Data writing method, data reading method and related devices

By using write-redundant polynomial encoding in memory to generate integrity error correction tags, the problem of insufficient memory data integrity protection is solved, and the data integrity verification and error correction capabilities are improved without affecting the error correction performance.

CN115827514BActive Publication Date: 2025-09-30HYGON INFORMATION TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202211408861.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-11
Publication Date
2025-09-30
Estimated Expiration
2042-11-11

AI Technical Summary

Technical Problem

While ensuring error correction capabilities, existing technologies have insufficient integrity protection for memory data. In particular, the MAC value of the SHA3 algorithm is truncated and stored, which results in a decreased error correction capability and a high probability of integrity verification collisions.

Method used

A write-redundant polynomial is used to encode the data and address to be written, generate an integrity error correction tag, and write it into the memory together with the data. Integrity verification and error correction are performed by reading the redundant polynomial to ensure data integrity and error correction capabilities.

Benefits of technology

Without taking up additional storage space, the integrity protection function and error correction capability of memory data are improved, reducing the risk of data errors.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115827514B_ABST
    Figure CN115827514B_ABST
Patent Text Reader

Abstract

The embodiments of the present application provide a data writing method, a data reading method, and related devices, wherein the data writing method includes obtaining data to be written and a data address to be written corresponding to the data to be written; performing a write redundancy coding operation on the data address to be written and the data to be written using a write redundancy polynomial to obtain an integrity error correction tag to be written, wherein the integrity error correction tag to be written is used for integrity verification and data error correction; and writing the data to be written and the integrity error correction tag to be written into a memory. The data writing method provided in the embodiments of the present application can improve the integrity protection function of memory data while ensuring error correction capability.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present application relate to the field of computer technology, and in particular to a data writing method, a data reading method, and related devices. Background Art

[0002] With the advancement of digital technology, a large amount of confidential information is processed on computer systems, making computer system security a particularly critical issue. Currently, computer system security is typically designed around the central processing unit (CPU) hardware and memory controller. While most confidential information is encrypted and stored in computer system memory, protecting it effectively prevents integrity verification of the confidential information stored in memory. If a malicious attacker physically attacks the encrypted memory, users will be unable to verify the data's integrity, posing a business risk.

[0003] In one method, a SHA3 (third-generation secure hash algorithm) digest calculation engine is added to the memory controller in a double-data-rate synchronous dynamic random access memory (DDR5) environment, and the redundant storage space of the DRAM (memory) itself, such as the ECC bit (error detection and correction bit), is used to store the data MAC value (Message Authentication Code).

[0004] However, while the SHA3 algorithm can verify data integrity, the MAC value used for this verification is truncated before being stored in memory. This truncated MAC value is only 28 bits long and cannot verify the integrity of the large number of bits stored in memory, severely weakening the memory data integrity protection function (the probability of a collision is approximately 1 in 100,000). Furthermore, the MAC value is stored in the ECC bit of memory, shortening the ECC bit originally used for error correction and detection, reducing the error correction capability of the error correction code for memory data. When memory error correction capability is reduced, data errors cannot be detected, leading to catastrophic consequences.

[0005] Therefore, how to improve the integrity protection function of memory data while ensuring error correction capabilities has become a technical problem that needs to be solved urgently. Summary of the Invention

[0006] The technical problem solved by the embodiments of the present application is how to improve the integrity protection function of memory data while ensuring the error correction capability.

[0007] To solve the above problems, the present invention provides a data writing method, a data reading method, and related devices, including:

[0008] In a first aspect, an embodiment of the present application provides a data writing method, the method comprising:

[0009] Acquire data to be written and a data address to be written corresponding to the data to be written;

[0010] Performing a write redundancy coding operation on the data address to be written and the data to be written using a write redundancy polynomial to obtain an integrity error correction tag to be written, wherein the integrity error correction tag to be written is used for integrity verification and data error correction;

[0011] The data to be written and the integrity error correction tag to be written are written into the memory.

[0012] In a second aspect, an embodiment of the present application provides a data reading method, the method comprising:

[0013] Obtaining data to be read stored at a data address to be read and an integrity error correction tag to be read corresponding to the data to be read, wherein the data address to be read includes the data address to be written in the data writing method according to the first aspect, and the integrity error correction tag to be read includes the integrity error correction tag to be written in the data writing method according to the first aspect, and the integrity error correction tag to be read is used to perform integrity verification and data error correction on the data to be read;

[0014] Obtaining a first redundant integrity error correction tag according to the integrity error correction tag to be read;

[0015] performing a read redundant coding operation on the to-be-read data and the to-be-read data address using a read redundant polynomial to obtain a second redundant integrity error correction tag, wherein the read redundant polynomial corresponds to the write redundant polynomial in the data writing method described in the first aspect;

[0016] When the first redundant integrity error correction tag is equal to the second redundant integrity error correction tag, determining that the data to be read is complete;

[0017] The data to be read that is confirmed to be complete is sent.

[0018] In a third aspect, an embodiment of the present application further provides a data writing device, the device comprising:

[0019] A write acquisition module, adapted to acquire data to be written and a data address to be written corresponding to the data to be written;

[0020] a write redundant coding operation module, adapted to perform a write redundant coding operation on the address of the data to be written and the data to be written using a write redundant polynomial to obtain an integrity error correction tag to be written, wherein the integrity error correction tag to be written is used for integrity verification and data error correction;

[0021] The writing module is adapted to write the data to be written and the integrity error correction tag to be written into the memory.

[0022] In a fourth aspect, an embodiment of the present application further provides a data reading device, comprising:

[0023] a read acquisition module, adapted to acquire data to be read stored at a data address to be read, and an integrity error correction tag to be read corresponding to the data to be read, wherein the data address to be read comprises the data address to be written in the data writing device as described in the third aspect, and the integrity error correction tag to be read comprises the integrity error correction tag to be written in the data writing device as described in the third aspect, and the integrity error correction tag to be read is used to perform integrity verification and data error correction on the data to be read;

[0024] a first redundant integrity error correction label acquisition module, adapted to acquire a first redundant integrity error correction label according to the integrity error correction label to be read;

[0025] a read redundant coding operation module, adapted to perform a read redundant coding operation on the to-be-read data and the to-be-read data address using a read redundant polynomial to obtain a second redundant integrity error correction tag, wherein the read redundant polynomial corresponds to the write redundant polynomial in the data writing device described in the third aspect;

[0026] an integrity determination module, adapted to determine that the to-be-read data is complete when the first redundant integrity error correction tag is equal to the second redundant integrity error correction tag;

[0027] The sending module is adapted to send the confirmed complete data to be read.

[0028] In a fifth aspect, an embodiment of the present application further provides a storage medium storing a program suitable for data writing and data reading to implement the data writing method described in the first aspect or the data reading method described in the second aspect.

[0029] In a sixth aspect, an embodiment of the present application further provides an electronic device comprising at least one memory and at least one processor, wherein the memory stores a data writing program, and the processor calls the program to execute the data writing method as described in the first aspect or the data reading method as described in the second aspect.

[0030] Compared with the prior art, the technical solution of the embodiment of the present application has the following advantages:

[0031] In an embodiment of the present application, first, data to be written and a data address to be written corresponding to the data to be written are obtained; the data to be written is encrypted to obtain the encrypted data to be written; a write redundant coding operation is performed on the data address to be written and the encrypted data to be written using a write redundant polynomial to obtain an integrity error correction tag; the integrity error correction tag is encrypted to obtain an encrypted integrity error correction tag to be written, and the encrypted integrity error correction tag to be written is used for integrity verification and data error correction; the encrypted data to be written and the encrypted integrity error correction tag to be written are written into a memory.

[0032] It can be seen that the technical solution provided in the embodiment of the present application first uses a write redundant polynomial to perform a write redundant coding operation on the data to be written and the data address to be written corresponding to the data to be written, to obtain an integrity error correction tag to be written, and then writes the integrity error correction tag to be written and the data to be written into the memory. The integrity error correction tag to be written can not only realize error correction of the data to be written when an error occurs in the data to be written, but also realize integrity verification of the data to be written corresponding to the data address to be written. There is no need to set up an additional tag for integrity verification, so the storage space of the error correction tag used for error correction will not be occupied, thereby ensuring the error correction performance. Therefore, the integrity protection function of the memory data can be improved without affecting the error correction performance of the data and ensuring the error correction capability. BRIEF DESCRIPTION OF THE DRAWINGS

[0033] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are merely embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without any creative work.

[0034] Figure 1 The basic system architecture diagram for computer-implemented data security processing is shown as an example.

[0035] Figure 2 The following is a schematic diagram showing an example of a basic system architecture for implementing memory error detection and correction using error checking and correction codes.

[0036] Figure 3a The following is a schematic diagram of a system framework for generating a write data integrity verification code using a message digest algorithm.

[0037] Figure 3b The following is a schematic diagram of a system framework for implementing read data integrity verification code verification using a message digest algorithm.

[0038] Figure 4a A schematic diagram of the architecture for implementing data writing in accordance with the data writing method provided in an embodiment of the present application.

[0039] Figure 4b A schematic diagram of the architecture for implementing data reading according to the data reading method provided in the embodiment of the present application.

[0040] Figure 5 1 is a flow chart of a data writing method provided in an embodiment of the present application.

[0041] Figure 6 This is another flowchart of the data writing method provided in an embodiment of the present application.

[0042] Figure 7 1 is a flow chart of a data reading method provided in an embodiment of the present application.

[0043] Figure 8 Schematic diagram of a data writing device provided in an embodiment of the present application.

[0044] Figure 9 It is a structural diagram of a data reading device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0045] The following will be combined with the drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are only part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.

[0046] Figure 1 The following is an example of a basic system architecture diagram for computer-implemented data security processing: Figure 1 As shown, the system architecture may include: a processor 110 , a memory controller 120 , and a memory 130 .

[0047] Among them, the processor 110 is mainly a high-performance computing processor, generally a CPU (central processing unit) or a GPGPU (general-purpose graphics processing unit). The processor 110 can send data read and write requests, and the memory 130 can store instructions and data. The processor 110 obtains instructions and corresponding data from the memory 130, then executes the instructions, and writes the result data back to the memory 130.

[0048] The memory 130 is a storage area for program execution codes and data, and is typically implemented using a DRAM (Dynamic Random Access Memory) type memory chip.

[0049] To protect data security, an encryption scheme is added to the processor 110 hardware to enhance the confidentiality of memory data. An encryption engine (using a key to encrypt and decrypt data) is added to the memory controller 120. This encrypts data written to the memory and stores the encrypted data in the memory 130. When data is read from the memory 130, the memory controller 120 decrypts the encrypted data and transmits it to the processor 110 for processing.

[0050] While many solutions exist for protecting the confidentiality of memory 130, none can verify the integrity of the data stored in memory. If a malicious attacker physically attacks the encrypted data stored in memory 130, users will be unable to verify the integrity of the data, leading to business risks. This is particularly prominent in security-critical sectors such as finance.

[0051] In order to ensure the integrity of memory data, ECC (error checking and correction) checksums have been added to the latest DDR5 (double data rate synchronous dynamic random access memory) memory technology to improve the stability of memory 130.

[0052] Figure 2 The following is a schematic diagram showing an example of a basic system architecture for implementing memory error detection and correction using error checking and correction codes.

[0053] As shown in the figure, the system may include: a processor 110 , an error checking and correction module 121 , and a memory 130 .

[0054] As shown in the figure, when the memory 130 has an error due to a fault or electrical noise, some bits of the memory data are reversed, resulting in data errors. The error checking and correction module 121 (ECC error detection and correction control) sets an additional storage unit ( Figure 2 The ECC bits shown store ECC check data. When the processor 110 issues a request to read data, the error checking and correction module 121 is used to correct erroneous memory data bits. Typically, DDR5 has enough memory cells with sufficient ECC check data bits. However, the ECC algorithm generally provides error correction and detection for a limited number of bits and cannot detect errors in all memory data bits.

[0055] Some CPU manufacturers add a SHA3 (Secure Hash Algorithm-3, one-way hash function) digest calculation engine to the memory controller 120, and use the redundant storage space of the memory 130 itself (such as Figure 2 The error detection and correction bits shown in the figure are used to save the data MAC value (Message Authentication Code). Specifically, Figure 3a and Figure 3b As shown, Figure 3a The following is a schematic diagram of a system framework for generating a data integrity verification code using a message digest algorithm. Figure 3b The following is a schematic diagram of a system framework for implementing read data integrity verification code verification using a message digest algorithm.

[0056] As shown in the figure, the system may include: an information summary calculation engine 150 and a memory 130 .

[0057] During the data write phase, the digest calculation engine 150 calculates a message verification code for the data to be written. The message verification code is truncated and stored in the redundant storage space of the memory 130. During the data read phase, the ciphertext data (i.e., the encrypted data and message verification code stored during write) are retrieved from the memory 130. The encrypted data then enters the digest calculation engine 150 for recalculation to obtain the calculated message verification code. The stored message verification code and the recalculated message verification code are compared. If the two are equal, the data has not been tampered with. If they are not equal, the data has been tampered with, and a data anomaly signal is issued. In the MAC calculation algorithm, MAC = SHA3(data, addr, MAC key, meta), where addr is the memory address of the encrypted data to be read; the MAC key is the protection key for the message verification code calculation. The MAC key is generated and stored internally by the integrated circuit chip and cannot be obtained externally; meta is a set of metadata determined by the manufacturer.

[0058] However, the message digest algorithm and message verification code are truncated to 28 bits, severely weakening the integrity protection of memory 130 (the probability of collision is approximately one in 100,000). Furthermore, they occupy error detection and correction bits, reducing the error correction capability of memory 130. When the error correction capability of memory 130 is reduced, data errors cannot be detected, leading to catastrophic consequences.

[0059] It can be seen that the above data integrity protection method will weaken the error correction capability and integrity protection function of the memory 130.

[0060] In order to solve the above problems, an embodiment of the present application provides a data writing method to implement memory data integrity protection and error correction functions.

[0061] Figure 4a A schematic diagram of the architecture for implementing data writing in accordance with the data writing method provided in an embodiment of the present application.

[0062] Specifically, the implementation of data writing may include:

[0063] Step 1: The processor issues a data write operation: writing the data to be written data to the location of the data address to be written addr in the memory.

[0064] Step 2, the plaintext data (i.e., the original data to be written that has not been encrypted) is encrypted by the data encryption module 001, such as: using the SM4 encryption algorithm, where SM4 is a block cipher algorithm, which is used to realize the encryption of the data to be written, protect the security of the data to be written, obtain the encrypted data to be written (ciphertext data), and save the encrypted data to be written to the data storage bits (data bits) of the memory. The second encryption key used by the data encryption module 001 can be the security encryption parameter generated by the security processor and the second encryption parameter (such as the random number 1 generated when the processor starts) is generated by the first key derivation function, such as KDF, which is a key derivation function. Since both the data to be written and the integrity error correction tag (plaintext tag) are encrypted in the embodiment of the present application, two key derivation functions are required. In order to distinguish them, they are divided into a first key generation function KDF1 and a second key generation function KDF2.

[0065] Of course, in other embodiments, the specific method of generating the second encryption key can be determined as needed.

[0066] In other embodiments, the data to be written may be directly stored without being encrypted.

[0067] Step 3: Using the address addr of the data to be written and the write redundant initial value parameter (such as the random number 3 generated when the processor starts), the write redundant initial value (i.e., the initial value of the 128-bit CRC) is calculated. The calculation process can be customized (for example, directly linked together, or through certain calculations). The data writing method provided in the embodiment of the present application does not specify a specific calculation, wherein the random number 3 is the initial value calculation parameter of the redundant coding operation module 002 (used to perform the write redundant coding operation), and the write redundant initial value is derived together with the address addr of the data to be written. The random number 3 is generated once by the processor hardware after the processor starts, and its content cannot be obtained externally. It remains unchanged during the entire working process of the processor, thereby ensuring the stability and determinism of the redundant coding operation module 002, providing a reliable basis for subsequent data integrity verification and data error correction.

[0068] Step 4: The redundant coding calculation module 002CRC128 uses the written redundant initial value and the redundant polynomial randomly generated when the processor starts (i.e., the written redundant polynomial) to calculate the integrity error correction tag (plaintext tag, i.e., redundant data) for the encrypted data to be written (ciphertext data);

[0069] Of course, in the scheme where the write redundancy initial value parameter is not obtained, the write redundancy initial value will not be obtained based on the address addr of the data to be written and the write redundancy initial value parameter. Then, the write redundancy encoding operation is directly performed on the address of the data to be written and the encrypted data to be written using the write redundancy polynomial to obtain the integrity error correction label.

[0070] In step 5, the data address addr to be written and the first encryption parameter (such as the random number 2 generated when the processor starts) are used to derive the current first encryption key through the second key generation function KDF 2. The integrity error correction tag (plaintext tag) is encrypted using the integrity error correction tag encryption module 003 (which can be the aforementioned SM4 encryption algorithm) to obtain the encrypted integrity error correction tag to be written (ciphertext tag), which is saved in the corresponding integrity verification error correction bit in the memory 004. Since the redundant coding operation module 002 is a linear transformation, in order to protect the security of the generated integrity error correction tag, additional encryption protection of the integrity error correction tag encryption module 003 is added to the integrity error correction tag.

[0071] In other implementations, the first encryption parameter may not be used, and the current first encryption key may be directly derived from the address addr of the data to be written through the second key generation function, and the integrity error correction label may be encrypted using the first encryption key to ensure the security of the integrity error correction label.

[0072] Accordingly, when reading the data stored in the memory through the above method, it is necessary to decrypt the encryption integrity error correction tag to be written (encryption integrity error correction tag to be read) and the encrypted data to be written (encrypted data to be read), and perform data integrity verification. If the data is determined to be complete, it can be read directly. If the data is incomplete, it needs to be corrected and then read. For details, please refer to Figure 4b , Figure 4b A schematic diagram of the architecture for implementing data reading according to the data reading method provided in the embodiment of the present application.

[0073] As shown in the figure, the implementation of data reading may include:

[0074] Step 1: The processor issues a data read operation to read the data to be read data from the data address to be read addr. Of course, the data address to be read addr corresponds to each data address to be written addr in the above-mentioned data writing process. Since the integrity of the data stored in the data address to be read addr needs to be verified, the correct data to be read can only be read after the data integrity is confirmed. Therefore, it is necessary to verify the integrity of the encrypted data to be read at the corresponding address based on the encryption integrity error correction tag to be read stored at the corresponding address during the writing process;

[0075] According to the data address addr to be read in the data read request, the encryption integrity error correction tag to be read and the encrypted data to be read stored in the data writing process are first read, and then integrity verification and error correction are performed, that is, step 2.

[0076] Of course, if unencrypted integrity error correction tags and data are stored during the writing process, then what is read during the reading process is the integrity error correction tags and data to be read.

[0077] Step 2: Using the address addr of the data to be read and the first decryption key, which is the same as the first encryption key used when writing the data, that is, the random number 2, a second key generation function is used to derive the first decryption key of the current encrypted integrity error correction tag to be read. SM4 can be used to decrypt the encrypted integrity error correction tag to be read in the integrity verification error correction bit corresponding to the address addr of the data to be read stored in memory 004 to obtain a first redundant integrity error correction tag.

[0078] It is easy to understand that when data is written, if only the address of the data to be written is used to derive the first key of the integrity error correction label to be written through the second key generation function, correspondingly, during the data reading process, only the address of the data to be read needs to be used to obtain the first decryption key through the second key generation function to decrypt the encrypted integrity error correction label to be read, so that the correct first redundant integrity error correction label can be obtained.

[0079] Step 3, the data address addr to be read and the read redundant initial value parameter, such as the write redundant initial value parameter used when writing data: random number 3, are calculated to obtain the read redundant initial value (initial value of 128-bit CRC);

[0080] According to the specific parameters used when the redundant coding operation module 002 performs the write redundant coding operation during the data writing process, the redundant coding operation module 012 needs to use the same calculation parameters when performing the read redundant coding operation during the data reading process. For example, when the write coding operation is directly performed on the data address to be written and the encrypted data to be written during the data writing process, the read coding operation can be directly performed using the data address to be read addr and the encrypted data to be read during the data reading process. If the data address to be written and the write redundant initial value parameters are used to obtain the write redundant initial value during the data writing process, and then the write redundant coding operation is performed on the encrypted data to be written, then when the data is read, the data address to be read and the read redundant initial value parameters need to be used to obtain the read redundant initial value, and then the read redundant coding operation is performed on the encrypted data to be read.

[0081] In step 4, the redundant coding operation module 012 (for performing the read redundant coding operation) uses the read redundant initial value and the redundant polynomial (i.e., the read redundant polynomial) calculated in step 3 to calculate a second redundant integrity error correction tag for the encrypted data to be read (ciphertext data) stored at the data address to be read addr.

[0082] During the data writing process, when only the encrypted data to be written and the address of the data to be written are used to perform the write redundant coding operation using the write redundant polynomial, during the data reading process, the corresponding read redundant coding operation needs to be performed using the address of the data to be read and the encrypted data to be read using the read redundant polynomial.

[0083] In step 5, the integrity verification and error correction module 013 performs integrity verification and error correction using the second redundant integrity error correction tag and the first redundant integrity error correction tag. When the two compare equal, the encrypted data to be read is determined to be intact and the data to be read is decrypted. When decrypting the data to be read, a second decryption key is generated using the second decryption parameter and the secure decryption parameter using the first key generation function. The secure decryption parameter is the same as the secure encryption parameter used during the data writing process, and the second encryption key corresponds to the second decryption key.

[0084] Of course, when only the security encryption parameters are used to encrypt the data to be written during the data writing process, during the data reading process, only the security decryption parameters are used to decrypt the encrypted data to be read. Or when only the second encryption parameters are used to encrypt the data to be written during the data writing process, during the data reading process, the corresponding second decryption parameters are also used to decrypt the encrypted data to be read, that is, to ensure that the encryption parameters and decryption parameters used when writing data and reading data are consistent.

[0085] If they are not equal, further judgment is performed. First, the error deviation of the encrypted data to be read data and the corresponding bit in the first redundant integrity error correction tag is obtained, and then the error deviation is judged. When the error deviation is greater than the error correction threshold, data abnormality information is obtained (notifying the processor that the encrypted data to be read at the current data address addr to be read is abnormal). When the error deviation is less than the error correction threshold, the redundant coding operation module 012 corrects the encrypted data to be read data to obtain the corrected encrypted data to be read, that is, data 1.

[0086] Step 6: Correct the encrypted data to be read data 1 and pass it through the data decryption module 010, such as the algorithm SM4 used when writing the data, to obtain the data to be read and send it to the processor.

[0087] Similarly, based on the type and number of encryption parameters used during the data writing process, corresponding decryption parameters are selected during data reading to correct the decryption of the encrypted data to be read. For example, if the encryption parameters used to encrypt the data to be written during data writing are the second encryption parameters or the secure decryption parameters, then the corresponding second decryption parameters or the secure decryption parameters will need to be used during data reading to correct the decryption of the encrypted data to be read. If the encryption parameters used to encrypt the data to be written during data writing are the second encryption parameters and the secure encryption parameters, then the corresponding second decryption parameters and the secure decryption parameters will need to be used during data reading to correct the decryption of the encrypted data to be read.

[0088] Below, for the convenience of understanding, further description is given in combination with the specific process of data reading and writing. To facilitate the description of the technical solution provided by the embodiment of the present application, the data writing method is first introduced. Please refer to Figure 5 , Figure 5 1 is a flow chart of a data writing method provided in an embodiment of the present application.

[0089] As shown in the figure, the data writing method provided in the embodiment of the present application may include the following steps:

[0090] Step S00: obtaining data to be written and a data address to be written corresponding to the data to be written.

[0091] The processor issues a data write request to write the data to be written into the address to be written of the memory. Therefore, when the data write request is received, the data to be written and the data address to be written corresponding to the data to be written can be obtained.

[0092] Step S01 , performing a write redundancy coding operation on the data address to be written and the data to be written using a write redundancy polynomial to obtain an integrity error correction tag to be written, wherein the integrity error correction tag to be written is used for integrity verification and data error correction.

[0093] It is easy to understand that the redundant polynomial refers to the coding formula used in redundant coding operations, which provides operators for redundant coding operations. It is randomly generated after the processor hardware is started and remains unchanged during the entire operation of the processor. Therefore, the redundant polynomial randomly generated by the processor is difficult to predict and remains unchanged during the operation process. In this way, the integrity error correction label to be written is not easy to be cracked and has high security.

[0094] The write redundancy polynomial can provide an error correction function. The integrity error correction tag obtained by performing a write redundancy coding operation based on the write redundancy polynomial can realize data correction when errors occur in the data to be written. The final integrity error correction tag used to implement integrity verification is calculated based on the write redundancy polynomial. The probability of conflict collision of the integrity error correction tag is extremely low, with a probability of approximately less than 1 / 100 million, and can be used as a verification code for integrity verification.

[0095] Since the write redundant coding operation is usually a linear block code, when the data to be written is the same, the integrity error correction tags generated will be the same, which is easy to be cracked and attacked, and has low security. Therefore, in order to improve the security of the integrity error correction tag, in one embodiment, the data writing method provided in the embodiment of the present application may further include:

[0096] Get the write redundancy initial value parameter;

[0097] The step of performing a write redundancy coding operation on the address of the data to be written and the data to be written using a write redundancy polynomial to obtain an integrity error correction tag to be written comprises:

[0098] Obtaining a write redundancy initial value according to the write redundancy initial value parameter and the address of the data to be written;

[0099] A write redundancy coding operation is performed on the data to be written using a write redundancy polynomial and the write redundancy initial value to obtain the integrity error correction label to be written.

[0100] The write redundant initial value parameter can be a random number generated once by the processor hardware after the processor is started. Its content cannot be obtained from the outside and remains unchanged during the entire processor operation process. It is not easy to be obtained and destroyed by the outside world and has high security. Therefore, using the write redundant initial value parameter and the address of the data to be written to obtain the redundant initial value can further enhance the security of the integrity error correction tag to be written.

[0101] Step S02: writing the data to be written and the integrity error correction tag to be written into the memory.

[0102] It can be seen that the technical solution provided in the embodiment of the present application first uses a write redundant polynomial to perform a write redundant coding operation on the data to be written and the data address to be written corresponding to the data to be written, to obtain an integrity error correction tag to be written, and then writes the integrity error correction tag to be written and the data to be written into the memory. The integrity error correction tag to be written can not only realize error correction of the data to be written when an error occurs in the data to be written, but also realize integrity verification of the data to be written corresponding to the data address to be written. There is no need to set up an additional tag for integrity verification, so the storage space of the error correction tag used for error correction will not be occupied, thereby ensuring the error correction performance. Therefore, the integrity protection function of the memory data can be improved without affecting the error correction performance of the data and ensuring the error correction capability.

[0103] In order to further enhance the security of the integrity error correction tag to be written, in one embodiment, the integrity error correction tag to be written can also be encrypted. For details, please refer to Figure 6 , Figure 6 This is another flowchart of the data writing method provided in an embodiment of the present application.

[0104] As shown in the figure, the process may include the following steps:

[0105] Step S10: obtaining data to be written and a data address to be written corresponding to the data to be written.

[0106] The content of step S10 can refer to the content of step S00 and will not be repeated here.

[0107] Step S11 , performing a write redundancy coding operation on the data address to be written and the data to be written using a write redundancy polynomial to obtain an integrity error correction tag to be written.

[0108] The content of step S11 can refer to step S01 and will not be repeated here.

[0109] Step S12: encrypt the integrity error correction tag to be written to obtain an encrypted integrity error correction tag to be written.

[0110] By encrypting the integrity error correction tag to be written, the protection of the integrity error correction tag to be written is increased, external attacks can be prevented, and the security of the integrity error correction tag to be written can be protected, thereby ensuring the accuracy of the integrity verification result when performing integrity verification and error correction.

[0111] In one embodiment, the step of encrypting the integrity error correction tag to be written to obtain the encrypted integrity error correction tag to be written may include:

[0112] Obtaining a first encryption key according to the address of the data to be written;

[0113] The integrity error correction label to be written is encrypted using the first encryption key to obtain the encrypted integrity error correction label to be written.

[0114] Among them, the first encryption key obtained according to the address of the data to be written can be obtained by the first key generation function KDF mentioned above. Of course, it can also be obtained according to other key generation methods. By using the first encryption key to encrypt the integrity error correction label to be written, the ability of the integrity error correction label to be written to resist external attacks is increased, and the security of the integrity error correction label to be written is improved.

[0115] In order to further enhance the self-defense performance of the integrity error correction tag to be written, in one embodiment, multiple parameters may be used to obtain the first encryption key. Specifically, the step of obtaining the first encryption key may further include:

[0116] Obtaining a first encryption parameter;

[0117] The step of obtaining a first encryption key according to the address of the data to be written comprises:

[0118] The first encryption key is obtained according to the first encryption parameter and the address of the data to be written.

[0119] The first encryption parameter can be a random number generated by the processor hardware when the aforementioned processor is started, so that the first encryption parameter is unpredictable and cannot be obtained by the outside world, further enhancing the security of the integrity error correction tag to be written.

[0120] Of course, in other implementations, other parameters that can increase the security of the integrity error correction tag to be written may also be used.

[0121] Step S13: writing the data to be written and the encryption integrity error correction tag to be written into the memory.

[0122] By encrypting the integrity error correction tag to be written, the integrity error correction tag to be written is not easily cracked, which can ensure the security of the integrity error correction tag to be written, making subsequent verification of data integrity and error correction more reliable.

[0123] Of course, in other implementations, the data to be written may be processed to improve the security of the data to be written, thereby improving the security of the integrity error correction tag to be written subsequently obtained based on the data to be written. Specifically, the data writing method provided in the embodiment of the present application may further include:

[0124] The data to be written is encrypted to obtain encrypted data to be written.

[0125] It is easy to understand that the security of the data to be written can be guaranteed through encryption processing.

[0126] In a specific embodiment, the step of encrypting the data to be written to obtain the encrypted data to be written includes:

[0127] obtaining a second encryption key based on security encryption parameters obtained by a security processor;

[0128] The data to be written is encrypted using the second encryption key to obtain the encrypted data to be written.

[0129] The security processor sets security encryption parameters for generating security encryption keys, which can ensure the security of the data to be written.

[0130] Of course, in a specific embodiment, the first encryption key can be directly a security encryption parameter.

[0131] In another specific embodiment, in order to further ensure the confidentiality of the second encryption key and improve the security protection of the data to be written, in one embodiment, the step of encrypting the data to be written to obtain the encrypted data to be written may further include:

[0132] Obtaining a second encryption parameter;

[0133] The step of obtaining the second encryption key comprises:

[0134] Obtaining the second encryption key according to the second encryption parameter and the security encryption parameter;

[0135] The data to be written is encrypted using the second encryption key to obtain the encrypted data to be written.

[0136] Among them, the second encryption parameter can be a random number generated when the CPU central processing unit is started. It is generated once by the processor hardware after the processor is started, and its content is removed externally. It remains unchanged during the entire working process of the processor and is random. Therefore, it can defend against external attacks and improve the defense capability of the data to be written. Then, based on the second encryption parameter and the security encryption parameter, a second encryption key is obtained to improve the security of the data to be written.

[0137] Of course, the second encryption parameter may also be other parameters as long as it can enhance the security of the second encryption key obtained using only the secure encryption parameter.

[0138] After obtaining the encrypted data to be written, the encrypted data to be written and the integrity error correction tag to be written are further written into the memory.

[0139] In this way, a piece of data to be written will have a corresponding integrity and error correction tag to be written for integrity verification and data error correction functions, which can realize integrity verification and data error correction for each piece of data to be written stored in the memory, thereby improving data security. Moreover, each piece of data to be written stored in the memory is encrypted data to be written obtained through encryption processing, further ensuring the security of the data to be written. While improving the security of the data to be written, it can also increase the functions of integrity verification and error correction of the data to be written.

[0140] In order to ensure the security of the data to be written while enhancing the security of the integrity error correction tag to be written, in other implementations, the encryption processing of the data to be written and the encryption processing of the integrity error correction tag to be written may be combined. Specifically, the data writing method provided in the embodiment of the present application may further include:

[0141] First, the data to be written and the data address to be written corresponding to the data to be written are obtained.

[0142] Then, in order to improve the security of the data to be written, the data to be written may be encrypted to obtain encrypted data to be written.

[0143] Of course, when encrypting the data to be written, the second encryption key can be obtained by adopting a single parameter or a multi-parameter method. For example, when the second encryption key is obtained by adopting a single parameter method, it can be:

[0144] obtaining a second encryption key based on security encryption parameters obtained by a security processor;

[0145] The data to be written is encrypted using the second encryption key to obtain the encrypted data to be written.

[0146] The second encryption key is obtained by using the secure encryption parameter to improve the security of the data to be written. In another specific embodiment, in order to prevent it from being damaged by the outside world, the second encryption key can be obtained by adding multiple parameters, specifically:

[0147] A second encryption parameter and a security encryption parameter are obtained, and the second encryption key is obtained according to the second encryption parameter and the security encryption parameter.

[0148] Since the second encryption parameter can be a parameter that is not easily obtained by the outside world and has its own special characteristics, such as the random number generated once when the processor starts as mentioned above, the security of the data to be written can be further improved by adding additional encryption parameters that are not easy to crack in combination with secure encryption parameters.

[0149] After obtaining the encrypted data to be written, the encrypted data to be written and the address of the data to be written are further combined to perform a write redundancy coding operation using a write redundancy polynomial to obtain an integrity error correction tag to be written.

[0150] Of course, in order to increase the security of the write redundant coding operation, a write redundant initial value parameter that can improve the prevention performance of the redundant coding operation can also be used, thereby obtaining a write redundant initial value based on the address of the data to be written and the write redundant initial value parameter, and further combining the encrypted data to be written to obtain the integrity error correction label to be written.

[0151] Next, in order to improve the security of the integrity error correction tag to be written, the integrity error correction tag to be written may be encrypted to obtain an encrypted integrity error correction tag to be written.

[0152] The specific encryption method of the integrity error correction label to be written can refer to the aforementioned embodiment. Of course, other types of first encryption parameters can be replaced or the number of key generation parameters for obtaining the first encryption key can be increased, that is, the number of first encryption parameters used can be increased.

[0153] Finally, the encrypted data to be written and the encrypted integrity error correction tag to be written are written into the memory.

[0154] In this way, by simultaneously adopting an encryption processing method for the data to be written and the integrity error correction tag to be written, the security of the data to be written and the security of the integrity error correction tag to be written can be achieved at the same time, so that the integrity verification of the data to be written corresponding to the address of the data to be written and the error correction of the data to be written when an error occurs in the data to be written can be achieved based on the encrypted integrity error correction tag to be written. The security protection, integrity verification and error correction of the data to be written can be achieved by utilizing the data to be written and the address of the data to be written. Therefore, the integrity protection function of the memory data and the security of the data to be written can be improved without affecting the error correction performance of the data and ensuring the error correction capability.

[0155] After the data to be written and the corresponding integrity error correction tag to be written are written into the memory, when the processor issues a data read request, the integrity error correction tag to be written can be used to verify the integrity of the data to be written and perform data error correction, thereby obtaining the correct data to be read, that is, the original complete data to be written stored in the memory during the data writing process.

[0156] For ease of understanding, the following is an explanation of data reading, please refer to Figure 7 , Figure 7 1 is a flow chart of a data reading method provided in an embodiment of the present application.

[0157] As shown in the figure, the process may include the following steps:

[0158] Step S20 , obtaining the data to be read stored at the data address to be read and the integrity error correction tag to be read corresponding to the data to be read.

[0159] The data address to be read includes the data address to be written in the data writing method as described in any of the aforementioned embodiments, and the integrity error correction tag to be read includes the integrity error correction tag to be written in the data writing method as described in any of the aforementioned embodiments.

[0160] It is easy to understand that in other embodiments, when data is written, what is written is the encrypted data to be written and the encrypted integrity error correction tag to be written, and when data is read, what is obtained is the corresponding encrypted data to be read and the encrypted integrity error correction tag to be read.

[0161] When data is written, encrypted data to be written and integrity error correction tag to be written are written. Accordingly, when data is read, encrypted data to be read and integrity error correction tag to be read are obtained.

[0162] When data is written, what is written is the data to be written and the encryption integrity error correction tag to be written. Correspondingly, when data is read, what is obtained is the data to be read and the encryption integrity error correction tag to be read.

[0163] That is, the data read from a certain data address and the data stored in a certain data address in the memory correspond to each other. Therefore, the integrity error correction tag of the corresponding data to be read or the encrypted integrity error correction tag to be read pre-written in the memory can be used to verify the integrity of the data and correct the errors before reading the correct data.

[0164] Step S21 : obtaining a first redundant integrity error correction tag according to the integrity error correction tag to be read.

[0165] Corresponding to the implementation process when writing data, data integrity verification and error correction are required when reading data.

[0166] When the data is written into the integrity error correction tag to be written during the data writing process, the integrity error correction tag to be read is obtained during the reading process.

[0167] Of course, in another specific implementation, when the data is written during the writing process, the encrypted integrity error correction tag to be written is obtained during reading. At this time, the encrypted integrity error correction tag to be read needs to be decrypted before the integrity of the data is verified.

[0168] Therefore, the steps of the data reading method provided in the embodiment of the present application may further include:

[0169] The encrypted integrity error correction label to be read is decrypted to obtain a first redundant integrity error correction label.

[0170] According to the steps during data writing, it can be known that data information suitable for integrity verification, ie, the first redundant integrity error correction tag, can be obtained only after the encrypted integrity error correction tag to be read is decrypted.

[0171] In order to enable the first redundant integrity error correction tag obtained by decryption to serve as the basis for data integrity verification and error correction, the parameters required for decryption must be the same as the encryption parameters used in the aforementioned data writing method.

[0172] Specifically, the step of decrypting the encrypted integrity error correction label to be read to obtain the first redundant integrity error correction label may include:

[0173] Obtaining a first decryption key using the address of the data to be read, where the first decryption key corresponds to a first encryption key, and the first encryption key is used to encrypt the integrity error correction tag when writing data to obtain the encrypted integrity error correction tag to be written;

[0174] The encrypted integrity error correction label to be read is decrypted using the first decryption key to obtain the first redundant integrity error correction label.

[0175] Since the first encryption key used in the data writing process is obtained based on the address of the data to be written, in order to ensure the implementation of data integrity verification when reading data, similarly, when decrypting the encryption integrity error correction tag to be read, the decryption key used also needs to use the address of the data to be read corresponding to the address of the data to be written in the data writing method to obtain the first decryption key.

[0176] Of course, when dual parameters (i.e., the first encryption parameter and the address of the data to be written) are used for encryption in order to further improve the security of the integrity error correction tag during encryption during the data writing process, the corresponding dual parameters are also required to obtain the decryption key during the data reading process, so as to successfully complete the decryption of the encrypted data to be read.

[0177] Specifically, the process of decrypting the encrypted data to be read may further include:

[0178] Obtaining a first decryption parameter, where the first decryption parameter corresponds to a first encryption parameter, and the first encryption parameter is used to obtain the first encryption key when writing data;

[0179] The step of obtaining a first decryption key by using the address of the data to be read comprises:

[0180] A first decryption key is obtained using the first decryption parameter and the address of the data to be read.

[0181] In this way, a correspondence can be formed with the key generation parameters used for security protection during the data writing process, and a decryption key suitable for the type of encrypted integrity error correction tag to be read can be obtained.

[0182] Step S22 : performing a read redundancy coding operation on the to-be-read data and the to-be-read data address using a read redundancy polynomial to obtain a second redundant integrity error correction tag.

[0183] The read redundancy polynomial corresponds to the write redundancy polynomial in any of the aforementioned data writing methods, thereby ensuring that the obtained second redundant integrity error correction label can be applied to the integrity verification and error correction of data in the same data address when data is written and when data is read.

[0184] Of course, when the data to be written is the data to be written during the data writing process, the data obtained by reading is the data to be read. At this time, when obtaining the second redundant integrity error correction label, it is necessary to use the data to be encrypted; and when the data to be written is the encrypted data to be written during the data writing process, the data obtained by reading is the encrypted data to be read. At this time, when obtaining the second redundant integrity error correction label, it is necessary to use the encrypted data to be read.

[0185] To this end, specifically, the data reading method provided in the embodiment of the present application may further include:

[0186] A read redundancy coding operation is performed on the encrypted data to be read and the data address to be read using a read redundancy polynomial to obtain a second redundant integrity error correction label.

[0187] The encrypted data to be read and the encrypted data to be written are in a corresponding relationship. According to the data writing process, when verifying whether the data is complete, the encrypted data to be read needs to be used as the generation parameter of the second redundant integrity error correction tag. In this way, the accuracy of the final data integrity can be ensured.

[0188] In order to ensure data security, when other parameters for protecting data security are added to perform write redundant coding operations when writing data, the same parameters need to be used to complete the read redundant coding operations during the corresponding data reading process.

[0189] Specifically, the data reading method may further include:

[0190] Get the read redundant initial value parameters;

[0191] The step of performing a read redundant coding operation on the to-be-read data and the to-be-read data address using a read redundant polynomial to obtain a second redundant integrity error correction label comprises:

[0192] Obtaining a read redundancy initial value according to the read redundancy initial value parameter and the address of the data to be read;

[0193] A read redundancy coding operation is performed on the data to be read using the read redundancy polynomial and the redundancy initial value to obtain the second redundant integrity error correction label.

[0194] The read redundancy initial value is the same as the write redundancy initial value in the aforementioned data writing method, and the corresponding read redundancy coding operation is also the same as the write redundancy coding operation, so that the corresponding second redundant integrity error correction label can be obtained to ensure the reliability of data integrity verification.

[0195] It is easy to understand that when the data to be read is encrypted data to be read, the encrypted data to be read also needs to be used in the process of performing the redundant coding operation using the redundant initial value parameter. Specifically, the step of obtaining the second redundant integrity error correction label may further include:

[0196] A read redundancy coding operation is performed on the encrypted data to be read using the read redundancy polynomial and the redundancy initial value to obtain the second redundant integrity error correction label.

[0197] In this way, equivalent data can be obtained by using corresponding redundant coding operation parameters, ensuring the accuracy of data integrity verification.

[0198] Step S23: Determine whether the first redundant integrity error correction tag is equal to the second redundant integrity error correction tag. If yes, execute step S27; otherwise, execute step S24.

[0199] When the first redundant integrity error correction tag is not equal to the second redundant integrity error correction tag, it means that an error occurs in reading the data after the redundant coding operation, that is, the second redundant integrity error correction tag. At this time, the second redundant integrity error correction tag needs to be corrected.

[0200] For details, please continue to refer to Figure 7 .

[0201] As shown in the figure, the process may also include the following steps:

[0202] Step S24: Obtain error deviations of the first redundant integrity error correction label and the second redundant integrity error correction label.

[0203] The error deviation may include the number of errors occurring on corresponding bits between the original data to be read and the decrypted data obtained after decryption, ie, the second redundant integrity error correction tag.

[0204] In one embodiment, the error deviation may include a Hamming distance.

[0205] In this way, the Hamming distance can determine the error deviation more accurately, ensure the accuracy of the judgment, and can quickly correct the data corresponding to the error bit to obtain the correct data to be read.

[0206] Step S25: Determine whether the error deviation is greater than the error correction threshold. If not, proceed to step S26; if yes, proceed to step S28.

[0207] Step S26 , performing data error correction on the data to be read and the first redundant integrity error correction tag using the read redundant coding operation to obtain corrected data to be read.

[0208] That is, the bit where the data error occurs in the above-mentioned data to be read is flipped and adjusted. For example, the original data is 1 at this bit, but an error occurs in the data of this bit during the writing process or due to a hardware problem in the memory, and it is flipped from 1 to 0. At this time, the error of this bit is flipped from 0 to 1 through redundant coding operation. In this way, the data error correction of this bit can be realized until the correction of all the bits with data flipping is completed, and the correct data to be read is obtained, that is, the corrected data to be read.

[0209] When the data to be read is encrypted data to be read, it is necessary to perform data error correction on the encrypted data to be read and the first redundant integrity error correction tag using the read redundant coding operation to obtain corrected encrypted data to be read.

[0210] Thus, corresponding correction data is obtained according to the actual data written during the data writing process.

[0211] When it is determined that the first redundant integrity error correction tag is equal to the second redundant integrity error correction tag, or after data correction is performed by reading the redundant coding operation, it is determined that the data to be read is complete, and the next step, that is, step S27, can be performed.

[0212] Step S27: sending the confirmed complete data to be read.

[0213] When the error deviation is greater than the error correction threshold, it means that the data exceeds the error correction range of the redundant coding operation and the error correction function cannot be realized. Therefore, a data abnormality information is sent to the external device, that is, step S28, to prompt the computer system that an error has occurred in the data stored at the data address, and external auxiliary correction is performed, so that erroneous data information will not be read, which will destroy the overall computer data operation and protect the security of the computer data.

[0214] Step S28: Send data abnormality information.

[0215] Since the write redundant coding operation and the read redundant coding operation are corresponding linear coding operations, the input address is the same address, and the integrity error correction tag to be read and the integrity error correction tag to be written are also the same. Therefore, the first redundant integrity error correction tag obtained can be used to verify the integrity of the data to be read and perform data error correction.

[0216] When the data to be read is encrypted data to be read, after integrity verification and error correction are performed on the encrypted data to be read, the corrected encrypted data to be read needs to be decrypted, and the correct decrypted data to be read is sent after the decrypted data to be read is obtained.

[0217] Specifically, the data reading method may further include:

[0218] Decrypting the encrypted data to be read to obtain decrypted data to be read;

[0219] The decrypted data to be read that is confirmed to be complete is sent.

[0220] After determining the integrity of the data based on the first redundant integrity error correction tag and the second redundant integrity error correction tag and completing the decryption of the encrypted data to be read, the data to be read is sent. That is, the data to be read is now safe and correct and can be sent to the processor.

[0221] According to the specific data written when writing data, corresponding operations are performed. When writing data, the encrypted data to be written is written. When reading data, the data integrity verification is the verification of the integrity of the encrypted data to be read, so that the correct verification result can be obtained.

[0222] Specifically, the step of decrypting the encrypted data to be read to obtain the decrypted data to be read includes:

[0223] Obtaining a security decryption parameter, the security decryption parameter corresponding to the security encryption parameter, the security encryption parameter being obtained by the security processor and used to obtain a second encryption key for encrypting the data to be written when writing data;

[0224] Obtaining a second decryption key according to the security decryption parameter;

[0225] The encrypted data to be read is decrypted using the second decryption key to obtain the decrypted data to be read.

[0226] In this way, according to the encryption parameters of the data to be written (the second encryption parameters) used in the data writing process, the same data decryption parameters (the second decryption parameters) are used correspondingly when reading the data, and a second key suitable for decrypting the encrypted data to be read is obtained, ensuring that the decryption of the encrypted data to be read corresponds to the encryption of the data to be written, thereby ensuring the smooth progress of subsequent data integrity verification.

[0227] Of course, when data is written, two parameters (security encryption parameter and second encryption parameter) are used to encrypt the data to be written. Similarly, when the data is read, two parameters are required to obtain the second decryption key.

[0228] Specifically, the step of decrypting the encrypted data to be read may further include:

[0229] Obtaining a second decryption parameter, where the second decryption parameter corresponds to a second encryption parameter, and the second encryption parameter is used to obtain the second encryption key when writing data;

[0230] The step of obtaining a second decryption key according to the security decryption parameter comprises:

[0231] Obtaining a second decryption key according to the second decryption parameter and the security decryption parameter;

[0232] The encrypted data to be read is decrypted using the second decryption key to obtain the decrypted data to be read.

[0233] According to the encryption parameters (second encryption parameter and security encryption parameter) specifically used when encrypting the data to be written during the data writing process, the corresponding second decryption parameters and security decryption parameters are selected for use when reading the data. In this way, the obtained second decryption key can be a key suitable for decrypting the encrypted data to be read stored in the memory.

[0234] Of course, when data is written, if multiple encryption parameters are used to encrypt the data to be written, similarly, the same number of decryption parameters need to be used to decrypt the data when it is read.

[0235] It can be seen that the technical solution provided in the embodiment of the present application obtains the data to be read and the integrity error correction tag to be read according to the address of the data to be read to be read. First, a first redundant integrity error correction tag is obtained based on the integrity error correction tag to be read, which is used to subsequently verify the integrity of the data to be read and perform error correction on the data to be read when an error occurs in the verification. Then, a read redundant coding operation is further performed on the data to be read and the address of the data to be read using a read redundant polynomial to obtain a second redundant integrity error correction tag. The integrity of the data to be read is determined by comparing the first redundant integrity error correction tag with the second redundant integrity error correction tag. When it is determined that the data to be read is complete, decryption is performed to obtain the data to be read, and the data to be read is sent. The address of the data to be read corresponds to the address of the data to be written during the data writing process. Therefore, the data to be read obtained according to the address of the data to be read is the data to be written during writing, and the integrity error correction tag to be read is the integrity error correction tag to be written corresponding to the data during writing. Therefore, the integrity error correction tag to be read can be used to implement integrity verification and data error correction of the data to be read. Moreover, since the read redundancy polynomial used is the same as the write polynomial used when writing the data, the second redundant integrity error correction tag obtained is the data to be written used when writing the data. Therefore, the data integrity can be verified together with the first redundant integrity error correction tag to implement integrity verification of the data to be read and error correction of the data to be read. This can improve the integrity protection function of the memory data without affecting the error correction performance of the data and ensuring the error correction capability.

[0236] To address the aforementioned issues, the present invention further provides a data writing device, which can be considered as a functional module required to implement the data writing method provided in the present invention. The device described below can be used in conjunction with the data writing method described above.

[0237] Please refer to Figure 8 , Figure 8 Schematic diagram of a data writing device provided in an embodiment of the present application.

[0238] As shown in the figure, the data writing device may include:

[0239] A write acquisition module 300 is adapted to acquire data to be written and a data address to be written corresponding to the data to be written;

[0240] A write redundant coding operation module 301 is adapted to perform a write redundant coding operation on the address of the data to be written and the data to be written using a write redundant polynomial to obtain an integrity error correction tag to be written, wherein the integrity error correction tag to be written is used for integrity verification and data error correction;

[0241] The writing module 302 is adapted to write the data to be written and the integrity error correction tag to be written into the memory.

[0242] In some embodiments, the data writing device may further include:

[0243] A write redundancy parameter acquisition module, adapted to acquire write redundancy initial value parameters;

[0244] The write redundant coding operation module 301 is adapted to perform write redundant coding on the address of the data to be written and the data to be written using a write redundant polynomial to obtain an integrity error correction tag to be written, including:

[0245] Obtaining a write redundancy initial value according to the write redundancy initial value parameter and the address of the data to be written;

[0246] A write redundancy coding operation is performed on the data to be written using a write redundancy polynomial and the write redundancy initial value to obtain the integrity error correction label to be written.

[0247] In some embodiments, the data writing device may further include:

[0248] an integrity error correction tag encryption module, adapted to encrypt the integrity error correction tag to be written to obtain an encrypted integrity error correction tag to be written;

[0249] The writing module 302 is adapted to write the data to be written and the integrity error correction tag to be written into the memory, and includes:

[0250] The data to be written and the encryption integrity error correction tag to be written are written into the memory.

[0251] In one embodiment, the integrity error correction tag encryption module is adapted to encrypt the integrity error correction tag to be written to obtain the encrypted integrity error correction tag to be written, including:

[0252] Obtaining a first encryption key according to the address of the data to be written;

[0253] The integrity error correction label to be written is encrypted using the first encryption key to obtain the encrypted integrity error correction label to be written.

[0254] In some embodiments, the data writing device may further include:

[0255] A first encryption parameter acquisition module, adapted to acquire a first encryption parameter;

[0256] The integrity error correction tag encryption module is adapted to obtain a first encryption key according to the address of the data to be written, including:

[0257] The first encryption key is obtained according to the first encryption parameter and the address of the data to be written.

[0258] In some embodiments, the data writing device may further include:

[0259] A data encryption module, adapted to encrypt the data to be written to obtain encrypted data to be written;

[0260] The writing module is adapted to write the data to be written and the integrity error correction tag to be written into the memory, and includes:

[0261] The encrypted data to be written and the integrity error correction tag to be written are written into the memory.

[0262] In one embodiment, the data encryption module is adapted to encrypt the data to be written to obtain the encrypted data to be written, including:

[0263] obtaining a second encryption key based on security encryption parameters obtained by a security processor;

[0264] The data to be written is encrypted using the second encryption key to obtain the encrypted data to be written.

[0265] In some embodiments, the data writing device may further include:

[0266] A second encryption parameter acquisition module, adapted to acquire a second encryption parameter;

[0267] The data encryption module is adapted to obtain the second encryption key, comprising:

[0268] The second encryption key is obtained according to the second encryption parameter and the security encryption parameter.

[0269] It can be seen that the technical solution provided in the embodiment of the present application first uses a write redundant polynomial to perform a write redundant coding operation on the data to be written and the data address to be written corresponding to the data to be written, to obtain an integrity error correction tag to be written, and then writes the integrity error correction tag to be written and the data to be written into the memory. The integrity error correction tag to be written can not only realize error correction of the data to be written when an error occurs in the data to be written, but also realize integrity verification of the data to be written corresponding to the data address to be written. There is no need to set up an additional tag for integrity verification, so the storage space of the error correction tag used for error correction will not be occupied, thereby ensuring the error correction performance. Therefore, the integrity protection function of the memory data can be improved without affecting the error correction performance of the data and ensuring the error correction capability.

[0270] To address the aforementioned issues, the present invention further provides a data reading device, which can be considered as a functional module required to implement the data reading method provided in the present invention. The device described below can be referenced in conjunction with the data reading method described above.

[0271] Please refer to Figure 9 , Figure 9 It is a structural diagram of a data reading device provided in an embodiment of the present application.

[0272] As shown in the figure, the data reading device may include:

[0273] The read acquisition module 400 is adapted to acquire data to be read stored at a data address to be read and an integrity error correction tag to be read corresponding to the data to be read, wherein the data address to be read includes the data address to be written in the data writing device as described in the aforementioned embodiment, and the integrity error correction tag to be read includes the integrity error correction tag to be written in the data writing device as described in the aforementioned embodiment, and the integrity error correction tag to be read is used to perform integrity verification and data error correction on the data to be read;

[0274] A first redundant integrity error correction tag acquisition module 401 is adapted to acquire a first redundant integrity error correction tag according to the integrity error correction tag to be read;

[0275] a read redundant coding operation module 402 adapted to perform a read redundant coding operation on the to-be-read data and the to-be-read data address using a read redundant polynomial to obtain a second redundant integrity error correction tag, wherein the read redundant polynomial corresponds to the write redundant polynomial in the data writing device described in any one of the preceding embodiments;

[0276] an integrity determination module 403, adapted to determine that the to-be-read data is complete when the first redundant integrity error correction tag is equal to the second redundant integrity error correction tag;

[0277] The sending module 404 is adapted to send the confirmed complete data to be read.

[0278] In one embodiment, the data reading device may further include:

[0279] a data error correction module 405 adapted to obtain an error deviation between the first redundant integrity error correction label and the second redundant integrity error correction label when the first redundant integrity error correction label is not equal to the second redundant integrity error correction label;

[0280] When the error deviation is not greater than the error correction threshold, performing data error correction on the data to be read and the first redundant integrity error correction tag by using the read redundant coding operation to obtain corrected data to be read;

[0281] The sending module 404 is adapted to send the confirmed complete data to be read, including:

[0282] The corrected data to be read is sent.

[0283] In one embodiment, the data reading device may further include:

[0284] The data error reporting module 406 is adapted to issue data anomaly information when the error deviation is greater than the error correction threshold.

[0285] In one embodiment, the error deviation comprises a Hamming distance.

[0286] In one embodiment, the data reading device further includes:

[0287] A redundant parameter acquisition module is used to acquire redundant initial value parameters;

[0288] The read redundant coding operation module is adapted to perform a read redundant coding operation on the to-be-read data and the to-be-read data address using a read redundant polynomial to obtain a second redundant integrity error correction label, including:

[0289] Obtaining a read redundancy initial value according to the read redundancy initial value parameter and the address of the data to be read;

[0290] A read redundancy encoding operation is performed on the data to be read using the read redundancy polynomial and the read redundancy initial value to obtain the second redundant integrity error correction label.

[0291] In one embodiment, the integrity error correction tag to be read includes an encrypted integrity error correction tag to be read, and the first redundant integrity error correction tag acquisition module is adapted to acquire the first redundant integrity error correction tag according to the integrity error correction tag to be read, including:

[0292] The encrypted integrity error correction label to be read is decrypted to obtain a first redundant integrity error correction label.

[0293] In one embodiment, the first redundant integrity error correction label acquisition module is adapted to decrypt the encrypted integrity error correction label to be read to obtain the first redundant integrity error correction label, including:

[0294] Obtaining a first decryption key using the address of the data to be read, where the first decryption key corresponds to a first encryption key, and the first encryption key is used to encrypt the integrity error correction tag when writing data to obtain the encrypted integrity error correction tag to be written;

[0295] The encrypted integrity error correction label to be read is decrypted using the first decryption key to obtain the first redundant integrity error correction label.

[0296] In one embodiment, the data reading device may further include:

[0297] a first decryption parameter acquisition module, adapted to acquire a first decryption parameter, the first decryption parameter corresponding to a first encryption parameter, the first encryption parameter being used to acquire the first encryption key when writing data;

[0298] The first redundant integrity error correction tag acquisition module is adapted to obtain a first decryption key using the address of the data to be read, and includes:

[0299] A first decryption key is obtained using the first decryption parameter and the address of the data to be read.

[0300] In one embodiment, the data to be read includes encrypted data to be read, and the sending module is adapted to further include:

[0301] A data decryption module, adapted to decrypt the encrypted data to be read to obtain the decrypted data to be read;

[0302] The sending module is adapted to send the confirmed complete data to be read, and includes:

[0303] The decrypted data to be read that is confirmed to be complete is sent.

[0304] In one embodiment, the data decryption module is adapted to decrypt the encrypted data to be read to obtain the decrypted data to be read, including:

[0305] Obtaining a security decryption parameter, the security decryption parameter corresponding to the security encryption parameter, the security encryption parameter being obtained by the security processor and used to obtain a second encryption key for encrypting the data to be written when writing data;

[0306] Obtaining a second decryption key according to the security decryption parameter;

[0307] The encrypted data to be read is decrypted using the second decryption key to obtain the decrypted data to be read.

[0308] In one embodiment, the data reading device may further include:

[0309] a second decryption parameter acquisition module, adapted to acquire a second decryption parameter, the second decryption parameter corresponding to a second encryption parameter, the second encryption parameter being used to acquire the second encryption key when writing data;

[0310] The data decryption module is adapted to obtain a second decryption key according to the security decryption parameter, comprising:

[0311] Obtaining a second decryption key according to the second decryption parameter and the security decryption parameter;

[0312] The encrypted data to be read is decrypted using the second decryption key to obtain the decrypted data to be read.

[0313] It can be seen that the technical solution provided in the embodiment of the present application obtains the data to be read and the integrity error correction tag to be read according to the address of the data to be read to be read. First, a first redundant integrity error correction tag is obtained based on the integrity error correction tag to be read, which is used to subsequently verify the integrity of the data to be read and perform error correction on the data to be read when an error occurs in the verification. Then, a read redundant coding operation is further performed on the data to be read and the address of the data to be read using a read redundant polynomial to obtain a second redundant integrity error correction tag. The integrity of the data to be read is determined by comparing the first redundant integrity error correction tag with the second redundant integrity error correction tag. When it is determined that the data to be read is complete, decryption is performed to obtain the data to be read, and the data to be read is sent. The address of the data to be read corresponds to the address of the data to be written during the data writing process. Therefore, the data to be read obtained according to the address of the data to be read is the data to be written during writing, and the integrity error correction tag to be read is the integrity error correction tag to be written corresponding to the data during writing. Therefore, the integrity error correction tag to be read can be used to implement integrity verification and data error correction of the data to be read. Moreover, since the read redundancy polynomial used is the same as the write polynomial used when writing the data, the second redundant integrity error correction tag obtained is the data to be written used when writing the data. Therefore, the data integrity can be verified together with the first redundant integrity error correction tag to implement integrity verification of the data to be read and error correction of the data to be read. This can improve the integrity protection function of the memory data without affecting the error correction performance of the data and ensuring the error correction capability.

[0314] An embodiment of the present application further provides a storage medium storing a program suitable for data writing and data reading, so as to implement the data writing method described in any one of the aforementioned embodiments or the data reading method described in any one of the aforementioned embodiments.

[0315] An embodiment of the present application also provides an electronic device, comprising at least one memory and at least one processor, wherein the memory stores a data writing program, and the processor calls the program to execute the data writing method described in any one of the aforementioned embodiments or the data reading method described in any one of the aforementioned embodiments.

[0316] Although the embodiments of the present application are disclosed above, the present application is not limited thereto. Any person skilled in the art may make various changes and modifications without departing from the spirit and scope of the present application. Therefore, the scope of protection of the present application shall be based on the scope defined by the claims.

Claims

1. A data writing method, characterized in that: include: Acquire data to be written and a data address to be written corresponding to the data to be written; performing a write redundancy coding operation on the data address to be written and the data to be written using a write redundancy polynomial to obtain an integrity error correction tag to be written, wherein the integrity error correction tag to be written is used for integrity verification and data error correction; the write redundancy polynomial is randomly generated after the processor hardware is started and remains unchanged throughout the entire operation of the processor, and the write redundancy polynomial provides an error correction function; The data to be written and the integrity error correction tag to be written are written into the memory.

2. The data writing method according to claim 1, wherein: Also includes: Get the write redundancy initial value parameter; The step of performing a write redundancy coding operation on the address of the data to be written and the data to be written using a write redundancy polynomial to obtain an integrity error correction tag to be written comprises: Obtaining a write redundancy initial value according to the write redundancy initial value parameter and the address of the data to be written; A write redundancy coding operation is performed on the data to be written using a write redundancy polynomial and the write redundancy initial value to obtain the integrity error correction label to be written.

3. The data writing method according to claim 1, wherein: Also includes: Encrypting the integrity error correction tag to be written to obtain an encrypted integrity error correction tag to be written; The step of writing the data to be written and the integrity error correction tag to be written into the memory includes: The data to be written and the encryption integrity error correction tag to be written are written into the memory.

4. The data writing method according to claim 3, wherein: The step of encrypting the integrity error correction tag to be written to obtain the encrypted integrity error correction tag to be written comprises: Obtaining a first encryption key according to the address of the data to be written; The integrity error correction label to be written is encrypted using the first encryption key to obtain the encrypted integrity error correction label to be written.

5. The data writing method according to claim 4, wherein: Also includes: Obtaining a first encryption parameter; The step of obtaining a first encryption key according to the address of the data to be written comprises: The first encryption key is obtained according to the first encryption parameter and the address of the data to be written.

6. The data writing method according to claim 1, wherein: Also includes: Encrypting the data to be written to obtain encrypted data to be written; The step of writing the data to be written and the integrity error correction tag to be written into the memory includes: The encrypted data to be written and the integrity error correction tag to be written are written into the memory.

7. The data writing method according to claim 6, wherein: The step of encrypting the data to be written to obtain the encrypted data to be written comprises: A second encryption key is obtained according to a security encryption parameter, wherein the security encryption parameter is obtained by a security processor; and the data to be written is encrypted using the second encryption key to obtain the encrypted data to be written.

8. The data writing method according to claim 7, wherein: Also includes: Obtaining a second encryption parameter; The step of obtaining the second encryption key according to the security encryption parameter includes: The second encryption key is obtained according to the second encryption parameter and the security encryption parameter.

9. A data reading method, characterized in that: include: Obtaining data to be read stored at a data address to be read and an integrity error correction tag to be read corresponding to the data to be read, wherein the data address to be read comprises the data address to be written in the data writing method according to any one of claims 1 to 8, the integrity error correction tag to be read comprises the integrity error correction tag to be written in the data writing method according to any one of claims 1 to 8, and the integrity error correction tag to be read is used to perform integrity verification and data error correction on the data to be read; Obtaining a first redundant integrity error correction tag according to the integrity error correction tag to be read; performing a read redundancy coding operation on the data to be read and the address of the data to be read using a read redundancy polynomial to obtain a second redundant integrity error correction tag, wherein the read redundancy polynomial corresponds to the write redundancy polynomial in the data writing method according to any one of claims 1 to 8; When the first redundant integrity error correction tag is equal to the second redundant integrity error correction tag, determining that the data to be read is complete; The data to be read that is confirmed to be complete is sent.

10. The data reading method according to claim 9, wherein: Also includes: When the first redundant integrity error correction label is not equal to the second redundant integrity error correction label, obtaining an error deviation between the first redundant integrity error correction label and the second redundant integrity error correction label; When the error deviation is not greater than the error correction threshold, performing data error correction on the data to be read and the first redundant integrity error correction tag by using the read redundant coding operation to obtain corrected data to be read; The corrected data to be read is sent.

11. The data reading method according to claim 10, wherein: Also includes: When the error deviation is greater than the error correction threshold, data abnormality information is issued.

12. The data reading method according to claim 10, wherein: The error deviation includes the Hamming distance.

13. The data reading method according to claim 9, wherein: Also includes: Get the read redundant initial value parameters; The step of performing a read redundant coding operation on the to-be-read data and the to-be-read data address using a read redundant polynomial to obtain a second redundant integrity error correction label comprises: Obtaining a read redundancy initial value according to the read redundancy initial value parameter and the address of the data to be read; A read redundancy encoding operation is performed on the data to be read using the read redundancy polynomial and the read redundancy initial value to obtain the second redundant integrity error correction label.

14. The data reading method according to claim 9, wherein: The integrity error correction tag to be read includes an encrypted integrity error correction tag to be read, and the step of obtaining a first redundant integrity error correction tag according to the integrity error correction tag to be read includes: The encrypted integrity error correction label to be read is decrypted to obtain the first redundant integrity error correction label.

15. The data reading method according to claim 14, wherein: The step of decrypting the encrypted integrity error correction label to be read to obtain the first redundant integrity error correction label includes: Obtaining a first decryption key using the address of the data to be read, where the first decryption key corresponds to a first encryption key, and the first encryption key is used to encrypt the integrity error correction tag when writing data to obtain the encrypted integrity error correction tag to be written; The encrypted integrity error correction label to be read is decrypted using the first decryption key to obtain the first redundant integrity error correction label.

16. The data reading method according to claim 15, wherein: Also includes: Obtaining a first decryption parameter, where the first decryption parameter corresponds to a first encryption parameter, and the first encryption parameter is used to obtain the first encryption key when writing data; The step of obtaining a first decryption key by using the address of the data to be read comprises: A first decryption key is obtained using the first decryption parameter and the address of the data to be read.

17. The data reading method according to claim 9, wherein: The data to be read includes encrypted data to be read, and before the step of sending the confirmed complete data to be read, the method further includes: Decrypting the encrypted data to be read to obtain decrypted data to be read; The step of sending the confirmed complete data to be read comprises: The decrypted data to be read that is confirmed to be complete is sent.

18. The data reading method according to claim 17, wherein: The step of decrypting the encrypted data to be read to obtain the decrypted data to be read comprises: Obtaining a security decryption parameter, the security decryption parameter corresponding to the security encryption parameter, the security encryption parameter being obtained by the security processor and used to obtain a second encryption key for encrypting the data to be written when writing data; Obtaining a second decryption key according to the security decryption parameter; The encrypted data to be read is decrypted using the second decryption key to obtain the decrypted data to be read.

19. The data reading method according to claim 18, wherein: Also includes: Obtaining a second decryption parameter, where the second decryption parameter corresponds to a second encryption parameter, and the second encryption parameter is used to obtain the second encryption key when writing data; The step of obtaining a second decryption key according to the security decryption parameter comprises: Obtaining a second decryption key according to the second decryption parameter and the security decryption parameter; The encrypted data to be read is decrypted using the second decryption key to obtain the decrypted data to be read.

20. A data writing device, characterized in that: include: A write acquisition module, adapted to acquire data to be written and a data address to be written corresponding to the data to be written; a write redundant coding operation module adapted to perform a write redundant coding operation on the data address to be written and the data to be written using a write redundant polynomial to obtain an integrity error correction tag to be written, wherein the integrity error correction tag to be written is used for integrity verification and data error correction; the write redundant polynomial is randomly generated after the processor hardware is started and remains unchanged throughout the entire operation of the processor, and the write redundant polynomial provides an error correction function; The writing module is adapted to write the data to be written and the integrity error correction tag to be written into the memory.

21. The data writing device according to claim 20, wherein: Also includes: A write redundancy parameter acquisition module, adapted to acquire write redundancy initial value parameters; The write redundant coding operation module is adapted to perform write redundant coding on the address of the data to be written and the data to be written using a write redundant polynomial to obtain an integrity error correction label to be written, and includes: Obtaining a write redundancy initial value according to the write redundancy initial value parameter and the address of the data to be written; A write redundancy coding operation is performed on the data to be written using a write redundancy polynomial and the write redundancy initial value to obtain the integrity error correction label to be written.

22. The data writing device according to claim 20, wherein: Also includes: an integrity error correction tag encryption module, adapted to encrypt the integrity error correction tag to be written to obtain an encrypted integrity error correction tag to be written; The writing module is adapted to write the data to be written and the integrity error correction tag to be written into the memory, and includes: The data to be written and the encryption integrity error correction tag to be written are written into the memory.

23. The data writing device according to claim 22, wherein: The integrity error correction tag encryption module is adapted to encrypt the integrity error correction tag to be written to obtain the encrypted integrity error correction tag to be written, and includes: Obtaining a first encryption key according to the address of the data to be written; The integrity error correction label to be written is encrypted using the first encryption key to obtain the encrypted integrity error correction label to be written.

24. The data writing device according to claim 23, wherein: Also includes: A first encryption parameter acquisition module, adapted to acquire a first encryption parameter; The integrity error correction tag encryption module is adapted to obtain a first encryption key according to the address of the data to be written, including: The first encryption key is obtained according to the first encryption parameter and the address of the data to be written.

25. The data writing device according to claim 20, wherein: Also includes: A data encryption module, adapted to encrypt the data to be written to obtain encrypted data to be written; The writing module is adapted to write the data to be written and the integrity error correction tag to be written into the memory, and includes: The encrypted data to be written and the integrity error correction tag to be written are written into the memory.

26. The data writing device according to claim 25, wherein: The data encryption module is adapted to encrypt the data to be written to obtain the encrypted data to be written, and includes: A second encryption key is obtained according to a security encryption parameter, wherein the security encryption parameter is obtained by a security processor; and the data to be written is encrypted using the second encryption key to obtain the encrypted data to be written.

27. The data writing device according to claim 26, wherein: Also includes: A second encryption parameter acquisition module, adapted to acquire a second encryption parameter; The data encryption module is adapted to obtain the second encryption key, comprising: The second encryption key is obtained according to the second encryption parameter and the security encryption parameter.

28. A data reading device, characterized in that: include: a read acquisition module, adapted to acquire data to be read stored at a data address to be read, and an integrity error correction tag to be read corresponding to the data to be read, wherein the data address to be read comprises the data address to be written in the data writing device according to any one of claims 20 to 27, and the integrity error correction tag to be read comprises the integrity error correction tag to be written in the data writing device according to any one of claims 20 to 27, and the integrity error correction tag to be read is used to perform integrity verification and data error correction on the data to be read; a first redundant integrity error correction label acquisition module, adapted to acquire a first redundant integrity error correction label according to the integrity error correction label to be read; a read redundant coding operation module, adapted to perform a read redundant coding operation on the to-be-read data and the to-be-read data address using a read redundant polynomial to obtain a second redundant integrity error correction tag, wherein the read redundant polynomial corresponds to the write redundant polynomial in the data writing device according to any one of claims 20 to 27; an integrity determination module, adapted to determine that the to-be-read data is complete when the first redundant integrity error correction tag is equal to the second redundant integrity error correction tag; The sending module is adapted to send the confirmed complete data to be read.

29. The data reading device according to claim 28, wherein Also includes: a data error correction module, adapted to obtain an error deviation between the first redundant integrity error correction label and the second redundant integrity error correction label when the first redundant integrity error correction label is not equal to the second redundant integrity error correction label; When the error deviation is not greater than the error correction threshold, performing data error correction on the data to be read and the first redundant integrity error correction tag by using the read redundant coding operation to obtain corrected data to be read; The sending module is adapted to send the confirmed complete data to be read, and includes: The corrected data to be read is sent.

30. The data reading device according to claim 29, wherein Also includes: The data error reporting module is adapted to issue data anomaly information when the error deviation is greater than the error correction threshold.

31. The data reading device according to claim 28, wherein Also includes: A redundant parameter acquisition module is used to acquire redundant initial value parameters; The read redundant coding operation module is adapted to perform a read redundant coding operation on the to-be-read data and the to-be-read data address using a read redundant polynomial to obtain a second redundant integrity error correction label, including: Obtaining a read redundancy initial value according to the read redundancy initial value parameter and the address of the data to be read; A read redundancy encoding operation is performed on the data to be read using the read redundancy polynomial and the read redundancy initial value to obtain the second redundant integrity error correction label.

32. The data reading device according to claim 28, wherein The integrity error correction label to be read includes an encrypted integrity error correction label to be read. The first redundant integrity error correction label acquisition module is adapted to acquire the first redundant integrity error correction label according to the integrity error correction label to be read, including: The encrypted integrity error correction label to be read is decrypted to obtain a first redundant integrity error correction label.

33. The data reading device according to claim 32, wherein: The first redundant integrity error correction label acquisition module is adapted to decrypt the encrypted integrity error correction label to be read to obtain the first redundant integrity error correction label, including: Obtaining a first decryption key using the address of the data to be read, where the first decryption key corresponds to a first encryption key, and the first encryption key is used to encrypt the integrity error correction tag when writing data to obtain the encrypted integrity error correction tag to be written; The encrypted integrity error correction label to be read is decrypted using the first decryption key to obtain the first redundant integrity error correction label.

34. The data reading device according to claim 33, wherein: Also includes: a first decryption parameter acquisition module, adapted to acquire a first decryption parameter, the first decryption parameter corresponding to a first encryption parameter, the first encryption parameter being used to acquire the first encryption key when writing data; The first redundant integrity error correction tag acquisition module is adapted to obtain a first decryption key using the address of the data to be read, and includes: A first decryption key is obtained using the first decryption parameter and the address of the data to be read.

35. The data reading device according to claim 28, wherein The data to be read includes encrypted data to be read, and the sending module is adapted to further include: A data decryption module, adapted to decrypt the encrypted data to be read to obtain the decrypted data to be read; The sending module is adapted to send the confirmed complete data to be read, and includes: The decrypted data to be read that is confirmed to be complete is sent.

36. The data reading device according to claim 35, wherein The data decryption module is adapted to decrypt the encrypted data to be read to obtain the decrypted data to be read, and includes: Obtaining a security decryption parameter, the security decryption parameter corresponding to the security encryption parameter, the security encryption parameter being obtained by the security processor and used to obtain a second encryption key for encrypting the data to be written when writing data; Obtaining a second decryption key according to the security decryption parameter; The encrypted data to be read is decrypted using the second decryption key to obtain the decrypted data to be read.

37. The data reading device according to claim 36, wherein: Also includes: a second decryption parameter acquisition module, adapted to acquire a second decryption parameter, the second decryption parameter corresponding to a second encryption parameter, the second encryption parameter being used to acquire the second encryption key when writing data; The data decryption module is adapted to obtain a second decryption key according to the security decryption parameter, comprising: Obtaining a second decryption key according to the second decryption parameter and the security decryption parameter; The encrypted data to be read is decrypted using the second decryption key to obtain the decrypted data to be read.

38. A storage medium, characterized in that The storage medium stores a program suitable for data writing and data reading, so as to implement the data writing method according to any one of claims 1 to 8, or the data reading method according to any one of claims 9 to 19.

39. An electronic device, characterized in that: The method comprises at least one memory and at least one processor, wherein the memory stores data writing and data reading programs, and the processor calls the programs to execute the data writing method according to any one of claims 1 to 8 or the data reading method according to any one of claims 9 to 19.

Citation Information

Patent Citations

  • Encryption integrity check in memory

    US20160085692A1