JTAG authentication method and device based on vehicle-mounted Ethernet chip and storage medium
By using username and double-layer key authentication methods in vehicle-mounted Ethernet chips, the existing JTAG authentication methods are solved in the application of on-board chips, and the unique authentication and multiple protection of each chip are realized, which significantly improves the security of the chip.
Patent Information
- Application Number
- CN202510036113.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-09
- Publication Date
- 2025-05-16
AI Technical Summary
The existing JTAG authentication methods have security risks in vehicle-mounted chip applications. The key authentication of the same batch of chips is consistent and is easy to be cracked. The public test data registers are not protected and cannot provide security authentication.
Authentication is performed using username and double-layer key. Username, password1 and password2 are input through the JTAG interface, and hardware algorithms are used to verify to ensure that each chip has a unique authentication key, increasing the difficulty of cracking, and locking the JTAG interface through Ethernet broadcast messages when authentication fails.
The unique authentication of each chip is realized, the security of the chip is improved, the same batch of chips are prevented from being cracked, and the security of the system is enhanced through multiple protection mechanisms.
Smart Images

Figure CN120012059A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of automotive Ethernet chips, and in particular to a JTAG authentication method, device and storage medium based on an automotive Ethernet chip. Background Art
[0002] As chip functional design becomes increasingly complex, the JTAG interface is no longer limited to debugging and testing chip functions. More and more applications can access the internal functions of ASIC chips and obtain chip status information, which undoubtedly poses certain risks to chip security, especially for automotive chips. Automotive-grade chips have strict requirements on functional safety and access management. Users who are not formally authorized cannot access or tamper with chip information. Therefore, external interfaces, such as JTAG debugging ports, also need to add corresponding access management mechanisms to ensure chip security. Many current access management methods are relatively simple. After the key is burned, the access authentication of chips in the same batch is the same, which is extremely risky. In addition, the entire application system cannot perceive the attack on the chip, and there is a problem of untimely response.
[0003] In the common JTAG authentication method, for example, the user's key is written into the public test data register (TDR) of the debugging module, and then compared with the key information burned in the chips of the same batch to verify the authority. This method is not very secure and cannot avoid the problem that if any chip in the same batch is cracked, the other chips will be in an unsafe state. In addition, the public TDR is not protected and cannot provide security authentication. Summary of the invention
[0004] In order to solve the above problems of the prior art solutions, the present invention sets a user name and a double-layer key to ensure that chips in the same batch are authenticated in a one-chip-one-password manner to solve the above technical problems.
[0005] In order to achieve the above object, the present invention adopts the following technical solution: a JTAG authentication method based on an in-vehicle Ethernet chip, comprising the following steps:
[0006] S1, configure chip id as the unique identifier of each Ethernet chip, and the keys used for authentication: auth_key0, auth_key1 and auth_key2;
[0007] S2, if the JTAG interface receives a debugging request or a request to access the inside of the chip, first enter the user name user_name, then enter password1, and finally enter password2. Password1 and password2 are compared with the expected results calculated by the hardware algorithm. If all verifications are successful, the JTAG access module is enabled, and then debugging or access to the inside of the chip is carried out; if any key verification fails, the access permission is not enabled, and the retry wait is entered. If the retry wait times reaches the upper limit, there is no response to the JTAG input, the hardware logic stops the authentication process, and closes the access channel.
[0008] Furthermore, in S2, if the number of retry waits reaches the upper limit, the status information of the JTAG authentication failure is sent to the trusted port in the format of a message based on the function of the Ethernet chip. The trusted port parses the message and handles this malicious access attack, stopping the access rights of the JTAG physical interface.
[0009] Further, in S2, the hardware algorithm includes:
[0010] The algorithm calculates logic 1, and calculates an exp_password1 according to the algorithm using the user_name input by JTAG, the chip_id of the Ethernet chip, and auth_key0;
[0011] Verify logic 1, compare exp_password1 obtained by algorithm logic 1 with password1 input by JTAG. If the comparison result is consistent, the output is high level: authenticated_en1;
[0012] The key selection logic selects auth_key1 or auth_key2 stored in EFUSE as the key input of algorithm calculation logic 2 according to the result of algorithm calculation logic 1;
[0013] The algorithm calculates logic 2, and calculates the calculated exp_password1 and the key selected by the key selection logic to obtain exp_password2;
[0014] Verify logic 2, compare exp_password2 with password2 input from the JTAG interface, and if the results are consistent, output high level authenticated_en2;
[0015] When authenticated_en1 and authenticated_en2 are both high, the authentication pass is performed, the authenticated_pass result is output, and the debugging module function is enabled.
[0016] Furthermore, when authentication fails, the information reported to the trusted port is organized into an Ethernet message in the form of a payload. The format of the payload includes the maximum number of authentication attempts try_max_num, the user_name1 / password1_1 / password1_2 entered for the first authentication failure, and all authentication failure status information.
[0017] Further, the algorithm calculation logic 1 is specifically as follows: the user_id input by JTAG and the chip_id and auth_key0 read from the efuse are combined into a new information code message m(x), such as m(x) = {user_id, chip_id, auth_key0, password1}. By using the characteristics of the characteristic generating polynomial, there is and only one generating polynomial g(x), so that m(x) = a(x)g(x). The verification logic calculates r(x) = m(x)%g(x). The verification result is represented by judging whether r(x) is 0. If r(x) = = 0, it means that the authentication algorithm 1 verification is successful, and authenticated_en1 is set to 1. Otherwise, the first key verification is unsuccessful, and authenticated_en1 is set to 0.
[0018] At the same time, the algorithm calculation logic 1 obtains the auth_key_sel result after bit XOR calculation based on the result of a(x)=m(x) / g(x). If the calculated auth_key_sel==0, auth_key1 will be selected as the algorithm key for the second key verification. Otherwise, if auth_key_sel==1, auth_key2 will be selected as the auth_second_key required for the second key algorithm calculation.
[0019] Specifically, the algorithm calculation logic 2 takes a(x) calculated by the algorithm calculation logic 1 and the selected auth_second_key as input, combines a(x) and auth_second_key into a new information code, such as m2={a(x), auth_second_key}, and generates a message digest through a hash algorithm for comparison with password2, such as the commonly used hash algorithm h=m2%P, where P is a relatively large prime number, and the calculated h is output to the verification logic 2 for comparison;
[0020] Verification logic 2 is mainly used to determine whether h is the same as the input password2. If they are the same, authenticated_en2 is set to 1. Otherwise, the verification fails and authenticated_en2 is set to 0.
[0021] The present invention also provides a JTAG authentication device based on an in-vehicle Ethernet chip, which is arranged in the Ethernet chip.
[0022] Memory, attached Figure 1 In the embodiment of the present invention, it is EFUSE, which is used to store the enable control signal of the authentication module and the chip_id / auth_key0 / auth_key1 / auth_key2 required by the authentication algorithm;
[0023] The authentication module is connected to the memory, the debugging module and the Ethernet broadcast module signal; it is used to verify whether the input user name and password meet the algorithm rules and complete the user information verification task;
[0024] JTAG interface, used to receive debugging requests or requests to access the inside of the chip; connected to the debugging module signal; the JTAG interface itself is a channel connecting the Ethernet chip with external devices, and external devices can debug the chip and access the internal information of the chip through the JTAG interface;
[0025] The debugging module is connected to the on-chip resource module signal; it is responsible for debugging the Ethernet chip and accessing the on-chip resources. The opening and closing of this module depends on the result of the authentication;
[0026] The Ethernet broadcast module is connected to the external trusted port signal. It is used to broadcast the authentication failure information to the trusted port in the form of a message through Ethernet. The trusted port disables the JTAG physical interface according to the received message to provide safer protection. The trusted port is generally an external device port that has been authenticated as safe by the vehicle-mounted Ethernet chip, which can be a system-level management chip.
[0027] Furthermore, the on-chip resource module includes configuration and status information inside the Ethernet chip.
[0028] Furthermore, the algorithm rules include:
[0029] The algorithm calculates logic 1, and calculates an exp_password1 according to the algorithm using the user_name input by JTAG, the chip_id of the Ethernet chip, and auth_key0;
[0030] Verify logic 1, compare exp_password1 obtained by algorithm logic 1 with password1 input by JTAG. If the comparison result is consistent, the output is high level: authenticated_en1;
[0031] The key selection logic selects auth_key1 or auth_key2 stored in EFUSE as the key input of algorithm calculation logic 2 according to the result of algorithm calculation logic 1;
[0032] The algorithm calculates logic 2, and calculates the calculated exp_password1 and the key selected by the key selection logic to obtain exp_password2;
[0033] Verify logic 2, compare exp_password2 with password2 input from the JTAG interface, and if the results are consistent, output high level authenticated_en2;
[0034] When authenticated_en1 and authenticated_en2 are both high, the authentication pass is performed, the authenticated_pass result is output, and the debugging module function is enabled.
[0035] The specific calculation logic 1 of the algorithm is as follows: the user_id input by JTAG and the chip_id and auth_key0 read from efuse form a new information code message m(x), such as m(x) = {user_id, chip_id, auth_key0, password1}. Using the characteristics of the characteristic generating polynomial, there is and only one generating polynomial g(x) such that m(x) = a(x)g(x). The verification logic calculates r(x) = m(x)%g(x). The verification result is represented by judging whether r(x) is 0. If r(x) = = 0, it means that the authentication algorithm 1 verification is successful, and authenticated_en1 is set to 1. Otherwise, the first key verification is unsuccessful, and authenticated_en1 is set to 0.
[0036] At the same time, the algorithm calculation logic 1 obtains the auth_key_sel result after bit XOR calculation based on the result of a(x)=m(x) / g(x). If the calculated auth_key_sel==0, auth_key1 will be selected as the algorithm key for the second key verification. Otherwise, if auth_key_sel==1, auth_key2 will be selected as the auth_second_key required for the second key algorithm calculation.
[0037] Specifically, the algorithm calculation logic 2 takes a(x) calculated by the algorithm calculation logic 1 and the selected auth_second_key as input, combines a(x) and auth_second_key into a new information code, such as m2={a(x), auth_second_key}, and generates a message digest through a hash algorithm for comparison with password2, such as the commonly used hash algorithm h=m2%P, where P is a relatively large prime number, and the calculated h is output to the verification logic 2 for comparison;
[0038] Verification logic 2 is mainly used to determine whether h is the same as the input password2. If they are the same, authenticated_en2 is set to 1. Otherwise, the verification fails and authenticated_en2 is set to 0.
[0039] The present invention also provides a computer-readable storage medium containing a computer program. When the computer program is executed by one or more processors, any of the above-mentioned JTAG authentication methods based on an in-vehicle Ethernet chip is implemented.
[0040] The present invention has the following advantages: the authentication method and device provided by the present invention ensure that when an external device wants to access the chip, it must be checked in the format of the user name and double passwords, and the access permission will be opened only after the authentication is passed. Different user names and passwords can be provided for the same batch of chip products for access. The user name and password must appear in pairs, otherwise the authentication will fail. In addition, the number of accesses will also be limited. Once the number of mismatches in the user name and password input reaches the upper limit, the authentication module will immediately stop the authentication and lock the JTAG permission access. Finally, the authentication failure information will be sent to the trusted port via Ethernet message. The trusted port can lock the physical access port of JTAG from the system application level, thereby achieving the effect of multiple protections and improving the security of the vehicle-mounted Ethernet chip. BRIEF DESCRIPTION OF THE DRAWINGS
[0041] Figure 1 A schematic diagram of a JTAG authentication device based on an in-vehicle Ethernet chip according to the present invention;
[0042] Figure 2 This is a schematic diagram of the internal structure of the authentication module of the present invention;
[0043] Figure 3 The PAYLOAD format of the Ethernet message of JTAG authentication failure of the present invention;
[0044] Figure 4 It is the Ethernet II message standard format of the present invention;
[0045] Figure 5This is a JTAG debugging flow chart of the chip return of the present invention;
[0046] Figure 6 The present invention is a flowchart of the authentication process for accessing the JTAG interface during operation of the chip. DETAILED DESCRIPTION
[0047] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0048] like Figure 1 As shown, a JTAG authentication method based on an in-vehicle Ethernet chip includes the following steps:
[0049] S1, configure chip id as the unique identifier of each Ethernet chip, and the keys used for authentication: auth_key0, auth_key1 and auth_key2;
[0050] S2, if the JTAG interface receives a debugging request or a request to access the inside of the chip, first enter the user name user_name, then enter password1, and finally enter password2. Password1 and password2 are compared with the expected results calculated by the hardware algorithm. If all verifications are successful, the JTAG access module is enabled, and then debugging or access to the inside of the chip is carried out; if any key verification fails, the access permission is not enabled, and the retry wait is entered. If the retry wait times reaches the upper limit, there is no response to the JTAG input, the hardware logic stops the authentication process, and closes the access channel.
[0051] The chip id of each chip is different. Even if the same username and password are used on all chips of the same batch, all authentication cannot be passed. This ensures that the chip id and the designed username and password are uniquely corresponding. In other words, if an attacker gets a set of usernames and passwords, only one unique chip id can be used, and other chipid chips cannot use this set of usernames and passwords. This achieves the purpose of one chip and one password, and improves security. The purpose of setting two keys (auth_key1 and auth_key2) is to increase the difficulty of cracking. The reason is that the selection of key1 or key2 needs to be based on the result calculated by algorithm 1, such as using the quotient obtained by message and polynomial division to judge. This ensures that each user_name may use key1 or key2, and there is uncertainty. For attackers, there is no way to know the key selection logic, which further improves security.
[0052] In S2, if the number of retry waits reaches the upper limit, the status information of JTAG authentication failure is sent to the trusted port in the format of a message based on the function of the Ethernet chip. The trusted port parses the message, handles this malicious access attack, and stops the access rights of the JTAG physical interface.
[0053] In S2, the hardware algorithm includes:
[0054] The algorithm calculates logic 1, and calculates an exp_password1 according to the algorithm using the user_name input by JTAG, the chip_id of the Ethernet chip, and auth_key0;
[0055] Verify logic 1, compare exp_password1 obtained by algorithm logic 1 with password1 input by JTAG. If the comparison result is consistent, the output is high level: authenticated_en1;
[0056] The key selection logic selects auth_key1 or auth_key2 stored in EFUSE as the key input of algorithm calculation logic 2 according to the result of algorithm calculation logic 1;
[0057] The algorithm calculates logic 2, and calculates the calculated exp_password1 and the key selected by the key selection logic to obtain exp_password2;
[0058] Verify logic 2, compare exp_password2 with password2 input from the JTAG interface, and if the results are consistent, output high level authenticated_en2;
[0059] When authenticated_en1 and authenticated_en2 are both high, the authentication pass is performed, the authenticated_pass result is output, and the debugging module function is enabled.
[0060] When authentication fails, the information reported to the trusted port is organized into the Ethernet message in the form of payload. The format of the payload includes the maximum number of authentication attempts try_max_num, the user_name1 / password1_1 / password1_2 entered for the first authentication failure, and all authentication failure status information.
[0061] The specific calculation logic 1 of the algorithm is as follows: the user_id input by JTAG and the chip_id and auth_key0 read from efuse form a new information code message m(x), such as m(x) = {user_id, chip_id, auth_key0, password1}. Using the characteristics of the characteristic generating polynomial, there is and only one generating polynomial g(x) such that m(x) = a(x)g(x). The verification logic calculates r(x) = m(x)%g(x). The verification result is represented by judging whether r(x) is 0. If r(x) = = 0, it means that the authentication algorithm 1 verification is successful, and authenticated_en1 is set to 1. Otherwise, the first key verification is unsuccessful, and authenticated_en1 is set to 0.
[0062] At the same time, the algorithm calculation logic 1 obtains the auth_key_sel result after bit XOR calculation based on the result of a(x)=m(x) / g(x). If the calculated auth_key_sel==0, auth_key1 will be selected as the algorithm key for the second key verification. Otherwise, if auth_key_sel==1, auth_key2 will be selected as the auth_second_key required for the second key algorithm calculation.
[0063] Specifically, the algorithm calculation logic 2 takes a(x) calculated by the algorithm calculation logic 1 and the selected auth_second_key as input, combines a(x) and auth_second_key into a new information code, such as m2={a(x), auth_second_key}, and generates a message digest through a hash algorithm for comparison with password2, such as the commonly used hash algorithm h=m2%P, where P is a relatively large prime number, and the calculated h is output to the verification logic 2 for comparison;
[0064] Verification logic 2 is mainly used to determine whether h is the same as the input password2. If they are the same, authenticated_en2 is set to 1. Otherwise, the verification fails and authenticated_en2 is set to 0.
[0065] The present invention also provides a JTAG authentication device based on an in-vehicle Ethernet chip, which is arranged in the Ethernet chip.
[0066] Memory, attached Figure 1 In the embodiment of the present invention, it is EFUSE, which is used to store the enable control signal of the authentication module and the chip_id / auth_key0 / auth_key1 / auth_key2 required by the authentication algorithm;
[0067] The authentication module is connected to the memory, the debugging module and the Ethernet broadcast module signal; it is used to verify whether the input user name and password meet the algorithm rules and complete the user information verification task;
[0068] JTAG interface, used to receive debugging requests or requests to access the inside of the chip; connected to the debugging module signal; the JTAG interface itself is a channel connecting the Ethernet chip with external devices, and external devices can debug the chip and access the internal information of the chip through the JTAG interface;
[0069] The debugging module is connected to the on-chip resource module signal; it is responsible for debugging the Ethernet chip and accessing the on-chip resources. The opening and closing of this module depends on the result of the authentication;
[0070] The Ethernet broadcast module is connected to the external trusted port signal. It is used to broadcast the authentication failure information to the trusted port in the form of a message through Ethernet. The trusted port disables the JTAG physical interface according to the received message to provide safer protection. The trusted port is generally an external device port that has been authenticated as safe by the vehicle-mounted Ethernet chip, which can be a system-level management chip.
[0071] On-chip resource module, including configuration and status information inside the Ethernet chip.
[0072] The algorithm rules include:
[0073] The algorithm calculates logic 1, and calculates an exp_password1 according to the algorithm using the user_name input by JTAG, the chip_id of the Ethernet chip, and auth_key0;
[0074] Verify logic 1, compare exp_password1 obtained by algorithm logic 1 with password1 input by JTAG. If the comparison result is consistent, the output is high level: authenticated_en1;
[0075] The key selection logic selects auth_key1 or auth_key2 stored in EFUSE as the key input of algorithm calculation logic 2 according to the result of algorithm calculation logic 1;
[0076] The algorithm calculates logic 2, and calculates the calculated exp_password1 and the key selected by the key selection logic to obtain exp_password2;
[0077] Verify logic 2, compare exp_password2 with password2 input from the JTAG interface, and if the results are consistent, output high level authenticated_en2;
[0078] When authenticated_en1 and authenticated_en2 are both high, the authentication pass is performed, the authenticated_pass result is output, and the debugging module function is enabled.
[0079] The specific calculation logic 1 of the algorithm is as follows: the user_id input by JTAG and the chip_id and auth_key0 read from efuse form a new information code message m(x), such as m(x) = {user_id, chip_id, auth_key0, password1}. Using the characteristics of the characteristic generating polynomial, there is and only one generating polynomial g(x) such that m(x) = a(x)g(x). The verification logic calculates r(x) = m(x)%g(x). The verification result is represented by judging whether r(x) is 0. If r(x) = = 0, it means that the authentication algorithm 1 verification is successful, and authenticated_en1 is set to 1. Otherwise, the first key verification is unsuccessful, and authenticated_en1 is set to 0.
[0080] At the same time, the algorithm calculation logic 1 obtains the auth_key_sel result after bit XOR calculation based on the result of a(x)=m(x) / g(x). If the calculated auth_key_sel==0, auth_key1 will be selected as the algorithm key for the second key verification. Otherwise, if auth_key_sel==1, auth_key2 will be selected as the auth_second_key required for the second key algorithm calculation.
[0081] Specifically, the algorithm calculation logic 2 takes a(x) calculated by the algorithm calculation logic 1 and the selected auth_second_key as input, combines a(x) and auth_second_key into a new information code, such as m2={a(x), auth_second_key}, and generates a message digest through a hash algorithm for comparison with password2, such as the commonly used hash algorithm h=m2%P, where P is a relatively large prime number, and the calculated h is output to the verification logic 2 for comparison;
[0082] Verification logic 2 is mainly used to determine whether h is the same as the input password2. If they are the same, authenticated_en2 is set to 1. Otherwise, the verification fails and authenticated_en2 is set to 0.
[0083] Specific combination of Figure 1-6 It should be noted that JTAG is a common debugging interface widely used in various chips. However, based on the functional safety requirements of automotive Ethernet chips, the access interface exposed to the chip interface will undoubtedly bring security risks. Therefore, the JTAG interface also needs to pass security authentication to provide external access rights. This process is called JTAG authentication. Based on the authentication function and the particularity of Ethernet chips, the present invention designs a JTAG authentication and system processing method and device, which can effectively improve the security of JTAG interface access. Figure 1 The JTAG authentication structure and system processing scheme of the Ethernet chip include EFUSE, which stores the enable control signal of the authentication module and the chip_id / auth_key0 / auth_key1 / auth_key2 required by the authentication algorithm; the authentication module is used to verify whether the input username and password meet the algorithm rules and complete the user information verification task; the debugging module is responsible for chip debugging and access to on-chip resources, and the opening and closing of this module depends on the authentication result; the on-chip resources include the internal configuration and status information of the chip; the JTAG interface itself is the channel connecting the chip with external devices, and the external devices can debug the chip and access the internal information of the chip through the JTAG interface; the Ethernet broadcast function mainly broadcasts the authentication failure information in the form of a message through Ethernet to the trusted port, and the trusted port prohibits the JTAG physical interface according to the received message to provide safer protection; the trusted port is generally an external device port that has been authenticated as safe by the vehicle-mounted Ethernet chip, which can be a system-level management chip.
[0084] Figure 2The specific implementation structure of the authentication module is shown. The algorithm calculation logic 1 calculates an exp_password1 according to the algorithm based on the user_name input by JTAG and the chip_id / auth_key0 burned by the chip EFUSE; the verification logic 1 compares the exp_password1 obtained by the algorithm logic 1 with the password1 input by JTAG. If the results are consistent, it outputs a high level authenticated_en1; the function of the key selection logic is mainly to select auth_key1 or auth_key2 stored in EFUSE as the key input of the algorithm calculation logic 2 according to the result of the algorithm calculation logic 1; the function of the algorithm calculation logic 2 is mainly to calculate an exp_password2 by calculating the calculated exp_password1 and the key selected by the key selection logic; the verification logic 2 compares exp_password2 with the password2 input by the JTAG interface. If the results are consistent, it outputs a high level authenticated_en2; authenticated_en1 and authenticated_en2 are both high levels to indicate authentication pass, and output the authenticated_pass result, and enable the function of the debugging module. On the contrary, if the authentication is not successful at present, the above authentication process will be repeated. Any successful authentication will enable the function of the debugging module. If none of them succeed, it means that the authentication has failed and the debugging module cannot be accessed by JTAG. At the same time, the authentication failure information is broadcast to the trusted port via Ethernet in the form of a message. The trusted port parses the message and takes corresponding measures, such as disabling the physical port of the JTAG interface.
[0085] Figure 3 Provides information reported to the trusted port after an authentication failure, organized into the Ethernet message in the form of a payload. The payload format includes the maximum number of authentication attempts try_max_num, the user_name1 / password1_1 / password1_2 entered for the first authentication failure, and all authentication failure status information.
[0086] Figure 4 A commonly used Ethernet II standard message format is provided, including the preamble and frame start delimiter added by the physical layer, and the MAC DA / MAC SA / TYPE / frame check sequence added by the MAC layer.
[0087] Figure 5A debugging flowchart for disabling the authentication function during the chip return debugging phase is provided. During the chip return debugging phase, the EFUSE configuration is to disable the authentication module, so that the JTAG interface can bypass the authentication logic and interact directly with the debugging module, so that JTAG debugging can be quickly entered.
[0088] Figure 6 The process of starting the authentication module when the vehicle Ethernet chip encounters JTAG access in working mode is shown. In normal working mode, EFUSE burning turns on the enable switch of the authentication module. All JTAG accesses must execute the authentication process and the chip can be accessed only after passing the authentication. When the JTAG interface initiates an access request, first enter the user name user_name, then enter password1, and finally enter password2. The authentication module calculates and determines whether the authentication is successful based on the chip_id, auth_key0, auth_key1 and auth_key2 information burned by EFUSE, as well as the input user_name / password1 / password2. If the authentication is successful, it becomes a trusted user and can access the chip through the JTAG interface. If the authentication fails, it determines whether the number of authentication attempts has reached the maximum value. If not, it is necessary to re-enter the user and key information in sequence and re-enter the authentication process to determine the authentication result. If the number of authentications reaches the maximum value, the authentication failure information will be sent to the trusted port in the form of a message. In order to enable the system level to respond quickly, this abnormal message will be forwarded according to the highest priority message processing. The message is automatically packaged in the above format by the hardware design logic of the chip circuit and broadcast to all ports. Only the trusted port can correctly receive such messages. Any trusted port receives the message to parse and obtain the JTAG authentication status. If it is judged to be under malicious attack, the trusted port has the authority to directly prohibit JTAG physical port access. The advantage of this abnormal reporting method is that it can respond quickly in combination with the characteristics of the Ethernet chip, and reuse the existing transmission channel at the same time, without incurring additional hardware costs. The design is relatively simple, and the chip itself is an automotive Ethernet chip. According to the forwarding configuration of the automotive Ethernet chip, the message information can be forwarded only to the trusted port for processing, further improving the security of the system.
[0089] A possible implementation case of an authentication algorithm proposes two possible verification algorithms based on the function of an authentication module to verify the correctness of an input user name and a key. A first key algorithm combines a user_id input by JTAG and a chip_id and auth_key0 read from efuse into a new information code message m(x), such as m(x)={user_id, chip_id, auth_key0, password1}. By utilizing the characteristics of a characteristic generating polynomial, there exists and only exists one generating polynomial g(x), such that m(x)=a(x)g(x). The verification logic calculates r(x)=m(x)%g(x). The verification result is indicated by judging whether r(x) is 0. If r(x)==0, it indicates that the verification of the authentication algorithm 1 is successful, and authenticated_en1 is set to 1. Otherwise, the first key verification is unsuccessful, and authenticated_en1 is set to 0. At the same time, the algorithm calculation logic 1 obtains the auth_key_sel result after bit XOR calculation based on the result of a(x)=m(x) / g(x). If the calculated auth_key_sel==0, auth_key1 will be selected as the algorithm key for the second key verification. Otherwise, if auth_key_sel==1, auth_key2 will be selected as the auth_second_key required for the second key algorithm calculation.
[0090] The second key algorithm can appropriately reduce the complexity, and take a(x) calculated by the algorithm calculation logic 1 and the selected auth_second_key as input, and combine a(x) and auth_second_key into a new information code, such as m2={a(x), auth_second_key}, and generate a message digest through a hash algorithm, which is used to compare with password2, such as the commonly used hash algorithm h=m2%P, P is a large prime number, and the calculated h is output to the verification logic 2 for comparison. Verification logic 2 mainly determines whether h is the same as the input password2. If they are the same, authent icated_en2 is set to 1, otherwise the verification fails and authent icated_en1 is set to 0.
[0091] Of course, the algorithm logic can be implemented in a variety of different ways. As long as a user name can be uniquely matched with two sets of keys, the validity of the authentication algorithm can be guaranteed.
[0092] The present invention also provides a computer-readable storage medium containing a computer program. When the computer program is executed by one or more processors, any of the above-mentioned JTAG authentication methods based on an in-vehicle Ethernet chip is implemented.
[0093] The present invention has the following advantages: the authentication method and device provided by the present invention ensure that when an external device wants to access the chip, it must be checked in the format of the user name and double passwords, and the access permission will be opened only after the authentication is passed. Different user names and passwords can be provided for the same batch of chip products for access. The user name and password must appear in pairs, otherwise the authentication will fail. In addition, the number of accesses will also be limited. Once the number of mismatches in the user name and password input reaches the upper limit, the authentication module will immediately stop the authentication and lock the JTAG permission access. Finally, the authentication failure information will be sent to the trusted port via Ethernet message. The trusted port can lock the physical access port of JTAG from the system application level, thereby achieving the effect of multiple protections and improving the security of the vehicle-mounted Ethernet chip.
[0094] The above description is only a preferred specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any technician familiar with the technical field can make equivalent replacements or changes according to the technical scheme and inventive concept of the present invention within the technical scope disclosed by the present invention, which should be covered by the protection scope of the present invention.
Claims
1. A JTAG authentication method based on an in-vehicle Ethernet chip, characterized in that: The following steps are involved: S1, configure chip id as the unique identifier of each Ethernet chip, and the keys used for authentication: auth_key0, auth_key1 and auth_key2; S2, if the JTAG interface receives a debugging request or a request to access the inside of the chip, first enter the user name user_name, then enter password1, and finally enter password2. Password1 and password2 are compared with the expected results calculated by the hardware algorithm. If all verifications are successful, the JTAG access module is enabled, and then debugging or access to the inside of the chip is carried out; If any key verification fails, the access permission will not be enabled and the system will enter the retry waiting mode. If the retry waiting times reaches the upper limit and the JTAG input is not responded to, the hardware logic will stop the authentication process and close the access channel.
2. The JTAG authentication method based on the vehicle Ethernet chip according to claim 1, characterized in that: In S2, if the number of retry waits reaches the upper limit, the status information of JTAG authentication failure is sent to the trusted port in the format of a message based on the function of the Ethernet chip. The trusted port parses the message, handles this malicious access attack, and stops the access rights of the JTAG physical interface.
3. The JTAG authentication method based on the vehicle Ethernet chip according to claim 2, characterized in that: In S2, the hardware algorithm includes: The algorithm calculates logic 1, and calculates an exp_password1 according to the algorithm using the user_name input by JTAG, the chip_id of the Ethernet chip, and auth_key0; Verify logic 1, compare exp_password1 obtained by algorithm logic 1 with password1 input by JTAG, if the comparison result is consistent, the output is high level: authenticated_en1; The key selection logic selects auth_key1 or auth_key2 stored in EFUSE as the key input of algorithm calculation logic 2 according to the result of algorithm calculation logic 1; The algorithm calculates logic 2, and calculates the calculated exp_password1 and the key selected by the key selection logic to obtain exp_password2; Verify logic 2, compare exp_password2 with password2 input from the JTAG interface, and if the results are consistent, output high level authenticated_en2; When authenticated_en1 and authenticated_en2 are both high, the authentication pass is performed, the authenticated_pass result is output, and the debugging module function is enabled.
4. The JTAG authentication method based on the vehicle Ethernet chip according to claim 3, characterized in that: When authentication fails, the information reported to the trusted port is organized into the Ethernet message in the form of payload. The format of the payload includes the maximum number of authentication attempts try_max_num, the user_name1 / password1_1 / password1_2 entered for the first authentication failure, and all authentication failure status information.
5. The JTAG authentication method based on the vehicle Ethernet chip according to claim 3 or 4, characterized in that: The specific calculation logic 1 of the algorithm is as follows: the user_id input by JTAG and the chip_id and auth_key0 read from efuse form a new information code message m(x), such as m(x) = {user_id, chip_id, auth_key0, password1}. Using the characteristics of the characteristic generating polynomial, there is and only one generating polynomial g(x) such that m(x) = a(x)g(x). The verification logic calculates r(x) = m(x)%g(x). The verification result is represented by judging whether r(x) is 0. If r(x) = = 0, it means that the authentication algorithm 1 verification is successful, and authenticated_en1 is set to 1. Otherwise, the first key verification is unsuccessful, and authenticated_en1 is set to 0. At the same time, the algorithm calculation logic 1 obtains the auth_key_sel result after bit XOR calculation based on the result of a(x)=m(x) / g(x). If the calculated auth_key_sel==0, auth_key1 will be selected as the algorithm key for the second key verification. Otherwise, if auth_key_sel==1, auth_key2 will be selected as the auth_second_key required for the second key algorithm calculation.
6. The JTAG authentication method based on the vehicle Ethernet chip according to claim 5, characterized in that: Specifically, the algorithm calculation logic 2 takes a(x) calculated by the algorithm calculation logic 1 and the selected auth_second_key as input, combines a(x) and auth_second_key into a new information code, such as m2={a(x), auth_second_key}, and generates a message digest through a hash algorithm for comparison with password2, such as the commonly used hash algorithm h=m2%P, where P is a relatively large prime number, and the calculated h is output to the verification logic 2 for comparison; Verification logic 2 is mainly used to determine whether h is the same as the input password2. If they are the same, authenticated_en2 is set to 1. Otherwise, the verification fails and authenticated_en2 is set to 0.
7. A JTAG authentication device based on an in-vehicle Ethernet chip, characterized in that: Set in the Ethernet chip, Memory, used to store the enable control signal of the authentication module and chip_id / auth_key0 / auth_key1 / auth_key2 required by the authentication algorithm; The authentication module is connected to the memory, the debugging module and the Ethernet broadcast module signal; it is used to verify whether the input user name and password meet the algorithm rules and complete the user information verification task; JTAG interface, used to receive debugging requests or requests to access the inside of the chip; Connected to the debugging module signal; the JTAG interface itself is a channel for connecting the Ethernet chip to external devices, and external devices can debug the chip and access the internal information of the chip through the JTAG interface; The debugging module is connected to the on-chip resource module signal; it is responsible for debugging the Ethernet chip and accessing the on-chip resources. The opening and closing of this module depends on the result of the authentication; Ethernet broadcast module, connected with external trusted port signal; It is used to broadcast the authentication failure information in the form of a message via Ethernet to the trusted port. The trusted port disables the JTAG physical interface based on the received message to provide safer protection. The trusted port is generally an external device port that has been authenticated as safe by the vehicle Ethernet chip, which can be a system-level management chip. On-chip resource module, including configuration and status information inside the Ethernet chip.
8. The JTAG authentication device based on the vehicle Ethernet chip according to claim 7, characterized in that: The algorithm rules include: The algorithm calculates logic 1, and calculates an exp_password1 according to the algorithm using the user_name input by JTAG, the chip_id of the Ethernet chip, and auth_key0; Verify logic 1, compare exp_password1 obtained by algorithm logic 1 with password1 input by JTAG, if the comparison result is consistent, the output is high level: authenticated_en1; The key selection logic selects auth_key1 or auth_key2 stored in EFUSE as the key input of algorithm calculation logic 2 according to the result of algorithm calculation logic 1; The algorithm calculates logic 2, and calculates the calculated exp_password1 and the key selected by the key selection logic to obtain exp_password2; Verify logic 2, compare exp_password2 and password2 input from the JTAG interface, if the results are consistent, output high level authenticated_en2; when authenticated_en1 and authenticated_en2 are both high levels, authentication pass is performed, authenticated_pass result is output, and the debugging module function is enabled.
9. The JTAG authentication device based on the vehicle Ethernet chip according to claim 8, characterized in that: The specific calculation logic 1 of the algorithm is as follows: the user_id input by JTAG and the chip_id and auth_key0 read from efuse form a new information code message m(x), such as m(x) = {user_id, chip_id, auth_key0, password1}. Using the characteristics of the characteristic generating polynomial, there is and only one generating polynomial g(x) such that m(x) = a(x)g(x). The verification logic calculates r(x) = m(x)%g(x). The verification result is represented by judging whether r(x) is 0. If r(x) = = 0, it means that the authentication algorithm 1 verification is successful, and authenticated_en1 is set to 1. Otherwise, the first key verification is unsuccessful, and authenticated_en1 is set to 0. At the same time, the algorithm calculation logic 1 obtains the auth_key_sel result after bit XOR calculation based on the result of a(x)=m(x) / g(x). If the calculated auth_key_sel==0, auth_key1 will be selected as the algorithm key for the second key verification. Otherwise, if auth_key_sel==1, auth_key2 will be selected as the auth_second_key required for the second key algorithm calculation. Specifically, the algorithm calculation logic 2 takes a(x) calculated by the algorithm calculation logic 1 and the selected auth_second_key as input, combines a(x) and auth_second_key into a new information code, such as m2={a(x), auth_second_key}, and generates a message digest through a hash algorithm for comparison with password2, such as the commonly used hash algorithm h=m2%P, where P is a relatively large prime number, and the calculated h is output to the verification logic 2 for comparison; Verification logic 2 is mainly used to determine whether h is the same as the input password2. If they are the same, authenticated_en2 is set to 1. Otherwise, the verification fails and authenticated_en2 is set to 0.
10. A computer-readable storage medium containing a computer program, characterized in that: When the computer program is executed by one or more processors, the JTAG authentication method based on an in-vehicle Ethernet chip as described in any one of claims 1 to 6 is implemented.