Methods, apparatus, devices and storage media for secure access to chip data

CN117688603BActive Publication Date: 2026-08-14GUANGZHOU ZHONO ELECTRONICS TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-12-11
Publication Date
2026-08-14

AI Technical Summary

Technical Problem

[0004]本申请提供了一种芯片数据安全访问方法、装置、设备及存储介质,解决了难以对芯片内部数据形成有效保护的问题,本方案能够在对主机端进行验证后还对工作环境进行验证,以有效地对芯片内部数据形成保护

Benefits of technology

[0019]本申请方案在主机端访问从机端对应的芯片所存储的数据的过程,不仅主机端与从机端需要进行双向身份验证,还需要对从机端所处的工作环境进行检测,进而在正常的工作环境下才允许主机端访问从机端上的目标数据,而在非正常的工作环境下禁止主机端访问从机端上的目标数据,从而有效地降低芯片内存储数据出现泄露的风险,对芯片内部数据形成有效保护。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117688603B_ABST
    Figure CN117688603B_ABST
Patent Text Reader

Abstract

This application provides a method, apparatus, device, and storage medium for secure access to chip data, relating to the field of computer technology. It solves the problem of difficulty in effectively protecting the data inside a chip. In the process of accessing the data stored on the chip corresponding to the slave device from the host side, this solution requires not only two-way authentication between the host and slave devices, but also detection of the working environment of the slave device. Thus, the host is allowed to access the target data on the slave device only under normal working conditions, while access to the target data on the slave device is prohibited under abnormal working conditions. This effectively reduces the risk of data leakage stored in the chip and provides effective protection for the data inside the chip.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technology, and in particular to a method, apparatus, device and storage medium for secure access to chip data. Background Technology

[0002] With the development of information technology, the use of chips is becoming increasingly widespread, making data security ever more important. Electronic devices such as industrial control computers and printers often contain one or more chips, each performing different functions or working together to achieve the same goal. These chips store critical data, and the frequent access to these chips by different users, as well as data retrieval between different chips, increases the risk of data leakage.

[0003] In related technologies, to ensure data security, data encryption is usually used to reduce the risk of data leakage, or authentication is used to authenticate visitors. However, regardless of whether data encryption or authentication is used, the risk of data leakage in the chip remains high, making it difficult to effectively protect the data inside the chip. Summary of the Invention

[0004] This application provides a method, apparatus, device, and storage medium for secure access to chip data, which solves the problem of difficulty in effectively protecting the data inside the chip. This solution can verify the working environment after verifying the host side, so as to effectively protect the data inside the chip.

[0005] In a first aspect, this application provides a method for secure access to chip data, wherein any one of a plurality of slave terminals communicating with a host terminal via a bus, wherein the host terminal and the slave terminal correspond to different chips, the method for secure access to chip data includes:

[0006] In response to access requests initiated by the host, perform two-way authentication with the host to authorize read and write access to the host.

[0007] If it is determined that the host has read permissions, grant read permissions to the host so that the host can access the internal storage data, and monitor the data to be accessed by the host.

[0008] If it is determined that the data to be accessed on the host is the first target data in the stored data, then a working environment check is performed to determine whether it meets the set working environment.

[0009] If the test results determine that the current working environment does not meet the settings, the host is prohibited from accessing the first target data.

[0010] Secondly, this application also provides a chip data security access device, applied to any one of a plurality of slave terminals communicating with a host terminal via a bus, wherein the host terminal and the slave terminal correspond to different chips, and the chip data security access device includes:

[0011] The first verification module is configured to respond to access requests initiated by the host and perform two-way authentication with the host to authenticate read and write permissions for the host.

[0012] The access monitoring module is configured to grant read permissions to the host when it is determined that the host has read permissions, so that the host can access the internal storage data, and to monitor the data to be accessed by the host.

[0013] The second verification module is configured to perform a working environment check if it determines that the data to be accessed by the host is the first target data in the stored data, in order to determine whether it meets the set working environment.

[0014] The access management module is configured to prohibit the host from accessing the first target data if the detection results determine that the current working environment does not meet the settings.

[0015] Thirdly, this application also provides an electronic device comprising:

[0016] One or more processors;

[0017] A storage device for storing one or more programs, which, when executed by one or more processors, enable the one or more processors to implement the chip data secure access method described above.

[0018] Fourthly, this application also provides a storage medium storing computer-executable instructions, which, when executed by a processor, perform the chip data security access method described above.

[0019] The proposed solution requires that the host access the data stored in the corresponding chip on the slave device through two-way authentication between the host and slave devices, as well as detection of the slave device's operating environment. Under normal operating conditions, the host is allowed to access the target data on the slave device, while under abnormal operating conditions, the host is prohibited from accessing the target data on the slave device. This effectively reduces the risk of data leakage within the chip and provides effective protection for the data inside the chip. Attached Figure Description

[0020] Figure 1 A schematic diagram illustrating the steps of a chip data secure access method provided in an embodiment of this application;

[0021] Figure 2A schematic diagram illustrating the steps of a slave device verifying a memory chip according to an embodiment of this application;

[0022] Figure 3 A schematic diagram illustrating the steps of a slave device verifying a security chip according to an embodiment of this application;

[0023] Figure 4 A schematic diagram of a structure in which multiple chips communicate via a bus, according to an embodiment of this application;

[0024] Figure 5 This is a schematic diagram of the structure of a chip data security access device provided in an embodiment of this application;

[0025] Figure 6 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation

[0026] The embodiments of this application will be further described in detail below with reference to the accompanying drawings and examples. It should be understood that the specific embodiments described herein are merely illustrative of the embodiments of this application and are not intended to limit the scope of this application. Furthermore, it should be noted that, for ease of description, the accompanying drawings only show the parts related to the embodiments of this application, not all structures. Those skilled in the art, after reading this specification, should be able to conceive that any combination of technical features can constitute an optional implementation method, provided that the technical features do not contradict each other.

[0027] The terms "first," "second," etc., used in the specification and claims of this application are used to distinguish similar objects and not to describe a specific order or sequence. It should be understood that such use of data can be interchanged where appropriate so that embodiments of this application can be implemented in orders other than those illustrated or described herein, and the objects distinguished by "first," "second," etc., are generally of the same class and the number of objects is not limited; for example, a first object can be one or more. Furthermore, in the specification and claims, "and / or" indicates at least one of the connected objects, and the character " / " generally indicates that the preceding and following objects are in an "or" relationship. In the description of this application, "multiple" means two or more, and "several" means one or more.

[0028] The chip communicates with other chips via a bus to exchange data. In bus communication, the master end acts as the sender of instructions, while the slave end acts as the receiver of instructions. In this application, the master end and slave end correspond to different chips. Figure 1 The diagram illustrates the steps of a chip data security access method according to an embodiment of this application. This method can be applied to a chip acting as a slave device, and the specific steps are as follows:

[0029] Step S110: In response to the access request initiated by the host, perform two-way authentication with the host to authorize the host to read and write.

[0030] After the host initiates a corresponding access request, the slave receives information associated with that request. The slave then performs two-way authentication with the host to verify the host's read and write permissions. For example, the slave and host can perform two-way authentication based on a shared-key authentication scheme, such as each generating a public-private key pair, exchanging the public key for data encryption, and then decrypting the data using the corresponding private key to ensure data integrity and authenticity. Alternatively, the slave and host can also perform two-way authentication based on a publicly available encryption algorithm, such as using the MD5 (Message-Digest Algorithm 5) algorithm.

[0031] Step S120: If it is determined that the host has read permission, grant read permission to the host so that the host can access the internal storage data, and monitor the data to be accessed by the host.

[0032] After completing two-way authentication, the slave device can determine that communication with the master device is secure. Accordingly, the slave device can determine that the master device has read permissions and grants read permissions to the master device, allowing the master device to access the stored data on the slave device. Furthermore, during the master device's data access process, the slave device also needs to monitor the data to be accessed by the master device to determine whether the data to be accessed is the first target data in the stored data. This first target data is the data stored on the slave device that needs protection. It is conceivable that a pre-set storage space can be allocated within the slave device to store this first target data.

[0033] For example, the slave device monitors the storage address of the data to be accessed, and by comparing the storage address of the data to be accessed with the storage address of the first target data, it can determine whether the data accessed by the host is the first target data in the stored data.

[0034] Step S130: If it is determined that the data to be accessed on the host is the first target data in the stored data, then a working environment test is performed to determine whether it meets the set working environment.

[0035] If the data to be accessed by the master device is determined to be the first target data in the stored data, the slave device needs to perform an operating environment check. This check verifies whether other slave devices communicating on the bus are verifiable chips, thus determining whether the current operating environment of the slave device conforms to the set operating environment. It's conceivable that conforming to the set operating environment refers to pre-defined requirements for the operating environment; for example, if all chips communicating on the same bus are required to pass verification, then the current operating environment is considered to conform to the set operating environment.

[0036] Step S140: If the detection results indicate that the current working environment does not meet the settings, the host terminal is prohibited from accessing the first target data.

[0037] It is conceivable that, based on the detection results of the aforementioned working environment test, if the slave device determines that it is currently in a working environment that does not meet the settings (i.e., at least one chip fails verification), the slave device will prohibit the master device from accessing the first target data. Conversely, if the slave device determines that it is currently in a working environment that meets the settings, it means that the current working environment is secure, and thus the master device is allowed to access the first target data.

[0038] It is understandable that if the slave device is currently in an environment that does not meet the specified settings, then the slave device can determine that there is a chip among the chips that use the bus for communication that cannot pass verification. In this case, if the slave device allows the master device to access the first target data, there is a significant risk of data leakage. Therefore, in order to ensure data security, the slave device prohibits the master device from accessing the first target data to avoid leakage of the first target data.

[0039] As can be seen from the above scheme, in addition to two-way authentication between the host and slave, the scheme of this application also needs to detect the working environment of the slave. In this way, the host is allowed to access the target data on the slave only under normal working conditions, while the host is prohibited from accessing the target data on the slave under abnormal working conditions. This effectively reduces the risk of leakage of data stored in the chip and provides effective protection for the data inside the chip.

[0040] In some embodiments, when it is determined that the data to be accessed by the master is the first target data in the storage data of the slave, the slave initiates an operating environment detection. To do this, the slave verifies each of the other slaves communicating on the bus to determine whether each chip acting as a slave is legitimate. Furthermore, if all chips are legitimate, the slave determines that it is currently in a working environment that meets the settings. Conversely, if at least one chip is illegitimate, the slave determines that it is currently in a working environment that does not meet the settings.

[0041] It is understandable that during the working environment detection process, the slave device that initiates the verification changes from a slave to a master. That is, the slave device that initiates the verification is a master relative to other slave devices, and thus the slave device verifies other slave devices one by one.

[0042] In one embodiment, for the storage chip, the slave device acts as the initiator of verification. The second target data it stores has a backup on the storage chip. This backup data is identical to the second target data, but their storage locations differ. The second target data is stored on the slave device, while the backup data is stored on the storage chip. The target area of ​​the storage chip is a pre-defined storage space used to store the backup data.

[0043] Figure 2 This is a schematic diagram illustrating the steps of a slave device verifying a memory chip according to an embodiment of this application. The specific steps are as follows:

[0044] Step S210: If the currently verified slave device is a storage chip, send a read command to the storage chip to obtain the backup data located in the target area of ​​the storage chip.

[0045] Step S220: After obtaining the backup data, compare the backup data with the second target data to determine whether the backup data is the same as the second target data.

[0046] Step S230: If the backup data is the same as the second target data, then the chip corresponding to the currently verified slave end is determined to be legitimate.

[0047] It is understandable that during the process of one slave device verifying another slave device, when the current slave device being verified is a storage chip, the slave device initiating the verification sends a read command to the storage chip to obtain the backup data in the target area of ​​the storage chip.

[0048] After acquiring the backup data, the slave device compares the second target data with the acquired backup data to determine if they are the same. For example, in one embodiment, when comparing the second target data with the acquired backup data, the slave device can calculate a first verification value corresponding to the backup data and a second verification value corresponding to the second target data based on a preset authentication algorithm, and then compare the first verification value and the second verification value to determine whether the first verification value and the second verification value are the same.

[0049] For example, the slave device can use algorithms such as MD5 or SHA1 as authentication algorithms to calculate a first checksum corresponding to the backup data and a second checksum corresponding to the second target data, and then compare the two. If the first checksum and the second checksum are equal, the slave device can determine that the backup data and the second target data are the same, and thus the slave device can determine that the storage chip is legitimate, that is, the legitimacy of the storage chip has been verified.

[0050] It should be noted that in some embodiments, if the slave device does not receive the backup data sent by the currently verified slave device within a preset time or the received backup data fails verification, the chip corresponding to the currently verified slave device is determined to be invalid.

[0051] In one embodiment, for chips that are not memory chips, such as security chips or detection chips, the slave device, as the initiator of verification, needs to send an authentication command to the chip to initiate the verification of the chip. Figure 3 This is a schematic diagram illustrating the steps of a slave device verifying a security chip according to an embodiment of this application. The specific steps are as follows:

[0052] Step S310: If the currently verified slave device is a security chip, send an authentication command to the currently verified slave device to obtain encrypted data.

[0053] Step S320: After receiving the encrypted data, verify the encrypted data based on the preset authentication algorithm to determine whether the chip corresponding to the currently verified slave terminal is legitimate.

[0054] Step S330: If the encrypted data passes the verification, the chip corresponding to the currently verified slave device is determined to be legitimate.

[0055] Understandably, the slave device sends an authentication command to the currently verified security chip. This authentication command can be used to obtain encrypted data, which is the data encrypted by the currently verified slave device using a preset authentication algorithm to encrypt its own identity information. In other words, the chip receiving this authentication command needs to encrypt its own identity information using the preset authentication algorithm to obtain encrypted data, and then send this encrypted data back to the slave device.

[0056] After receiving the encrypted data, the slave device decrypts it using the same authentication algorithm to verify it, thereby determining the legitimacy of the chip corresponding to the currently verified slave device. It's conceivable that the slave device and the chip being verified could also employ a two-way authentication method, similar to the one used between the master and slave devices, to achieve the slave device's verification of the chip. Therefore, after the encrypted data passes verification, the slave device can determine that the currently verified chip is legitimate, meaning the security chip's legitimacy has been verified.

[0057] It should be noted that in some embodiments, if the slave device does not receive encrypted data sent by the currently verified slave device within a preset time or the received encrypted data fails verification, the chip corresponding to the currently verified slave device is determined to be invalid.

[0058] Therefore, the slave device initiates verification to other slave devices. By setting corresponding verification schemes for different types of chips, the slave device can verify the working environment of the slave device in combination with the corresponding functions of the chip, which helps to effectively protect the data inside the chip.

[0059] For example, Figure 4 This is a schematic diagram illustrating the structure of multiple chips communicating via a bus according to an embodiment of this application. The chips communicate via a communication bus such as an IIC bus or an SPI bus. Chip A is the slave device accessed by the master, while chips B, C, and D are other slave devices on the communication bus. Chips A, B, and C are all security chips, while chip D is a memory chip.

[0060] When verifying the legitimacy of chip B, chip A changes from a slave device to a master device, initiating communication with chip B. Chip A sends an authentication command to chip B. Upon receiving the authentication command, chip B encrypts its own identity information using a preset authentication algorithm and returns the result to chip A. After receiving the result from chip B, chip A uses the verification process corresponding to the authentication algorithm to determine whether chip B is legitimate.

[0061] Correspondingly, the legitimacy of chip C will also be verified. During the verification process of chip C, chip A changes from a slave device to a master device, thereby initiating communication with chip C. Chip A sends an authentication command to chip C. After receiving the authentication command, chip C encrypts its own identity information using a preset authentication algorithm and returns the result to chip A. After receiving the result returned by chip C, chip A uses the verification process corresponding to the authentication algorithm to determine whether chip C is legitimate.

[0062] Chip D acts as a storage chip. When verifying the legitimacy of chip D, chip A switches from a slave to a master identity, initiating communication with chip D. Chip A sends a read command to chip D to retrieve backup data from the target area. Upon receiving the read command, chip D returns the data at the corresponding address in the target area to chip A. After receiving the data, chip A compares and determines whether the backup data is identical to the second target data to verify the legitimacy of chip D.

[0063] Therefore, if chips B, C, and D are all valid (i.e., all other chips are valid), chip A is determined to be in a working environment that meets the settings, and thus chip A grants the host computer permission to access the first target data. Conversely, if any one of chips B, C, or D is invalid, chip A is determined to be in a working environment that does not meet the settings, and thus chip A prohibits the host computer from accessing the first target data.

[0064] In one embodiment, if the slave device determines, based on the detection results, that it is currently in a working environment that does not meet the settings, it sends error data to the master device. This error data is different from the first target data; it can be garbled data, random code, or other similar data. Therefore, even if data leakage occurs, the leaked data is only error data, effectively protecting the target data. Furthermore, upon receiving this error data, the master device can also determine that a counterfeit chip exists in the bus communication chip, thus alerting the user.

[0065] Figure 5 This is a schematic diagram of a chip data security access device provided in an embodiment of this application. The device is used to execute the chip data security access method provided in the above embodiment, and has the functional modules and beneficial effects corresponding to the execution method. As shown in the figure, the device includes a first verification module 501, an access monitoring module 502, a second verification module 503, and an access management module 504.

[0066] Specifically, the first verification module 501 is configured to respond to an access request initiated by the host and perform two-way authentication with the host to authenticate the host's read and write permissions; the access monitoring module 502 is configured to grant read permissions to the host if it is determined that the host has read permissions, allowing the host to access internal storage data, and to monitor the data to be accessed by the host; the second verification module 503 is configured to perform a working environment detection if it is determined that the data to be accessed by the host is the first target data in the storage data, to determine whether it conforms to the set working environment; and the access management module 504 is configured to prohibit the host from accessing the first target data if the detection result determines that the current working environment does not conform to the set working environment.

[0067] Based on the above embodiments, the second verification module 503 is further configured as follows:

[0068] Verification is initiated one by one for other slave devices communicating on the bus to determine whether each chip acting as a slave device is legitimate;

[0069] Assuming all chips are valid, determine the operating environment that meets the setup requirements.

[0070] Based on the above embodiments, the second verification module 503 is further configured as follows:

[0071] If the slave device being verified is a memory chip, a read command is sent to the memory chip to obtain backup data located in the target area of ​​the memory chip. The backup data is a backup of the second target data of this chip.

[0072] After obtaining the backup data, compare the backup data with the second target data to determine whether the backup data is the same as the second target data;

[0073] If the backup data is the same as the second target data, then the chip corresponding to the currently verified slave device is determined to be legitimate.

[0074] Based on the above embodiments, the second verification module 503 is further configured as follows:

[0075] Based on a preset authentication algorithm, the first verification value corresponding to the backup data and the second verification value corresponding to the second target data are determined.

[0076] Compare the first check value and the second check value to determine whether the first check value and the second check value are the same.

[0077] Based on the above embodiments, the second verification module 503 is further configured as follows:

[0078] If the currently verified slave device is not a storage chip, an authentication command is sent to the currently verified slave device to obtain encrypted data. The encrypted data is the data after the currently verified slave device has encrypted the identity information based on a preset authentication algorithm.

[0079] Upon receiving encrypted data, the encrypted data is verified based on a preset authentication algorithm to determine whether the chip corresponding to the currently verified slave device is legitimate.

[0080] If the encrypted data passes verification, the chip corresponding to the currently verified slave device is determined to be legitimate.

[0081] Based on the above embodiments, the second verification module 503 is further configured as follows:

[0082] If encrypted data is not received from the currently verified slave device within the preset time, or if the received encrypted data fails verification, then the chip corresponding to the currently verified slave device is determined to be invalid.

[0083] Based on the above embodiments, the chip data security access device further includes a data output module, which is configured as follows:

[0084] If the detection results determine that the current working environment does not meet the settings, then error data is sent to the host.

[0085] It is worth noting that in the embodiments of the chip data security access device described above, the modules are divided according to functional logic, but are not limited to the above division, as long as the corresponding functions can be achieved; in addition, the specific names of each module are only for easy differentiation and are not used to limit the scope of protection of this application.

[0086] Figure 6 This is a schematic diagram of an electronic device provided in an embodiment of this application. The device is used to execute the chip data security access method provided in the above embodiment and has corresponding functional modules and beneficial effects for executing the method. As shown in the figure, the electronic device includes a processor 601, a memory 602, an input device 603, and an output device 604. The number of processors 601 can be one or more; one processor 601 is shown as an example in the figure. The processor 601, memory 602, input device 603, and output device 604 can be connected via a bus or other means; a bus connection is shown as an example in the figure. The memory 602, as a computer-readable storage medium, can be used to store software programs, computer-executable programs, and modules, such as the program instructions / modules corresponding to the chip data security access method in the embodiments of this application. The processor 601 executes various corresponding functional applications and data processing by running the software programs, instructions, and modules stored in the memory 602, thereby realizing the above-mentioned chip data security access method.

[0087] The memory 602 may primarily include a program storage area and a data storage area. The program storage area may store the operating system and at least one application program required for a given function; the data storage area may store data recorded or created during use. Furthermore, the memory 602 may include high-speed random access memory and non-volatile memory, such as at least one disk storage device, flash memory device, or other non-volatile solid-state storage device. In some embodiments, the memory 602 may further include memory remotely located relative to the processor 601, which can be connected to a terminal device via a network. Examples of such networks include, but are not limited to, the Internet, intranets, local area networks, mobile communication networks, and combinations thereof.

[0088] The input device 603 can be used to input corresponding digital or character information to the processor 601, and to generate key signal inputs related to the user settings and function control of the device; the output device 604 can be used to send or display key signal outputs related to the user settings and function control of the device.

[0089] This application also provides a storage medium storing computer-executable instructions, which, when executed by a processor, are used to perform related operations in the chip data security access method provided in any embodiment of this application.

[0090] Computer-readable storage media include both permanent and non-permanent, removable and non-removable media, and information storage can be achieved by any method or technology. Information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, disk storage or other magnetic storage devices, or any other non-transfer medium that can be used to store information accessible by a computing device.

[0091] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.

[0092] Note that the above are merely preferred embodiments and the technical principles employed in this application. Those skilled in the art will understand that this application is not limited to the specific embodiments described herein, and various obvious changes, readjustments, and substitutions can be made without departing from the scope of protection of this application. Therefore, although this application has been described in detail through the above embodiments, this application is not limited to the above embodiments, and may include many other equivalent embodiments without departing from the concept of this application, the scope of which is determined by the scope of the appended claims.

Claims

1. A method for secure access to chip data, characterized in that, The method is applied to any one of a plurality of slave terminals that communicate with a master terminal via a bus, wherein the master terminal and the slave terminal correspond to different chips. In response to the access request initiated by the host, perform two-way authentication with the host to authorize the host to read and write. If it is determined that the host has read permission, read permission is granted to the host to allow the host to access the internal storage data, and the data to be accessed by the host is monitored. If it is determined that the data to be accessed by the host is the first target data in the stored data, then a working environment detection is performed to determine whether it meets the set working environment. The first target data is the data that needs to be protected stored in the slave. If the detection results determine that the current working environment does not meet the settings, the host terminal is prohibited from accessing the first target data; Wherein, if it is determined that the data to be accessed by the host is the first target data in the stored data, then a working environment detection is performed to determine whether it meets the set working environment, including: Verification is initiated one by one for other slave devices communicating on the bus to determine whether each chip acting as a slave device is legitimate; Assuming all chips are valid, determine the operating environment that meets the setup requirements.

2. The chip data secure access method according to claim 1, characterized in that, The step of initiating verification one by one for other slave terminals communicating on the bus to determine whether each chip acting as a slave terminal is legitimate includes: If the slave device being verified is a memory chip, a read command is sent to the memory chip to obtain backup data located in the target area of ​​the memory chip. The backup data is a backup of the second target data of this chip. After obtaining the backup data, the backup data and the second target data are compared to determine whether the backup data is the same as the second target data. If the backup data is the same as the second target data, then the chip corresponding to the currently verified slave device is determined to be legitimate.

3. The chip data secure access method according to claim 2, characterized in that, The step of comparing the backup data with the second target data after obtaining the backup data to determine whether the backup data is the same as the second target data includes: Based on a preset authentication algorithm, a first verification value corresponding to the backup data and a second verification value corresponding to the second target data are determined. The first check value and the second check value are compared to determine whether the first check value and the second check value are the same.

4. The chip data secure access method according to claim 1 or 2, characterized in that, The step of initiating verification one by one for other slave terminals communicating on the bus to determine whether each chip acting as a slave terminal is legitimate includes: If the currently verified slave device is a security chip, an authentication command is sent to the currently verified slave device to obtain encrypted data. The encrypted data is the data after the currently verified slave device encrypts the identity information based on a preset authentication algorithm. Upon receiving the encrypted data, the encrypted data is verified based on the preset authentication algorithm to determine whether the chip corresponding to the currently verified slave device is legitimate. If the encrypted data passes verification, the chip corresponding to the currently verified slave device is determined to be legitimate.

5. The chip data secure access method according to claim 4, characterized in that, The method further includes: If encrypted data is not received from the currently verified slave device within a preset time, or if the received encrypted data fails verification, then the chip corresponding to the currently verified slave device is determined to be invalid.

6. The chip data secure access method according to claim 1, characterized in that, The method further includes: If the detection results determine that the current working environment does not meet the settings, then error data is sent to the host.

7. A chip data security access device, characterized in that, The device comprises: any one of several slave terminals that communicate with a master terminal via a bus, wherein the master terminal and the slave terminal correspond to different chips; the device includes: The first verification module is configured to respond to the access request initiated by the host and perform two-way authentication with the host to perform read and write authorization on the host. The access monitoring module is configured to grant read permissions to the host terminal when it is determined that the host terminal has read permissions, so that the host terminal can access the internal storage data, and to monitor the data to be accessed by the host terminal. The second verification module is configured to perform a working environment detection if it is determined that the data to be accessed by the host is the first target data in the stored data, in order to determine whether it meets the set working environment. The first target data is the data that needs to be protected stored in the slave. The access management module is configured to prohibit the host from accessing the first target data if the detection result determines that the current working environment does not meet the settings. The second verification module is specifically configured as follows: Verification is initiated one by one for other slave devices communicating on the bus to determine whether each chip acting as a slave device is legitimate; Assuming all chips are valid, determine the operating environment that meets the setup requirements.

8. An electronic device, characterized in that, include: One or more processors; Storage device for storing one or more programs, when one or more of the programs are accessed by one or more... The processor executes the method described in any one of the processors, causing one or more of the processors to implement the chip data secure access method as claimed in any one of claims 1-6.

9. A storage medium storing computer-executable instructions, characterized in that, The computer-executable instructions, when executed by a processor, are used to perform the chip data security access method as described in any one of claims 1-6.

Citation Information

Patent Citations

  • Intranet and extranet access control method for network security chip and network security chip

    CN112714129A

  • Method and device for transmitting data under industrial control network

    CN114363076A