Security module, security chip, communication device and communication system
By introducing XOR gate units and OR gate units as protective circuits into the security chip, combined with a verification unit and registers, damage to the top metal can be detected in real time and verification data can be generated. This solves the problem of the top metal being vulnerable to attack and improves the security and legitimacy of communication equipment.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- GUANGZHOU ZHONO ELECTRONICS TECH CO LTD
- Filing Date
- 2024-11-22
- Publication Date
- 2026-05-29
AI Technical Summary
The top-level metal protection technology of existing security chips is vulnerable to reverse engineering attacks, leading to security risks and failing to effectively prevent the theft of sensitive information.
A protection circuit is formed by using XOR gate units and OR gate units. Combined with a verification unit and a register, the output of the XOR gate unit is compared with the communication data to detect whether the top metal has been damaged in real time. If it is damaged, protection measures are activated. At the same time, a selector generates verification data to identify legitimate communication objects.
It improves the security of communication equipment, enabling timely identification and prevention of the top metal layer being hacked, ensuring the security and legitimacy of communication data, and preventing attackers from stealing information.
Smart Images

Figure CN119561701B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of communication technology, and more specifically, to a security protection module, a security chip, a communication device, and a communication system. Background Technology
[0002] A security chip is a chip capable of independently generating and encrypting / decrypting keys. It has its own processor and storage unit to store keys and feature data, providing encryption and security authentication services for devices. With the development of security chips, techniques for attacking them have also emerged, making security chip protection technologies increasingly important.
[0003] However, some current protection technologies can no longer meet the security requirements of security chips in certain specific scenarios. For example, active shielding layer technology, also known as top-layer metal protection layer technology, works by using the top-layer metal wiring of the security chip, such as... Figure 1 As shown, Figure 1 This is a structural block diagram of a security chip in related technologies. The active shielding layer module forms a complex wiring network to shield the normal logic of the chip. At the same time, it works with related protection logic to detect the integrity of the top metal layer. This enables the implementation of protective measures to prevent sensitive information from being further attacked when the top metal layer is damaged.
[0004] Please see Figure 2 , Figure 2 yes Figure 1 The block diagram of the active shielding layer module in the image illustrates the working principle of the aforementioned protection logic: The output value of the active signal is compared with the output value via the top-layer metal wiring. When they are equal, it indicates that the top-layer metal has not been damaged; conversely, when they are unequal, it indicates that the top-layer metal has been damaged. In this case, the comparator will trigger an attack flag, and the security chip will execute corresponding protection measures. However, for attackers based on reverse engineering, with extremely low-cost focused ion beam (FIB) attacks, the attack flag can be fixed to a "no attack" or "comparison passed" state, rendering the top-layer metal meaningless and allowing attackers to probe and attack the chip. Therefore, current chip protection technologies are relatively easy to crack, resulting in certain security vulnerabilities in security chips. Summary of the Invention
[0005] In view of this, the purpose of the present invention is to provide a security protection module, a security chip, a communication device, and a communication system to at least improve communication security.
[0006] To achieve the above objectives, the technical solutions adopted in the embodiments of the present invention are as follows:
[0007] A first aspect of the present invention provides a security protection module, including an active signal input terminal, a top metal layer, an XOR gate unit, an OR gate, a gate unit, a verification unit, and a register;
[0008] The active signal input terminal is used to receive communication data and transmit the communication data in parallel to the top layer metal, the XOR gate unit, and the gate unit;
[0009] The output terminal of the top metal is connected to the other input terminal of the XOR gate unit;
[0010] The two outputs of the XOR gate unit are respectively connected to the other input of the gate unit and the OR gate; the OR gate is used to output an attack flag indicating whether the top layer metal has been damaged;
[0011] The gate unit, the verification unit, and the register are connected in series. The gate unit is an XOR gate unit or an OR gate unit. The register is used to output the verification data output by the verification unit.
[0012] Specifically, if the output of the gate unit is inconsistent with the communication data accessed by the active signal input terminal when the attack flag indicates that the top layer metal has not been damaged, it indicates that the top layer metal has been damaged.
[0013] The security protection module provided in this embodiment of the invention forms a first protection circuit through a top-layer metal, XOR gate units, and OR gates; a second protection circuit through XOR gate units and gate units; and a third protection circuit through gate units, a verification unit, and a register. This allows the top-layer metal to be damaged by an attack, causing the attack flag output by the first protection circuit to be set to a state indicating that the top-layer metal is not damaged. However, because the top-layer metal is damaged, the output of the XOR gate units inevitably changes relative to the undamaged state. Since the XOR gate units are part of the second protection circuit, their output affects the output of the gate units in the second protection circuit. That is, when the top-layer metal is not damaged, the output of the XOR gate units and the output obtained after processing the communication data should be consistent with the communication data; however, when the top-layer metal is damaged, because the output of the XOR gate units changes relative to the undamaged state, the output of the XOR gate units and the output obtained after processing the communication data are inconsistent with the communication data. This allows communication devices equipped with security protection modules to detect whether they have been attacked (i.e., whether the top metal has been damaged) even when the top metal is damaged but the attack flag is set to indicate that the top metal is not damaged. This enables timely activation of protection measures, thereby improving communication security. Furthermore, the verification unit in the third protection circuit calculates verification data to be sent to the receiver based on the output of the gate unit. This allows the receiver to determine whether the sender has been attacked based on the received communication data and the verification data. Consequently, even if the sender is attacked, the receiver can also promptly implement corresponding protection measures to prevent the theft of communication data, further enhancing communication security.
[0014] In an optional implementation, the two outputs of the XOR gate unit produce the same result;
[0015] When the top layer metal is not damaged, the XOR results output by the XOR gate unit contain the same values, and the attack flag output by the OR gate is a first preset value, which is used to indicate that the top layer metal is not damaged; when the top layer metal has been damaged, the XOR results output by the XOR gate unit contain different values, and the attack flag output by the OR gate is a second preset value, which is used to indicate that the top layer metal has been damaged.
[0016] In an optional implementation, the security protection module further includes a selector; the selector includes two input terminals for accessing external communication data and internal communication data, respectively, or the selector further includes a third input terminal for accessing an internal random code stream; the output terminal of the selector is connected to the active signal input terminal.
[0017] By incorporating a selector within the security protection module, the module can not only generate verification data to be sent to the receiver based on internal communication data, but also calculate legitimate verification data based on external communication data sent by the receiver. This legitimate verification data is then compared with the external verification data sent by the receiver to determine the receiver's legitimacy. This allows communication devices equipped with the security protection module provided in this embodiment to identify whether the receiver is being impersonated by an attacker, thereby further enhancing communication security. Furthermore, the selector is also equipped with an input terminal for accessing an internal random bitstream. This allows the security device to perform a self-check using the internal random bitstream upon power-up to determine if it has been attacked. This prevents data reading and communication from continuing even under attack, thus avoiding data theft by the attacker and further enhancing communication security.
[0018] In an optional implementation, the number of XOR gates in the XOR gate unit is the same as the number of bits in the communication data, and the number of gates in the gate unit is the same as the number of bits in the communication data.
[0019] With the above configuration, the XOR gate unit and the gate unit can process the communication data of the corresponding number of bits normally, avoiding errors.
[0020] In a second aspect, the present invention provides a security chip, including a processor and a security protection module provided in any of the first aspects above; the active signal output terminal of the processor is connected to the active signal input terminal of the security protection module, and the verification data input terminal of the processor is connected to the output terminal of the register.
[0021] A third aspect of the present invention provides a communication device including the security protection module provided in any of the first aspects described above.
[0022] In an optional implementation, before the communication device sends the target data to the data receiver, the security protection module calculates sender verification data based on the target data, and then sends the target data and the sender verification data to the data receiver.
[0023] In an optional implementation, the security protection module is a security protection module without a selector; when the communication device receives external communication data and external verification data sent from the outside, it calculates the valid verification data of the external communication data through its own configured verification module, and compares whether the external verification data and the valid verification data are consistent. If the external verification data and the valid data are inconsistent, protection measures are activated.
[0024] In an optional implementation, the security protection module is a security protection module configured with a selector; when the communication device receives external communication data and external verification data sent from the outside, it controls the selector of the security protection module to access the external communication data, and calculates the valid verification data of the external communication data through the security protection module, and compares whether the external verification data and the valid verification data are consistent. If the external verification data and the valid data are inconsistent, protection measures are activated.
[0025] In an optional implementation, the security protection module is a security protection module including a selector with three input terminals; when the communication device is powered on, it controls the selector of the security protection module to access the internal random code stream, and determines whether the top layer metal has been damaged based on the internal random code stream through the security protection module, and activates protection measures when it is determined that the top layer metal has been damaged.
[0026] A fourth aspect of the present invention provides a communication system including a host and a slave connected in communication; at least one of the host and the slave is a communication device provided in any of the third aspects above.
[0027] Since the security chip, communication device, and communication system provided by the present invention include the security protection module provided in any of the first aspects of the embodiments of the present invention, the communication device and communication system provided by the present invention also have the beneficial technical effects produced by the security protection module provided in any of the first aspects, which will not be elaborated here.
[0028] To make the above-mentioned objects, features and advantages of the present invention more apparent and understandable, preferred embodiments are described below in detail with reference to the accompanying drawings. Attached Figure Description
[0029] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings used in the embodiments will be briefly introduced below. It should be understood that the following drawings only show some embodiments of the present invention and should not be regarded as a limitation on the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.
[0030] Figure 1 A structural block diagram of a security chip in the related technology is shown;
[0031] Figure 2 It shows Figure 1 The structural block diagram of the active shielding layer module in the middle;
[0032] Figure 3 This diagram illustrates a structural block diagram of a security protection module provided in an embodiment of the present invention.
[0033] Figure 4 A structural block diagram of another security protection module provided in an embodiment of the present invention is shown.
[0034] Icons: A - Communication data, B - Output of top-layer metal, C - Output of XOR gate, D - Output of gate, E - Verification data output by the verification unit. Detailed Implementation
[0035] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. The components of the embodiments of the present invention described and shown in the accompanying drawings can generally be arranged and designed in various different configurations.
[0036] Therefore, the following detailed description of the embodiments of the invention provided in the accompanying drawings is not intended to limit the scope of the claimed invention, but merely to illustrate selected embodiments of the invention. All other embodiments obtained by those skilled in the art based on the embodiments of the invention without inventive effort are within the scope of protection of the invention.
[0037] It should be noted that similar labels and letters in the following figures indicate similar items. Therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures.
[0038] In the description of this invention, it should be noted that when terms such as "center," "upper," "lower," "left," "right," "vertical," "horizontal," "inner," and "outer" are used, these terms indicate the orientation or positional relationship based on the orientation or positional relationship shown in the corresponding drawings, or the orientation or positional relationship commonly used when the product of the invention is in use. They are used only for the convenience of describing the invention and for simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation. Therefore, they should not be construed as limitations on the invention. Furthermore, the terms "first," "second," and "third," etc., are used only to distinguish descriptions and should not be construed as indicating or implying relative importance.
[0039] Furthermore, terms such as "horizontal" and "vertical" do not imply that the component must be absolutely horizontal or suspended, but rather that it can be slightly tilted. For example, "horizontal" may simply mean that its direction is more horizontal than "vertical," and does not mean that the structure must be completely horizontal, but can be slightly tilted.
[0040] In the embodiments of the present invention, it should also be noted that, unless otherwise explicitly specified and limited, the terms "set," "install," "connect," "link," etc., should be interpreted broadly. For example, they can refer to a fixed connection, a detachable connection, or an integral connection; they can refer to a mechanical connection or an electrical connection; they can refer to a direct connection or a connection through an intermediate medium; and they can refer to the internal connection of two components. For those skilled in the art, the specific meaning of the above terms in the present invention can be understood according to the specific circumstances.
[0041] To address the technical problem that the top metal layer of security chips is easily compromised, leading to significant security vulnerabilities, this invention provides a security protection module. This module forms a first protection circuit using the top metal layer, XOR gates, and OR gates; a second protection circuit using XOR gates and gates; and a third protection circuit using gates, a verification unit, and a register. When the top metal layer is damaged by an attack, the attack flag output by the first protection circuit is reset to indicate that the top metal layer is not damaged. However, because the top metal layer is damaged, the output of the XOR gates inevitably changes relative to the undamaged state. Since the XOR gates are part of the second protection circuit, their output affects the output of the gates in the second protection circuit. Specifically, when the top metal layer is intact, the output of the XOR gates and the output obtained after processing the communication data should be consistent with the communication data. However, when the top metal layer is damaged, because the output of the XOR gates changes relative to the undamaged state, the output of the XOR gates and the output obtained after processing the communication data are inconsistent with the communication data. This allows communication devices equipped with security protection modules to detect whether they have been attacked (i.e., whether the top metal has been damaged) even when the top metal is damaged but the attack flag is set to indicate that the top metal is not damaged. This enables timely activation of protection measures, thereby improving communication security. Furthermore, the verification unit in the third protection circuit calculates verification data to be sent to the receiver based on the output of the gate unit. This allows the receiver to determine whether the sender has been attacked based on the received communication data and the verification data. Consequently, even if the sender is attacked, the receiver can also promptly implement corresponding protection measures to prevent the theft of communication data, further enhancing communication security.
[0042] The following, combined with Figure 3 The security protection module provided in the embodiments of the present invention will be described in detail. Please refer to [link / reference]. Figure 3 , Figure 3This is a structural block diagram of a security protection module provided in an embodiment of the present invention; the security protection module includes an active signal input terminal, a top metal layer, an XOR gate unit, an OR gate, a gate unit, a verification unit, and a register.
[0043] The active signal input terminal is used to receive communication data and transmit the communication data in parallel to the top layer metal, the XOR gate unit, and the gate unit.
[0044] The output terminal of the top layer metal is connected to the other input terminal of the XOR gate unit.
[0045] The two outputs of the XOR gate unit are respectively connected to the other input of the gate unit and the OR gate; the OR gate is used to output an attack flag indicating whether the top layer metal has been damaged.
[0046] The gate unit, the verification unit, and the register are connected in series. The gate unit is an XOR gate unit or an OR gate unit. The register is used to output the verification data output by the verification unit.
[0047] Specifically, if the output of the gate unit is inconsistent with the communication data accessed by the active signal input terminal when the attack flag indicates that the top layer metal has not been damaged, it indicates that the top layer metal has been damaged.
[0048] Furthermore, the structure and technical principles of the top layer metal can be found in relevant technologies, and will not be elaborated here.
[0049] The security protection module provided in this invention can be a standalone circuit module product, assembled in a security chip or communication device; or it can be a part of a security chip or communication device, pre-assembled in the security chip or communication device at the time of manufacture and sold together with the security chip or communication device. The communication device includes, but is not limited to: the master and slave devices in a master-slave communication system, as well as other devices requiring consideration of communication security.
[0050] When applying the security protection module provided in the embodiments of the present invention to a communication device, the working principle of the security protection module is explained below using a slave device as an example:
[0051] Please continue reading. Figure 3 When the slave device needs to send communication data to the master device, the communication data is used as an active signal of the security protection module and input to the security protection module through the active signal input terminal. At this time, signal A at the active signal input terminal is the communication data. Then, after the communication data A is processed by the top metal layer, the output result of the top metal layer is B.
[0052] Subsequently, the XOR gate unit performs an XOR operation on each bit of the communication data A and each bit of the output result B, obtaining the result C formed by XORing the corresponding bits of the communication data A and the corresponding bits of the output result B. At this point, if the top layer metal is not damaged, for example, if the wiring network is intact, then each bit of the result C is 0; conversely, if the top layer metal is damaged, for example, if the wiring network is incomplete, then the XOR result of the bit corresponding to the damaged wiring in the top layer metal is 1, that is, the corresponding bit in the result C is 1.
[0053] Next, the OR gate performs an OR operation on all bits of the result C. As described above regarding C, the attack flag outputs logic 0 if and only if every bit of C is 0, indicating that the top-layer metal has not been damaged and communication data can pass safely. Conversely, if any bit of C is not 0, the attack flag outputs logic 1, indicating that the top-layer metal is under attack. In this case, the slave device will perform protective measures, such as resetting or issuing a warning to associated devices to alert them of the communication risk, or alerting relevant users through associated devices to resolve the security issue in a timely manner. Although the above example uses every bit of C being 0 as an XOR result indicating that the top-layer metal has not been damaged, in other modified embodiments, the XOR gate unit can be replaced with an XNOR gate unit, in which case every bit of C must be 1 to indicate that the top-layer metal has not been damaged. In other words, when the top layer metal is not damaged, the XOR results output by the XOR gate all contain the same value, and the attack flag output by the OR gate is a first preset value, which indicates that the top layer metal is not damaged. When the top layer metal has been damaged, the XOR results output by the XOR gate contain different values, and the attack flag output by the OR gate is a second preset value, which indicates that the top layer metal has been damaged. Therefore, the slave device can determine whether to execute protective measures based on the value output by the attack flag.
[0054] Furthermore, in the example above, the attack flag outputs 0 when the top metal is not damaged, and outputs 1 when the top metal is being attacked. It can be seen that the first set value is 0 and the second set value is 1. However, in other variations, the two can be interchanged; that is, the first set value can be 1 and the second set value can be 0. Based on this, the attack flag outputs 1 when the top metal is not damaged, and outputs 0 when the top metal is being attacked.
[0055] Simultaneously or subsequently, the gate unit continues to perform OR or XOR operations on each bit of the communication data A and each bit of the output result C, respectively, to obtain the corresponding result D. Since the gate unit is an OR gate unit or an XOR gate unit, it can be known that when the top metal is not attacked or the wiring is complete, D = A; conversely, when the top metal has been attacked or the wiring is incomplete, D ≠ A. It is important to note that when the gate unit is an OR gate unit, as long as one of the corresponding bits in A and C is 1, the result of the OR operation on that corresponding bit will be 1. For example, if A = 10 and C = 10, the result D obtained by XORing the corresponding bits in A and C is 10. It can be seen that in this case, even if C represents that the top metal has been damaged, the result D obtained after the gate unit performs the OR operation on A and C is still related to A. It is evident that the gate unit using the OR gate unit has certain security vulnerabilities. Therefore, in order to solve this technical problem, in some embodiments, the gate unit is preferentially configured as an XOR gate unit. Continuing with the above example, after using the XOR gate unit as the gate unit, the result D obtained after performing the XOR operation on A and C is 00, which is obviously different from A. It can be seen that it can correctly detect whether the top metal has been damaged.
[0056] Next, the value of D is passed to the verification unit for verification data calculation, resulting in verification data E. After verification data E is stored in the register, the register can send the verification data E to the host via the IIC serial communication bus.
[0057] It is evident that when the top metal layer is damaged, even if the attacker sets the attack flag to the pass state, indicating that the top metal layer is not damaged, the verification data calculated by the security protection module will still be affected by the attack. At this time, the security protection module cannot calculate the correct verification data. Therefore, when the host receives the communication data and verification data sent by the slave device, it can detect whether the slave device has been attacked by simply calculating the verification data based on the communication data and comparing the calculated verification data with the verification data sent by the slave device. When it is determined that the slave device has been attacked, the host can promptly implement the corresponding protection measures.
[0058] The communication data mentioned above may include, but is not limited to: instruction data, text data, password data, and true random numbers.
[0059] Furthermore, as can be seen from the above, both the XOR gate unit and the gate unit need to perform related gate operations on each bit of the data received from their two input terminals. Therefore, in order to ensure the smooth and correct execution of the gate operations on the two sets of input data, the number of XOR gates contained in the XOR gate unit is the same as the number of bits of the communication data, and the number of gates contained in the gate unit is the same as the number of bits of the communication data.
[0060] As described above, although communication devices equipped with the aforementioned security protection modules can detect whether they are under attack and allow legitimate communication objects to detect whether they are under attack, the attacked communication device will still respond to the received communication data and verification data, and use other verification modules configured outside the security protection modules to calculate verification data based on the received communication data. In this case, the calculated verification data may be identical to the received verification data, causing the communication device to be unable to identify whether the current data sender is legitimate. For example, assuming the attacked communication device is a slave device, the slave device may be unable to determine whether the current data sender is a legitimate host or an attacker impersonating the host. In other words, the attacker can deceive the slave device by using the verification data calculation rules of the verification module configured inside the slave device to obtain the verification data, thereby causing the slave device to respond to relevant instructions and obtain the private data within the slave device. Therefore, to solve this technical problem, in some embodiments, the present invention also provides corresponding solutions, namely, please refer to... Figure 4 , Figure 4 This is a structural block diagram of another security protection module provided in an embodiment of the present invention. The security protection module provided in this embodiment of the present invention may further include a selector; the selector includes two input terminals, which are respectively used to access external communication data and internal communication data, or the selector further includes a third input terminal, which is used to access an internal random code stream; the output terminal of the selector is connected to the active signal input terminal.
[0061] The following will continue to use the example of a slave device in a communication device to illustrate the configuration of... Figure 4 The slave unit of the security protection module shown demonstrates how it identifies whether the sender is a legitimate host or an imposter:
[0062] Please continue reading Figure 4 When the slave device receives external communication data and external verification data sent by the sender, it first controls the selector of the security protection module to access the external communication data and uses it as an active signal. This signal is then input to the security protection module through the active signal input terminal, where signal A represents the external communication data. Next, after communication data A is processed by the top-layer metal, the output of the top-layer metal is B.
[0063] Subsequently, the XOR gate unit performs an XOR operation on each bit of the communication data A and each bit of the output result B to obtain the result C. At this time, if the top layer metal is not damaged, for example, if the wiring network is intact, then each bit of the result C is 0; conversely, if the top layer metal is damaged, for example, if the wiring network is incomplete, then the XOR result of the bit corresponding to the damaged wiring in the top layer metal is 1, that is, the corresponding bit in the result C is 1.
[0064] Next, the OR gate performs a bitwise OR operation on all bits of the result C. As can be seen from the above description of C, the attack flag outputs logic 0 if and only if every bit of C is 0, indicating that the top metal has not been damaged and communication data can pass safely. Conversely, if any bit of C is not 0, the attack flag outputs logic 1, indicating that the top metal is being attacked, and the slave device will perform protective measures.
[0065] Simultaneously or subsequently, the gate unit continues to perform OR or XOR operations on each bit of the external communication data A and each bit of the output result C, respectively, to obtain the corresponding result D. Since the gate unit is an OR gate unit or an XOR gate unit, it can be known that when the top metal is not attacked or the wiring is complete, D = A; conversely, when the top metal has been attacked or the wiring is incomplete, D ≠ A. It is important to note that when the gate unit is an OR gate unit, as long as one of the corresponding bits in A and C is 1, the result of the OR operation on that corresponding bit will be 1. For example, if A = 10 and C = 10, the result D obtained by XORing the corresponding bits in A and C is 10. It can be seen that in this case, even if C represents that the top metal has been damaged, the result D obtained after the gate unit performs the OR operation on A and C is still related to A. It is evident that the gate unit using the OR gate unit has certain security vulnerabilities. Therefore, in order to solve this technical problem, in some embodiments, the gate unit is preferentially configured as an XOR gate unit. Continuing with the above example, after using the XOR gate unit as the gate unit, the result D obtained after performing the XOR operation on A and C is 00, which is obviously different from A. It can be seen that it can correctly detect whether the top metal has been damaged.
[0066] Next, the value of D is passed to the verification unit for verification data calculation, resulting in verification data E. Verification data E is then output by the verification unit to the slave processor.
[0067] Subsequently, the slave device compares the verification data E with the external verification data. If they match, it indicates that the current sender is a legitimate host, and the slave device can function normally. If they do not match, it indicates that the current sender is impersonating the host, and the slave device can trigger an error code and will not respond to any subsequent commands from that sender. This prevents attackers from impersonating the host and continuing to simulate communication with the slave device after damaging the top metal layer of the slave device.
[0068] As can be seen, by configuring a selector in the security protection module, the security protection module can not only generate verification data to be sent to the receiver based on internal communication data, but also calculate legitimate verification data based on external communication data sent by the receiver. Then, the legitimate verification data is compared with the external verification data sent by the receiver to determine whether the receiver is legitimate. Thus, the communication device configured with the security protection module provided in this embodiment of the invention can identify whether the receiver is impersonated by an attack target, thereby further improving communication security.
[0069] Furthermore, to further enhance communication security, in embodiments where the selector is also equipped with an input terminal for accessing an internal random bitstream, the communication device can generate an internal random bitstream upon power-up and control the selector to select this internal random bitstream. This internal random bitstream is then input to the security protection device to determine whether the device itself has been attacked or whether the top-layer metal wiring is intact. The relevant principles are described above and will not be repeated here. Thus, the security protection module uses the internal random bitstream for self-testing, which can determine whether it has been attacked, thereby preventing data reading and communication from continuing even under attack and thus avoiding data theft by the attacker, further enhancing communication security.
[0070] In any of the above embodiments, the verification unit may be configured with any algorithm for implementing the verification calculation, such as Cyclic Redundancy Check (CRC), addition algorithm, subtraction algorithm, but not limited to these.
[0071] Corresponding to the embodiments of the security protection module, the embodiments of the present invention also provide a security chip, which includes a processor and a security protection module in any of the above embodiments of the present invention; the active signal output terminal of the processor is connected to the active signal input terminal of the security protection module, and the verification data input terminal of the processor is connected to the output terminal of the register.
[0072] Corresponding to the embodiments of the security protection module, the embodiments of the present invention also provide a communication device, which includes the security protection module 100 in any of the above embodiments of the present invention.
[0073] Based on this, before the communication device sends the target data to the data receiver, the security protection module calculates the sender verification data based on the target data, and then sends the target data and the sender verification data to the data receiver.
[0074] In any embodiment of the security protection module without a selector, when the communication device receives external communication data and external verification data sent from the outside, it calculates the valid verification data of the external communication data through its own configured verification module, and compares whether the external verification data and the valid verification data are consistent. If the external verification data and the valid data are inconsistent, protection measures are activated.
[0075] In any embodiment of the security protection module including a selector, when the communication device receives external communication data and external verification data sent from the outside, it controls the selector of the security protection module to access the external communication data, calculates the valid verification data of the external communication data through the security protection module, and compares whether the external verification data and the valid verification data are consistent. If the external verification data and the valid data are inconsistent, protection measures are activated.
[0076] Based on any embodiment of the security protection module including a selector with three input terminals, when the communication device is powered on, it controls the selector of the security protection module to access the internal random code stream, and determines whether the top layer metal has been damaged based on the internal random code stream through the security protection module, and activates protection measures when it is determined that the top layer metal has been damaged.
[0077] Corresponding to the embodiments of the security protection module, the embodiments of the present invention also provide a communication system, which includes a host and a slave device with a communication connection; at least one of the host and the slave device is a communication device in any of the above embodiments of the present invention.
[0078] In some embodiments, in order to improve the communication security between the host and slave devices and more effectively prevent the top-level metal from being quickly cracked and to prevent impersonating communication objects from stealing more important data, both the host and slave devices are configured with security protection modules from any of the above embodiments.
[0079] The security protection principles of the security chip, communication equipment, and communication system described above can be found in the relevant descriptions of the security protection module in any embodiment of the present invention, and will not be repeated here.
[0080] It is worth noting that the technical features or technical solutions in any of the above embodiments of the present invention can be combined or combined with each other, as long as there is no contradiction in the combination or combination.
[0081] The above description is merely a preferred embodiment of the present invention and is not intended to limit the invention. Various modifications and variations can be made to the present invention by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.
Claims
1. A security protection module, characterized in that, This includes active signal input terminals, top metal, XOR gate units, OR gates, gate units, check units, and registers; The active signal input terminal is used to receive communication data and transmit the communication data in parallel to the top layer metal, the XOR gate unit, and the gate unit; The output terminal of the top metal is connected to the other input terminal of the XOR gate unit; The two outputs of the XOR gate unit are respectively connected to the other input of the gate unit and the OR gate; the OR gate is used to output an attack flag indicating whether the top layer metal has been damaged; The gate unit, the verification unit, and the register are connected in series. The gate unit is an XOR gate unit or an OR gate unit. The register is used to output the verification data output by the verification unit, so that the receiver can determine whether the sender has been attacked based on the received communication data and the verification data. Specifically, if the output of the gate unit is inconsistent with the communication data accessed by the active signal input terminal when the attack flag indicates that the top layer metal has not been damaged, it indicates that the top layer metal has been damaged.
2. The security protection module according to claim 1, characterized in that, The two outputs of the XOR gate unit are the same; When the top layer metal is not damaged, the XOR results output by the XOR gate unit contain the same values, and the attack flag output by the OR gate is a first preset value, which is used to indicate that the top layer metal is not damaged; when the top layer metal has been damaged, the XOR results output by the XOR gate unit contain different values, and the attack flag output by the OR gate is a second preset value, which is used to indicate that the top layer metal has been damaged.
3. The security protection module according to claim 1 or 2, characterized in that, It also includes a selector; the selector has two input terminals, which are used to access external communication data and internal communication data respectively, or the selector also includes a third input terminal, which is used to access an internal random code stream; the output terminal of the selector is connected to the active signal input terminal.
4. The security protection module according to claim 1, characterized in that, The number of XOR gates in the XOR gate unit is the same as the number of bits in the communication data, and the number of gates in the gate unit is the same as the number of bits in the communication data.
5. A security chip, characterized in that, It includes a processor and a security protection module as described in any one of claims 1 to 4; the active signal output terminal of the processor is connected to the active signal input terminal of the security protection module, and the verification data input terminal of the processor is connected to the output terminal of the register.
6. A communication device, characterized in that, Includes the security protection module as described in any one of claims 1 to 4.
7. The communication device according to claim 6, characterized in that, Before sending target data to the data receiver, the communication device calculates sender verification data based on the target data through the security protection module, and then sends the target data and the sender verification data to the data receiver.
8. The communication device according to claim 6 or 7, characterized in that, The security protection module is the security protection module described in claim 1, 2, or 4; When the communication device receives external communication data and external verification data sent from outside, it calculates the valid verification data of the external communication data through its own configured verification module, and compares whether the external verification data and the valid verification data are consistent. If the external verification data and the valid verification data are inconsistent, protection measures are activated.
9. The communication device according to claim 6 or 7, characterized in that, The security protection module is the security protection module described in claim 4; When the communication device receives external communication data and external verification data sent from outside, it controls the selector of the security protection module to access the external communication data, and calculates the valid verification data of the external communication data through the security protection module. It then compares whether the external verification data and the valid verification data are consistent. If the external verification data and the valid verification data are inconsistent, protection measures are activated.
10. The communication device according to claim 9, characterized in that, The security protection module is a security protection module that includes a selector with three input terminals; When the communication device is powered on, it controls the selector of the security protection module to access the internal random code stream, and the security protection module determines whether the top layer metal has been damaged based on the internal random code stream, and activates protection measures when it is determined that the top layer metal has been damaged.
11. A communication system, characterized in that, It includes a host and a slave device with a communication connection; at least one of the host and the slave device is the communication device according to any one of claims 6 to 10.