System on chip and security service providing method
By introducing the target host controller and the target device controller in the on-chip system, designing corresponding drivers, and using high-speed buses for communication, the problem of low communication efficiency between the trusted security module and the main processor in the prior art is solved, and high-speed data transmission is realized.
Patent Information
- Application Number
- CN202510114029.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-21
- Publication Date
- 2025-05-13
AI Technical Summary
In the prior art, the communication method between the trusted security module and the main processor chip is limited, resulting in low data transmission efficiency.
The target host controller and the first driver are added to the first processor, the target device controller and the second driver are designed in the trusted security module, and communicate through a high-speed bus (such as a USB bus and a PCIe bus), and the device identification information is used to match the driver to achieve high-speed communication.
By expanding the communication method, the data transmission rate between the first processor and the trusted security module is improved, the high-speed communication needs are met, and the communication efficiency is improved.
Smart Images

Figure CN119988310A_ABST
Abstract
Description
Technical Field
[0001] The present specification relates to the field of computer application technology, specifically, to trusted computing technology under the field of computer application technology, and more specifically, to a system on chip and a method for providing security services. Background Art
[0002] Trusted computing is a security technology framework that aims to enhance the security and trust of computer systems through a series of hardware and software components. It focuses on protecting the integrity of data, authenticating the components of the computing platform, and ensuring the secure boot of the system to prevent malware and unauthorized modifications. Several key components of trusted computing technology include TCM (Trusted Computing Module), TPM (Trusted Platform Module) and TPCM (Trusted Platform Control Module). In some cases, TCM, TPM and TPCM can be referred to as Trusted Security Module (TSM).
[0003] In the related art, the communication method between the trusted security module and the main processor chip is limited, resulting in low data transmission efficiency between the trusted security module and the main processor chip. Summary of the invention
[0004] The embodiments of this specification provide a system on chip and a method for providing security services to achieve the purpose of expanding the communication method between the trusted security module and the first processor and improving the data transmission efficiency between the trusted security module and the first processor.
[0005] To achieve the above technical objectives, the embodiments of this specification provide the following technical solutions:
[0006] An embodiment of the present specification provides a system on chip, comprising: a first processor and a trusted security module; the first processor comprises a first driver and a target host controller; the trusted security module comprises a target device controller, a second driver and a password module, the target host controller and the target device controller are connected via a high-speed bus, and the data transmission rate of the high-speed bus is higher than a set threshold; wherein,
[0007] The second driver includes a target descriptor, and the target descriptor includes device identification information; the device identification information is used to match the first driver;
[0008] The first driver is used to respond to a security request for the cryptographic module and send the security request to the target device controller through the target host controller according to the device identification information carried in the security request;
[0009] The target device controller is used to respond to the security request and call the password module through the second driver to provide security services.
[0010] In conjunction with the first aspect, in certain embodiments of the first aspect, the first processor further includes a target controller driver;
[0011] The security request includes a write request, and the write request also carries data to be written;
[0012] The first driver is specifically configured to, in response to the write request, drive the target controller to send the write request to the target device controller through the target host controller according to the device identification information;
[0013] The target device controller is specifically configured to, in response to the write request, store the data to be written into a cache queue and send a first interrupt to the second driver;
[0014] The second driver is specifically configured to, in response to the first interrupt, obtain the data to be written from the cache queue and write the data to be written into the password module.
[0015] In combination with the first aspect, in some implementations of the first aspect, the second driver program obtains the to-be-written data from the cache queue specifically for:
[0016] The second driver program reads a first target register of the target device controller to obtain the data to be written.
[0017] In combination with the first aspect, in certain implementations of the first aspect, further comprising: a second processor, the second processor comprising a security element subsystem and a storage module corresponding to the security element subsystem;
[0018] The second driver is further configured to, in response to the first interrupt, write the data to be written into a storage module corresponding to the secure element subsystem.
[0019] In conjunction with the first aspect, in certain embodiments of the first aspect, the first processor further includes a target controller driver;
[0020] The security request includes a read request;
[0021] The first driver is specifically configured to, in response to the read request, drive the target controller to send the read request to the target device controller through the target host controller according to the device identification information;
[0022] The target device controller is specifically used to, in response to the read request, send a second interrupt to the second driver, and when receiving the to-be-sent data returned by the second driver, send the to-be-sent data to the target host controller through the high-speed bus to instruct the target host controller to return the to-be-sent data to the requester of the read request;
[0023] The second driver is specifically used to, in response to the second interrupt, read the data to be sent from the target location and return the data to be sent to the target device controller; the target location includes the password module.
[0024] In combination with the first aspect, in some implementations of the first aspect, the second driver program returns the to-be-sent data to the target device controller specifically for:
[0025] The second driver program writes the data to be sent into the first target register of the target device controller and writes into the second target register of the target device controller to instruct the target device controller to send out the data to be sent written in the first target register.
[0026] In combination with the first aspect, in certain embodiments of the first aspect, the high-speed bus includes at least one of a USB bus and a PCIe bus.
[0027] In combination with the first aspect, in certain implementations of the first aspect, the trusted security module includes at least one of a trusted cryptographic module TCM, a trusted platform module TPM, and a trusted platform control module TPCM.
[0028] In a second aspect, an embodiment of the present specification provides a method for providing a security service, which is applied to a system on chip, wherein the system on chip includes: a first processor and a trusted security module; the first processor includes a first driver and a target host controller; the trusted security module includes a target device controller, a second driver and a password module, the target host controller and the target device controller are connected via a high-speed bus, and the data transmission rate of the high-speed bus is higher than a set threshold; wherein the second driver includes a target descriptor, and the target descriptor includes device identification information; the device identification information is used to match the first driver; the method for providing a security service includes:
[0029] In response to the security request for the cryptographic module through the first driver, the security request is sent to the target device controller through the target host controller according to the device identification information carried in the security request;
[0030] The target device controller responds to the security request and the second driver program calls the cryptographic module to provide security services.
[0031] In conjunction with the second aspect, in certain embodiments of the second aspect, the first processor further includes a target controller driver;
[0032] The security request includes a write request, and the write request also carries data to be written;
[0033] The step of responding to the security request for the cryptographic module through the first driver and sending the security request to the target device controller through the target host controller according to the device identification information carried in the security request includes:
[0034] In response to the write request through the first driver, according to the device identification information, the write request is sent to the target device controller through the target host controller through the target controller driver;
[0035] The step of, in response to the security request, calling the cryptographic module through the second driver to provide security services through the target device controller includes:
[0036] Through the target device controller, in response to the write request, the data to be written is stored in a cache queue, a first interrupt is sent to the second driver, and through the second driver, in response to the first interrupt, the data to be written is obtained from the cache queue and written into the password module.
[0037] In combination with the second aspect, in some implementations of the second aspect, obtaining the to-be-written data from the cache queue includes:
[0038] A first target register of the target device controller is read to obtain the data to be written.
[0039] In conjunction with the second aspect, in some implementations of the second aspect, the system on chip further includes: a second processor, the second processor including a secure element subsystem and a storage module corresponding to the secure element subsystem;
[0040] The method for providing the security service also includes:
[0041] In response to the first interrupt, the second driver writes the data to be written into a storage module corresponding to the secure element subsystem.
[0042] In conjunction with the second aspect, in certain embodiments of the second aspect, the first processor further includes a target controller driver;
[0043] The security request includes a read request;
[0044] The step of responding to the security request for the cryptographic module through the first driver and sending the security request to the target device controller through the target host controller according to the device identification information carried in the security request includes:
[0045] In response to the read request through the first driver, according to the device identification information, the read request is sent to the target device controller through the target host controller through the target controller driver;
[0046] The step of, in response to the security request, calling the cryptographic module through the second driver to provide security services through the target device controller includes:
[0047] In response to the read request, the target device controller sends a second interrupt to the second driver, and when receiving the data to be sent returned by the second driver, it is sent to the target host controller through the high-speed bus to instruct the target host controller to return the data to be sent to the requester of the read request; in response to the second interrupt, the second driver reads the data to be sent from the target location and returns the data to be sent to the target device controller; the target location includes the password module.
[0048] In conjunction with the second aspect, in some implementations of the second aspect, returning the to-be-sent data to the target device controller includes:
[0049] The data to be sent is written into a first target register of the target device controller, and a second target register of the target device controller is written to instruct the target device controller to send out the data to be sent written in the first target register.
[0050] In combination with the second aspect, in certain embodiments of the second aspect, the high-speed bus includes at least one of a USB bus and a PCIe bus.
[0051] In combination with the second aspect, in certain embodiments of the second aspect, the trusted security module includes at least one of a trusted cryptographic module TCM, a trusted platform module TPM, and a trusted platform control module TPCM.
[0052] In a third aspect, an embodiment of the present specification further provides a computing device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the method for providing security services as described above when executing the computer program.
[0053] In a fourth aspect, an embodiment of the present specification further provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the method for providing security services as described above is implemented.
[0054] In a fifth aspect, an embodiment of the present specification provides a computer program product or a computer program, wherein the computer program product includes a computer program, and the computer program is stored in a computer-readable storage medium; the processor of the computer device reads the computer program from the computer-readable storage medium, and the processor implements the steps of the above-mentioned method for providing security services when executing the computer program.
[0055] It can be seen from the above technical solution that in the system on chip provided by the embodiment of this specification, the first processor includes a first driver and a target host controller, the trusted security module includes a target device controller, a second driver and a password module, the target host controller and the target device controller are connected via a high-speed bus, the data transmission rate of the high-speed bus is higher than a set threshold, the second driver includes a target descriptor, and the target descriptor includes device identification information; the device identification information is used to match the first driver, so that during the communication process between the first processor and the trusted security module, the first driver can identify the second driver through the device identification information, so that the first processor can identify the trusted security module as complying with the high-speed bus communication The invention relates to a device for communicating with a trusted security module through a high-speed bus. In a specific communication process, the first driver responds to a security request for the cryptographic module, and sends the security request to the target device controller through the target host controller according to the device identification information carried in the security request; and the target device controller responds to the security request through the second driver to call the cryptographic module to provide security services. In this way, the need for the first processor and the trusted security module to communicate through the high-speed bus during the security service provision process is met, and the purpose of expanding the communication mode between the first processor and the trusted security module and meeting the high-speed communication need of the first processor and the trusted security module is achieved, thereby improving the data communication rate between the first processor and the trusted security module. BRIEF DESCRIPTION OF THE DRAWINGS
[0056] In order to more clearly illustrate the embodiments of this specification or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of this specification. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without paying creative work.
[0057] Figure 1 A schematic diagram of the structure of a system on a chip provided for one embodiment of the present specification;
[0058] Figure 2 A schematic diagram of the structure of another system on chip provided for one embodiment of the present specification;
[0059] Figure 3 A schematic diagram of the structure of another system on chip provided for one embodiment of the present specification;
[0060] Figure 4 A schematic diagram of the structure of another system on chip provided for one embodiment of the present specification;
[0061] Figure 5 A schematic diagram of the structure of an optional system on chip provided for one embodiment of this specification;
[0062] Figure 6 A schematic diagram of the structure of another optional system on chip provided for one embodiment of this specification;
[0063] Figure 7 A flowchart of a method for providing a security service provided in one embodiment of this specification;
[0064] Figure 8 A schematic diagram of the structure of a computing device provided for one embodiment of the present specification. DETAILED DESCRIPTION
[0065] Unless otherwise defined, the technical terms or scientific terms used in the embodiments of this specification shall have the common meanings understood by persons with ordinary skills in the field to which this specification belongs. The words "first", "second" and similar words used in the embodiments of this specification do not indicate any order, quantity or importance, but are only used to avoid confusion of constituent elements.
[0066] Unless the context requires otherwise, throughout the specification, "plurality" means "at least two", and "including" is interpreted as an open, inclusive meaning, that is, "including, but not limited to". In the description of the specification, the terms "one embodiment", "some embodiments", "exemplary embodiments", "examples", "specific examples" or "some examples" are intended to indicate that a particular feature, structure, material or characteristic associated with the embodiment or example is included in at least one embodiment or example of the specification. The schematic representation of the above terms does not necessarily refer to the same embodiment or example.
[0067] The following will be combined with the drawings in the embodiments of this specification to clearly and completely describe the technical solutions in the embodiments of this specification. Obviously, the described embodiments are only part of the embodiments of this specification, not all of the embodiments. Based on the embodiments in this specification, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this specification.
[0068] Overview
[0069] The trusted security module can provide security services for the system on chip to effectively protect the system security and prevent attackers from illegally accessing the system. The security services that the trusted security module can provide include but are not limited to data encryption and decryption, key management, digital signature and signature verification, integrity verification, and security measurement services. In the related art, the trusted security module can be implemented in the form of a hardware chip, so as to easily access the main processor of the system on chip and provide corresponding security services to the main processor. However, due to the hardware design of the trusted security module, the trusted security module is currently connected to the main processor through a low-speed bus such as the SPI (Serial Peripheral Interface) bus or the I2C (Inter-Integrated Circuit) bus, which results in a low communication rate between the main processor and the trusted security module, affecting the data transmission efficiency between the main processor and the trusted security module.
[0070] In order to solve this problem, the inventors have found that a target host controller that meets the high-speed bus communication requirements can be added to the main processor (hereinafter referred to as the first processor), and a first driver can be designed. The first driver can be used for forwarding security requests and identifying the second driver; a target device controller and a second driver are designed in the trusted security module, and the second driver includes a target descriptor, and the target descriptor includes device identification information; the device identification information is used to match the first driver, so that during the communication process between the first processor and the trusted security module, the first driver can identify the second driver through the device identification information, so that the first processor can identify the trusted security module as following the high-speed bus communication protocol. A communicating device, in a specific communication process, responds to a security request for the cryptographic module through the first driver, and sends the security request to the target device controller through the target host controller according to the device identification information carried in the security request; and responds to the security request through the target device controller, and calls the cryptographic module through the second driver to provide security services. In this way, the need for the first processor and the trusted security module to communicate through the high-speed bus during the security service provision process is met, and the purpose of expanding the communication method between the first processor and the trusted security module and meeting the high-speed communication needs of the first processor and the trusted security module is achieved, thereby improving the data communication rate between the first processor and the trusted security module.
[0071] Based on the above concept, an embodiment of the present specification provides a system on chip. The system on chip provided by the embodiment of the present specification will be exemplarily described below in conjunction with the accompanying drawings.
[0072] Exemplary Systems
[0073] The embodiments of the present specification provide a system on a chip, such as Figure 1 and Figure 2 As shown, it includes: a first processor 10 and a trusted security module 11; the first processor 10 includes a first driver 103 and a target host controller 101; the trusted security module 11 includes a target device controller 110, a second driver 111 and a password module 112, the target host controller 101 and the target device controller 110 are connected via a high-speed bus, and the data transmission rate of the high-speed bus is higher than a set threshold; wherein,
[0074] The second driver 111 includes a target descriptor, and the target descriptor includes device identification information; the device identification information is used to match the first driver 103;
[0075] The first driver 103 is used to respond to the security request for the password module 112 and send the security request to the target device controller 110 through the target host controller 101 according to the device identification information carried in the security request;
[0076] The target device controller 110 is used to respond to the security request and call the password module 112 through the second driver 111 to provide security services.
[0077] refer to Figure 1 In addition to the traditional low-speed bus 13 connection between the trusted security module 11 and the first processor 10, a high-speed bus is extended. In the traditional communication process, the trusted security module 11 and the first processor 10 communicate through the low-speed bus 13 and their respective low-speed bus controllers, and the communication rate is low and the communication efficiency is poor. Therefore, in this embodiment, reference Figure 2 , a target host controller 101 that meets the high-speed bus communication requirements is added to the first processor 10, and a first driver 103 is designed. The first driver 103 can be used for forwarding security requests and identifying the second driver 111; a target device controller 110 and a second driver 111 are designed in the trusted security module 11, and the second driver 111 includes a target descriptor, and the target descriptor includes device identification information; the device identification information is used to match the first driver 103, so that during the communication process between the first processor 10 and the trusted security module 11, the first driver 103 can identify the second driver 111 through the device identification information, so that the first processor 10 can identify the trusted security module 11 as a device that follows the high-speed bus communication protocol for communication, and in the specific communication During the process, the first driver 103 responds to the security request for the cryptographic module 112, and sends the security request to the target device controller 110 through the target host controller 101 according to the device identification information carried in the security request; the target device controller 110 responds to the security request and calls the cryptographic module 112 through the second driver 111 to provide security services. In this way, the need for the first processor 10 and the trusted security module 11 to communicate through the high-speed bus during the security service provision process is met, thereby achieving the purpose of expanding the communication method between the first processor 10 and the trusted security module 11, meeting the high-speed communication needs of the first processor 10 and the trusted security module 11, and improving the data communication rate between the first processor 10 and the trusted security module 11.
[0078] It should be noted that the cryptographic module 112 may refer to a core module for providing security services in the trusted security module 11, and the cryptographic module 112 may be used to store security-related data such as keys and measurement values. A high-speed bus refers to a communication bus capable of providing high-speed data transmission, and such a bus may have a higher bandwidth and a lower latency. In some embodiments, a high-speed bus may refer to a communication bus with a communication rate greater than 100Mbps (Megabits Per Second) or higher, that is, a threshold value may be set greater than or equal to 100Mbps, and of course, as the technical level increases, the threshold value may be set to increase accordingly. In contrast, a low-speed bus may refer to a communication bus with a communication rate of several Mbps or less. This specification does not limit this, and it depends on the actual situation. In an optional embodiment, the target bus includes but is not limited to at least one of a USB (Universal Serial Bus) bus and a PCIe (Peripheral Component Interconnect Express) bus.
[0079] In an optional implementation, a feasible representation of a target descriptor is provided. Taking the target bus including a USB bus as an example, the target descriptor may include the following information:
[0080]
[0081]
[0082] The explanation of the above target descriptors is as follows:
[0083] 1. Bus 001 Device 002: indicates that the trusted security module 11 is connected to bus 001 of the USB bus and is the second device on the bus.
[0084] 2. ID 4875:0100: represents the vendor ID and product ID of the trusted security module 11. The vendor ID is 4875 and the product ID is 0100. These IDs are unique and are used to identify the trusted security module 11. In some implementations, the device identification information may include at least one of the vendor ID and the product ID.
[0085] 3. Device Descriptor: Device descriptor, which contains basic information of the trusted security module 11.
[0086] o bLength: The length of the descriptor, here is 18 bytes.
[0087] o bDescriptorType: descriptor type, 1 means this is a device descriptor.
[0088] o bcdUSB: The version number of the USB specification, here 2.00, indicating USB 2.0.
[0089] o bDeviceClass, bDeviceSubClass, bDeviceProtocol: Device class, subclass, and protocol, all 0 here, indicating that these properties are unspecified or not applicable.
[0090] o bMaxPacketSize0: The default maximum packet size, here is 64 bytes.
[0091] o idVendor,idProduct: Vendor ID and product ID, which are the same as the IDs mentioned above.
[0092] o bcdDevice: The version number of the trusted security module 11, here it is 1.00.
[0093] o iManufacturer,iProduct,iSerial: These are the manufacturer index, product index, and serial number index, respectively, which point to string descriptors that provide human-readable text for the manufacturer, product, and serial number.
[0094] o bNumConfigurations: The number of device configurations, here 1.
[0095] 4.Configuration Descriptor: Configuration descriptor, which describes the configuration information of the device.
[0096] o bLength, bDescriptorType: length and type, 9 bytes, type 2 indicates configuration descriptor.
[0097] o wTotalLength: The total length of the configuration descriptor.
[0098] o bNumInterfaces: The number of interfaces, here is 1.
[0099] o bConfigurationValue,iConfiguration: configuration value and configuration index, used to select configuration.
[0100] o bmAttributes: Configuration attributes, 0x80 indicates that the device is bus-powered.
[0101] o MaxPower: The maximum power consumption of the device, here it is 200mA.
[0102] 5.Interface Descriptor: Interface descriptor, which describes an interface of a device.
[0103] o bLength, bDescriptorType: length and type, 9 bytes, type 4 indicates interface descriptor.
[0104] o bInterfaceNumber, bAlternateSetting: interface number and alternate setting number, both are 0 here.
[0105] o bNumEndpoints: The number of endpoints of the interface, here is 2.
[0106] o bInterfaceClass, bInterfaceSubClass, bInterfaceProtocol: interface class, subclass, and protocol, here 8 (mass storage device), 6 (SCSI), 80 (Bulk-Only).
[0107] o iInterface: Interface index, pointing to the string descriptor of the interface.
[0108] 6.Endpoint Descriptor: Endpoint descriptor, which describes the endpoint of the interface.
[0109] o bLength, bDescriptorType: length and type, 7 bytes, type 5 indicates endpoint descriptor.
[0110] o bEndpointAddress: endpoint address, 0x81 and 0x02 represent input and output endpoints respectively.
[0111] o bmAttributes: endpoint attributes, including transfer type, synchronization type, and usage type.
[0112] o wMaxPacketSize: Maximum packet size, here is 512 bytes.
[0113] o bInterval: interval, used to control the frequency of transmission.
[0114] 7.Device Qualifier: Device qualifier provides device information at different USB speeds.
[0115] o bLength, bDescriptorType: length and type, 10 bytes, type 6 indicates device qualifier.
[0116] o bcdUSB: Same as the device descriptor, indicating the version of the USB specification.
[0117] o bDeviceClass, bDeviceSubClass, bDeviceProtocol: Class, subclass, and protocol, same as the device descriptor.
[0118] o bMaxPacketSize0: Same as the device descriptor, indicating the default maximum packet size.
[0119] o bNumConfigurations: The number of configurations, the same as the device descriptor.
[0120] Correspondingly, when the high-speed bus is a bus of a protocol such as PCIe, the target descriptor only needs to be adaptively adjusted according to the protocol such as PCIe, and this specification does not list them all here.
[0121] In one embodiment, a feasible processing process is provided when a security request includes a read request. Specifically, refer to Figure 3 , the first processor 10 also includes a target controller driver 102;
[0122] The security request includes a write request, and the write request also carries data to be written;
[0123] The first driver 103 is specifically used to, in response to the write request, send the write request to the target device controller 110 through the target host controller 101 through the target controller driver 102 according to the device identification information;
[0124] The target device controller 110 is specifically configured to, in response to the write request, store the data to be written into a cache queue and send a first interrupt to the second driver 111;
[0125] The second driver 111 is specifically configured to, in response to the first interrupt, obtain the data to be written from the cache queue, and write the data to be written into the password module 112 .
[0126] The write request may be initiated by software running on the first processor 10, or may be initiated by a remote host and transmitted to the first processor 10. For example, in an application scenario, the software running on the first processor 10 initiates measurement of the kernel image, etc., obtains the measured measurement value as the data to be written, and sends a write request to the first driver 103. The first driver 103 sends the write request carrying the measurement value to the target controller driver 102, and the target controller driver 102 instructs the target host controller 101 to send the write request carrying the measurement value through the high-speed bus;
[0127] After receiving the write request from the high-speed bus, the target device controller 110 stores the measurement value in the cache queue and sends a first interrupt to the second driver 111. The second driver 111 responds to the first interrupt, obtains the measurement value (i.e., the data to be written) from the cache queue, and writes the measurement value into the cryptographic module 112. In some embodiments, the measurement value written into the cryptographic module 112 may be a ciphertext encrypted by the private key of the cryptographic module 112.
[0128] In some embodiments, reference Figure 4 , the system on chip may further include a second processor 12, wherein the second processor 12 includes a secure element (Secure Element, SE) subsystem and a storage module corresponding to the secure element subsystem;
[0129] The second driver 111 is further configured to, in response to the first interrupt, write the data to be written into a storage module corresponding to the secure element subsystem.
[0130] In this embodiment, a security element subsystem is also provided in the system on chip to cooperate with the trusted security module 11 to provide security services. In addition, the security element subsystem can provide a secure execution environment to ensure the safe storage and processing of sensitive data. In a system on chip with a security element subsystem, the second driver 111 can also write the data to be written into the storage module corresponding to the security element subsystem to achieve a safe backup of the data to be written. The storage module corresponding to the security element subsystem includes but is not limited to SRAM (Static Random-Access Memory).
[0131] In one embodiment, a feasible method for obtaining the data to be written from the cache queue is provided. Specifically, the second driver 111 obtains the data to be written from the cache queue for:
[0132] The second driver 111 reads the first target register of the target device controller 110 to obtain the data to be written.
[0133] The first target register includes but is not limited to 0x180 to 0x187 registers. In the target device controller 110, the first target register can be used to form the cache queue. The register has the characteristics of low latency and instant access. In this embodiment, the data to be written is transmitted between the second driver 111 and the target device controller 110 through the register, which is conducive to improving the data transmission efficiency. After the data is received, the interrupt can be cleared by writing the third target register (for example, the 0x1BC register).
[0134] The above mainly involves the feasible process of the target device controller 110 processing the interruption of notifying the reception of data issued by the control endpoint. For this type of interruption issued by the non-control endpoint, the actual data packet can be obtained through the DMA (Direct Memory Access) module.
[0135] For a read request, in one embodiment, refer to Figure 5 , the security request includes a read request;
[0136] The first driver 103 is specifically used to, in response to the read request, send the read request to the target device controller 110 through the target host controller 101 through the target controller driver 102 according to the device identification information;
[0137] The target device controller 110 is specifically configured to, in response to the read request, send a second interrupt to the second driver 111, and when receiving the to-be-sent data returned by the second driver 111, send the to-be-sent data to the target host controller 101 through the high-speed bus, so as to instruct the target host controller 101 to return the to-be-sent data to the requester of the read request;
[0138] The second driver 111 is specifically used for, in response to the second interrupt, reading the data to be sent from the target location and returning the data to be sent to the target device controller 110 ; the target location includes the password module 112 .
[0139] The read request may be initiated by software running on the first processor 10, or may be initiated by a remote host and sent to the first processor 10. For example, in an application scenario, the remote host sends a read request to the first processor 10 to obtain a measurement value. After the first processor 10 receives the read request, the first driver 103 matches the second driver 111 according to the device identification information, and sends the read request to the target controller driver 102. The target controller driver 102 sends the read request through the high-speed bus through the target host controller 101. After receiving the read request transmitted by the high-speed bus, the target device controller 110 issues a second interrupt to notify the second driver 111. After the second driver 111 obtains the measurement value from the target location, it returns it to the target device controller 110. The target device controller 110 returns the measurement value to the target host controller 101 through the high-speed bus. The target host controller 101 returns the measurement value to the remote host through the target controller driver 102 and the first driver 103.
[0140] refer to Figure 6 In some embodiments, the system on chip may further include a second processor 12, which includes a security element subsystem and a storage module corresponding to the security element subsystem; in this case, the target location includes at least one of the cryptographic module 112 and the storage module corresponding to the security element subsystem. In this embodiment, the storage module corresponding to the security element subsystem may also be used to store data related to security services, which may be obtained from the cryptographic module 112 and / or the storage module corresponding to the security element subsystem in response to a read request.
[0141] In an optional implementation, a feasible process is provided in which the second driver 111 returns the to-be-sent data to the target device controller 110, specifically including:
[0142] The second driver 111 writes the data to be sent into the first target register of the target device controller 110 and writes into the second target register of the target device controller 110 to instruct the target device controller 110 to send out the data to be sent written in the first target register.
[0143] Optionally, for the request sent by the first processor 10, the data to be sent can be written into the first target register (for example, registers 0x180 to 0x187). After the second driver 111 writes the data to be sent into the first target register, it can notify the target device controller 110 to send the data to be sent by writing the second target register (for example, register 0x424) of the target device controller 110.
[0144] The above mainly involves the feasible process of the target device controller 110 processing the interruption issued by the control endpoint to notify the sending of data. For this type of interruption issued by the non-control endpoint, the data to be sent can be placed in the fourth target register (for example, the 0x420 register), and then the second target register is written to send the data to be sent through the target device controller 110.
[0145] Optionally, in one embodiment, the trusted security module 11 includes at least one of a trusted cryptography module 112 (TCM), a trusted platform module (TPM) and a trusted platform control module (TPCM). When the trusted security module 11 includes at least two of the TCM, TPM and TPCM, that is, when the number of the trusted security modules 11 is multiple, the number of the second drivers 111 can also be multiple, and the multiple second drivers 111 correspond to the multiple trusted security modules 11 respectively, and each second driver 111 matches the first driver 103 through a target descriptor.
[0146] Exemplary Methods
[0147] The embodiments of this specification also provide a method for providing a security service, which is applied to Figure 1 to Figure 6 The system on chip shown in the figure comprises: a first processor 10 and a trusted security module 11; the first processor 10 comprises a first driver 103 and a target host controller 101; the trusted security module 11 comprises a target device controller 110, a second driver 111 and a cryptographic module 112, the target host controller 101 and the target device controller 110 are connected via a high-speed bus, and the data transmission rate of the high-speed bus is higher than a set threshold; wherein the second driver 111 comprises a target descriptor, and the target descriptor comprises device identification information; the device identification information is used to match the first driver 103; Figure 7 As shown, the method for providing the security service includes:
[0148] S701: In response to a security request for the cryptographic module 112 through the first driver 103, the security request is sent to the target device controller 110 through the target host controller 101 according to the device identification information carried in the security request;
[0149] S702: In response to the security request, the target device controller 110 calls the cryptographic module 112 through the second driver 111 to provide security services.
[0150] Optionally, in some embodiments, the first processor further comprises a target controller driver;
[0151] The security request includes a write request, and the write request also carries data to be written;
[0152] The step of responding to the security request for the cryptographic module through the first driver and sending the security request to the target device controller through the target host controller according to the device identification information carried in the security request includes:
[0153] In response to the write request through the first driver, according to the device identification information, the write request is sent to the target device controller through the target host controller through the target controller driver;
[0154] The step of, in response to the security request, calling the cryptographic module through the second driver to provide security services through the target device controller includes:
[0155] Through the target device controller, in response to the write request, the data to be written is stored in a cache queue, a first interrupt is sent to the second driver, and through the second driver, in response to the first interrupt, the data to be written is obtained from the cache queue and written into the password module.
[0156] Optionally, in some implementations, obtaining the to-be-written data from the cache queue includes:
[0157] A first target register of the target device controller is read to obtain the data to be written.
[0158] Optionally, in some embodiments, the system on chip further includes: a second processor, the second processor including a secure element subsystem and a storage module corresponding to the secure element subsystem;
[0159] The method for providing the security service also includes:
[0160] In response to the first interrupt, the second driver program writes the data to be written into a storage module corresponding to the secure element subsystem.
[0161] Optionally, in some embodiments, the first processor further comprises a target controller driver;
[0162] The security request includes a read request;
[0163] The step of responding to the security request for the cryptographic module through the first driver and sending the security request to the target device controller through the target host controller according to the device identification information carried in the security request includes:
[0164] In response to the read request through the first driver, according to the device identification information, the read request is sent to the target device controller through the target host controller through the target controller driver;
[0165] The step of, in response to the security request, calling the cryptographic module through the second driver to provide security services through the target device controller includes:
[0166] In response to the read request, the target device controller sends a second interrupt to the second driver, and when receiving the data to be sent returned by the second driver, it is sent to the target host controller through the high-speed bus to instruct the target host controller to return the data to be sent to the requester of the read request; in response to the second interrupt, the second driver reads the data to be sent from the target location and returns the data to be sent to the target device controller; the target location includes the password module.
[0167] Optionally, in some implementations, returning the to-be-sent data to the target device controller includes:
[0168] The data to be sent is written into a first target register of the target device controller, and a second target register of the target device controller is written to instruct the target device controller to send out the data to be sent written in the first target register.
[0169] Optionally, in some embodiments, the high-speed bus includes at least one of a USB bus and a PCIe bus.
[0170] Optionally, in some implementations, the trusted security module includes at least one of a trusted cryptographic module TCM, a trusted platform module TPM, and a trusted platform control module TPCM.
[0171] For the specific limitations on the method of providing security services, please refer to the relevant limitations above, and this manual will not go into details here.
[0172] Exemplary Computing Devices
[0173] Another embodiment of the present application further provides a computing device, see Figure 8As shown, an exemplary embodiment of the present specification also provides a computing device, including: a memory and a processor, the memory storing a computer program, and the processor executing the computer program when executing the computer program performs the steps of the method for providing security services according to various embodiments of the present specification described in the above embodiments of the present specification.
[0174] The internal structure of the computing device can be as follows Figure 8 As shown, the computing device includes a processor, a memory, a network interface and an input device connected through a system bus. Among them, the processor of the computing device is used to provide computing and control capabilities. The memory of the computing device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The network interface of the computing device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, the steps of the method for providing security services according to various embodiments of the present specification described in the above embodiments of the present specification are performed.
[0175] The processor may include a main processor and may also include a baseband chip, a modem, etc.
[0176] The memory stores a program for executing the technical solution of the present invention, and may also store an operating system and other key services. Specifically, the program may include a program code, and the program code includes computer operation instructions. More specifically, the memory may include a read-only memory (ROM), other types of static storage devices that can store static information and instructions, a random access memory (RAM), other types of dynamic storage devices that can store information and instructions, a disk storage, a flash, and the like.
[0177] The processor may be a general-purpose processor, such as a general-purpose central processing unit (CPU), a microprocessor, etc., or an application-specific integrated circuit (ASIC), or one or more integrated circuits for controlling the execution of the program of the scheme of the present invention. It may also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic device, a discrete gate or transistor logic device, or a discrete hardware component.
[0178] The input device may include a device for receiving data and information input by a user, such as a keyboard, a mouse, a camera, a scanner, a light pen, a voice input device, a touch screen, a pedometer, or a gravity sensor.
[0179] Output devices may include means that allow information to be output to a user, such as display screens, printers, speakers, etc.
[0180] The communication interface may include using any transceiver or the like to communicate with other devices or communication networks, such as Ethernet, Radio Access Network (RAN), Wireless Local Area Network (WLAN), etc.
[0181] The processor executes the program stored in the memory and calls other devices, which can be used to implement each step of the method for providing any security service provided in the above embodiments of the present application.
[0182] The computing device may also include a display component and a voice component. The display component may be a liquid crystal display or an electronic ink display. The input device of the computing device may be a touch layer covered on the display component, or a button, trackball or touchpad provided on the housing of the computing device, or an external keyboard, touchpad or mouse.
[0183] Those skilled in the art will understand that Figure 8 The structure shown in the figure is only a block diagram of a part of the structure related to the scheme of this specification, and does not constitute a limitation on the computing device to which the scheme of this specification is applied. The specific computing device may include more or fewer components than shown in the figure, or combine certain components, or have a different arrangement of components.
[0184] Exemplary computer program products and storage media
[0185] In addition to the above-mentioned methods and devices, the method for providing security services provided in the embodiments of this specification may also be a computer program product, which includes computer program instructions, which, when executed by a processor, enable the processor to execute the steps of the method for providing security services according to various embodiments of this specification described in the above "Exemplary Method" section of this specification.
[0186] The computer program product may be written in any combination of one or more programming languages to write program code for performing the operations of the embodiments of the present specification, including object-oriented programming languages such as Java, C++, etc., and conventional procedural programming languages such as "C" or similar programming languages. The program code may be executed entirely on the user computing device, partially on the user device, as a separate software package, partially on the user computing device and partially on a remote computing device, or entirely on a remote computing device or server.
[0187] In addition, an embodiment of the present specification also provides a computer-readable storage medium on which a computer program is stored, and the computer program is executed by a processor to execute the steps of the method for providing security services according to various embodiments of the present specification described in the above "Exemplary Method" section of the present specification.
[0188] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, storage, database or other media used in the embodiments provided in this specification can include non-volatile and / or volatile memory. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM) or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. As an illustration and not limitation, RAM is available in many forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link (Synchlink) DRAM (SLDRAM), memory bus (Rambus) direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM).
[0189] The technical features of the above embodiments may be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0190] The above-mentioned embodiments only express several implementation methods of this specification, and the descriptions are relatively specific and detailed, but they cannot be understood as limiting the scope of the solutions provided by the embodiments of this specification. It should be pointed out that for ordinary technicians in this field, several modifications and improvements can be made without departing from the concept of this specification, which all belong to the protection scope of this specification. Therefore, the protection scope of the patent of this specification shall be based on the attached claims.
Claims
1. A system on chip, characterized in that: include: a first processor and a trusted security module; The first processor includes a first driver and a target host controller; The trusted security module includes a target device controller, a second driver and a password module, the target host controller and the target device controller are connected via a high-speed bus, and the data transmission rate of the high-speed bus is higher than a set threshold; wherein, The second driver includes a target descriptor, and the target descriptor includes device identification information; the device identification information is used to match the first driver; The first driver is used to respond to a security request for the cryptographic module and send the security request to the target device controller through the target host controller according to the device identification information carried in the security request; The target device controller is used to respond to the security request and call the password module through the second driver to provide security services.
2. The system on chip according to claim 1, characterized in that: The first processor also includes a target controller driver; The security request includes a write request, and the write request also carries data to be written; The first driver is specifically configured to, in response to the write request, drive the target controller to send the write request to the target device controller through the target host controller according to the device identification information; The target device controller is specifically configured to, in response to the write request, store the data to be written into a cache queue and send a first interrupt to the second driver; The second driver is specifically configured to, in response to the first interrupt, obtain the data to be written from the cache queue and write the data to be written into the password module.
3. The system on chip according to claim 2, characterized in that: The second driver program obtains the to-be-written data from the cache queue specifically for: The second driver program reads a first target register of the target device controller to obtain the data to be written.
4. The system on chip according to claim 2, characterized in that: Also includes: a second processor, the second processor comprising a security element subsystem and a storage module corresponding to the security element subsystem; The second driver is further configured to, in response to the first interrupt, write the data to be written into a storage module corresponding to the secure element subsystem.
5. The system on chip according to claim 1, characterized in that: The first processor also includes a target controller driver; The security request includes a read request; The first driver is specifically configured to, in response to the read request, drive the target controller to send the read request to the target device controller through the target host controller according to the device identification information; The target device controller is specifically used to, in response to the read request, send a second interrupt to the second driver, and when receiving the to-be-sent data returned by the second driver, send the to-be-sent data to the target host controller through the high-speed bus to instruct the target host controller to return the to-be-sent data to the requester of the read request; The second driver is specifically used to, in response to the second interrupt, read the data to be sent from the target location and return the data to be sent to the target device controller; the target location includes the password module.
6. The system on chip according to claim 5, characterized in that: The second driver program returns the to-be-sent data to the target device controller specifically for: The second driver program writes the data to be sent into the first target register of the target device controller and writes into the second target register of the target device controller to instruct the target device controller to send out the data to be sent written in the first target register.
7. The system on chip according to any one of claims 1 to 6, characterized in that: The high-speed bus includes at least one of a USB bus and a PCIe bus.
8. The system on chip according to any one of claims 1 to 6, characterized in that: The trusted security module includes at least one of a trusted cryptographic module TCM, a trusted platform module TPM, and a trusted platform control module TPCM.
9. A method for providing a security service, characterized in that: The invention is applied to a system on chip, the system on chip comprises: a first processor and a trusted security module; the first processor comprises a first driver and a target host controller; the trusted security module comprises a target device controller, a second driver and a password module; the target host controller and the target device controller are connected via a high-speed bus, and the data transmission rate of the high-speed bus is higher than a set threshold; wherein the second driver comprises a target descriptor, and the target descriptor comprises device identification information; the device identification information is used to match the first driver; the method for providing security services comprises: In response to the security request for the cryptographic module through the first driver, the security request is sent to the target device controller through the target host controller according to the device identification information carried in the security request; The target device controller responds to the security request and the second driver program calls the cryptographic module to provide security services.
10. A computing device, characterized in that: The invention comprises a memory, a processor and a computer program stored in the memory and executable on the processor, wherein the method for providing security services as claimed in claim 9 is implemented when the processor executes the computer program.
11. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method for providing a security service according to claim 9 is implemented.