A side channel attack protection system and device
By designing a side channel attack protection system in an encrypted hardware wallet, using current check circuits and random number generators to defend against DPA and SPA attacks, the security risks of traditional encrypted hardware wallets in the face of these attacks are solved, achieving higher security and data protection.
Patent Information
- Application Number
- CN202510105018.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-23
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2045-01-23
AI Technical Summary
Traditional crypto hardware wallets have security risks when facing side channel attacks such as DPA and SPA, and existing technologies are difficult to fully withstand these advanced attack technologies.
A side channel attack protection system is designed, including a power abnormality protection module, a main control module and an operation interaction module. The system enhances encryption randomness through current check circuits and random number generators and stops working when power abnormalities are detected to prevent attack behavior.
It effectively improves the resistance of encrypted electronic devices to attacks such as DPA and SPA, enhances the security of the device, and ensures the security of the data in encrypted electronic devices.
Smart Images

Figure CN119544187B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the fields of cryptography and information security, and in particular to a side channel attack protection system and device. Background Art
[0002] With the popularity of digital assets and the booming market of encrypted virtual resources, some encrypted electronic devices, such as encrypted hardware wallets, have become important tools for protecting the security of personal assets. Encrypted hardware wallets usually use physical isolation and cryptography technology to ensure the safe storage of private keys and other key information, and perform functions such as digital signatures and transaction authorization through cryptographic operations. However, with the continuous evolution of attack technology, traditional encrypted hardware wallets may face increasingly complex security threats.
[0003] Side-channel attack is an attack method that uses physical information accidentally leaked by computing devices when performing cryptographic operations to infer keys or other sensitive data. It mainly includes differential power analysis (DPA) and simple power analysis (SPA). In a DPA attack, the attacker analyzes the power consumption changes of cryptographic electronic devices in different operations to infer the encryption keys or other sensitive information inside the device. SPA attacks use electromagnetic radiation or other side channel information generated by cryptographic electronic devices when performing cryptographic operations to infer secret information inside the device by analyzing this information. These attack techniques may cause the private keys of cryptographic electronic devices to be leaked, resulting in theft or tampering of assets. Therefore, prevention of side-channel attacks such as DPA and SPA has become an important issue in the design of cryptographic electronic devices. Traditional solutions mainly rely on physical isolation and traditional cryptographic algorithms to protect the security of cryptographic electronic devices, but these methods may not be able to completely resist advanced attack techniques.
[0004] At present, the mainstream technical solutions are generally centered around the design, manufacture and application of encryption electronic devices. These solutions mainly focus on how to improve the security, usability and compatibility of encryption electronic devices. For example: using fingerprint recognition, key confirmation, etc. to further increase the security of transactions; by optimizing the user interface, simplifying the operation process, providing multi-language support, etc., the user threshold is lowered and the user experience is improved; usually supports the storage and management of multiple digital virtual resources to achieve a one-stop solution. However, the above technologies have certain defects. First, the designed encryption electronic devices adopt the same type of general electronic products, which cannot resist malicious disassembly, may lead to some design negligence or insufficient technical level, and make the encryption electronic devices have security risks in certain specific scenarios. Secondly, currently encryption electronic devices mostly use encryption chips to implement related algorithms and preserve their security, but it increases the cost of the product and also limits the solutions that can be adopted by the design product and the possibility of realizing rich product functions. In addition, the currently designed encryption electronic devices, such as encryption hardware wallet products, usually do not consider the prevention of DPA and SPA cracking, and for some algorithms that use fixed parameters for encryption or signing, their security is insufficient. Therefore, a more advanced and comprehensive design solution is needed to improve the resistance of encryption electronic devices to attacks such as DPA and SPA, and to improve the security, usability and compatibility of encryption electronic devices, thereby ensuring the security of data in encryption electronic devices. Summary of the invention
[0005] In view of this, the present application provides a side-channel attack protection system and device to improve the resistance of cryptographic electronic devices to attacks such as DPA and SPA, improve the security of cryptographic electronic devices, and thus ensure the security of data in the cryptographic electronic devices.
[0006] In a first aspect, the present application provides a side channel attack protection system, which is applied to encryption electronic equipment, and the system includes a power abnormality protection module, a main control module, and an operation interaction module;
[0007] The main control module includes a main controller module and a support module, which are used to provide an operating environment for the main controller, control and manage the operation of the side channel attack protection system;
[0008] The operation interaction module is used to display various options that need to be selected in the user's operation process, and perform corresponding processing according to the user's selection;
[0009] The power anomaly protection module includes a current checking circuit and a first random number generator. The first random number generator is used for the encryption electronic device to generate a random number when executing any instruction. The current checking circuit is used to periodically detect the actual power of the encryption electronic device and instruct the system to stop working when the actual power anomaly is detected.
[0010] Optionally, the system further includes an output power random control module;
[0011] The output power random control module includes a second random number generator, which is used to randomly adjust the generation algorithm of the second random number generator according to preset conditions, and map the random number generated by the second random number generator to the current control signal to make the output power random.
[0012] Optionally, the system further includes a hardware protection module, and the hardware protection module includes a first anti-disassembly module;
[0013] The first anti-disassembly module is used to activate a protection program to protect data in the encryption electronic device when it is determined through pressure detection and / or light detection that the encryption electronic device is abnormally opened.
[0014] Optionally, the hardware protection module further includes a second anti-disassembly module;
[0015] The second anti-disassembly module is used to wake up the MCU to protect the data in the encryption electronic device when it is determined through a spring button structure and / or a light-sensitive sensor that the encryption electronic device is opened abnormally.
[0016] Optionally, the hardware protection module further includes a third anti-disassembly module;
[0017] The third anti-disassembly module is used to fill the encryption electronic device with a flexible FPC circuit board drawn with a preset curve, and when an abnormality of the encryption electronic device is detected, wake up the MCU to protect the data in the encryption electronic device.
[0018] Optionally, the system further includes an abnormal temperature detection module;
[0019] The abnormal temperature detection module is used to detect the real-time temperature of the encryption electronic device through a temperature sensor, and protect the data in the encryption electronic device when it is determined that the real-time temperature exceeds a temperature threshold.
[0020] Optionally, the first random number generator is a true random number generator, and the second random number generator is a pseudo-random number generator.
[0021] Optionally, the preset curve is a Hilbert curve.
[0022] A second aspect of the present application provides a side channel attack protection device, which is applied to an encryption electronic device, and the device includes:
[0023] An operating environment providing unit, used to provide an operating environment for the main controller, and control and manage the operation of the side channel attack protection system;
[0024] The operation interaction unit is used to display various options that the user needs to select in the operation process and perform corresponding processing according to the user's selection;
[0025] The attack protection unit is used to generate a random number by a first random number generator when the encryption electronic device executes any instruction, and periodically detect the actual power of the encryption electronic device through a current detection circuit, and instruct the system to stop working when the actual power is detected to be abnormal.
[0026] Optionally, the device further comprises:
[0027] An output power random control unit, used for randomly adjusting a generation algorithm of a second random number generator according to preset conditions, and mapping the random number generated by the second random number generator to a current control signal, so that the output power has randomness;
[0028] A first anti-disassembly unit is used to activate a protection program to protect data in the encryption electronic device when it is determined through pressure detection and / or light detection that the encryption electronic device is abnormally opened;
[0029] A second anti-disassembly unit is used to wake up the MCU to protect the data in the encryption electronic device when it is determined through a spring button structure and / or a light-sensitive sensor that the encryption electronic device is abnormally opened;
[0030] A third anti-disassembly unit is used to fill the encryption electronic device with a flexible FPC circuit board with a preset curve drawn on it, and when an abnormality of the encryption electronic device is detected, wake up the MCU to protect the data in the encryption electronic device;
[0031] The abnormal temperature detection unit is used to detect the real-time temperature of the encryption electronic device through a temperature sensor, and protect the data in the encryption electronic device when it is determined that the real-time temperature exceeds a temperature threshold.
[0032] In the embodiments provided in the present application, for encryption electronic devices, in order to defend against DPA / SPA attacks, the device uses a random number generator built into the chip to generate random numbers when executing any instructions, thereby enhancing encryption randomness, and combines a current check circuit to detect abnormal power to ensure the security of data in the encryption electronic device.
[0033] Furthermore, the hardware protection module of the present application can provide multi-level protection for the encrypted electronic device at the hardware level through pressure detection, spring button structure, photosensitive sensor, flexible FPC circuit board with special curves drawn, and temperature sensor, effectively deal with scenarios such as violent disassembly, drilling, and unauthorized disassembly, and effectively ensure the security of data in the encrypted electronic device. BRIEF DESCRIPTION OF THE DRAWINGS
[0034] Figure 1 A system module diagram provided for an embodiment of the present application;
[0035] Figure 2 A logic diagram for implementing the dynamic random obfuscation strategy provided in an embodiment of the present application;
[0036] Figure 3 An internal structure diagram of a device provided in an embodiment of the present application;
[0037] Figure 4 A diagram of a flexible FPC circuit board provided in an embodiment of the present application;
[0038] Figure 5 A circuit design diagram provided for an embodiment of the present application;
[0039] Figure 6 A structural diagram of a device provided in an embodiment of the present application;
[0040] Figure 7 A schematic diagram of the internal structure of a computer device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0041] Exemplary embodiments will be described in detail herein, examples of which are shown in the accompanying drawings. When the following description refers to the drawings, the same numbers in different drawings represent the same or similar elements unless otherwise indicated. The implementations described in the following exemplary embodiments do not represent all implementations consistent with the present application. Instead, they are merely examples of devices and methods consistent with some aspects of the present application as detailed in the appended claims.
[0042] The terms used in this application are for the purpose of describing specific embodiments only and are not intended to limit this application. The singular forms of "a", "said" and "the" used in this application and the appended claims are also intended to include plural forms unless the context clearly indicates other meanings. It should also be understood that the term "and / or" used herein refers to and includes any or all possible combinations of one or more associated listed items.
[0043] It should be understood that although the terms first, second, third, etc. may be used in the present application to describe various information, these information should not be limited to these terms. These terms are only used to distinguish the same type of information from each other. For example, without departing from the scope of the present application, the first information may also be referred to as the second information, and similarly, the second information may also be referred to as the first information. Depending on the context, the word "if" as used herein may be interpreted as "at the time of" or "when" or "in response to determining".
[0044] The present application provides a side channel attack protection system and device to improve the resistance of cryptographic electronic devices to attacks such as DPA and SPA, improve the security of cryptographic electronic devices, and thus ensure the security of data in the cryptographic electronic devices.
[0045] The technical solution of the present application is described in detail with specific embodiments below. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described in detail in some embodiments.
[0046] like Figure 1 As shown, it is a module diagram of a side channel attack protection system provided by the present application, and the system includes a power anomaly protection module, a main control module, and an operation interaction module.
[0047] The following is an explanation of the composition and functions of each module:
[0048] 1. Main control module. This module includes a main controller module and a support module, which is used to provide an operating environment for the main controller and control and manage the operation of the side channel attack protection system.
[0049] In this embodiment, the main controller module may include a microcontroller unit MCU and a memory. The MCU is the brain of the main control unit, responsible for executing program instructions, processing data, and controlling other hardware components. The MCU generally includes one or more processor cores, memory (including program storage and data storage), input / output interfaces, etc. The memory includes a FLASH memory for storing firmware or operating systems. And a random access memory RAM for temporarily storing data and programs for access by the MCU during operation.
[0050] Support modules may include a power management module, which is responsible for providing a stable power supply to the MCU and other components, and may include voltage regulation, power monitoring, and battery management functions. A clock module provides a clock signal to the MCU to ensure the synchronous execution of instructions. A reset module provides a reset signal to restart the MCU when the system starts or an error occurs. Interface modules include three types of interface modules: serial port module, USB module, and Bluetooth module. The Bluetooth module is the core interface of this solution, providing the communication required for transactions, and the serial port and USB provide debugging and other uses.
[0051] 2. Operation interaction module: This module is used to display various options that users need to select in the operation process and perform corresponding processing according to the user's selection.
[0052] In this embodiment, an intuitive operation interface can be provided to the user through the display screen, and information such as text, images, and videos can be displayed on the operation interface, so that the user can clearly understand the current status and available options. The user is also allowed to interact with the device by directly touching the screen to perform operations such as sliding and clicking.
[0053] 3. Power abnormality protection module. This module includes a current checking circuit and a first random number generator. The first random number generator is used for the encryption electronic device to generate a random number when executing any instruction. The current checking circuit is used to periodically detect the actual power of the encryption electronic device and instruct the system to stop working when the actual power abnormality is detected.
[0054] Since DPA / SPA attack is a technology that infers specific operations in the encryption process by analyzing the system's working power disturbance. Its core principle is that there are differences in the power consumed when different instructions are executed. If the correspondence between power and instructions can be accurately established, it is possible to restore the entire encryption process and then crack the encryption. However, in order to obtain accurate inference results, the same operation needs to be monitored multiple times. The main goal of monitoring is to obtain sensitive information such as keys.
[0055] Therefore, in this embodiment, when the encryption electronic device executes any instruction, such as the instruction of key generation, storage, distribution and management, the security protocol configuration instruction or the data encryption and decryption instruction, the random number is generated by the first random number generator. When the cracker performs a DPA / SPA attack on the encryption electronic device, it is impossible to obtain the data generated by it through monitoring means, resulting in the inability to obtain the monitoring result, and thus the inability to obtain an accurate inference result.
[0056] Furthermore, since the hacker attempts to access the external detection circuit, it will affect the power of the entire system. Therefore, this system also adds a current detection circuit at the hardware level, which can periodically detect the actual power. Once the power is abnormal, the system will immediately stop working, thus effectively preventing potential attacks.
[0057] So far, completed Figure 1 Description of the system modules shown.
[0058] In the above embodiment, in order to defend against DPA / SPA attacks, the device uses the built-in random number generator of the chip to generate random numbers when executing any instructions to enhance encryption randomness, and combines the current detection circuit to detect abnormal power to ensure the security of data in the encryption electronic device.
[0059] In another embodiment, the system further comprises an output power random control module;
[0060] The output power random control module includes a second random number generator, which is used to randomly adjust the generation algorithm of the second random number generator according to preset conditions, and map the random number generated by the second random number generator to the current control signal to make the output power random.
[0061] This embodiment provides another random number generator, such as a pseudo-random number generator, and adopts a dynamic random confusion strategy, such as Figure 2 As shown in the figure, time management can be achieved through a beat scheduler or timer. Before the output signal, the encryption algorithm starts to start the obfuscation thread, and then the beat scheduler performs random scheduling. Finally, the output signal is encrypted by the random number generated by the random number generator. This makes the output power show unpredictable randomness, enhancing the ability to resist attacks such as DPA / SPA.
[0062] Through this embodiment, the anti-DPA / SPA attack capability of the encryption electronic device can be further enhanced.
[0063] In another embodiment, the system further comprises a hardware protection module, wherein the hardware protection module comprises a first anti-disassembly module;
[0064] The first anti-disassembly module is used to activate a protection program to protect data in the encryption electronic device when it is determined through pressure detection and / or light detection that the encryption electronic device is abnormally opened.
[0065] The first anti-disassembly module implemented in this embodiment is a structural anti-disassembly design, mainly through pressure detection and light detection. The pressure detection adopts a switch detection mode, and electrode contacts are arranged on the front, back and sides of the mainboard of the encryption electronic device. They are short-circuited through the shell design. When opened, the corresponding interrupt information will be triggered, thereby playing the role of preserving the security hardware.
[0066] For light detection, photoelectric detection sensors are arranged on the front and back sides of the motherboard. The corresponding light detection sensor positions are designed with a masking mechanical structure. When opened, abnormal light signals will be detected, and it can be determined that the casing of the encrypted electronic device has been opened. At the same time, the protection program will be activated and the relevant data will be deleted.
[0067] In another embodiment, the hardware protection module further includes a second anti-disassembly module;
[0068] The second anti-disassembly module is used to wake up the MCU to protect the data in the encryption electronic device when it is determined through a spring button structure and / or a light-sensitive sensor that the encryption electronic device is opened abnormally.
[0069] In this embodiment, four spring button structures are designed on the housing of the encryption electronic device, such as Figure 3As shown, 64, 65, 66, and 67 are four spring button structures on the housing. After installation, these spring button structures use a locking mechanism to firmly press the springs on the circuit board. Once the spring is released, it will automatically pop open, triggering an external interrupt signal. This signal quickly wakes up the MCU, and then resets the data in the encrypted electronic device. When the user actively disassembles the device, the external interrupt signal can be triggered by a command to stop, thereby avoiding data reset.
[0070] like Figure 3 As shown, this embodiment also adds 62, 63 photosensitive sensors inside the encryption electronic device, and the sensors are arranged on the front (component side) and back (non-component side) of the encryption electronic device. When the shell of the encryption electronic device is opened, the sensor is activated, and its resistance will change accordingly, and a switch level signal is finally generated through the comparator circuit. The signal wakes up the MCU, and then resets the data in the encryption electronic device. 61 is a temperature sensor, which can automatically protect when abnormal temperature occurs.
[0071] In another embodiment, the hardware protection module further includes a third anti-disassembly module;
[0072] The third anti-disassembly module is used to fill the encryption electronic device with a flexible FPC circuit board drawn with a preset curve, and when an abnormality of the encryption electronic device is detected, wake up the MCU to protect the data in the encryption electronic device.
[0073] Due to certain malicious operations, they do not open the device directly, but install monitoring or cracking devices on the circuit board inside the encrypted electronic device by drilling holes in the casing without triggering the first and second anti-disassembly module mechanisms mentioned above.
[0074] According to the shape of the housing, this embodiment designs a flexible FPC circuit board, such as Figure 4 As shown. The Hilbert curve is drawn on the circuit board, which allows the circuit board to fit tightly inside the housing. And the curve starts from the input end and has only one 71 input and one 72 output when reaching the output end. Based on this characteristic, in the circuit design such as Figure 5 ,in Figure 4 Connection between 71 and 72 Figure 5 To find the corresponding position in the curve, just apply a specific voltage signal to the input end of the curve and connect the output end to the comparator circuit to convert it into a switch signal. Once the signal is lost, it can be quickly determined whether the curve has been damaged, and then whether malicious behavior such as drilling has occurred. Once such damage is detected, the system will immediately wake up the MCU and reset the data in the encrypted electronic device to ensure the security of the device and the integrity of the data.
[0075] Through the above-mentioned first, second and third anti-disassembly modules, the encrypted electronic device can be protected at the hardware level at multiple levels, effectively dealing with scenarios such as violent disassembly, drilling, and unauthorized disassembly, and effectively ensuring the security of data in the encrypted electronic device.
[0076] In another embodiment, the system further comprises an abnormal temperature detection module;
[0077] The abnormal temperature detection module is used to detect the real-time temperature of the encryption electronic device through a temperature sensor, and protect the data in the encryption electronic device when it is determined that the real-time temperature exceeds a temperature threshold.
[0078] Because some encrypted electronic devices use rubber strips to install and reinforce their back covers, screens and other parts, this means that when the device needs to be disassembled, it is necessary to heat the device. In order to prevent the device from being damaged due to excessive temperature, a temperature sensor is designed on the encrypted electronic device in this embodiment, which can automatically provide protection when abnormal temperature occurs.
[0079] In the above embodiments, the system integrates a variety of protection measures to ensure the security of encrypted electronic devices and the integrity of data. Specifically, the system adopts an active protection strategy to detect and respond to unauthorized disassembly through spring buttons and photosensitive sensors. At the same time, the design of flexible FPC circuit boards and Hilbert curves can effectively prevent malicious operations such as drilling and cracking. In terms of anti-DPA / SPA attacks, the system uses the built-in TRNG module of the chip to generate random numbers, which enhances the randomness and unpredictability of the encryption process. In addition, the current check circuit monitors current changes and power anomalies in real time. Once an anomaly is found, the system will stop working immediately, thereby effectively preventing potential attacks. The comprehensive application of these key points provides the system with all-round and multi-level protection to ensure the user's information security and the integrity of the data in encrypted electronic devices.
[0080] The present application also provides a side channel attack protection device, which is applied to encryption electronic devices, such as Figure 6 As shown, the device comprises:
[0081] An operating environment providing unit 601 is used to provide an operating environment for the main controller, control and manage the operation of the side channel attack protection system;
[0082] The operation interaction unit 602 is used to display various options that need to be selected in the user's operation process and perform corresponding processing according to the user's selection;
[0083] The attack protection unit 603 is used to generate a random number through a first random number generator when the encryption electronic device executes any instruction. The current checking circuit is used to periodically detect the actual power of the encryption electronic device and instruct the system to stop working when the actual power is detected to be abnormal.
[0084] In another embodiment, the apparatus further comprises:
[0085] An output power random control unit 604, used to randomly adjust the generation algorithm of the second random number generator according to preset conditions, and map the random number generated by the second random number generator to the current control signal, so that the output power has randomness;
[0086] The first anti-disassembly unit 605 is used to activate a protection program to protect the data in the encryption electronic device when it is determined through pressure detection and / or light detection that the encryption electronic device is abnormally opened;
[0087] The second anti-disassembly unit 606 is used to wake up the MCU to protect the data in the encryption electronic device when it is determined through the spring button structure and / or the light-sensitive sensor that the encryption electronic device is opened abnormally;
[0088] The third anti-disassembly unit 607 is used to fill the encryption electronic device with a flexible FPC circuit board with a preset curve drawn on it, and when an abnormality of the encryption electronic device is detected, wake up the MCU to protect the data in the encryption electronic device;
[0089] The abnormal temperature detection unit 608 is used to detect the real-time temperature of the encryption electronic device through a temperature sensor, and protect the data in the encryption electronic device when it is determined that the real-time temperature exceeds a temperature threshold.
[0090] The above embodiment of the present invention provides a side channel attack protection system, and based on the system provides a side channel attack protection device. Through the above system and device, the ability of the encryption electronic device to resist attacks such as DPA and SPA is improved, the security of the encryption electronic device is improved, and the security of the data in the encryption electronic device is ensured.
[0091] This embodiment also discloses a computer device, such as Figure 7 As shown, the computer device includes a processor and a memory, wherein the memory stores at least one instruction, and the at least one instruction is loaded and executed by the processor to implement the functions of any of the side channel attack protection systems described above.
[0092] In addition, in the implementation of the side-channel attack protection device in the above-mentioned example, the logical division of each program module is only an example. In actual application, the above-mentioned functions can be assigned to different program modules as needed, for example, for the configuration requirements of the corresponding hardware or the convenience of software implementation. That is, the internal structure of the side-channel attack protection device is divided into different program modules to complete all or part of the functions described above.
[0093] The above description is only a preferred embodiment of the present application and is not intended to limit the present application. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present application shall be included in the scope of protection of the present application.
Claims
1. A side channel attack protection system, characterized in that: Applied to encryption electronic equipment, the system includes a power anomaly protection module, a main control module, an operation interaction module, an output power random control module and a hardware protection module; The main control module includes a main controller module and a support module, which are used to provide an operating environment for the main controller, control and manage the operation of the side channel attack protection system; The operation interaction module is used to display various options that need to be selected in the user's operation process, and perform corresponding processing according to the user's selection; The power abnormality protection module comprises a current checking circuit and a first random number generator, wherein the first random number generator is used for the encryption electronic device to generate a random number when executing any instruction, and the current checking circuit is used to periodically detect the actual power of the encryption electronic device and instruct the system to stop working when the actual power abnormality is detected; The output power random control module includes a second random number generator, adopts a dynamic random obfuscation strategy, starts the encryption algorithm to start the obfuscation thread before the output signal, and then performs random scheduling through the beat scheduler, and finally encrypts the current control signal with the random number generated by the second random number generator, so that the output power has randomness; The hardware protection module is used to fill the encryption electronic device with a flexible FPC circuit board drawn with a Hilbert curve, and when an abnormality is detected in the encryption electronic device, wake up the MCU to protect the data in the encryption electronic device, wherein the Hilbert curve only includes one input terminal and one output terminal, which is used to apply a signal of a specific voltage to the input terminal and connect the output terminal to a comparator circuit to convert it into a switching signal.
2. The system according to claim 1, characterized in that The hardware protection module includes a first anti-disassembly module; The first anti-disassembly module is used to activate a protection program to protect data in the encryption electronic device when it is determined through pressure detection and / or light detection that the encryption electronic device is abnormally opened.
3. The system according to claim 2, characterized in that The hardware protection module also includes a second anti-disassembly module; The second anti-disassembly module is used to wake up the MCU to protect the data in the encryption electronic device when it is determined through a spring button structure and / or a light-sensitive sensor that the encryption electronic device is opened abnormally.
4. The system according to claim 1, characterized in that The system also includes an abnormal temperature detection module; The abnormal temperature detection module is used to detect the real-time temperature of the encryption electronic device through a temperature sensor, and protect the data in the encryption electronic device when it is determined that the real-time temperature exceeds a temperature threshold.
5. The system according to claim 1, characterized in that The first random number generator is a true random number generator, and the second random number generator is a pseudo random number generator.
6. A side channel attack protection device, characterized in that: Applied to encryption electronic equipment, the device comprises: An operating environment providing unit, used to provide an operating environment for the main controller, control and manage the operation of the side channel attack protection system; The operation interaction unit is used to display various options that the user needs to select in the operation process and perform corresponding processing according to the user's selection; an attack protection unit, configured to generate a random number by a first random number generator when the encryption electronic device executes any instruction, and periodically detect the actual power of the encryption electronic device by a current detection circuit, and instruct the system to stop working when the actual power is detected to be abnormal; The output power random control unit adopts a dynamic random obfuscation strategy, starts the encryption algorithm to start the obfuscation thread before the output signal, and then performs random scheduling through the beat scheduler. Finally, the current control signal is algorithmically encrypted through the random number generated by the second random number generator, so that the output power has randomness; The hardware protection unit is used to fill the encryption electronic device with a flexible FPC circuit board drawn with a Hilbert curve, and when an abnormality of the encryption electronic device is detected, wake up the MCU to protect the data in the encryption electronic device, wherein the Hilbert curve only includes one input terminal and one output terminal, and is used to apply a signal of a specific voltage to the input terminal, and connect the output terminal to a comparator circuit to convert it into a switching signal.
7. The device according to claim 6, characterized in that The device also includes: A first anti-disassembly unit is used to activate a protection program to protect data in the encryption electronic device when it is determined through pressure detection and / or light detection that the encryption electronic device is abnormally opened; A second anti-disassembly unit is used to wake up the MCU to protect the data in the encryption electronic device when it is determined through a spring button structure and / or a light-sensitive sensor that the encryption electronic device is abnormally opened; The abnormal temperature detection unit is used to detect the real-time temperature of the encryption electronic device through a temperature sensor, and protect the data in the encryption electronic device when it is determined that the real-time temperature exceeds a temperature threshold.
Citation Information
Patent Citations
Internet of Things terminal safety protection device and method
CN112272083A
Safety management method of data collector
CN117439924A
High-integration semiconductor chip security detection system and method
CN118673538A