN) bus) and a possible multimedia bus (such as a media oriented system transmit (MOST) bus) connected to the vehicle control bus via a gateway. Typically, the processing system 10 is located at different locations in the vehicle and may include, for example, an engine control unit, a transmission control unit (TCU), an anti-lock braking system (ABS), a body control module (BCM), and / or a navigation and / or multimedia audio system. Thus, one or more of the processing systems in the processing system 10 may also implement real-time control and regulation functions. These processing systems are generally identified as electronic control units.
[0006] Figure 2 Shown can be used as Figure 1 1 is a block diagram of an exemplary digital processing system 10, such as a microcontroller, for example.
[0007] In the example considered, the processing system 10 includes a microprocessor 102 (typically a central processing unit (CPU)) that is programmed via software instructions. Typically, the software executed by the microprocessor 102 is stored in a non-volatile program memory 104 (such as flash memory or EPROM). Thus, the memory 104 is configured to store firmware for the processing unit 102, wherein the firmware includes software instructions to be executed by the microprocessor 102. Generally speaking, the non-volatile memory 104 can also be used to store other data, such as configuration data, for example, calibration data.
[0008] Microprocessor 102 is also typically associated with volatile memory 104b, such as random access memory (RAM). For example, memory 104b may be used to store temporary data.
[0009] like Figure 2 As shown, communication with the memory 104 and / or 104b is typically performed via one or more memory controllers 100. The memory controller(s) 100 may be integrated into the microprocessor 102 or connected to the microprocessor 102 via a communication channel, such as a system bus of the processing system 10. Similarly, the memory 104 and / or 104b may be integrated with the microprocessor 102 in a single integrated circuit, or the memory 104 and / or 104b may take the form of separate integrated circuits and be connected to the microprocessor 102, for example, via traces of a printed circuit board.
[0010] In the example considered, the microprocessor 102 may be associated with one or more (hardware) resources / peripherals 106 selected from the group consisting of:
[0011] One or more communication interfaces IF, for example, for exchanging data via the communication system 20, such as a Universal Asynchronous Receiver / Transmitter (UART), a Serial Peripheral Interface Bus (SPI), an Inter-Integrated Circuit (I 2 C), Controller Area Network (CAN) bus, and / or Ethernet interface, and / or debug interface; and / or
[0012] one or more analog-to-digital converters AD and / or digital-to-analog converters DA; and / or
[0013] One or more dedicated digital components DC, such as hardware timers and / or counters, or cryptographic co-processors; and / or
[0014] One or more analog components AC, such as comparators, sensors such as temperature sensors, etc.; and / or
[0015] One or more mixed signal components MSC, such as PWM (Pulse Width Modulation) drivers.
[0016] Typically, the dedicated digital component DC may also correspond to an FPGA integrated in the processing system 10. In this case, for example, the memory 104 may also include program data for such an FPGA.
[0017] Thus, the digital processing system 10 can support different functionalities. For example, the behavior of the microprocessor 102 is determined by firmware (e.g., software instructions executed by the microprocessor 102 of the microcontroller 10) stored in the memory 104. Thus, by installing different firmware, the same hardware (microcontroller) can be used for different applications.
[0018] In this respect, future generations of such processing systems 10 (e.g., microcontrollers suitable for use in automotive applications) are expected to exhibit an increase in complexity, primarily due to an increase in the number of requested functionalities (new protocols, new features, etc.) and strict constraints on execution conditions (e.g., lower power consumption, increased computing power and speed, etc.).
[0019] For example, more complex multi-core processing systems 10 have recently been proposed. For example, such multi-core processing systems can be used to execute (in parallel) Figure 1 Several of the processing systems 10 are shown, such as several processing systems of a vehicle.
[0020] Figure 3 An example of a multi-core processing system 10 is shown. Specifically, in the example considered, the processing system 10 comprises n processing cores 1021 to 1022 connected to an (on-chip) communication system 114. n For example, in the context of a real-time control system, processing cores 1021 to 102 n Can be ARM - R52 core. In general, the communication system 114 may include one or more bus systems based on, for example, the Advanced eXtensible Interface (AXI) bus architecture and / or a Network on Chip (NoC).
[0021] For example, as shown in the example of processing core 1021, each processing core 102 may include a microprocessor 1020 and a communication interface 1022 configured to manage communications between the microprocessor 1020 and the communication system 114. Typically, the interface 1022 is a master interface configured to forward a given (read or write) request from the microprocessor 1020 to the communication system 114 and to forward an optional response from the communication system 114 to the microprocessor 1020. However, the processing core 102 may also include a slave interface 1024. In this manner, for example, a first microprocessor 1020 may send a request to a second microprocessor 1020 (via the first microprocessor's communication interface 1022, the communication system 114, and the second microprocessor's communication interface 1024).
[0022] Typically, each processing core 1021 to 102 n Additional local resources may also be included, such as one or more local memories 1026, often identified as Tightly Coupled Memory (TCM).
[0023] As previously mentioned, typically, the processing cores 1021 to 102 n Arranged to exchange data with non-volatile memory 104 and / or volatile memory 104b. In a multi-core processing system 10, these memories are typically for example for processing cores 1021 to 102 n However, as described above, each processing core 1021 to 102 n One or more additional local memories 1026 may be included.
[0024] For example, Figure 3 As shown, the processing system 10 may include one or more memory controllers 100 configured to connect at least one non-volatile memory 104 and at least one volatile memory 104b to the communication system 114. As previously described, one or more of the memories 104 and / or 104b may be integrated into an integrated circuit of the processing system 10 or externally connected to the integrated circuit. For example, the processing system 10 may include:
[0025] A first volatile memory 104b, integrated in an integrated circuit of the processing system 10 and connected to the communication system 114 via the first memory controller 100, and
[0026] The second volatile memory 104 b is external to the integrated circuit of the processing system 10 and is connected to the communication system 114 via the second memory controller 100 .
[0027] As previously mentioned, processing system 10 may include one or more resources 106, such as one or more communication interfaces or coprocessors (e.g., a cryptographic coprocessor). Resources 106 are typically connected to communication system 114 via corresponding slave communication interfaces 1064. For example, in this manner, processing core 102 can send a request to a resource 106, and the resource returns given data. Typically, one or more of resources 106 may also include a corresponding master interface 1062. Such a master interface 1062 may be useful, for example, when a resource must initiate communication in order to exchange data (read and / or write) with another circuit connected to communication system 114 (such as resource 106 or processing core 102). For example, for this purpose, communication system 114 may actually include an Advanced Microcontroller Bus Architecture (AMBA) high-performance bus (AHB) and an Advanced Peripheral Bus (APB) for connecting resources / peripherals 106 to the AMBA AHB bus.
[0028] Typically, such a processing system 10 also includes one or more direct memory access (DMA) controllers 110. Specifically, the DMA controller 110 includes at least one functional channel connected to the resources 106. Typically, the resource 106 associated with a given channel can also be selected based on configuration data. Specifically, the DMA channel is configured to transfer data from a source address to a destination address. For example, in this way, the communication interface IF can be connected to the DMA controller 110 via two channels:
[0029] a first channel configured to autonomously transfer data from a source address (eg associated with a first memory range in the memory 104b) to the communication interface IF; and
[0030] - a second channel configured to transfer data from the communication interface IF to a target address (eg associated with a second memory range in the memory 104b).
[0031] Therefore, the DMA controller 110 is generally associated with:
[0032] - a slave interface 1104 for receiving configuration data from the communication system 114, the configuration data being used to configure the channels of the DMA controller 110, such as the address range associated with each channel; and
[0033] A master interface 1102 for sending read or write requests to the memory controller 100 via the communication system 114 .
[0034] Typically, DMA controller 110 may also be connected directly to a DMA interface of memory controller 110 , rather than sending read or write requests indirectly (via communication system 114 ) to memory controller 110 .
[0035] For example, Figure 4 shows a DMA channel for communicating via the communication interface IF (in Figure 4 For example, as will be described below, the present application specifically relates to a case where the communication interface 50 is a serial inter-processor interface (SIPI).
[0036] Specifically, in the example considered, the data to be transmitted TD are stored to a given memory range in the volatile memory 104 b of the processing system 10 .
[0037] Thus, once the transmission of data has been requested, for example because the processing core 102 sends a corresponding transmission request to the corresponding slave interface ( Figure 4 Not shown, but can be referred to Figure 3 1064 of the slave interface 1064), the control circuit 506 of the communication interface 50 can generate a request signal REQ1, which is provided to the first DMA channel 1101. Specifically, the corresponding DMA controller 110 is configured to transfer one or more bytes from the source address to the destination address in response to the request signal REQ1. Therefore, the DMA channel 1101 can be used to read data TD, which is provided to one or more registers 502 of the communication interface 50. For example, the registers 502 may include one or more data registers for storing data bytes to be transmitted.
[0038] The data stored in the one or more registers 502 is then provided to the hardware communication interface 504 of the communication interface 50 so as to be transmitted via one or more terminals 10 (such as pads of a corresponding integrated circuit die, or pins of a corresponding packaged integrated circuit). For example, the hardware communication interface 504 may be a SIPI interface circuit configured to generate a SIPI frame, which is then transmitted via a physical interface (particularly a fast asynchronous serial transmit (LFAST) interface), the LFAST interface including:
[0039] - a differential transmitter configured to transmit the bits of the LFAST frame via two differential data lines SIPI_TXP and SIPI_TXN; and
[0040] - A differential receiver configured to receive the bits of the LFAST frame via two differential data lines SIPI_RXP and SIPI_RXN.
[0041] Those skilled in the art will appreciate that the LFAST transceiver can operate at a low-speed operating frequency (typically 5 MHz) and a high-speed operating frequency (typically 320 MHz). In addition, the various transceivers are synchronized via the PLLs (typically supporting 32 or 16 PLL multipliers) of the transceivers that exchange a reference clock signal REFCLOCK (typically set to 10 MHz or 20 MHz).
[0042] In essence, each SIPI frame comprises a SIPI header, a SIPI payload corresponding to data to be sent and a SIPI CRC field, is used to transmission layer and session layer. Otherwise, the LFAST interface is used to exchange LFAST frames, and this LFAST frame comprises a LFAST header, a LFAST payload corresponding to the SIPI frame and a stop bit. Therefore, LFAST is used to media layer (physical layer, data link layer and network layer). This SIPI-LFAST communication interface is also referred to as Zipwire usually.
[0043] Thus, in the case of a SIPI communication interface, processing core 102 may configure SIPI communication interface 50, for example, to use given SIPI header information.
[0044] For a general description of SIPI and LFAST, reference may be made, for example, to the document Application Note AN5134, Introduction to the Zipwire Interface, Inter-Processor Communication with SIPI / LFAST on MPC57xx and S32Vxxx Family, by Randy Dees et al., Edition 0, May 2015, Freescale Semiconductor, which is incorporated herein by reference for this purpose.
[0045] For security reasons, it is often preferable to send encrypted data ED. This also applies to automotive applications, for example, especially after it has been demonstrated how hackers can remotely control cars. Therefore, in this case, processing system 10 may include a cryptographic coprocessor 40, such as an AES (Advanced Encryption Standard) coprocessor.
[0046] Thus, the processing core 102 can store the original / unencrypted data OD to a given memory range in the volatile memory 104b of the processing system 10. Furthermore, the processing core 102 can send a command ENCCMD to the cryptographic coprocessor 40, for example, specifying the number of bytes of the data OD to be encrypted. Furthermore, the command ENCCMD can also specify a configuration for encrypting the data OD. For example, in the case of an AES communication interface, the command ENCCMD can indicate the type of operation to be used, such as an electronic codebook (ECB) or cipher block chaining (CBC).
[0047] Therefore, once encryption of the data has been requested, the control circuit 406 of the coprocessor 40 can generate a request signal REQ2, which is provided to the second DMA channel 1102. Thus, the DMA channel 1102 can be used to read the data OD provided to one or more registers 402 of the coprocessor 40. For example, the registers 402 may include one or more data registers for storing bytes of data to be encrypted. The data stored in the one or more registers 502 is then provided to the hardware encryption processor 404 of the coprocessor 40 to encrypt the data OD. Therefore, in this case, the DMA channel 1102 should be configured to transfer one or more bytes of the data OD to be encrypted from the memory 104b to the data register(s) of the coprocessor 40.
[0048] Specifically, the encrypted data ED generated by the hardware encryption processor 404 is stored in one or more additional registers 408 of the coprocessor 40. Therefore, once the encryption of the data has been completed, the control circuit 406 of the coprocessor 40 can generate a request signal REQ3, which is provided to the DMA channel 1103. Specifically, the corresponding DMA controller 110 is configured to transfer the data from the register(s) 408 to the memory 104b in response to the request signal REQ3.
[0049] Thus, by configuring the DMA channel 1103 so as to transfer the encrypted data ED to the memory range associated with the data to be sent TD, the communication interface 50 can directly send the encrypted data ED. Thus, in the example considered, the processing core 102 can:
[0050] -Configure DMA channels 1101, 1102 and 1103;
[0051] - Send a request to start data encryption operation;
[0052] -Wait until the encryption operation is completed;
[0053] - Send a request to start a data sending operation; and
[0054] -Wait until the data sending operation is completed. Summary of the Invention
[0055] Figure 4 The solution shown in allows encryption of data OD and transmission of the encrypted data ED without significant involvement of the processing core(s) 102. However, the interface 50 cannot transmit the encrypted data ED until all the data has been encrypted. This presents problems in terms of latency and available bandwidth, particularly when large amounts of data must be transmitted, for example, in streaming mode using the SIPI protocol.
[0056] In view of the above, some embodiments provide a solution for encrypting data via an AES coprocessor and sending the encrypted data via a SIPI communication interface.
[0057] Embodiments of the present disclosure relate to a processing system, such as a microcontroller, configured to encrypt data and transmit the encrypted data, and / or receive data and decrypt the received data.
[0058] Some embodiments are directed to processing systems having the features set out in particular in the appended claims. Embodiments are also directed to related integrated circuits, devices and methods.
[0059] The claims are an integral part of the disclosed technical teaching provided herein.
[0060] As previously mentioned, various embodiments of the present disclosure relate to a processing system (such as a microcontroller), for example, integrated in an integrated circuit.
[0061] In various embodiments, the processing system includes a microprocessor programmable via software instructions, a memory controller configured to connect to a memory, and a communication system connecting the microprocessor to the memory controller. In various embodiments, the processing system also includes a cryptographic coprocessor (such as an AES coprocessor) and a serial interprocessor interface (SIPI) communication interface.
[0062] Specifically, in various embodiments, a cryptographic coprocessor includes: a plurality of input data registers configured to store a first data block having 16 bytes, wherein the number of the input data registers corresponds to a first number of registers; a plurality of output data registers configured to store a first processed data block, wherein the number of the output data registers corresponds to the first number of registers; and a control register programmable by a microprocessor and configured to store first configuration data. The cryptographic coprocessor also includes cryptographic processing circuitry configured to process (i.e., encrypt or decrypt) data stored in the input data registers according to the first configuration data stored in the control registers and store the corresponding processed data in the output data registers, wherein the cryptographic processing circuitry is configured to generate a first control signal when the processed data has been stored in the output data registers.
[0063] In various embodiments, a cryptographic coprocessor enables the use of DMA transfers. Specifically, in this case, the cryptographic coprocessor includes a first DMA interface circuit and a second DMA interface circuit. Specifically, the first DMA interface circuit is configured to generate a first request signal requesting that a new first data block be transferred to an input data register. Specifically, to this end, the first DMA interface circuit may assert the first request signal based on first configuration data stored in a control register (specifically for the first DMA request and / or to implement the DMA transfer) and in response to a synchronization signal provided by a second DMA interface circuit (specifically for subsequent DMA requests), and de-assert the first request signal in response to a first confirmation signal. The second DMA interface circuit is configured to generate a second request signal requesting that a first processed data block be transferred from an output data register. Specifically, to this end, the second DMA interface circuit may assert the second request signal based on a first control signal provided by the cryptographic processing circuit, and de-assert the second request signal in response to a second confirmation signal. The second DMA interface circuit is further configured to assert a synchronization signal in response to the second confirmation signal.
[0064] The SIPI communication interface may include a SIPI transmitter and / or a SIPI receiver.
[0065] In the case of a SIPI transmitter, the SIPI communication interface includes: a plurality of transmit data registers configured to store a second data block having 32 bytes, wherein the number of transmit data registers corresponds to a second number of registers, wherein the second number of registers corresponds to double the first number of registers; and a control register programmable by the microprocessor and configured to store second configuration data. Furthermore, the SIPI communication interface includes a hardware SIPI communication interface, specifically including at least one SIPI transmitter configured to transmit data stored in the transmit data register according to the second configuration data stored in the control register, wherein the SIPI hardware communication interface is configured to generate a second control signal when the data stored in the transmit data register has been transmitted.
[0066] In various embodiments, such a SIPI communication interface allows the use of DMA transmission for data to be transmitted. Specifically, in this case, the SIPI communication interface includes a DMA interface circuit that is configured to generate a third request signal that requests the transfer of a new second data block to the transmit data register. To this end, the DMA interface circuit can assert the third request signal based on second configuration data stored in the control register (particularly for the first DMA request and / or to implement DMA transmission) and in response to a second control signal (particularly for subsequent DMA requests), and de-assert the third request signal in response to a third confirmation signal.
[0067] Conversely, in the case of a SIPI receiver, the SIPI communication interface is associated with a storage element having a plurality of slots configured to store a second data block having 32 bytes. Specifically, in various embodiments, the number of slots corresponds to twice the first number of registers. Specifically, as will be described in more detail below, the storage element can be implemented using a receive data register of the SIPI communication interface or a temporary buffer implemented using a memory slot in a memory.
[0068] Furthermore, the SIPI communication interface comprises a hardware SIPI communication interface, in particular comprising at least one SIPI receiver configured to receive data and store the received data in a slot of the storage element, wherein the SIPI hardware communication interface is configured to generate a second control signal when the SIPI hardware communication interface has stored 32 bytes in the slot of the storage element.
[0069] In various embodiments, such a SIPI communication interface allows for DMA transfer of received data. Specifically, in this case, the SIPI communication interface includes a DMA interface circuit configured to generate a third request signal requesting that a second block of data be transferred from a slot of a storage element. To this end, the DMA interface circuit may assert the third request signal in response to a second control signal and deassert the third request signal in response to a third confirmation signal.
[0070] For example, where the storage element is implemented with a receive data register, the SIPI hardware communication interface is configured to assert the second control signal when the SIPI hardware communication interface has stored 32 bytes into the receive data register.
[0071] Alternatively, where the storage element is implemented using a memory slot in a memory, the SIPI hardware communication interface may include: a plurality of receive data registers, wherein the SIPI hardware communication interface is configured to assert a third control signal when the SIPI hardware communication interface has stored 32 bytes in the receive data registers; and an additional DMA channel configured to transfer data from the receive data registers to the memory slot in the memory in response to the third control signal. Thus, once 32 bytes have been transferred from the receive data registers to the memory slot in the memory, the additional DMA channel may assert the second control signal.
[0072] In various embodiments, such a cryptographic coprocessor and a SIPI communication interface including a SIPI transmitter can be used to transmit encrypted data. Specifically, in this case, a first DMA channel can be configured to transmit data to the cryptographic coprocessor, and a second DMA channel can be configured to transmit data from the cryptographic coprocessor to the SIPI communication interface.
[0073] For example, the first DMA channel can be configured to: in response to a first request signal provided by the cryptographic coprocessor, send a request to the memory controller to transfer a new first data block from the memory to the input data register of the cryptographic coprocessor, and assert a first confirmation signal once the new first data block has been transferred from the memory to the input data register.
[0074] The second DMA channel can be configured to receive an initial source address and an initial destination address, wherein the initial source address corresponds to an address associated with a first register in the output data registers, and the initial destination address corresponds to an address associated with a first register in the transmit data registers. Next, the second DMA channel sets the source address to the initial source address, sets the destination address to the initial destination address, and executes two loops. During each loop, the second DMA channel executes a given number of data transfer operations from the source address to the destination address in response to the DMA request signal, wherein the given number of data transfer operations corresponds to the first number of registers, and wherein the source address and destination address increment for each data transfer operation. Furthermore, once the given number of data transfer operations have been executed, the second DMA channel asserts a second acknowledge signal provided to the cryptographic coprocessor and resets the source address to the initial source address. Once the two loops have been executed, the second DMA channel asserts a third acknowledge signal provided to the SIPI communication interface and resets the destination address to the initial destination address.
[0075] In this case, the processing system further includes a request control circuit configured to assert a DMA request signal for the second DMA channel in response to determining that a second request signal provided by the cryptographic coprocessor and a third request signal provided by the SIPI communication interface are asserted, and to deassert the DMA request signal in response to determining that the second request signal or the third request signal is deasserted.
[0076] In various embodiments, a SIPI communication interface including a SIPI receiver and a cryptographic coprocessor can be used to receive data and decrypt the received data. Specifically, in this case, a first DMA channel can be configured to transfer data from the cryptographic coprocessor to the memory, and a second DMA channel can be configured to transfer data from the SIPI communication interface to the cryptographic coprocessor.
[0077] For example, the first DMA channel can be configured to: in response to a second request signal provided by the cryptographic coprocessor, send a request to the memory controller to transfer the first data block from the output data register to the memory, and assert a second confirmation signal provided to the cryptographic coprocessor once the first data block has been transferred from the output data register to the memory.
[0078] The second DMA channel can be configured to: receive an initial source address and an initial destination address, wherein the initial source address corresponds to an address associated with a first slot in a storage element, and the initial destination address corresponds to an address associated with a first register in an input data register of a cryptographic coprocessor. For example, based on the implementation of the storage element, the initial source address can correspond to an address associated with a first register in a receive data register, or to an address associated with a first memory slot in a memory. Next, the second DMA channel sets the source address to the initial source address, sets the destination address to the initial destination address, and executes two loops. During each loop, the second DMA channel executes a given number of data transfer operations from the source address to the destination address in response to a DMA request signal, wherein the given number of data transfer operations corresponds to a first number of registers, and wherein the source address and the destination address are incremented for each data transfer operation. Furthermore, once the given number of data transfer operations have been executed, the second DMA channel asserts a first confirmation signal provided to the cryptographic coprocessor, and resets the destination address to the initial destination address. Once two loops have been executed, the second DMA channel asserts a third confirmation signal provided to the SIPI communication interface, and resets the source address to the initial source address.
[0079] Therefore, also in this case, the processing system includes a request control circuit configured to: assert the DMA request signal provided to the second DMA channel in response to determining that the first request signal provided by the cryptographic coprocessor and the third request signal provided by the third SIPI communication interface, and de-assert the DMA request signal in response to determining that the first request signal or the third request signal is de-asserted.
[0080] Thus, when implementing either the transmit or receive chain, the processing system uses, in both cases, a second DMA channel configured to perform two cycles of the same number of data transfers, which allows assertion of corresponding acknowledgement signals provided to the DMA interface circuitry of the cryptographic coprocessor and the SIPI communication interface. Furthermore, in both cases, a request control circuit is used to synchronize the corresponding request signals provided by the DMA interface circuitry of the cryptographic coprocessor and the SIPI communication interface.
[0081] Therefore, in various embodiments, the processing system can support two modes, namely, a transmit mode and a receive mode, by reconfiguring the first DMA channel and the second DMA channel. For example, to this end, the first DMA channel and the second DMA channel can be implemented using a general-purpose DMA controller configured to transfer data by sending a read request to a corresponding source address and sending a write request to a corresponding destination address, the write request including data received in response to the read request.
[0082] In various embodiments, in the case of a transmit chain, a cryptographic operation may be initiated in response to a first confirmation signal provided by a first DMA channel. Conversely, in the case of a receive chain, a cryptographic operation may be initiated in response to a second confirmation signal provided by a second DMA channel.
[0083] Alternatively, the cryptographic operation may be started by writing a control command to a control register of the cryptographic coprocessor. For example, for this purpose, the processing system may include an additional DMA channel configured to transmit an encryption or decryption command from a fixed source address to an address associated with a first control register of the cryptographic coprocessor once a new first block has been stored in an input data register of the cryptographic coprocessor, as notified, for example, via an acknowledgement signal of the corresponding DMA channel used to transfer the corresponding data block. BRIEF DESCRIPTION OF THE DRAWINGS
[0084] Embodiments of the present disclosure will now be described with reference to the accompanying drawings, provided by way of non-limiting examples only, in which:
[0085] Figure 1 An example of an electronic system including multiple processing systems is shown;
[0086] Figure 2 and Figure 3 An example of a processing system is shown;
[0087] Figure 4 An example of a processing system configured to encrypt data and transmit the encrypted data is shown;
[0088] Figure 5 An embodiment of a processing system including a cryptographic coprocessor, such as an AES coprocessor, is shown;
[0089] Figure 6 and Figure 7 An embodiment of a DMA controller is shown;
[0090] Figure 8 An embodiment of a processing system including a serial communication interface, such as a SIPI communication interface, is shown;
[0091] Figure 9 、 Figure 10A 、 Figure 10B 、 Figure 10C and Figure 11 An embodiment of a processing system configured to encrypt data and transmit the encrypted data is shown;
[0092] Figure 12 、 Figure 13A 、 Figure 13B 、 Figure 13C and Figure 14 An embodiment of a processing system configured to receive data and decrypt the received data is shown; and
[0093] Figure 15 、 Figure 16A 、 Figure 16B 、 Figure 16C and Figure 17 Another embodiment of a processing system configured to receive data and decrypt the received data is shown. DETAILED DESCRIPTION
[0094] In the following description, numerous specific details are provided to provide a thorough understanding of the embodiments. The embodiments may be practiced without one or more of the specific details (or with other methods, components, materials, etc.). In other instances, well-known structures, materials, or operations are not shown or described in detail to avoid obscuring aspects of the embodiments.
[0095] Reference throughout this specification to "one embodiment" or "an embodiment" means that a particular feature, structure, or characteristic described in connection with the embodiment is included in at least one embodiment. Thus, appearances of the phrases "in one embodiment" or "in an embodiment" throughout this specification are not necessarily all referring to the same embodiment. Furthermore, the particular features, structures, or characteristics may be combined in any suitable manner in one or more embodiments.
[0096] The headings provided herein are for convenience only and do not interpret the scope or meaning of the embodiments.
[0097] In the following Figures 5 to 17 In, reference has been made Figures 1 to 4 Described parts, elements or components are indicated by the same reference numerals used previously in the figure; in order not to unduly burden this detailed description, the description of these previously described elements will not be repeated below.
[0098] Figure 5 An embodiment of a processing system 10a is shown that includes a cryptographic coprocessor 40a.
[0099] In the embodiment under consideration, the underlying architecture of the processing system 10a corresponds to Figures 1 to 4The processing system described herein and the corresponding description applies in its entirety. Thus, also in this case, the processing system 10a, such as an integrated circuit, comprises:
[0100] - a communication system 114, such as a bus or a NoC;
[0101] at least one processing core 102a, wherein each processing core comprises at least one microprocessor 1020 and at least one communication interface 1022, the communication interface 1022 being configured to connect the microprocessor(s) 1020 to the communication system 114;
[0102] at least one memory controller 100 configured to be connected to (internal or external) non-volatile memory 104 and / or volatile memory 104b;
[0103] - Cryptographic coprocessor 40a;
[0104] - At least two DMA channels T1 and DMA T2 , which may belong to the same DMA controller 110 or to two separate DMA controllers 110; and
[0105] - Optional additional circuitry, such as one or more resources / peripherals 106 .
[0106] Specifically, in the embodiment under consideration, the cryptographic coprocessor 40a includes a cryptographic processing circuit 404 configured to perform cryptographic operations based on a symmetric cipher, in particular the AES cryptographic algorithm. Typically, the AES algorithm processes blocks of 16 bytes (128 bits) at a time, referred to as AES blocks.
[0107] Thus, in the embodiment under consideration, the cryptographic processing circuit 404 is associated with a register DATAIN for storing data to be processed and a register DATAOUT for storing processed data. For example, assuming a 64-bit processing system 10a, the cryptographic coprocessor 40a may include:
[0108] - two input data registers DATAIN0 and DATAIN1, each having 8 bytes (64 bits) for storing data to be processed; and
[0109] - Two output data registers DATAOUT0 and DATAOUT1, each with 8 bytes (64 bits), for storing processed data.
[0110] Typically, the number and size of the input data registers DATAIN and the output data registers DATAOUT depend on the number of bits w to be transmitted via the communication system 114. Specifically, the size of the input data registers DATAIN and the output data registers DATAOUT corresponds to the number w, and the number of registers k can be calculated as 128 / w. For example, in the case of a 32-bit (i.e., w=32) system, four (i.e., k=128 / w=4) registers DATAIN0 to DATAIN3, each having a size of 32 (i.e., w) bits, will be used. In addition, the same number of output data registers DATAOUT can be used, or the register DATAIN can be used to store both the data to be processed and the processed data, i.e., the output data registers DATAOUT can correspond to the registers DATAIN.
[0111] Furthermore, the cryptographic processing circuit 404 is associated with one or more control registers CONTROL for storing control data. For example, in various embodiments, the (or each) control register has w bits, such as 64 bits.
[0112] For example, Figure 5 As schematically shown, the cryptographic coprocessor 40a may include a slave interface 410 connected to the communication system 114 and configured to interface the control register(s) CONTROL, the input data register DATAIN, and the output data register DATAOUT with the communication system 114 through an interface.
[0113] For example, in this manner, processing core 102 may send a request sequence REQ to slave interface 410 to:
[0114] - write the contents of the input data register DATAIN and the contents of the control register(s) CONTROL, and
[0115] - Once the cryptographic operation has been performed, read the contents of the output data register DATAOUT.
[0116] Thus, in the embodiment considered, the cryptographic processing circuit 404 is configured to generate data stored to the output data register DATAOUT by performing a cryptographic operation on data stored to the input data register DATAIN in accordance with data stored to the control register(s) CONTROL.
[0117] For example, in various embodiments, the cryptographic coprocessor 40 can be configured to use AES cipher block chaining (CBC) mode. In this case, data is encrypted (or decrypted) based on a combination of the result of the previous block merged with the new AES block. Secret keys are involved during data processing, so data can only be decrypted if the entity encrypting the data and the entity decrypting the data use the same secret key / cryptographic key. Key sharing is typically performed during startup and specific implementation of the processing system and is not of particular interest to this disclosure. Therefore, the data stored in the control register(s) specifies the operation to be performed, such as the encryption or decryption operation, the AES mode to be used, the optional secret key that should be used, etc.
[0118] like Figure 5 As shown, in the embodiment considered, the cryptographic coprocessor 40a also includes two DMA interfaces 406a and 406b. Specifically, the first interface 406a is connected to the DMA channel DMA T1 , and generates a first request signal REQ1 for requesting new data to be processed. Conversely, the second interface 406b is connected to the DMA channel DMAT2, and generates a second request signal REQ2 for requesting to read processed data.
[0119] Generally, based on the implementation of the cryptographic processing circuit 404 , cryptographic operations may be initiated in various modes.
[0120] For example, in various embodiments, the processing core 102 is configured to first write a start command INIT to the control register CONTROL, whereby the control command indicates the parameters to be used for the cryptographic operation. The processing core 102 may then encrypt one or more data blocks by writing the data to be encrypted to the input data register DATAIN and optionally writing a new command ENCCMD to the control register CONTROL, where the command ENCCMD indicates that the parameters of the previously initialized cryptographic operation should be used.
[0121] Similarly, when DMA transfer is used, the control command INIT can implement DMA transfer for the DMA interface 406a. Therefore, in response to the command INIT, the DMA interface 406a asserts the first request signal REQ1. Therefore, in this case, the DMA channel DMA T1 Should it be configured to read from a memory such as volatile memory 104b, for each cryptographic operation, one AES block, i.e., 128 bits of data, will be stored into the input data register DATAIN.
[0122] In various embodiments, DMA channel DMA TlTherefore, it can also be configured to transfer a new command ENCCMD to the control register CONTROL, that is, transfer w bits of data to the control register CONTROL, thereby starting the processing operation for the AES block. For example, in the case of w=64 bits, the DMA channel DMA T1 It may be configured to transfer 24 bytes from the memory controller 100 associated with the memory 104b to registers DATAIN and CONTROL.
[0123] Typically, the DMA controller may be a general-purpose DMA controller or an integrated DMA controller integrated into a circuit of the processing system 10a, such as the memory controller 100, the cryptographic coprocessor 40, or the communication interface IF. Generally, a common feature of such DMA controllers is that each data transfer is identified by a given source address and a given destination address.
[0124] Specifically, in the case of a general-purpose DMA controller, the DMA controller is configured as follows:
[0125] - Start a read transfer including the source address;
[0126] - Once data corresponding to a response to a read request is received, a write transfer including a target address and the received data is started.
[0127] Therefore, in this case, two communications are performed via the communication system 114. For example, to implement a DMA channel DMA Tl , the source address may point to the memory 104b and the destination address may point to one of the registers DATAIN or CONTROL.
[0128] On the contrary, in case of integrated DMA channel, one of the communications via the communication system 114 can be omitted. T1 It can be an integrated DMA channel of the memory controller 100 or the coprocessor 40a. In the former case, the DMA channel DMA T1 Only the address range handled by the memory controller 100 is managed as the source address, and the memory controller 100 is configured to directly read data from the source address of the memory 104b and send a write request including the target address and read data associated with one of the registers DATAIN or CONTROL to the communication system 114, so that the read data is received by the slave interface 410 of the coprocessor 40a and stored in one of the registers DATAIN or CONTROL. Conversely, in the latter case, the DMA channel DMA T1Only the address associated with register DATAIN or CONTROL is managed as the target address, and it is configured to send a read request including the memory address of memory 104b as the source address, and directly store the received data in one of registers DATAIN or CONTROL. Therefore, in the case of an integrated DMA controller, a single communication is performed via communication system 114. In general, instead of sending a write or read request via communication system 114, a dedicated DMA communication interface of memory controller 100 can also be used.
[0129] For example, independent of DMA channel DMA Tl In a specific implementation, in order to correctly map the data in the memory 104b to the registers DATAIN and CONTROL, the data stored in the memory 104b may always include a sequence of three groups, the three groups including two original data groups to be stored in the registers DATAIN0 and DATAIN1 and one control data group to be stored in the register CONTROL.
[0130] Alternatively, Figure 5 As shown, the control data ENCCMD to be transmitted to the (multiple) control registers CONTROL can be stored in the first address ADR l The first memory location at which the data OD to be processed (such as packets OD1 to OD n ) can be stored to n memory locations starting at the second address ADR2. Thus, in this case, the DMA channel DMA T1 Can be configured to perform the following operations for each AES processing cycle:
[0131] - transferring k data words from the memory 104b to the input data register DATAIN, wherein the source address corresponds to ADR2, ADR2 being incremented for each data transfer, and wherein the destination address sequentially points to one of the input data registers DATAIN; and
[0132] - Transfer command ENCCMD from fixed address ADR1 to the target address associated with register CONTROL.
[0133] For example, DMA channel DMA Tl The above-described configuration can be implemented using a specific configuration of a (eg, general-purpose) DMA controller included in various microcontrollers sold by the present applicant.
[0134] Figure 6 In this regard, an embodiment of a DMA controller 110a is shown.
[0135] Specifically, in the embodiment considered, the DMA controller 110a comprises at least two DMA channels DMA CHl and DMA CHl For example, in the embodiment considered, the DMA controller 110a comprises a slave interface 1104 connected to the communication system 114 for configuring the DMA channel DMA CH1 and DMA CH1 For example, each of the DMA channels may be associated with a corresponding configuration register. For example, as other programmable registers, each configuration register may be associated with a corresponding physical address (within an address range managed by the communication system 114), whereby the configuration register may be programmed, for example, via software instructions, by sending a write request including the corresponding address of the configuration register to the communication system 114. For example, each DMA channel may be:
[0136] an integrated DMA write channel, wherein the DMA channel is directly connected to at least one register of the associated circuitry and is configured to send the contents of the register (essentially identified via a source address) to the communication system 114 or directly to the memory controller 100 via a write request (including a target address);
[0137] an integrated DMA read channel, wherein the DMA channel is directly connected to at least one register of the associated circuitry and is configured to send read requests (including a source address) to the communication system 114 or directly to the memory controller 100 and store the corresponding received data to a register (essentially identified via a target address); or
[0138] - A general DMA channel, wherein the DMA channel is configured to send a read request (including a source address) to the communication system 114, temporarily store the corresponding received data, and send the temporarily stored data to the communication system 114 via a write request (including a target address).
[0139] Specifically, if Figure 7 As shown, in various embodiments, each DMA channel is configured to implement two cycles: a secondary cycle and a primary cycle. For example, to this end, the DMA channel can be implemented using a control circuit associated with the above-mentioned configuration register, which is configured to store channel configuration data, and the channel configuration data can be programmed via the slave interface 1104.
[0140] Specifically, after starting step 2000, the DMA channel may verify in step 2002 whether the request signal R is asserted, such as for channel DMA CHl The request signal R Cl Or for channel DMA CH2 The request signal RC2 Typically, the DMA channel may also verify further conditions at step 2002, such as whether the DMA channel is implemented as indicated by the channel configuration data stored to the configuration register.
[0141] If the request signal R is deasserted (output "N" of verification step 2002), the DMA channel returns to step 2002. Conversely, if the request signal R is asserted (output "Y" of verification step 2002), the DMA channel performs a data transfer operation between the source address and the target address, for example, by executing a read or write request, or first executing a read request and then executing a write request, in step 2004. For example, the initial source address and the initial target address may be stored in the channel configuration data.
[0142] In the embodiment under consideration, the DMA channel then verifies whether a given number of requested transfers have been performed in step 2006. For example, the number of requested transfers may be stored to a configuration register.
[0143] If the number of transfers is less than the number of transfers requested (output "N" of verification step 2006), the DMA channel proceeds to step 2008, where the DMA channel, for example, increments a first counter that identifies the number of transfers. However, the DMA channel may also perform one or more further operations, which may be programmed according to channel configuration data, such as incrementing the source address and / or the destination address. Next, the DMA channel returns to step 2002 to perform the next data transfer in response to the request signal R.
[0144] On the other hand, in the case that the number of transfers reaches the number of transfers requested (output "Y" of verification step 2006), the DMA channel sets a first confirmation signal A1 in step 2010, such as for channel DMA CH1 Confirmation signal A1 C1 Or for channel DMA CH2 Confirmation signal A1 C2 , and resets the first counter. Thus, the first acknowledgement signal indicates the completion of the first cycle of the requested transmission, indicated below as the secondary cycle.
[0145] In the embodiment under consideration, the DMA channel then verifies whether a given number of requested cycles have been performed in step 2012. For example, the number of requested cycles may be stored in a configuration register.
[0146] If the number of cycles is less than the requested number of cycles (output "N" of verification step 2012), the DMA channel proceeds to step 2014, where the DMA channel, for example, increments a second counter identifying the number of cycles. However, the DMA channel may also perform one or more further operations, which may be programmed based on the data stored in the configuration register, such as resetting the source address and / or the destination address to respective initial values. Next, the DMA channel returns to step 2002 to perform the next data transfer in response to the request signal R.
[0147] On the other hand, in the case that the number of cycles reaches the requested number of cycles (output “Y” of verification step 2012 ), the DMA channel sets a second confirmation signal A2 in step 2016 , such as for channel DMA CH1 Confirmation signal A2 C1 Or for channel DMA CH2 Confirmation signal A2 C2 , and resets the second counter. Thus, the second acknowledge signal A2 indicates the completion of the second cycle in the requested secondary cycle, hereinafter referred to as the main cycle. Typically, the DMA channel may also perform one or more further operations in step 2016, which may be programmed according to the channel configuration data, such as resetting the source address and / or destination address to respective initial values. Next, the DMA channel returns to step 2002 to perform the next data transfer in response to the request signal R.
[0148] In various embodiments, the second DMA channel DMA CH2 The request signal R C2 Can correspond to the first DMA channel DMA CH1 The second (main cycle) confirmation signal A2 C1 Or the first (cycle) confirmation signal A1 C1 Preferably, the configuration is programmable, such as by applying a request signal R C2 Connected to confirmation signal A2 C1 An electronic switch SW is shown schematically.
[0149] For example, such a DMA controller can be used to utilize DMA channels DMA CHl and DMA CH2 To implement DMA channel DMA Tl Specifically, the first DMA channel DMA CH1It can be configured to transfer k data packets (i.e., the number of input data registers DATAIN) from a source address to a destination address via a secondary loop (2002, 2004, 2006, 2008). In this case, the source address is initialized to address ADR2 and incremented in step 2008, i.e., for each data transfer. Conversely, the destination address is initialized to the address associated with the first input data register DATAIN0 and incremented in step 2008, but then reset to the initial value in step 2014, whereby each inner loop starts from the address associated with the first input data register DATAIN0 and then increments during the inner loop. In addition, once the data transfer of k data packets is completed, the first DMA channel generates an acknowledgement signal A1 in step 2010. C1 , confirm signal A1 C1 As the request signal R C2 is provided to the DMA channel DMA CH2 Therefore, in response to the confirmation signal A1 C1 ,DMA channel DMA CH2 It can be configured to transfer a single data packet from a source address to a destination address, where the source address is set to address ADR1 and the destination address is set to the address associated with the control register CONTROL. For example, as previously described, in various embodiments, a new cryptographic operation can be started by writing the contents of the control register CONTROL. Thus, in the embodiment under consideration, the secondary cycle transfers data for a single cryptographic operation, and the number of cycles requested (implemented using the primary cycle) indicates the total number of cryptographic operations to be performed by the coprocessor 40a.
[0150] For example, in this case, the signal REQ generated by the DMA interface circuit 406a l can be connected to the request signal R Cl , and optionally, a DMA channel DMA may be provided to the DMA interface 406a CH2 (Inner loop) confirmation signal A1 C2 As the confirmation signal ACK1. In this case, the cryptographic operation can also be started in response to the confirmation signal ACK1.
[0151] On the contrary, if the transmission of the control command ENCCMD is not required, only channel DMA can be used. CHl , where a DMA channel DMA can be provided to the DMA interface 406a CHl Confirmation signal A1 Cl As an acknowledgment signal ACK l , the confirmation signal ACK l Can be used to start a cryptographic operation.
[0152] Therefore, once the cryptographic processing circuit 404 completes processing of the data stored in the input data register DATAIN, the data stored in the output data register DATAOUT can be read. For example, for this purpose, the cryptographic processing circuit 404 can generate a signal DONE, which is provided to the second DMA interface 406b. For example, in response to the signal DONE, the second DMA interface 406a can set the request signal REQ2 to request reading of the data stored in the output data register DATAOUT. Therefore, in this case, the DMA channel DMA T2 is configured to transfer the data stored in the output data register DATAOUT. Typically, also in this case, the DMA channel DMA T2 The processing data may be provided by an integrated DMA controller of the coprocessor 40 a , which is configured to read the processed data directly from the output data register DATAOUT, or by a general DMA controller configured to read the processed data from the output data register DATAOUT via the slave interface 410 .
[0153] In various embodiments, DMA channel DMA T2 The first DMA interface 406a is configured to generate an acknowledgement signal ACK2 once the data stored in the output data register DATAOUT has been transferred. Specifically, in various embodiments, the second interface 406b is configured to generate a synchronization signal SYNC in response to the acknowledgement signal ACK2, thereby indicating when the data stored in the output data register DATAOUT has been transferred. For example, the synchronization signal SYNC can directly correspond to the acknowledgement signal ACK2. For example, in response to the signal SYNC, the first DMA interface 406a can set the request signal REQ1 to request the transfer of new data.
[0154] Thus, by configuring the cryptographic coprocessor 40a in a suitable manner, for example, via the slave interface 410, the cryptographic coprocessor 40a may be configured to:
[0155] - asserting the request signal REQ1 in order to request the transfer of an AES block to the input data register DATAIN and of an optional command ENCCMD to the control register(s) CONTROL;
[0156] - performing the requested cryptographic operation, for example, as indicated via the command ENCCMD;
[0157] - when the cryptographic processing of the current AES block is completed (as notified via the signal DONE), asserting the request signal REQ2 in order to request the transmission of the processed AES block from the output data register DATAOUT; and
[0158] - Once the data has been transferred from the output data register DATAOUT (as signaled via the signal SYNC), the next AES block is processed.
[0159] Specifically, as previously described, to process data OD, the processing core 102 may be configured to send a first command INIT for initializing the cryptographic processing circuit 404, and the command ENCCMD may correspond to a second command DATA_APPEND that specifies that a given operation belongs to an already initialized cryptographic processing operation. For example, the DMA interface 406a may be configured to set the request signal REQ1 for the first time in response to receiving the command INIT (and then according to the synchronization signal SYNC).
[0160] Thus, the above solution allows automatic processing of the raw data OD, wherein once the request signal REQ2 is set, the processed data stored in the output data register DATAOUT is automatically processed via the DMA channel DMA T2 Specifically, in response to determining that the request signal REQ2 is set, the DMA channel DMA T2 One AES block of processed data, i.e. 16 bytes, is transmitted.
[0161] For example, about Figure 4 The arrangement shown in the DMA channel DMA T2 It may be configured to transfer the processed data to the memory 104b.
[0162] on the contrary, Figure 8 An embodiment of a SIPI communication interface 50a is shown.
[0163] Specifically, in the embodiment under consideration, the SIPI communication interface 50a comprises a SIPI (Zipwire) hardware communication interface 504 configured to transmit or receive data. Typically, in the case of streaming applications, the SIPI protocol is based on frames that include a 32-byte (256-bit) SIPI payload for each transmission.
[0164] Therefore, the hardware communication interface 506 is associated with a register DATATX for storing data to be sent and a register DATARX for storing received data. For example, assuming a 64-bit processing system 10a, the SIPI communication interface 50a may include:
[0165] - four transmit data registers DATATX0 to DATATX3, each having 8 bytes (64 bits) for storing data to be transmitted; and
[0166] - Four receive data registers DATARX0 to DATARX3, each having 8 bytes (64 bits), for storing received data.
[0167] Typically, the number and size of the transmit data registers DATATX and receive data registers DATARX depend on the number of bits w to be transmitted via the communication system 114. Specifically, the size of the transmit data registers DATATX and receive data registers DATATRX corresponds to the number w, and the number of registers m can be calculated as 256 / w. For example, in the case of a 32-bit (i.e., w=32) system, eight (i.e., m=256 / w=8) registers DATATX0 to DATATX7, each having a size of 32 (i.e., w) bits, will be used. Furthermore, the same number of receive data registers DATARX can be used, or registers DATATX can be used to store both the data to be transmitted and the data received.
[0168] Furthermore, the hardware communication interface 504 has associated one or more control registers CTRL for storing control data. For example, in various embodiments, the (or each) control register has w bits, such as 64 bits.
[0169] For example, Figure 8 As schematically shown, the SIPI communication interface 50a may include a slave interface 510 connected to the communication system 114 and configured to interface the control register(s) CTRL, the transmit data register DATATX, and the receive data register DATARX with the communication system 114 .
[0170] For example, in this manner, the processing core 102 may send a request sequence REQ to the slave interface 510 to transmit data by writing the contents of the transmit data register DATATX and the contents of the control register(s) CTRL. Similarly, the processing core 102 may send a request sequence REQ to the slave interface 510 to read received data from the receive data register DATARX.
[0171] Thus, in the embodiment under consideration, the SIPI hardware communication interface 504 is configured to transmit data stored in the transmit data register DATATX according to control data stored in the control register(s) CTRL. For example, the control data may indicate one or more data to be included in the SIPI header added to the SIPI payload. For example, the control data may indicate a channel number.
[0172] like Figure 8As shown, in the embodiment under consideration, the SIPI communication interface 50a further comprises two DMA interfaces 506a and 506b. Specifically, the first interface 506a is connected to a DMA channel DMA T3 , and generates a first request signal REQ3 for requesting to send new data. On the other hand, the second interface 506b is connected to the DMA channel DMA T4 , and generates a second request signal REQ4 for requesting to read the received data. T3 and / or DMA channel DMA T4 This can be implemented using a general-purpose DMA controller, or via an integrated DMA controller that can be configured to send read or write requests to the communication system 114 or directly to the memory controller 110, respectively. Figure 8 As schematically shown, in various embodiments, the DMA channel DMA T3 This is achieved using a general DMA channel that therefore sends data to the register DATATX via the slave interface 510, while the DMA channel DMA T4 is an integrated DMA write channel implemented in the SIPI communication interface 50 a , which thus transfers data directly from the register DATARX to the communication system 114 or directly to the memory controller 100 .
[0173] For example, in various embodiments, data transmission can be initiated by first writing the contents of the control register (s) CTRL and then writing the data to be transmitted into the transmit data register DATATX, wherein the write to the last input data register automatically initiates data transmission. In various embodiments, once the transmission of the SIPI frame is completed, the SIPI hardware communication interface 504 can assert the signal TX_OK. For example, in response to the signal TX_OK, the DMA interface circuit 506a can set the request signal REQ3, thereby requesting new data.
[0174] Therefore, in order to transmit the data TD stored in the memory 104b l to TD n , the processing core 102 may configure DMA channels, such as Figure 6 The DMA channel DMA of the DMA controller 110a is described CHl, to send m data packets (i.e., the number of transmit data registers DATAIN) from the source address to the destination address via the inner loop. In this case, the source address is initialized to the address ADR3 of the first word of transmit data TD1 and is incremented in step 2008 for each data transfer. Conversely, the destination address is initialized to the address associated with the first transmit data register DATATX0 and is incremented in step 2008, but is then reset to the initial value in step 2014, whereby each inner loop starts at the address associated with the transmit data register DATATX0 and is then incremented in step 2008 during the inner loop.
[0175] Therefore, by using the request signal REQ3 as the request signal R of the DMA channel, it is sufficient for the processing core 102 to write one or more control registers CTRL to set the header information and activate the DMA transfer, whereby when the transmission of the SIPI frame is completed (as indicated by the signal TX_OK), the DMA interface circuit automatically requests new data via the signal REQ3. Generally, when DMA transfer is used, the SIPI hardware communication interface 504 can also respond to the request signal R of the DMA channel DMA. T3 The data transmission starts with the confirmation signal ACK3 provided, and the confirmation signal ACK3 can correspond to the DMA channel DMA CH1 signal A1.
[0176] Similarly, once a new SIPI frame has been received, the SIPI hardware communication interface 504 may assert the signal RX_OK. For example, in this case, the DMA interface circuit 506b may be configured to assert the request signal REQ4, and the DMA channel DMA T4 It may be configured to transfer m packets from the reception data register DATARX to the memory 104 b , thereby sequentially storing the received data RD1 to RDn in the memory 104 b .
[0177] In various embodiments, the DMA interface circuit 506b is configured to DMA from a DMA channel T4 Receive an acknowledgment signal ACK4, wherein the acknowledgment signal ACK4 indicates that the DMA data transfer of m packets has been completed. Specifically, in response to the acknowledgment signal ACK4, the DMA interface circuit 506b can assert a ready signal RDY, which is provided to the SIPI hardware communication interface 504. Specifically, in this case, the SIPI hardware communication interface 504 can be configured to accept new data only when the signal RDY is asserted. Typically, the flow control between the SIPI transmitter and the SIPI receiver for notifying the receiver whether it is available can be handled via the SIPI / LFAST protocol.
[0178] Therefore, as regards Figure 5 and Figure 8 As described, the cryptographic coprocessor 40a can use the DMA channel DMA T2 At the same time, the SIPI communication interface 50a can use the DMA channel DMA T3 , the DMA channel DMA T2 The DMA channel is configured to transfer k data words consisting of 128 bits from the output data register DATAOUT. T3 is configured to transfer m data words consisting of 256 bits. In addition, the DMA channel DMA T2 While receiving the request signal REQ2 from the DMA interface 406b, the DMA channel DMA T3 The request signal REQ3 is received from the DMA interface 506a.
[0179] An embodiment of data exchange between the cryptographic coprocessor 40a and the SIPI communication interface 50a via a DMA channel will be described below. The DMA channel will be again referred to as DMA below. T2 Logo.
[0180] Specifically, if Figure 9 As shown, in this case, the processing system 10a includes:
[0181] - Cryptographic coprocessor 40a;
[0182] -DMA channel DMA T1 , configured to transfer data OD and an optional encryption command ENCCMD to an input data register DATAIN and a control register CONTROL of an optional cryptographic coprocessor 40 a by using a request signal REQ1 and an optional acknowledgement signal ACK1 ;
[0183] - SIPI communication interface 50b; and
[0184] - Additional DMA channel DMA T2 , configured to transfer the encrypted data from the output data register DATAOUT of the cryptographic coprocessor 40a to the transmit data register DATATX of the SIPI communication interface 50b.
[0185] Usually, such as Figure 8 As shown, the processing system 10A further includes a processing core 102 configured to send a request REQ to the communication system 114 in order to configure the DMA channel DMA T1 and DMA T2 , a cryptographic coprocessor (e.g., by storing the command INIT to the control register CONTROL) and a SIPI interface (e.g., by programming the control register(s) CTRL).
[0186] Typically, DMA channels T1 and DMA T2 This can be, for example, an integrated DMA channel of the cryptographic coprocessor 40a, or preferably a channel of the general DMA controller 110a. T1 For operation, please refer to Figures 5 to 7 Description.
[0187] About DMA channel DMA T2 Operation, you can observe:
[0188] the cryptographic coprocessor 40a, in particular the corresponding DMA interface circuit 406b, is configured to generate a request signal REQ2 requesting the transfer of 128 bits from the output data register DATAOUT, and to receive an acknowledgement signal ACK2 indicating that the 128 bits have been transferred from the output data register DATAOUT; and
[0189] The SIPI communication interface 50a, in particular the corresponding DMA interface circuit 406a, is configured to generate a request signal REQ3 requesting the transfer of 256 bits to the transmit data register DATATX and to receive an acknowledgement signal ACK3 indicating that the 256 bits have been transferred to the transmit data register DATATX.
[0190] On the contrary, as regards Figure 6 and Figure 7 As described, the DMA channel of the DMA controller 110a expects a single request signal R, but may generate two acknowledge signals: acknowledge signal A1 (eg, for channel DMA CH1 Signal A1 C1 ), indicating the completion of the secondary cycle; and confirmation signal A2 (eg, for channel DMA CH1 Signal A2 C1 ), indicating the completion of the main loop.
[0191] Therefore, in various embodiments, the DMA channel DMA T2 The request control circuit 120 is associated with (eg, may include) a request control circuit 120 configured to generate a DMA channel DMA according to request signals REQ2 and REQ3. T2 The request signal R (for example, for channel DMA CH1 The signal R C1 ). In addition, by DMA channel DMA CH1Configured to use two major cycles and k minor cycles required to transmit 128 bits (16 bytes), acknowledgement signal A1 may be provided to cryptographic coprocessor 40a as acknowledgement signal ACK2, and acknowledgement signal A2 may be provided to SIPI communication interface 50a as acknowledgement signal ACK3.
[0192] Specifically, this is also Figure 10A 、 Figure 10B 、 Figure 10C and Figure 11 Shown in more detail in .
[0193] Specifically, if Figure 10A As shown, the cryptographic coprocessor 40a asserts the request signal REQ2 at a given time.
[0194] In response to the request signal REQ2 and also as Figure 10C As shown, the request control circuit 120 asserts the DMA channel DMA T2 Therefore, in response to the request signal R, the DMA channel DMA T2 The execution consists of k sub-loops ( Figure 7 2004, 2006 and 2008 in order to transfer 128 bits (16 bytes), for example by performing k=2 cycles in the case of w=64. Once k sub-cycles have been performed (step 2006), the DMA channel DMA T2 The acknowledgement signal A1 is asserted (step 2010), and the acknowledgement signal A1 is provided to the cryptographic coprocessor 40a as the acknowledgement signal ACK2.
[0195] Therefore, in response to the acknowledgement signal ACK2, the cryptographic coprocessor 40a deasserts the request signal REQ2 and transmits the data to the DMA channel DMA. T1 New data is requested, processed, and once the processing operation is completed, the request signal REQ2 is asserted again.
[0196] In response to the request signal REQ2, the request control circuit 120 asserts the DMA channel DMA again. T2 The request signal R, thus the DMA channel DMA T2 The execution includes k sub-loops (steps 2002, 2004, 2006 and 2008 in Figure 7 The second main cycle of the transmission module 2000 is performed in order to further transmit 128 bits (16 bytes), and then the confirmation signal A1 is asserted (step 2010) and the confirmation signal A2 is asserted (step 2016).
[0197] However, in practice, the request control circuit 120 should assert the request signal R only when the request signal REQ3 also indicates that the SIPI communication interface 50a can receive data. Therefore, in various embodiments, the request control circuit 120 is actually configured to assert the request signal R when both the request signals REQ2 and REQ3 are asserted, and to de-assert the request signal R when at least one of the request signals REQ2 and REQ3 is de-asserted.
[0198] For example, this Figure 11 As schematically shown in FIG, the request control circuit 120 is implemented with a logic AND gate 1200 that receives the request signals REQ2 and REQ3 at input and provides a request signal R at output.
[0199] Typically, where the cryptographic coprocessor 40A and the SIPI communication interface 50A operate with different clock signals (i.e., asynchronously), the request signals REQ2 and / or REQ3 may be synchronized via some synchronization circuitry, such as a sequence of flip-flops driven by the same clock signal. Typically, where the clock signal corresponds to the clock signal of the cryptographic coprocessor 40a or the SIPI communication interface 50a, one of the synchronization chains may be omitted.
[0200] Therefore, DMA channel DMA T2 The two 16-byte data transfers to the cryptographic coprocessor 40A are confirmed via signal A1 (see Figure 10A ) and confirms via signal A2 the single 32-byte data transfer to the SIPI communication interface 50a (see Figure 10B ).
[0201] Therefore, in various embodiments, in order to correctly transfer data from the output data register DATAOUT to the transmit data register DATATX, the DMA channel DMA T2 is configured (e.g., via processing core 102a and slave interface 1104) to use the following configuration:
[0202] - the initial source address corresponds to the address of the first output data register DATAOUT0;
[0203] -The initial target address corresponds to the address of the first transmit data register DATATX0;
[0204] - the number of requested transmissions (minor cycles) corresponds to k;
[0205] - the number of requested loops (main loops) corresponds to 2;
[0206] - the source address is incremented for each minor cycle (step 2008), and the source address for each major cycle is reset to the initial source address (eg, by resetting the source address at step 2014); and
[0207] - The target address is incremented for each minor cycle (step 2008), and once two major cycles are completed, the target address is reset to the initial target address (eg, by resetting the target address at step 2016).
[0208] Therefore, in the embodiment considered, the DMA channel DMA T2 It is configured to transfer data from the cryptographic coprocessor 40a to the SIPI communication interface 50a without temporarily storing the data in the memory 104b.
[0209] In various embodiments, similar data transmission may also be implemented on the receiving side.
[0210] Specifically, Figure 12 、 Figure 13A 、 Figure 13B 、 Figure 13C and Figure 14 An embodiment is shown in which processing system 10a is configured to receive encrypted data via SIPI communication interface 50a and to decrypt the received data via cryptographic coprocessor 40a.
[0211] In particular, in the embodiment considered (see also Figure 8 ), the SIPI communication interface 50a is configured to assert a request signal REQ4 when new data has been received, thereby requesting the transmission of 256 bits (32 bytes). In addition, the cryptographic coprocessor 40a is configured to assert a request signal REQ1 when the cryptographic coprocessor 40a is available to process new data, thereby requesting the transmission of 128 bits (16 bytes).
[0212] Specifically, in the embodiment considered, the DMA channel DMA Tl It is used to transfer the received data from the receive data register DATARX of the SIPI communication interface 50a to the input data register DATAIN of the cryptographic coprocessor 40a.
[0213] Specifically, in the embodiment considered, the request signals REQ4 and REQ1 are provided to a request control circuit 120, such as an AND gate 1200, which is configured to generate a DMA channel DMA Tl The request signal R is provided, wherein the (minor cycle) confirmation signal A1 is provided as confirmation signal ACK1 to the cryptographic coprocessor 40a, and the (major cycle) confirmation signal A2 is provided as confirmation signal ACK4 to the SIPI communication interface 50a.
[0214] Therefore, once new data has been received (e.g. via Figure 8 Once both request signals REQ1 and REQ4 are asserted, the request control circuit 120 asserts the request signal R, thereby DMA channel DMA T1 K sub-cycles are executed to transfer 128 bits (16 bytes) from the receive data register DATARX to the input data register DATAIN.
[0215] In various embodiments, DMA channel DMA Tl It is also possible to transfer the decryption command DECCMD from the memory 104b to the control register CONTROL of the cryptographic coprocessor 40a at the end of the main loop. For example, the decryption command DECCMD can be used for this purpose. Figure 6 DMA controller 110a is shown, wherein:
[0216] - Request signal R corresponds to the channel DMA CH1 The request signal R C1 ;
[0217] -Confirmation signal A1 C1 As the request signal R C1 is connected to the channel DMA CH2 ;
[0218] - confirmation signal A1 corresponds to confirmation signal A1 C2 ;
[0219] - confirmation signal A2 corresponds to confirmation signal A2 C2 ;
[0220] - Channel DMA CH1 is configured to transfer data from the receive data register DATARX to the input data register DATAIN; and
[0221] - Channel DMA CH2 It is configured to transfer the decryption command DECCMD from a fixed storage location in the memory 104b to the control register CONTROL.
[0222] Thus, at the end of the first major cycle (as signaled via the acknowledge signal A1), the DMA channel DMA T4128 bits (16 bytes) and the optional command DECCMD have been transferred from the first half of the receive data register DATARX, whereby the cryptographic coprocessor performs a decryption operation to obtain the original data OD again. Typically, the cryptographic coprocessor can also start the ongoing operation in response to the confirmation signal ACK1. In addition, in this case as well, the processing core 102 can first send the command INIT for initializing the cryptographic processing circuit 404, and the command DECCMD can correspond to the second command DATA_APPEND, which specifies that the given operation belongs to the already initialized cryptographic processing operation.
[0223] Once the decryption operation is completed (as signaled via the DONE signal), the cryptographic coprocessor 40a can again use the DMA channel DMA T2 Therefore, once the data has been transferred (as notified via the synchronization signal SYNC), the cryptographic coprocessor 40a can again assert the request signal REQ1, thereby DMA channel DMA T1 Execute the second main loop.
[0224] Thus, at the end of the second major cycle (as signaled via the acknowledge signal A1), the DMA channel DMA T4 128 bits (16 bytes) and the optional command DECCMD have been transferred from the second half of the receive data register DATARX, whereby the cryptographic coprocessor performs a decryption operation to obtain the original data OD again.
[0225] However, in this case, the DMA channel DMA T4 An acknowledgement signal ACK4 is also asserted, indicating that 256 bits (32 bytes) have been read from the receive data register DATARX, thereby indicating that new data may be received.
[0226] Therefore, in various embodiments, in order to correctly transfer data from the receive data register DATARX to the input data register DATAIN, the DMA channel DMA Tl (especially channel DMA CHl ) is configured (e.g., via processing core 102a and slave interface 1104) to use the following configuration:
[0227] - the initial source address corresponds to the address of the first receive data register DATARX0;
[0228] - the initial target address corresponds to the address of the first input data register DATAIN0;
[0229] - the number of requested transmissions (minor cycles) corresponds to k;
[0230] - the number of requested loops (main loops) corresponds to 2;
[0231] - the target address is incremented for each minor cycle (step 2008), and the target address of each major cycle is reset to the initial target address (eg, by resetting the source address at step 2014); and
[0232] - The source address is incremented for each minor cycle (step 2008), and once both major cycles are complete, the source address is reset to the initial source address (eg, by resetting the destination address at step 2016).
[0233] at last, Figure 15 、 Figure 16A 、 Figure 16B 、 Figure 16C and Figure 17 An embodiment is shown in which the SIPI communication interface already includes an integrated DMA interface DMA T4 (For clarity reasons only, Figure 15 ), the integrated DMA interface DMA T4 Configured to always transfer 256 bits directly to the memory controller 100 .
[0234] In this case, the DMA channel DMA T4 It can be configured to: in response to the request signal REQ4 generated by the DMA interface circuit 506b, transfer 256 bits from the receive data register DATARX to the storage area in the volatile memory 104b, which is located at Figure 15 In the buffer BUF, the number of memory locations such as BUF0 to BUF3 of the buffer BUF corresponds to the number m of the receive data registers DATARX.
[0235] For example, in this case, a simple DMA controller can be used which performs only a given number of requested transfers (minor cycles), for example, by using steps 2002, 2004, 2006, 2008 and 2010, wherein the DMA channel returns to step 2002 after step 2010 (see Figure 7 ). For example, in this case, in order to correctly transfer data from the receive data register DATARX to the buffer BUF, the DMA channel DMA T4 is configured (e.g., via processing core 102a and slave interface 1104) to use the following configuration:
[0236] -The initial source address corresponds to the address of the first receive data register DATARX0 (in the case of a custom DMA channel, this value can also be fixed);
[0237] - the initial target address corresponds to the address of the first buffer memory location BUF0;
[0238] - the number of requested transfers to be performed corresponds to m (in case of a custom DMA channel this value can also be fixed);
[0239] - the source address is incremented for each transmission (step 2008), and the source address is reset to the initial source address at the end of the m transmissions (eg, by resetting the source address in step 2010); and
[0240] - The target address is incremented for each transfer (step 2008), and at the end of m transfers the target address is reset to the initial target address (eg, by resetting the source address in step 2010).
[0241] Also in this case, when the requested number of transfers has been performed, the DMA channel DMA T4 Generates an acknowledgment signal ACK T4 (Step 2010). However, in this case, the DMA channel DMA T4 Generated confirmation signal ACK T4 (and indicating that the 256-bit transfer has been completed) is not provided to the DMA interface circuit 506b, but is provided to the request control circuit 120.
[0242] Therefore, in response to the request signal REQ generated by the cryptographic coprocessor 40a l and confirmation signal ACK T4 , the request control circuit 120 may assert the DMA channel DMA Tl Specifically, in this case, the DMA channel DMA T1 Essentially configured as about Figure 12 The embodiment shown, however, instead of using the address of the receive data register DATARX as the source address, the source address now points to the address associated with the buffer BUF.
[0243] Specifically, for this purpose, the DMA channel DMA Tl Can be used Figure 6 The DMA controller 110a shown is implemented as follows, wherein:
[0244] -Request signal R corresponds to channel DMA CH1 The request signal R C1 ;
[0245] -Confirmation signal A1 C1 As the request signal R C1 is connected to the channel DMA CH2 ;
[0246] - confirmation signal A1 corresponds to confirmation signal A1 C2 ;
[0247] - confirmation signal A2 corresponds to confirmation signal A2 C2 ;
[0248] - Channel DMA CH1 is configured to transfer data from the buffer BUF to the input data register DATAIN; and
[0249] - Channel DMA CH2 is configured to transfer a decryption command DECCMD from a fixed memory location in the memory 104b to the control register CONTROL.
[0250] Specifically, in various embodiments, in order to correctly transfer data from the buffer BUF to the input data register DATAIN, the DMA channel DMA Tl (especially channel DMA CHl ) may be configured (e.g., via processing core 102a and slave interface 1104) to use the following configuration:
[0251] The initial source address corresponds to the address of the first buffer location BUF0;
[0252] - the initial target address corresponds to the address of the first input data register DATAIN0;
[0253] - the number of requested transmissions (minor cycles) corresponds to k;
[0254] - the number of requested loops (main loops) corresponds to 2;
[0255] - the target address is incremented for each minor cycle (step 2008), and the target address of each major cycle is reset to the initial target address (eg, by resetting the source address at step 2014); and
[0256] - The source address is incremented for each minor cycle (step 2008), and once both major cycles are completed, the source address is reset to the initial source address (eg, by resetting the destination address at step 2016).
[0257] So, in this case, the DMA channel DMA TlDuring the first main cycle, data is transferred from the first half of the buffer BUF (such as the buffers BUF0 and BUF1) to the input data register DATAIN, and optionally the command DECCMD is transferred to the control register CONTROL. Similarly, the DMA channel DMA T1 During the second main cycle, data is transferred from the second half of the buffer BUF (such as buffers BUF2 and BUF3) to the input data register DATAIN, and optionally the command DECCMD is transferred to the control register CONTROL.
[0258] Therefore, once the second main loop is completed, the DMA channel DMA Tl The acknowledge signal A2 is asserted and provided as an acknowledge signal ACK4 to the DMA interface circuit 506b of the SIPI communication interface 50a.
[0259] Therefore, if Figure 16A As shown, the signals exchanged with the cryptographic coprocessor 40a are essentially the same as Figure 12 The same as the embodiment (see Figure 13A ).
[0260] However, the acknowledge signal is typically just a trigger signal (e.g., asserted for a single clock signal). Figure 16B As shown, in various embodiments, in order to simulate Figure 12 In the embodiment of the present invention, the request control circuit 120 can be configured to use the request signal REQ4 in the ACK signal. T4 1 is activated, the request signal REQ5 is asserted. Conversely, the request control circuit 120 may de-assert the request signal REQ5 in response to the acknowledgement signal A2 corresponding to the acknowledgement signal ACK4. For example, for this purpose, the request control circuit 120 may include a set-reset flip-flop or latch 1202, wherein:
[0261] -Signal ACK T4 is connected to the set terminal of the flip-flop or latch 1202;
[0262] - an acknowledge signal ACK4 is connected to the reset terminal of the flip-flop or latch 1202; and
[0263] - The output of the flip-flop or latch 1202 provides the request signal REQ5.
[0264] Therefore, in Figure 14 and Figure 17 In the illustrated embodiment, the SIPI interface 50a stores the received data into a storage element having m slots (ie, a buffer BUF) or directly into a receive data register DATARX.
[0265] Furthermore, the SIPI interface generates a control signal when 32 bytes have been written to the storage element, namely a signal ACK when the data has been stored in the buffer BUF. T4 Or the signal RX_OK when the data has been directly stored into the receive data register DATARX.
[0266] In response to the control signal, the DMA interface circuit generates a request signal requesting that the data stored in the storage area be transferred to the cryptographic coprocessor 40a. Figure 14 In the embodiment, this operation is implemented in the DMA interface circuit 506b, which asserts the request signal REQ4 in response to the signal TX_OK and deasserts the request signal REQ4 in response to the acknowledgement signal ACK4. Figure 17 , the set-reset register or latch 1202 that generates the request signal REQ5 emulates the same behavior because the circuit also asserts the request signal REQ5 in response to the signal ACKT4 and deasserts the request signal in response to the acknowledgement signal ACK4. In both cases, the acknowledgement signal ACK4 signals to the SIPI interface 50a that the data has been read from the storage element.
[0267] Thus, the aforementioned disclosed solution allows the processing core 102a to configure the DMA channels, SIPI communication interface 50a, and cryptographic coprocessor 40a to:
[0268] - transmitting the encrypted data stream generated for the data OD stored in the memory 104b; or
[0269] - Receive the encrypted data stream and store the decrypted data OD to the memory 104b.
[0270] For example, regarding the transmission chain, once the corresponding configuration has been programmed into the DMA channel, the SIPI communication interface and the cryptographic coprocessor, it is sufficient for the processing core 102a to send a command to the cryptographic coprocessor 40a, such as the command INIT, in order to start the streaming transmission operation of the encrypted data. T1 The (main loop) acknowledgement signal A2 may also be used to generate an interrupt for the processing core 102a, thereby signaling that the original data OD has been processed.
[0271] Of course, without prejudice to the principle of the invention, the details of construction and the embodiments may vary widely with respect to what is described and illustrated herein purely by way of example, without departing from the scope of the present invention, as defined by the following claims.
Claims
1. A processing system comprising: A microprocessor, which can be programmed via software instructions; a memory controller configured to be coupled to the memory; a communication system coupling the microprocessor to the memory controller; Cryptographic coprocessor, including: a plurality of input data registers configured to store a first data block having a plurality of bytes, wherein the number of the input data registers corresponds to the first number of registers, a plurality of output data registers configured to store a first processed block of data, wherein the number of said output data registers corresponds to said first number of registers, a first control register, programmable by the microprocessor and configured to store first configuration data, a cryptographic processing circuit configured to process data stored in the input data register according to the first configuration data stored in the first control register and store the processed data in the output data register, wherein the cryptographic processing circuit is configured to generate a first control signal when the processed data has been stored in the output data register. The first DMA interface circuit is configured to generate a first request signal, wherein the first request signal requests to transfer a new first data block to the input data register by performing the following operations: asserting the first request signal in response to a synchronization signal according to the first configuration data stored in the first control register, and in response to a first confirmation signal, de-asserting the first request signal, The second DMA interface circuit is configured to generate a second request signal, wherein the second request signal requests the transfer of the first processed data block from the output data register by: asserting the second request signal in response to the first control signal, and de-asserting the second request signal in response to a second confirmation signal, wherein the second DMA interface circuit is configured to: assert the synchronization signal in response to the second confirmation signal; The first communication interface includes: a plurality of transmit data registers configured to store a second data block having a plurality of bytes, wherein the number of the transmit data registers corresponds to the second number of registers, a second control register, programmable by the microprocessor and configured to store second configuration data, a hardware communication interface configured to transmit data stored in the transmit data register according to the second configuration data stored in the second control register, wherein the hardware communication interface is configured to generate a second control signal when the data stored in the transmit data register has been transmitted, and The third DMA interface circuit is configured to generate a third request signal, wherein the third request signal requests to transfer the new second data block to the transmit data register by performing the following operations: asserting the third request signal according to the second configuration data stored in the second control register and in response to the second control signal, and deasserting the third request signal in response to a third confirmation signal; The first DMA channel is configured as: In response to the first request signal, sending a request to the memory controller to transfer a new first data block from the memory to the input data register, and asserting the first acknowledge signal once the new first data block has been transferred from the memory to the input data register; The second DMA channel is configured as: receiving an initial source address and an initial destination address, wherein the initial source address corresponds to an address associated with a first register in the output data registers and the initial destination address corresponds to an address associated with a first register in the transmit data registers, Setting the source address to the initial source address and the destination address to the initial destination address, performing a given number of data transfer operations from the source address to the destination address in response to a DMA request signal, wherein the given number of data transfer operations corresponds to the first number of registers, and wherein the source address and the destination address are incremented for each data transfer operation, Once the given number of data transfer operations have been performed, asserting the second acknowledge signal and resetting the source address to the initial source address, and asserting the third confirmation signal and resetting the target address to the initial target address; and The request control circuit is configured to: In response to determining that the second request signal and the third request signal are asserted, asserting the DMA request signal, and In response to determining that the second request signal or the third request signal is de-asserted, the DMA request signal is de-asserted. 2 . The processing system of claim 1 , wherein the first data block comprises 16 bytes, and wherein the second data block comprises 32 bytes.
3. The processing system of claim 1, wherein the first communication interface is a serial inter-processor interface (SIPI). The processing system of claim 1 , wherein the second number of registers corresponds to double the first number of registers.
5. The processing system of claim 1 , wherein the second DMA channel is configured to perform the following steps: performing the given number of data transfer operations from the source address to the target address, and after setting the source address to the initial source address and setting the target address to the initial target address twice, once the given number of data transfer operations have been performed, asserting the first confirmation signal and resetting the target address to the initial target address.
6. The processing system of claim 1 , comprising a further DMA channel configured to transfer commands from a fixed source address to an address associated with the first control register once a new first block has been stored to the input data register.
7. The processing system of claim 1, wherein the cryptographic processing circuit is an Advanced Encryption Standard (AES) processing circuit.
8. The processing system of claim 1 , wherein the first DMA channel and the second DMA channel are implemented using a programmable general-purpose DMA controller, the programmable general-purpose DMA controller configured to transfer data by sending a read request to the corresponding source address and sending a write request to the corresponding destination address, the write request including the data received in response to the read request.
9. The processing system of claim 1, wherein the processing system is integrated into an integrated circuit.
10. The processing system of claim 1, wherein the processing system is implemented in a device comprising a plurality of processing systems, the plurality of processing systems being coupled via a further communication system. The processing system of claim 10 , wherein the device is a vehicle.
12. A processing system comprising: A microprocessor, which can be programmed via software instructions; a memory controller configured to be coupled to the memory; a communication system coupling the microprocessor to the memory controller; Cryptographic coprocessor, including: a plurality of input data registers configured to store a first data block having a plurality of bytes, wherein the number of the input data registers corresponds to the first number of registers, a plurality of output data registers configured to store a first processed block of data, wherein the number of said output data registers corresponds to said first number of registers, a first control register, programmable by the microprocessor and configured to store first configuration data, a cryptographic processing circuit configured to process data stored in the input data register according to the first configuration data stored in the first control register and store the processed data in the output data register, wherein the cryptographic processing circuit is configured to generate a first control signal when the processed data has been stored in the output data register. The first DMA interface circuit is configured to generate a first request signal, wherein the first request signal requests to transfer a new first data block to the input data register by performing the following operations: asserting the first request signal in response to a synchronization signal according to the first configuration data stored in the first control register, and in response to a first confirmation signal, de-asserting the first request signal, The second DMA interface circuit is configured to generate a second request signal, wherein the second request signal requests the transfer of the first processed data block from the output data register by: asserting the second request signal in response to the first control signal, and deasserting the second request signal in response to a second confirmation signal, wherein the second DMA interface circuit is configured to: assert the synchronization signal in response to the second confirmation signal; A first communication interface is associated with a storage element having a plurality of slots, the slots being configured to store a second data block having a plurality of bytes, wherein the number of the slots corresponds to the second number, the first communication interface comprising: a hardware communication interface configured to receive data and store the received data in the slot of the storage element, wherein the hardware communication interface is configured to generate a second control signal when the hardware communication interface has stored a plurality of bytes in the slot of the storage element, and The third DMA interface circuit is configured to generate a third request signal, wherein the third request signal requests the transfer of a second data block from the slot of the storage element by: In response to the second control signal, asserting the third request signal, and deasserting the third request signal in response to a third confirmation signal; The first DMA channel is configured as: sending a request to the memory controller to transfer a first block of data from the output data register to the memory in response to the second request signal, and asserting the second acknowledge signal once the first block of data has been transferred from the output data register to the memory; The second DMA channel is configured as: receiving an initial source address and an initial destination address, wherein the initial source address corresponds to an address associated with a first slot in the storage element and the initial destination address corresponds to an address associated with a first register in the input data registers, Setting the source address to the initial source address and the destination address to the initial destination address, performing a given number of data transfer operations from the source address to the destination address in response to a DMA request signal, wherein the given number of data transfer operations corresponds to the first number of registers, and wherein the source address and the destination address are incremented for each data transfer operation, once the given number of data transfer operations have been performed, asserting the first acknowledge signal and resetting the target address to the initial target address, and asserting the third confirmation signal and resetting the source address to the initial source address; and The request control circuit is configured to: In response to determining that the first request signal and the third request signal are asserted, asserting the DMA request signal, and In response to determining that the first request signal or the third request signal is de-asserted, the DMA request signal is de-asserted.
13. The processing system of claim 12, wherein the first communication interface is a serial inter-processor interface (SIPI). The processing system of claim 12 , wherein the second number corresponds to double the first number of registers.
15. The processing system of claim 12 , wherein the second DMA channel is configured to perform the following steps: performing the given number of data transfer operations from the source address to the target address, and after setting the source address to the initial source address and setting the target address to the initial target address twice, once the given number of data transfer operations have been performed, asserting the first confirmation signal and resetting the target address to the initial target address.
16. The processing system of claim 12 , wherein the first data block comprises 16 bytes, and wherein the second data block comprises 32 bytes, and wherein the hardware communication interface is configured to generate the second control signal when the hardware communication interface has stored 32 bytes to the slot of the storage element.
17. The processing system of claim 16 , wherein the storage element is implemented using a receive data register of the first communication interface, wherein the hardware communication interface is configured to assert the second control signal when the hardware communication interface has stored 32 bytes into the receive data register (DATARX), and wherein the initial source address corresponds to an address associated with a first register in the receive data registers.
18. The processing system of claim 16, wherein the storage element is implemented using a memory slot in the memory, and wherein the hardware communication interface comprises: a plurality of receive data registers, wherein the hardware communication interface is configured to: assert a third control signal when the hardware communication interface has stored 32 bytes into the receive data registers; as well as The third DMA channel is configured as: transferring the 32 bytes from the receive data register to the memory slot in the memory in response to the third control signal, and The second control signal is asserted once the 32 bytes have been transferred from the receive data register to the memory slots in the memory, wherein the initial source address corresponds to an address associated with a first one of the memory slots in the memory.
19. The processing system of claim 12, comprising a further DMA channel configured to transfer commands from a fixed source address to an address associated with the first control register once a new first block has been stored to the input data register.
20. The processing system of claim 12, wherein the cryptographic processing circuit is an Advanced Encryption Standard (AES) processing circuit.
21. The processing system of claim 12 , wherein the first DMA channel and the second DMA channel are implemented using a programmable general-purpose DMA controller, the programmable general-purpose DMA controller configured to transfer data by sending a read request to the corresponding source address and sending a write request to the corresponding destination address, the write request including the data received in response to the read request.
22. The processing system of claim 12, wherein the processing system is integrated into an integrated circuit.
23. The processing system of claim 12, wherein the processing system is implemented in a device comprising a plurality of processing systems, the plurality of processing systems being coupled via a further communication system.
24. The processing system of claim 23, wherein the device is a vehicle.
25. A method of operating a processing system to transmit data via the processing system, the method comprising: storing data to be sent to a memory of the processing system; The method further comprises transferring the stored data from the memory to an input data register of a cryptographic coprocessor via a first DMA channel, wherein the cryptographic coprocessor comprises: a plurality of input data registers for storing a first data block; a plurality of output data registers for storing a first processed data block; a first control register for storing first configuration data; a cryptographic processing circuit for processing the data stored in the input data registers according to the first configuration data stored in the first control register, and for storing the corresponding processed data in the output data registers, wherein the cryptographic processing circuit generates a first control signal when the processed data has been stored in the output data registers; and a first DMA interface circuit for generating a first request signal, wherein the first request signal requests the processing of the cryptographic coprocessor by performing the following operations: transferring a new first block of data to the input data register by asserting the first request signal in accordance with the first configuration data stored in the first control register and in response to a synchronization signal, and de-asserting the first request signal in response to a first confirmation signal; and a second DMA interface circuit for generating a second request signal, the second request signal requesting transfer of a first processed block of data from the output data register by asserting the second request signal in accordance with the first control signal and de-asserting the second request signal in response to a second confirmation signal, wherein the second DMA interface circuit asserts the synchronization signal in response to the second confirmation signal, and wherein the cryptographic coprocessor generates encrypted data stored in the output data register of the cryptographic coprocessor; and The encrypted data is transferred from the output data register of the cryptographic coprocessor to a transmit data register of a first communication interface via a second DMA channel, wherein the first communication interface includes: a plurality of transmit data registers for storing a second data block; a second control register for storing second configuration data; and a hardware communication interface for sending the data stored in the transmit data register according to the second configuration data stored in the second control register, wherein the hardware communication interface generates a second control signal when the data stored in the transmit data register has been sent, and wherein the first communication interface sends the data stored in the transmit data register of the first communication interface.
26. A method of operating a processing system to receive data via the processing system, the method comprising: receiving data via a first communication interface associated with a storage element having a plurality of slots, wherein the first communication interface stores the received data in the slots of the storage element, wherein the cryptographic coprocessor comprises: a plurality of input data registers; a plurality of output data registers; a first control register; a cryptographic processing circuit for processing the data stored in the input data registers according to first configuration data stored in the first control register, and for storing the corresponding processed data in the output data registers, wherein the cryptographic processing circuit generates a first control signal when the processed data has been stored in the output data registers; and a first DMA interface circuit for generating a first request signal, wherein the first request signal requests that a new first data block be transferred to the input data register by: a first DMA interface circuit configured to generate a second request signal, the second request signal requesting transfer of a first processed block of data from the output data register by asserting the second request signal in response to the first control signal, and deasserting the second request signal in response to a second confirmation signal, wherein the second DMA interface circuit asserts the synchronization signal in response to the second confirmation signal, wherein the first DMA channel sends a request to a memory controller to transfer the first block of data from the output data register to a memory of the processing system in response to the second request signal, and asserts the second confirmation signal once the first block of data has been transferred from the output data register to the memory; transferring the received data from the storage element to an input data register of the cryptographic coprocessor via a second DMA channel, wherein the cryptographic coprocessor generates decrypted data that is stored to an output data register of the cryptographic coprocessor; and The encrypted data is transferred from the output data register of the cryptographic coprocessor to the memory of the processing system via the first DMA channel.
Citation Information
Patent Citations
High-performance password card and communication method thereof
CN112035900A
Data communication system and method of cipher card
CN112052483A