A Cryptographic Coprocessor Architecture and Working Method that Balances Security and Flexibility
By designing a cryptographic coprocessor architecture that takes into account both security and flexibility, and providing algorithm security mode and user programming mode, it solves the problem that cryptographic coprocessors in the prior art is difficult to increase algorithm flexibility, and achieves the effect of increasing algorithm flexibility while ensuring security.
Patent Information
- Application Number
- CN202510000658.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-02
- Publication Date
- 2025-06-20
- Estimated Expiration
- 2045-01-02
AI Technical Summary
While ensuring safety and efficiency, existing password coprocessors are difficult to increase algorithm flexibility, which limits their adaptability in different application scenarios.
A cryptographic coprocessor architecture that takes into account both security and flexibility is designed, using clock gated units, coprocessors, bus and control registers, read-only memory ROMs and static random memory RAMs, providing algorithmic safe mode and user programming mode, and implementing the optimization of instruction and data space through arbitration unit and instruction register REG.
It realizes the algorithm flexibility of the password coprocessor while ensuring security is unchanged. Users can choose the working mode according to their needs to adapt to different application scenarios without increasing the use of on-chip resources.
Smart Images

Figure CN119402195B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of data security, and more specifically, relates to a cryptographic co-processor architecture and working method that take into account both security and flexibility. Background Art
[0002] With the in-depth development of the Internet of Things, the number of Internet of Things intelligent terminal devices has shown an explosive growth, thus bringing more complex security problems such as device authentication, data protection, and wireless communication. Therefore, it is very important for a cryptographic co-processor to provide a chip-level cryptographic technology application solution to ensure the security and privacy of data transmission. However, the existing cryptographic co-processors have poor balance between security and flexibility.
[0003] Chinese Patent Document CN220874549U discloses a data encryption and decryption processing module, including an SOC chip and a key memory. The SOC chip and the key memory are electrically connected through a PCB board for power supply and data communication. The key memory is used to store quantum keys. The SOC chip integrates an encryption and decryption co-processor and a temporary storage unit. The temporary storage unit is used to cache data to be encrypted. The encryption and decryption co-processor is used to substitute the data to be encrypted and the quantum key into the national cryptographic algorithm to implement data encryption and decryption.
[0004] Currently, most of the cryptographic co-processors on the market integrate operator units related to common cryptographic algorithms internally, and rely on instructions to use and schedule various types of operators to compile the entire cryptographic algorithm. For the above-mentioned cryptographic co-processors that rely on instructions to run, an instruction memory is required to store the algorithm. The main types of instruction memories used are RAM and ROM. The RAM storage component has read / write ability and volatility, which means it supports users to write data and can modify existing data, but the internal data will be lost after power-off. The ROM storage component has readability and non-volatility, does not support users to change data, but the data will not be lost after power-off.
[0005] The design of cryptographic co-processors has attracted much attention in recent years. The choice of the instruction storage component of the cryptographic co-processors on the market also varies according to the application scenario. Choosing RAM as the instruction storage component for a cryptographic co-processor means that the security and efficiency of the cryptographic co-processor are not easily guaranteed, while choosing ROM as the instruction storage component for a cryptographic co-processor means that the flexibility of the cryptographic co-processor is not easily guaranteed. How to make the cryptographic co-processor increase algorithm flexibility while ensuring security and efficiency has become one of the important factors restricting the widespread development of cryptographic co-processors. However, there is little relevant research and innovation on the above main restricting factors, and further research is needed. Summary of the Invention
[0006] The present invention aims to overcome at least one defect of the above-mentioned prior art, and provides a cryptographic coprocessor architecture that takes into account both security and flexibility, so as to solve the problem of how to increase the algorithm flexibility of the cryptographic coprocessor while ensuring security and efficiency.
[0007] The present invention also provides a working method for a cryptographic coprocessor architecture that takes into account both security and flexibility.
[0008] The present invention also provides a computer-readable storage medium for implementing the above method.
[0009] The detailed technical solution of the present invention is as follows:
[0010] A cryptographic coprocessor architecture that takes into account both security and flexibility, the architecture includes: a clock gating unit, a coprocessor, a bus and a control register, a read-only memory ROM, and a static random access memory RAM;
[0011] The coprocessor is used for instruction execution and data transfer;
[0012] The clock gating unit is used to control the clock signal transmission of the coprocessor, and turn off the clock of the coprocessor when the coprocessor is not working;
[0013] The bus and the control register are used to control the working mode and state of the coprocessor, and there is an instruction register REG that is used as an instruction space in the user programming mode; the working modes include an algorithm security mode and a user programming mode, and the instruction register REG is used to store user programming mode instructions;
[0014] The read-only memory ROM is used to store algorithm security mode instructions, with built-in security algorithms, and cannot be accessed by customers;
[0015] The static random access memory RAM is used for data storage space, and part of the space is used as a privacy space to temporarily store operation intermediate quantities in the algorithm security mode; different storage spaces are divided in the static random access memory RAM, and different access permissions are set according to the working mode.
[0016] Further, the coprocessor includes an instruction fetch unit, an arbitration unit, a decoding unit, a dispatch unit, and multiple functional units;
[0017] The instruction fetch unit is used for the instruction fetch operation after the coprocessor is started, and selects different instruction spaces for instruction fetching according to the working mode;
[0018] The arbitration unit is used to select valid instructions in different instruction spaces according to the working mode, and transmit the valid instructions to the decoding unit;
[0019] The decoding unit is used to decode the valid instructions, decompose them into different functional instructions and split the information;
[0020] A transmitting unit, configured to send the decoded instructions to different functional units for execution;
[0021] A functional unit, specifically the functional unit N of the coprocessor, configured to execute specific instruction functions and perform actions.
[0022] Further, the arbitration unit includes a working mode register MODE_REG and an arbiter. The working mode register MODE_REG is configured to configure the working mode of the coprocessor;
[0023] The arbiter is configured to arbitrate between user programming mode instructions and algorithm security mode instructions and select one of them.
[0024] The present invention further includes a working method based on a cryptographic coprocessor architecture that takes into account both security and flexibility. The two working modes of the coprocessor are respectively configured as an algorithm security mode and a user programming mode, as follows:
[0025] When the user configures the working mode of the coprocessor as the algorithm security mode, the steps include:
[0026] S1. Configure the working mode of the coprocessor as the algorithm security mode through a bus and a control register;
[0027] S2. Write the data to be computed DATA to a fixed location of a static random access memory RAM;
[0028] S3. Start the coprocessor operation, and the coprocessor runs the instructions in a read-only memory ROM;
[0029] S4. The coprocessor starts to compute. If the computation is completed, read the computation result from the fixed location of the static random access memory RAM; otherwise, continue to wait for the coprocessor to complete the computation.
[0030] When the user configures the working mode of the coprocessor as the user programming mode, the steps include:
[0031] S01. Configure the working mode of the coprocessor as the user programming mode through a bus and a control register;
[0032] S02. Write the data to be computed DATA to a user-specified location of the static random access memory RAM;
[0033] S03. Write a user programming instruction User_INST to an instruction register REG;
[0034] S04. Start the coprocessor operation, and the coprocessor runs the instructions in the instruction register REG;
[0035] S05. The coprocessor starts to operate. If the coprocessor finishes the operation, go to step S06; otherwise, continue to wait for the coprocessor to complete the operation.
[0036] S06. Determine whether the user algorithm, i.e., the custom algorithm, is completed. If it is completed, go to step S07; otherwise, return to step S03 to work in a loop.
[0037] S07. Read the operation result from the user-specified location of the static random access memory (RAM).
[0038] Furthermore, the instruction arbitration of the coprocessor includes:
[0039] The user instructions stored in the instruction register REG are the user programming instruction User_INST and the end instruction END. The secure algorithm instructions are stored in the memory ROM. Under the selection of the working mode register MODE_REG, the user programming mode instruction and the algorithm security mode instruction are output by arbitration of the arbitration unit ARBITER through a one-out-of-two selection.
[0040] The valid instruction INST output will be passed through the pipe timing beat and transmitted to the decoding unit.
[0041] The decoding unit decodes the valid instruction, decomposes it into different functional instructions, and splits the information.
[0042] The emission unit sends the decoded instruction to multiple functional units to execute the specific instruction functions.
[0043] In another aspect of the present invention, a machine-readable storage medium is further provided, which stores executable instructions. When the instructions are executed, the machine executes the working method of a cryptographic coprocessor architecture that takes into account both security and flexibility as described above.
[0044] Compared with the prior art, the beneficial effects of the present invention are:
[0045] (1) The cryptographic coprocessor architecture and working method that take into account both security and flexibility provided by the present invention propose a cryptographic coprocessor architecture that can provide two working modes. Users can select the working mode according to their needs, making the system take into account both security and flexibility.
[0046] (2) The present invention provides a cryptographic co-processor architecture and working method that takes into account both security and flexibility. The proposed algorithm security mode allows the cryptographic co-processor to run algorithms in the read-only memory (ROM), while calculating intermediate data in the privacy space, which is more efficient while ensuring security, and users do not need to learn or write algorithm instructions, making it convenient to use; the proposed user programming mode allows the cryptographic co-processor to run instructions in the REG. Users can customize and write algorithms, and can implement custom algorithms by writing instructions to the REG in a loop and starting the cryptographic co-processor, greatly increasing the flexibility of the cryptographic co-processor without increasing the occupation of on-chip resources. BRIEF DESCRIPTION OF THE DRAWINGS
[0047] Figure 1 It is a schematic diagram of the architectural design of the cryptographic co-processor described in the present invention.
[0048] Figure 2 It is a schematic diagram of the arbitration circuit in Embodiment 1 of the present invention.
[0049] Figure 3 It is a schematic diagram of the static random access memory (RAM) space permissions in Embodiment 1 of the present invention.
[0050] Figure 4 It is a schematic diagram of the working process of the algorithm security mode in Embodiment 1 of the present invention.
[0051] Figure 5 It is a schematic diagram of the working process of the user programming mode in Embodiment 1 of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0052] The present invention will be further described below in conjunction with the drawings and embodiments.
[0053] It should be noted that the following detailed description is exemplary and is intended to provide further explanation of the present invention. Unless otherwise specified, all technical and scientific terms used herein have the same meaning as commonly understood by those of ordinary skill in the technical field to which the present invention belongs.
[0054] It should be noted that the terms used herein are only for describing specific embodiments and are not intended to limit the exemplary embodiments of the present invention. As used herein, unless the context clearly indicates otherwise, the singular form is also intended to include the plural form. In addition, it should be understood that when the terms "comprising" and / or "including" are used in this specification, they indicate the presence of features, steps, operations, devices, components, and / or combinations thereof.
[0055] Without conflict, the embodiments in the present invention and the features in the embodiments can be combined with each other.
[0056] Embodiment 1
[0057] Reference Figure 1 In this embodiment, a cryptographic coprocessor architecture that takes into account both security and flexibility is provided. The architecture includes: a clock gating unit, a coprocessor, a bus and control registers, a read-only memory ROM, and a static random access memory RAM;
[0058] The coprocessor is used for instruction execution and data transfer;
[0059] The clock gating unit is used to control the transmission of the clock signal of the coprocessor and turn off the clock of the coprocessor when the coprocessor is not working;
[0060] The bus and control registers are used to control the working mode and status of the coprocessor. There is an instruction register REG that is used as an instruction space in the user programming mode. The working modes include an algorithm security mode and a user programming mode. The instruction register REG is used to store user programming mode instructions;
[0061] An instruction register REG is added to the bus register. Without increasing on-chip resources, only registers can be used to provide an instruction space for users to execute custom algorithms. If users execute fixed algorithms, ROM will be used as the instruction space; at the same time, an arbitration unit is added to the coprocessor as the core component for distinguishing the effective instruction space in different working modes. It receives both REG instructions and ROM instructions and makes an arbitration between the two to output valid instructions.
[0062] The read-only memory ROM is used to store algorithm security mode instructions, with built-in security algorithms that cannot be accessed by customers;
[0063] The static random access memory RAM is used for data storage space. Part of the space is used as a privacy space to temporarily store intermediate calculation results in the algorithm security mode;
[0064] Specifically, different storage spaces are divided in the static random access memory RAM, and different access permissions are set according to the working mode. The space permissions of the static random access memory RAM are as Figure 3 shown:
[0065] In the algorithm security mode, the coprocessor can access all spaces of the static random access memory RAM, and cooperate with the instructions in the ROM to load and store input data and output data in the non-privacy space, that is, the normal space, and load and store privacy data, that is, intermediate calculation data, in the privacy space;
[0066] In user programming mode, the coprocessor can only access the non-privacy space of the static random access memory RAM, namely the normal space. The user loads and stores the input data, output data and intermediate calculation data of the custom algorithm in this space, limiting the user's access rights to the privacy space to protect the privacy data in the secure mode from being leaked.
[0067] Preferably, the coprocessor comprises an instruction fetch unit, an arbitration unit, a decoding unit, a transmitting unit and a plurality of functional units, namely, functional unit 1 to functional unit N;
[0068] The instruction fetch unit is used for fetching instructions after the coprocessor is started, and selects different instruction spaces for fetching instructions according to the working mode;
[0069] An arbitration unit, used to select valid instructions from different instruction spaces according to the working mode, and transmit the valid instructions to the decoding unit;
[0070] A decoding unit is used to decode valid instructions, decompose them into different functional instructions and split the information;
[0071] A transmitting unit, used to send the decoded instructions to different functional units for execution;
[0072] Functional unit, the functional unit N of the coprocessor is used to execute specific instruction functions and perform actions.
[0073] Further, the arbitration unit includes a working mode register MODE_REG and an arbiter, and the working mode register MODE_REG is used to configure the working mode of the coprocessor;
[0074] The arbiter is used to arbitrate between user programming mode instructions and algorithm security mode instructions, and select one of the two.
[0075] Example 2
[0076] This embodiment also provides a working method based on the above-mentioned cryptographic coprocessor architecture that takes into account both security and flexibility. The two matching working modes are an algorithm security mode and a user programming mode, as follows:
[0077] When the user configures the coprocessor to work in safe mode, the instructions in the ROM will be output to the next stage through the arbitration circuit. When the pipeline encounters the end instruction, the pipeline will stop and the coprocessor will be turned off. At this time, the coprocessor will run a safe and efficient fixed algorithm, which is easy to use.
[0078] The workflow when configured in algorithm security mode is as follows Figure 4 As shown, the steps are:
[0079] S1. Configure the working mode of the coprocessor as the algorithm security mode through the bus and control register;
[0080] S2. Write the data to be calculated DATA to a fixed position in the static random access memory RAM; that is, in the algorithm security mode, the coprocessor can access the entire space of the static random access memory RAM, and cooperate with the instructions in the ROM to load and store the input data and output data in the non-private space, that is, the normal space, and load and store the private data, that is, the intermediate calculation data, in the private space;
[0081] S3. Start the coprocessor operation, and the coprocessor runs the instructions in the read-only memory ROM;
[0082] S4. The coprocessor starts to operate. If the operation is completed, read the operation result from a fixed position in the static random access memory RAM; otherwise, continue to wait for the coprocessor to complete the operation;
[0083] When the user configures the working mode of the coprocessor as the user mode, the instructions in the register REG will be output to the subsequent stage through the arbitration circuit. In order not to increase the control logic, the pipeline control end circuit is reused, and the hard-wired connection is used as the next end instruction to automatically stop the pipeline and turn off the coprocessor. At this time, the coprocessor will run the user-defined algorithm to improve the working flexibility of the coprocessor.
[0084] The working process configured as the user programming mode is as Figure 5 shown, and the steps are as follows:
[0085] S01. Configure the working mode of the coprocessor as the user programming mode through the bus and control register;
[0086] S02. Write the data to be calculated to the user-specified position in the static random access memory RAM; that is, in the user programming mode, the coprocessor only accesses the non-private space, that is, the normal space, of the static random access memory RAM, and the user loads and stores the input data, output data and intermediate calculation data of the user-defined algorithm in this space;
[0087] S03. Write the user programming instruction User_INST to the instruction register REG;
[0088] S04. Start the coprocessor operation, and the coprocessor runs the instructions in the instruction register REG;
[0089] S05. The coprocessor starts to operate. If the coprocessor finishes the operation, enter step S06; otherwise, continue to wait for the coprocessor to complete the operation;
[0090] S06. Determine whether the user algorithm, i.e., the custom algorithm, is completed. If it is completed, proceed to step S07; otherwise, return to step S03 to loop and work.
[0091] S07. Read the operation result from the user-specified location in the static random access memory (RAM).
[0092] Among them, the user algorithm includes multiple user programming instructions.
[0093] Furthermore, the instruction arbitration of the coprocessor is implemented through an instruction arbitration circuit;
[0094] The instruction arbitration circuit is as Figure 2 shown, and includes an instruction register REG, user programming instructions User_INST, end instruction END, read-only memory ROM, arbitration unit ARBITER, working mode register MODE_REG, valid instruction INST, and pipe instant timing beats;
[0095] The instruction arbitration of the coprocessor includes:
[0096] The user instructions stored in the instruction register REG are the user programming instructions User_INST and the end instruction END. The security algorithm instructions are stored in the memory ROM. Under the selection of the working mode register MODE_REG, the user programming mode instructions and the algorithm security mode instructions are output through the arbitration of the arbitration unit ARBITER by a one-for-one selection;
[0097] The output valid instruction INST will be transmitted to the decoding unit through the pipe timing beats;
[0098] The decoding unit decodes the valid instruction, decomposes it into different functional instructions, and splits the information;
[0099] The emission unit sends the decoded instructions to functional unit 1, functional unit 2,..., functional unit N - 1, and functional unit N to execute the specific instruction functions.
[0100] In summary, the novel coprocessor architecture proposed by the present invention optimizes the instruction space and data space, and proposes two working modes. The present invention proposes two types for the instruction space, namely ROM as the security algorithm instruction space and REG as the user programming algorithm instruction space. Using ROM to run the algorithm, the algorithm content cannot be accessed externally, realizing the secure operation of the algorithm. At the same time, the algorithm in ROM is written and designed by the manufacturer according to the coprocessor architecture, and the operation is more efficient; using the register REG to run the algorithm, the user can fill in instructions in a loop and run them to realize the custom algorithm, without increasing the on-chip resource occupancy and having high flexibility.
[0101] The present invention proposes two types of permission divisions for the data space, namely the normal space for storing ordinary data and the privacy space for storing private data. When running in the algorithm security mode, the coprocessor can access all spaces. When running in the user programming mode, the coprocessor can only access the normal space, protecting private data from leakage at the hardware level and further improving the security of the cryptographic coprocessor.
[0102] The proposed architecture combines multi-type instruction storage space technology, data storage space technology with divided permissions, and working modes, which can solve the drawback that the current coprocessor cannot balance security and flexibility during operation, and further improve the adaptability of the coprocessor in different application scenarios.
[0103] Embodiment 3
[0104] This embodiment also provides a computer-readable storage medium storing executable instructions that, when executed, cause the machine to execute the working method of a cryptographic coprocessor architecture that balances security and flexibility as described above.
[0105] Specifically, a system or device equipped with a readable storage medium can be provided. On this readable storage medium, software program code for implementing the functions of any one of the above embodiments is stored, and the computer or processor of the system or device is caused to read and execute the instructions stored in the readable storage medium.
[0106] In this case, the program code read from the readable medium itself can implement the functions of any one of the above embodiments. Therefore, the machine-readable code and the readable storage medium storing the machine-readable code constitute a part of this specification.
[0107] Examples of readable storage media include floppy disks, hard disks, magneto-optical disks, optical disks (such as CD-ROM, CD-R, CD-RW, DVD-ROM, DVD-RAM, DVD-RW, DVD-RW), magnetic tapes, non-volatile memory cards, and ROMs. Optionally, the program code can be downloaded from a server computer or a cloud via a communication network.
[0108] Those skilled in the art should understand that the embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memories, CD-ROMs, optical memories, etc.) containing computer-usable program code.
[0109] The present invention is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to embodiments of the present invention. It should be understood that each flow and / or block in the flowchart and / or block diagram, and the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate means for implementing the functions specified in one process Figure 1 one process or multiple processes and / or blocks Figure 1 or means for implementing the functions specified in multiple blocks.
[0110] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured article including instruction means, and the instruction means implement the functions specified in one process Figure 1 one process or multiple processes and / or blocks Figure 1 or means for implementing the functions specified in multiple blocks.
[0111] These computer program instructions can also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one process Figure 1 one process or multiple processes and / or blocks Figure 1 or means for implementing the functions specified in multiple blocks.
[0112] Obviously, the above embodiments of the present invention are merely examples for clearly illustrating the technical solutions of the present invention, rather than limitations on the specific implementation manners of the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the claims of the present invention shall be included in the protection scope of the claims of the present invention.
Claims
1. A cryptographic coprocessor architecture that takes into account both security and flexibility, characterized in that: The architecture includes a coprocessor, a clock gating unit, a bus and control registers, a read-only memory ROM and a static random access memory RAM; The coprocessor is used for instruction execution and data transmission; the coprocessor includes an instruction fetch unit, an arbitration unit, a decoding unit, a transmitting unit and a plurality of functional units; The instruction fetch unit is used for fetching instructions after the coprocessor is started, and selects different instruction spaces for fetching instructions according to the working mode; An arbitration unit, used to select valid instructions from different instruction spaces according to the working mode, and transmit the valid instructions to the decoding unit; The arbitration unit includes a working mode register MODE_REG and an arbiter, wherein the working mode register MODE_REG is used to configure the working mode of the coprocessor; the arbiter is used to arbitrate between a user programming mode instruction and an algorithm security mode instruction, and select one of the two; A decoding unit is used to decode valid instructions, decompose them into different functional instructions and split the information; A transmitting unit, used to send the decoded instructions to different functional units for execution; Functional unit, used to execute specific instruction functions and perform actions; The clock gating unit is used to control the clock signal transmission of the coprocessor and turn off the clock of the coprocessor when the coprocessor is not working; The bus and control register are used to control the coprocessor working mode and state, and are stored in the instruction register REG as an instruction space in the user programming mode; wherein the working mode includes the algorithm security mode and the user programming mode; The read-only memory ROM is used to store algorithm security mode instructions, has a built-in security algorithm, and cannot be accessed by customers; The static random access memory RAM is used for data storage space, and part of the space is used as a privacy space to temporarily store intermediate calculation quantities in the algorithm security mode.
2. A method for operating a cryptographic coprocessor architecture that takes into account both security and flexibility, characterized in that: The two working modes of the configuration coprocessor are algorithm security mode and user programming mode; When the user configures the coprocessor's working mode to algorithm security mode, it includes: S1, configure the coprocessor's working mode to algorithm security mode through the bus and control register; S2, write the data to be calculated DATA into the fixed position of the static random access memory RAM; S3, start the coprocessor operation, and the coprocessor runs the instructions in the read-only memory ROM; S4, the coprocessor starts the operation. If the operation is completed, the operation result is read from the fixed position of the static random access memory RAM; otherwise, continue to wait for the coprocessor to complete the operation; When the user configures the coprocessor's operating mode to user programming mode, it includes: S01, configuring the coprocessor's working mode to be a user programming mode through the bus and control register; S02, write the data to be calculated DATA into the user-specified location of the static random access memory RAM; S03, write the user programming instruction User_INST into the instruction register REG; S04, start the coprocessor operation, and the coprocessor runs the instruction in the instruction register REG; S05, the coprocessor starts to calculate. If the coprocessor completes the calculation, the process proceeds to step S06; otherwise, the process continues to wait for the coprocessor to complete the calculation. S06, judging whether the user algorithm, i.e., the custom algorithm, is completed. If it is completed, i.e., the custom algorithm is finished, then proceeding to step S07; otherwise, returning to step S03 to loop back and forth; S07, reading the operation result from the user-specified location of the static random access memory RAM.
3. The method for operating a cryptographic coprocessor architecture that takes into account both security and flexibility according to claim 2, characterized in that: The instruction arbitration of the coprocessor includes: The instruction register REG stores user instructions, which are user programming instructions User_INST instructions and end instructions END instructions. The memory ROM stores security algorithm instructions. Under the selection of the working mode register MODE_REG, the user programming mode instructions and the algorithm security mode instructions are output in a selected manner through arbitration by the arbitration unit ARBITER. The output valid instruction INST will be transmitted to the decoding unit through the pipe timing beat; The decoding unit decodes the valid instructions, decomposes them into different functional instructions and splits the information; The transmitting unit sends the decoded instructions to multiple functional units to execute specific instruction functions.
4. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 2 to 3 are implemented.
Citation Information
Patent Citations
Data encryption and decryption processing module
CN220874549U
Resource access methods and devices
CN108256298A
Memory device, Method of operating the memory device and Memory system including the memory device
CN111354406A
Security coprocessor architecture based on fifth generation reduced instruction set architecture and security coprocessor
CN118898079A
Information processing device
CN1521638A