Chip data acquisition method, device, system, chip and storage medium

Through the encryption and decryption process between the security chip and the control chip, it is ensured that the control chip can only obtain data in a secure environment, solving the problem of easy access to the control chip's operating data and improving data security.

CN115935392BActive Publication Date: 2025-09-12GUANGZHOU ZHONO ELECTRONICS TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211602952.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-13
Publication Date
2025-09-12
Estimated Expiration
2042-12-13

AI Technical Summary

Technical Problem

In the prior art, the operating data of the control chip can be easily obtained by other devices, resulting in poor security.

Method used

By establishing an electrical connection between the security chip and the control chip, the security chip receives the encrypted data acquisition instruction from the control chip and decrypts it, encrypts it after obtaining the target operating data, and sends the encrypted data to the control chip for decryption, ensuring that the control chip can only obtain data in a secure environment.

Benefits of technology

The security of the operating data of the control chip is improved, preventing other devices from illegally obtaining the data and strengthening the data protection mechanism.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115935392B_ABST
    Figure CN115935392B_ABST
Patent Text Reader

Abstract

The embodiments of the present invention provide a chip data acquisition method, device, system, chip, and storage medium, relating to the field of data security. A security chip is electrically connected to a control chip, and the security chip stores the operating data of the control chip. The security chip can receive an encrypted data acquisition instruction sent by the control chip; the encrypted data acquisition instruction is generated by the control chip; the encrypted data acquisition instruction is decrypted to obtain a data acquisition instruction; the data acquisition instruction includes a data storage location; the corresponding target operating data is obtained according to the data storage location; the target operating data is encrypted and sent to the control chip so that the control chip can decrypt the encrypted target operating data to obtain the target operating data. Through this method, it can be ensured that the operating data of the control chip will not be obtained by other devices, thereby improving the security of the operating data of the control chip.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data security, and in particular to a chip data acquisition method, device, system, chip and storage medium. Background Art

[0002] Currently, the control chip generally needs to obtain data stored in the on-chip FLASH during operation. However, in the prior art, the data in the on-chip FLASH of the control chip is always easily obtained by other devices, so there is a problem of poor security of the operating data of the control chip. Summary of the Invention

[0003] In view of this, an object of the present invention is to provide a chip data acquisition method, device, system, chip and storage medium to solve the problem of poor security of operating data of control chips in the prior art.

[0004] In order to achieve the above objectives, the technical solutions adopted in the embodiments of the present invention are as follows:

[0005] In a first aspect, the present invention provides a chip data acquisition method, which is applied to a security chip, wherein the security chip is electrically connected to a control chip, and the security chip stores operating data of the control chip, the method comprising:

[0006] receiving an encrypted data acquisition instruction sent by the control chip; the encrypted data acquisition instruction is generated by the control chip;

[0007] Decrypting the encrypted data acquisition instruction to obtain a data acquisition instruction; the data acquisition instruction includes a data storage location;

[0008] Acquire corresponding target operation data according to the data storage location;

[0009] The target operation data is encrypted and sent to the control chip so that the control chip decrypts the encrypted target operation data to obtain the target operation data.

[0010] In an optional embodiment, decrypting the encrypted data acquisition instruction to obtain the data acquisition instruction includes:

[0011] generating a first decryption key according to a current count value of the security chip;

[0012] Decrypting the encrypted data acquisition instruction according to the first decryption key to obtain a data acquisition instruction;

[0013] The encrypted data acquisition instruction is obtained by the control chip after generating the data acquisition instruction according to the data storage location and generating a first encryption key according to the current count value of the control chip, and encrypting the data acquisition instruction according to the first encryption key.

[0014] In an optional embodiment, after generating the first decryption key according to the current count value of the security chip, the method further includes:

[0015] Updating the current count value of the security chip according to a preset update rule;

[0016] The encrypting the target operating data and sending the encrypted target operating data to the control chip so that the control chip decrypts the encrypted target operating data to obtain the target operating data includes:

[0017] generating a second encryption key according to the updated count value of the security chip, and encrypting the target operation data according to the second encryption key;

[0018] sending the encrypted target operating data to the control chip, so that the control chip generates a second decryption key according to the updated count value of the control chip, and decrypts the encrypted target operating data according to the second decryption key to obtain the target operating data;

[0019] The updated count value of the control chip is obtained by updating the current count value of the control chip according to a preset update rule after the control chip generates the first encryption key.

[0020] In an optional embodiment, the method further comprises:

[0021] If decryption of the encrypted data acquisition instruction fails, generating a random character string, generating a third encryption key according to the updated count value of the security chip, and encrypting the random character string according to the third encryption key;

[0022] The encrypted random character string is sent to the control chip.

[0023] In an optional embodiment, the method further comprises:

[0024] When the power is turned on for the first time, the security chip firmware is burned so that the count value of the security chip is set to a first initial count value; wherein the first initial count value is the same as the second initial count value of the control chip, and the second initial count value is obtained by burning the control chip firmware when the control chip is powered on for the first time.

[0025] In an optional embodiment, the method further comprises:

[0026] In the case that the decryption of the encrypted data acquisition instruction fails, a self-destruction program is started.

[0027] In a second aspect, the present invention provides a chip data acquisition method, which is applied to a control chip, wherein the control chip is electrically connected to a security chip, and the security chip stores the operating data of the control chip, the method comprising:

[0028] generating an encrypted data acquisition instruction and sending the encrypted data acquisition instruction to the security chip so that the security chip decrypts the encrypted data acquisition instruction to obtain a data acquisition instruction, acquires corresponding target operating data according to the data storage location, and encrypts the target operating data; the data acquisition instruction includes the data storage location;

[0029] The encrypted target operation data sent by the security chip is received, and the encrypted target operation data is decrypted to obtain the target operation data.

[0030] In a third aspect, the present invention provides a chip data acquisition device, which is applied to a security chip, wherein the security chip is electrically connected to a control chip, and the operating data of the control chip is stored on the security chip, and the device includes:

[0031] A receiving module, configured to receive an encrypted data acquisition instruction sent by the control chip; the encrypted data acquisition instruction is generated by the control chip;

[0032] A first decryption module is used to decrypt the encrypted data acquisition instruction to obtain a data acquisition instruction; the data acquisition instruction includes a data storage location;

[0033] The first decryption module is further configured to obtain corresponding target operation data according to the data storage location;

[0034] The encryption module is used to encrypt the target operation data and send the encrypted target operation data to the control chip so that the control chip decrypts the encrypted target operation data to obtain the target operation data.

[0035] In a fourth aspect, the present invention provides a chip data acquisition device, which is applied to a control chip, wherein the control chip is electrically connected to a security chip, and the security chip stores the operating data of the control chip, and the device includes:

[0036] a sending module, configured to generate an encrypted data acquisition instruction and send the encrypted data acquisition instruction to the security chip, so that the security chip decrypts the encrypted data acquisition instruction to obtain a data acquisition instruction, obtains corresponding target operating data according to the data storage location, and encrypts the target operating data; the data acquisition instruction includes the data storage location;

[0037] The second decryption module is configured to receive the encrypted target operation data sent by the security chip, and decrypt the encrypted target operation data to obtain the target operation data.

[0038] In a fifth aspect, the present invention provides a chip data acquisition system, including a security chip and a control chip.

[0039] In a sixth aspect, the present invention provides a chip comprising a processor and a memory, wherein the memory stores a computer program that can be executed by the processor, and the processor can execute the computer program to implement any of the methods described in the aforementioned embodiments.

[0040] In a seventh aspect, the present invention provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the method as described in any one of the aforementioned embodiments.

[0041] The chip data acquisition method, device, system, chip and storage medium provided by the embodiment of the present invention are as follows: the control chip is electrically connected to the security chip that stores the operating data of the control chip; the security chip can receive the encrypted data acquisition instruction generated and sent by the control chip, and obtain the data acquisition instruction by decrypting the encrypted data acquisition instruction, and then obtain the corresponding target operating data according to the data storage location in the data acquisition instruction. After that, the security chip can encrypt the target operating data and send the encrypted target operating data to the control chip so that the control chip can decrypt the encrypted target operating data to obtain the target operating data. In this method, the security chip can store the operating data on the control chip. When the control chip needs to obtain the target operating data, it can confirm whether the current data acquisition environment is safe through the decryption verification of the security chip and the decryption verification of the control chip. The control chip can only obtain the target operating data under the safe condition. Therefore, it can be ensured that the operating data of the control chip will not be obtained by other devices, thereby improving the security of the operating data of the control chip.

[0042] In order to make the above-mentioned objects, features and advantages of the present invention more obvious and easy to understand, preferred embodiments are given below and described in detail with reference to the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0043] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for use in the embodiments. It should be understood that the following drawings only illustrate certain embodiments of the present invention and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other relevant drawings can be obtained based on these drawings without paying any creative work.

[0044] Figure 1 FIG2 shows a block diagram of a chip data acquisition system provided by an embodiment of the present invention;

[0045] Figure 2 A block diagram of a chip provided by an embodiment of the present invention is shown;

[0046] Figure 3 A schematic diagram showing a flow chart of a chip data acquisition method applied to a security chip provided by an embodiment of the present invention;

[0047] Figure 4 Another schematic flow chart of a chip data acquisition method applied to a security chip provided by an embodiment of the present invention is shown;

[0048] Figure 5 A schematic flow chart of a chip data acquisition method applied to a control chip provided by an embodiment of the present invention is shown;

[0049] Figure 6 A functional module diagram of a chip data acquisition device applied to a security chip provided by an embodiment of the present invention is shown;

[0050] Figure 7 A functional module diagram of a chip data acquisition device applied to a control chip provided by an embodiment of the present invention is shown.

[0051] Icon: 10-chip data acquisition system; 100-security chip; 110-control chip; 20-chip; 200-memory; 210-processor; 220-communication module; 300-receiving module; 310-first decryption module; 320-encryption module; 400-sending module; 410-second decryption module. DETAILED DESCRIPTION

[0052] The following will be combined with the accompanying drawings to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Generally, the components of the embodiments of the present invention described and shown in the drawings herein can be arranged and designed in various different configurations.

[0053] Therefore, the following detailed description of the embodiments of the present invention provided in the accompanying drawings is not intended to limit the scope of the invention as claimed, but is merely intended to represent selected embodiments of the present invention. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative work are within the scope of protection of the present invention.

[0054] It should be noted that relational terms such as "first" and "second" are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or apparatus. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of additional identical elements in the process, method, article, or apparatus comprising the element.

[0055] Currently, the normal operation of the control chip in a certain device often depends on the firmware stored in its on-chip FLASH. The firmware refers to the program written into the memory, which can be EPROM (Erasable Programmable Read-Only Memory) or EEPROM (Electric Erasable Programmable Read-Only Memory).

[0056] In this case, if other devices want to implement some of the functions of the original device, they need to obtain the firmware stored in the on-chip FLASH of the control chip from the original device. Generally, there are two ways to do this:

[0057] 1. The other device will extract data from the on-chip FLASH of the control chip of the original device, and then burn the data in the on-chip FLASH into the control chip in the other device. At this time, the control chip in the other device can obtain the program in the control chip, and the other device can realize the functions of the original device.

[0058] 2. Other devices can disassemble the extracted FLASH data to obtain the program of the original device, and then transplant the functional program of the original device into the code of other devices, so that other devices can realize the functions of the original device.

[0059] Obviously, for original equipment, the firmware of the on-chip FLASH of its control chip is very easy to be obtained by other devices. Therefore, how to protect the firmware of the on-chip FLASH of the control chip has become an urgent problem to be solved.

[0060] In the prior art, it is generally possible to set a unique identification code for the control chip and verify the unique identification code when the control chip obtains data for operation, thereby ensuring that other devices will not obtain the on-chip FLASH firmware of the control chip of the original device by the first acquisition method mentioned above, and to ensure that other devices will not obtain the on-chip FLASH firmware of the control chip of the original device by the second acquisition method mentioned above by encrypting and saving the firmware. However, the methods in the prior art are often unable to restrain the above two acquisition methods at the same time. Therefore, there is still a problem of poor security of the operating data of the control chip.

[0061] Based on this, the embodiment of the present application provides a chip data acquisition method to solve the above problems. Specifically, Figure 1 For a block diagram of the chip data acquisition system 10 provided in the embodiment of the present application, see Figure 1 The chip data acquisition system 10 includes a security chip 100 and a control chip 110. The security chip 100 and the control chip 110 are electrically connected.

[0062] Optionally, the security chip 100 is provided with a first on-chip FLASH and a first count value storage unit, wherein the first on-chip FLASH is used to store the operating program of the control chip 110, such as the operating program, and the first count value storage unit is used to store the current count value of the security chip.

[0063] In a possible implementation, the first on-chip FLASH can store not only the operating program of the control chip 110 , but also other important data of the control chip, such as operating parameters.

[0064] Optionally, the control chip 110 is provided with a second on-chip FLASH and a second count value storage unit, wherein the second on-chip FLASH is used to store some basic data of the control chip, such as basic programs, etc., and the second count value storage unit is used to store the current count value of the control chip.

[0065] Optionally, the control chip 110 may be used to execute corresponding programs to implement corresponding functions of the device. In one possible implementation, the control chip 110 may be an MCU (Microcontroller Unit).

[0066] Further, Figure 2A schematic block diagram of a chip 20 provided in an embodiment of the present application, wherein the chip 20 may refer to the above-mentioned Figure 1 The security chip 100 in the embodiment may also refer to the above Figure 1 The control chip 110 in.

[0067] See Figure 2 , is a block diagram of a chip 20 provided in an embodiment of the present application. Chip 20 includes a memory 200, a processor 210, and a communication module 220. The memory 200, processor 210, and communication module 220 are electrically connected to each other, directly or indirectly, to enable data transmission or interaction. For example, these components may be electrically connected to each other via one or more communication buses or signal lines.

[0068] The memory 200 is used to store programs or data. The memory 200 may be, but is not limited to, a random access memory (RAM), a read-only memory (ROM), a programmable read-only memory (PROM), an erasable read-only memory (EPROM), or an electrically erasable read-only memory (EEROM).

[0069] The processor 210 is used to read / write data or programs stored in the memory and execute corresponding functions.

[0070] The communication module 220 is used to establish a communication connection between the server and other communication terminals through the network, and to send and receive data through the network.

[0071] It should be understood that Figure 2 The structure shown is only a schematic diagram of the structure of the chip 20. The chip 20 may also include Figure 2 More or fewer components than shown, or with Figure 2 Different configurations shown. Figure 2 Each component shown in the figure can be implemented by hardware, software or a combination thereof.

[0072] An embodiment of the present application further provides a computer-readable storage medium on which a computer program is stored. When the computer program is executed by a processor, the chip data acquisition method provided in the embodiment of the present application can be implemented.

[0073] Next, the above Figure 1 The security chip 100 in the embodiment is the execution subject, and the chip data acquisition method provided in the embodiment of the present application is exemplarily introduced in combination with the flow chart. Specifically, Figure 3 A flow chart of a chip data acquisition method for a security chip provided in an embodiment of the present application is provided. Figure 3, the method comprising:

[0074] Step S20, receiving the encrypted data acquisition instruction sent by the control chip;

[0075] Wherein, the encrypted data acquisition instruction is generated by the control chip;

[0076] Step S21, decrypting the encrypted data acquisition instruction to obtain the data acquisition instruction;

[0077] Wherein, the data acquisition instruction includes a data storage location;

[0078] Optionally, the control chip may generate the encrypted data acquisition instruction when receiving an operation instruction, or may generate the encrypted data acquisition instruction when set in advance by a developer.

[0079] Optionally, the control chip may first generate a data acquisition instruction, and then encrypt the data acquisition instruction to generate the encrypted data acquisition instruction.

[0080] Optionally, after generating the encrypted data acquisition instruction, the control chip may send the encrypted data acquisition instruction to the security chip, and the security chip may decrypt the encrypted data acquisition instruction. It is understandable that if the security chip successfully decrypts the encrypted data acquisition instruction, the data acquisition instruction can be obtained, and then the data storage location can be obtained.

[0081] Optionally, the data storage location is a storage location in the security chip of target operating data that the control chip needs to obtain. In a possible implementation, the data storage location may include a starting address and data length of the target operating data.

[0082] Step S22, obtaining corresponding target operation data according to the data storage location;

[0083] Optionally, the target operation data may be an operation program, important parameters, etc. required for the operation of the control chip. Step S23 encrypts the target operation data and sends the encrypted target operation data to the control chip so that the control chip decrypts the encrypted target operation data to obtain the target operation data.

[0084] Optionally, the security chip may extract the target running data from an on-chip FLASH of the security chip according to the data storage location.

[0085] In this embodiment, after obtaining the target operating data, the security chip may encrypt the target operating data and send the encrypted target operating data to the control chip, which may then decrypt the encrypted target operating data. It is understood that if the control chip successfully decrypts the encrypted target operating data, the control chip can obtain the target operating data.

[0086] It can be understood that if the security chip successfully decrypts the encrypted data acquisition instruction and the control chip successfully decrypts the encrypted target operation data, it means that the current data acquisition environment is safe. In this case, the control chip can successfully obtain valid target operation data.

[0087] The chip data acquisition method provided by the embodiment of the present application is that the control chip is electrically connected to the security chip that stores the operating data of the control chip. The security chip can receive the encrypted data acquisition instruction generated and sent by the control chip, and obtain the data acquisition instruction by decrypting the encrypted data acquisition instruction. Then, the corresponding target operating data can be obtained according to the data storage location in the data acquisition instruction. After that, the security chip can encrypt the target operating data and send the encrypted target operating data to the control chip so that the control chip can decrypt the encrypted target operating data to obtain the target operating data. In this method, the security chip can store the operating data on the control chip. When the control chip needs to obtain the target operating data, it can confirm whether the current data acquisition environment is safe through the decryption verification of the security chip and the decryption verification of the control chip. The control chip can only obtain the target operating data under the safe condition. Therefore, it can be ensured that the operating data of the control chip will not be obtained by other devices, thereby improving the security of the operating data of the control chip.

[0088] Optionally, both the control chip and the security chip need to perform encryption and decryption based on the encryption key and decryption key. Therefore, count values ​​can be set in the control chip and the security chip respectively, and the control chip and the security chip can generate encryption keys or decryption keys respectively based on the count values ​​set therein.

[0089] In one possible implementation, the control chip and the security chip may generate an encryption key or a decryption key according to a count value set therein using a hash algorithm.

[0090] In this case, in order to ensure that the encryption and decryption processes of the control chip and the security chip proceed smoothly, the same initial count value can be set for the control chip and the security chip. Specifically, the above method also includes:

[0091] When the power is turned on for the first time, the security chip firmware is burned so that the count value of the security chip is set to a first initial count value; wherein the first initial count value is the same as the second initial count value of the control chip, and the second initial count value is obtained by burning the control chip firmware when the control chip is powered on for the first time.

[0092] Optionally, the initial power-on refers to the first power-on of the security chip and the control chip after leaving the factory.

[0093] In this embodiment, when the security chip is powered on for the first time, firmware is burned according to its on-chip FLASH. The security chip firmware can be the factory security information of the security chip, such as the program fragment, serial number, verification information, manufacturer information, etc. of the security chip. At the same time, the security chip will obtain a first initial count value after the firmware is burned.

[0094] Optionally, the first initial count value may be set by a developer. In one possible implementation, the first initial count value may be a number, such as 0.

[0095] Optionally, when the control chip is powered on for the first time, the firmware will also be burned according to its on-chip FLASH. The control chip firmware can be the program machine code for the control chip program to run. The program machine code is the data required for the control chip to run. At the same time, the control chip will obtain a second initial count value after the firmware is burned.

[0096] Optionally, the second initial count value may be set by a developer.

[0097] In this embodiment, the first initial count value should be consistent with the second initial count value of the control chip corresponding to the security chip. For example, if the first initial count value of the security chip is 0, the second initial count value of the control chip corresponding to the security chip should also be set to 0.

[0098] In this embodiment, the first initial count value may be stored in a first count value storage unit of the security chip, and the second initial count value may be stored in a second count value storage unit of the control chip. Optionally, when generating an encrypted data acquisition instruction, the control chip may obtain the current count value of the control chip from the second count value storage unit, encrypt the data acquisition instruction based on the current count value of the control chip, and then send the encrypted data acquisition instruction to the security chip. After receiving the encrypted data acquisition instruction sent by the control chip, the security chip may obtain the current count value of the security chip from the first count value storage unit, decrypt the encrypted data acquisition instruction based on the current count value, and thus obtain the data acquisition instruction.

[0099] Specifically, in the above Figure 3 On the basis of Figure 4 Another flow chart of the chip data acquisition method for a security chip provided in an embodiment of the present application is shown in FIG. Figure 4 , the above step S21 can also be implemented by the following steps:

[0100] Step S21-1, generating a first decryption key according to the current count value of the security chip;

[0101] Step S21-2, decrypting the encrypted data acquisition instruction according to the first decryption key to obtain the data acquisition instruction;

[0102] The encrypted data acquisition instruction is obtained by the control chip after generating the data acquisition instruction according to the data storage location and generating the first encryption key according to the current count value of the control chip, and then encrypting the data acquisition instruction according to the first encryption key.

[0103] Optionally, the control chip may obtain the data storage location according to the received operation instruction, or may obtain the data storage location set in advance by the developer when the developer sets in advance that an encrypted data acquisition instruction should be generated.

[0104] In this embodiment, the control chip can generate a data acquisition instruction based on the data storage location, and generate a first encryption key based on the current count value of the control chip. The control chip can then encrypt the data acquisition instruction according to the first encryption key according to a preset encryption algorithm.

[0105] In one possible implementation, the preset encryption algorithm can be set in advance by the developer according to the actual operating conditions, for example, performing addition and subtraction operations, XOR operations, shift operations, a combination of multiple operations, etc. This application does not limit this.

[0106] In this embodiment, the control chip will send the generated encrypted data acquisition instruction to the security chip. After receiving the encrypted data acquisition instruction, the security chip can generate a first decryption key based on the current count value of the security chip, and then decrypt the encrypted data acquisition instruction according to the first decryption key according to the preset decryption algorithm.

[0107] It can be understood that the preset decryption algorithm should correspond to the preset encryption algorithm. In one possible implementation method, the preset decryption algorithm can be set in advance by the developer according to the actual operating conditions, for example, performing addition and subtraction operations, XOR operations, displacement, a combination of multiple operation methods, etc. This application does not limit this.

[0108] Optionally, to further ensure data security, the security chip may also verify the legitimacy of the data acquisition instruction, for example, verifying the legitimacy of the read address range and the legitimacy of the read length in the data acquisition instruction.

[0109] In this case, if decryption is successful and legitimacy verification is passed, the security chip will then retrieve the corresponding target operating data based on the data storage location in the data retrieval instruction. Optionally, to further ensure data security, the count values ​​in the control chip and the security chip can be updated during the encryption and decryption process. Specifically, after executing step S21-1, the security chip can also update the current count value of the security chip according to a preset update rule.

[0110] Optionally, for the control chip, when generating an encrypted data acquisition instruction, it needs to generate a first encryption key based on the current count value of the control chip. After generating the first encryption key, the control chip can also update the current count value of the control chip according to a preset update rule.

[0111] Obviously, the update rules preset in the security chip should be consistent with the update rules preset in the control chip.

[0112] In one possible implementation, the preset update rule may be to update the current count value to the sum of the current count value and a preset threshold, or the difference with the preset threshold, or to update it to a specified value, etc., which is not limited in this application.

[0113] It is understandable that the security chip may first generate a first decryption key according to its current count value, and then update the current count value of the security chip to obtain the updated count value of the security chip and store it in the first count value storage unit.

[0114] At this time, the security chip can encrypt the target operation data using the count value of the updated security chip. Specifically, the above step S23 can also be implemented by the following steps:

[0115] generating a second encryption key according to the updated count value of the security chip, and encrypting the target operating data according to the second encryption key; sending the encrypted target operating data to the control chip, so that the control chip generates a second decryption key according to the updated count value of the control chip, and decrypts the encrypted target operating data according to the second decryption key to obtain the target operating data;

[0116] The updated count value of the control chip is obtained by updating the current count value of the control chip according to a preset update rule after the control chip generates the first encryption key.

[0117] In this embodiment, the security chip can update its current count value after generating the first decryption key, and after the decryption is successful and the target operation data is obtained, generate a second encryption key based on the updated count value of the security chip to encrypt the target operation data, and then send the encrypted target operation data to the control chip.

[0118] Optionally, the control chip may generate a second decryption key according to the updated count value of the control chip, and use it to decrypt the encrypted target operation data, thereby obtaining the target operation data.

[0119] In this embodiment, the current count value of the security chip should be the same as the current count value of the control chip, and the updated count value of the security chip should be the same as the updated count value of the control chip.

[0120] In one example, if the first initial count value of the security chip and the second initial count value of the control chip are both 0, and the preset update rule is to update the current count value to the sum of the current count value and 1, the control chip can first generate a first encryption key based on the current count value 0, and then update the current count value 0 to 1, encrypt the data acquisition instruction according to the first encryption key, thereby obtaining an encrypted data acquisition instruction, and sending it to the security chip.

[0121] The security chip receives the encrypted data acquisition instruction. At this time, the current count value of the security chip is 0. The security chip can save the first decryption key based on the current count value 0, and then update the current count value 0 to 1. The data acquisition instruction is decrypted according to the first decryption key. It can be understood that the decryption is successful at this time, so the security chip can obtain the data acquisition instruction, and thus obtain the corresponding target operation data according to the data storage location in the data acquisition instruction.

[0122] Afterwards, the security chip may generate a second encryption key according to the updated count value 1 of the security chip, and encrypt the target operation data according to the second encryption key, obtain the encrypted target operation data, and send it to the control chip.

[0123] The control chip receives the encrypted target operation data. At this time, the count value of the updated control chip is also 1. Therefore, the control chip can generate a second decryption key based on the count value 1 of the updated control chip, and decrypt the encrypted target operation data according to the second decryption key to obtain the target operation data.

[0124] The next time the control chip needs to obtain target operation data, it can generate an encryption key based on the current count value 1, and so on.

[0125] Obviously, under this mechanism, if any one of the security chip or the control chip is connected to other devices and attempts to exchange data, the decryption will inevitably fail due to the mismatch of the count value, so data exchange cannot be carried out or valid target operation data cannot be obtained. In this case, no matter which method of obtaining the data of the control chip in the original device is used in the above-mentioned existing technology, the valid data of the control chip in the original device cannot be successfully obtained.

[0126] At the same time, since the count value changes during each data exchange process, once any security chip or control chip is connected to other devices and attempts to exchange data, even if it is later connected to the original corresponding control chip or security chip, data exchange will not be possible due to the mismatch of the count value, thus further ensuring data security.

[0127] On this basis, if the security chip fails to decrypt the encrypted data acquisition instruction, it means that the data acquisition environment is not safe at this time. The security chip can then generate a random string and generate a third encryption key based on the updated security chip count value, encrypt the random string based on the third encryption key, and then send the encrypted random string to the control chip.

[0128] It is understandable that, considering that the data acquisition environment is not safe at this time, there may be cracking behavior. Therefore, in order to enhance the deception, the security chip can generate an invalid random string and encrypt it and return it to the control chip. In this way, even if the cracker successfully cracks it, it will not be possible to determine whether the decryption is successful based on the pattern of the decrypted data.

[0129] Optionally, considering the possibility or risk that the operating data in the security chip may be obtained by other devices, the security chip may start a self-destruct program to destroy the operating data stored therein if the decryption of the encrypted data acquisition instruction fails.

[0130] Optionally, considering that there is a possibility or risk that the operating data in the control chip may be obtained by other devices, the control chip may also start a self-destruct program to destroy the operating data stored therein when decryption of the encrypted target operating data or the encrypted random character string fails.

[0131] Next, the above Figure 1 The control chip 110 in the embodiment is the execution body, and the chip data acquisition method provided in the embodiment of the present application is exemplarily introduced in combination with the flow chart. Specifically, Figure 5 A flow chart of a chip data acquisition method for a control chip provided in an embodiment of the present application is shown in FIG. Figure 5 , the method comprising:

[0132] Step S30: Generate an encrypted data acquisition instruction and send the encrypted data acquisition instruction to the security chip, so that the security chip decrypts the encrypted data acquisition instruction to obtain the data acquisition instruction, obtains the corresponding target operating data according to the data storage location, and encrypts the target operating data;

[0133] Wherein, the data acquisition instruction includes a data storage location;

[0134] Step S31 : receiving the encrypted target operation data sent by the security chip, and decrypting the encrypted target operation data to obtain the target operation data.

[0135] In this embodiment, the control chip can generate an encrypted data acquisition instruction and send it to the security chip, which decrypts the encrypted data acquisition instruction to obtain a data acquisition instruction, then obtains the corresponding target operation data according to the data storage location and encrypts the target operation data.

[0136] In this embodiment, the control chip may receive the encrypted target operation data sent by the security chip, and decrypt the encrypted target operation data to obtain the target operation data.

[0137] Optionally, the control chip may operate according to the target operation data after obtaining the target operation data.

[0138] The chip data acquisition method provided by the embodiment of the present application is that the control chip can generate an encrypted data acquisition instruction and send the encrypted data acquisition instruction to the security chip so that the security chip decrypts the encrypted data acquisition instruction to obtain the data acquisition instruction, obtains the corresponding target operation data according to the data storage location in the data acquisition instruction, and encrypts the target operation data. Then, the control chip can receive the encrypted target operation data sent by the security chip and decrypt the encrypted target operation data to obtain the target operation data. In this method, the security chip can store the operation data on the control chip. When the control chip needs to obtain the target operation data, it can confirm whether the current data acquisition environment is safe through the decryption verification of the security chip and the decryption verification of the control chip. The control chip can only obtain the target operation data under the safe condition. Therefore, it can be ensured that the operation data of the control chip will not be obtained by other devices, thereby improving the security of the operation data of the control chip.

[0139] In order to execute the corresponding steps in the above embodiments and various possible methods, the following provides an implementation method of a chip data acquisition device applied to a security chip. Figure 6 , Figure 6This is a functional block diagram of a chip data acquisition device for a security chip according to an embodiment of the present invention. It should be noted that the basic principles and technical effects of the chip data acquisition device provided in this embodiment are the same as those of the aforementioned embodiments. For the sake of brevity, any details not mentioned in this embodiment are referred to the corresponding contents of the aforementioned embodiments. The chip data acquisition device includes a receiving module 300, a first decryption module 310, and an encryption module 320.

[0140] The receiving module 300 is used to receive the encrypted data acquisition instruction sent by the control chip; the encrypted data acquisition instruction is generated by the control chip.

[0141] It is understandable that the receiving module 300 can also be used to execute the step S20.

[0142] The first decryption module 310 is used to decrypt the encrypted data acquisition instruction to obtain a data acquisition instruction; the data acquisition instruction includes a data storage location;

[0143] It is understandable that the first decryption module 310 can also be used to implement the above step S21.

[0144] The first decryption module 310 is further configured to obtain corresponding target operation data according to the data storage location;

[0145] It is understandable that the first decryption module 310 can also be used to execute the above step S22.

[0146] The encryption module 320 is used to encrypt the target operation data and send the encrypted target operation data to the control chip so that the control chip decrypts the encrypted target operation data to obtain the target operation data.

[0147] It is understandable that the encryption module 320 can also be used to execute the above step S23.

[0148] Optionally, the first decryption module 310 is also used to generate a first decryption key based on the current count value of the security chip; decrypt the encrypted data acquisition instruction based on the first decryption key to obtain a data acquisition instruction; the encrypted data acquisition instruction is obtained by the control chip after generating the data acquisition instruction based on the data storage location and generating the first encryption key based on the current count value of the control chip, and encrypting the data acquisition instruction based on the first encryption key.

[0149] It is understandable that the first decryption module 310 can also be used to execute the above steps S21 - 1 to S21 - 2.

[0150] Optionally, the first decryption module 310 is further configured to update the current count value of the security chip according to a preset update rule.

[0151] Optionally, the encryption module 320 is also used to generate a second encryption key based on the updated count value of the security chip, and encrypt the target operation data according to the second encryption key; send the encrypted target operation data to the control chip, so that the control chip generates a second decryption key based on the updated count value of the control chip, and decrypts the encrypted target operation data according to the second decryption key to obtain the target operation data; wherein, the updated count value of the control chip is obtained by the control chip updating the current count value of the control chip according to a preset update rule after generating the first encryption key.

[0152] Optionally, the encryption module 320 is also used to generate a random string when the decryption of the encrypted data acquisition instruction fails, generate a third encryption key based on the updated count value of the security chip, encrypt the random string based on the third encryption key; and send the encrypted random string to the control chip.

[0153] Optionally, the receiving module 300 is also used to burn the security chip firmware when the power is first turned on, so that the count value of the security chip is set to a first initial count value; wherein the first initial count value is the same as the second initial count value of the control chip, and the second initial count value is obtained by burning the control chip firmware when the control chip is powered on for the first time.

[0154] Optionally, the first decryption module 310 is further configured to initiate a self-destruction program when decryption of the encrypted data acquisition instruction fails.

[0155] The chip data acquisition device provided in the embodiment of the present application receives an encrypted data acquisition instruction sent by a control chip through a receiving module; the encrypted data acquisition instruction is generated by the control chip; the encrypted data acquisition instruction is decrypted by a first decryption module to obtain a data acquisition instruction; the data acquisition instruction includes a data storage location, and corresponding target operating data is obtained according to the data storage location; the target operating data is encrypted by the encryption module, and the encrypted target operating data is sent to the control chip so that the control chip decrypts the encrypted target operating data to obtain the target operating data. In this device, the security chip can store the operating data on the control chip. When the control chip needs to obtain the target operating data, it can confirm whether the current data acquisition environment is safe through the decryption verification of the security chip and the decryption verification of the control chip. The control chip can only obtain the target operating data under the safe condition, thereby ensuring that the operating data of the control chip will not be obtained by other devices, thereby improving the security of the operating data of the control chip.

[0156] In order to execute the corresponding steps in the above embodiments and various possible methods, an implementation method of a chip data acquisition device applied to a control chip is given below. Figure 7 , Figure 7 This is a functional block diagram of a chip data acquisition device for a control chip according to an embodiment of the present invention. It should be noted that the basic principles and technical effects of the chip data acquisition device provided in this embodiment are the same as those of the aforementioned embodiments. For the sake of brevity, any details not mentioned in this embodiment are referred to the corresponding contents of the aforementioned embodiments. The chip data acquisition device includes a sending module 400 and a second decryption module 410.

[0157] The sending module 400 is configured to generate an encrypted data acquisition instruction and send the encrypted data acquisition instruction to the security chip. The security chip decrypts the encrypted data acquisition instruction to obtain a data acquisition instruction, acquires the corresponding target operating data based on the data storage location, and encrypts the target operating data. The data acquisition instruction includes the data storage location. It is understood that the sending module 400 may also perform the aforementioned step S30.

[0158] The second decryption module 410 is configured to receive the encrypted target operating data sent by the security chip, and decrypt the encrypted target operating data to obtain the target operating data.

[0159] It is understandable that the second decryption module 410 can also execute the above step S31.

[0160] The chip data acquisition device provided in the embodiment of the present application generates an encrypted data acquisition instruction through a sending module and sends the encrypted data acquisition instruction to a security chip so that the security chip decrypts the encrypted data acquisition instruction to obtain a data acquisition instruction, obtains the corresponding target operating data according to the data storage location, and encrypts the target operating data; the data acquisition instruction includes the data storage location; the encrypted target operating data sent by the security chip is received through a second decryption module, and the encrypted target operating data is decrypted to obtain the target operating data. In this device, the security chip can store the operating data on the control chip. When the control chip needs to obtain the target operating data, it can confirm whether the current data acquisition environment is safe through decryption verification of the security chip and decryption verification of the control chip. Only when it is safe can the control chip obtain the target operating data. Therefore, it can be ensured that the operating data of the control chip will not be obtained by other devices, thereby improving the security of the operating data of the control chip.

[0161] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can also be implemented in other ways. The device embodiments described above are merely illustrative. For example, the flowcharts and block diagrams in the accompanying drawings show the possible architectures, functions and operations of the devices, methods and computer program products according to multiple embodiments of the present invention. In this regard, each box in the flowchart or block diagram can represent a module, a program segment or a portion of code, and the module, program segment or a portion of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in an order different from that marked in the accompanying drawings. For example, two consecutive boxes can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flowchart, and the combination of boxes in the block diagram and / or flowchart, can be implemented using a dedicated hardware-based system that performs the specified function or action, or can be implemented using a combination of dedicated hardware and computer instructions.

[0162] In addition, the functional modules in the various embodiments of the present invention may be integrated together to form an independent part, or each module may exist independently, or two or more modules may be integrated to form an independent part.

[0163] If the functions are implemented in the form of software function modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.

[0164] The foregoing description is merely a preferred embodiment of the present invention and is not intended to limit the present invention. Those skilled in the art will readily appreciate that various modifications and variations of the present invention are possible. Any modifications, equivalent substitutions, or improvements made within the spirit and principles of the present invention are intended to be within the scope of protection of the present invention.

Claims

1. A chip data acquisition method, characterized in that: Applied to a security chip, the security chip is electrically connected to a control chip, and the operating data of the control chip is stored on the security chip, the method includes: receiving an encrypted data acquisition instruction sent by the control chip; the encrypted data acquisition instruction is generated by the control chip; Decrypting the encrypted data acquisition instruction to obtain a data acquisition instruction; the data acquisition instruction includes a data storage location; Decrypting the encrypted data acquisition instruction to obtain the data acquisition instruction includes: generating a first decryption key according to a current count value of the security chip; Updating the current count value of the security chip according to a preset update rule; Decrypting the encrypted data acquisition instruction according to the first decryption key to obtain a data acquisition instruction; The encrypted data acquisition instruction is obtained by the control chip generating a data acquisition instruction according to the data storage location and generating a first encryption key according to the current count value of the control chip, and then encrypting the data acquisition instruction according to the first encryption key; Acquire corresponding target operation data according to the data storage location; encrypting the target operation data and sending the encrypted target operation data to the control chip so that the control chip decrypts the encrypted target operation data to obtain the target operation data; In the case that the decryption of the encrypted data acquisition instruction fails, a self-destruction program is started.

2. The method according to claim 1, characterized in that The encrypting the target operating data and sending the encrypted target operating data to the control chip so that the control chip decrypts the encrypted target operating data to obtain the target operating data includes: generating a second encryption key according to the updated count value of the security chip, and encrypting the target operation data according to the second encryption key; sending the encrypted target operating data to the control chip, so that the control chip generates a second decryption key according to the updated count value of the control chip, and decrypts the encrypted target operating data according to the second decryption key to obtain the target operating data; The updated count value of the control chip is obtained by updating the current count value of the control chip according to a preset update rule after the control chip generates the first encryption key.

3. The method according to claim 2, characterized in that The method further comprises: If decryption of the encrypted data acquisition instruction fails, generating a random character string, generating a third encryption key according to the updated count value of the security chip, and encrypting the random character string according to the third encryption key; The encrypted random character string is sent to the control chip.

4. The method according to claim 1, wherein The method further comprises: When the power is turned on for the first time, the security chip firmware is burned so that the count value of the security chip is set to a first initial count value; wherein the first initial count value is the same as the second initial count value of the control chip, and the second initial count value is obtained by burning the control chip firmware when the control chip is powered on for the first time.

5. A chip data acquisition method, characterized in that: Applied to a control chip, the control chip is electrically connected to a security chip, and the security chip stores operating data of the control chip, the method comprising: Generate an encrypted data acquisition instruction and send the encrypted data acquisition instruction to the security chip, so that the security chip generates a first decryption key based on the current count value of the security chip, updates the current count value of the security chip according to a preset update rule, decrypts the encrypted data acquisition instruction based on the first decryption key to obtain a data acquisition instruction, obtains corresponding target operating data based on the data storage location, encrypts the target operating data, and initiates a self-destruction program if decryption of the encrypted data acquisition instruction fails; the data acquisition instruction includes the data storage location; the encrypted data acquisition instruction is obtained by the control chip after generating the data acquisition instruction based on the data storage location and generating the first encryption key based on the current count value of the control chip, and encrypting the data acquisition instruction based on the first encryption key; The encrypted target operation data sent by the security chip is received, and the encrypted target operation data is decrypted to obtain the target operation data.

6. A chip data acquisition device, characterized in that: Applied to a security chip, the security chip is electrically connected to a control chip, and the operating data of the control chip is stored on the security chip, the device includes: A receiving module, configured to receive an encrypted data acquisition instruction sent by the control chip; the encrypted data acquisition instruction is generated by the control chip; A first decryption module is used to decrypt the encrypted data acquisition instruction to obtain a data acquisition instruction; the data acquisition instruction includes a data storage location; The first decryption module is further configured to generate a first decryption key based on the current count value of the security chip; update the current count value of the security chip according to a preset update rule; and decrypt the encrypted data acquisition instruction using the first decryption key to obtain a data acquisition instruction; the encrypted data acquisition instruction is obtained by the control chip generating the data acquisition instruction based on the data storage location and generating the first encryption key based on the current count value of the control chip, and then encrypting the data acquisition instruction using the first encryption key. The first decryption module is further configured to obtain corresponding target operation data according to the data storage location; an encryption module, configured to encrypt the target operation data and send the encrypted target operation data to the control chip so that the control chip decrypts the encrypted target operation data to obtain the target operation data; The first decryption module is further configured to start a self-destruction program if decryption of the encrypted data acquisition instruction fails.

7. A chip data acquisition device, characterized in that: Applied to a control chip, the control chip is electrically connected to a security chip, and the security chip stores the operating data of the control chip, the device includes: a sending module, configured to generate an encrypted data acquisition instruction and send the encrypted data acquisition instruction to the security chip, so that the security chip generates a first decryption key based on the current count value of the security chip, updates the current count value of the security chip according to a preset update rule, decrypts the encrypted data acquisition instruction based on the first decryption key to obtain a data acquisition instruction, acquires corresponding target operating data based on the data storage location, encrypts the target operating data, and initiates a self-destruction program if decryption of the encrypted data acquisition instruction fails; the data acquisition instruction includes the data storage location; the encrypted data acquisition instruction is obtained by the control chip after generating the data acquisition instruction based on the data storage location and generating the first encryption key based on the current count value of the control chip, and encrypting the data acquisition instruction based on the first encryption key; The second decryption module is configured to receive the encrypted target operation data sent by the security chip, and decrypt the encrypted target operation data to obtain the target operation data.

8. A chip data acquisition system, characterized in that: The invention comprises a security chip and a control chip, wherein the security chip is used to implement the method described in any one of claims 1 to 4, and the control chip is used to implement the method described in claim 5.

9. A chip, characterized in that: The method comprises a processor and a memory, wherein the memory stores a computer program that can be executed by the processor, and the processor can execute the computer program to implement the method according to any one of claims 1 to 4, or implement the method according to claim 5.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the method according to any one of claims 1 to 4 is implemented, or the method according to claim 5 is implemented.

Citation Information

Patent Citations

  • Instruction sending method and system, electronic equipment and storage medium

    CN111385793A

  • Chip program protection method and device, chip and computer readable storage medium

    CN115408668A