Data processing method, memory controller, memory and data processing system
By using the message authentication code generation and verification mechanism in the memory controller, the problem of difficulty in detecting and preventing memory data tampering in the prior art is solved, and data integrity detection and system security are improved.
Patent Information
- Application Number
- CN202510156645.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-12
- Publication Date
- 2025-05-16
AI Technical Summary
The prior art is difficult to effectively detect and prevent tampering and attacks of memory data, especially in the face of physical attacks and memory data integrity detection.
By introducing a message authentication code (MAC) generation and verification mechanism into the memory controller, a first message authentication code is generated in response to a write request, and a second message authentication code is generated when a read request is generated, so as to determine the integrity and consistency of the written data.
It realizes the integrity detection and protection of memory data, improves the security of the system, and prevents data tampering and attacks.
Smart Images

Figure CN120012171A_ABST
Abstract
Description
Technical Field
[0001] Embodiments of the present disclosure relate to a data processing method, a memory controller, a memory, and a data processing system. Background Art
[0002] With the rapid development of information technology, the amount of data stored and exchanged in computer systems and networks continues to increase. Although the efficiency of information processing has been improved, the problem of data security has become increasingly prominent as the efficiency has been improved. Summary of the invention
[0003] At least one embodiment of the present disclosure provides a data processing method, comprising: in response to a write request for a target address of a memory, generating a first message authentication code based at least on write data of the write request and a message authentication code key, wherein the message authentication code key and the target address are in one-to-one correspondence; writing the write data and the first message authentication code into a target storage space corresponding to the target address; in response to a read request for the target address of the memory, reading the write data and the first message authentication code from the target storage space; and determining whether the read write data is consistent with the write data based on the write request based on the read first message authentication code and a second message authentication code generated based on the read write data and the message authentication code key.
[0004] For example, in the data processing method provided in at least some embodiments of the present disclosure, a first message authentication code is generated based at least on the write data of a write request and a message authentication code key, including: generating the first message authentication code based on the write data of the write request, the message authentication code key and the target address; performing one or more of shift processing, XOR processing and non-linear obfuscation processing on the write data, the message authentication code key and the target address to obtain a first processing result, so as to generate a first message authentication code based on the first processing result.
[0005] For example, in the data processing method provided by at least some embodiments of the present disclosure, generating a first message authentication code based on a first processing result includes: processing the first processing result through a digest algorithm to generate a first message authentication code.
[0006] For example, in the data processing method provided in at least some embodiments of the present disclosure, before performing one or more of shift processing, XOR processing and non-linear obfuscation processing on the write data, the message authentication code key and the target address, the data processing method also includes: performing bit width alignment processing on the write data, the message authentication code key and the target address.
[0007] For example, in the data processing method provided by at least some embodiments of the present disclosure, wherein the write data is encrypted data, the data processing method further includes: encrypting the plaintext data of the write request by using an encryption and decryption key generated based on the target address to generate the write data; generating a first message authentication code based at least on the write data of the write request and a message authentication code key, including: generating the first message authentication code based at least on the write data and the message authentication code key.
[0008] For example, in the data processing method provided by at least some embodiments of the present disclosure, the encryption and decryption key is used as a message authentication code key.
[0009] For example, in the data processing method provided by at least some embodiments of the present disclosure, the write data and the first message authentication code are written into the target storage space corresponding to the target address, including: encoding the write data and the first message authentication code to obtain verification information; writing the write data, the first message authentication code and the verification information into the target storage space corresponding to the target address.
[0010] For example, in the data processing method provided in at least some embodiments of the present disclosure, the write data is divided into N sub-write data, N ≥ 2 and is an integer; the write data and the first message authentication code are written into the target storage space corresponding to the target address, including: dividing the first message authentication code into N sub-message authentication codes, and combining the N sub-write data and the N sub-message authentication codes in a one-to-one correspondence and writing them into the target storage space.
[0011] For example, in the data processing method provided by at least some embodiments of the present disclosure, read write data and a first message authentication code from a target storage space, including: reading N sub-write data and N sub-message authentication codes from the target storage space; determining the read first message authentication code based on the read N sub-message authentication codes, and determining the read write data based on the read N sub-write data.
[0012] For example, in the data processing method provided in at least some embodiments of the present disclosure, based on the read first message authentication code and the second message authentication code generated based on the read write data and the message authentication code key, it is determined whether the read write data is consistent with the write data based on the write request, including: in response to the first message authentication code and the second message authentication code being consistent, determining that the read write data is consistent with the write data; or in response to the first message authentication code and the second message authentication code being inconsistent, determining that the read write data is inconsistent with the write data.
[0013] For example, the data processing method provided in at least some embodiments of the present disclosure further includes: in response to the first message authentication code being consistent with the second message authentication code, outputting the read write data; or in response to the first message authentication code being inconsistent with the second message authentication code, intercepting the read write data.
[0014] At least one embodiment of the present disclosure also provides a memory controller, which includes a write module, a read module and a message authentication module, wherein the write module is configured to generate a first message authentication code in response to a write request for a target address of the memory, at least based on the write data of the write request and a message authentication code key, wherein the message authentication code key and the target address are in a one-to-one correspondence; write the write data and the first message authentication code to a target storage space corresponding to the target address; the read module is configured to read the read and write data and the first message authentication code from the target storage space in response to a read request for the target address of the memory; the message authentication module is configured to determine whether the read write data is consistent with the write data based on the write request based on the read first message authentication code and the second message authentication code generated based on the read write data and the message authentication code key.
[0015] At least one embodiment of the present disclosure also provides a memory controller, which also includes: a first processing module, configured to perform one or more of shift processing, XOR processing and non-linear obfuscation processing on write data and a message authentication code key to obtain a first processing result, so as to generate a first message authentication code based on the first processing result.
[0016] At least one embodiment of the present disclosure further provides a memory controller, which further includes: a second processing module configured to process the first processing result through a digest algorithm to generate a first message authentication code.
[0017] At least one embodiment of the present disclosure also provides a memory controller, which also includes: a verification module, configured to encode the write data and the first message authentication code to obtain verification information, so as to write the write data, the first message authentication code and the verification information into a target storage space corresponding to the target address.
[0018] At least one embodiment of the present disclosure also provides a memory controller, which also includes: an encryption and decryption module, which is configured to encrypt the plaintext data of the write request using an encryption and decryption key generated based on the target address to generate write data, and the write module is also configured to generate a first message authentication code based on at least the write data and the message authentication code key.
[0019] At least some embodiments of the present disclosure further provide a memory system, which includes: a memory and a memory controller provided by any embodiment of the present disclosure.
[0020] At least some embodiments of the present disclosure also provide a data processing system, which includes a memory, a processor, and a memory controller provided by any embodiment of the present disclosure; the memory controller is communicatively connected to the processor, and the memory controller is communicatively connected to the memory to manage access operations to the memory. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] In order to more clearly illustrate the technical solutions of the embodiments of the present disclosure, the drawings of the embodiments will be briefly introduced below. Obviously, the drawings in the following description only relate to some embodiments of the present disclosure, but are not intended to limit the present disclosure.
[0022] Figure 1A A schematic diagram of an exemplary ECC algorithm check is shown;
[0023] Figure 1B A schematic diagram of an exemplary ECC algorithm check is shown;
[0024] Figure 2 A schematic diagram showing a flow chart of a data processing method provided by at least one embodiment of the present disclosure;
[0025] Figure 3 An exemplary logic diagram of a write request provided by at least one embodiment of the present disclosure is shown;
[0026] Figure 4 An exemplary logic diagram of a read request provided by at least one embodiment of the present disclosure is shown;
[0027] Figure 5 A block diagram of a memory controller provided by at least one embodiment of the present disclosure is shown;
[0028] Figure 6 A block diagram of a memory system provided by at least one embodiment of the present disclosure is shown;
[0029] Figure 7 A block diagram of a data processing system provided by at least one embodiment of the present disclosure is shown;
[0030] Figure 8 A schematic block diagram showing an electronic device provided by at least one embodiment of the present disclosure; and
[0031] Fig. 9 A schematic diagram of a non-transitory storage medium provided by at least one embodiment of the present disclosure is shown. DETAILED DESCRIPTION
[0032] In order to make the purpose, technical solution and advantages of the embodiments of the present disclosure clearer, the technical solution of the embodiments of the present disclosure will be clearly and completely described below in conjunction with the drawings of the embodiments of the present disclosure. Obviously, the described embodiments are part of the embodiments of the present disclosure, not all of the embodiments. Based on the described embodiments of the present disclosure, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present disclosure.
[0033] Unless otherwise defined, the technical terms or scientific terms used in the present disclosure should be understood by people with ordinary skills in the field to which the present disclosure belongs. The "first", "second" and similar words used in the present disclosure do not indicate any order, quantity or importance, but are only used to distinguish different components. Similarly, similar words such as "one", "one" or "the" do not indicate quantity restrictions, but indicate that there is at least one. Similar words such as "include" or "comprise" mean that the elements or objects appearing before the word cover the elements or objects listed after the word and their equivalents, without excluding other elements or objects. Similar words such as "connect" or "connected" are not limited to physical or mechanical connections, but can include electrical connections, whether direct or indirect. "Up", "down", "left", "right" and the like are only used to indicate relative positional relationships. When the absolute position of the described object changes, the relative positional relationship may also change accordingly.
[0034] The present disclosure is described below through several specific embodiments. In order to keep the following description of the embodiments of the present disclosure clear and concise, the present disclosure omits the detailed description of known functions and known components. When any component of the embodiments of the present disclosure appears in more than one figure, the component is represented by the same or similar reference numeral in each figure.
[0035] The terms used in the present disclosure are those common terms currently widely used in the art in consideration of the functions of the present disclosure, but these terms may vary according to the intention of a person of ordinary skill in the art, precedents, or new technologies in the art. In addition, specific terms may be selected by the applicant, and in this case, their detailed meanings will be described in the detailed description of the present disclosure. Therefore, the terms used in the specification should not be understood as simple names, but rather as an overall description based on the meaning of the terms and the present disclosure.
[0036] Flowcharts are used in this disclosure to illustrate the operations performed by the system according to the embodiments of the present application. It should be understood that the preceding or following operations are not necessarily performed precisely in order. On the contrary, various steps may be processed in reverse order or simultaneously as required. At the same time, other operations may also be added to these processes, or one or more operations may be removed from these processes.
[0037] First, the abbreviations and related terms involved in this application are defined and explained.
[0038] DDR (Double Data Rate): double data rate.
[0039] DDR SDRAM: Double data rate synchronous dynamic random access memory, commonly known as DDR.
[0040] ECC (Error Check Correction): Error correction code or error correction coding is a technology that can implement "error checking and correction" to improve the stability of computer operation and increase reliability.
[0041] RS (Reed-Solomon): RS coding, also known as Reed-Solomon codes, is a forward error correction channel coding that is effective for polynomials generated by correcting oversampled data. RS code is a special type of non-binary BCH code with strong error correction capability. For any positive integer S, a corresponding q-based BCH code with a code length of n=qS-1 can be constructed, and q is a power of a prime number. When S=1, q>2, the q-based BCH code with a code length of n=q-1 established is called RS code. When q=2m (m>1), the binary RS code whose code element symbols are taken from F(2m) can be used to correct burst errors. It is the most commonly used RS code.
[0042] MAC (Message Authentication Code): Message authentication code, that is, code value, used to verify the integrity of the message.
[0043] Data Device: A memory device that stores data.
[0044] ECC Device: Memory device that stores check bits.
[0045] It is understandable that the terms defined above are only exemplary definitions in specific application scenarios to facilitate a better understanding of the present application. For example, the exemplary definitions for specific memory described above can be extended to other types of memory or other storage.
[0046] As a key link of data storage, the security of memory (e.g., internal memory) is directly related to the security of the entire system. Therefore, the data security of the memory is particularly important. Exemplary memory includes internal memory. For example, an example of internal memory may be a random access memory, such as a dynamic random access memory (DRAM).
[0047] Due to various reasons, data errors may occur in the memory, that is, the data read from the same address is not equal to the data written previously. Taking the memory as dynamic random access memory as an example, memory errors are mainly divided into two categories:
[0048] The first type is a hard error, which means that the circuit of part of the storage array inside the dynamic random access memory is permanently damaged, resulting in irreversible errors in the data of this part. This type of error is mainly caused by defects in the chip manufacturing process and circuit aging. The MBIST (Memory Build-In-Self Test) circuit can be used to detect the storage area with errors. When using the chip, it is necessary to avoid using the storage area with errors.
[0049] The second type is soft errors, which are not permanent. The original errors will disappear after new data is written to the same address.
[0050] There are two main reasons for soft errors: one is the penetration of radioactive particles causing the inversion of the storage cells of the dynamic random access memory, and the other is the inversion of the storage cells caused by dynamic voltage noise when reading and writing data. As the size of transistors decreases, the operating voltage of the dynamic random access memory is getting lower and lower, and the distance between adjacent storage cells in the dynamic random access memory is getting closer and closer, which makes soft errors in dynamic random access memory more and more common. Since soft errors are dynamic errors, that is, they may occur in the reading and writing of data at any time and any location when the chip is working normally, and cannot be detected and avoided in advance like hard errors, soft errors must be processed dynamically.
[0051] The two reasons that cause soft errors in dynamic random access memory are both localized, that is, the errors are usually concentrated in the local storage area for the following reasons:
[0052] (a) Soft errors caused by radioactive particle penetration mainly come from radioactive particles penetrating semiconductor materials and disturbing the voltage of the memory cell latch. Depending on the angle and intensity of the radioactive particle penetration, one or more memory cells may be flipped. Generally speaking, this penetration is a straight line, and the errors caused may occur in local areas in three directions (horizontally, vertically, and diagonally). The probability of radioactive events is low, and generally only 1 to 2 bits will be caused to have errors.
[0053] (b) Soft errors caused by dynamic voltage noise mainly come from the flipping of local storage cells caused by power supply noise when reading and writing dynamic random access memory. For example, when the main clock in the chip is turned on (clock signal input exists) to turned off (clock signal input does not exist), many other transistors will jump, causing dynamic noise on the power line. If the storage cell is read or written at this time, some weaker storage cells may be disturbed. In addition, noise may also come from external events of the chip, such as dynamic fluctuations and noise of board-level voltage. Dynamic power supply noise only affects weaker storage cells, and weaker storage cells are caused by variations (Variant) in the manufacturing process and are localized. Therefore, soft errors generally occur in 1 to 2 local bits. Like radioactive particle penetration, with the advancement of technology and the reduction of chip operating voltage, the impact of dynamic voltage noise will become increasingly greater.
[0054] In summary, soft errors in dynamic random access memory generally only occur in local areas, and the probability of occurrence is low, generally only 1 to 2 bits. However, once a soft error occurs, if it cannot be recovered, it may cause serious problems in the system, so recovery from soft errors must be considered when designing chips.
[0055] Soft error detection usually occurs when data is read. For example, an ECC (Error-Correcting Code) algorithm can be used to detect and correct errors when data is written and read. The following uses a dynamic random access memory with a read and write data width of m bits as an example to illustrate error detection and correction, where m is a positive integer.
[0056] Regarding error detection and correction using the ECC algorithm, according to the aforementioned causes of soft errors, the probability of soft errors in general dynamic random access memory is relatively small, usually only 1 to 2 bits. Therefore, a typical solution is to use the SECDED (Single Error Correction, Double Error Detection) correction method in the dynamic random access memory, that is, to add the SECDED check bit, such as Figure 1A As shown. The advantage of this solution is that the error data can be corrected directly after reading the data of the dynamic random access memory, without the performance impact caused by additional delay. However, the disadvantage of this solution is that only one error bit can be corrected. Some chips also use the DECTED (double-error correction and triple-error-detection) method for soft error correction, such as Figure 1BAlthough this method can correct 2-bit soft errors, it requires more storage overhead, is more complex in hardware implementation, and introduces additional delay and power consumption.
[0057] Although the above ECC algorithm can correct the bit errors that occur randomly in DRAM data and the errors that occur during data transmission by adding SECDED and DECTED check bits, the integrity of data not only involves bit errors, but also includes whether the data has been modified or tampered with without authorization. For example, physical attacks on memory, such as side channel attacks, cold start attacks, and DMA attacks, are likely to lead to data leakage and tampering. Data tampering may involve multiple bits changing at the same time, or the overall change of the data structure, which are not within the scope of correction of the ECC algorithm. Therefore, the ECC algorithm cannot detect the integrity of the data, nor can it prevent the memory data from being attacked and tampered.
[0058] In addition, the security of memory data can be increased by adding an encryption module to the memory controller. For example, data will be encrypted before being written to DRAM and then stored in DRAM in ciphertext form; when reading data from DRAM, the memory controller will first decrypt the ciphertext and then transmit the decrypted data to the CPU for processing. However, although this method enhances the confidentiality of data, it also cannot detect the integrity of the data, let alone prevent memory data from being attacked and tampered with.
[0059] Data integrity and preventing memory data from being attacked and tampered are the key to ensuring system security. In addition, with the complexity and concealment of memory attack methods, it is difficult to detect whether memory data is safe. Therefore, the problem that urgently needs to be solved is how to detect the integrity of memory data to protect the security of memory data and system security.
[0060] To this end, at least one embodiment of the present disclosure provides a data processing method, including: in response to a write request for a target address of a memory, generating a first message authentication code based at least on the write data of the write request and a message authentication code key, the message authentication code key and the target address being in a one-to-one correspondence; writing the write data and the first message authentication code to a target storage space corresponding to the target address; in response to a read request for the target address of the memory, reading the write data and the first message authentication code from the target storage space; and determining whether the read write data is consistent with the write data based on the write request based on the read first message authentication code and a second message authentication code generated based on the read write data and the message authentication code key.
[0061] In the data processing method of the above-mentioned embodiment of the present disclosure, since the first message authentication code is generated according to the message authentication code key corresponding to the target address of the write request when writing the write data, the write data of the same target address and the first message authentication code are made to correspond one to one, that is, one address and one message authentication code key are realized, which greatly increases the independence of data protection; and, in order to solve the problem that the write data read from the same address is not equal to the write data, the first message authentication code read from the target address and the second message authentication code generated based on the read write data are compared, so as to determine whether the read write data is consistent with the write data based on the write request, thereby protecting the integrity of the data and improving the security of the system.
[0062] Various embodiments of the present disclosure will be described below with reference to specific examples.
[0063] like Figure 2 As shown, in some embodiments of the present disclosure, the data processing method may include steps S30-S33.
[0064] In step S30, in response to a write request for a target address of the memory, a first message authentication code may be generated based at least on write data of the write request and a message authentication code key, wherein the message authentication code key corresponds one-to-one to the target address.
[0065] The memory, such as the internal memory, may be a random access memory (Random-Access Memory, RAM), such as a dynamic random access memory (Dynamic Random Access Memory, DRAM), etc. For example, the memory may be a memory with a DIMM (Dual Inline Memory Module) structure.
[0066] The target address of the memory may be any address in the memory for storing data. For example, the processor may send a write request for the target address of the memory, and the memory controller may generate a first message authentication code based on the write data of the write request and the message authentication code key in response to the write request for the target address of the memory.
[0067] The message authentication code key has a one-to-one correspondence with the target address. For example, the correspondence between each address in the memory and the message authentication code key can be preset. For example, in response to obtaining the target address of the write request, the message authentication code key corresponding to the target address is obtained according to the preset correspondence. For example, the message authentication code key can also be calculated based on the target address.
[0068] A message authentication code (for example, a first message authentication code) is generated based on the write data of the write request and the message authentication code key. This allows the message authentication code to carry information about the write data and the message authentication code key, and the message authentication code key corresponds one-to-one to the target address of the write request. Therefore, such a message authentication code may include information about the write data and the message authentication code key and may also indirectly include information about the corresponding target address, so that the write data at the target address can be uniquely identified based on the message authentication code.
[0069] The message authentication code corresponds one-to-one to the write request of the target address of the memory. For example, for write requests to different addresses, the message authentication code key corresponding to the address of each write request can be obtained according to the different addresses of different write requests, and then the message authentication code corresponding to each write request is generated according to the write data corresponding to each write request and the corresponding message authentication code key. Therefore, each write request can generate its own message authentication code according to its own write data and its own message authentication code key. Therefore, each write request will have a unique corresponding message authentication code, which greatly increases the independence of data protection.
[0070] It should be noted that other information may be introduced when generating a message authentication code, so that the message authentication code may further include other information for unique identification and authentication.
[0071] For example, the write data may be plain text data corresponding to the write request, or the write data may be encrypted data obtained by encrypting the plain text data corresponding to the write request.
[0072] In some embodiments of the present disclosure, step S30 in the data processing method may further include step S301 and step S302.
[0073] In step S301, a first message authentication code may be generated based on write data of a write request, a message authentication code key, and a target address;
[0074] In step S302, one or more of shift processing, XOR processing and non-linear obfuscation processing may be performed on the write data, the message authentication code key and the target address to obtain a first processing result, so as to generate a first message authentication code based on the first processing result.
[0075] For example, the target address may be introduced when generating a message authentication code (eg, a first message authentication code), for example, the first message authentication code is generated based on write data of a write request, a message authentication code key, and the target address.
[0076] In this way, the first message authentication code can carry the address of the write request, the write data, and the information uniquely corresponding to the message authentication code key.
[0077] For example, the target address can be obtained after processing according to the minimum access granularity of the memory to ensure that the calculation is based on the effective address bits to improve efficiency. For example, if the minimum access granularity of the memory is 64 bytes, then according to the minimum access granularity 64=2q, q=6, it can be determined that the lowest 6 bits of the address need to be ignored first to obtain the target address. For example, the address Addr[40:0] of the write request can be removed by removing the lowest 6 bits to obtain the target address Addr[40:6].
[0078] The shift processing may include shifting the written data, the message authentication code key, and the target address to the left by a certain number of bits or to the right by a certain number of bits, wherein the shift directions of the written data, the message authentication code key, and the target address may be the same or different, and the number of bits shifted may be the same or different, and the direction and number of bits of the shift processing are not limited in this disclosure. For example, the 256-bit written data data may be shifted to the left by 9 bits, for example, {data[255:0]}<<9.
[0079] When the write data, the message authentication code key and the target address are XORed, for example, any two of them can be XORed in pairs and then XORed together, or, for example, the result of XORing two of them is XORed with another one, or the three are XORed together, etc., which is not limited in the present disclosure. For example, the 256-bit write data data can be XORed with the 128-bit message authentication code key Mac_key after being shifted left by 9 bits, for example, {data[255:0]}<<9 xor {Mac_key[127:0]}.
[0080] In some embodiments, the shift process and the XOR process may both be linear obfuscation processes. Of course, the embodiments of the present disclosure are not limited thereto. For example, in some embodiments, considering that the linear obfuscation process may be subject to certain attacks, in order to make it difficult for the attacker to obtain the written data or the target address of the written data when the memory is attacked, nonlinear obfuscation may be used.
[0081] Nonlinear confusion can be achieved, for example, by quantum nonlinear function confusion, multi-table displacement method, etc., which is not limited in the present disclosure.
[0082] One or more of shift processing, XOR processing and non-linear obfuscation processing can be performed on the write data, the message authentication code key and the target address to obtain a first processing result, wherein one or more of the shift processing, XOR processing and non-linear obfuscation processing is a scrambling and obfuscation operation before generating the first message authentication code.
[0083] For example, when the bit width of the first processing result is not large, the first processing result may be used as the first message authentication code. For example, the first processing result may be calculated to generate the first message authentication code.
[0084] In some embodiments of the present disclosure, the step S302 of generating a first message authentication code based on the first processing result in the data processing method may further include a step S3011.
[0085] In step S3011, the first processing result may be processed by a digest algorithm to generate a first message authentication code.
[0086] For example, if the bit width of the first processing result is relatively large, for example, the bit width of the first processing result is equal to the maximum bit width of the written data, the message authentication code key, and the target address, the first processing result can be processed according to the digest algorithm to generate a first message authentication code with a smaller bit width. For example, if the bit width of the first processing result is 256 bits, the first message authentication code of, for example, 16 bits can be generated by processing according to the digest algorithm.
[0087] The digest algorithm may be, for example, the national secret algorithm SM3 or the national secret algorithm SM4, etc., which are used for digital signature and verification or message authentication code generation and verification.
[0088] Of course, the embodiments of the present disclosure are not limited thereto, and the first processing result may also be processed by other algorithms to generate a first message authentication code. For example, a HASH algorithm may be used.
[0089] In some embodiments of the present disclosure, the data processing method may further include step S3010 before step S302.
[0090] In step S3010, bit width alignment processing may be performed on the write data, the message authentication code key, and the target address.
[0091] For example, the widest data bit width among the written data, the message authentication code key and the target address can be used as a reference for bit width alignment. For example, if the written data bit width is 256 bits, the message authentication code key bit width is 128 bits, and the target address bit width is 35 bits, the 256-bit data bit width can be used as a reference to expand the message authentication code key and the target address to align the bit widths.
[0092] For example, when the write data, the message authentication code key and the target address are subjected to bit width alignment processing, each can be extended according to the respective data to align the bit width, or can be extended using a preset extension bit to align the bit width.
[0093] For example, if the written data data is 256-bit data data[255:0], the message authentication code key Mac_key is 128-bit data Mac_key[127:0], and the target address Addr is 35-bit data Addr[40:6], then both the message authentication code and the target address can be expanded to 256 bits. For example, the message authentication code key Mac_key[127:0] can be expanded using the data of the message authentication code key itself, for example, the message authentication code key Mac_key[127:0] can be expanded to {Mac_key[127:64], ~Mac_key[127:64], Mac_key[63:0], ~Mac_key[63:0]}. For example, the target address Addr[40:6] can be extended using a preset extension bit. For example, the target address Addr[40:6] can be extended to {Addr[40:6],0,~Addr[40:6],0} by padding the extension bit 0.
[0094] For example, after the write data, the message authentication code key and the target address are aligned in bit width, one or more scrambling and confusion operations including shift processing, XOR processing and nonlinear confusion processing may be performed to obtain the first processing result.
[0095] In step S31, the write data and the first message authentication code may be written into a target storage space corresponding to the target address.
[0096] In some embodiments, the first message authentication code and the write data may be combined accordingly and then written into the target storage space.
[0097] For example, the first message authentication code and the write data can be combined accordingly, and the combined data can be written into the target storage space corresponding to the target address. For example, the write data data is 256 bits of data data[255:0], and the obtained first message authentication code is 16 bits of data MAC [15:0], and the combined data is { data[255:0], MAC[15:0]}. In this way, for example, the first message authentication code and the write data can be stored in consecutive addresses of the target storage space, so that the storage of the first message authentication code and the write data can be realized, for example, based on a single address information. In an additional aspect, the reading of the first message authentication code and the write data can be realized, for example, based on a single address information.
[0098] Of course, the embodiments of the present disclosure are not limited to this. For example, the first message authentication code and the write data may be written to non-continuous addresses of the target storage space respectively, for example, the write data may be written to the data storage space (e.g., data storage particles), and the first message authentication code may be written to the same data storage space (e.g., data storage particles) or the ECC storage space (e.g., ECC storage particles) corresponding to the data storage space. The specific writing method is not limited in the present disclosure.
[0099] In some embodiments of the present disclosure, step S31 in the data processing method may include step S311 and step S312.
[0100] In step S311, the written data and the first message authentication code may be encoded to obtain verification information.
[0101] In step S312, the write data, the first message authentication code and the verification information may be written into the target storage space corresponding to the target address.
[0102] For example, the written data and the first message authentication code may be encoded before being written into the target storage space to obtain verification information capable of verifying the written data and the first message authentication code. For example, RS encoding (Reed-solomon codes) may be used.
[0103] RS coding is usually expressed as RS(n, k), where n represents the code block length and k represents the information length in the code block. Both n and k are positive integers. The code block length n refers to the length of the entire code block, including the information length and the check information length; the information length k refers to the length of the original data, excluding the check information; the number of check information bits is equal to nk, and these check bits are used for error detection and correction.
[0104] For example, if RS encoding is performed on 128-bit write data and 16-bit first message authentication code, the actual information length k is equal to the number of bits of the write data plus the number of bits of the first message authentication code, that is, the information length k = 144. According to the definition of RS encoding, n = k + 2t, where 2t is the length of the check information, t is the number of errors that the check information can correct, and t is a positive integer.
[0105] For example, the first message authentication code is MAC (Message Authentication Code) and the verification information obtained by RS encoding may play different roles. For example, MAC is a code used to verify data integrity and authenticate the identity of the message sender. It is added to the data (such as written data) to detect whether the data is complete (such as whether it has been tampered with), while the verification information is used to detect and correct errors in data (such as written data and the first message authentication code) during transmission or storage. Therefore, the verification information and the first message authentication code (MAC) can be used at the same time to provide stronger data protection in different aspects.
[0106] It should be noted that although the generation of check information is illustrated above by using RS encoding, the check information can also be generated by other encoding methods or algorithms, such as Hamming Code, cyclic redundancy check (CRC), etc., and the present disclosure does not limit this.
[0107] Since both the written data and the first message authentication code can be protected by the verification information, the reliability of the written data and the first message authentication code read from the memory is increased.
[0108] In some embodiments of the present disclosure, in the data processing method, the write data may be divided into N sub-write data, where N≥2 and is an integer, and step S31 in the data processing method may include step S313.
[0109] In step S313, the first message authentication code may be divided into N sub-message authentication codes, and the N sub-write data may be combined with the N sub-message authentication codes in a one-to-one correspondence and then written into the target storage space.
[0110] When the bit width of the write data is wider, for example, due to the limitation of the number of data bits processed in a single transaction by the memory controller or components in the memory controller (such as an encryption and decryption module, a verification module), the write data can be divided into N sub-write data, where N ≥ 2 and is an integer.
[0111] The first message authentication code generated according to the above implementation can be divided into a plurality of sub-message authentication codes equal to the number of the plurality of sub-write data. For example, the first message authentication code is divided into N sub-message authentication codes, and the N sub-write data are combined with the N sub-message authentication codes in a one-to-one correspondence and then written into the target storage space. For example, if the write data is divided into 2 sub-write data, the first message authentication code is divided into 2 sub-message authentication codes, one of the sub-write data is combined with one of the sub-message authentication codes in a corresponding manner and then written into the target storage space, and the other sub-write data is combined with the other sub-message authentication code in a corresponding manner and then written into the target storage space.
[0112] By placing the first message authentication code in a plurality of sub-write data in the write data, it is difficult to obtain the complete write data when the memory is attacked, thereby increasing the anti-attack capability of the memory and improving the security of the memory.
[0113] Step S32: In response to a read request to a target address of the memory, read the write data and the first message authentication code from the target storage space.
[0114] Each address in the memory is unique and points to a specific location in the memory. Therefore, whether it is a read request or a write request, as long as the target address is the same, they all point to the same location in the memory. Therefore, in response to a read request to the target address of the memory, the content written in the target storage space corresponding to the target address can be read according to the read request to the target address. For example, the write data read from the target storage space and the first message authentication code read can be the same as the write data and the first message authentication code written previously.
[0115] For example, since the first message authentication code has fewer bits and the written data has more bits, the probability that the written data is tampered with when the memory is physically attacked is significantly higher than the probability that the first message authentication code is tampered with. It can be considered that the first message authentication code read in response to the read request is the same as the first message authentication code written previously, and the read written data may be different from the written data. Therefore, it is necessary to verify whether the read written data is consistent with the written data to determine the integrity of the data.
[0116] In some embodiments of the present disclosure, step S32 in the data processing method may include step S323 and step S324.
[0117] In step S323, N sub-write data and N sub-message authentication codes may be read from the target storage space.
[0118] In step S324, the read first message authentication code may be determined according to the read N sub-message authentication codes, and the read write data may be determined according to the read N sub-write data.
[0119] In some embodiments, since in response to a write request, N sub-write data and N sub-message authentication codes are written into the target storage space in a one-to-one correspondence combination, correspondingly, when reading from the target storage space in response to a read request, N sub-write data and N sub-message authentication codes may also be read correspondingly, thereby obtaining the read N sub-write data and the read N sub-message authentication codes.
[0120] In some embodiments, the read N sub-message authentication codes may be combined or calculated to determine the read first message authentication code, and the read N sub-write data may be combined or calculated to determine the read write data.
[0121] In step S33, whether the read write data is consistent with the write data based on the write request may be determined based on the read first message authentication code and the second message authentication code generated based on the read write data and the message authentication code key.
[0122] In order to verify whether the read write data is consistent with the write data based on the write request, a message authentication code (such as a second message authentication code) can be generated for the read write data in the same manner as the first message authentication code is generated in response to the write request. For example, when the first message authentication code is generated, it is based on the message authentication code key corresponding to the target address, and the second message authentication code is also generated for the read write data based on the same message authentication code key. For example, when the first message authentication code is generated, it is based on the target address and the message authentication code key, and a shift process is first used and then a nonlinear obfuscation process is used. When the second message authentication code is generated, the read write data is also based on the same target address and message authentication code key, and the same processing algorithm and processing order (i.e., a shift process is first used and then a nonlinear obfuscation process is used) is used to generate the second message authentication code.
[0123] Thus, based on the read first message authentication code and the second message authentication code generated based on the read write data and the message authentication code key, it can be determined whether the read write data is consistent with the write data based on the write request, thereby determining the integrity of the data.
[0124] For example, the first message authentication code and the second message authentication code may be compared to determine whether they are consistent, and whether the read write data is consistent with the write data based on the write request.
[0125] In some embodiments of the present disclosure, step S33 in the data processing method may include step S331 or step S332.
[0126] In step S331, in response to the first message authentication code being consistent with the second message authentication code, it may be determined that the read write data is consistent with the write data.
[0127] In step S332, in response to the first message authentication code being inconsistent with the second message authentication code, it may be determined that the read write data is inconsistent with the write data.
[0128] In some embodiments of the present disclosure, the data processing method may further include step S34 or step S35.
[0129] In step S34, in response to the first message authentication code being consistent with the second message authentication code, the read write data may be output.
[0130] In step S35, the read write data may be intercepted in response to the first message authentication code being inconsistent with the second message authentication code.
[0131] For example, in response to a read request for a target address of a memory, after obtaining the read write data and the read first message authentication code from the target storage space, the read write data is not output first, and the read write data is output after it is determined that the first message authentication code is consistent with the second message authentication code.
[0132] For example, if the first message authentication code is inconsistent with the second message authentication code, the read write data is intercepted. Thus, the read request will not read incomplete data, thereby avoiding subsequent problems caused by reading incomplete data, such as deepening of system errors or degradation of system security.
[0133] Additionally or alternatively, since the read write data is intercepted, it means that the data at the target address may be incomplete. Therefore, the user or system may be reminded by alarming or reporting an abnormality so as to perform relevant processing.
[0134] In some embodiments of the present disclosure, the data written in the data processing method may be encrypted data, and the data processing method may further include step S40.
[0135] In step S40, the plaintext data of the write request may be encrypted using an encryption and decryption key generated based on the target address to generate write data.
[0136] For example, before generating the first message authentication code, the plaintext data of the write request is encrypted to obtain the write data.
[0137] In the data processing method, step S30 may further include step S303.
[0138] In step S303, a first message authentication code may be generated based on at least the written data and the message authentication code key.
[0139] The method of generating the encryption and decryption key based on the target address may be determined according to a specific encryption algorithm, which may be a symmetric encryption algorithm, an asymmetric encryption algorithm, or a hash encryption algorithm, etc., which is not limited in the present disclosure. For example, the plaintext data may be encrypted according to a national encryption algorithm (such as the SM4 algorithm).
[0140] In some embodiments of the present disclosure, the data processing method may further include step S41.
[0141] In step S41, the encryption and decryption key may be used as a message authentication code key.
[0142] Since the encryption and decryption keys are generated based on the target address, the encryption and decryption keys also have a one-to-one correspondence with the target address. In order to simplify the system process and improve efficiency, when the plaintext data of the write request needs to be encrypted, the encryption and decryption keys can be used not only for encryption and decryption of the write data and the read write data, but also as a message authentication code key to generate a message authentication code to verify whether the write data based on the write request and the read write data are consistent, so that the encryption and decryption keys are involved in the process of ensuring data integrity.
[0143] Figure 3 An exemplary logical diagram of a write request provided by at least one embodiment of the present disclosure is shown.
[0144] like Figure 3 As shown, for example, the write data is encrypted data, and the plaintext data of the write request is 256-bit data Data[255:0]. For example, the encryption and decryption engine of the encryption and decryption module 670 can process 128-bit data per transaction, so the plaintext data can be divided into two 128-bit plaintext sub-data, which are processed by two encryption and decryption engines respectively.
[0145] In response to a write request to the target address Addr of the memory, the encryption and decryption key generated based on the target address Addr in the key generation module 6700 of the encryption and decryption module 670 is sent to the encryption and decryption engine 1 and the encryption and decryption engine 2 to obtain the encrypted output. For example, the encryption and decryption engine 1 obtains the first encrypted sub-data Enc_data[127:0] based on the first plaintext sub-data Data[127:0] and the encryption and decryption key, and the encryption and decryption engine 2 obtains the first encrypted sub-data Enc_data[127:0] based on the second plaintext sub-data Data[255:128] and the encryption and decryption key. The second encrypted sub-data Enc_data[255:128] is obtained, and the first encrypted sub-data Enc_data[127:0] and the second encrypted sub-data Enc_data[255:128] are respectively used as the first sub-write data data1 and the second sub-write data data2. For example, the encrypted data Enc_data[255:0] can be determined as the write data data based on the first encrypted sub-data Enc_data[127:0] and the second encrypted sub-data Enc_data[255:128].
[0146] The encryption and decryption key can be used as the message authentication code key Mac_Key. For example, before the first message authentication code MAC is calculated, the 256-bit write data Enc_data[255:0], the 128-bit message authentication code key Mac_Key and the 35-bit target address Addr[40:6] obtained based on the encryption output are scrambled in the first processing module 640, for example, Scramble(Enc_data 256bit, Mac_key 128bit, addr 35bit), and the shift processing is first performed to make the above data become 256 bits or 128 bits. Then, the XOR processing and nonlinear confusion processing are performed, and then the above scrambling and confusion operations are performed to obtain the first processing result. For example, the first processing result is 256 bits of data.
[0147] According to the first processing result, the digest algorithm SM3 national encryption algorithm is used for processing in the second processing module 650, and 16 bits of data in the first processing result are taken as valid information to generate a first message authentication code MAC. For example, the first processing result is data greater than 256 bits. When the first message authentication code is generated according to the first processing result, a 16-bit first message authentication code MAC can be generated for every 256 bits of data.
[0148] The generated first message authentication code MAC may be divided into a plurality of sub-message authentication codes equal in number to the plurality of sub-write data, for example, the first message authentication code MAC may be divided into a first sub-message authentication code MAC1 and a second sub-message authentication code MAC2. The first sub-write data data1 may be combined with the first sub-message authentication code MAC1 and the second sub-write data data2 may be combined with the second sub-message authentication code MAC2.
[0149] For example, the verification module 660 can encode the combined data of the first sub-write data data1 and the first sub-message authentication code MAC1 to obtain the first verification information, and encode the combined data of the second sub-write data data2 and the second sub-message authentication code MAC2 to obtain the second verification information.
[0150] Afterwards, the first sub-write data data1, the first sub-message authentication code MAC1 and the first verification information can be written into the target storage space of the target address in the memory 701, and the second sub-write data data2, the second sub-message authentication code MAC2 and the second verification information can be written into the target storage space of the target address in the memory 701. The first verification information and the second verification information are both verification information Checkbits of the write data and the first message authentication code corresponding to the write request.
[0151] The target storage space may be determined by the target storage particles of the memory 701 , and the target storage particles may include data storage particles for storing data and ECC storage particles for storing verification information.
[0152] For example, when writing the write data data, the first message authentication code MAC and the check information Checkbit into the target storage space corresponding to the target address, the write data data can be written into the data storage space corresponding to the data storage particle, and the check information Checkbit can be written into the ECC storage space corresponding to the ECC storage particle. For example, the first message authentication code MAC can be written into the ECC storage particle (for example, the redundant ECC storage particle) or the data storage particle.
[0153] Figure 4 An exemplary logical diagram of a read request provided by at least one embodiment of the present disclosure is shown.
[0154] like Figure 4 As shown, Figure 4 is corresponding to Figure 3 The read request diagram of the write request diagram.
[0155] After the memory 701 receives the read request of the target storage space corresponding to the target address Addr, for example, the read write data Rdata and the read first message authentication code RMAC can be directly obtained from the target storage space.
[0156] For example, before obtaining the read write data Rdata and the read first message authentication code RMAC, the check information Checkbit can be used to perform error correction through the check module 660. For example, the check module 660 can perform error correction on the read first sub-write data and the read first sub-message authentication code according to the first check information, and the check module 660 can perform error correction on the read second sub-write data and the read second sub-message authentication code according to the second check information.
[0157] Corresponds to Figure 3 The first sub-write data data1 corresponds to the first sub-message authentication code MAC1 combination and the second sub-write data data2 corresponds to the second sub-message authentication code MAC2 combination. Figure 4 When a read request of the target storage space is received, the first sub-write data Rdata1 and the first sub-message authentication code RMAC1 and the second sub-write data Rdata2 and the second sub-message authentication code RMAC2 are read respectively.
[0158] For example, the read first message authentication code RMAC is determined according to the read first sub-message authentication code RMAC1 and the read second sub-message authentication code RMAC2. The read write data Rdata is determined according to the first sub-write data Rdata1 and the second sub-write data Rdata2. Figure 3 The writing process is encrypted, therefore, the first sub-write data Rdata1 is the first data to be decrypted Dec_data[127:0], and the second sub-write data Rdata2 is the second data to be decrypted Dec_data[255:128]. According to the first data to be decrypted Dec_data[127:0] and the second data to be decrypted Dec_data[255:128], the complete data to be decrypted Dec_data[255:0] can be determined as the read write data Rdata.
[0159] For example, you can use Figure 3 The same first processing module 640 and second processing module 650 use the same scrambling and confusion operation and digest algorithm as those used during writing to process the read write data Rdata, the target address Addr, and the message authentication code key Mac_Key to generate a second message authentication code, wherein the message authentication code key Mac_Key may be the same as the message authentication code key Mac_Key used during writing, and the acquisition method may be the same as that used during writing, which will not be repeated here.
[0160] After obtaining the second message authentication code, the read first message authentication code RMAC and the second message authentication code can be compared to determine whether the read write data Rdata is consistent with the write data data. For example, if they are consistent, the first sub-write data Rdata1 and the second sub-write data Rdata2 included in the read write data Rdata can be input into the encryption and decryption engine 1 and the encryption and decryption engine 2 respectively for decryption, so as to respond to the read request and read the plaintext data Data[255:0] written by the previous write request. For example, the first data to be decrypted Dec_data[127:0] can be decrypted by the encryption and decryption engine 1 to obtain the first plaintext sub-data Data[127:0], and the second data to be decrypted Dec_data[255:128] can be decrypted by the encryption and decryption engine 2 to obtain the second plaintext sub-data Data[255:128].
[0161] If they are inconsistent, the read write data Rdata is intercepted so that it cannot be output.
[0162] Figure 5 A block diagram of a memory controller provided by at least one embodiment of the present disclosure is shown.
[0163] At least one embodiment of the present disclosure further provides a memory controller 600 , which includes a write module 610 , a read module 620 , and a message authentication module 630 .
[0164] The write module 610 is configured to respond to a write request for a target address of the memory, generate a first message authentication code based at least on the write data of the write request and a message authentication code key, wherein the message authentication code key and the target address are in one-to-one correspondence; and write the write data and the first message authentication code into a target storage space corresponding to the target address.
[0165] The read module 620 is configured to read the write data and the first message authentication code from the target storage space in response to a read request to the target address of the memory.
[0166] The message authentication module 630 is configured to determine whether the read write data is consistent with the write data based on the write request based on the read first message authentication code and the second message authentication code generated based on the read write data and the message authentication code key.
[0167] In some embodiments of the present disclosure, the memory controller 600 may further include a first processing module 640 .
[0168] The first processing module 640 may be configured to perform one or more of shift processing, XOR processing, and nonlinear obfuscation processing on the written data and the message authentication code key to obtain a first processing result, so as to generate a first message authentication code based on the first processing result.
[0169] In some embodiments of the present disclosure, the memory controller 600 may further include a second processing module 650 .
[0170] The second processing module 650 may be configured to process the first processing result through a digest algorithm to generate a first message authentication code.
[0171] In some embodiments of the present disclosure, the first processing module 640 may be further configured to perform bit width alignment processing on the write data, the message authentication code key, and the target address before performing one or more of shift processing, XOR processing, and non-linear obfuscation processing on the write data and the message authentication code key.
[0172] In some embodiments of the present disclosure, the memory controller 600 may further include a checking module 660 .
[0173] The verification module 660 may be configured to encode the write data and the first message authentication code to obtain verification information, so as to write the write data, the first message authentication code and the verification information into the target storage space corresponding to the target address.
[0174] In some embodiments of the present disclosure, the memory controller 600 may further include an encryption / decryption module 670 .
[0175] The encryption / decryption module 670 may be configured to encrypt the plaintext data of the write request using an encryption / decryption key generated based on the target address to generate encrypted write data.
[0176] The writing module 610 may be further configured to generate a first message authentication code based on at least the writing data and the message authentication code key.
[0177] In some embodiments of the present disclosure, the encryption and decryption key may be used as a message authentication code key.
[0178] In some embodiments of the present disclosure, the write data can be divided into N sub-write data, where N ≥ 2 and is an integer. The write module 610 can also be configured to divide the first message authentication code into N sub-message authentication codes, and combine the N sub-write data with the N sub-message authentication codes in a one-to-one correspondence and write them into the target storage space.
[0179] In some embodiments of the present disclosure, the read module 620 may be further configured to read N sub-write data and N sub-message authentication codes from the target storage space; determine the read first message authentication code based on the read N sub-message authentication codes, and determine the read write data based on the read N sub-write data.
[0180] In some embodiments of the present disclosure, the message authentication module 630 may be further configured to determine that the read write data is consistent with the write data in response to the first message authentication code being consistent with the second message authentication code; or to determine that the read write data is inconsistent with the write data in response to the first message authentication code being inconsistent with the second message authentication code.
[0181] In some embodiments of the present disclosure, the message authentication module 630 may be further configured to output the read write data in response to the first message authentication code being consistent with the second message authentication code; or to intercept the read write data in response to the first message authentication code being inconsistent with the second message authentication code.
[0182] Other additional aspects of the memory controller 600 may correspond to one or more aspects of the data processing method described above, and will not be described in detail here.
[0183] The above-mentioned memory controller 600 can be a hardware circuit module. For example, since the first processing module 640, the second processing module 650 and the encryption and decryption module 670 in the memory controller 600 are all hardware circuit modules and there is no software read channel, the data security of write request and read request operations is greatly increased.
[0184] The technical effect of the memory controller of the above embodiment of the present disclosure is the same as the technical effect of the above data processing method, and thus will not be described in detail.
[0185] Figure 6 A block diagram of a memory system provided by at least one embodiment of the present disclosure is shown.
[0186] At least one embodiment of the present disclosure further provides a memory system 700 , which includes: a memory 701 and a memory controller 600 provided by any embodiment of the present disclosure.
[0187] In some embodiments, memory 701 may be any memory that memory controller 600 may control.
[0188] The technical effect of the memory system of the above embodiment of the present disclosure is the same as the technical effect of the above data processing method, and thus will not be described in detail.
[0189] Figure 7 A block diagram of a data processing system provided by at least one embodiment of the present disclosure is shown.
[0190] At least some embodiments of the present disclosure further provide a data processing system 800 , which includes a memory 701 , a processor 801 , and a memory controller 600 provided by any embodiment of the present disclosure.
[0191] The memory controller 600 is communicatively connected to the processor 801 . The memory controller 600 is communicatively connected to the memory 701 to manage access operations to the memory 701 .
[0192] For example, the access operation to the memory 701 may be a read request or a write request issued by the processor 801. When the processor 801 needs to access data or instructions in the memory 701, the processor 801 may issue a request to the memory controller 600. For example, the processor 801 needs to read a value in the memory 701 and may send an access address to the memory controller 600. The memory controller 600 reads the data corresponding to the access address from the memory and then sends it to the processor. For example, the memory 701 may be a memory, and the memory controller 600 may be a memory controller.
[0193] The technical effect of the data processing system of the above embodiment of the present disclosure is the same as the technical effect of the above data processing method, so it will not be repeated.
[0194] Figure 8 A schematic block diagram of an electronic device provided for at least one embodiment of the present disclosure.
[0195] The electronic devices in the embodiments of the present disclosure may include, but are not limited to, mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, PDAs (personal digital assistants), PADs (tablet computers), PMPs (portable multimedia players), vehicle-mounted terminals (such as vehicle-mounted navigation terminals), etc., and fixed terminals such as digital TVs, desktop computers, etc. Figure 8 The electronic device 1000 shown is merely an example and should not bring any limitation to the functions and scope of use of the embodiments of the present disclosure.
[0196] For example, refer to Figure 8 In some examples, the electronic device 1000 includes a processing device (e.g., a central processing unit, a graphics processing unit, etc.) 1001, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 1002 or a program loaded from a storage device 1008 to a random access memory (RAM) 1003. For example, RAM 1003 can be a memory in at least one embodiment of the present disclosure. Various programs and data required for the operation of the computer system are also stored in RAM 1003. The processing device 1001, ROM 1002, and RAM 1003 are connected to each other via an Internet 1004. An input / output (I / O) interface 1005 is also connected to the Internet 1004.
[0197] For example, the following components may be connected to the I / O interface 1005: an input device 1006 including, for example, a touch screen, a touchpad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, etc.; an output device 1007 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; a storage device 1008 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 1009 which may also include, for example, a network interface card such as a LAN card, a modem, etc. The communication device 1009 may allow the electronic device 1000 to communicate with other devices wirelessly or by wire to exchange data, performing communication processing via a network such as the Internet. The drive 1010 is also connected to the I / O interface 1005 as needed. Removable media 1011, such as magnetic disks, optical disks, magneto-optical disks, semiconductor memories, etc., are installed on the drive 1010 as needed, so that the computer program read therefrom is installed into the storage device 1008 as needed. Although Figure 8 The electronic device 1000 is shown to include various devices, but it should be understood that it is not required to implement or include all of the devices shown. More or fewer devices may be implemented or included instead.
[0198] For example, the electronic device 1000 may further include a peripheral interface (not shown in the figure), etc. The peripheral interface may be various types of interfaces, such as a USB interface, a lightning interface, etc. The communication device 1009 may communicate with a network and other devices through wireless communication, such as the Internet, an intranet and / or a wireless network such as a cellular phone network, a wireless local area network (LAN) and / or a metropolitan area network (MAN). Wireless communication may use any of a variety of communication standards, protocols, and techniques, including, but not limited to, Global System for Mobile Communications (GSM), Enhanced Data GSM Environment (EDGE), Wideband Code Division Multiple Access (W-CDMA), Code Division Multiple Access (CDMA), Time Division Multiple Access (TDMA), Bluetooth, Wi-Fi (e.g., based on IEEE 802.11a, IEEE 802.11b, IEEE 802.11g, and / or IEEE 802.11n standards), Voice over Internet Protocol (VoIP), Wi-MAX, protocols for email, instant messaging, and / or Short Message Service (SMS), or any other suitable communication protocol.
[0199] For example, the electronic device 1000 can be any device such as a mobile phone, a tablet computer, a laptop computer, an e-book, a game console, a television, a digital photo frame, a navigator, a server, etc., or it can be a combination of operating devices and hardware of any memory controller, and the embodiments of the present disclosure are not limited to this.
[0200] At least one embodiment of the present disclosure further provides a non-transitory storage medium that non-transitorily stores computer executable instructions. For example, when the computer executable instructions are executed by a processor, the data processing method provided by at least one embodiment of the present disclosure is implemented.
[0201] Fig. 9 is a schematic diagram of a non-transitory storage medium provided by some embodiments of the present disclosure. Fig. 9 As shown, the non-transitory storage medium 900 can non-transitorily store computer executable instructions 910 , and the computer executable instructions 910 implement the data processing method provided by any embodiment of the present disclosure when executed by a computer.
[0202] There are a few points to note about this disclosure:
[0203] (1) In the drawings of the embodiments of the present disclosure, only the structures related to the embodiments of the present disclosure are involved, and other structures can refer to the general design.
[0204] (2) In the absence of conflict, features in the same embodiment or in different embodiments of the present disclosure may be combined with each other.
[0205] The above are only specific embodiments of the present disclosure, but the protection scope of the present disclosure is not limited thereto. Any technician familiar with the technical field can easily think of changes or substitutions within the technical scope disclosed in the present disclosure, which should be included in the protection scope of the present disclosure. Therefore, the protection scope of the present disclosure should be based on the protection scope of the claims.
Claims
1. A data processing method, comprising: In response to a write request for a target address of a memory, generating a first message authentication code based at least on write data of the write request and a message authentication code key, wherein the message authentication code key corresponds one-to-one to the target address; Writing the write data and the first message authentication code into a target storage space corresponding to the target address; In response to a read request for a target address of the memory, reading the write data and the first message authentication code from the target storage space; and Based on the read first message authentication code and a second message authentication code generated based on the read write data and the message authentication code key, it is determined whether the read write data is consistent with the write data based on the write request.
2. The data processing method according to claim 1, wherein: The generating a first message authentication code based at least on the write data of the write request and a message authentication code key comprises: generating the first message authentication code based on the write data of the write request, a message authentication code key, and the target address; One or more of shift processing, XOR processing and non-linear obfuscation processing are performed on the write data, the message authentication code key and the target address to obtain a first processing result, so as to generate the first message authentication code based on the first processing result.
3. The data processing method according to claim 2, wherein: The generating the first message authentication code based on the first processing result includes: The first processing result is processed by a digest algorithm to generate the first message authentication code.
4. The data processing method according to claim 2, wherein: Before performing one or more of shift processing, XOR processing and non-linear obfuscation processing on the write data, the message authentication code key and the target address, the data processing method further includes: The write data, the message authentication code key and the target address are subjected to bit width alignment processing.
5. The data processing method according to claim 1, wherein: The written data is encrypted data, and the data processing method further includes: Encrypting the plaintext data of the write request by using an encryption and decryption key generated based on the target address to generate the write data; The step of generating a first message authentication code based at least on the write data of the write request and a message authentication code key comprises: The first message authentication code is generated based on at least the write data and the message authentication code key.
6. The data processing method according to claim 5, wherein: The encryption and decryption key is used as the message authentication code key.
7. The data processing method according to claim 1, wherein: Writing the write data and the first message authentication code into the target storage space corresponding to the target address includes: Encoding the written data and the first message authentication code to obtain verification information; The write data, the first message authentication code and the verification information are written into a target storage space corresponding to the target address.
8. The data processing method according to claim 1, wherein: The write data is divided into N sub-write data, where N≥2 and is an integer; and the writing of the write data and the first message authentication code into the target storage space corresponding to the target address includes: The first message authentication code is divided into N sub-message authentication codes, and the N sub-write data are combined with the N sub-message authentication codes in a one-to-one correspondence and then written into the target storage space.
9. The data processing method according to claim 8, wherein: The reading the write data and the first message authentication code from the target storage space includes: reading the N sub-write data and the N sub-message authentication codes from the target storage space; and The read first message authentication code is determined according to the read N sub-message authentication codes, and the read write data is determined according to the read N sub-write data.
10. The data processing method according to claim 1, wherein: The determining, based on the read first message authentication code and the second message authentication code generated based on the read write data and the message authentication code key, whether the read write data is consistent with the write data based on the write request comprises: In response to the first message authentication code being consistent with the second message authentication code, determining that the read write data is consistent with the write data; or In response to the first message authentication code being inconsistent with the second message authentication code, it is determined that the read write data is inconsistent with the write data.
11. The data processing method according to claim 10, further comprising: In response to the first message authentication code being consistent with the second message authentication code, outputting the read write data; or In response to the first message authentication code being inconsistent with the second message authentication code, intercepting the read write data.
12. A memory controller comprising: Write module, configured as: In response to a write request for a target address of a memory, generating a first message authentication code based at least on write data of the write request and a message authentication code key, wherein the message authentication code key corresponds one-to-one to the target address; Writing the write data and the first message authentication code into a target storage space corresponding to the target address; a reading module configured to: read the write data and the first message authentication code from the target storage space in response to a read request for a target address of the memory; and The message authentication module is configured to determine whether the read write data is consistent with the write data based on the write request based on the read first message authentication code and a second message authentication code generated based on the read write data and the message authentication code key.
13. The memory controller of claim 12, further comprising: The first processing module is configured to: perform one or more of shift processing, XOR processing and non-linear obfuscation processing on the written data and the message authentication code key to obtain a first processing result, so as to generate the first message authentication code based on the first processing result.
14. The memory controller of claim 13, further comprising: The second processing module is configured to: process the first processing result through a digest algorithm to generate the first message authentication code.
15. The memory controller of claim 12, further comprising: The verification module is configured to: encode the write data and the first message authentication code to obtain verification information, so as to write the write data, the first message authentication code and the verification information into the target storage space corresponding to the target address.
16. The memory controller of claim 12, further comprising: an encryption and decryption module, configured to: encrypt the plaintext data of the write request using an encryption and decryption key generated based on the target address to generate the write data, and The writing module is further configured to generate the first message authentication code based at least on the writing data and the message authentication code key.
17. A memory system comprising: Memory; as well as A memory controller as claimed in any one of claims 12 to 16.
18. A data processing system comprising: Memory; processor; as well as The memory controller according to any one of claims 12 to 16, wherein the memory controller is communicatively connected to the processor, and the memory controller is communicatively connected to the memory to manage access operations to the memory.