Chip security mechanism self-checking system and method, computer equipment and storage medium
By designing a chip safety mechanism self-test system including self-test control module, pseudo-random number generation module, cyclic redundancy verification module and safety mechanism unit, the problem of the need to design a detection circuit for each safety mechanism in the prior art is solved, and general testing of different safety mechanism units is realized, and testing efficiency and design cycle are improved.
Patent Information
- Application Number
- CN202510037158.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-09
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2045-01-09
AI Technical Summary
When verifying chip safety mechanisms, the prior art requires the design of detection circuits for each safety mechanism separately, which cannot be generalized, which increases design complexity and time cost.
Design a chip safety mechanism self-test system, including a self-test control module, a pseudo-random number generation module, a cyclic redundancy verification module and a safety mechanism unit. Through pseudo-random number excitation and cyclic redundancy verification, general testing of different safety mechanism units is realized.
A general testing method for different safety mechanism units is realized, which avoids the waste of resources for full-range testing, improves testing efficiency and fault coverage, and shortens the design cycle.
Smart Images

Figure CN119940246A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of security mechanism detection, and in particular to a chip security mechanism self-checking system, method, computer device and storage medium. Background Art
[0002] With the rapid development of chip design technology, functional safety has become an indispensable part of modern chip design. In chip design with functional safety requirements, it is necessary to ensure that the chip can still work normally when a single point failure occurs, so as to avoid chip functional errors that cannot be detected due to multiple point failures. Therefore, safety mechanisms are usually added to the design to simulate and detect single point failures of safety functions.
[0003] At present, in order to verify the effectiveness of these safety mechanisms, the industry has adopted a variety of detection methods. These detection methods usually apply excitation signals to specific safety mechanisms and determine whether the mechanism is working properly by detecting whether its output meets expectations. However, this method requires a separate detection circuit to be designed for each safety mechanism, which cannot be used across different types of safety mechanisms, greatly increasing the design complexity and time cost.
[0004] In order to solve the above problems, the Logic Built-In Self-Test (LBIST) technology came into being. LBIST technology uses the Design for Testability (DFT) circuit to apply stimulus to all circuits in a module and detect whether their outputs meet expectations. A notable feature of this technology is that it does not depend on the specific type of security mechanism and can achieve universal detection to a large extent.
[0005] However, LBIST technology tests all circuits inside the block, which will affect the test time, coverage and power consumption, and verification needs to wait until the netlist stage to be performed, which prolongs the entire design cycle. Summary of the invention
[0006] Based on this, it is necessary to provide a chip safety mechanism self-check system, method, computer device and storage medium to address the above technical problems.
[0007] A chip safety mechanism self-checking system, the system comprising:
[0008] A self-check control module, a pseudo-random number generation module, a cyclic redundancy check module and at least one security mechanism unit;
[0009] The self-check control module is connected to the pseudo-random number generation module, the security mechanism unit and the cyclic redundancy check module, and is used to send a control signal to the security mechanism unit that needs self-checking according to the configuration, enable the self-checking function of the security mechanism unit, send a pseudo-random number seed to the pseudo-random number generation module, and compare the check code sent by the cyclic redundancy check module with the check value, and output the self-check result according to the comparison result;
[0010] The pseudo-random number generation module generates a number of pseudo-random numbers according to the pseudo-random number seeds provided by the self-check control module, and outputs the pseudo-random numbers to each security mechanism unit;
[0011] The safety mechanism unit is used to start self-check according to the control signal, receive pseudo-random number stimulus, perform corresponding operations, and send output data to the cyclic redundancy check module;
[0012] The cyclic redundancy check module is used to receive the output data generated by each security mechanism unit after traversing each pseudo-random number, perform a cyclic redundancy check operation on the output data of each security mechanism unit, generate a corresponding check code, and send the current check code to the self-check control module when the pseudo-random number traversal is completed.
[0013] A chip safety mechanism self-check method, the method comprising:
[0014] The self-check control module sends a control signal to the security mechanism unit that needs self-check according to the configuration, enables the self-check function of the security mechanism unit, sends a pseudo-random number seed to the pseudo-random number generation module, and compares the check code sent by the cyclic redundancy check module with the check value, and outputs the self-check result according to the comparison result;
[0015] Generate a number of pseudo-random numbers through the pseudo-random number generation module according to the pseudo-random number seeds provided by the self-check control module, and output the pseudo-random numbers to each security mechanism unit;
[0016] The safety mechanism unit starts a self-check according to a control signal, receives a pseudo-random number stimulus, performs a corresponding operation, and sends output data to a cyclic redundancy check module;
[0017] The cyclic redundancy check module receives the output data generated by each security mechanism unit after traversing each pseudo-random number, performs a cyclic redundancy check operation on the output data of each security mechanism unit, generates a corresponding check code, and sends the current check code to the self-check control module when the pseudo-random number traversal is completed.
[0018] A computer device comprises a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, the following steps are implemented:
[0019] The self-check control module sends a control signal to the security mechanism unit that needs self-check according to the configuration, enables the self-check function of the security mechanism unit, sends a pseudo-random number seed to the pseudo-random number generation module, and compares the check code sent by the cyclic redundancy check module with the check value, and outputs the self-check result according to the comparison result;
[0020] Generate a number of pseudo-random numbers through the pseudo-random number generation module according to the pseudo-random number seeds provided by the self-check control module, and output the pseudo-random numbers to each security mechanism unit;
[0021] The safety mechanism unit starts a self-check according to a control signal, receives a pseudo-random number stimulus, performs a corresponding operation, and sends output data to a cyclic redundancy check module;
[0022] The cyclic redundancy check module receives the output data generated by each security mechanism unit after traversing each pseudo-random number, performs a cyclic redundancy check operation on the output data of each security mechanism unit, generates a corresponding check code, and sends the current check code to the self-check control module when the pseudo-random number traversal is completed.
[0023] A computer-readable storage medium stores a computer program, which, when executed by a processor, implements the following steps:
[0024] The self-check control module sends a control signal to the security mechanism unit that needs self-check according to the configuration, enables the self-check function of the security mechanism unit, sends a pseudo-random number seed to the pseudo-random number generation module, and compares the check code sent by the cyclic redundancy check module with the check value, and outputs the self-check result according to the comparison result;
[0025] Generate a number of pseudo-random numbers through the pseudo-random number generation module according to the pseudo-random number seeds provided by the self-check control module, and output the pseudo-random numbers to each security mechanism unit;
[0026] The safety mechanism unit starts a self-check according to a control signal, receives a pseudo-random number stimulus, performs a corresponding operation, and sends output data to a cyclic redundancy check module;
[0027] The cyclic redundancy check module receives the output data generated by each security mechanism unit after traversing each pseudo-random number, performs a cyclic redundancy check operation on the output data of each security mechanism unit, generates a corresponding check code, and sends the current check code to the self-check control module when the pseudo-random number traversal is completed.
[0028] The above chip security mechanism self-check system, method, computer device and storage medium flexibly select the security mechanism unit that needs self-check according to the configuration through the self-check control module, enable its self-check function, and accurately test the security mechanism through the pseudo-random number excitation provided by the pseudo-random number generation module, thereby avoiding the waste of resources for full-range testing and improving the test efficiency and fault coverage. The pseudo-random number generation module can generate a variety of pseudo-random numbers according to the seed, provide a unified excitation input for all security mechanisms, and the cyclic redundancy check module receives the response output of all security mechanisms for unified verification, thereby realizing a universal test method for different security mechanism units, which is highly adaptable and easy to expand. The security mechanism unit can control only the specified module to perform excitation testing through the multiplexer design to ensure that irrelevant circuits work normally. The cyclic redundancy check module compresses the output data after each pseudo-random number test and generates a check code, thereby realizing fast and accurate result verification, and the verification can be completed in the RTL stage, which greatly shortens the design cycle. The embodiment of the present invention can improve the efficiency and reliability of security mechanism self-check in a complex chip environment. BRIEF DESCRIPTION OF THE DRAWINGS
[0029] Figure 1 A structural block diagram of a chip safety mechanism self-checking system in one embodiment;
[0030] Figure 2 A schematic diagram of the working process of the system of the present invention in one embodiment;
[0031] Figure 3 FIG. 4 is a diagram showing the internal structure of a computer device in one embodiment. DETAILED DESCRIPTION
[0032] In order to make the purpose, technical solution and advantages of the present application more clearly understood, the present application is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0033] In one embodiment, Figure 1 As shown, a chip security mechanism self-check system is provided, including a self-check control module, a pseudo-random number generation module, a cyclic redundancy check module and at least one security mechanism unit;
[0034] The self-check control module is connected to the pseudo-random number generation module, the security mechanism unit and the cyclic redundancy check module, and is used to send a control signal to the security mechanism unit that needs self-checking according to the configuration, enable the self-checking function of the security mechanism unit, send a pseudo-random number seed to the pseudo-random number generation module, and compare the check code sent by the cyclic redundancy check module with the check value, and output the self-check result according to the comparison result;
[0035] The pseudo-random number generation module generates a number of pseudo-random numbers according to the pseudo-random number seeds provided by the self-check control module, and outputs the pseudo-random numbers to each security mechanism unit;
[0036] The safety mechanism unit is used to start self-check according to the control signal, receive the pseudo-random number stimulus, perform the corresponding operation, and send the output data to the cyclic redundancy check module;
[0037] The cyclic redundancy check module is used to receive the output data generated by each security mechanism unit after traversing each pseudo-random number, perform cyclic redundancy check operation on the output data of each security mechanism unit, generate a corresponding check code, and send the current check code to the self-check control module when the pseudo-random number traversal is completed.
[0038] Figure 1 In the example, bist_ctrl represents the self-check control module. According to the configuration and control information of the CPU or hardware, the corresponding security mechanism is started to perform self-check, and the crc is checked after the self-check is completed. prng represents the pseudo-random number generation module. Each time, it obtains the pseudo-random number seed from bist_ctrl, generates a round of pseudo-random numbers, and outputs them to each module. sm0sm1...smn represent the security mechanism module. The input and output of these modules need to be added with mux. When sm_bist_en is valid, the stimulus provided by prng is selected and output to the crc module. When sm_bist_en is invalid, the original function input is selected, and the output is also connected to the original function module. crc represents the cyclic redundancy check module. This module receives the output of all security mechanism units, generates a crc check code, and outputs it to bist_ctrl for comparison.
[0039] In the above chip security mechanism self-check system, the self-check control module flexibly selects the security mechanism unit that needs self-check according to the configuration, enables its self-check function, and accurately tests the security mechanism through the pseudo-random number excitation provided by the pseudo-random number generation module, thereby avoiding the waste of resources for full-range testing and improving the test efficiency and fault coverage. The pseudo-random number generation module can generate a variety of pseudo-random numbers according to the seed, provide a unified excitation input for all security mechanisms, and the cyclic redundancy check module receives the response output of all security mechanisms for unified verification, thereby realizing a universal test method for different security mechanism units, which is highly adaptable and easy to expand. The security mechanism unit can control only the specified module to perform excitation testing through the multiplexer design to ensure that irrelevant circuits work normally. The cyclic redundancy check module compresses the output data after each pseudo-random number test and generates a check code, thereby realizing fast and accurate result verification, and the verification can be completed in the RTL stage, which greatly shortens the design cycle. The embodiment of the present invention can improve the efficiency and reliability of security mechanism self-check in a complex chip environment.
[0040] In one embodiment, the security mechanism unit includes a security mechanism module, a first multiplexer and a second multiplexer; the input interface and the output interface of the security mechanism module are respectively connected to the first multiplexer and the second multiplexer, the first multiplexer is connected to the pseudo-random number generation module, and is used to receive the pseudo-random number sent by the pseudo-random number generation module, and the second multiplexer is connected to the cyclic redundancy check module, and is used to send the output data of the security mechanism module to the cyclic redundancy check module.
[0041] In one embodiment, the first multiplexer is further used to receive input data from a normal function path; and the second multiplexer is further used to send output data of the safety mechanism module to the normal function path.
[0042] In one embodiment, the system further includes a processor; the processor is connected to the self-test control module, and is used to read configuration data from a non-volatile memory, and initialize the self-test control module using the configuration data. In this embodiment, the processor (CPU) is used to implement software control of bist_ctrl configuration and startup, and for chips without a CPU, hardware control startup can be used. The non-volatile memory (NVM) stores the prng seed and the related configuration of bist_ctrl, and different test coverage and test objects are achieved according to different configurations.
[0043] In one embodiment, the check code sent by the cyclic redundancy check module is compared with the check value, and a self-check result is output according to the comparison result, including: analyzing whether the check code sent by the cyclic redundancy check module meets the check value, if so, determining whether the random number seed needs to be replaced, if not, outputting a correct self-check result; if not, the self-check fails, and a self-check error result is output.
[0044] In one embodiment, the check code sent by the cyclic redundancy check module is compared with the check value, and the self-check result is output according to the comparison result, and it also includes: if the random number seed needs to be replaced, a new pseudo-random number seed is sent to the pseudo-random number generation module according to the configuration.
[0045] In one embodiment, determining whether the random number seed needs to be replaced includes: if the fault coverage of a number of random numbers corresponding to the current pseudo-random number seed for the security mechanism module is lower than an expected target, the random number seed needs to be replaced.
[0046] In a specific embodiment, Figure 2 As shown, a schematic diagram of the workflow of the system of the present invention is provided, and the steps are described as follows:
[0047] S1, cpu or hardware initializes the configuration of bist_ctrl according to NVM.
[0048] S2. bist_ctrl enables the corresponding safety mechanism self-checking according to the configuration.
[0049] S3, bist_ctrl provides a pseudo-random number seed to prng and enables prng to generate pseudo-random numbers.
[0050] S4, the pseudo-random number of PRNG is sent to various security mechanisms. Therefore, each time the pseudo-random number changes, the internal logic will perform different operations, and the output will also change accordingly. The output is sent to the crc module, and the crc verifies all the signals sent in each cycle.
[0051] S5. Traverse all pseudo-random numbers in sequence.
[0052] S6. After all pseudo-random numbers are traversed, check whether the crc meets the expectations. If not, output a self-check error state or an alarm signal.
[0053] S7. It is possible that the random number corresponding to a pseudo-random number seed does not have a high fault coverage rate for the security mechanism. In this case, the pseudo-random number seed can be replaced and the execution can be started again from S3.
[0054] S8. If all seeds are executed and the CRCs are correctly compared, the self-check is considered to have passed.
[0055] In this embodiment, through the control of the self-check control module, it supports the expansion of different categories of security mechanisms. It only needs to configure the corresponding security mechanism unit, and there is no need to design a specific detection circuit for each security mechanism. In addition, the security mechanism unit that needs self-checking can be accurately controlled to enable, and the irrelevant circuit works normally, avoiding resource waste and improving the self-checking efficiency. Using pseudo-random numbers as test stimuli does not rely on the implementation method and type of a specific security mechanism, which enhances the universality of the test. The pseudo-random number generation module generates multiple test vectors according to the seed, covering more test scenarios, so as to more effectively detect the potential faults of the security mechanism. The pseudo-random number generation module provides a unified stimulus and the CRC module uniformly verifies the output of the security mechanism unit. The system can adapt to different types of security mechanisms and realize a unified test process. By real-time verification of the output data, it is compressed into a check code, and the status of the security mechanism unit is quickly evaluated, which reduces the time for analyzing the original output data. The functions of each module of this system can be designed and verified in the RTL stage, avoiding the delay in the netlist stage, and greatly shortening the entire design cycle.
[0056] It should be understood that although Figure 2 The steps in the flowchart are shown in sequence as indicated by the arrows, but these steps are not necessarily executed in the order indicated by the arrows. Unless otherwise specified in this document, there is no strict order restriction for the execution of these steps, and these steps can be executed in other orders. Moreover, Figure 2 At least part of the steps may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily executed at the same time, but can be executed at different times. The execution order of these sub-steps or stages is not necessarily sequential, but can be executed in turn or alternately with other steps or at least part of the sub-steps or stages of other steps.
[0057] In one embodiment, a chip safety mechanism self-check method is provided, comprising the following steps:
[0058] The self-check control module sends a control signal to the security mechanism unit that needs self-check according to the configuration, enables the self-check function of the security mechanism unit, sends a pseudo-random number seed to the pseudo-random number generation module, and compares the check code sent by the cyclic redundancy check module with the check value, and outputs the self-check result according to the comparison result;
[0059] Generate a number of pseudo-random numbers using a pseudo-random number generation module based on a pseudo-random number seed provided by the self-check control module, and output the pseudo-random numbers to each security mechanism unit;
[0060] The safety mechanism unit starts a self-check according to a control signal, receives a pseudo-random number stimulus, performs a corresponding operation, and sends output data to a cyclic redundancy check module;
[0061] The cyclic redundancy check module receives the output data generated by each security mechanism unit after traversing each pseudo-random number, performs a cyclic redundancy check operation on the output data of each security mechanism unit, generates a corresponding check code, and sends the current check code to the self-check control module when the pseudo-random number traversal is completed.
[0062] For the specific definition of the chip safety mechanism self-checking method, please refer to the definition of the chip safety mechanism self-checking system above, which will not be repeated here. Each module in the above chip safety mechanism self-checking system can be implemented in whole or in part by software, hardware and a combination thereof. The above modules can be embedded in or independent of the processor in the computer device in the form of hardware, or can be stored in the memory of the computer device in the form of software, so that the processor can call and execute the operations corresponding to the above modules.
[0063] In one embodiment, a computer device is provided. The computer device may be a terminal, and its internal structure diagram may be as follows: Figure 3As shown. The computer device includes a processor, a memory, a network interface, a display screen and an input device connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The network interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, a chip security mechanism self-test method is implemented. The display screen of the computer device can be a liquid crystal display screen or an electronic ink display screen, and the input device of the computer device can be a touch layer covered on the display screen, or a key, trackball or touchpad set on the computer device housing, or an external keyboard, touchpad or mouse, etc.
[0064] Those skilled in the art will understand that Figure 3 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine certain components, or have a different arrangement of components.
[0065] In one embodiment, a computer device is provided, including a memory and a processor, wherein the memory stores a computer program, and the processor implements the steps of the method in the above embodiment when executing the computer program.
[0066] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the steps of the method in the above embodiment are implemented.
[0067] A person of ordinary skill in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be implemented by instructing related hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods.
[0068] The technical features of the above embodiments may be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0069] The above-mentioned embodiments only express several implementation methods of the present application, and the descriptions thereof are relatively specific and detailed, but they cannot be understood as limiting the scope of the invention patent. It should be pointed out that, for a person of ordinary skill in the art, several variations and improvements can be made without departing from the concept of the present application, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the attached claims.
Claims
1. A chip safety mechanism self-checking system, characterized in that: The system includes a self-check control module, a pseudo-random number generation module, a cyclic redundancy check module and at least one security mechanism unit; The self-check control module is connected to the pseudo-random number generation module, the security mechanism unit and the cyclic redundancy check module, and is used to send a control signal to the security mechanism unit that needs self-checking according to the configuration, enable the self-checking function of the security mechanism unit, send a pseudo-random number seed to the pseudo-random number generation module, and compare the check code sent by the cyclic redundancy check module with the check value, and output the self-check result according to the comparison result; The pseudo-random number generation module generates a number of pseudo-random numbers according to the pseudo-random number seeds provided by the self-check control module, and outputs the pseudo-random numbers to each security mechanism unit; The safety mechanism unit includes a safety mechanism module, a first multiplexer and a second multiplexer; used to start self-check according to a control signal, receive a pseudo-random number stimulus, perform corresponding operations, and send output data to a cyclic redundancy check module; The input interface and the output interface of the security mechanism module are connected to the first multiplexer and the second multiplexer respectively; The cyclic redundancy check module is used to receive the output data generated by each security mechanism unit after traversing each pseudo-random number, perform a cyclic redundancy check operation on the output data of each security mechanism unit, generate a corresponding check code, and send the current check code to the self-check control module when the pseudo-random number traversal is completed.
2. The system according to claim 1, characterized in that The first multiplexer is connected to the pseudo-random number generation module and is used to receive the pseudo-random number sent by the pseudo-random number generation module; The second multiplexer is connected to the cyclic redundancy check module and is used to send the output data of the security mechanism module to the cyclic redundancy check module.
3. The system according to claim 2, characterized in that The first multiplexer is further used to receive input data from a normal function path; the second multiplexer is further used to send output data of the safety mechanism module to the normal function path.
4. The system according to claim 1, characterized in that The system also includes a processor; The processor is connected to the self-check control module and is used to read configuration data from the non-volatile memory and initialize the self-check control module using the configuration data.
5. The system according to claim 1, characterized in that Compare the check code sent by the cyclic redundancy check module with the check value, and output the self-test result according to the comparison result, including: Analyze whether the check code sent by the cyclic redundancy check module meets the check value. If yes, determine whether the random number seed needs to be replaced. If not, output the correct result of the self-check. If it does not meet the requirements, the self-test fails and an error result is output.
6. The system according to claim 5, characterized in that Compare the check code sent by the cyclic redundancy check module with the check value, and output the self-check result according to the comparison result, and also include: If the random number seed needs to be replaced, a new pseudo-random number seed is sent to the pseudo-random number generation module according to the configuration.
7. The system according to claim 5, characterized in that Determine whether the random number seed needs to be changed, including: If the fault coverage of several random numbers corresponding to the current pseudo-random number seed for the security mechanism module is lower than the expected target, the random number seed needs to be replaced.
8. A chip security mechanism self-checking method implemented in the system according to any one of claims 1 to 7, characterized in that: The method comprises: The self-check control module sends a control signal to the security mechanism unit that needs self-check according to the configuration, enables the self-check function of the security mechanism unit, sends a pseudo-random number seed to the pseudo-random number generation module, and compares the check code sent by the cyclic redundancy check module with the check value, and outputs the self-check result according to the comparison result; Generate a number of pseudo-random numbers through the pseudo-random number generation module according to the pseudo-random number seeds provided by the self-check control module, and output the pseudo-random numbers to each security mechanism unit; The safety mechanism unit starts a self-check according to a control signal, receives a pseudo-random number stimulus, performs a corresponding operation, and sends output data to a cyclic redundancy check module; The cyclic redundancy check module receives the output data generated by each security mechanism unit after traversing each pseudo-random number, performs a cyclic redundancy check operation on the output data of each security mechanism unit, generates a corresponding check code, and sends the current check code to the self-check control module when the pseudo-random number traversal is completed.
9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method described in claim 8 are implemented.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method described in claim 8 are implemented.
Citation Information
Patent Citations
Self-test chip and self-test method
CN118465506A
System-on-chip (SOC) having built-in-self-test circuits and a self-test method of the SOC
CN1661388A
Built-in self test circuit
KR1020030050394A
Functional built-in self-test architecture in an emulation system
US10990728B1