QSPI controller interface combined with AES encryption

By introducing AES encryption technology into QSPI communication, the design of a QSPI controller interface combined with AES encryption solves the shortcomings in data security of QSPI communication and realizes efficient and secure data transmission and storage.

CN119938569APending Publication Date: 2025-05-06HANGZHOU DIANZI UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411760085.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-03
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

Existing QSPI communications have insufficient data security and fail to provide encryption or authentication mechanisms, resulting in the risk of data being vulnerable to eavesdropping and tampering during transmission.

Method used

Combined with AES encryption technology, a QSPI controller interface is designed, which includes a QSPI controller module and an AES module. The data is encrypted and decrypted through the AES module to ensure the security and integrity of the data during transmission and storage.

Benefits of technology

It achieves the ability to ensure data transmission efficiency while providing strong security guarantees, prevent unauthorized access and data leakage, and meets the dual needs of modern applications for speed and security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119938569A_ABST
    Figure CN119938569A_ABST
Patent Text Reader

Abstract

The invention provides a QSPI controller interface combined with AES encryption. The QSPI controller interface comprises a QSPI controller module and an AES module. The QSPI controller module reads back corresponding data from an external Flash based on bus requirements, and AES encryption, decryption or conventional processing is carried out; the AES module comprises an AES encryption module and an AES decryption module, and the AES module performs multiple rounds of encryption and decryption operations based on data read back by the QSPI controller module; wherein in the encryption and decryption process, the AES module generates an extended key based on a 16-byte initial key, and the plaintext or ciphertext is encrypted and decrypted based on the extended key; the QSPI controller module and the AES module are matched to perform multiple rounds of encryption and decryption, so that the security of data is enhanced, and a guarantee is provided for the security and integrity of the data in the transmission and storage process.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of integrated circuit digital ICs, and in particular to a QSPI controller interface combined with AES encryption. Background Art

[0002] In modern embedded systems, fast storage and data processing capabilities are key requirements in the design. QSPI is widely used in various devices such as microcontrollers, FPGAs (field programmable gate arrays), and storage devices due to its high data transfer rate and high concurrent access capabilities. The main advantages of QSPI include high-speed transmission, flexible architecture, and efficient memory access. By using multiple data lines to transmit data in parallel, the data transfer rate is significantly improved, and data can be read and written faster than the traditional SPI interface. At the same time, QSPI supports multiple data transfer modes, can be flexibly used in different application scenarios, and can directly access external memory, reducing the burden on the processor and improving the overall system performance.

[0003] QSPI has obvious advantages in speed and efficiency, but its shortcomings in data security are also increasingly concerned. QSPI communication itself does not provide encryption or authentication mechanisms, which makes data vulnerable to eavesdropping and tampering during transmission. Therefore, encrypting data in combination with the Advanced Encryption Standard (AES) can effectively improve the security of the system. AES is a symmetric encryption algorithm that is widely used in the field of data protection. Combining AES with QSPI can provide strong security protection while ensuring data transmission efficiency. Only legitimate users holding decryption keys can access data, thereby effectively preventing unauthorized access and data leakage. This combination provides an efficient and secure storage solution for embedded systems, meeting the dual needs of speed and security for modern applications.

[0004] The QSPI interface provides efficient serial data transmission capabilities, but balancing speed and security in data encryption scenarios remains a challenge. Summary of the invention

[0005] In order to overcome the shortcomings of the prior art, the present invention provides a QSPI controller interface combined with AES encryption, aiming to solve the data security problem in the prior art. The interface is mainly used in embedded systems and storage devices, and can read data from external Flash, and select AES encryption or decryption according to needs. The QSPI controller module includes a clock control module, a control module, and a data transceiver module to ensure the efficiency and accuracy of data transmission. In application, when the system enables AES, QSPI will process data according to the configuration mode: in encryption mode, plaintext data will be encrypted and transmitted; in decryption mode, ciphertext data will be decrypted and restored to plaintext. The AES encryption module and the AES decryption module enhance the security of data through multiple rounds of processing, which can ensure the security and integrity of data during transmission and storage.

[0006] In order to achieve the above object, the present invention provides a QSPI controller interface combined with AES encryption, including: a QSPI controller module and an AES module;

[0007] The QSPI controller module reads the corresponding data from the external Flash based on the bus requirements and performs AES encryption and decryption processing;

[0008] AES module, including AES encryption module and AES decryption module. The AES module performs multiple rounds of encryption and decryption operations based on the data read back by the QSPI controller module;

[0009] During the encryption and decryption process, the AES module expands the initial key, generates multiple round keys, and performs encryption and decryption operations based on the multiple round keys and the data read back by the QSPI controller module.

[0010] Preferably, the QSPI controller module includes a clock control module, a control module and a data transceiver module; the clock control module is used to generate an SCLK clock signal and a chip select signal CS, and output them to an external Flash for data transmission control; the control module uses a state machine to control state jumps; and the data transceiver module is used to send and receive data.

[0011] Preferably, the specific steps of AES module key expansion are:

[0012] Input the initial key into a 4*4 state matrix, where each element of the initial key represents a byte; in the state matrix, the 4 bytes in each column form a word, which are named W[0], W[1], W[2], and W[3] respectively;

[0013] Expand the W[i] array to obtain all elements;

[0014] When expanding elements, the i-th column element is determined recursively, and the steps are as follows:

[0015] If i is not a multiple of 4, the i-th column element is determined by the following equation:

[0016] If i is a multiple of 4, then the i-th column is determined by the following equation:

[0017] Wherein, W represents WORD; T represents T operation, and its steps include: word loop, byte substitution and round constant XOR.

[0018] Preferably, before the AES module performs multiple rounds of encryption and decryption operations, it performs a round key addition operation based on the expanded multiple round keys: the current state is XORed with the round key of the current round, and the XOR operation result is used as the round key of the first round of decryption or encryption operation; the multiple rounds of encryption and decryption operations include main round steps and last round steps.

[0019] Preferably, when data encryption is performed, the steps of the main round of encryption include:

[0020] Get the round key of the current round and perform byte replacement: Perform nonlinear replacement on each byte in the state matrix through the lookup table;

[0021] Row shift: Each row is cyclically shifted to the left according to specific rules;

[0022] Column confusion: linear transformation of each column;

[0023] Round key addition: XOR the current state with the round key of the current round;

[0024] The round key after the XOR operation is used as the round key for the next round of encryption operation.

[0025] Preferably, when performing data decryption, the steps of the main round of decryption include:

[0026] Get the round key of the current round and perform reverse shift: perform reverse cyclic shift on each row of the state matrix to restore the order of data;

[0027] Inverse byte replacement: Use the inverse lookup table to replace each byte in the state matrix;

[0028] Round key addition: XOR the current state with the current round key;

[0029] Inverse column confusion: perform an inverse linear transformation on each column and reintegrate the bytes in the column;

[0030] The round key after the inverse column confusion operation is used as the round key for the next round of decryption operation.

[0031] Preferably, in the last round of steps, the last round of encryption steps include: byte replacement, row shift, and round key addition; the last round of decryption steps include: reverse row shift, reverse byte replacement, and round key addition.

[0032] Preferably, the QSPI controller module configures whether the AES module is enabled through a register. If the AES module is not enabled, the data read back from the external Flash by the QSPI controller module is directly transmitted to the bus; if the AES module is enabled, the mode of the AES module is configured according to the register.

[0033] Preferably, if the mode of the AES module is encryption mode, the QSPI controller module sends the plaintext read back from the external Flash to the AES module, waits for the AES module to complete the encryption operation, and generates the corresponding ciphertext; the AES module sends the ciphertext to the QSPI controller module, and the QSPI controller module sends the ciphertext to the bus;

[0034] If the AES module is in decryption mode, the QSPI controller module will send the ciphertext read back from the external Flash to the AES module, and wait for the AES module to complete the decryption operation to generate the corresponding plaintext; the AES module will send the plaintext to the QSPI controller module, and the QSPI controller module will send the plaintext to the bus.

[0035] Preferably, the working modes of the QSPI controller module include: indirect mode, status polling mode and memory mapping mode; when the QSPI controller module works in conjunction with the AES module, the working mode of the QSPI controller module is the memory mapping mode.

[0036] The invention provides a QSPI controller interface combined with AES encryption, which has the following beneficial effects:

[0037] 1. The QSPI controller interface is mainly used in embedded systems and storage devices. The QSPI controller module reads the data required by the bus from the external Flash, and cooperates with the AES module to encrypt and decrypt the transmitted data according to the needs.

[0038] 2. During the encryption and decryption process, multiple rounds of encryption and decryption are repeated. During multiple rounds of encryption and decryption, the round key generated by the current encryption or decryption is used as the round key for the next round of encryption or decryption, and finally a highly secure plaintext or ciphertext is generated, which provides protection for the security and integrity of data during transmission and storage.

[0039] 3. During the encryption and decryption process, multiple round keys are generated by extending the key, so that the keys used in each round of encryption and decryption operations are different, which increases the difficulty for attackers to crack and enhances the security of the encryption and decryption process.

[0040] 4. The QSPI controller module includes a clock control module, a control module, and a data transceiver module, which ensures the efficiency and accuracy of data transmission. BRIEF DESCRIPTION OF THE DRAWINGS

[0041] Figure 1 A schematic diagram of the structure of a QSPI controller interface combined with AES encryption provided by the present invention;

[0042] Figure 2 A schematic diagram of key expansion by the AES module provided by the present invention;

[0043] Figure 3 This is a schematic diagram of the AES module encryption and decryption process provided by the present invention. DETAILED DESCRIPTION

[0044] The following describes the embodiments of the present invention by specific examples, and those skilled in the art can easily understand other advantages and effects of the present invention from the contents disclosed in this specification. The present invention can also be implemented or applied through other different specific embodiments, and the details in this specification can also be modified or changed in various ways based on different viewpoints and applications without departing from the spirit of the present invention. It should be noted that the following embodiments and features in the embodiments can be combined with each other without conflict.

[0045] like Figure 1 As shown, the present invention provides a QSPI controller interface combined with AES encryption, which includes: a QSPI controller module and an AES module. The QSPI controller module reads back corresponding data from an external Flash based on bus requirements and performs AES encryption and decryption processing. The AES module includes an AES encryption module and an AES decryption module, and the AES module performs multiple rounds of encryption and decryption operations based on the data read back by the QSPI controller module; wherein, during the encryption and decryption process, the AES module performs key expansion on the initial key, generates multiple round keys, and performs encryption and decryption operations based on the multiple round keys and the data read back by the QSPI controller module.

[0046] Specifically, in the present invention, the QSPI controller module reads back the data required by the bus from the external Flash, and implements encryption and decryption of the transmitted data by cooperating with the AES module. Encryption and decryption are performed in a repeated multiple rounds. During the multiple rounds of encryption and decryption, the round key generated by the current encryption or decryption is used as the round key for the next round of encryption or decryption, and finally a plaintext or ciphertext with higher security is generated, which provides a guarantee for the security and integrity of the data during transmission and storage. Among them, the QSPI controller module reads back the data required by the bus from the external Flash, and is also used for conventional processing, that is, without AES processing. Among them, the data read back from the external Flash by the QSPI controller module is ciphertext or plaintext. When the acquired data is ciphertext, the decryption step is executed, and when the acquired data is plaintext, the encryption step is executed. The initial key is provided by the user; the QSPI controller module is responsible for reading back the data (plaintext or ciphertext) from the external Flash, and the user provides the initial key. The AES module can encrypt the plaintext with the key into ciphertext or decrypt the ciphertext with the key into plaintext.

[0047] In this embodiment, the QSPI controller module includes a clock control module, a control module and a data transceiver module; the clock control module is used to generate an SCLK clock signal and a chip select signal CS, and output them to the external Flash for data transmission control; the control module uses a state machine to control state jumps to ensure the correct operation of the entire QSPI controller module; the data transceiver module is used to send and receive data. Among them, the QSPI controller module communicates data with the CPU / DMA through the AHB bus.

[0048] like Figure 2 As shown, in the present invention, the specific steps of AES module expansion key are:

[0049] The AES module inputs the initial key into a 4*4 state matrix, where each element represents a byte. In this matrix, the 4 bytes in each column form a word, which are named W[0], W[1], W[2], and W[3]. On this basis, the W[i] array will be expanded with additional elements. For example, when i=43, another 40 elements will be expanded. When expanding the elements, the i-th column element is determined recursively. The steps are as follows:

[0050] If i is not a multiple of 4, the i-th column is determined by the following equation:

[0051] If i is a multiple of 4, the i-th column is determined by the following equation:

[0052] Among them, W represents WORD word; T represents T operation, which consists of three parts: word loop, byte substitution and round constant XOR. The functions of these three parts are as follows:

[0053] Word rotation: Circularly shift the 4 bytes in a word by 1 byte. That is, the input word [b0, b1, b2, b3] is transformed into [b1, b2, b3, b0].

[0054] Byte substitution: Use S-box to perform byte substitution on the result of word loop.

[0055] Round constant XOR: XOR the results of the first two steps with the round constant Rcon[j], where j represents the round number. Rcon[j] is a one-dimensional array with the following values: RC = {0x00, 0x01, 0x02, 0x04, 0x08, 0x10, 0x20, 0x40, 0x80, 0x1B, 0x36}.

[0056] Figure 2 In the example, the round key format is W[0:3]...W[40:43], where W represents a WORD word. A word contains 4 bytes. W[0:3] represents word 0, word 1, word 2, and word 3. The 4 words are a total of 16 bytes (the initial key is 16 bytes). The 4 words are grouped together. The initial key is expanded once to generate W[0:3] for the first round of key addition with the plaintext. W[4:7] is expanded based on W[0:3] to perform the second round of key addition with the output of the first round, and so on.

[0057] In the present invention, before the AES module performs multiple rounds of encryption and decryption operations, a round key addition operation is performed based on the expanded multiple round keys: the current state is XORed with the round key of the current round, and the XOR operation result is used as the round key of the first round of decryption or encryption operation; the multiple rounds of encryption and decryption operations include a main round step and a last round step. Among them, the main round refers to the first round to the second to last round, the steps are the same, and the last round is the last round. The present invention effectively improves the security of the ciphertext or plaintext finally generated through multiple rounds of encryption or decryption processing, and improves the security and reliability of data transmission.

[0058] In the present invention, when data encryption is performed, the steps of the main round of encryption include:

[0059] Get the round key of the current round and perform byte replacement: Perform nonlinear replacement on each byte in the state matrix through the lookup table (S-Box) to enhance the nonlinear characteristics;

[0060] Row shift: Each row is cyclically shifted to the left according to a specific rule to disrupt the data arrangement and improve diffusion;

[0061] Column confusion: linearly transform each column to make the output column more diffuse than the column before confusion;

[0062] Round key addition: XOR the current state with the round key of the current round to ensure the influence of the key on the encryption process;

[0063] The round key after the XOR operation is used as the round key for the next round of encryption operation.

[0064] These steps of the main round encryption can be repeated multiple times, allowing the AES module to effectively obfuscate the input data and improve security.

[0065] like Figure 3 As shown, in the present invention, when data decryption is performed, the steps of the main round of decryption include:

[0066] Get the round key of the current round and perform reverse shift: perform reverse cyclic shift on each row of the state matrix to restore the order of data;

[0067] Reverse byte replacement: Use the inverse lookup (S-Box) table to replace each byte in the state matrix to restore the original byte;

[0068] Round key addition: XOR the current state with the current round key;

[0069] Inverse column confusion: perform an inverse linear transformation on each column and reintegrate the bytes in the column;

[0070] The round key after the inverse column confusion operation is used as the round key for the next round of decryption operation.

[0071] Repeated multiple rounds of these steps of primary round decryption effectively convert the ciphertext back to the original plaintext, ensuring the security and integrity of the data.

[0072] In the present invention, in the last round of steps, the last round of encryption steps include: byte replacement, row shift, round key addition; the last round of decryption steps include: reverse row shift, reverse byte replacement, round key addition. The functions of the above steps are the same as those in the decryption and encryption steps. The reason for removing the column obfuscation process in the last round of decryption and encryption steps is that because the column obfuscation is performed according to certain rules, it can be easily restored. In the last round, if column obfuscation is performed, this step can be easily restored during decryption, but it cannot effectively increase the encryption effect, and it also takes a certain amount of time.

[0073] In the present invention, multiple round keys are generated by expanding the key during the encryption and decryption process to enhance the security of the encryption and decryption process. Each round key is expanded into a new round key by word circulation, byte substitution and round constant XOR processing, so that the relationship between the generated round key and the original key is not easy to be guessed. The existence of multiple round keys makes the encryption and decryption operations of each round use different keys (i.e., one round key for each round, and the round key used each time is expanded on the basis of the previous round key, and the round key addition is that the round key corresponding to the current round is output by the round and the round key is XORed), which increases the difficulty of the attacker to crack. In addition, key expansion ensures the consistency of the encryption and decryption process, allowing the same round key to be used in the encryption and decryption process, thereby ensuring that the original plaintext can be correctly restored. This embodiment also supports keys of different lengths (e.g., 128, 192 and 256 bits), and generates round keys adapted to different needs through key expansion, thereby improving flexibility and applicability.

[0074] In the present invention, the QSPI controller module supports multiple working modes, including: indirect mode, status polling mode and memory mapping mode. The present invention works in combination with AES in memory mapping mode. In memory mapping mode, external Flash is regarded as internal memory, and only read operations are allowed in this mode. Memory mapping mode is entered by setting FMODE=11 in the QUADSPI_CCR register.

[0075] The QSPI controller in the present invention needs to be configured as memory mapping mode when working in conjunction with AES, and the memory mapping mode can be used in conjunction with other protocol modes. By configuring the DMODE field of the QUADSPI_CCR register, single, dual, or quad-wire communication with external Flash can be selected; by configuring the DDRM field of the QUADSPI_CCR register, SDR (default) or DDR mode communication can be selected; by configuring the SIOO field of the QUADSPI_CCR register, single instruction mode can be entered; by configuring the DFM field of the QUADSPI_CR register, dual Flash mode can be entered. Multiple protocol modes can be used in combination. The memory mapping mode can be better compatible with external Flash from different manufacturers by being used in conjunction with other protocol modes. The communication timing of different manufacturers may be different. Freely configuring other protocol modes can meet the timing requirements of different manufacturers.

[0076] In the present invention, a workflow of a QSPI controller interface combined with AES encryption is as follows:

[0077] The QSPI controller module configures whether the AES module is enabled through registers. If the AES module is not enabled, the data read back from the external Flash by the QSPI controller module is directly transmitted to the bus; if the AES module is enabled, the mode of the AES module is configured according to the registers.

[0078] If the AES module is in encryption mode, the QSPI controller module sends the plaintext read back from the external Flash to the AES module, waiting for the AES module to complete the encryption operation and generate the corresponding ciphertext; the AES module sends the ciphertext to the QSPI controller module, and the QSPI controller module sends the ciphertext to the bus.

[0079] If the AES module is in decryption mode, the QSPI controller module will send the ciphertext read back from the external Flash to the AES module, and wait for the AES module to complete the decryption operation to generate the corresponding plaintext; the AES module will send the plaintext to the QSPI controller module, and the QSPI controller module will send the plaintext to the bus.

[0080] Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of the present invention.

Claims

1. A QSPI controller interface combined with AES encryption, characterized in that: include: QSPI controller module and AES module; The QSPI controller module reads the corresponding data from the external Flash based on the bus requirements and performs AES encryption and decryption processing; AES module, including AES encryption module and AES decryption module. The AES module performs multiple rounds of encryption and decryption operations based on the data read back by the QSPI controller module; During the encryption and decryption process, the AES module expands the initial key, generates multiple round keys, and performs encryption and decryption operations based on the multiple round keys and the data read back by the QSPI controller module.

2. The QSPI controller interface combined with AES encryption according to claim 1, characterized in that: The QSPI controller module includes a clock control module, a control module and a data transceiver module; the clock control module is used to generate an SCLK clock signal and a chip select signal CS, and output them to an external Flash for data transmission control; the control module uses a state machine to control state jumps; the data transceiver module is used to send and receive data.

3. The QSPI controller interface combined with AES encryption according to claim 1, characterized in that: The specific steps of the AES module key expansion are: Input the initial key into a 4*4 state matrix. Each element in the initial key represents a byte. In the state matrix, the 4 bytes in each column form a word, which are named W[0], W[1], W[2], and W[3] respectively. Expand the W[i] array to obtain other elements; When expanding elements, the i-th column element is determined recursively, and the steps are as follows: If i is not a multiple of 4, the i-th column element is determined by the following equation: If i is a multiple of 4, the i-th column is determined by the following equation: Wherein, W represents WORD; T represents T operation, and its steps include: word loop, byte substitution and round constant XOR.

4. The QSPI controller interface combined with AES encryption according to claim 1, characterized in that: Before the AES module performs multiple rounds of encryption and decryption operations, it performs a round key addition operation based on the expanded multiple round keys: the current state is XORed with the round key of the current round, and the XOR operation result is used as the round key of the first round of decryption or encryption operation; the multiple rounds of encryption and decryption operations include a main round step and a final round step.

5. The QSPI controller interface combined with AES encryption according to claim 4, characterized in that: When encrypting data, the main round of encryption steps include: Get the round key of the current round and perform byte replacement: Perform nonlinear replacement on each byte in the state matrix through the lookup table; Row shift: Each row is cyclically shifted to the left according to specific rules; Column confusion: linear transformation of each column; Round key addition: XOR the current state with the round key of the current round; The round key after the XOR operation is used as the round key for the next round of encryption operation.

6. The QSPI controller interface combined with AES encryption according to claim 4, characterized in that: When decrypting data, the main round of decryption steps include: Get the round key of the current round and perform reverse shift: perform reverse cyclic shift on each row of the state matrix to restore the order of data; Inverse byte replacement: Use the inverse lookup table to replace each byte in the state matrix; Round key addition: XOR the current state with the current round key; Inverse column confusion: perform an inverse linear transformation on each column and reintegrate the bytes in the column; The round key after the inverse column confusion operation is used as the round key for the next round of decryption operation.

7. The QSPI controller interface combined with AES encryption according to claim 4, characterized in that: In the last round of steps, The steps of the final round of encryption include: byte substitution, row shift, and round key addition; The steps of the final round of decryption include: reverse shift, reverse byte replacement, and round key addition.

8. The QSPI controller interface combined with AES encryption according to claim 1, characterized in that: The QSPI controller module configures whether the AES module is enabled through a register. If the AES module is not enabled, the data read back from the external Flash by the QSPI controller module is directly transmitted to the bus; if the AES module is enabled, the mode of the AES module is configured according to the register.

9. The QSPI controller interface combined with AES encryption according to claim 8, characterized in that: If the mode of the AES module is encryption mode, the QSPI controller module sends the plaintext read back from the external Flash to the AES module, waits for the AES module to complete the encryption operation, and generates the corresponding ciphertext; the AES module sends the ciphertext to the QSPI controller module, and the QSPI controller module sends the ciphertext to the bus; If the mode of the AES module is decryption mode, the QSPI controller module will send the ciphertext read back from the external Flash to the AES module, and wait for the AES module to complete the decryption operation to generate the corresponding plaintext; The AES module sends the plaintext to the QSPI controller module, and the QSPI controller module sends the plaintext to the bus.

10. The QSPI controller interface combined with AES encryption according to claim 9, characterized in that: The working modes of the QSPI controller module include: indirect mode, status polling mode and memory mapping mode; when the QSPI controller module works in conjunction with the AES module, the working mode of the QSPI controller module is the memory mapping mode.