Chip functional security vulnerability detection method and system
By performing multi-dimensional energy consumption analysis and functional verification in the chip, combined with FFT and Z-Score algorithms, dynamic monitoring of task integrity is solved, and the problems of insufficient detection accuracy and imperfect repair mechanism in the existing technology are achieved, high-precision vulnerability detection and intelligent repair are enhanced, and the security and stability of the chip are enhanced.
Patent Information
- Application Number
- CN202510042945.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-10
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2045-01-10
AI Technical Summary
The existing chip functional security detection methods have insufficient side channel leakage detection accuracy, limited dynamic task integrity verification capabilities, and incomplete vulnerability repair mechanisms, making it difficult to achieve multi-dimensional collaborative detection and intelligent repair of energy consumption analysis and functional verification.
By conducting chip data acquisition and preliminary waveform analysis, energy consumption characteristic analysis and initially identify vulnerabilities, verify functionality and task integrity, combine fast Fourier transform (FFT) and Z-Score anomaly detection algorithm, extract frequency domain features and calculate leakage risk values, dynamically monitor the hash value and memory access of the task code, build comprehensive anomaly detection indicators, and promptly repair vulnerabilities.
It significantly improves the accuracy and real-time nature of vulnerability detection, realizes multi-dimensional vulnerability detection and intelligent repair, and enhances the functional security and stability of the chip.
Smart Images

Figure CN119989359A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of chip security vulnerability detection, and in particular to a chip functional security vulnerability detection method and system. Background Art
[0002] With the widespread application of embedded devices, IoT terminals and smart hardware, the functionality and security of chips in scenarios such as data encryption, identity authentication, and task execution have become the focus of research. Modern chips usually integrate complex security function modules, such as encryption engines, secure boot circuits, and performance monitoring units (PMUs) to deal with external attack threats and internal functional abnormalities. In addition, side channel attacks, as a non-invasive attack method, have become one of the main means of threatening chip security by obtaining sensitive information through methods such as energy consumption analysis. At the same time, the functionality and integrity of chip tasks are also faced with problems such as code tampering and unauthorized memory access. Therefore, in order to ensure the security and stability of chips, studying how to comprehensively detect functional security vulnerabilities in chips, identify risks in a timely manner, and repair them has become an important development direction in the current field of chip security technology.
[0003] Existing chip security detection technologies mainly focus on single-dimensional vulnerability analysis, such as side channel analysis based on energy consumption characteristics or functional verification based on task integrity. However, these technologies have significant limitations in practical applications. First, detection methods for side channel attacks are mostly limited to single analysis in the frequency domain or time domain, lacking effective feature extraction and risk quantification mechanisms, making it difficult to fully capture energy leakage risks. Secondly, functional verification technology is usually based on hash comparison or static instruction flow analysis of task codes, and cannot dynamically monitor the real-time execution process of tasks, especially in complex task switching and multi-threaded scenarios, which can easily lead to omissions or misjudgments. In addition, existing technologies generally lack systematic vulnerability classification and repair mechanisms. Faced with different types of vulnerabilities, such as side channel leaks and memory unauthorized access, it is difficult to take targeted repair strategies in a timely manner. Summary of the invention
[0004] In view of the above-mentioned problems, the present invention is proposed.
[0005] Therefore, the technical problem solved by the present invention is: the existing chip functional safety detection methods have insufficient side channel leakage detection accuracy, limited dynamic task integrity verification capabilities, imperfect vulnerability repair mechanisms, and how to achieve multi-dimensional collaborative detection and intelligent repair mechanisms for energy consumption analysis and functional verification.
[0006] To solve the above technical problems, the present invention provides the following technical solutions: A chip functional security vulnerability detection method, comprising collecting chip data and performing preliminary waveform analysis on the collected data. Performing energy consumption feature analysis and preliminarily identifying vulnerabilities, verifying functionality and task integrity. Performing vulnerability analysis and making processing decisions.
[0007] As a preferred solution of the chip functional security vulnerability detection method of the present invention, wherein: the chip data acquisition includes initializing the detection environment, connecting the oscilloscope and the power analyzer, and setting the sampling frequency and sampling period; Activate the chip's encryption engine and digital signature module, start executing tasks, and record energy consumption data in real time; A low-pass filter is used to denoise the collected signal and filter out high-frequency noise.
[0008] As a preferred solution of the chip functional security vulnerability detection method described in the present invention, the energy consumption characteristic analysis and preliminary vulnerability identification include using fast Fourier transform FFT to extract the frequency domain characteristics of the energy waveform, analyzing the periodic changes in the calculation stage, setting the peak amplitude threshold, and in the dynamic stage of the calculation task, if a peak with an amplitude exceeding a preset value appears in the energy waveform, it is marked as a potential vulnerability, and an abnormal detection algorithm based on Z-Score is used to determine whether the energy fluctuation exceeds the normal range. If the Z-Score exceeds the set value, it is determined to be an abnormal fluctuation; The extracted features are compared with the normal energy consumption feature database, which includes the standard energy consumption mode of computing tasks. If the current waveform differs from the normal mode in the database by more than a preset value, it is marked as a potential vulnerability. The frequency domain energy component extracted by FFT is combined to calculate the quantized value of the leakage feature, which is expressed as:
[0009] in, represents the frequency domain leakage risk value, is the frequency domain component extracted by FFT, is an orthogonal polynomial filter function, is the frequency weighting function, which mainly weights high frequency signals. is the target frequency range, is the frequency cutoff point, take the chip main frequency When the value exceeds the preset value, it is identified as a leak.
[0010] As a preferred solution of the chip functional security vulnerability detection method described in the present invention, the verification of functionality and task integrity includes obtaining the hash value of the currently executed task code and comparing it with the pre-stored reference hash value. When the hash value does not match, it indicates that the task code may have been tampered with and vulnerability analysis needs to be triggered.
[0011] After each task stage is completed, the hash value is checked and the instruction execution flow is captured using the chip performance monitoring unit PMU to ensure that the instruction sequence is executed as planned. If skipping or reentry of illegal instructions is detected, it is marked as an exception. When it is marked as an exception, the energy fluctuation characteristics and real-time instruction flow characteristics are combined to construct a comprehensive anomaly detection index, which is expressed as:
[0012] in, represents the comprehensive anomaly detection score, For the period The temporal anomaly ZScore, is the execution time, Indicates time period The deviation of the execution time from the reference time, is the normal instruction running time, For the period The number of instruction jumps or exception executions, is the total number of time periods.
[0013] As a preferred solution of the chip functional security vulnerability detection method of the present invention, the verification of functionality and task integrity also includes calculating the task integrity score by hash verification of the task code and monitoring of memory access, which is expressed as:
[0014] in, represents the task completeness score, Code snippet for the task The hash value of is the reference hash value, is a hash matching function, if , then the value is 1, otherwise it is 0. Represents a code snippet The amount of memory access, is the threshold of normal memory access, is the total number of task code segments.
[0015] As a preferred solution of the chip functional security vulnerability detection method of the present invention, wherein: the vulnerability analysis includes: The functional verification results are used to confirm whether the chip can perform all tasks normally. If there are functional anomalies, they are marked as functional vulnerabilities, and there are problems with task code integrity or memory access control.
[0016] As a preferred solution of the chip functional security vulnerability detection method described in the present invention, the processing decision includes triggering a repair strategy when a vulnerability is detected, setting the chip's security pin to a high level, triggering a repair operation, downloading the repair code from a backup storage area or through a secure server, and reloading it into the chip.
[0017] After the repair is completed, the chip is powered off and restarted, and the task code and function verification are performed again. After the retest is qualified, the chip's safety pin is restored to a low level and the chip's safety boot circuit is forced to be enabled.
[0018] Another object of the present invention is to provide a chip functional security vulnerability detection system, which can solve the technical problem that the current chip security detection technology lacks comprehensiveness and pertinence through a multi-dimensional collaborative detection method of comprehensive energy consumption analysis and functional verification, and can efficiently identify side channel leakage risks, dynamically verify task integrity, and repair vulnerabilities in a timely manner, overcoming the shortcomings of traditional detection technology in terms of insufficient detection accuracy, poor real-time performance, and lack of repair mechanism.
[0019] As a preferred solution of the chip functional security vulnerability detection system described in the present invention, it includes: a data acquisition module, a vulnerability detection module, and a decision module. The data acquisition module is used to collect chip data and perform preliminary waveform analysis on the collected data. The vulnerability detection module is used to analyze energy consumption characteristics and preliminarily identify vulnerabilities, verify functionality and task integrity. The decision module is used to analyze vulnerabilities and make processing decisions.
[0020] A computer device includes a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement a method for detecting functional security vulnerabilities in a chip.
[0021] A computer-readable storage medium stores a computer program, which, when executed by a processor, implements the steps of a chip functional security vulnerability detection method.
[0022] Beneficial effects of the present invention: The chip functional security vulnerability detection method provided by the present invention combines energy consumption feature analysis with functional verification to provide a multi-dimensional vulnerability detection method that can cover two types of problems: side channel attacks and functional vulnerabilities. Through the optimization of orthogonal polynomial filters and anomaly detection algorithms, the accuracy of vulnerability detection is significantly improved; through the intelligent repair mechanism, dynamic repair of vulnerabilities and secure startup enhancement are achieved. The present invention achieves better results in detection coverage, real-time performance, and repair efficiency. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other accompanying drawings can be obtained based on these accompanying drawings without paying creative work.
[0024] Figure 1 An overall flow chart of a chip functional security vulnerability detection method provided for the first embodiment of the present invention. DETAILED DESCRIPTION
[0025] In order to make the above-mentioned purposes, features and advantages of the present invention more obvious and easy to understand, the specific implementation methods of the present invention are described in detail below in conjunction with the drawings of the specification. Obviously, the described embodiments are part of the embodiments of the present invention, but not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary persons in the art without creative work should fall within the scope of protection of the present invention.
[0026] Example 1, reference Figure 1 , as an embodiment of the present invention, provides a chip functional security vulnerability detection method, comprising: S1: Collect chip data and perform preliminary waveform analysis on the collected data.
[0027] Furthermore, chip data collection includes initializing the detection environment, connecting the oscilloscope and power analyzer, setting the sampling frequency to 1MHz and the sampling period to 1µs. This frequency is chosen to capture the rapidly changing energy consumption in the chip computing task, and the 1MHz frequency can cover the small fluctuations in the high-frequency computing process.
[0028] Activate the chip's encryption engine and digital signature module, start executing tasks, and record energy consumption data in real time.
[0029] When the energy consumption is less than 2mW, the chip is identified as being in standby or idle state. This value is set according to chip design and process differences. Usually, when idle, the energy consumption of low-power chips is less than 2mW.
[0030] When the energy consumption fluctuation exceeds 5mW and lasts for more than 50ms, the identification chip is in working state and is determined to be in the dynamic stage.
[0031] A low-pass filter with a cutoff frequency of 500kHz is used to denoise the collected signal and filter out high-frequency noise. The frequency of 500kHz is based on the frequency range of most computing tasks and can effectively remove noise caused by environmental interference.
[0032] S2: Perform energy consumption signature analysis and preliminarily identify vulnerabilities to verify functionality and mission integrity.
[0033] Furthermore, energy consumption characteristic analysis and preliminary vulnerability identification include using fast Fourier transform (FFT) to extract frequency domain characteristics of the energy waveform, analyzing periodic changes in the calculation phase, setting a peak amplitude threshold, and marking it as a potential vulnerability in the dynamic phase of the calculation task if a peak with an amplitude exceeding 3mW appears in the energy waveform. An anomaly detection algorithm based on Z-Score is used to determine whether the energy fluctuation exceeds the normal range. If the Z-Score exceeds the set value of 3, it is determined to be an abnormal fluctuation.
[0034] The extracted features are compared with the normal energy consumption feature database, which includes the standard energy consumption pattern of computing tasks. If the current waveform differs from the normal pattern in the database by more than 10%, it is marked as a potential vulnerability. The frequency domain energy component extracted by FFT is combined to calculate the quantized value of the leakage feature, which is expressed as:
[0035] in, represents the frequency domain leakage risk value, is the frequency domain component extracted by FFT, is an orthogonal polynomial filter function, is the frequency weighting function, which mainly weights high frequency signals. is the target frequency range, is the frequency cutoff point, take the chip main frequency When the value exceeds the preset value, it is identified as a leak.
[0036] Z-Score is a standardized statistical tool used to quantify the degree of fluctuation. The present invention introduces this method to judge energy fluctuations and can quickly identify the range of abnormal fluctuations. During the execution of chip tasks, energy consumption is affected by factors such as task type and environmental fluctuations. Although these fluctuations will lead to some discrete values, most data will be concentrated around the average value. In other words, it conforms to the normal distribution, and a value greater than 3 is 0.3%, which is an extreme value or an outlier.
[0037] It should be noted that verifying functionality and task integrity includes obtaining the hash value of the currently executing task code and comparing it with the pre-stored reference hash value. When the hash values do not match, it means that the task code may have been tampered with and a vulnerability analysis needs to be triggered.
[0038] After each task stage is completed, the hash value is checked and the instruction execution flow is captured using the chip performance monitoring unit PMU to ensure that the instruction sequence is executed as planned. If skipping or reentry of illegal instructions is detected, it is marked as an exception. When it is marked as an exception, the energy fluctuation characteristics and real-time instruction flow characteristics are combined to construct a comprehensive anomaly detection index, which is expressed as:
[0039] in, represents the comprehensive anomaly detection score, For the period The temporal anomaly ZScore, is the execution time, Indicates time period The deviation of the execution time from the reference time, is the normal instruction running time, For the period The number of instruction jumps or exception executions, is the total number of time periods.
[0040] It should also be noted that verifying functionality and task integrity also includes calculating the task integrity score by hash verification of the task code and monitoring memory access, expressed as:
[0041] in, represents the task completeness score, Code snippet for the task The hash value of is the reference hash value, is a hash matching function, if , then the value is 1, otherwise it is 0. Represents a code snippet The amount of memory access, is the threshold of normal memory access, is the total number of task code segments.
[0042] S3: Perform vulnerability analysis and make processing decisions.
[0043] Furthermore, vulnerability analysis includes The functional verification results are used to confirm whether the chip can perform all tasks normally. If there are functional anomalies, they are marked as functional vulnerabilities, and there are problems with task code integrity or memory access control.
[0044] It should be noted that the processing decision includes triggering a repair strategy when a vulnerability is detected, setting the chip's security pin to a high level, triggering a repair operation, downloading the repair code from a backup storage area or through a secure server, and reloading it into the chip.
[0045] After the repair is completed, the chip is powered off and restarted, and the task code and function verification are performed again. After the retest is qualified, the chip's safety pin is restored to a low level and the chip's safety boot circuit is forced to be enabled.
[0046] And classify the vulnerabilities. Side channel leakage vulnerabilities are detected through energy consumption feature analysis, which are usually related to the energy leakage of sensitive information during the calculation process. Energy leakage information leads to key recovery, such as recovering private keys through side channel analysis in the elliptic curve encryption process. High-frequency energy leakage leaks the operation mode of the encryption algorithm. Functional vulnerabilities are related to task code integrity, memory access control or hardware function failure, which are usually manifested in code tampering or unauthorized access to specific memory areas during chip execution. It is mainly manifested in malicious tampering of tasks, such as inserting malicious code, memory access control failure, resulting in the leakage or illegal modification of confidential data, and abnormal chip function, resulting in the inability to execute tasks correctly. Hardware defects are defects related to the operation of the physical hardware or hardware modules of the chip, which may be caused by manufacturing processes, design problems or hardware aging during long-term operation. It is mainly manifested in chip startup failure or abnormal operation. Functional modules fail to work properly. Hardware resources cannot be generated or used in critical operations.
[0047] Example 2, an embodiment of the present invention, provides a chip functional security vulnerability detection method. In order to verify the beneficial effects of the present invention, scientific demonstration is carried out through economic benefit calculation and simulation experiments.
[0048] First, the chip's operating status at different mission stages was simulated, and potential vulnerabilities were identified, analyzed, and repaired. The experiment used an embedded chip with an encryption engine and a digital signature module to evaluate its energy consumption characteristics, mission integrity verification, and the effectiveness of the repair strategy during mission execution. An oscilloscope and power analyzer were used to connect the target chip, with a sampling frequency of 1MHz and a sampling period of 1µs to ensure the accuracy of high-frequency feature acquisition.
[0049] A low-pass filter is configured with a cut-off frequency of 500kHz to eliminate the interference of high-frequency noise on the energy consumption signal.
[0050] Activate the chip's encryption engine and digital signature module to put the chip into normal task execution state, while recording its energy consumption data in real time.
[0051] Table 1 Experimental data comparison table The energy consumption in the static phase remained at 1.7-1.9 mW, which was consistent with the expected level of less than 2 mW, proving that the method can accurately distinguish between the static and dynamic phases.
[0052] The average energy consumption in the dynamic stage exceeds the set threshold (5mW), and the peak amplitude is between 3.5-4.0mW, clearly identifying the potential risk of side channel leakage.
[0053] In the dynamic stage of task execution, the task integrity scores were 0.72, 0.65, and 0.68, respectively, all below the security threshold (0.9), indicating that the task code may have been tampered with or memory access was abnormal.
[0054] After the repair, the scores were all improved to 1.0, proving the effectiveness of the repair strategy and successfully restoring the normal execution of the task.
[0055] Existing methods usually rely only on time-domain energy consumption analysis, which makes it difficult to identify anomalies in high-frequency fluctuations. This method significantly improves the accuracy and sensitivity of vulnerability identification by extracting frequency-domain features through FFT and using the Z-Score anomaly detection algorithm.
[0056] In terms of task integrity verification, the combination of hash value comparison and instruction flow monitoring can dynamically detect task tampering and instruction anomalies, while traditional methods mainly focus on static code analysis and cannot respond to anomalies in real time.
[0057] Embodiment 3, an embodiment of the present invention provides a chip functional security vulnerability detection system, including a data acquisition module, a vulnerability detection module, and a decision module.
[0058] The data acquisition module is used to collect chip data and perform preliminary waveform analysis on the collected data. The vulnerability detection module is used to analyze energy consumption characteristics and preliminarily identify vulnerabilities, verify functionality and task integrity. The decision module is used to analyze vulnerabilities and make processing decisions.
[0059] If the function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium, including several instructions for a computer device (which can be a personal computer, server, or network device, etc.) to perform all or part of the steps of the methods of each embodiment of the present invention. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), disk or optical disk, etc. Various media that can store program codes.
[0060] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as an ordered list of executable instructions for implementing logical functions, and can be embodied in any computer-readable medium for use by an instruction execution system, device or apparatus (such as a computer-based system, a system including a processor, or other system that can fetch instructions from an instruction execution system, device or apparatus and execute instructions), or in conjunction with such instruction execution systems, devices or apparatuses. For the purposes of this specification, "computer-readable medium" can be any device that can contain, store, communicate, propagate or transmit a program for use by an instruction execution system, device or apparatus, or in conjunction with such instruction execution systems, devices or apparatuses.
[0061] More specific examples of computer-readable media (a non-exhaustive list) include the following: an electrical connection with one or more wires (electronic devices), a portable computer disk case (magnetic devices), a random access memory (RAM), a read-only memory (ROM), an erasable and programmable read-only memory (EPROM or flash memory), an optical fiber device, and a portable compact disk read-only memory (CDROM). In addition, the computer-readable medium may even be a paper or other suitable medium on which the program is printed, since the program may be obtained electronically, for example, by optically scanning the paper or other medium, followed by editing, deciphering or, if necessary, processing in another suitable manner, and then stored in a computer memory.
[0062] It should be understood that the various parts of the present invention can be implemented by hardware, software, firmware or a combination thereof. In the above-mentioned embodiments, multiple steps or methods can be implemented by software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented by hardware, as in another embodiment, it can be implemented by any one of the following technologies known in the art or their combination: a discrete logic circuit having a logic gate circuit for implementing a logical function for a data signal, a dedicated integrated circuit having a suitable combination of logic gate circuits, a programmable gate array (PGA), a field programmable gate array (FPGA), etc. It should be noted that the above embodiments are only used to illustrate the technical solution of the present invention and are not limited. Although the present invention is described in detail with reference to the preferred embodiments, it should be understood by those skilled in the art that the technical solution of the present invention can be modified or replaced by equivalents without departing from the spirit and scope of the technical solution of the present invention, which should be included in the scope of the claims of the present invention.
[0063] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solutions of the present invention may be modified or replaced by equivalents without departing from the spirit and scope of the technical solutions of the present invention, which should all be included in the scope of the claims of the present invention.
Claims
1. A chip functional security vulnerability detection method, characterized in that: include: Collect chip data and conduct preliminary waveform analysis on the collected data; Conduct energy consumption signature analysis and preliminary vulnerability identification to verify functionality and mission integrity; Conduct vulnerability analysis and make processing decisions.
2. The chip functional security vulnerability detection method according to claim 1, characterized in that: The chip data acquisition includes initializing the detection environment, connecting the oscilloscope and the power analyzer, and setting the sampling frequency and the sampling period; Activate the chip's encryption engine and digital signature module, start executing tasks, and record energy consumption data in real time; A low-pass filter is used to denoise the collected signal and filter out high-frequency noise.
3. The chip functional security vulnerability detection method according to claim 2, characterized in that: The energy consumption characteristic analysis and preliminary vulnerability identification include extracting the frequency domain characteristics of the energy waveform using the fast Fourier transform FFT, analyzing the periodic changes in the calculation stage, setting the peak amplitude threshold, and in the dynamic stage of the calculation task, if a peak with an amplitude exceeding a preset value appears in the energy waveform, it is marked as a potential vulnerability, and the anomaly detection algorithm based on the Z-Score is used to determine whether the energy fluctuation exceeds the normal range. If the Z-Score exceeds the set value, it is determined to be an abnormal fluctuation; The extracted features are compared with the normal energy consumption feature database, which includes the standard energy consumption mode of computing tasks. If the current waveform differs from the normal mode in the database by more than a preset value, it is marked as a potential vulnerability. The frequency domain energy component extracted by FFT is combined to calculate the quantized value of the leakage feature, which is expressed as: ; in, represents the frequency domain leakage risk value, is the frequency domain component extracted by FFT, is an orthogonal polynomial filter function, is the frequency weighting function, which mainly weights high frequency signals. is the target frequency range, is the frequency cutoff point, take the chip main frequency When the value exceeds the preset value, it is identified as a leak.
4. The chip functional security vulnerability detection method according to claim 3, characterized in that: The verification of functionality and task integrity includes obtaining the hash value of the currently executed task code and comparing it with the pre-stored reference hash value. When the hash values do not match, it indicates that the task code may have been tampered with and a vulnerability analysis needs to be triggered. After each task stage is completed, the hash value is checked and the instruction execution flow is captured using the chip performance monitoring unit PMU to ensure that the instruction sequence is executed as planned. If skipping or reentry of illegal instructions is detected, it is marked as an exception. When it is marked as an exception, the energy fluctuation characteristics and real-time instruction flow characteristics are combined to construct a comprehensive anomaly detection index, which is expressed as: ; in, represents the comprehensive anomaly detection score, , For the period The temporal anomaly ZScore, is the execution time, Indicates time period The deviation of the execution time from the reference time, is the normal instruction running time, For the period The number of instruction jumps or exception executions, is the total number of time periods.
5. The chip functional security vulnerability detection method according to claim 4, characterized in that: The verification of functionality and task integrity also includes calculating a task integrity score by hash verification of task code and monitoring of memory access, which is expressed as: ; in, represents the task completeness score, Code snippet for the task The hash value of is the reference hash value, is a hash matching function, Represents a code snippet The amount of memory access, is the threshold of normal memory access, is the total number of task code segments.
6. The chip functional security vulnerability detection method according to claim 5, characterized in that: The vulnerability analysis includes: The functional verification results are used to confirm whether the chip can perform all tasks normally. If there are functional anomalies, they are marked as functional vulnerabilities, and there are problems with task code integrity or memory access control.
7. The chip functional security vulnerability detection method according to claim 6, characterized in that: The processing decision includes triggering a repair strategy when a vulnerability is detected, setting the chip's security pin to a high level, triggering a repair operation, downloading a repair code from a backup storage area or through a secure server, and reloading it into the chip; After the repair is completed, the chip is powered off and restarted, and the task code and function verification are performed again. After the retest is qualified, the chip's safety pin is restored to a low level and the chip's safety boot circuit is forced to be enabled.
8. A system using the chip functional security vulnerability detection method according to any one of claims 1 to 7, characterized in that: Including data collection module, vulnerability detection module, and decision-making module; The data acquisition module is used to collect chip data and perform preliminary waveform analysis on the collected data; The vulnerability detection module is used to perform energy consumption feature analysis and preliminarily identify vulnerabilities, verifying functionality and mission integrity; The decision module is used to perform vulnerability analysis and make processing decisions.
9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the chip functional security vulnerability detection method described in any one of claims 1 to 7 are implemented.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the chip functional security vulnerability detection method described in any one of claims 1 to 7 are implemented.
Citation Information
Patent Citations
Vulnerability protection method and device and electronic equipment
CN111027075A
Side channel attack detection method and device, equipment and storage medium
CN116208960A
High-integration semiconductor chip security detection system and method
CN118673538A
Cited By
Method and system for checking and detecting security vulnerabilities of computing power chip
CN121389200A
A method and system for checking and detecting security vulnerabilities of a computing power chip
CN121389200B