Design and manufacturing methods of electronic devices and integrated circuits, and operating methods of products

By curing preset key information in integrated circuit design and decrypting it, the problem of easy key leakage is solved, the security and production efficiency of private information are improved, and the management process is simplified.

CN115694805BActive Publication Date: 2025-08-05SHANGHAI BIREN TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211338940.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-10-28
Publication Date
2025-08-05
Estimated Expiration
2042-10-28

AI Technical Summary

Technical Problem

In the prior art, the keys are easily leaked or cracked during the chip design process, resulting in lower security of privacy information during the production process.

Method used

During the integrated circuit design process, the preset key information is solidified, and the ciphertext is decrypted through the decryption processing module and the mapping module to ensure that the privacy information is processed in a secure environment.

Benefits of technology

It realizes the security of private information with low development and maintenance costs, avoids the risk of batch leakage caused by single chip leakage, and simplifies management and production processes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115694805B_ABST
    Figure CN115694805B_ABST
Patent Text Reader

Abstract

The present disclosure provides an electronic device, an integrated circuit design and manufacturing method, and an operating method for the product. The electronic device includes a key pre-storage unit, a ciphertext storage unit, and a decryption processing module. The key pre-storage unit is configured to store preset key information solidified during the integrated circuit design process. The ciphertext storage unit is configured to store ciphertext encrypted using the preset key information. The decryption processing module is configured to decrypt the ciphertext based on the preset key information. By solidifying the preset key information in the circuit during the integrated circuit design process, the present disclosure can achieve a low development and maintenance cost while also preventing privacy information from being leaked during the production process, thereby improving the security of privacy information.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of the present disclosure relate to an electronic device, a design and manufacturing method of an integrated circuit, and an operating method of a product. Background Art

[0002] To protect data integrity and confidentiality, encryption algorithms are widely used in the information security field. Currently, in traditional key burning security controls, chip designers typically provide the key generation and burning procedures to manufacturers. The manufacturer then installs the key generation and burning procedures into test equipment, which then uses the equipment to burn the key and other information into designated storage within the chip. This makes the key more susceptible to leakage or cracking, and reduces security for privacy information that needs to be protected during the production process. However, the security of device privacy protection is also a key factor that needs to be considered during chip design and production. Summary of the Invention

[0003] At least one embodiment of the present disclosure provides an electronic device, comprising: a key pre-storage unit, configured to store preset key information solidified during an integrated circuit design process; a ciphertext storage unit, configured to store ciphertext encrypted using the preset key information; and a decryption processing module, configured to decrypt the ciphertext based on the preset key information.

[0004] For example, in an electronic device provided by at least one embodiment of the present disclosure, the decryption processing module includes a first decryption processing unit, which is configured to extract the preset key information and use the preset key information to decrypt the ciphertext.

[0005] For example, an electronic device provided by at least one embodiment of the present disclosure also includes a mapping module, wherein the ciphertext storage unit is also configured to store mapping information, and the mapping module is configured to map the preset key information based on the mapping information to obtain the mapped mapping key information.

[0006] For example, in an electronic device provided by at least one embodiment of the present disclosure, the decryption processing module includes a second decryption processing unit, which is configured to extract the mapping key information and use the mapping key information to decrypt the ciphertext.

[0007] For example, in an electronic device provided by at least one embodiment of the present disclosure, the second decryption processing unit includes security firmware, which is configured to read the mapping key information and the ciphertext, and use the mapping key information to decrypt the ciphertext to obtain plaintext.

[0008] For example, in an electronic device provided by at least one embodiment of the present disclosure, the mapping module includes a multiplexer and a selector, the multiplexer is configured to rearrange the preset key information and obtain the arranged key information, and the selector is configured to perform multi-bit width selection on the arranged key information and obtain the mapping key information.

[0009] For example, in an electronic device provided by at least one embodiment of the present disclosure, the pre-set key information includes N1-bit hard code, and the hard code includes M groups of N2-bit pre-set keys, where M is an integer greater than 1, and N1=M*N2.

[0010] For example, in an electronic device provided in at least one embodiment of the present disclosure, the mapping information includes at least one of the following: the starting bit in the hard-coded N1 bit, the bit step of each jump, the direction information from high bit to low bit or from low bit to high bit, and the starting offset of the selected N3 bit, wherein N3 is smaller than N1.

[0011] For example, in an electronic device provided by at least one embodiment of the present disclosure, the ciphertext storage unit includes a one-time programmable memory.

[0012] At least one embodiment of the present disclosure also provides a method for designing an integrated circuit, comprising: obtaining preset key information; designing a key pre-storage unit in the integrated circuit, and solidifying the preset key information in the key pre-storage unit of the integrated circuit; and providing design information of the integrated circuit for use in manufacturing products of the integrated circuit.

[0013] For example, in a design method provided in at least one embodiment of the present disclosure, the preset key information is solidified in the key pre-storage unit of the integrated circuit, including: solidifying the preset key information in the key pre-storage unit during the register conversion level circuit stage in the integrated circuit design process.

[0014] For example, in a design method provided in at least one embodiment of the present disclosure, obtaining preset key information includes: generating M groups of N2-bit preset keys to obtain N1-bit hard codes, thereby generating the preset key information, where M is an integer greater than 1, and N1=M*N2.

[0015] For example, a design method provided by at least one embodiment of the present disclosure further includes: in response to the register conversion stage circuit being wired, distributing the preset key information.

[0016] At least one embodiment of the present disclosure further provides a method for manufacturing an integrated circuit, which obtains design information of the integrated circuit obtained by the design method described in any one of the above items; and obtains at least one product of the integrated circuit through tape-out based on the design information.

[0017] For example, in a manufacturing method provided in at least one embodiment of the present disclosure, private information to be protected is obtained, the private information is encrypted using the preset key information to obtain a ciphertext, and the ciphertext is burned into a ciphertext storage unit of the integrated circuit product.

[0018] For example, a manufacturing method provided by at least one embodiment of the present disclosure further includes: burning mapping information used to decrypt the ciphertext into the ciphertext storage unit.

[0019] At least one embodiment of the present disclosure further provides an operating method for an integrated circuit product, comprising: obtaining the integrated circuit product obtained by the manufacturing method described above; extracting the preset key information, and using the preset key information to decrypt the ciphertext in the ciphertext storage unit of the integrated circuit product.

[0020] At least one embodiment of the present disclosure also provides an operating method for an integrated circuit product, comprising: obtaining the integrated circuit product obtained by the manufacturing method described above; and decrypting the ciphertext in the ciphertext storage unit of the integrated circuit product based on the preset key information and the mapping information.

[0021] For example, in an operating method provided in at least one embodiment of the present disclosure, the ciphertext in the ciphertext storage unit of the product of the integrated circuit is decrypted based on the preset key information and the mapping information, including: mapping the preset key information based on the mapping information to obtain the mapped mapping key information; extracting the mapping key information, and using the mapping key information to decrypt the ciphertext.

[0022] For example, in an operating method provided in at least one embodiment of the present disclosure, the mapping key information is extracted, and the ciphertext is decrypted using the mapping key information, including: reading the mapping key information and the ciphertext through the security firmware, and using the mapping key information to decrypt the ciphertext to obtain plaintext.

[0023] For example, in an operating method provided in at least one embodiment of the present disclosure, the preset key information is mapped based on the mapping information to obtain the mapped mapping key information, including: rearranging the preset key information to obtain the arranged key information; and selecting multiple bit widths of the arranged key information to obtain the mapping key information.

[0024] For example, in an operating method provided by at least one embodiment of the present disclosure, the preset key information includes a hard-coded N1 bit, and the hard-coded preset key includes M groups of N2 bits, where M is an integer greater than 1, and N1=M*N2; the mapping information includes at least one of the following: the starting bit in the hard-coded N1 bit, the bit step of each jump, the direction information from the high bit to the low bit or from the low bit to the high bit, and the starting offset of the selected N3 bits, where N3 is less than N1.

[0025] For example, in an operating method provided in at least one embodiment of the present disclosure, the preset key information is mapped based on the mapping information to obtain the mapped mapping key information, including: based on the starting bit in the hard-coded N1 bit, the bit step of each jump and the direction information, the preset key information is rearranged to obtain the arranged arrangement key information; based on the starting offset of the selected N3 bit, multiple bit widths are selected for the arrangement key information to obtain the mapping key information.

[0026] For example, in an operating method provided in at least one embodiment of the present disclosure, the ciphertext in the ciphertext storage unit of the integrated circuit product is decrypted based on the preset key information and the mapping information, including: decrypting the ciphertext through a symmetric encryption algorithm to obtain plaintext.

[0027] For example, in an operating method provided in at least one embodiment of the present disclosure, the privacy information includes at least one of: a user's root key, factory debugging parameters of the device, power configuration information, and operating frequency configuration information.

[0028] For example, in an operating method provided by at least one embodiment of the present disclosure, the mapping key information and the ciphertext are read by the security firmware, including: the security firmware sends an access request to the storage space where the mapping key information is located according to the target storage access address to read the mapping key information, wherein the target storage access address is configured to be used uniquely by the security firmware.

[0029] For example, in an operating method provided by at least one embodiment of the present disclosure, the mapping key information and the ciphertext are read by the security firmware, including: in response to the access information obtained by the security firmware based on the access request sent, including the mapping key information, the product of the integrated circuit starts normally.

[0030] At least one embodiment of the present disclosure provides an electronic device, comprising: a processor and a memory, wherein a computer program is stored in the memory, and when the computer program is executed by the processor, the design method or the operating method as described in any one of the above items is implemented.

[0031] At least one embodiment of the present disclosure provides a computer-readable storage medium, wherein the storage medium stores a computer program, and when the computer program is executed by a processor, implements the design method as described in any one of the above or the operating method as described in any one of the above. BRIEF DESCRIPTION OF THE DRAWINGS

[0032] In order to more clearly illustrate the embodiments of the present disclosure or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present disclosure. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0033] Figure 1 is a schematic diagram of the composition of an electronic device provided by some embodiments of the present disclosure;

[0034] Figure 2 is a schematic diagram of the composition of an electronic device provided in some other embodiments of the present disclosure;

[0035] Figure 3 is a schematic diagram of the composition of an electronic device provided by some other embodiments of the present disclosure;

[0036] Figure 4 A schematic diagram of a mapping module provided in some embodiments of the present disclosure;

[0037] Figure 5 is a flow chart of a method for designing an integrated circuit provided by some embodiments of the present disclosure;

[0038] Figure 6 is a flow chart of a method for manufacturing an integrated circuit provided by some embodiments of the present disclosure;

[0039] Figure 7 is a flow chart of a method for manufacturing an integrated circuit provided in some other embodiments of the present disclosure;

[0040] Figure 8 is a flowchart of an operating method of an integrated circuit product provided by some embodiments of the present disclosure;

[0041] Figure 9 is a flowchart of an operating method of an integrated circuit product provided by other embodiments of the present disclosure;

[0042] Figure 10 yes Figure 9 A flowchart of an execution process of step Q2 of the operating method;

[0043] Figure 11 yes Figure 10A flowchart of an execution process of step Q21 of the operation method;

[0044] Figure 12 yes Figure 10 A flowchart of another specific execution process of step Q21 of the operation method;

[0045] Figure 13 This is a structural diagram of an electronic device provided by at least one embodiment of the present disclosure. DETAILED DESCRIPTION

[0046] The following will be combined with the accompanying drawings in the embodiments of the present disclosure to clearly and completely describe the technical solutions in the embodiments of the present disclosure. Obviously, the embodiments described are only part of the embodiments of the present disclosure, not all of the embodiments. Based on the embodiments of the present disclosure, all other embodiments obtained by ordinary technicians in this field without making any creative efforts shall fall within the scope of protection of the present disclosure.

[0047] Unless otherwise defined, all terms (including technical and scientific terms) used in the embodiments of the present disclosure have the same meaning as commonly understood by those skilled in the art to which the present disclosure belongs. It should also be understood that terms such as those defined in common dictionaries should be interpreted as having meanings consistent with their meanings in the context of the relevant technology, and should not be interpreted in an idealized or extremely formal sense, unless explicitly defined in this manner in the embodiments of the present disclosure.

[0048] The words "first", "second" and similar words used in the embodiments of the present disclosure do not indicate any order, quantity or importance, but are only used to distinguish different components. Words such as "one", "an" or "the" do not indicate a quantity limitation, but rather indicate the existence of at least one. Similarly, words such as "include" or "comprise" mean that the elements or objects preceding the word include the elements or objects listed after the word and their equivalents, without excluding other elements or objects. Words such as "connect" or "connected" are not limited to physical or mechanical connections, but may include electrical connections, whether direct or indirect. Flowcharts are used in the embodiments of the present disclosure to illustrate the steps of the method according to the embodiments of the present disclosure. It should be understood that the previous or subsequent steps are not necessarily performed in exact order. Instead, the various steps may be processed in reverse order or simultaneously. At the same time, other operations may be added to these processes, or one or more steps may be removed from these processes.

[0049] Current methods for protecting device privacy during chip production carry the risk of privacy leaks. Chip memories (such as one-time programmable memory) contain various private information. The programming process for this memory is typically performed by a third-party manufacturer. This information can serve as a key for chip startup or affect initial configuration behavior, necessitating additional protection for this information.

[0050] The inventors of the present disclosure have discovered that current device privacy protection methods are relatively complex to apply. For example, each chip is required to have a unique key, that is, a one-chip-one-key method. This method is difficult to implement in a series of production and must be accompanied by a more complex management system and production interaction system. The usage process and application development will also be more complicated. For example, different application keys need to be used for the keys of each device, which also requires additional development and management costs.

[0051] At least one embodiment of the present disclosure provides an electronic device, comprising: a key pre-storage unit, configured to store preset key information solidified during an integrated circuit design process; a ciphertext storage unit, configured to store ciphertext encrypted using the preset key information; and a decryption processing module, configured to decrypt the ciphertext based on the preset key information.

[0052] At least one embodiment of the present disclosure also provides a method for designing an integrated circuit, comprising: obtaining preset key information; designing a key pre-storage unit in the integrated circuit, and solidifying the preset key information in the key pre-storage unit of the integrated circuit; and providing integrated circuit design information for use in manufacturing integrated circuit products.

[0053] At least one embodiment of the present disclosure further provides a method for manufacturing an integrated circuit, comprising: obtaining design information of the integrated circuit obtained by the design method described in the above embodiment; and obtaining at least one integrated circuit product through tape-out based on the design information.

[0054] At least one embodiment of the present disclosure further provides an operating method for a product based on the integrated circuit of the above embodiment.

[0055] By solidifying the preset key information within the circuit during the integrated circuit design process, the electronic devices or methods of the aforementioned embodiments of the present disclosure can achieve low development and maintenance costs while also preventing private information from being leaked during the production process, thereby enhancing the security of private information and meeting the need for privacy information protection. For example, even when multiple integrated circuit chips share the same key, at least one embodiment of the present disclosure can ensure high security of the device's private information, preventing the unfavorable situation of information leakage across an entire batch of integrated circuit chips due to information leakage from a single integrated circuit chip. This approach is simple and highly efficient.

[0056] Figure 1 This is a schematic diagram of the composition of an electronic device provided in some embodiments of the present disclosure.

[0057] For example, Figure 1 As shown, the electronic device 100 includes at least a key pre-storage unit 110, a ciphertext storage unit 120, and a decryption processing module 130. The key pre-storage unit 110 is configured to store preset key information A1 solidified during the integrated circuit design process. The ciphertext storage unit 120 is configured to store ciphertext B1 encrypted using the preset key information A1. The decryption processing module 130 is configured to decrypt the ciphertext B1 based on the preset key information A1.

[0058] The electronic device of the above-mentioned embodiment of the present disclosure solidifies the preset key information in the circuit during the integrated circuit design process, so that the privacy information in the production process is not easily leaked while the development and maintenance costs are low. This makes the privacy information more secure, the method is simple, and the production is efficient. At the same time, it can also meet the privacy information protection requirements of using the same key.

[0059] In some examples, the ciphertext storage unit 120 includes a one-time programmable memory. Of course, this is merely exemplary and not a limitation of the present disclosure.

[0060] Figure 2 It is a schematic diagram of the composition of an electronic device provided in some other embodiments of the present disclosure.

[0061] For example, Figure 2 As shown, the decryption processing module 130 includes a first decryption processing unit 131 , which is configured to extract pre-set key information A1 and decrypt the ciphertext B1 using the pre-set key information A1 .

[0062] The embodiment of the present disclosure realizes decryption of ciphertext by directly using preset key information, which is simple and improves efficiency.

[0063] Figure 3 This is a schematic diagram of the composition of an electronic device provided in some other embodiments of the present disclosure.

[0064] For example, Figure 3 As shown, the electronic device 100 further includes a mapping module 140. The ciphertext storage unit 120 is further configured to store mapping information D1, and the mapping module 140 is configured to map the preset key information A1 based on the mapping information D1 to obtain the mapped mapping key information A2.

[0065] For example, Figure 3As shown, the decryption processing module 130 includes a second decryption processing unit 132, which is configured to extract the mapping key information A2 and decrypt the ciphertext B1 using the mapping key information A2.

[0066] The embodiments of the present disclosure map pre-set key information and keep the mapping rules confidential, thereby improving the security of privacy information protection.

[0067] In some examples, the second decryption processing unit 132 includes security firmware, which is configured to read the mapping key information A2 and the ciphertext B1 and decrypt the ciphertext B1 using the mapping key information A2 to obtain plaintext. For example, the security firmware can send an access request to the storage space where the mapping key information A2 is located based on a target storage access address to read the mapping key information A2, and the target storage access address is configured to be uniquely used by the security firmware.

[0068] Therefore, the embodiment of the present disclosure greatly improves the security of privacy information protection by allocating a space for the security firmware that is only known to the security firmware and cannot be read by the external bus or other access components.

[0069] Figure 4 A schematic diagram of the principles of a mapping module provided in some embodiments of the present disclosure.

[0070] For example, Figure 3 and Figure 4 As shown, the mapping module 140 includes a multiplexer 141 and a selector 142. The multiplexer 141 is configured to rearrange the preset key information A1 to obtain the arranged key information A3. The selector 142 is configured to select the arranged key information A3 in multiple bit widths to obtain the mapping key information A2.

[0071] In some examples, the pre-key information A1 includes N1 bits of hard-coded information, which includes M groups of N2 bits of pre-key information, where M is an integer greater than 1 and N1 = M * N2. The embodiments of the present disclosure securely generate multiple sets of hardened keys to accommodate different users and different application segments. For example, N2 is a multiple of 8. Of course, this is merely exemplary and not a limitation of the present disclosure. N2 can also be selected from other reasonable numbers, and this is not exhaustively listed here.

[0072] For example, in Figure 4 In the example of , N1 can be 1024. For example, M can be 32. Therefore, the hard coding of the embodiment of the present disclosure adopts 32 groups of 32-bit wide preset key information, a total of 1024 bits, for example Figure 4The hardbit 0 to hardbit 1023 included in the M groups of N2-bit preset keys can be different from each other. For example, the arrangement key information A3 is also 1024 bits in total, for example Figure 4 The remap bit 0 to remap bit 1023 included in the byte are shown in FIG. Of course, this is only for example and is not intended to limit the present disclosure.

[0073] In some examples, the mapping information D1 includes at least one of the following: a starting bit D101 in the hard-coded N1 bits, a bit step D102 for each jump, direction information D103 from high bit to low bit or from low bit to high bit, and a starting offset D104 of the selected N3 bits, where N3 is smaller than N1.

[0074] In some examples, N3 is a multiple of 8. Of course, this is merely exemplary and not limiting of the present disclosure, and N3 may also be selected from other reasonable numbers, which will not be exhaustively listed or elaborated herein.

[0075] For example, in Figure 4 In the example, N3 can be 256, for example Figure 4 The mapping key information A2 in is 256 bits in total and includes select bit 0 to select bit 255. Of course, this is only for example and is not a limitation of the present disclosure.

[0076] Figure 5 This is a flowchart of a method for designing an integrated circuit provided by some embodiments of the present disclosure.

[0077] For example, Figure 5 As shown, the design method at least includes steps S1 to S3.

[0078] Step S1: Obtain preset key information A1.

[0079] Step S2: Design a key pre-storage unit 110 in the integrated circuit, and solidify the preset key information A1 in the key pre-storage unit 110 of the integrated circuit.

[0080] Step S3: providing integrated circuit design information for use in manufacturing integrated circuit products.

[0081] The above-mentioned embodiments of the present disclosure generate pre-set key information in a secure manner and fix it into the design of the integrated circuit. This can simply and effectively solve the potential problem of private information being provided to third parties in its original form. Instead, the embodiments of the present disclosure can retain the original text of the private information in a secure environment for use and provide the private information in the form of ciphertext. Therefore, the security is high, the method is simple, and the production is efficient.

[0082] In some examples, the secure environment may be an internal company environment that is not connected to the Internet or other secure environments protected by hardware. Of course, this is merely exemplary and is not intended to limit the present disclosure.

[0083] For example, for step S1, in some examples, obtaining the preset key information A1 includes the following process or steps: generating M groups of N2-bit preset keys to obtain N1-bit hard codes, thereby generating the preset key information A1, where M is an integer greater than 1, and N1=M*N2.

[0084] For example, N2 is a multiple of 8. Of course, this is only exemplary and is not a limitation of the present disclosure.

[0085] For example, with respect to step S2, in some examples, fixing the preset key information A1 in the key pre-storage unit of the integrated circuit includes the following process or steps: During the register transfer level (RTL) stage of the integrated circuit design process, fixing the preset key information A1 in the key pre-storage unit 110. In this way, the embodiments of the present disclosure fix the preset key information in the RTL, so that after the integrated circuit is tape-out, attackers cannot obtain the preset key information in a circuit with a large number of transistors, thereby improving the security of privacy information protection.

[0086] In some examples, the integrated circuit design method further includes the following process or step: in response to the register conversion stage circuit being wired, distributing the preset key information A1.

[0087] The above-mentioned embodiments of the present disclosure disperse the preset key information during RTL wiring to increase interference, making it difficult for attackers to obtain it from, for example, tens of billions of transistors, thereby improving the security of privacy information protection.

[0088] Figure 6 This is a flowchart of a method for manufacturing an integrated circuit provided by some embodiments of the present disclosure.

[0089] For example, Figure 6 As shown, the manufacturing method at least includes step T1 and step T2.

[0090] Step T1: Obtain design information of the integrated circuit.

[0091] Step T2: obtaining at least one integrated circuit product through tape-out based on the design information.

[0092] For example, for step T1, in some examples, obtaining the design information of the integrated circuit includes the following process or steps: obtaining the design information of the integrated circuit obtained by the design method described in any of the above embodiments. For details, please refer to the above description of the design method and will not be repeated here.

[0093] For example, for step T2, in some examples, obtaining a product of at least one integrated circuit through tape-out based on design information includes the following process or steps: obtaining a product of multiple integrated circuits having the same preset key information A1 based on design information through tape-out.

[0094] The manufacturing method of the above embodiment of the present disclosure is very simple and has high production efficiency, and can also meet the privacy information protection requirements of integrated circuit chips using the same key.

[0095] Figure 7 This is a flowchart of a method for manufacturing an integrated circuit provided in some other embodiments of the present disclosure.

[0096] For example, Figure 7 As shown, the manufacturing method includes not only step T1 and step T2, but also step T3 and step T4.

[0097] Step T3: Obtain the private information to be protected, and use the preset key information A1 to encrypt the private information to obtain the ciphertext B1.

[0098] Step T4: Burn the ciphertext B1 into the ciphertext storage unit 120 of the integrated circuit product.

[0099] In some examples, the manufacturing method further includes: programming mapping information D1 for decrypting the ciphertext B1 into the ciphertext storage unit 120 .

[0100] For example, in a secure environment, private information exists in plain text and can be encrypted or decrypted. Thus, information sent out of the secure environment is in cipher text. For example, private information can be sent to a third-party production factory in cipher text. Therefore, the security of the private information to be protected in the embodiments of the present disclosure is relatively high.

[0101] For example, in step T3, in some examples, the private information includes at least one of the user's root key, factory-set debugging parameters for the device, power configuration information, and operating frequency configuration information. Of course, this is merely illustrative and not a limitation of this disclosure. Any private information required for encryption during the production process is protected by this disclosure and will not be further elaborated here.

[0102] In some examples, the electronic device 100 of the above-mentioned embodiments of the present disclosure may be the integrated circuit product itself obtained based on the above-mentioned manufacturing method, or it may be a combination of the integrated circuit product obtained based on the above-mentioned manufacturing method and other functional circuits. The embodiments of the present disclosure do not limit or elaborate on this.

[0103] Figure 8 This is a flowchart of an operating method of an integrated circuit product provided by some embodiments of the present disclosure.

[0104] For example, Figure 8 As shown, the operation method at least includes step P1 and step P2.

[0105] Step P1: Obtain integrated circuit products.

[0106] Step P2: extract the pre-set key information A1, and use the pre-set key information A1 to decrypt the ciphertext B1 in the ciphertext storage unit 120 of the integrated circuit product.

[0107] For example, for step P1, in some examples, obtaining an integrated circuit product includes the following process or steps: obtaining an integrated circuit product obtained by the manufacturing method described in any of the above embodiments. For details, please refer to the above description of the manufacturing method and will not be repeated here.

[0108] Figure 9 This is a flowchart of an operating method of an integrated circuit product provided by other embodiments of the present disclosure.

[0109] For example, Figure 9 As shown, the operation method at least includes step Q1 and step Q2.

[0110] Step Q1: Obtain integrated circuit products.

[0111] Step Q2: decrypt the ciphertext B1 in the ciphertext storage unit of the integrated circuit product based on the preset key information A1 and the mapping information D1.

[0112] For example, for step Q1, in some examples, obtaining an integrated circuit product includes the following process or steps: obtaining an integrated circuit product obtained by the manufacturing method described in the above embodiment. For details, please refer to the above description of the manufacturing method and will not be repeated here.

[0113] In the above-mentioned embodiment of the present disclosure, private information is encrypted in the form of ciphertext during production and then provided to a third-party factory, and the third-party factory writes the ciphertext into a one-time programmable memory. In this way, although the ciphertext may be leaked, the original text corresponding to the private information will be kept safe or confidential from beginning to end, and the security of the private information is relatively high.

[0114] Figure 10 yes Figure 9 Flowchart of an execution process of step Q2 of the operating method.

[0115] For example, Figure 10 As shown, an example of step Q2 includes at least step Q21 and step Q22.

[0116] Step Q21: Map the preset key information A1 based on the mapping information D1 to obtain the mapped key information A2.

[0117] Step Q22: Extract the mapping key information A2 and use the mapping key information A2 to decrypt the ciphertext B1.

[0118] For example, in some examples, extracting mapping key information A2 and using mapping key information A2 to decrypt ciphertext B1 includes the following process or step Q221: The secure firmware reads mapping key information A2 and ciphertext B1, and uses mapping key information A2 to decrypt ciphertext B1 to obtain plaintext. In this way, embodiments of the present disclosure can ensure that the original text of the private information is always used in a secure environment, and only the secure firmware can access the mapping key information and pre-set key information, thereby improving the security of private information protection.

[0119] Figure 11 yes Figure 10 Flowchart of an execution process of step Q21 of the operation method. Figure 12 yes Figure 10 Flowchart of another specific execution process of step Q21 of the operation method.

[0120] For example, Figure 11 As shown, an example of step Q21 includes at least step Q211 and step Q212.

[0121] Step Q211: Rearrange the preset key information A1 and obtain the arranged key information A3.

[0122] Step Q212: Select multiple bit widths for the arrangement key information A3 to obtain the mapping key information A2.

[0123] In some examples, the pre-key information A1 includes N1 bits of hard code, and the hard code includes M groups of N2 bits of pre-key, where M is an integer greater than 1, and N1=M*N2.

[0124] In some examples, N2 is a multiple of 8. Of course, this is merely exemplary and not limiting of the present disclosure, and N2 may also be selected from other reasonable numbers, which will not be exhaustively listed or elaborated herein.

[0125] For example, N1 may be 1024. In some examples, the mapping information D1 includes at least one of the following: a hard-coded start bit D101 in the N1 bits, a bit step size D102 of each jump, direction information D103 from a high bit to a low bit or from a low bit to a high bit, and a start offset D104 of a selected N3 bit, where N3 is smaller than N1.

[0126] In some examples, N3 is a multiple of 8. Of course, this is merely exemplary and not limiting of the present disclosure. N3 may also be selected from other reasonable numbers, which will not be exhaustively listed here. For example, N3 may be 256.

[0127] In this regard, Figure 12 As shown, an example of step Q21 may further include step Q211a and step Q212a.

[0128] Step Q211a: Based on the hard-coded start bit D101 in the N1 bit, the bit step D102 of each jump, and the direction information D103, the preset key information A1 is rearranged to obtain the arranged key information A3.

[0129] Step Q212a: Based on the selected N3-bit starting offset D104, multiple bit widths are selected for the arrangement key information A3 to obtain the mapping key information A2.

[0130] It should be noted that the present disclosure is not limited to the specific example described in the above embodiment of mapping preset key information based on mapping information to obtain mapped mapping key information, and any other reasonable mapping method can also be used, which will not be repeated here.

[0131] For example, regarding step Q2, in some examples, decrypting ciphertext B1 in the ciphertext storage unit 120 of the integrated circuit product based on the pre-set key information A1 and the mapping information D1 includes the following process or steps: decrypting ciphertext B1 using a symmetric encryption algorithm to obtain plaintext. In this way, embodiments of the present disclosure achieve rapid encryption or decryption of information and simplified key management.

[0132] In some examples, the symmetric encryption algorithm includes the SM4 encryption algorithm. Of course, this is merely exemplary and not limiting of the present disclosure. For example, embodiments of the present disclosure may also decrypt ciphertext to obtain plaintext using an asymmetric encryption algorithm, which will not be described in detail here.

[0133] For example, for step Q221, in some examples, reading the mapping key information and ciphertext through the secure firmware includes the following process or steps: the secure firmware sends an access request to the storage space where the mapping key information A2 is located according to the target storage access address to read the mapping key information A2, wherein the target storage access address is configured to be used uniquely by the secure firmware.

[0134] In some examples, reading the mapping key information and ciphertext through the secure firmware may also include the following process or steps: in response to the secure firmware obtaining access information including the mapping key information based on the access request sent, the integrated circuit product starts normally, i.e., at this time, verification is passed, and decryption can be successfully performed using the mapping key information, and the integrated circuit product can then be started and used normally; conversely, if the secure firmware does not access and obtain the mapping key information, the integrated circuit product does not start, i.e., at this time, verification does not pass, and the integrated circuit product does not start. Therefore, the embodiments of the present disclosure enable the integrated circuit chip to be started and used very securely, and can greatly improve the security of privacy information protection.

[0135] For example, the private information to be protected is as follows:

[0136] EF7E09B382945F7731A6DDC83EBCAD5E53C345F1D9275D1B1118B564A952B382.

[0137] For example, the encrypted ciphertext B1 of the private information will be written into the ciphertext storage unit 120. The ciphertext B1 is as follows:

[0138] 0FC8B5C41F4744A55D9D2DDE445B96C548A7287C4CC2726F84B1139D8CF3D720.

[0139] For example, the preset key information A1 is: 117AC9C66D9AEC6804D4E9DD2269ED10.

[0140] Based on the above, the information read after startup is ciphertext B1. After decryption, the plaintext sent to the secure firmware is as follows:

[0141] EF7E09B382945F7731A6DDC83EBCAD5E53C345F1D9275D1B1118B564A952B382.

[0142] Of course, the privacy information, pre-set key information, ciphertext, etc. provided above are merely exemplary and are not limitations of the present disclosure.

[0143] It should be noted that in the embodiment of the present disclosure, the electronic device 100 may include more or fewer modules, and the connection relationship between the modules is not limited and can be determined according to actual needs. The specific configuration of each module is not limited.

[0144] It should be noted that the specific implementation methods and technical effects of the electronic device 100, the integrated circuit design method, the integrated circuit manufacturing method and the integrated circuit product operation method in the embodiments of the present disclosure can refer to each other's related contents and will not be repeated here.

[0145] The various modules in the above embodiments of the present disclosure may be configured as software, hardware, firmware, or any combination thereof to perform specific functions. For example, these modules may correspond to dedicated integrated circuits, pure software codes, or modules that combine software and hardware.

[0146] It should be noted that although the electronic device 100 is divided into modules for respectively performing corresponding processing when describing it above, it is clear to those skilled in the art that the processing performed by each module can also be performed without any specific module division in the electronic device 100 or without clear boundaries between the modules.

[0147] Figure 13 This is a structural diagram of an electronic device provided by at least one embodiment of the present disclosure. The electronic device 200 includes a processor 210 and a memory 220, wherein a computer program is stored on the memory 220. When the computer program is executed by the processor 210, the design method or operation method of at least some embodiments of the present disclosure is implemented.

[0148] The electronic devices in the embodiments of the present disclosure may include, but are not limited to, mobile terminals such as laptop computers, tablet computers, etc., and fixed terminals such as desktop computers, etc. Figure 13 The electronic device shown is only an example and should not limit the functions and scope of use of the embodiments of the present disclosure.

[0149] For example, according to embodiments of the present disclosure, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments of the present disclosure include a computer program product comprising a computer program carried on a non-transitory computer-readable medium, the computer program including program code for executing the methods shown in the flowcharts. When the computer program is executed by a processor, the design method or operating method of the embodiments of the present disclosure is executed.

[0150] It should be noted that the computer-readable medium mentioned above in the present disclosure may be a computer-readable signal medium or a computer-readable storage medium, or any combination of the two. The computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device, or device, or any combination of the above. More specific examples of computer-readable storage media may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In embodiments of the present disclosure, a computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, device, or device. In embodiments of the present disclosure, a computer-readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, which carries computer-readable program code. Such propagated data signals may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. A computer-readable signal medium may also be any computer-readable medium other than a computer-readable storage medium that can transmit, propagate, or transport a program for use by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium may be transmitted using any suitable medium, including but not limited to wires, optical cables, RF (radio frequency), etc., or any suitable combination thereof.

[0151] The computer-readable medium may be included in the electronic device, or may exist independently without being incorporated into the electronic device.

[0152] It should be noted that, in the embodiment of the present disclosure, the specific functions and technical effects of the electronic device 200 can refer to the above description of the design method or operation method, which will not be repeated here.

[0153] There are a few points to note:

[0154] (1) The drawings of the embodiments of the present disclosure only relate to the structures involved in the embodiments of the present disclosure. Other structures may refer to conventional designs.

[0155] (2) In the absence of conflict, the embodiments of the present disclosure and the features therein may be combined with each other to form new embodiments.

[0156] The above description is only a specific embodiment of the present disclosure, but the protection scope of the present disclosure is not limited thereto. The protection scope of the present disclosure shall be based on the protection scope of the claims.

Claims

1. An electronic device comprising: A key pre-storage unit configured to store preset key information solidified in the stage of the register conversion stage circuit in the integrated circuit design process; a ciphertext storage unit configured to store ciphertext encrypted using the preset key information; the ciphertext storage unit includes a one-time programmable memory, the ciphertext is configured to be obtained by encrypting the private information to be protected using the preset key information, and the ciphertext is configured to be burned into the ciphertext storage unit; The decryption processing module is configured to decrypt the ciphertext based on the preset key information.

2. The electronic device according to claim 1, wherein The decryption processing module includes a first decryption processing unit configured to extract the pre-set key information and decrypt the ciphertext using the pre-set key information.

3. The electronic device according to claim 1, further comprising a mapping module, wherein The ciphertext storage unit is further configured to store mapping information, The mapping module is configured to map the preset key information based on the mapping information and obtain the mapped mapping key information.

4. The electronic device according to claim 3, wherein: The decryption processing module includes a second decryption processing unit configured to extract the mapping key information and decrypt the ciphertext using the mapping key information.

5. The electronic device according to claim 4, wherein: The second decryption processing unit includes a security firmware, and the security firmware is configured to read the mapping key information and the ciphertext, and use the mapping key information to decrypt the ciphertext to obtain plaintext.

6. The electronic device according to claim 3, wherein: The mapping module includes a multiplexer and a selector, The multiplexer is configured to rearrange the preset key information to obtain rearranged key information; The selector is configured to perform multi-bit-width selection on the arrangement key information to obtain the mapping key information.

7. The electronic device according to claim 3, wherein: The pre-set key information includes N1-bit hard code, and the hard code includes M groups of N2-bit pre-set keys, where M is an integer greater than 1, and N1=M*N2.

8. The electronic device according to claim 7, wherein: The mapping information includes at least one of the following: the starting bit in the hard-coded N1 bit, the bit step of each jump, the direction information from high bit to low bit or from low bit to high bit, and the starting offset of the selected N3 bit, wherein N3 is smaller than N1.

9. A method for manufacturing an integrated circuit, comprising: obtaining design information of the integrated circuit; Obtaining at least one product of the integrated circuit by tape-out based on the design information; The design information of the integrated circuit is obtained by the following design method: Get the preset key information; Designing a key pre-storage unit in the integrated circuit, and fixing the preset key information in the key pre-storage unit of the integrated circuit; providing design information of the integrated circuit for use in manufacturing products of the integrated circuit; The step of fixing the preset key information in the key pre-storage unit of the integrated circuit comprises: fixing the preset key information in the key pre-storage unit during the register conversion stage circuit stage of the integrated circuit design process; The manufacturing method further comprises: Acquire the private information to be protected, and encrypt the private information using the preset key information to obtain a ciphertext; The ciphertext is burned into a ciphertext storage unit of a product of the integrated circuit, wherein the ciphertext storage unit includes a one-time programmable memory.

10. The manufacturing method according to claim 9, wherein: Get the pre-configured key information, including: Generate M groups of N2-bit pre-keys to obtain N1-bit hard codes, thereby generating the pre-key information, where M is an integer greater than 1, and N1=M*N2.

11. The manufacturing method according to claim 10, wherein: The design method further includes: In response to the register conversion stage circuit being wired, the preset key information is dispersedly arranged.

12. The manufacturing method according to claim 9, further comprising: The mapping information used to decrypt the ciphertext is burned into the ciphertext storage unit.

13. A method for operating an integrated circuit product, comprising: Obtaining the integrated circuit product obtained by the manufacturing method according to claim 9; The pre-set key information is extracted, and the ciphertext in the ciphertext storage unit of the product of the integrated circuit is decrypted using the pre-set key information.

14. A method for operating an integrated circuit product, comprising: Obtaining the integrated circuit product obtained by the manufacturing method according to claim 12; The ciphertext in the ciphertext storage unit of the product of the integrated circuit is decrypted based on the preset key information and the mapping information.

15. The operating method according to claim 14, wherein: Decrypting the ciphertext in the ciphertext storage unit of the product of the integrated circuit based on the preset key information and the mapping information includes: Mapping the preset key information based on the mapping information to obtain mapped key information; The mapping key information is extracted, and the ciphertext is decrypted using the mapping key information.

16. The operating method according to claim 15, wherein: Extracting the mapping key information and decrypting the ciphertext using the mapping key information includes: The mapping key information and the ciphertext are read by the security firmware, and the ciphertext is decrypted using the mapping key information to obtain plaintext.

17. The operating method according to claim 15, wherein: Mapping the preset key information based on the mapping information to obtain the mapped key information includes: Rearranging the preset key information to obtain arranged key information; Multiple bit widths are selected for the arrangement key information to obtain the mapping key information.

18. The operating method according to claim 14, wherein: The pre-set key information includes N1-bit hard code, and the hard code includes M groups of N2-bit pre-set keys, where M is an integer greater than 1, and N1=M*N2; The mapping information includes at least one of the following: the starting bit in the hard-coded N1 bit, the bit step of each jump, the direction information from high bit to low bit or from low bit to high bit, and the starting offset of the selected N3 bit, wherein N3 is smaller than N1.

19. The operating method according to claim 18, wherein: Mapping the preset key information based on the mapping information to obtain the mapped key information includes: Rearranging the preset key information based on the start bit in the hard-coded N1 bits, the bit step of each jump, and the direction information to obtain arranged key information; Based on the selected N3-bit starting offset, multiple bit widths are selected for the arrangement key information to obtain the mapping key information.

20. The operating method according to claim 14, wherein: Decrypting the ciphertext in the ciphertext storage unit of the product of the integrated circuit based on the preset key information and the mapping information includes: The ciphertext is decrypted using a symmetric encryption algorithm to obtain plaintext.

21. The operating method according to claim 14, wherein: The privacy information includes at least one of: a user's root key, factory debugging parameters of the device, power configuration information, and operating frequency configuration information.

22. The operating method according to claim 16, wherein: Reading the mapping key information and the ciphertext through the secure firmware includes: The security firmware sends an access request to the storage space where the mapping key information is located according to a target storage access address to read the mapping key information, wherein the target storage access address is configured to be uniquely used by the security firmware.

23. The operating method according to claim 16, wherein: Reading the mapping key information and the ciphertext through the secure firmware includes: In response to the access information acquired by the security firmware based on the access request sent including the mapping key information, the product of the integrated circuit starts normally.

24. An electronic device comprising: processor and memory, Wherein, a computer program is stored in the memory, and when the computer program is executed by the processor, the operating method according to any one of claims 13 to 23 is implemented.

25. A computer-readable storage medium, wherein: The storage medium stores a computer program, and when the computer program is executed by the processor, the operating method according to any one of claims 13 to 23 is implemented.

Citation Information

Patent Citations

  • Apparatus and method for securely managing keys

    CN113094720A

  • Methods for Protecting Against Piracy of Integrated Circuits

    US20100284539A1