A DMA system, method, device, and medium for countering power consumption attacks

By inserting flipped data into the DMA system to obfuscate hardware power consumption, the problems of stable level flip and easy timing analysis in the password chip are solved, the ability to resist power consumption attacks is enhanced, and the chip's security is improved.

CN116055030BActive Publication Date: 2025-07-08SHANDONG YUNHAI GUOCHUANG CLOUD COMPUTING EQUIP IND INNOVATION CENT CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310106959.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-02-10
Publication Date
2025-07-08
Estimated Expiration
2043-02-10

AI Technical Summary

Technical Problem

The existing DMA technology has stable level flip, easy to analyze the timing of read and write operations in the cryptographic chip, and lacks resistance to power consumption attack characteristics, resulting in susceptibility to power consumption attacks.

Method used

设计一种DMA系统,包括数据接收、功耗调整和数据发送模块,通过插入翻转数据混淆硬件功耗,产生与业务逻辑无关的翻转功耗以对抗功耗攻击。

Benefits of technology

Effectively obfuscate hardware power consumption, reduce power attack success rate, protect password chips from power consumption analysis, and improve security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116055030B_ABST
    Figure CN116055030B_ABST
Patent Text Reader

Abstract

The present invention belongs to the field of computers, and specifically relates to a DMA system, method, device, and medium for countering power consumption attacks. Among them, the system includes: a data receiving module configured to receive communication data sent by a bus to a target hardware; a power consumption adjustment module configured to generate inversion data based on the inversion data in a predetermined policy or according to the power consumption conditions of the target hardware, and insert the inversion data into the communication data in a predetermined manner; a data sending module configured to send the communication data inserted with the inversion data to the target hardware. Through the DMA system for countering power consumption attacks proposed by the present invention, inversion data that causes a level inversion is inserted into the target hardware to be protected, generating an inversion power consumption that has nothing to do with the business logic of the target hardware. In this way, the protection against power consumption attacks on the target hardware is achieved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of computers, and particularly relates to a DMA system, method, device and medium for countering power consumption attacks. Background Art

[0002] The present invention relates to the field of chip verification, and particularly relates to chip verification methodology, register models, and the determination of the correctness of netlist registers. Since UVM has the advantages of high speed, high efficiency, flexibility, stability, and high integration, it is very necessary in hardware logic verification and design. Simple Power Analysis (SPA) and Differential Power Analysis (DPA). Simple Power Analysis directly analyzes one or several collected power consumption curves to obtain the key, while Differential Power Analysis analyzes a large number of power consumption curves, searches for the correlation between the collected power consumption information and the input plaintext and guessed key, and uses statistical methods to obtain the key information. Power consumption attacks have the characteristics of easy acquisition of power consumption information and high attack success rate. Therefore, compared with common mathematical attack methods such as linear analysis and differential analysis, power consumption attacks pose a more serious security threat to cryptographic chips.

[0003] Existing DMA technologies have the following defects:

[0004] 1. Level inversion is one of the main reasons for power consumption. While processing a large amount of data, due to the fixity of the hardware algorithm, the switching power consumption is too stable;

[0005] 2. The timing of read and write operations has a large gap, making it easy to analyze the behavior of transmitted data;

[0006] 3. It does not have the characteristic of countering power consumption attacks, but it is generally deployed on a large scale in cryptographic chips.

[0007] Therefore, an effective solution is urgently needed to address the above problems. Summary of the Invention

[0008] To solve the above problems, the present invention proposes a DMA system for countering power consumption attacks, including:

[0009] A data receiving module configured to receive communication data sent by a bus to a target hardware;

[0010] A power consumption adjustment module configured to generate inversion data based on the inversion data in a predetermined policy or according to the power consumption conditions of the target hardware, and insert the inversion data into the communication data in a predetermined manner;

[0011] A data sending module configured to send the communication data inserted with the inversion data to the target hardware.

[0012] In some embodiments of the present invention, the system further includes:

[0013] A control module configured to receive communication data on the bus from the data receiving module and configure the functions of the power consumption adjustment module and the data sending module based on the communication data.

[0014] In some embodiments of the present invention, the power consumption adjustment module includes:

[0015] A power consumption adjustment configuration module configured to send the inversion data in the predetermined policy to the power consumption adjustment execution module based on the configuration of the control module, or generate inversion data according to the configuration scheme of the chip power management module and the simulation power consumption given by the simulation tool, and send the inversion data to the power consumption adjustment execution module;

[0016] A power consumption adjustment execution module configured to generate a corresponding inversion data insertion scheme in combination with the bus protocol of the data sending module according to the inversion data received from the power consumption adjustment configuration module, and send the communication data containing the inversion data to the data sending module according to the inversion data insertion scheme.

[0017] In some embodiments of the present invention, the data sending module includes:

[0018] A bus interface module configured to send communication data containing inversion data to the target hardware module;

[0019] A channel control module that selects a corresponding bus interface module according to the control of the control module, receives the communication data containing inversion data from the power consumption adjustment execution module, and forwards it to the corresponding bus interface module.

[0020] In some embodiments of the present invention, the data sending module further includes:

[0021] A channel register module configured to configure the bus interface function according to the configuration of the control module.

[0022] In some embodiments of the present invention, the system further includes:

[0023] A status feedback module configured to feedback the status of the communication data sent to the target hardware to the outside.

[0024] In some embodiments of the present invention, the system further includes:

[0025] An interrupt module configured to initiate a corresponding interrupt to the CPU according to the sending situation of the communication data.

[0026] Another aspect of the present invention also provides a method for countering power consumption attacks, including:

[0027] Receiving communication data sent by a bus to target hardware;

[0028] Generating inversion data based on the inversion data in a predetermined policy or according to the power consumption condition of the target hardware, and inserting the inversion data into the communication data in a predetermined manner;

[0029] Sending the communication data inserted with the inversion data to the target hardware.

[0030] Another aspect of the present invention also provides a computer device, including:

[0031] At least one processor; and

[0032] A memory storing computer instructions executable on the processor, and when the instructions are executed by the processor, the steps of the method described in any one of the above embodiments are implemented.

[0033] Another aspect of the present invention also provides a computer-readable storage medium storing a computer program, and when the computer program is executed by a processor, the steps of the method described in any one of the above embodiments are implemented.

[0034] Through the DMA system for countering power consumption attacks proposed by the present invention, inversion data causing a level inversion is inserted into the target hardware to be protected, generating an inversion power consumption unrelated to the business logic of the target hardware. In this way, the protection against power consumption attacks on the target hardware is achieved. BRIEF DESCRIPTION OF THE DRAWINGS

[0035] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of the present invention, and for those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0036] Figure 1 It is a schematic structural diagram of a DMA system for countering power consumption attacks provided by an embodiment of the present invention;

[0037] Figure 2 It is a schematic flowchart of a method for countering power consumption attacks provided by an embodiment of the present invention;

[0038] Figure 3 It is a schematic structural diagram of a computer device provided by an embodiment of the present invention;

[0039] Figure 4Schematic diagram of the structure of a computer-readable storage medium provided by an embodiment of the present invention;

[0040] Figure 5 Schematic diagram of the structure of a DMA system for countering power consumption attacks provided by an embodiment of the present invention;

[0041] Figure 6 Schematic diagram of the structure of a DMA system for countering power consumption attacks provided by an embodiment of the present invention;

[0042] Figure 7 Schematic diagram of the application of the DMA system provided by an embodiment of the present invention;

[0043] Figure 8 Schematic diagram of the read timing of the DMA system provided by an embodiment of the present invention;

[0044] Figure 9 Schematic diagram of the write timing of the DMA system provided by an embodiment of the present invention;

[0045] Figure 10 Schematic diagram of the multi-data timing of the DMA system provided by an embodiment of the present invention. Detailed implementation manners

[0046] To make the objectives, technical solutions, and advantages of the present invention clearer and more understandable, the following further elaborates on the embodiments of the present invention in detail with reference to specific embodiments and the accompanying drawings.

[0047] The present invention aims to solve the problem of obtaining data in hardware units through power consumption analysis. In a chip, data is stored in the chip circuit in the form of electrical signals. Generally, there are corresponding hardware circuits and interfaces for isolation to prevent illegal acquisition of corresponding data through the data interface of the chip (except for chips with backdoors left). Therefore, it is almost impossible to obtain the input and output data of each module of each hardware circuit through traditional methods. However, since the power consumption of the hardware circuit on the chip is mainly caused by level flips, especially after obtaining the design structure of the hardware, the power consumption caused by the input data can be analyzed by monitoring the power consumption, and furthermore, the corresponding data can be analyzed based on the power consumption generated by a chip with a known design structure or function in practice, that is, power consumption attack. The current DMA has the following problems:

[0048] 1. Level flip is one of the main reasons for power consumption. When processing a large amount of data, due to the fixity of the hardware algorithm, the flip power consumption is too stable;

[0049] 2. The timing of read and write operations has a large gap, making it easy to analyze the behavior of transmitted data;

[0050] 3. It does not have the characteristic of countering power consumption attacks, but it is generally deployed on a large scale in cryptographic chips.

[0051] To solve the above problems, the present invention proposes a DMA system for countering power consumption attacks, including:

[0052] A data receiving module 1, which is configured to receive communication data sent by a bus to a target hardware;

[0053] A power consumption adjustment module 2, which is configured to generate inversion data based on the inversion data in a predetermined policy or according to the power consumption conditions of the target hardware, and insert the inversion data into the communication data in a predetermined manner;

[0054] A data sending module 3, which is configured to send the communication data inserted with the inversion data to the target hardware.

[0055] In an embodiment of the present invention, the DMA (Direct Memory Access) system proposed by the present invention refers to an application in the field of chips or a circuit implemented by FPGA programming. The target hardware refers to the hardware circuit to be protected from power consumption attacks. The data receiving module 1 is determined according to the bus corresponding to the scenario where the DMA system for countering power consumption attacks proposed by the present invention is applied, that is, whatever bus is used for communication between the target hardware and other hardware circuits, the data receiving module 1 is correspondingly designed as a bus communication module that can be used to receive data on this bus. The communication data refers to the data originally received by the target hardware from other hardware. The specific application scenario of the DMA system proposed by the present invention can be referred to Figure 7 , Figure 7 which shows an application schematic diagram of power consumption attack resistance of an encryption / decryption module in a chip. In the figure, the encryption / decryption module is used as the target hardware. The inversion data refers to the data that realizes the corresponding level inversion on the target hardware to confuse the power consumption of the target hardware.

[0056] Furthermore, the power consumption adjustment module 2 is used to generate inversion data, which can be to select the optimal inversion data for countering power consumption attacks through relevant power consumption analysis of the target hardware as a predetermined policy and send it to and save it in the power consumption adjustment module 2. During normal operation, the inversion data in the predetermined policy is inserted into the communication data, and then sent to the target hardware by the data sending module 3.

[0057] In some embodiments of the present invention, the system further includes:

[0058] A control module 4, which is configured to receive the communication data on the bus from the data receiving module 1, and configure the functions of the power consumption adjustment module 2 and the data sending module 3 based on the communication data.

[0059] In an embodiment of the present invention, as Figure 5As shown in the figure, the DMA system proposed by the present invention for anti-power consumption attack further includes a control module 4. The control module 4 is responsible for configuring the working tasks of the entire anti-power consumption attack DMA. After the DMA system is started, the control module 4 configures the functions of each module in the DMA system based on the communication data received by the data receiving module 1 from the bus, so as to insert the flipped data into the communication data and send it to the target hardware.

[0060] In some embodiments of the present invention, the power consumption adjustment module 2 includes:

[0061] A power consumption adjustment configuration module 21, and the power consumption adjustment configuration module 22 is configured to send the flipped data in the predetermined policy to the power consumption adjustment execution module or generate flipped data according to the configuration scheme of the chip power consumption management module and the simulated power consumption given by the simulation tool, and send the flipped data to the power consumption adjustment execution module 22 based on the configuration of the control module;

[0062] A power consumption adjustment execution module 22, and the power consumption adjustment execution module 22 is configured to generate a corresponding flipped data insertion scheme according to the flipped data received from the power consumption adjustment configuration module in combination with the bus protocol of the data sending module, and send the communication data including the flipped data to the data sending module according to the flipped data insertion scheme.

[0063] In this embodiment, the power consumption adjustment module 2 specifically includes a power consumption adjustment configuration module 21 and a power consumption execution module 22. On the one hand, the power consumption adjustment configuration module sends the flipped data to the power consumption execution module 22 according to the flipped data in the predetermined policy described above. On the other hand, it directly generates flipped data randomly according to the configuration of the PMU (Power Management Unit) of the chip and the power consumption of the target hardware given by the simulation tool PTXT, and sends the flipped data to the power consumption execution module 22 for execution. That is, when there is no predetermined policy, the power consumption adjustment module 21 randomly generates flipped data. The number of bits and the length of the randomly generated flipped data for inserting into the communication data can be set according to the configuration of the PMU and the power consumption of the target hardware given by the simulation tool PTXT.

[0064] The power consumption adjustment execution module 22 further inserts the flipped data according to the bus characteristics in the presence of a corresponding data insertion mode. In some embodiments of the present invention, when the communication data with flipped data is sent to the target hardware under normal operation, the flipped data is inserted into the data frame that does not affect the original communication data for calculation in the target hardware. For example, some other instructions or bus requests of the control type are sent more, and the flipped data is inserted into the bus request. The flipped data causes corresponding circuit flips in the target hardware but does not participate in the relevant calculations.

[0065] In some embodiments of the present invention, the data sending module 3 includes:

[0066] A bus interface module 31, which is configured to send communication data containing inverted data to the target hardware module;

[0067] A channel control module 32, which selects a corresponding bus interface module 31 according to the control of the control module, and receives the communication data containing inverted data from the power consumption adjustment execution module and forwards it to the corresponding bus interface module.

[0068] As Figure 5 shown, in this embodiment, the data sending module 3 specifically includes a bus interface module 31 and a channel control module 32. The bus interface module 31 is also set according to the bus type used in the original connection mode of the target hardware. For example, as Figure 5 shown, if the bus interface between the original target hardware and the memory is the AHB bus, the bus interface module is the AHB bus data transmission module.

[0069] In some embodiments of the present invention, there may be multiple target hardwares served by the DMA system proposed by the present invention, and each target hardware is configured with a bus interface module 31. Therefore, the channel control module 32 is used to select the corresponding bus interface module 31 according to the target hardware to which the communication data is to be sent.

[0070] The functions of the channel control module 32 are all controlled by the control module 1.

[0071] In some embodiments of the present invention, the data sending module 3 further includes:

[0072] A channel register module 33, which is configured to configure the bus interface function according to the configuration of the control module.

[0073] In this embodiment, the data sending module 3 further includes a channel register module 33. The channel register module 33 further configures the relevant registers of the bus interface module 31 specifically for transmitting communication data according to the configuration of the control module 1. In some embodiments of the present invention, an interrupt signal is also generated and sent to the interrupt module 6.

[0074] In some embodiments of the present invention, the system further includes:

[0075] A status feedback module 5, which is configured to feedback the status of the communication data sent to the target hardware to the outside.

[0076] As Figure 5As shown, in this embodiment, the status feedback module 5 is used to send the status of the data transfer operation to the target hardware to the external CPU bus upstream hardware module, that is, when a data transfer to the target hardware is completed (including inserting inverted data therein), information such as the response result is sent to the module that sends the communication data on the bus.

[0077] In some embodiments of the present invention, the system further includes:

[0078] An interrupt module, configured to initiate corresponding interrupts to the CPU according to the sending situation of the communication data.

[0079] In some embodiments of the present invention, the DMA system proposed for countering power consumption attacks further includes an interrupt module 6, which is used to initiate interrupts to the CPU according to the needs of communication data transmission.

[0080] Embodiment:

[0081] As Figure 6 shown, taking the anti-power consumption attack of the encryption and decryption module on the FPGA as an example in this embodiment, the DMA system proposed by the present invention is applied on the FPGA as Figure 7 shown, that is, the anti-power consumption attack DMA system proposed by the present invention is added between the memory and the encryption and decryption module, and the AHB bus is used between the memory and the encryption and decryption module.

[0082] As Figure 6 is the implementation schematic diagram of this design, Figure 7 is the application scenario, Figure 8 、 Figure 9 、 Figure 10 are the AHB transfer protocol timings. Next, according to Figure 6 、 Figure 7 the specific implementation method of this design will be introduced.

[0083] In this embodiment, each DMA system is configured to provide unidirectional DMA transfer for a single source and target. The source area and the target area can both be memory areas or peripheral devices, and can be accessed through the same AHB host, or each host accesses one area. The base address of the DMA is not fixed and can be different for any specific system implementation. However, the offset of any specific register relative to the base address is fixed.

[0084] AHB_SLAVE0 interface (equivalent to the data receiving module 1): A slave device interface that conforms to the AMBA AHB protocol. The read and write timings of the interface refer to Figure 8 、 Figure 9 、 Figure 10, write the configuration data of the AHB bus to the DMA's Control logic and register module (equivalent to control module 4). All transactions on the AHB slave programming bus of the DMA are 32-bit. This eliminates the endianness issue when programming the DMAC.

[0085] Control logic and register (equivalent to control module 4): The register block stores the data written or read through the AMBA AHB interface. Use this block to program the DMA working mode using the AMBA AHB slave interface. The peripheral device that controls the packet length is called the stream controller. The stream controller is usually the DMA, and the packet length is programmed by software before enabling the DMA channel.

[0086] IST-DAT config module (equivalent to power consumption adjustment configuration module 21): According to the configuration results of the PMU, combined with PTPX, obtain the simulated power consumption of each module, refer to the power consumption table and the power consumption curves of multiple tests, and design this module when transmitting data blocks of different sizes.

[0087] Req / rsp interface (equivalent to status feedback module 5): The encryption peripheral uses the DMA request signal to request data transmission. The DMA response signal indicates whether the transmission initiated by the DMA request signal has been completed. The response signal can be used to indicate whether a complete data packet has been transmitted.

[0088] Interrupt Gen (equivalent to interrupt module 6): Generate an interrupt and send it to the CPU for interrupt handling.

[0089] IST-DAT logic (equivalent to power consumption adjustment execution module 22): There are two types of inserted data logics. 1. When the AHB bus is IDLE, increase the invalid transitions to increase the power consumption. The number of increases and the generated power consumption are evaluated by the IST-DAT config. 2. When the bus is working normally, insert the flipped data at the timing when the ahb hsel and htrans are invalid. The flipped power consumption can be carefully evaluated through PTPX. For the first simulation, collect data, use 32’h0 and 32’hFFFFFFFF for flipping, and then create a fine-grained power consumption model based on the power consumption loss caused by the number of flipped DFFs.

[0090] Channel data path (equivalent to channel control module 32): Design dedicated hardware channels to support each stream, including source and destination controllers, FIFOs, and discontinuous address transmission.

[0091] Channel register (equivalent to channel register module 33): The channel logic and channel register group contain the registers and logic required for each DMA channel.

[0092] Ahb-master interface (equivalent to bus interface module 31): DMA contains two complete AHB masters. Figure 1 The block diagram of two master device interfaces is shown. The master controller adopts the AMBA AHB master protocol to send data to the attached devices on the AHB bus or the extended devices of the AHB bridge.

[0093] Figure 8 It is the read timing of the DMA system. Figure 9 It is the write timing of the DMA system. Figure 10 It is the multi-data timing.

[0094] Furthermore, the operation process of the DMA system for anti-power consumption attack proposed by the present invention is as follows:

[0095] 1. Select an idle channel with necessary priority.

[0096] 2. Clear any pending interrupts on the channel to be used by writing to the configuration register. Previous channel operations may have left the interrupts active.

[0097] 3. Write the source address to the configuration register of the control module.

[0098] 4. Write the destination address to the configuration register of the control module.

[0099] 6. Write the control information to the configuration register of the control module.

[0100] 7. Write the channel configuration information to the configuration register of the control module. Enable the power consumption adjustment function.

[0101] 8. Select the power consumption adjustment data execution mode;

[0102] 9. Execute multiple times, collect power consumption data, and generate a fine-grained model. Obtain multiple simulation data based on the same flip data, analyze the power consumption brought by different communication data under this flip data on the target hardware, and analyze the power consumption.

[0103] 10. Modify the IST-DAT config. That is, generate new flip data anew.

[0104] 11. Continue the simulation verification to collect data.

[0105] 12. Repeat steps 9 - 11 until the purpose of achieving power consumption balance of the data and hiding the key power consumption curve is realized.

[0106] The above process is a simulation process for finding the optimal flipped data of the target hardware in the DMA system against power consumption attacks proposed by the present invention.

[0107] A DMA system against power consumption attacks proposed by the present invention adopts the AHB bus master-slave protocol, and is provided with an address conversion module, a cache module, an encryption / decryption read / write transmission power consumption balancing module, and a random data insertion module (according to the simulated power consumption analysis). Further, the PXPT tool is used to analyze the power consumption, confirm the flipped power consumption of the encryption / decryption module in the encryption / decryption chip, and the additional flipped power consumption generated when the added random data insertion module operates, so as to solve the problem of the stability of the power consumption curve. It is designed with an AHB transmission timing and a read / write transmission power consumption balancing module. The encryption / decryption module integrates the DMA function, making the power consumption of the encryption / decryption part of the chip controllable by software and reducing the possibility of the key being analyzed through power consumption.

[0108] As Figure 2 shown, another aspect of the present invention also proposes a method for realizing resistance to power consumption attacks, including:

[0109] Step S1, receiving communication data sent by the bus to the target hardware;

[0110] Step S2, generating flipped data based on the flipped data in the predetermined policy or according to the power consumption conditions of the target hardware, and inserting the flipped data into the communication data in a predetermined manner;

[0111] Step S3, sending the communication data inserted with the flipped data to the target hardware.

[0112] As Figure 3 shown, yet another aspect of the present invention also proposes a computer device, including:

[0113] At least one processor 21; and

[0114] A memory 22, the memory 22 stores computer instructions 23 that can run on the processor 21, and when the instructions 23 are executed by the processor 21, the steps of the method described in any one of the above embodiments are implemented.

[0115] As Figure 4 shown, still another aspect of the present invention also proposes a computer-readable storage medium 401, the computer-readable storage medium 401 stores a computer program 402, and when the computer program 402 is executed by a processor, the steps of the method described in any one of the above embodiments are implemented.

[0116] Finally, it should be noted that a person of ordinary skill in the art can understand that all or part of the processes in the above-mentioned embodiments can be implemented by instructing the relevant hardware through a computer program, and the program can be stored in a computer-readable storage medium. When the program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, the storage medium can be a disk, an optical disk, a read-only storage memory (ROM) or a random access memory (RAM), etc. The embodiment of the computer program can achieve the same or similar effect as any of the above-mentioned method embodiments corresponding thereto.

[0117] In addition, typically, the devices and equipment disclosed in the embodiments of the present invention may be various electronic terminal devices, such as mobile phones, personal digital assistants (PDAs), tablet computers (PADs), smart TVs, etc., or large terminal devices, such as servers, etc. Therefore, the protection scope disclosed in the embodiments of the present invention should not be limited to a certain type of device or equipment. The client disclosed in the embodiments of the present invention may be applied to any of the above electronic terminal devices in the form of electronic hardware, computer software, or a combination of the two.

[0118] In addition, the method disclosed in the embodiment of the present invention can also be implemented as a computer program executed by a CPU, and the computer program can be stored in a computer-readable storage medium. When the computer program is executed by the CPU, the above functions defined in the method disclosed in the embodiment of the present invention are performed.

[0119] In addition, the above method steps and system units may also be implemented using a controller and a computer-readable storage medium for storing a computer program that enables the controller to implement the above steps or unit functions.

[0120] In addition, it should be understood that a computer-readable storage medium (e.g., a memory) as described herein can be a volatile memory or a non-volatile memory, or can include both volatile and non-volatile memories. By way of example and not limitation, non-volatile memories can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memories can include random access memory (RAM), which can serve as external cache memory. By way of example and not limitation, RAM can be obtained in various forms, such as synchronous RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), and direct Rambus RAM (DRRAM). The storage devices of the disclosed aspects are intended to include, but are not limited to, these and other suitable types of memories.

[0121] Those skilled in the art will also understand that the various exemplary logical blocks, modules, circuits, and algorithm steps described in connection with the disclosure herein can be implemented as electronic hardware, computer software, or a combination of both. To clearly illustrate this interchangeability of hardware and software, various illustrative components, blocks, modules, circuits, and steps have been described generally in terms of their functionality. Whether such functionality is implemented as software or hardware depends upon the particular application and the design constraints imposed on the overall system. Those skilled in the art can implement the described functionality in various ways for each particular application, but such implementation decisions should not be interpreted as causing a departure from the scope of the embodiments of the present invention disclosed.

[0122] The various exemplary logical blocks, modules, and circuits described in connection with the disclosure herein can be implemented or performed using the following components designed to perform the functions described herein: a general-purpose processor, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), or other programmable logic device, discrete gate or transistor logic, discrete hardware components, or any combination of these components. A general-purpose processor can be a microprocessor, but in the alternative, the processor can be any conventional processor, controller, microcontroller, or state machine. The processor can also be implemented as a combination of computing devices, e.g., a combination of a DSP and a microprocessor, multiple microprocessors, one or more microprocessors in conjunction with a DSP, and / or any other such configuration.

[0123] The steps of a method or algorithm described in connection with the disclosure herein can be embodied directly in hardware, in a software module executed by a processor, or in a combination of the two. A software module may reside in RAM memory, flash memory, ROM memory, EPROM memory, EEPROM memory, registers, a hard disk, a removable disk, a CD-ROM, or any other form of storage medium known in the art. An exemplary storage medium is coupled to the processor such that the processor can read information from, or write information to, the storage medium. In an alternative, the storage medium may be integral to the processor. The processor and the storage medium may reside in an ASIC. The ASIC may reside in a user terminal. In an alternative, the processor and the storage medium may reside as discrete components in a user terminal.

[0124] In one or more exemplary designs, the functions may be implemented in hardware, software, firmware, or any combination thereof. If implemented in software, the functions may be stored on or transmitted over as one or more instructions or code on a computer-readable medium. Computer-readable media includes both computer storage media and communication media including any medium that facilitates transfer of a computer program from one location to another. A storage media may be any available media that can be accessed by a general purpose or special purpose computer. By way of example, and not limitation, such computer-readable media can comprise RAM, ROM, EEPROM, CD-ROM or other optical disk storage, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and that can be accessed by a general purpose or special purpose computer or a general purpose or special purpose processor. Additionally, any connection is properly termed a computer-readable medium. For example, if the software is transmitted from a website, server, or other remote source using a coaxial cable, fiber optic cable, twisted pair, DSL, or wireless technologies such as infrared, radio, and microwave, then the coaxial cable, fiber optic cable, twisted pair, DSL, or wireless technologies such as infrared, radio, and microwave are included in the definition of medium. As used herein, disk and disc include compact disc (CD), laser disc, optical disc, digital versatile disc (DVD), floppy disk, and Blu-ray disc where disks usually reproduce data magnetically, while discs reproduce data optically with lasers. Combinations of the above should also be included within the scope of computer-readable media.

Claims

1. A DMA system for countering power consumption attacks, characterized in that, Comprising: A data receiving module configured to receive communication data sent by a bus to a target hardware; A power consumption adjustment module configured to generate inversion data based on inversion data in a predetermined policy or according to power consumption conditions of the target hardware, and insert the inversion data into the communication data in a predetermined manner; A data sending module configured to send the communication data with inserted inversion data to the target hardware; A control module configured to receive communication data on the bus through the data receiving module, and configure the functions of the power consumption adjustment module and the data sending module based on the communication data; The power consumption adjustment module includes a power consumption adjustment configuration module and a power consumption adjustment execution module. Among them, the power consumption adjustment configuration module is configured to send the inversion data in the predetermined policy to the power consumption adjustment execution module based on the configuration of the control module or randomly generate inversion data according to the configuration of the power management unit of the target hardware and the simulated power consumption of the target hardware given by a simulation tool, and send the inversion data to the power consumption adjustment execution module; the power consumption adjustment execution module is configured to generate a corresponding inversion data insertion scheme in combination with the bus protocol of the data sending module according to the inversion data received from the power consumption adjustment configuration module, and send the communication data containing the inversion data to the data sending module according to the inversion data insertion scheme; Wherein, the predetermined policy is used to select the optimal inversion data for anti-power consumption attack according to the target hardware; when there is no predetermined policy, the power consumption adjustment module randomly generates inversion data; The insertion scheme includes inserting the inversion data into a data frame that does not affect the calculation of the original communication data on the target hardware; The inversion data is used to achieve corresponding level inversion on the target hardware to confuse the power consumption of the target hardware.

2. The system according to claim 1, wherein The data sending module includes: A bus interface module configured to send the communication data containing the inversion data to the target hardware module; A channel control module that selects a corresponding bus interface module according to the control of the control module, and receives the communication data containing the inversion data from the power consumption adjustment execution module and forwards it to the corresponding bus interface module.

3. The system according to claim 2, wherein The data sending module further includes: A channel register module configured to configure the bus interface function according to the configuration of the control module.

4. The system according to claim 1, characterized in that Further comprising: A status feedback module configured to feedback the status of the communication data sent to the target hardware to the outside.

5. The system according to claim 1, wherein Further comprising: An interrupt module configured to initiate corresponding interrupts to the CPU according to the sending situation of the communication data.

6. A method for implementing countermeasure against power consumption attacks, characterized in that, Comprising: Receiving, by the data receiving module, communication data sent by the bus to the target hardware; Generating, by the power consumption adjustment module, inversion data based on inversion data in a predetermined policy or according to power consumption conditions of the target hardware, and inserting the inversion data into the communication data in a predetermined manner; Sending, by the data sending module, the communication data with inserted inversion data to the target hardware; The control module receives communication data on the bus through the data receiving module, and configures the functions of the power consumption adjustment module and the data sending module based on the communication data; The power consumption adjustment module includes a power consumption adjustment configuration module and a power consumption adjustment execution module. Among them, the power consumption adjustment configuration module sends the inversion data in the predetermined strategy to the power consumption adjustment execution module based on the configuration of the control module, or randomly generates inversion data according to the configuration of the power management unit of the target hardware and the simulated power consumption of the target hardware given by the simulation tool, and sends the inversion data to the power consumption adjustment execution module; the power consumption adjustment execution module generates a corresponding inversion data insertion scheme according to the inversion data received from the power consumption adjustment configuration module in combination with the bus protocol of the data sending module, and sends the communication data containing the inversion data to the data sending module according to the inversion data insertion scheme; Among them, the predetermined strategy is the optimal inversion data for anti-power consumption attack selected according to the relevant power consumption analysis of the target hardware; when there is no predetermined strategy, the power consumption adjustment module randomly generates inversion data; The insertion scheme includes inserting the inversion data into the data frame that will not affect the original communication data calculated by the target hardware; The inversion data is used to achieve the corresponding level inversion on the target hardware to confuse the power consumption of the target hardware.

7. A computer device, characterized in that, Comprising: At least one processor; And A memory, the memory stores computer instructions that can be run on the processor, and when the instructions are executed by the processor, the steps of the method described in claim 6 are implemented.

8. A computer-readable storage medium, the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the method described in claim 6 are implemented.

Citation Information

Patent Citations

  • Encryption key transmission with power analyis attack resistance

    US20130151842A1

  • Bus security protection method and apparatus

    US20180137311A1