A method and system for protecting and encrypting bug injection for chip software
By encrypting and decrypting information during the chip software error injection process, the problem of insufficient chip security is solved, security protection is achieved during the error injection process, and the security of chip operation is improved.
Patent Information
- Application Number
- CN202410102141.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-01-24
- Publication Date
- 2025-12-12
- Estimated Expiration
- 2044-01-24
AI Technical Summary
During the chip software injection process, existing technologies can easily expose the software processing flow and chip functional logic, resulting in insufficient security.
By encrypting the stored information to generate data information register verification information bits, and then decrypting and comparing them, the erroneous stored information is injected into the chip only when the verification is correct. At the same time, when the verification fails, the failure result is fed back to stop or retry the injection of errors.
This improves the security of the chip during operation, prevents malicious cracking from causing input errors and exposing the chip's internal logic functions, and enhances the chip's security protection.
Smart Images

Figure CN117852104B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of chip testing in general. In particular, the present application relates to a method and system for protecting and encrypting software inject error of a chip. BACKGROUND
[0002] Software inject error is a test method for evaluating the reliability and safety of software, in which the system is artificially injected with faults and the system's reaction behavior information is collected for reliability analysis.
[0003] For example, Chinese invention patent "CN108766501B" discloses a memory fault injection design and verification method with EDAC fault tolerance. Different controls are performed on the read / write access of the data / instruction domain and the check domain in different working modes. In the test mode, when the data / instruction domain is read, only the control signal of the data / instruction domain read operation is enabled to realize the test read access of the data / instruction domain; when the check domain is read, only the control signal of the check domain read operation is enabled to realize the test read access of the check domain; when the data / instruction domain is fault injected, only the control signal of the data / instruction domain write operation is enabled; when the check domain is fault injected, only the control signal of the check domain write operation is enabled to realize the arbitrary fault injection of the data / instruction domain and the check domain.
[0004] However, in the process of software inject error of a chip, some non-functional safety features are present, which can easily expose the software processing flow and chip function logic in the software inject error process, and thus a method capable of providing protection and encryption in the software inject error process and improving the safety of chip operation is needed. SUMMARY
[0005] To at least partially solve the above problems in the prior art, the present application provides a method for protecting and encrypting software inject error of a chip, comprising the following steps:
[0006] encrypting the stored information to generate data information register check information bits;
[0007] decrypting the data information register check information bits; and
[0008] comparing the decrypted information, and when the check is correct, injecting error storage information into the chip to perform software inject error.
[0009] In an embodiment of the present application, the method for protecting and encrypting software inject error of a chip further comprises:
[0010] When the check fails, the failure result is fed back to the function module to abort the software bug injection or to reattempt the software bug injection.
[0011] In one embodiment of the present application, it is specified that the encryption of the stored information to generate the data information register check information bits comprises:
[0012] The encrypted verification code is added before or after the information data address of the stored information; or
[0013] The encryption code with the unique features of the chip is added before or after the information data address of the stored information.
[0014] In one embodiment of the present application, it is specified that the encryption of the stored information comprises Advanced Encryption Standard encryption.
[0015] The present application also provides a system for protecting and encrypting the software bug injection of a chip, comprising:
[0016] a memory configured to store and output stored information;
[0017] an encryption module configured to encrypt the stored information to generate data information register check information bits; and
[0018] a software bug injection module comprising:
[0019] a security check module configured to decrypt the data information register check information bits and compare the decrypted information; and
[0020] a bug injection module configured to inject error stored information into the chip to perform software bug injection when the check is correct.
[0021] In one embodiment of the present application, it is specified that the system for protecting and encrypting the software bug injection of a chip further comprises:
[0022] a function module, wherein when the check fails, the failure result is fed back to the function module to abort the software bug injection or to reattempt the software bug injection.
[0023] The present application also provides a computer readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, performs the steps of the method.
[0024] The present application also provides a computer system, comprising:
[0025] a processor configured to execute machine executable instructions; and
[0026] a memory having stored thereon machine executable instructions, the machine executable instructions when executed by the processor perform steps in accordance with the method.
[0027] The present application has at least the following beneficial effects: the present application can provide security protection in the chip software bug injection process, thereby avoiding malicious cracking to cause input error information so that the upper layer of the chip handles the chip error, and can avoid malicious cracking to cause the chip internal logic function to be exposed, greatly improving the security in the chip running process. BRIEF DESCRIPTION OF DRAWINGS
[0028] To further clarify the advantages and features of the embodiments of the present application, a more particular description of embodiments of the application will be rendered by reference to specific embodiments thereof, which are illustrated in the appended drawings. It is appreciated that these drawings depict only typical embodiments of the application and are therefore not to be considered limiting of its scope. The same or corresponding elements in the drawings are denoted by the same or similar reference signs.
[0029] Figure 1 A schematic diagram of a computer system implementing a system and / or method according to the present application is shown.
[0030] Figure 2 A flowchart of a method for protecting and encrypting chip software bug injection in an embodiment of the present application is shown.
[0031] Figure 3 A module diagram of a system for protecting and encrypting chip software bug injection in an embodiment of the present application is shown. DETAILED DESCRIPTION
[0032] It should be noted that the components in the various figures can be shown exaggerated in size for illustrative purposes and are not necessarily drawn to scale. In the various figures, the same or corresponding elements are denoted by the same or similar reference signs.
[0033] In the present application, unless specifically indicated, "arranged on", "arranged above" and "arranged over" do not exclude the presence of an intermediate object between them. In addition, "arranged on or above" only indicates the relative position relationship between the two components, and in some cases, such as after reversing the product direction, it can also be converted to "arranged below or below", and vice versa.
[0034] In the present application, the embodiments are only intended to illustrate the solutions of the present application and should not be understood as limiting.
[0035] In the present application, unless specifically indicated, the quantifier "one", "a" does not exclude the scenario of multiple elements.
[0036] It should also be noted that, in the embodiments of the present invention, only a portion of the components or parts may be shown for clarity and simplicity. However, those skilled in the art will understand that, under the teachings of the present invention, necessary components or parts can be added as needed for specific scenarios. Furthermore, unless otherwise stated, features in different embodiments of the present invention can be combined with each other. For example, a feature in the second embodiment can replace a corresponding or functionally identical or similar feature in the first embodiment, and the resulting embodiment will also fall within the scope of disclosure or description of this application.
[0037] It should also be noted that, within the scope of this invention, the terms "same," "equal," and "equal to" do not imply that the two values are absolutely equal, but rather allow for a certain reasonable margin of error. In other words, the terms also encompass "substantially the same," "substantially equal," and "substantially equal to." Similarly, in this invention, the directional terms "perpendicular to," "parallel to," etc., also encompass the meanings of "substantially perpendicular to" and "substantially parallel to."
[0038] Furthermore, the numbering of the steps in the methods of the present invention does not limit the execution order of the method steps. Unless otherwise specified, the method steps may be executed in different orders.
[0039] The present invention will be further described below with reference to the accompanying drawings and specific embodiments.
[0040] Figure 1 A computer system 100 implementing the system and / or method according to the present invention is shown. Unless otherwise specified, the method and / or system according to the present invention can be implemented in... Figure 1 The invention may be implemented in the computer system 100 shown to achieve the objectives of the invention, or the invention may be implemented in a distributed manner in multiple computer systems 100 according to the invention via a network, such as a local area network or the Internet. The computer system 100 of the invention may include various types of computer systems, such as handheld devices, laptop computers, personal digital assistants (PDAs), multiprocessor systems, microprocessor-based or programmable consumer electronic devices, network PCs, minicomputers, mainframes, network servers, tablet computers, etc.
[0041] like Figure 1 As shown, the computer system 100 includes a processor 111, a system bus 101, a system memory 102, a video adapter 105, an audio adapter 107, a hard disk drive interface 109, an optical drive interface 113, a network interface 114, and a Universal Serial Bus (USB) interface 112. The system bus 101 can be any of several bus architecture types, such as a memory bus or memory controller, a peripheral bus, and a local bus using various bus architectures. The system bus 101 is used for communication between the various bus devices. In addition to...Figure 1 Other bus devices or interfaces are also conceivable in addition to the bus devices or interfaces shown in the figure. The system memory 102 comprises a read-only memory (ROM) 103 and a random access memory (RAM) 104, wherein the ROM 103 can store, for example, basic input / output system (BIOS) data for implementing basic routines for information transfer at start-up, and the RAM 104 is used to provide the system with a fast-access running memory. The computer system 100 further comprises a hard disk drive 109 for reading and writing the hard disk 110, an optical drive interface 113 for reading and writing optical media such as CD-ROMs, and the like. The hard disk 110 can store, for example, an operating system and application programs. The drive and its associated computer-readable medium provide nonvolatile storage of computer-readable instructions, data structures, program modules, and other data for the computer system 100. The computer system 100 can further comprise a video adapter 105 for image processing and / or image output, which is used to connect an output device such as a display 106. The computer system 100 can further comprise an audio adapter 107 for audio processing and / or audio output, which is used to connect an output device such as a loudspeaker 108. In addition, the computer system 100 can further comprise a network interface 114 for network connection, wherein the network interface 114 can be connected to the Internet 116 through a network device such as a router 115, wherein the connection can be wired or wireless. In addition, the computer system 100 can further comprise a universal serial bus interface (USB) 112 for connecting peripheral devices, wherein the peripheral devices include, for example, a keyboard 117, a mouse 118, and other peripheral devices such as microphones, cameras, and the like.
[0042] When the present application is implemented on the computer system 100 described above, security protection can be provided during the chip software bug injection process, so as to avoid malicious cracking to cause input of incorrect information to enable the chip upper layer to process chip errors, and to avoid malicious cracking to expose the internal logic function of the chip, greatly improving the security during chip operation. Figure 1 The computer system 100 described above can provide security protection during the chip software bug injection process, so as to avoid malicious cracking to cause input of incorrect information to enable the chip upper layer to process chip errors, and to avoid malicious cracking to expose the internal logic function of the chip, greatly improving the security during chip operation.
[0043] Furthermore, embodiments can be provided as a computer program product, which can include one or more machine-readable media having stored thereon instructions that, when executed by one or more machines such as a computer, network of computers, or other electronic devices, can cause the one or more machines to perform as described herein. The machine-readable media can include, but is not limited to, floppy diskettes, optical disks, CD-ROMs (compact disk-read only memories), and magneto-optical disks, ROMs (read only memories), RAMs (random access memories), EPROMs (erasable programmable read only memories), EEPROMs (electrically erasable programmable read only memories), magnetic or optical cards, flash memory, or other type of media / machine-readable media suitable for storing electronic instructions. Moreover, embodiments can also be provided as a computer program product, which can include one or more computer program flow paths having stored thereon instructions that, when executed by one or more machines such as a computer, network of computers, or other electronic devices, can cause the one or more machines to perform as described herein. The computer program flow paths can include, but are not limited to, hardwired circuitry, one or more semiconductors, logic chips, memories, etc. that are configured to provide the instructions that, when executed by one or more machines, cause the machine to provide the functionality described herein.
[0044] Furthermore, embodiments can be downloaded as a computer program product, wherein the program can be transferred from a remote computer (e.g., a server) to a requesting computer (e.g., a client) by way of one or more data signals embodied in and / or modulated by a carrier wave or other propagation medium via a communication link (e.g., a modem and / or a network connection). Accordingly, a machine-readable medium, as used herein, can include a self-contained program product, floppy diskette, optical disk, CD-ROM (compact disk-read only memory), and magneto-optical disk, ROM (read only memory), RAM (random access memory), EPROM (erasable programmable read only memory), EEPROM (electrically erasable programmable read only memory), magnetic or optical cards, flash memory, or other type of media / media-readable medium suitable for storing electronic instructions.
[0045] In the present disclosure, each module of the system according to the present disclosure can be implemented using software, hardware, firmware, or a combination thereof. When a module is implemented using software, the functions of the module can be implemented by computer program flows, for example, the module can be implemented by a code segment (e.g., a code segment in C, C++, etc.) stored in a storage device (e.g., a hard disk, a memory, etc.) and capable of implementing the corresponding functions of the module when executed by a processor. When a module is implemented using hardware, the functions of the module can be implemented by setting a corresponding hardware structure, for example, by hardware programming of a programmable device such as a field programmable logic gate array (FPGA), or by designing a special integrated circuit (ASIC) including a plurality of transistors, resistors, and capacitors, etc. electronic devices. When a module is implemented using firmware, the functions of the module can be written in the form of program code in the read-only memory of the device such as EPROM or EEPROM, and when the program code is executed by the processor, the corresponding functions of the module can be implemented. In addition, some functions of the module can need to be implemented by separate hardware or by cooperation with the hardware, for example, detection functions are implemented by corresponding sensors (such as proximity sensors, acceleration sensors, gyroscopes, etc.), signal transmission functions are implemented by corresponding communication devices (such as Bluetooth devices, infrared communication devices, baseband communication devices, Wi-Fi communication devices, etc.), output functions are implemented by corresponding output devices (such as displays, speakers, etc.), and the like.
[0046] Figure 2A flow chart of a method for protecting and encrypting software error injection for a chip is shown in one embodiment of the present application. As shown in Figure 2 the method can include the following steps:
[0047] Step 201, encrypting the storage information to generate data information register check information bits (Raw Data With Register Flag).
[0048] Step 202, decrypting the data information register check information bits.
[0049] Step 203, comparing the decrypted information, when the check is correct, injecting error storage information into the chip to perform software error injection, when the check fails, feeding back the failure result to the function module to abort the software error injection or to retry the software error injection.
[0050] Among them, encrypting the storage information to generate data information register check information bits includes: adding a data encrypted verification code before or after the information data address of the storage information; or adding an encryption code with a unique feature of the chip before or after the information data address of the storage information. The unique feature of the chip can be a chip signal or other features. The encryption method can be an advanced encryption standard (AES) encryption or other encryption methods.
[0051] Figure 3 A module diagram of a system for protecting and encrypting software error injection for a chip is shown in one embodiment of the present application. As shown in Figure 3 the system includes a memory 301 (Ram Array), an encryption module (not shown in the figure), a software error injection module 302 (Software Inject Error Module) and a function module 303 (Function Module).
[0052] The memory 301 is configured to store and output storage information.
[0053] The encryption module is configured to encrypt the storage information to generate data information register check information bits.
[0054] The software error injection module includes a safety check module 304 (Safety Calculate Module) and an error injection module (not shown in the figure). The safety check module 304 is configured to decrypt the information bits of the data information register and compare the decrypted information. The error injection module is configured to inject error storage information (Error Inject Word 0-n) into the chip to perform software error injection when the check is correct. When the check fails, the failure result is fed back to the function module 303 to abort the software error injection or retry the software error injection.
[0055] While the foregoing describes various embodiments of the application, such should not be taken as limiting. It will be apparent to those of ordinary skill in the relevant arts that various modifications, substitutions and alterations can be made without departing from the spirit and scope of the present application. Thus, the breadth and scope of the present application should not be limited by any of the above-described exemplary embodiments, but should be defined only in accordance with the following claims and their equivalents.
Claims
1. A method for protecting and encrypting a chip software bug injection to prevent malicious cracking, characterized in that, comprises the following steps: encrypting the stored information to generate data information register check information bits, wherein the stored information is stored in a random access memory (RAM), wherein encrypting the stored information to generate data information register check information bits comprises: adding a data encrypted verification code before or after the information data address of the stored information; or adding a code encrypted with a chip unique feature before or after the information data address of the stored information; decrypting the data information register check information bits; and comparing the decrypted information, and when the check is correct, injecting error stored information into the chip to perform software error injection, and when the check fails, aborting the software error injection to prevent input of error information to cause cracking when error injection.
2. The method for protecting and encrypting the bug injection software of a chip to prevent malicious cracking according to claim 1, characterized in that, Further comprising: when the check fails, feeding back the failure result to a function module to abort the software error injection or to retry the software error injection.
3. The method of claim 1, wherein the manner of encrypting the stored information comprises Advanced Encryption Standard (AES) encryption.
4. A system for protecting and encrypting a chip software bug injection to prevent malicious cracking, characterized by, comprises: a memory configured to store and output stored information; an encryption module configured to encrypt the stored information to generate data information register check information bits, wherein the stored information is stored in a random access memory (RAM), wherein encrypting the stored information to generate data information register check information bits comprises: adding a data encrypted verification code before or after the information data address of the stored information; or adding a code encrypted with a chip unique feature before or after the information data address of the stored information; and a software error injection module comprising: a security check module configured to decrypt the data information register check information bits, and to compare the decrypted information; and an error injection module configured to inject error stored information into the chip to perform software error injection when the check is correct.
5. The system for protecting and encrypting bug-injected chip software against malicious cracking according to claim 4, characterized in that, Further comprising: a function module, wherein when the check fails, the failure result is fed back to the function module to abort the software error injection or to retry the software error injection.
6. A computer-readable storage medium having stored thereon a computer program, characterized in that, The computer program, when executed by the processor, performs the steps of the method according to any one of claims 1-3.
7. A computer system, characterized by comprises: a processor configured to execute machine executable instructions; and a memory having stored thereon machine executable instructions, the machine executable instructions, when executed by the processor, performing the steps of the method according to any one of claims 1-3. comprises: a processor configured to execute machine executable instructions; and a memory having stored thereon machine executable instructions, the machine executable instructions, when executed by the processor, performing the steps of the method according to any one of claims 1-3.
Citation Information
Patent Citations
A Memory Fault Injection Design and Verification Method with EDAC Fault Tolerance
CN108766501B
Automatic verification platform and method for on-chip memory management unit fault-tolerant structure
CN105185413A
Software platform management method based on softdog
CN106650325A
FPGA single event upset fault injection method in satellite-borne equipment
CN113254288A