A trusted debugging system and method

By designing a trusted debugging system including CPU processor, trusted metric module, FLASH memory, CPLD programmable logic and analog signal switch, the problem of power equipment being unable to determine the cause when it cannot be started is solved, the system is quickly started and the accurate measurement results are obtained, and the work efficiency of developers is improved.

CN119440914BActive Publication Date: 2025-05-06TAIZHOU YUNYONG ELECTRONICS
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411509115.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-10-28
Publication Date
2025-05-06
Estimated Expiration
2044-10-28

AI Technical Summary

Technical Problem

In the trusted debugging stage of power equipment, if the system cannot be started, it cannot be determined whether it is caused by measurement failure, abnormal measurement operation or the reliability measurement chip damage, resulting in cumbersome debugging and inefficient efficiency.

Method used

A trusted debugging system is designed, including a CPU processor, a trusted metric module, a FLASH memory, a CPLD programmable logic and an analog signal switch. The CPLD programmable logic sends signals to the analog signal switch, and controls the electrical connection between the trusted metric module and the FLASH memory, realizes the processing of metric results and the automatic reset of the system, ensuring that the system can be started smoothly when the metric fails.

Benefits of technology

It improves the work efficiency of developers in debugging the trusted metric chip functions, avoids the problem of the system being unable to start due to the failure or corruption of trusted metrics, and realizes the rapid startup of the system and the acquisition of accurate measurement results.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119440914B_ABST
    Figure CN119440914B_ABST
Patent Text Reader

Abstract

The present invention discloses a trusted debugging system, comprising a CPU processor, a trusted measurement module, a FLASH memory, a CPLD programmable logic device and an analog signal switch. The present invention sends the measurement result of the trusted measurement module to the CPLD programmable logic device for processing, and sets the analog signal switch so that when the measurement result is a failure, the CPLD programmable logic device can control the analog signal switch to make the CPU processor communicate with the FLASH memory, thereby realizing that the operating system can be smoothly started even when the measurement fails. In this way, when developers debug the trusted measurement module function, they avoid the technical problem that the operating system cannot be started due to the failure or damage of the trusted measurement, thereby failing to obtain the measurement result, and greatly improve the work efficiency of developers.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The invention belongs to the technical field of trusted debugging, and in particular relates to a trusted debugging system and method. Background Art

[0002] In order to ensure the safe and stable operation of the power system and prevent the hardware and software information of power equipment from being maliciously tampered with, more and more power equipment is required to be embedded with trusted technology. During the startup phase of power equipment, the BIOS information of the equipment is measured through trusted measurement technology, which can avoid the phenomenon that the equipment system can still start normally after being modified, effectively ensuring the system security and information security of the equipment.

[0003] However, during the trusted debugging phase of device development, if the system cannot start, it is impossible to verify and obtain trusted measurement information. In this way, it is impossible to determine whether the system cannot start due to measurement failure, measurement abnormality, or damage to the trusted measurement chip.

[0004] In order to solve the above problems and ensure that the system can be restarted, the existing technology adopts the method of removing the trusted measurement chip of the device and then reburning the firmware, or directly replacing the trusted measurement chip. Although this method can realize the restart of the system, it is cumbersome and inefficient, and it is not convenient to find problems during the debugging stage. Therefore, it is very important to develop an efficient and convenient trusted debugging system and method. Summary of the invention

[0005] In view of the above problems, the present invention provides a trusted debugging system, and the technical solutions adopted are as follows:

[0006] A trusted debugging system includes a CPU processor, a trusted measurement module, a FLASH memory, a CPLD programmable logic device and an analog signal switch;

[0007] The CPLD programmable logic device is electrically connected to the FLASH memory through the analog signal switch, and the CPLD programmable logic device is electrically connected to the trusted measurement module, and when the CPLD programmable logic device is powered on, the FLASH memory is enabled to be powered on, and a first reset signal is sent to the trusted measurement module;

[0008] The FLASH memory stores a boot file of the operating system, and the operating system can be successfully started by loading and running the boot file;

[0009] The analog signal switch is used to select the FLASH memory to be electrically connected to the CPU processor or to be electrically connected to the trust measurement module according to the received signal;

[0010] In the initial state, the CPLD programmable logic device sends a low-level switch signal to the analog signal switch after being powered on, and the analog signal switch establishes an electrical connection between the FLASH memory and the trusted measurement module after receiving the low-level switch signal;

[0011] The trusted measurement module performs a reset after receiving the first reset signal, and starts to measure the files in the FLASH memory after the reset is completed, and sends the measurement results to the CPLD programmable logic device;

[0012] If the measurement result is successful, the CPLD programmable logic device sends a successful measurement instruction to the CPU processor, and the operating system is directly started;

[0013] If the measurement result is a failure, the operating system cannot be started, and the CPLD programmable logic device sends a high-level switch signal to the analog signal switch. After receiving the high-level switch signal, the analog signal switch establishes an electrical connection between the FLASH memory and the CPU processor. Then, the CPLD programmable logic device sends a reset instruction to the CPU processor. After receiving the reset instruction, the CPU processor completes the reset, thereby starting the operating system.

[0014] Furthermore, the CPU processor is electrically connected to the trusted metric module and is used to read the measurement result of the trusted metric module.

[0015] Furthermore, the CPU processor communicates with the trusted measurement module via an I2C protocol.

[0016] Furthermore, the CPU processor performs an online upgrade operation on the firmware program of the trusted measurement module through an I2C protocol.

[0017] Furthermore, the CPU processor is a Rockchip RK3568 processor.

[0018] Furthermore, the trust measurement module is a CCM3310 chip.

[0019] Furthermore, the CPLD programmable logic device is a CPLD PGC2KL_6ISSBG256 chip.

[0020] The present invention also provides a trusted debugging method, the steps of which are:

[0021] S1: After the CPLD programmable logic device is powered on, the FLASH memory is enabled to supply power;

[0022] S2: After the FLASH memory is powered, the CPLD programmable logic device sends a reset signal to the trusted measurement module. After receiving the reset signal, the trusted measurement module completes the reset and starts measurement work;

[0023] S3: within a certain period of time, the trusted measurement module sends the measurement result to the CPLD programmable logic device. If the measurement result is successful, the operating system will be directly started successfully; if the measurement result is failed, the operating system cannot be started, and the process goes to step S4;

[0024] S4: The CPLD programmable logic device sends a high-level switch signal to the analog signal switch. After receiving the high-level switch signal, the analog signal switch electrically connects the FLASH memory to the CPU processor, and then sends a reset signal to the CPU processor, so that the CPU processor performs a reset operation. After the reset is completed, the operating system is successfully started.

[0025] Furthermore, step S5 is also included: when the operating system is successfully started, the CPU processor reads the measurement result of the trusted measurement module through the I2C communication protocol, and compares the value of the measurement result with the BIOS file check value in the FLASH memory to see if they are consistent. If they are consistent, it means that the measurement of the trusted measurement module is normal; if they are inconsistent, it means that the measurement of the trusted measurement module is abnormal.

[0026] Beneficial effects of the present invention:

[0027] In the process of debugging the trusted measurement chip function, developers avoid the technical problem of being unable to start the system due to trusted measurement failure or damage, thereby being unable to obtain measurement results, which greatly improves the work efficiency of developers. The system structure of the present invention is simple, easy to implement, novel in control logic, and strong in practicality. BRIEF DESCRIPTION OF THE DRAWINGS

[0028] Figure 1 : System architecture block diagram of embodiment 1 of the present invention. DETAILED DESCRIPTION

[0029] The present invention is described in detail below with reference to the accompanying drawings and embodiments.

[0030] This embodiment is described by taking the CPU processor using the Rockchip domestic processor model RK3568, the trusted measurement module using the chip model CCM3310, the FLASH memory using the chip model GD25LQ128ESIG, the CPLD programmable logic device using the chip model Ziguang CPLD PGC2KL_6ISSBG256, and the analog signal switch using the device model SGM44600 as an example. The specific actual application can be replaced accordingly according to the specific situation.

[0031] like Figure 1 As shown, a trusted debugging system includes a Rockchip RK3568 domestic processor, a trusted measurement module CCM3310, a FLASH memory GD25LQ128ESIG, a Tsinghua Unigroup CPLD PGC2KL_6ISSBG256 chip, and an analog signal switch SGM44600.

[0032] The Unisplendour CPLD PGC2KL_6ISSBG256 chip is electrically connected to the FLASH memory GD25LQ128ESIG through the analog signal switch SGM44600. The Unisplendour CPLD PGC2KL_6ISSBG256 chip is electrically connected to the trusted measurement module CCM331, and when the Unisplendour CPLD PGC2KL_6ISSBG256 chip is powered on, the FLASH memory GD25LQ128ESIG is enabled to be powered on, and a TPCM_RESET_IN reset signal is also sent to the trusted measurement module CCM3310.

[0033] In the initial state, after the Tsinghua CPLD PGC2KL_6ISSBG256 chip is powered on, it controls the analog signal switch SGM44600 to electrically connect the trusted measurement module CCM3310 with the FLASH memory GD25LQ128ESIG, that is, the signal SPI_CH_SEL sent by the Tsinghua CPLD PGC2KL_6ISSBG256 chip to the analog signal switch SGM44600 is at a low level. When the signal SPI_CH_SEL received by the analog signal switch SGM44600 is at a low level, the trusted measurement module CCM3310 will be connected to the FLASH memory GD25LQ128ESIG.

[0034] The FLASH memory GD25LQ128ESIG stores a boot file of the operating system, and the operating system can be successfully started by loading and running the boot file.

[0035] The trusted measurement module CCM3310 will perform a reset operation after receiving the TPCM_RESET_IN reset signal, and after the reset is completed, it will start to measure the files in the FLASH memory GD25LQ128ESIG, and send the measurement result signal TPCM_RESET_OUT to the Ziguang CPLD PGC2KL_6ISSBG256 chip;

[0036] The Ziguang CPLD PGC2KL_6ISSBG256 chip processes the received measurement result signal TPCM_RESET_OUT, and the specific processing method is as follows:

[0037] When the measurement result signal TPCM_RESET_OUT is at a high level, it means that the measurement result is successful. The Tsinghua Unigroup CPLD PGC2KL_6ISSBG256 chip directly assigns the signal TPCM_RESET_OUT value to the reset signal CPU_RST_N, that is, the reset signal CPU_RST_N is also at a high level, and sends the reset signal CPU_RST_N to the Rockchip RK3568 domestic processor to reset the Rockchip RK3568 domestic processor, thereby realizing the smooth startup of the operating system.

[0038] When the measurement result signal TPCM_RESET_OUT is at a low level, indicating that the measurement result is a failure, the Unisplendour CPLD PGC2KL_6ISSBG256 chip sends a high level signal SPI_CH_SEL to the analog signal switch SGM44600. After receiving the high level signal SPI_CH_SEL, the analog signal switch SGM44600 establishes an electrical connection between the FLASH memory GD25LQ128ESIG and the Rockchip RK3568 domestic processor. The Unisplendour CPLD PGC2KL_6ISSBG256 chip then assigns the reset signal CPU_RST_N to a high level signal and sends it to the Rockchip RK3568 domestic processor, thereby realizing the smooth startup of the operating system.

[0039] After the operating system is successfully started, the Rockchip RK3568 domestic processor reads the measurement information of the trusted measurement module CCM3310 through I2C protocol communication, and compares the measurement information with the BIOS file check value in the actual FLASH memory GD25LQ128ESIG to see if they are consistent. If they are consistent, it means that the measurement work of the trusted measurement module CCM3310 is normal, otherwise it means that the work is abnormal, thereby accurately judging whether the trusted measurement module CCM3310 is carrying out the measurement work normally.

[0040] The working method of this embodiment is described in detail below. A trusted debugging method includes the following steps:

[0041] S1: In the initial state, after the Ziguang CPLD PGC2KL_6ISSBG256 chip is powered on, the timing is 10ms, and then the FLASH memory GD25LQ128ESIG is enabled for power supply;

[0042] S2: 15ms after the FLASH memory GD25LQ128ESI is powered on, the Unisplendour CPLD PGC2KL_6ISSBG256 chip sends a reset signal TPCM_RESET_IN to the trusted measurement module CCM3310. After receiving the reset signal TPCM_RESET_IN, the trusted measurement module CCM3310 completes the reset operation and starts measurement work;

[0043] S3: After the measurement work, the timer is set to 4s (normally measuring a 4M BIOS takes about 2.8s). Within 4s, the trusted measurement module CCM3310 sends the measurement result signal TPCM_RESET_OUT to the Unisplendour CPLD PGC2KL_6ISSBG256 chip. The Unisplendour CPLD PGC2KL_6ISSBG256 chip processes the measurement result signal TPCM_RESET_OUT. When the measurement result signal TPCM_RESET_OUT is at a high level, it indicates that the measurement is successful, and then the process goes to step S5. When the measurement result signal TPCM_RESET_OUT is at a low level, it indicates that the measurement fails, and the operating system cannot be started, and then the process goes to the next step S4. If the Unisplendour CPLD PGC2KL_6ISSBG256 chip does not receive the measurement result signal TPCM_RESET_OUT after more than 4s, the trusted measurement module CCM3310 is reset again in step S2.

[0044] S4: the Tsinghua CPLD PGC2KL_6ISSBG256 chip sends a high-level signal SPI_CH_SEL to the analog signal switch SGM44600. After receiving the high-level signal SPI_CH_SEL, the analog signal switch SGM44600 establishes an electrical connection between the FLASH memory GD25LQ128ESIG and the Rockchip RK3568 domestic processor. The timing is 20ms. The Tsinghua CPLD PGC2KL_6ISSBG256 chip sends a high-level CPU reset signal CPU_RST_N to the Rockchip RK3568 domestic processor. After receiving the CPU reset signal CPU_RST_N, the Rockchip RK3568 domestic processor completes the reset operation, so that the operating system can be successfully started;

[0045] S5: The Ziguang CPLD PGC2KL_6ISSBG256 chip directly assigns the value of the measurement result signal TPCM_RESET_OUT to the CPU reset signal CPU_RST_N, and sends the CPU reset signal CPU_RST_N to the Rockchip RK3568 domestic processor. After receiving the signal, the Rockchip RK3568 domestic processor completes the reset operation, so that the operating system successfully starts;

[0046] S6: When the operating system is started, the Rockchip RK3568 domestic processor reads the measurement information of the trusted measurement module CCM3310 through I2C protocol communication, and compares the measurement information with the BIOS file check value in the actual FLASH memory GD25LQ128ESIG to see if they are consistent. If they are consistent, it means that the measurement work of the trusted measurement module CCM3310 is normal, otherwise it means that the work is abnormal, thereby accurately judging whether the trusted measurement module CCM3310 is carrying out the measurement work normally.

[0047] This embodiment sends the measurement result of the trusted measurement module CCM3310 to the Unisplendour CPLD PGC2KL_6ISSBG256 chip for processing, and sets the analog signal switch SGM44600 so that when the measurement result is a failure, the Unisplendour CPLD PGC2KL_6ISSBG256 chip can control the analog signal switch SGM44600 to connect the Rockchip RK3568 domestic processor to the FLASH memory GD25LQ128ESIG communication, thereby achieving smooth startup of the operating system even when the measurement fails. In this way, when developers are debugging the trusted measurement module CCM3310 function, they avoid the technical problem that the operating system cannot be started due to the failure or damage of the trusted measurement, thereby failing to obtain the measurement result, which greatly improves the work efficiency of developers.

[0048] During debugging, this embodiment can also realize online upgrading of the firmware of the trusted measurement module CCM3310 through the I2C protocol. The entire debugging process does not require the trusted measurement module CCM3310 to be removed from the mainboard and then upgraded with the help of other tools, making the debugging work simple and convenient.

[0049] Finally, it should be noted that the above embodiments are only used to illustrate the present invention and are not intended to limit the technical solutions described in the present invention. Therefore, although the present invention has been described in detail with reference to the above embodiments, it should be understood by those skilled in the art that the present invention can still be modified or replaced by equivalents. All technical solutions and improvements that do not depart from the spirit and scope of the present invention should be included in the scope of the claims of the present invention.

Claims

1. A trusted debugging system, characterized in that: It includes CPU processor, trusted measurement module, FLASH memory, CPLD programmable logic device and analog signal switch; The CPLD programmable logic device is electrically connected to the FLASH memory through the analog signal switch, and the CPLD programmable logic device is electrically connected to the trusted measurement module, and when the CPLD programmable logic device is powered on, the FLASH memory is enabled to be powered on, and a first reset signal is sent to the trusted measurement module; The FLASH memory stores a boot file of the operating system, and the operating system can be successfully started by loading and running the boot file; The analog signal switch is used to select the FLASH memory to be electrically connected to the CPU processor or to be electrically connected to the trust measurement module according to the received signal; In the initial state, the CPLD programmable logic device sends a low-level switch signal to the analog signal switch after being powered on, and the analog signal switch establishes an electrical connection between the FLASH memory and the trusted measurement module after receiving the low-level switch signal; The trusted measurement module performs a reset after receiving the first reset signal, and starts to measure the files in the FLASH memory after the reset is completed, and sends the measurement results to the CPLD programmable logic device; If the measurement result is successful, the CPLD programmable logic device sends a successful measurement instruction to the CPU processor, and the operating system is directly started; If the measurement result is a failure, the operating system cannot be started, and the CPLD programmable logic device sends a high-level switch signal to the analog signal switch. After receiving the high-level switch signal, the analog signal switch establishes an electrical connection between the FLASH memory and the CPU processor. Then, the CPLD programmable logic device sends a reset instruction to the CPU processor. After receiving the reset instruction, the CPU processor completes the reset, thereby starting the operating system.

2. A trusted debugging system according to claim 1, characterized in that: The CPU processor is electrically connected to the trusted measurement module and is used to read the measurement result of the trusted measurement module.

3. A trusted debugging system according to claim 2, characterized in that: The CPU processor communicates with the trusted measurement module through an I2C protocol.

4. A trusted debugging system according to claim 3, characterized in that: The CPU processor performs an online upgrade operation on the firmware program of the trusted measurement module through the I2C protocol.

5. A trusted debugging system according to claim 1, characterized in that: The CPU processor is Rockchip RK3568 processor.

6. A trusted debugging system according to claim 1, characterized in that: The trusted measurement module is a CCM3310 chip.

7. A trusted debugging system according to claim 1, characterized in that: The CPLD programmable logic device is a CPLD PGC2KL_6ISSBG256 chip.

8. A trusted debugging method, characterized in that: Applying the trusted debugging system as claimed in claim 1, the steps are: S1: After the CPLD programmable logic device is powered on, the FLASH memory is enabled to supply power; S2: After the FLASH memory is powered, the CPLD programmable logic device sends a reset signal to the trusted measurement module. After receiving the reset signal, the trusted measurement module completes the reset and starts measurement work; S3: within a certain period of time, the trusted measurement module sends the measurement result to the CPLD programmable logic device. If the measurement result is successful, the operating system will be directly started successfully; if the measurement result is failed, the operating system cannot be started, and the process goes to step S4; S4: The CPLD programmable logic device sends a high-level switch signal to the analog signal switch. After receiving the high-level switch signal, the analog signal switch electrically connects the FLASH memory to the CPU processor, and then sends a reset signal to the CPU processor, so that the CPU processor performs a reset operation. After the reset is completed, the operating system is successfully started.

9. The trusted debugging method according to claim 8, characterized in that: The process also includes step S5: when the operating system is successfully started, the CPU processor reads the measurement result of the trusted measurement module through the I2C communication protocol, and compares the value of the measurement result with the BIOS file check value in the FLASH memory to see if they are consistent. If they are consistent, it indicates that the trusted measurement module is measuring normally. If they are inconsistent, it means that the measurement of the trusted measurement module is abnormal.

Citation Information

Patent Citations

  • BIOS trusted measurement method and device and terminal equipment

    CN111046392A

  • Bidirectional authentication trusted starting system and method based on TPCM chip

    CN114077740A