A method and chip for assisting firmware upgrade

By introducing security resources to the chip, the problem of insufficient storage space and security risks during firmware upgrades is solved, and efficient and secure firmware upgrades are achieved.

CN119597321BActive Publication Date: 2025-05-13北京中科昊芯科技有限公司
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510143259.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-10
Publication Date
2025-05-13
Estimated Expiration
2045-02-10

AI Technical Summary

Technical Problem

During the firmware upgrade process, the device may lack storage space, resulting in inefficient upgrade efficiency; at the same time, the security firmware may be tampered with or data leaked, posing a security risk.

Method used

By introducing security resource release control and monitoring devices into the chip, the security resource release control signal is configured as an effective state, and the secure storage resource is initialized and released as a non-secure storage resource to support firmware upgrades; when the upgrade is completed, the initial state of the secure storage resource is restored.

Benefits of technology

Improve the efficiency of firmware upgrades, ensure the security of the upgrade process, and prevent the leakage or tampering of secure data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119597321B_ABST
    Figure CN119597321B_ABST
Patent Text Reader

Abstract

The present application provides a method and chip for assisting firmware upgrade, which are applied to a chip, wherein the chip includes on-chip firmware and a security resource release control and monitoring device; the security resource release control and monitoring device provides a security resource release control signal to the security storage resource of the chip, and initializes the security storage resource after configuring the security resource release control signal to a valid state or a clear state; when the firmware is upgraded, the security resource release control signal is configured to a valid state, the security storage resource is initialized to erase the security data and security program and release the security storage resource as a non-security storage resource for assisting firmware upgrade; after the firmware upgrade is completed, the security resource release control signal is configured to a clear state, the released non-security storage resource is initialized and the previously stored security data and security program are restored, thereby improving the efficiency of the firmware upgrade and ensuring the safety of the firmware upgrade process.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of chip technology, and in particular to a method and chip for assisting firmware upgrade. Background Art

[0002] For chips with security protection policies, they are usually equipped with security partitions. Storage resources with security partition attributes are not allowed to be accessed by resources without security attributes without decryption. Therefore, the current technical solution has the following problems when upgrading firmware: the device may not have enough storage space to temporarily store the new firmware, resulting in low firmware upgrade efficiency; during the firmware upgrade process, the secure firmware may be tampered with or data may be leaked, posing security issues.

[0003] In order to solve the problem of insufficient device storage space during firmware upgrade, secure resources can be released as non-secure resources to support firmware upgrade; however, usually releasing secure resources as non-secure resources requires decryption, which requires a password. In some cases, some customers do not have the decryption password. For example, some programs and data stored in the firmware security zone, some users only have the right to use, but not the read and write permissions to the contents stored in the firmware security zone. Therefore, during firmware upgrade, because there is no decryption password, they cannot release secure storage resources (RAM) by decryption to support firmware upgrade. Summary of the invention

[0004] In view of this, the purpose of this application is to provide a method and chip for assisting firmware upgrade, which can improve the efficiency of firmware upgrade and ensure the security of the firmware upgrade process.

[0005] An embodiment of the present application provides a method for assisting firmware upgrade, which is applied to a chip, wherein the chip includes a processor, on-chip firmware, and a security resource release control and monitoring device; the on-chip storage resources of the chip include security storage resources and non-security storage resources; the security storage resources store security data and security programs; the method includes:

[0006] The security resource release control and monitoring device provides a security resource release control signal to the security storage resource of the chip, and after configuring the security resource release control signal to be in a valid state or a cleared state, the security storage resource is initialized;

[0007] When the firmware is upgraded, the security resource release control signal is configured to be in a valid state, the security storage resource is initialized to erase the security data and security program, and the security storage resource is released as a non-security storage resource for assisting the firmware upgrade;

[0008] When the firmware upgrade is completed, the security resource release control signal is configured to be in a clear state, the on-chip storage resources that originally belong to the security storage resources are initialized, and after the initialization is completed, the previously stored security data and security programs are restored.

[0009] In some embodiments, in the method for assisting firmware upgrade, the method further includes:

[0010] The security resource release control and monitoring device provides a security resource attribute control signal to the on-chip storage resource;

[0011] The security resource release control and monitoring device combines the security resource release control signal and the security storage resource initialization state to control the security resource attribute control signal to switch between the original security configuration attribute and the non-security state; wherein, when the security resource attribute control signal is in the non-security state, the on-chip storage resource is considered to be a non-security storage resource; when the security resource attribute control signal is the original security configuration attribute, the security attribute of the on-chip storage resource is maintained.

[0012] In some embodiments, in the method for assisting firmware upgrade, when the security resource release control signal is switched to a valid state and a cleared state, the switching timing of the security resource attribute control signal relative to the secure storage resource initialization process is different.

[0013] In some embodiments, in the method for assisting firmware upgrade, the security resource release control and monitoring device combines the security resource release control signal and the security storage resource initialization process to control the security resource attribute control signal to switch between the original security configuration attribute and the non-security state, including:

[0014] When the security resource release control signal is switched to a valid state, the security resource attribute control signal maintains the original security configuration attribute, provides security attribute configuration information to the on-chip storage resource control logic of the security storage resource, so that the security storage resource is initialized; and maintains the security attributes of the security storage resource that has not yet started to be initialized;

[0015] The security resource release control and monitoring device detects that all security storage resources have completed initialization, and controls the security resource attribute control signal to switch to a non-security state.

[0016] In some embodiments, in the method for assisting firmware upgrade, the security resource release control and monitoring device combines the security resource release control signal and the security storage resource initialization process to control the security resource attribute control signal to switch between the original security configuration attribute and the non-security state, including:

[0017] When the security resource release control signal is switched to a clear state, the security resource release control and monitoring device controls the security resource attribute control signal to switch back to the original security configuration attribute to assist the security resource in initializing.

[0018] In some embodiments, the method for assisting firmware upgrade further includes:

[0019] The safety resource release control and monitoring device provides a safety resource release bus control signal for the bus of the chip;

[0020] The security resource release bus control signal is used to perform bus blocking control after configuring the security resource release control signal to a valid state or a cleared state, thereby preventing data transfer on the bus until all security storage resources are initialized, and then releasing the bus blocking control.

[0021] In some embodiments, the method for assisting firmware upgrade further includes:

[0022] After configuring the safety resource release control signal to switch to a valid state or a cleared state, the safety resource release control and monitoring device generates a recording signal internally;

[0023] After the initialization of the secure storage resource is completed, an initialization completion signal is generated to the secure resource release control and monitoring device. The secure resource release control and monitoring device determines that the switching control corresponding to the secure resource release control signal is effective based on the recording signal and the initialization completion signal.

[0024] In some embodiments, in the method for assisting firmware upgrade, when the configuration security resource release control signal is switched to a valid state, the generated recording signal is a high level signal;

[0025] When the configuration security resource release control signal is switched to the clear state, the generated record signal is a low level signal.

[0026] In some embodiments, in the method for assisting firmware upgrade, the initialization completion signal sent by the security resource release control and monitoring device when all security storage resources are initialized is a pulse signal.

[0027] In some embodiments, in the method for assisting firmware upgrade, the method further includes:

[0028] When the safety resource release control and monitoring device detects that the safety resource release control signal is in a valid state, the instruction fetch operation on the program in the on-chip firmware is disabled.

[0029] In some embodiments, a chip is further provided, the chip comprising a processor, on-chip firmware, and a security resource release control and monitoring device; the on-chip storage resources of the chip comprise security storage resources and non-security storage resources; the security storage resources store security data and security programs;

[0030] The security resource release control and monitoring device is used to provide a security resource release control signal to the security storage resource of the chip, and after configuring the security resource release control signal to be in a valid state or a cleared state, the security storage resource is initialized;

[0031] When the firmware is upgraded, the security resource release control signal is configured to be in a valid state, so that the security storage resource is initialized to erase the security data and security program, and the security storage resource is released as a non-security storage resource for assisting the firmware upgrade;

[0032] When the firmware upgrade is completed, the security resource release control signal is configured to be in a clear state, the on-chip storage resources that originally belong to the security storage resources are initialized, and after the initialization is completed, the previously stored security data and security programs are restored.

[0033] In an embodiment of the present application, a method and a chip for assisting firmware upgrade are provided. The method for assisting firmware upgrade is applied to a chip, wherein the chip includes a processor, on-chip firmware, and a secure resource release control and monitoring device; the on-chip storage resources of the chip include secure storage resources and non-secure storage resources; the secure storage resources store secure data and secure programs; the secure resource release control and monitoring device provides a secure resource release control signal to the secure storage resources of the chip, and after configuring the secure resource release control signal to be in a valid state or a cleared state, the secure storage resources are initialized; when the firmware is upgraded, the secure resource release control signal is configured to be in a valid state, The secure storage resources are initialized to erase the secure data and secure programs, and the secure storage resources are released as non-secure storage resources to assist in firmware upgrades. When the firmware upgrade is completed, the secure resource release control signal is configured to be in a clear state, the on-chip storage resources that originally belong to the secure storage resources are initialized, and the previously stored security data and security programs are restored after the initialization is completed. The secure storage resources in the chip are securely opened by the secure resource release control and monitoring device, so that when the firmware is upgraded, the on-chip secure storage resources can be effectively utilized to support the firmware upgrade, and it is ensured that in this usage scenario, the security data in the chip will not be leaked or tampered with, thereby improving the efficiency of the firmware upgrade. BRIEF DESCRIPTION OF THE DRAWINGS

[0034] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required for use in the embodiments will be briefly introduced below. It should be understood that the following drawings only show certain embodiments of the present application and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without paying creative work.

[0035] Figure 1 A schematic diagram of a conventional firmware upgrade solution according to an embodiment of the present application is shown;

[0036] Figure 2 A schematic diagram of a method for assisting firmware upgrade according to an embodiment of the present application is shown;

[0037] Figure 3 A flowchart of the method for assisting firmware upgrade according to an embodiment of the present application is shown;

[0038] Figure 4 A flowchart of another method for assisting firmware upgrade according to an embodiment of the present application is shown;

[0039] Figure 5 A flowchart of the method for assisting firmware upgrade described in an embodiment of the present application is shown. DETAILED DESCRIPTION

[0040] To make the purpose, technical scheme and advantages of the embodiments of the present application clearer, the technical scheme in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. It should be understood that the drawings in the present application only serve the purpose of explanation and description and are not used to limit the scope of protection of the present application. In addition, it should be understood that the schematic drawings are not drawn in real proportion. The flowchart used in this application shows the operations implemented according to some embodiments of the present application. It should be understood that the operations of the flowchart can be implemented out of sequence, and the steps without logical context can be reversed in order or implemented simultaneously. In addition, those skilled in the art can add one or more other operations to the flowchart under the guidance of the content of the present application, or remove one or more operations from the flowchart.

[0041] In addition, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. The components of the embodiments of the present application described and shown in the drawings here can be arranged and designed in various configurations. Therefore, the following detailed description of the embodiments of the present application provided in the drawings is not intended to limit the scope of the application claimed for protection, but merely represents the selected embodiments of the present application. Based on the embodiments of the present application, all other embodiments obtained by those skilled in the art without making creative work belong to the scope of protection of the present application.

[0042] It should be noted that the term "comprising" will be used in the embodiments of the present application to indicate the existence of the features declared thereafter, but does not exclude the addition of other features.

[0043] For chips with security protection policies, they are usually equipped with security partitions. Storage resources with security partition attributes are not allowed to be accessed by resources without security attributes without decryption. Therefore, the current technical solutions have the following problems: the device may not have enough storage space to temporarily store the new firmware; during the firmware upgrade process, the security firmware may be tampered with or data may be leaked, which poses a security problem.

[0044] In order to solve the problem of insufficient device storage space during firmware upgrade, secure resources can be released as non-secure resources to support firmware upgrade; however, usually releasing secure resources as non-secure resources requires decryption, which requires a password. In some cases, some customers do not have the decryption password. For example, some programs and data stored in the firmware security zone, some users only have the right to use, but not the read and write permissions to the contents stored in the firmware security zone. Therefore, during firmware upgrade, because there is no decryption password, they cannot release secure storage resources (RAM) by decryption to support firmware upgrade.

[0045] For details, please refer to Figure 1 , Figure 1 A schematic diagram of a conventional firmware upgrade solution according to an embodiment of the present application is shown; Figure 1 As shown, when the firmware is upgraded, the on-chip storage resources are used to store the firmware upgrade program and data; however, because the secure storage resources store secure data, the data in the secure storage resources cannot be accessed when they are not decrypted or accessed by instructions from the unified security zone. Otherwise, the secure data will be at risk of being tampered with or leaked; in this way, if the user does not have a security password, if the firmware is upgraded, only public non-secure storage resources can be used. If the capacity of this part of the resources is small, it will obviously seriously affect the efficiency of the firmware upgrade.

[0046] Based on this, in an embodiment of the present application, a method and a chip for assisting firmware upgrade are provided, wherein the method for assisting firmware upgrade is applied to a chip, wherein the chip includes a processor, on-chip firmware, and a security resource release control and monitoring device; the on-chip storage resources of the chip include secure storage resources and non-secure storage resources; the secure storage resources store secure data and secure programs; the secure resource release control and monitoring device provides a secure resource release control signal to the secure storage resources of the chip, and after configuring the secure resource release control signal to be in a valid state or a cleared state, the secure storage resources are initialized; when the firmware is upgraded, the secure resource release control signal is configured to be in a valid state. state, the secure storage resources are initialized to erase the secure data and secure programs, and the secure storage resources are released as non-secure storage resources to assist in firmware upgrades; when the firmware upgrade is completed, the secure resource release control signal is configured to be in the clear state, the on-chip storage resources that originally belong to the secure storage resources are initialized, and the previously stored security data and security programs are restored after the initialization is completed. The secure storage resources in the chip are securely opened by the secure resource release control and monitoring device, so that when the firmware is upgraded, the on-chip secure storage resources can be effectively used to support the firmware upgrade, and it is ensured that in this usage scenario, the on-chip security data will not be leaked or tampered with, thereby improving the efficiency of the firmware upgrade.

[0047] Please refer to Figure 2 , Figure 2 The schematic diagram of the method for assisting firmware upgrade described in the embodiment of the present application is shown; please refer to Figure 3 , Figure 3 A flowchart of the method for assisting firmware upgrade described in an embodiment of the present application is shown.

[0048] like Figure 2 and Figure 3 As shown, the embodiment of the present application provides a method for assisting firmware upgrade, which is applied to a chip, please refer to Figure 2 The chip includes a processor, an on-chip firmware 201 and a security resource release control and monitoring device 202; the on-chip storage resources 203 of the chip include security storage resources and non-security storage resources; the security storage resources store security data and security programs; Figure 3 As shown, the method includes the following steps S301-S303:

[0049] S301, the security resource release control and monitoring device provides a security resource release control signal to the security storage resource of the chip, and after configuring the security resource release control signal to be in a valid state or a cleared state, the security storage resource is initialized;

[0050] S302: when the firmware is upgraded, the security resource release control signal is configured to be in a valid state, the security storage resource is initialized to erase the security data and security program, and the security storage resource is released as a non-security storage resource for assisting the firmware upgrade;

[0051] S303: After the firmware upgrade is completed, the security resource release control signal is configured to be in a clear state, the on-chip storage resources that originally belong to the security storage resources are initialized, and after the initialization is completed, the previously stored security data and security programs are restored.

[0052] The on-chip storage resources of the chip include secure storage resources and non-secure storage resources, and the security attributes of the on-chip storage resources are configurable.

[0053] In other words, the secure storage resources and non-secure storage resources in the on-chip storage resources are configurable and can be modified.

[0054] Through the security resource opening control and monitoring device, users can temporarily unlock all on-chip security resources to support firmware upgrades without unlocking the security zone, and after the firmware upgrade is completed, restore the previous security configuration properties without resetting.

[0055] The released non-secure storage resources are initialized, and after the initialization is completed, the previously stored secure data and secure programs are restored. The restoration of data or programs needs to be completed by the user. In step S301, the secure resource release control and monitoring device provides a secure resource release control signal to the secure storage resources of the chip. After configuring the secure resource release control signal to be in a valid state or a cleared state, the secure storage resources are initialized.

[0056] The security resource release control signal is configured to be in a valid state or a cleared state. Specifically, the configuration may be performed through a processor, other on-chip master devices, or a debugging device.

[0057] In order to safely use the on-chip secure storage resources for firmware upgrades, once the secure resource release control signal provided by the secure resource opening control and monitoring device is configured to be in a valid state or cleared state, the on-chip secure storage resources will be initialized according to the secure resource release control signal to erase the previously stored secure data and programs, thereby preventing the data and programs of the secure storage resources from being leaked or tampered with. For each on-chip memory, whether it belongs to a secure storage resource is controlled by the secure resource opening control and monitoring device. During the initialization period, the secure resource being initialized cannot be accessed, thereby ensuring that the secure data is not leaked.

[0058] Because the reset domain of the on-chip storage resource is different from the reset domain of the security resource release control and monitoring device, in order to avoid state and control logic disorder caused by different resets, the security resource release control signal is a pulse signal.

[0059] In some embodiments, please refer to Figure 4 , Figure 4 A flowchart of another method for assisting firmware upgrade according to an embodiment of the present application is shown; Figure 4 As shown, the method for assisting firmware upgrade also includes the following steps S401-S402:

[0060] S401, the security resource release control and monitoring device provides a security resource attribute control signal to the on-chip storage resource;

[0061] S402. The security resource release control and monitoring device combines the security resource release control signal and the security storage resource initialization state to control the security resource attribute control signal to switch between the original security configuration attribute and the non-security state; wherein, when the security resource attribute control signal is in the non-security state, the on-chip storage resource is considered to be a non-security storage resource; when the security resource attribute control signal is the original security configuration attribute, the security attribute of the on-chip storage resource is maintained.

[0062] The security attributes of the on-chip storage resources themselves are configurable and can be either secure or non-secure. The security resource release control signal provides a means to temporarily change the storage resources configured as secure to non-secure. Based on this, the security resource attribute control signal needs to cooperate with the security resource release control signal to switch between the original security configuration attributes and the non-secure state.

[0063] When the security resource attribute control signal is in a non-secure state, the storage resource is considered to be a non-secure storage resource, and the stored data or program will not be protected; when the security resource attribute control signal is the original security configuration attribute, access to the data or program stored in the secure storage resource of the storage resource will be protected by on-chip security logic.

[0064] When the security resource attribute control signal is the original security configuration attribute, the security attribute of the on-chip storage resource is maintained, that is, the secure storage resource in the on-chip storage resource is initialized as the secure storage resource is affected by the security resource release control signal; the non-secure storage resource is not affected by the security resource release control signal and does not need to be initialized.

[0065] When the security resource release control signal is switched to a valid state and a clear state, the switching timing of the security resource attribute control signal relative to the security storage resource initialization process is different.

[0066] Specifically, when the security resource release control signal is switched to a valid state, the security resource attribute control signal is switched after the security storage resource is initialized, and is switched from the original security configuration attribute to a non-secure state.

[0067] When the security resource release control signal is switched to the clear state, the security resource attribute control signal is switched immediately, that is, before the security storage resource is initialized, and is switched from the non-secure state to the secure state.

[0068] In some embodiments, in the method for assisting firmware upgrade, the security resource release control and monitoring device combines the security resource release control signal and the security storage resource initialization process to control the security resource attribute control signal to switch between the original security configuration attribute and the non-security state, including:

[0069] When the security resource release control signal is switched to a valid state, the security resource attribute control signal maintains the original security configuration attribute, provides security attribute configuration information to the on-chip storage resource control logic of the security storage resource, so that the security storage resource is initialized; and maintains the security attributes of the security storage resource that has not yet started to be initialized;

[0070] The security resource release control and monitoring device detects that all security storage resources have completed initialization, and controls the security resource attribute control signal to switch to a non-security state.

[0071] In some embodiments, in the method for assisting firmware upgrade, the security resource release control and monitoring device combines the security resource release control signal and the security storage resource initialization process to control the security resource attribute control signal to switch between the original security configuration attribute and the non-security state, including:

[0072] When the security resource release control signal is switched to a clear state, the security resource release control and monitoring device controls the security resource attribute control signal to switch back to the original security configuration attribute to assist the security resource in initializing.

[0073] That is to say, for the chip described in the embodiment of the present application, the security attributes of each on-chip storage area are provided by the security resource opening control and monitoring device, which determines whether each on-chip storage unit belongs to a security resource and the specific security partition affiliation.

[0074] When the security resource opening function is required for firmware upgrade, each on-chip storage resource control logic decides whether to perform initialization operation when the security resource release control signal is in a valid or cleared state according to the security resource attribute control signal; specifically, when the security resource release control signal is switched to a valid state, the security resource attribute control signal will not be switched immediately. On the one hand, this is to provide security attribute information to the on-chip storage resource control logic to assist it in initialization operation; on the other hand, for the security storage resources that have not yet been initialized, their security attributes are maintained to prevent the leakage of the data or programs stored therein.

[0075] After all on-chip secure storage resources are initialized, the secure resource attribute control signal will switch to a non-secure state, and the original secure storage resources on the chip can be used by any device, and their stored data are all in the initialized state.

[0076] When the security resource release control signal is switched to the clear state, the security resource attribute control signal will immediately switch back to the original security attribute to help the storage device belonging to the security partition to initialize and prevent its data from being tampered with.

[0077] Please refer to Figure 5 , Figure 5 A flowchart of the method for assisting firmware upgrade according to an embodiment of the present application is shown; Figure 5 As shown, the method for assisting firmware upgrade also includes the following steps S501-S502:

[0078] S501, the security resource release control and monitoring device provides a security resource release bus control signal for the bus of the chip;

[0079] S502, the security resource releases the bus control signal, which is used to perform bus blocking control after configuring the security resource release control signal to a valid state or a cleared state, to prevent data transfer on the bus until all the security storage resources are initialized, and then release the bus blocking control.

[0080] After the configuration security resource release control signal is valid or cleared and before all on-chip security storage resources are initialized, if bus access is not restricted, there will be a vulnerability in which the security storage resource data is leaked or tampered with.

[0081] After the security resource release control signal configuration is effective, for the on-chip security resources that have completed initialization, since other security resources on the chip have not yet completed initialization, the security attribute control signal of the on-chip storage resource has not yet switched to a non-secure state. If the encrypted data on the chip is moved to this storage resource at this time, the system will believe that this data transfer is still secure and the data transfer can be successful. But in fact, this storage resource has completed initialization, and as long as the initialization of other security storage resources on the chip is completed, its security attribute control signal will switch to a non-secure state, and the security access restrictions on this storage resource will be cancelled. This means that the security data moved during this period will be leaked.

[0082] After the security resource release control signal configuration is cleared, although the security attribute control signal of the on-chip storage resource will be immediately switched to a secure state and initialized in sequence, there is still a risk that after the initialization is completed, the last non-secure data before the security attribute control signal is switched is moved to the on-chip security resource, which will create a risk of security data being tampered with.

[0083] To address this type of security risk, in an embodiment of the present application, the security resource release control and monitoring device will provide a security resource release bus control signal for the bus. After the security resource release control signal is configured to be valid or cleared, this control signal will block all data transfer behaviors on the bus until all on-chip security storage resources are initialized, and then release the bus blocking control.

[0084] In some embodiments, in the method for assisting firmware upgrade, the method further includes:

[0085] After configuring the safety resource release control signal to switch to a valid state or a cleared state, the safety resource release control and monitoring device generates a recording signal internally;

[0086] After the initialization of the secure storage resource is completed, an initialization completion signal is generated to the secure resource release control and monitoring device. The secure resource release control and monitoring device determines that the switching control corresponding to the secure resource release control signal is effective based on the recording signal and the initialization completion signal.

[0087] The switching control takes effect when the secure storage resources are initialized and released as non-secure storage resources for firmware upgrade; or when the upgrade is completed and the released non-secure storage resources are initialized.

[0088] Specifically, after the initialization is completed, an initialization completion signal will be sent to the security resource release control and monitoring device; the security resource release control and monitoring device records the signal and the initialization completion signal, and a status register inside the control device switches the state to indicate the state of the security resource release. Based on this state, the user can know whether the switching control corresponding to the security resource release control signal is effective, whether the firmware upgrade can be started or the security data can be reconfigured.

[0089] In some embodiments, when the security resource release control signal is switched to a valid state or a cleared state, the corresponding record signal state is different.

[0090] Specifically, when the configuration security resource release control signal is switched to a valid state, the generated recording signal is a high level signal;

[0091] When the configuration security resource release control signal is switched to the clear state, the generated record signal is a low level signal.

[0092] Specifically, the initialization completion signal sent by the security resource release control and monitoring device when all security storage resources are initialized is a pulse signal.

[0093] The security resource release control and monitoring device monitors the chip security resource release vacancy state according to the security resource release configuration state and the initialization state of the on-chip security storage resources; when the security resource release control signal is valid or cleared, there will be a level signal inside to record the configuration state of the configured security resource release function. After the configuration of this function is valid, the configuration state signal is high level, and after the configuration of this function is cleared, the configuration state signal is low level. When the state signal is high level, if a pulse signal indicating that all security storage resources have been initialized is received, it means that the security resource release function is already valid, the security resource release function monitoring signal becomes valid, and all security resources in the chip can be used to assist in firmware upgrades. Conversely, when the state signal is low level, if a pulse signal indicating that all security storage resources have been initialized is received, it means that the security resource release function has been closed, the security resource release function monitoring signal becomes invalid, indicating that the firmware upgrade has been completed, and the system can reconfigure the data in the security storage resources for system applications.

[0094] In some embodiments, in the method for assisting firmware upgrade, the method further includes:

[0095] When the safety resource release control and monitoring device detects that the safety resource release control signal is in a valid state, the instruction fetch operation on the program in the on-chip firmware is disabled.

[0096] When the security resource release function monitoring signal is in the valid state, because the on-chip storage resources are switched to a non-secure state at this time, if the program in the firmware can still run at this time, if there is data transfer between the secure zone firmware and the secure zone on-chip storage unit in the program, it will lead to vulnerabilities of on-chip security data leakage and tampering. Therefore, once the security resource release control and monitoring device detects that the security resource release function is in the valid state, the instruction fetch operation of the program in the firmware will be disabled to prevent the above security vulnerabilities.

[0097] The method for assisting firmware upgrade described in the embodiment of the present application is based on the release of control and monitoring devices based on secure resources, and safely utilizes secure on-chip storage resources to assist chip firmware upgrades, thereby increasing the flexibility of using on-chip storage resources, and is of great help to chip application products with limited on-chip non-secure storage resource capacity and the need for firmware upgrades.

[0098] Furthermore, while flexibly applying the security chip storage resources, by controlling the bus, the chip's encrypted data and algorithm programs can be prevented from being maliciously leaked or tampered with during the release of security resources.

[0099] Furthermore, while assisting in firmware upgrades, the security resource release control and monitoring device can also ensure the security of the chip's overall data and code, preventing the chip's encrypted data and algorithm programs from being maliciously leaked or tampered with during the firmware upgrade process.

[0100] Based on the same inventive concept, a chip corresponding to the method for assisting firmware upgrade is also provided in the embodiment of the present application. Since the principle of solving the problem by the chip in the embodiment of the present application is similar to the method for assisting firmware upgrade in the embodiment of the present application, the implementation of the chip can refer to the implementation of the method, and the repeated parts will not be repeated.

[0101] In some embodiments, a chip is further provided, the chip comprising a processor, on-chip firmware, and a security resource release control and monitoring device; the on-chip storage resources of the chip comprise security storage resources and non-security storage resources; the security storage resources store security data and security programs;

[0102] The security resource release control and monitoring device is used to provide a security resource release control signal to the security storage resource of the chip, and after configuring the security resource release control signal to be in a valid state or a cleared state, the security storage resource is initialized;

[0103] When the firmware is upgraded, the security resource release control signal is configured to be in a valid state, so that the security storage resource is initialized to erase the security data and security program, and the security storage resource is released as a non-security storage resource for assisting the firmware upgrade;

[0104] When the firmware upgrade is completed, the security resource release control signal is configured to be in a clear state, the on-chip storage resources that originally belong to the security storage resources are initialized, and after the initialization is completed, the previously stored security data and security programs are restored.

[0105] In some embodiments, in the chip, the security resource release control and monitoring device is further used to provide a security resource attribute control signal to the on-chip storage resource;

[0106] The security resource release control and monitoring device is also used to combine the security resource release control signal and the security storage resource initialization state to control the security resource attribute control signal to switch between the original security configuration attribute and the non-security state; wherein, when the security resource attribute control signal is in the non-security state, the on-chip storage resource is considered to be a non-security storage resource; when the security resource attribute control signal is the original security configuration attribute, the security attribute of the on-chip storage resource is maintained.

[0107] In some embodiments, in the chip, when the security resource release control signal switches to a valid state and a clear state, the switching timing of the security resource attribute control signal relative to the security storage resource initialization process is different.

[0108] In some embodiments, in the chip, the security resource release control and monitoring device, when used to control the security resource attribute control signal to switch between the original security configuration attribute and the non-security state in combination with the security resource release control signal and the security storage resource initialization process, is specifically used to:

[0109] When the security resource release control signal is switched to a valid state, the security resource attribute control signal maintains the original security configuration attribute, provides security attribute configuration information to the on-chip storage resource control logic of the security storage resource, so that the security storage resource is initialized; and maintains the security attributes of the security storage resource that has not yet started to be initialized;

[0110] The security resource release control and monitoring device detects that all security storage resources have completed initialization, and controls the security resource attribute control signal to switch to a non-security state.

[0111] In some embodiments, in the chip, the security resource release control and monitoring device, when used to control the security resource attribute control signal to switch between the original security configuration attribute and the non-security state in combination with the security resource release control signal and the security storage resource initialization process, is specifically used to:

[0112] When the security resource release control signal is switched to a clear state, the security resource release control and monitoring device controls the security resource attribute control signal to switch back to the original security configuration attribute to assist the security resource in initializing.

[0113] In some embodiments, in the chip, the secure resource release control and monitoring device is further used to provide a secure resource release bus control signal for the bus of the chip;

[0114] The security resource release bus control signal is used to perform bus blocking control after configuring the security resource release control signal to a valid state or a cleared state, thereby preventing data transfer on the bus until all security storage resources are initialized, and then releasing the bus blocking control.

[0115] In some embodiments, in the chip, the processor is further configured to generate a recording signal inside the security resource release control and monitoring device after the security resource release control signal is switched to a valid state or a cleared state;

[0116] After the initialization of the secure storage resource is completed, an initialization completion signal is generated to the secure resource release control and monitoring device. The secure resource release control and monitoring device determines that the switching control corresponding to the secure resource release control signal is effective based on the recording signal and the initialization completion signal.

[0117] In some embodiments, in the chip, when the security resource release control signal is switched to a valid state or a cleared state, the state of the corresponding recording signal is different.

[0118] In some embodiments, in the chip, when the configuration security resource release control signal is switched to a valid state, the generated recording signal is a high level signal;

[0119] When the configuration security resource release control signal is switched to the clear state, the generated record signal is a low level signal.

[0120] In some embodiments, in the chip, the initialization completion signal sent by the security resource release control and monitoring device when all security storage resources are initialized is a pulse signal.

[0121] In some embodiments, in the chip, the security resource release control and monitoring device is further used to disable instruction fetch operations on programs in the on-chip firmware when it is detected that the security resource release control signal is in a valid state.

[0122] Those skilled in the art can clearly understand that, for the convenience and simplicity of description, the specific working process of the system and device described above can refer to the corresponding process in the method embodiment, and will not be repeated in this application. In the several embodiments provided in this application, it should be understood that the disclosed system, device and method can be implemented in other ways. The device embodiments described above are merely schematic. For example, the division of the modules is only a logical function division. There may be other division methods in actual implementation. For example, multiple modules or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some communication interfaces, indirect coupling or communication connection of devices or modules, which can be electrical, mechanical or other forms.

[0123] The modules described as separate components may or may not be physically separated, and the components shown as modules may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0124] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0125] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a non-volatile computer-readable storage medium that is executable by a processor. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium, including several instructions for a computer device (which can be a personal computer, a platform server, or a network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as USB flash drives, mobile hard drives, ROM, RAM, magnetic disks, or optical disks.

[0126] The above are only specific implementations of the present application, but the protection scope of the present application is not limited thereto. Any technician familiar with the technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.

Claims

1. A method for assisting firmware upgrade, characterized in that: Applied to a chip, the chip includes a processor, on-chip firmware and a security resource release control and monitoring device; the on-chip storage resources of the chip include secure storage resources and non-secure storage resources; The secure storage resource stores secure data and secure programs; the method comprises: The security resource release control and monitoring device provides a security resource release control signal to the security storage resource of the chip, and after configuring the security resource release control signal to be in a valid state or a cleared state, the security storage resource is initialized; When the firmware is upgraded, the security resource release control signal is configured to be in a valid state, the security storage resource is initialized to erase the security data and security program, and the security storage resource is released as a non-security storage resource for assisting the firmware upgrade; when the security resource release control and monitoring device detects that the security resource release control signal is in a valid state, the instruction fetch operation of the program in the on-chip firmware is disabled; When the firmware upgrade is completed, the security resource release control signal is configured to be in a clear state, the on-chip storage resources that belong to the security storage resources are initialized, and after the initialization is completed, the previously stored security data and security programs are restored; the method also includes: The security resource release control and monitoring device provides a security resource attribute control signal to the on-chip storage resource; The security resource release control and monitoring device combines the security resource release control signal and the security storage resource initialization state to control the security resource attribute control signal to switch between the original security configuration attribute and the non-security state; wherein, when the security resource attribute control signal is in the non-security state, the on-chip storage resource is considered to be a non-security storage resource; when the security resource attribute control signal is the original security configuration attribute, the security attribute of the on-chip storage resource is maintained; when the security resource release control signal is switched to the valid state and the cleared state, the switching timing of the security resource attribute control signal relative to the security storage resource initialization process is different.

2. The method for assisting firmware upgrade according to claim 1, characterized in that: The security resource release control and monitoring device combines the security resource release control signal and the security storage resource initialization process to control the security resource attribute control signal to switch between the original security configuration attribute and the non-security state, including: When the security resource release control signal is switched to a valid state, the security resource attribute control signal maintains the original security configuration attribute, provides security attribute configuration information to the on-chip storage resource control logic of the security storage resource, so that the security storage resource is initialized; and maintains the security attributes of the security storage resource that has not yet started to be initialized; The security resource release control and monitoring device detects that all security storage resources have completed initialization, and controls the security resource attribute control signal to switch to a non-security state.

3. The method for assisting firmware upgrade according to claim 2, characterized in that: The security resource release control and monitoring device combines the security resource release control signal and the security storage resource initialization process to control the security resource attribute control signal to switch between the original security configuration attribute and the non-security state, including: When the security resource release control signal is switched to a clear state, the security resource release control and monitoring device controls the security resource attribute control signal to switch back to the original security configuration attribute to assist the security resource in initializing.

4. The method for assisting firmware upgrade according to claim 1, characterized in that: The method further comprises: The safety resource release control and monitoring device provides a safety resource release bus control signal for the bus of the chip; The security resource release bus control signal is used to perform bus blocking control after configuring the security resource release control signal to a valid state or a cleared state, thereby preventing data transfer on the bus until all security storage resources are initialized, and then releasing the bus blocking control.

5. The method for assisting firmware upgrade according to claim 1, characterized in that: The method further comprises: After configuring the safety resource release control signal to switch to a valid state or a cleared state, the safety resource release control and monitoring device generates a recording signal internally; After the initialization of the secure storage resource is completed, an initialization completion signal is generated to the secure resource release control and monitoring device. The secure resource release control and monitoring device determines that the switching control corresponding to the secure resource release control signal is effective based on the recording signal and the initialization completion signal.

6. The method according to claim 5, characterized in that When the configuration safety resource release control signal is switched to a valid state, the generated recording signal is a high level signal; When the configuration security resource release control signal is switched to the clear state, the generated record signal is a low level signal.

7. The method for assisting firmware upgrade according to claim 6, characterized in that: The initialization completion signal sent by the security resource release control and monitoring device when all security storage resources are initialized is a pulse signal.

8. A chip, characterized in that: The chip includes a processor, on-chip firmware and a security resource release control and monitoring device; the on-chip storage resources of the chip include secure storage resources and non-secure storage resources; the secure storage resources store secure data and secure programs; The security resource release control and monitoring device is used to provide a security resource release control signal to the security storage resource of the chip, and after configuring the security resource release control signal to be in a valid state or a cleared state, the security storage resource is initialized; When the firmware is upgraded, the security resource release control signal is configured to be in a valid state, so that the security storage resource is initialized to erase the security data and security program, and the security storage resource is released as a non-security storage resource for assisting the firmware upgrade; When the security resource release control and monitoring device detects that the security resource release control signal is in a valid state, disabling the instruction fetch operation of the program in the on-chip firmware; When the firmware upgrade is completed, the security resource release control signal is configured to be in a clear state, the on-chip storage resources that originally belong to the security storage resources are initialized, and after the initialization is completed, the previously stored security data and security programs are restored; The security resource release control and monitoring device is also used to provide a security resource attribute control signal to the on-chip storage resource; The security resource release control and monitoring device is further used to control the security resource attribute control signal to switch between the original security configuration attribute and the non-security state in combination with the security resource release control signal and the security storage resource initialization state; wherein, when the security resource attribute control signal is in the non-security state, the on-chip storage resource is considered to be a non-security storage resource; when the security resource attribute control signal is in the original security configuration attribute, the security attribute of the on-chip storage resource is maintained; When the security resource release control signal is switched to a valid state and a clear state, the switching timing of the security resource attribute control signal relative to the security storage resource initialization process is different.

Citation Information

Patent Citations

  • Dynamic resource sharing

    CN104021037A

  • Processor switching between secure and non-secure modes

    WO2004046924A1