A low-cost trusted loading method and system for an embedded main control chip

By constructing a trusted loading method of star trust chain and low-cost general-purpose MCU, the problem of expensive trusted loading chips in embedded devices is solved, and a low-cost and reliable embedded master chip startup process is realized to ensure data security.

CN116880331BActive Publication Date: 2025-07-22JIANGSU WISCOM TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202311044957.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-08-18
Publication Date
2025-07-22
Estimated Expiration
2043-08-18

AI Technical Summary

Technical Problem

Trusted loading chips in existing embedded devices are expensive, resulting in increased costs of embedded devices and risk of program tampering, affecting data security.

Method used

Using a microcontroller with a serial peripheral interface and built-in memory, the program writing and metric value storage are controlled through jumpers and jumper caps, and a star trust chain is constructed to realize step by step trust loading of the main control chip. A low-cost general purpose MCU is used as a trusted loading chip, combining the SPI interface with external nonvolatile memory for program measurement and loading.

Benefits of technology

It realizes low-cost trusted loading, ensures the reliability and immutability of program loading, reduces the overall cost of embedded devices, and ensures data security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116880331B_ABST
    Figure CN116880331B_ABST
Patent Text Reader

Abstract

The present invention discloses a low-cost trusted loading method and system for an embedded main control chip. A microcontroller with a serial peripheral interface and an internal memory is selected. External program burning and measurement value storage are controlled through jumpers and jumper caps, and the uboot program is stored in the internal memory. The main control chip is respectively connected to the microcontroller and an external non-volatile memory through a first serial peripheral interface and a second serial peripheral interface. The kernal program and / or other application programs are stored in the external non-volatile memory. When the device is powered on, the microcontroller controls the main control chip to be in a reset state. The microcontroller reads the uboot program and measures the uboot program. If the measurement passes, the main control chip reads the uboot program and completes the uboot startup. Then, by reading the kernal program and loading it, the startup of the main control chip is completed. The present invention realizes the step-by-step trusted loading of the uboot, kernal, and APP of the main control chip by constructing a star-shaped trust chain with a trusted loading chip as the core.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of embedded design and control technologies, and particularly relates to a low-cost trusted loading method and system for an embedded main control chip. Background Art

[0002] With the continuous development of embedded control technologies, embedded devices are increasingly widely used in the industrial field. A lot of important data in industrial production undergoes data calculation, data transmission, data verification, etc. through embedded devices. Therefore, once the program of an embedded device is tampered with after being attacked, it may lead to serious consequences such as data leakage and data forgery of the data processed by the embedded device. However, currently, trusted loading chips are expensive, and adding a trusted loading chip will significantly increase the cost of the embedded device. Summary of the Invention

[0003] The purpose of the present invention is to provide a low-cost trusted loading method for an embedded main control chip, which solves the problem of trusted loading during the startup of the embedded main control chip at low cost.

[0004] To achieve the above technical objectives, the present invention adopts the following solutions:

[0005] A low-cost trusted loading method for an embedded main control chip, comprising:

[0006] Select a microcontroller with a serial peripheral interface and an internal memory, lead its first data input interface to the outside through a first jumper, and connect its second data input interface to the power supply through a second jumper; after plugging a jumper cap on the first jumper, perform external program burning on the microcontroller, then unplug the jumper cap, plug the jumper cap on the second jumper, obtain the program to be measured through the serial peripheral interface, store the measurement value of the uboot program, the measurement value of the kernal program, and the uboot program in the internal memory, and unplug the jumper cap;

[0007] Connect the main control chip to the microcontroller and an external non-volatile memory through a first serial peripheral interface and a second serial peripheral interface respectively, and the microcontroller can control the reset of the main control chip; the external non-volatile memory has a serial peripheral interface, and the kernal program and / or other application programs are stored in the external non-volatile memory;

[0008] When the device is powered on, the microcontroller controls the main control chip to be in a reset state, the microcontroller reads the uboot program and measures the uboot program. If the measurement passes, the main control chip reads the uboot program through the first serial peripheral interface and completes the uboot startup. Then, the main control chip reads the kernal program through the second serial peripheral interface and sends it to the microcontroller for measurement. If the measurement passes, the main control chip loads the kernal program to complete the startup of the main control chip.

[0009] As a preferred embodiment, plug the second jumper onto the jumper cap, and write the measurement value after a high level is detected at the second data input interface.

[0010] As a preferred embodiment, the method of writing the measurement value is as follows:

[0011] Send the program to be measured to the microcontroller through the Serial Peripheral Interface. The microcontroller uses its unique device ID as the reference measurement value, measures the program according to a preset encryption algorithm, and then writes the measurement value and / or the program to the built-in memory.

[0012] As a preferred embodiment, the built-in memory also stores the measurement values of other application programs.

[0013] As a preferred embodiment, when loading other application programs, first measure them through the microcontroller. After the measurement passes, notify the main control chip to load the corresponding program through communication via the Serial Peripheral Interface.

[0014] As a preferred embodiment, the method for the microcontroller to control the reset of the main control chip is as follows:

[0015] Connect a general-purpose input / output interface of the microcontroller to the reset interface of the main control chip, and output a high / low level through this general-purpose input / output interface to control the reset of the main control chip. Specifically, when the device is powered on, the microcontroller pulls down the level of the reset pin of the main control chip, so that the main control chip is always in the reset state. Then the microcontroller reads the uboot program of the main control chip in the built-in memory for measurement. If the measurement fails, continuously pull down the level of the reset pin of the main control chip to prohibit the main control chip from starting. If the measurement passes, pull up the level of the reset pin of the main control chip, and the main control chip starts.

[0016] As a preferred embodiment, after the measurement passes, the microcontroller controls the main control chip to work normally. The trusted loading chip simulates the Serial Peripheral Interface to send the uboot program from the external non-volatile memory to the main control chip. After the main control chip starts, it will regard the trusted loading chip as an external non-volatile memory of the SPI interface to read the uboot program. At this time, the trusted loading chip simulates the external non-volatile memory of the SPI interface to send the uboot program to the main control chip.

[0017] As a preferred embodiment, the built-in memory is a non-volatile memory built in the MCU; preferably on-chip Flash, and on-chip Flash is the built-in memory that most traditional chips currently have.

[0018] As a preferred embodiment, the external non-volatile memory is a NOR Flash, ferroelectric memory, magnetoresistive memory or phase change memory. NOR Flash is preferably used, and NOR Flash is the most widely used memory at present.

[0019] Another object of the present invention is to provide an embedded main control chip low-cost trusted loading system, which includes a main control chip, a microcontroller and an external non-volatile memory;

[0020] The microcontroller has a serial peripheral interface and an internal memory. The first data input interface of the microcontroller is led to the outside through a first jumper, and the second data input interface is connected to the power supply through a second jumper; a general input / output interface of the microcontroller is connected to the reset interface of the main control chip, and the main control chip is reset by outputting high / low levels; the serial peripheral interface of the microcontroller is connected to the first serial peripheral interface of the main control chip;

[0021] The external non-volatile memory has a serial peripheral interface, and its serial peripheral interface is connected to the second serial peripheral interface of the main control chip; the kernal program and / or other application programs are stored in the external non-volatile memory;

[0022] After the first jumper is plugged with a jumper cap, the microcontroller is externally programmed, and then the jumper cap is removed. The second jumper is plugged with a jumper cap, and the program to be measured, including the uboot program, is obtained through the serial peripheral interface. The calculated measurement value and the uboot program are stored in the internal memory, and then the jumper cap is removed; when the device is powered on, the microcontroller controls the main control chip to be in a reset state. The microcontroller reads the uboot program and measures the uboot program. If the measurement passes, the main control chip reads the uboot program through the first serial peripheral interface and completes the uboot startup. Then, the main control chip reads the kernal program through the second serial peripheral interface and sends it to the microcontroller for measurement. If the measurement passes, the main control chip loads the kernal program and completes the startup of the main control chip.

[0023] The present invention has the following beneficial effects:

[0024] The present invention realizes the hierarchical trusted loading of the uboot, kernal and APP of the main control chip by constructing a star-shaped trust chain with a low-cost general-purpose MCU-based trusted loading chip as the core. Since the trusted loading chip has complete network isolation, and the program writing and measurement value writing of the trusted loading chip both require physical intervention by externally plugging a jumper cap, it is ensured that the program and measurement value of the trusted loading chip cannot be tampered with, ensuring the reliability of each level of program loading, and realizing the use of a low-cost general-purpose chip as the trusted loading chip. Description of the Drawings

[0025] To more clearly illustrate the technical solution of the present invention, the accompanying drawings required for the embodiments will be briefly introduced below. Obviously, the accompanying drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can be obtained based on these drawings.

[0026] Figure 1 is the hardware architecture of the trusted loading method.

[0027] Figure 2 is the hardware wiring of the trusted loading method provided by the embodiment of the present invention.

[0028] Figure 3 is the flowchart of the trusted loading chip program burning and measurement value writing provided by the embodiment of the present invention.

[0029] Figure 4 is the flowchart of the trusted loading method provided by the embodiment of the present invention. Embodiment

[0030] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, rather than all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.

[0031] It should be understood that the step numbers used in the text are only for convenient description and do not limit the execution order of the steps.

[0032] It should be understood that the terms used in the specification of the present invention are only for the purpose of describing specific embodiments and are not intended to limit the present invention. As used in the specification of the present invention and the appended claims, unless the context clearly indicates otherwise, the singular forms "a", "an" and "the" are intended to include the plural forms.

[0033] The terms "comprising" and "including" indicate the presence of the described features, wholes, steps, operations, elements and / or components, but do not exclude the presence or addition of one or more other features, wholes, steps, operations, elements, components and / or their combinations.

[0034] The term "and / or" refers to any combination and all possible combinations of one or more of the associated listed items, and includes these combinations. Embodiment

[0035] The hardware architecture of the trusted loading method described in the present invention is as Figure 1As shown in the figure, a low-cost MCU with an SPI interface and on-chip FLASH is used as the trusted loading chip. The trusted loading chip can control the reset of the main control chip and communicate with the main control chip through the SPI interface. The uboot program of the main control chip is stored in the on-chip FLASH of the trusted loading chip, and the kernal program is stored in the NOR FLASH of the SPI interface.

[0036] When programming the trusted loading chip, the first jumper needs to be inserted into the jumper cap. The program burned here is some programs necessary for the trusted loading chip to execute its own functions, such as the measurement value encryption program. After the program burning is completed, remove the jumper cap of the first line. Then insert the jumper cap of the second jumper, and send the uboot program to be encrypted to the trusted loading chip through the SPI interface. The trusted loading chip uses its unique device ID as the reference measurement value, measures the uboot program according to a specific encryption algorithm, and writes the uboot program and the measurement value into the on-chip FLASH. Then send the kernal program to the trusted loading chip through the SPI interface. The trusted loading chip measures the kernal program according to a specific encryption algorithm and writes the measurement value of the kernal program into the on-chip FLASH. Then use the same method to write the measurement values of other APP programs to be run into the on-chip FLASH. After all the measurement values are written, remove the jumper cap of the second jumper.

[0037] After the programming of the trusted loading chip and the writing of the measurement values are completed, when the device is powered on, the trusted loading chip pulls down the level of the reset pin of the main control chip, so that the main control chip is always in the reset state. Then the trusted loading chip reads the uboot program of the main control chip in the on-chip FLASH for measurement. If the measurement fails, the level of the reset pin of the main control chip is continuously pulled down to prohibit the main control chip from starting; if the measurement passes, the level of the reset pin of the main control chip is pulled up, and the main control chip starts. After the main control chip starts, it regards the trusted loading chip as the NOR FLASH of the SPI interface to read the uboot program. At this time, the trusted loading chip simulates the NOR FLASH of the SPI interface and sends the uboot program to the main control chip. After the uboot program of the main control chip starts, it reads the kernal program in the NOR FLASH of the SPI interface through another SPI interface, and sends the kernal program to the trusted loading chip for measurement through the SPI interface between the trusted loading chip and the main control chip. If the measurement passes, the trusted loading chip notifies the main control chip to load the kernal program through the SPI interface, thus completing the entire trusted startup process. Embodiment

[0038] This embodiment provides a specific trusted loading system. As Figure 2As shown, in this embodiment, the microprocessor (trusted loading chip) uses GD32F103, which supports the SPI interface; the reset signal RESET of the main control chip is controlled by GPIO1 of the trusted loading chip GD32F103. When GPIO1 outputs a low level, the main control chip remains in the reset state, and when GPIO1 outputs a high level, the main control chip cancels the reset state; the main control chip communicates with the trusted loading chip GD32F103 through the SPI1 interface; the main control chip accesses the SPI interface NOR FLASH through the SPI2 interface, and the kernal program of the main control chip is stored in this NOR FLASH. The TDI interface of the JTAG pin of the trusted loading chip is led to the outside through the first jumper, so programming can only be performed after the jumper cap is plugged into the first jumper; the GPIO2 pin of the trusted loading chip is connected to the 3.3V power supply through the second jumper. When it is necessary to write measurement values to the trusted loading chip, the second jumper cap must be plugged in first, and the measurement value can be written only after GPIO2 detects a high level.

[0039] Figure 3 It is the flowchart of the program programming and encryption label writing of the trusted loading chip. When programming the program of the trusted loading chip, the jumper cap of the first jumper needs to be plugged in. After the program programming is completed, the jumper cap of the first jumper is unplugged. Then plug in the jumper cap of the second jumper, and send the uboot program to be encrypted to the trusted loading chip through the SPI interface. The trusted loading chip GD32F103 uses its own unique 96-bit ID as the reference measurement value, measures the uboot program according to the SM3 encryption algorithm, and writes the uboot program and the measurement value to the on-chip FLASH. Then send the kernal program to the trusted loading chip through the SPI interface. The trusted loading chip measures the kernal program according to the SM3 encryption algorithm and writes the measurement value of the kernal program to the on-chip FLASH. Then use the same method to measure other APP programs to be run and write the measurement values to the on-chip FLASH. After all the measurement values are written, unplug the jumper cap of the second jumper.

[0040] Figure 4It is a flowchart of the trusted loading method. When the device is powered on, the trusted loading chip's GPIO1 outputs a low level, keeping the main control chip in a reset state all the time. Then the trusted loading chip reads the uboot program of the main control chip in the on-chip FLASH for measurement. If the measurement fails, GPIO1 continuously outputs a low level to prohibit the main control chip from starting; if the measurement passes, GPIO1 outputs a high level and the main control chip starts. After the main control chip starts, it reads the uboot program through the SPI1 interface, and the trusted loading chip simulates the SPI interface NOR FLASH to send the uboot program to the main control chip. After the uboot program of the main control chip starts, it reads the kernal program in the SPI interface NOR FLASH through the SPI2 interface and sends the kernal program to the trusted loading chip for measurement through the SPI1 interface. If the measurement passes, the trusted loading chip notifies the main control chip to load the kernal program through the SPI1 interface; if the measurement fails, it notifies the main control chip to abandon loading the kernal program, thus completing the entire trusted startup process. All APP programs that need to run after the main control chip starts need to be measured in advance through the SM3 encryption algorithm and the measurement values are written into the trusted loading chip. When an APP program needs to be loaded during the operation of the main control chip program, first send the APP program to the trusted loading chip through the SPI1 interface. After the trusted loading chip measures the APP program, if the measurement passes, it notifies the main control chip program to load the APP; if the measurement fails, it notifies the main control chip to abandon loading the APP program, thus realizing the trusted loading of the APP.

Claims

1. A low-cost trusted loading method for an embedded main control chip, characterized in that Comprising: Select a microcontroller with a serial peripheral interface and built-in memory. Lead its first data input interface to the outside through a first jumper, and connect its second data input interface to the power supply through a second jumper. After plugging the jumper cap on the first jumper, perform external program burning on the microcontroller. Then unplug the jumper cap, plug the jumper cap on the second jumper, obtain the program to be measured through the serial peripheral interface, store the measurement value of the uboot program, the measurement value of the kernel program, and the uboot program in the built-in memory, and then unplug the jumper cap. Connect the main control chip to the microcontroller and the external non-volatile memory through the first serial peripheral interface and the second serial peripheral interface respectively. The microcontroller can control the reset of the main control chip. The external non-volatile memory has a serial peripheral interface, and the kernel program and / or other application programs are stored in the external non-volatile memory. When the device is powered on, the microcontroller controls the main control chip to be in the reset state. The microcontroller reads the uboot program and measures the uboot program. If the measurement passes, the main control chip reads the uboot program through the first serial peripheral interface and completes the uboot startup. Then the main control chip reads the kernel program through the second serial peripheral interface and sends it to the microcontroller for measurement. If the measurement passes, the main control chip loads the kernel program and completes the startup of the main control chip.

2. The method according to claim 1, characterized in that Plug the jumper cap on the second jumper, and write the measurement value after detecting a high level at the second data input interface.

3. The method according to claim 2, wherein The way of writing the measurement value is: Send the program to be measured to the microcontroller through the serial peripheral interface. The microcontroller uses its unique device ID as the reference measurement value, measures the program according to a preset encryption algorithm, and then writes the measurement value and / or the program to the built-in memory.

4. The method according to claim 1, characterized in that The measurement values of other application programs are also stored in the built-in memory.

5. The method according to claim 4, wherein When loading other application programs, first measure them through the microcontroller. After the measurement passes, notify the main control chip to load the corresponding program through serial peripheral interface communication.

6. The method according to claim 1, wherein After the measurement passes, the microcontroller controls the main control chip to work normally. The trusted loading chip simulates the serial peripheral interface of the external non-volatile memory and sends the uboot program to the main control chip.

7. The method according to claim 1, wherein The way for the microcontroller to control the reset of the main control chip is: Connect a general-purpose input / output interface of the microcontroller to the reset interface of the main control chip, and control the reset of the main control chip by outputting high / low level through this general-purpose input / output interface.

8. The method according to claim 1, wherein The built-in memory is a non-volatile memory built in the MCU.

9. The method according to claim 1, wherein The external non-volatile memory is a NOR Flash, ferroelectric memory, magnetoresistive memory or phase change memory.

10. An embedded main control chip low-cost trusted loading system, characterized in that, Including a main control chip, a microcontroller and an external non-volatile memory; The microcontroller has a serial peripheral interface and a built-in memory. The first data input interface of the microcontroller is led to the outside through a first jumper, and the second data input interface is connected to the power supply through a second jumper. A general-purpose input / output interface of the microcontroller is connected to the reset interface of the main control chip, and the main control chip is reset by outputting high / low level. The serial peripheral interface of the microcontroller is connected to the first serial peripheral interface of the main control chip; The external non-volatile memory has a serial peripheral interface, and its serial peripheral interface is connected to the second serial peripheral interface of the main control chip; The kernel program and / or other application programs are stored in the external non-volatile memory; After inserting the jumper cap on the first jumper, perform external program burning on the microcontroller, then remove the jumper cap, insert the jumper cap on the second jumper, obtain the program to be measured through the serial peripheral interface, store the measurement values of the uboot program, the measurement values of the kernel program, and the uboot program in the built-in memory, and then remove the jumper cap; when the device is powered on, the microcontroller controls the main control chip to be in a reset state, the microcontroller reads the uboot program and measures the uboot program. If the measurement passes, the main control chip reads the uboot program through the first serial peripheral interface and completes the uboot startup. Then, the main control chip reads the kernel program through the second serial peripheral interface and sends it to the microcontroller for measurement. If the measurement passes, the main control chip loads the kernel program to complete the startup of the main control chip.

Citation Information

Patent Citations

  • A system for monitoring cable interface connections in a network

    CN101263682A

  • Method for designing domestic BMC (Baseboard Management Controller) chip trusted firmware

    CN106127056A