Chip encryption method and device with dynamically configurable secret key

By implementing the dynamic update mechanism of the key in the chip, the problem that the key cannot be changed in the prior art is solved, and the dynamic authorization use of the chip and multiple encryption transformations are realized.

CN120030611APending Publication Date: 2025-05-23NANJING COLLEGE OF INFORMATION TECH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510120423.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-25
Publication Date
2025-05-23

AI Technical Summary

Technical Problem

In the existing chip encryption method, the key cannot be changed after one injection, resulting in encryption failure and the chip dynamic authorization cannot be realized.

Method used

The chip is activated by inputting the initial key through the chip decryption instruction, and then writing the new key through the encryption instruction for the initial encryption. The user can update the key multiple times to achieve dynamic chip encryption.

Benefits of technology

It realizes multiple transformations of chip encryption keys, solves the problem that keys cannot be changed at one time, realizes dynamic authorization and use of chips, and supports authorization and use of fields, scenarios, and time periods.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120030611A_ABST
    Figure CN120030611A_ABST
Patent Text Reader

Abstract

The invention discloses a chip encryption method and device with a dynamically configurable key, and relates to the technical field of chip security, the method comprises the following steps: inputting an initial key to a chip through a chip decryption instruction, activating the chip, writing a new key through an encryption instruction, storing the new key in a chip memory, and carrying out primary encryption on the chip; and the user decrypts the instruction to input a correct key to activate the chip, and enters a normal working state. And when encryption is carried out again, the user inputs a correct secret key to activate the chip through a decryption instruction, then a new secret key is written into the chip through an encryption instruction, the chip stores the new secret key, the encryption state of the chip is updated, and dynamic encryption of the chip is achieved. In order to achieve the method, the encryption device comprises a synchronous serial peripheral interface circuit, a live-line erasable programmable read-only memory and an encryption and decryption circuit, multiple times of conversion of a chip encryption key can be achieved, the problem that the key cannot be changed due to one-time injection is solved, and therefore chip dynamic authorization use can be achieved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of chip security technology, and in particular to a chip encryption method and device with dynamically configurable keys. Background Art

[0002] With the rapid development of digital technology, more and more information is being digitized, transmitted and stored. In order to prevent sensitive information from being accessed or stolen by unauthorized third parties, data security has become the focus of attention in various industries today. By using encryption algorithms to directly protect the generation and transmission of data, data can be effectively prevented from being intercepted. This method is often used in fields such as identity authentication and information security. For the integrated circuit industry, the encryption technology of the chip itself is also receiving increasing attention. In order to prevent their chip products from being copied or authorized for use, chip companies will embed encryption circuits into the chip, and only authorized users can use the chip.

[0003] Chinese invention patent CN118940328A discloses a chip encryption method and decryption method, which mainly adds a key for encryption when the chip is recorded. The encryption chip disclosed in Chinese invention patent CN117932699A has a built-in combined encryption module to store multiple sets of encrypted information. If the chip encryption key is fixedly configured and stored in the chip when burning or leaving the factory, once the fixed key is cracked, the encryption will become invalid and the key cannot be injected again. Therefore, it is necessary to develop a dynamic chip encryption method and device to solve this problem. Summary of the invention

[0004] The present invention aims to solve one of the technical problems in the related art at least to a certain extent.

[0005] To achieve the above object, the present invention proposes a chip encryption method with dynamically configurable keys, comprising the following steps:

[0006] S1. First, input the initial key into the chip through the chip decryption instruction to activate the chip;

[0007] S2, write the new key through the encryption instruction, save it to the chip memory, and perform the initial encryption of the chip;

[0008] S3. Decryption is performed by writing the key into the decryption instruction.

[0009] Furthermore, in step S3, when using the chip, the user enters the correct key through the decryption instruction to activate the chip and the chip works normally.

[0010] Furthermore, in step S3, the wrong key is written into the decryption instruction, and the chip decryption fails and cannot work.

[0011] Furthermore, in step S3, when encrypting again, the user needs to first input the correct key to activate the chip through the decryption instruction, and then write the new key into the chip through the encryption instruction. The chip saves the new key and updates the chip encryption status. This method realizes dynamic encryption of the chip.

[0012] Furthermore, in step S1, before the chip is used, the chip is initially powered on and a factory initial key is built into the chip.

[0013] In order to achieve the above-mentioned purpose, the present invention provides a chip encryption device with dynamically configurable keys, which adopts the above-mentioned chip encryption method with dynamically configurable keys, including a synchronous serial peripheral interface circuit, an electrically erasable programmable read-only memory, and an encryption and decryption circuit connected to each other.

[0014] Furthermore, the synchronous serial port peripheral interface circuit adopts a high-speed full-duplex synchronous communication bus and full-duplex mode communication for data interaction between the chip memory and the peripheral main control circuit, and the interaction protocol follows the SPI protocol.

[0015] Furthermore, the electrically erasable programmable read-only memory supports four operating modes: read mode, write mode, erase mode, and verify mode, and communicates with the encryption and decryption circuit using a parallel interface.

[0016] Furthermore, the encryption and decryption circuit is responsible for parsing the SPI instruction format and performing read, erase and write operations on the electrically erasable programmable read-only memory.

[0017] Beneficial effect: The present invention provides a dynamic chip encryption method and a device for implementing the method, which can realize multiple changes of the chip encryption key, solve the problem that the key cannot be changed after one injection, and thus realize dynamic authorized use of the chip, and authorized use in different fields, scenarios and time periods.

[0018] Additional aspects and advantages of the present invention will be given in part in the following description and in part will be obvious from the following description, or will be learned through practice of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] The above and / or additional aspects and advantages of the present invention will become apparent and easily understood from the following description of the embodiments in conjunction with the accompanying drawings, in which:

[0020] Figure 1 A flowchart of a chip encryption method with dynamically configurable keys according to an embodiment of the present invention;

[0021] Figure 2 It is a schematic diagram of the structure of a chip encryption device with dynamically configurable keys according to an embodiment of the present invention;

[0022] Figure 3This is a schematic diagram of the chip encryption and decryption module working according to an embodiment of the present invention;

[0023] Figure 4 Schematic diagram of the chip encryption and decryption instruction format according to an embodiment of the present invention. DETAILED DESCRIPTION

[0024] Embodiments of the present invention are described in detail below, examples of which are shown in the accompanying drawings, wherein the same or similar reference numerals throughout represent the same or similar elements or elements having the same or similar functions. The embodiments described below with reference to the accompanying drawings are exemplary and are intended to be used to explain the present invention, and should not be construed as limiting the present invention.

[0025] The following describes a chip encryption method and device with dynamically configurable keys according to an embodiment of the present invention in conjunction with the accompanying drawings.

[0026] A chip encryption method and device with dynamically configurable keys, the method comprising: first inputting an initial key into a chip through a chip decryption instruction to activate the chip, then writing a new key through an encryption instruction, saving it to a chip memory, and performing initial encryption of the chip. When using the chip, the user can activate the chip and enter a normal working state only after inputting the correct key through a decryption instruction. When encrypting again, the user needs to first input the correct key through a decryption instruction to activate the chip, then write a new key into the chip through an encryption instruction, the chip saves the new key, and updates the chip encryption state. This method realizes dynamic chip encryption.

[0027] In order to realize the above method, the encryption device designed by the present invention comprises: a synchronous serial peripheral interface circuit, an electrically erasable programmable read-only memory, and an encryption and decryption circuit.

[0028] The synchronous serial port peripheral interface circuit adopts a high-speed full-duplex synchronous communication bus and full-duplex mode communication for data interaction between the chip memory and the peripheral main control circuit. The interaction protocol follows the SPI (Serial Peripheral Interface) protocol.

[0029] Electrically Erasable Programmable Read-Only Memory (EEPROM) implements the storage function of data without loss after the chip loses power, and can be erased and written repeatedly to complete the writing and storage of dynamic keys. EEPROM supports four working modes: read mode, write mode, erase mode, and verify mode, and communicates with the encryption and decryption circuit using a parallel interface.

[0030] The encryption and decryption circuit is the main control circuit in the device of the present invention, which is responsible for parsing the SPI instruction format, reading, erasing and writing operations on the EEPROM, comparing the instruction key and the storage key, determining whether the decryption is correct, and generating enable control signals for other circuits of the chip.

[0031] In order to facilitate understanding of the above embodiments, refer to Figure 1 As shown, each time the encryption chip is powered on, it will first perform decryption and wait for the user to input a decryption command. Only when the key in the decryption command is consistent with the key stored in the chip and the chip is decrypted successfully can it enter the normal working state. The key must also be updated after the chip enters the normal state.

[0032] The initial key of the chip is set by the technicians in the designated chip read-only register area during the design and development process. After all chips are manufactured, the built-in initial key is the same. After the chip is initially powered on, the user inputs the decryption instruction through the SPI interface protocol. During the initial decryption, the decryption instruction carries the factory initial key. After receiving the decryption instruction, the chip decryption circuit parses the instruction initial key and then compares it with the chip built-in initial key. If the keys are the same, the decryption is successful, the chip enters the normal working state, and the chip activation action is completed.

[0033] When the chip is in normal working state, the user inputs encryption instructions through SPI. The encryption instructions carry new keys. After the chip receives the encryption instructions, the encryption circuit parses the new keys and stores the new keys in EEPROM. The keys required for the subsequent chip power-on decryption process are all read from EEPROM for comparison. The factory initial key is invalid, thus completing the initial encryption of the chip. When the chip is powered on again, the user needs to input the new key to the chip through the decryption instruction. After the chip is successfully decrypted, it will enter normal operation. Otherwise, the decryption fails and the chip cannot work.

[0034] If the key needs to be updated again, after the chip is powered on, the user first inputs the correct key of the chip through the decryption instruction. The chip decrypts successfully and enters the normal working state. Then the new key is input through the encryption instruction. After being processed by the chip encryption circuit, the new key is parsed and saved to the chip's internal EEPROM memory. The chip password update is completed.

[0035] The chip decryption instructions and encryption instructions mentioned above all communicate with the chip through the SPI protocol. The instruction format is not limited to a fixed protocol format. As long as the key is included in the instruction, the chip can parse the key according to the protocol format. The key length and encoding method are not limited to a fixed length and a fixed encoding method.

[0036] Furthermore, if Figure 2As shown, the chip encryption device of the present invention includes a synchronous serial peripheral interface circuit, an encryption and decryption circuit and a powered erasable programmable read-only memory.

[0037] The synchronous serial peripheral interface circuit enables the chip to communicate with other control devices in a serial manner and exchange information. The synchronous serial peripheral interface circuit is implemented using the SPI serial peripheral interface circuit, which is a high-speed full-duplex synchronous communication bus that is simple and easy to use.

[0038] The encryption and decryption circuit implements the functions of instruction parsing and reading the stored key. The encryption and decryption circuit identifies the instruction type through the instruction header according to the instruction protocol format. When the instruction type is an encryption instruction or a decryption instruction, the instruction is checked for data bits. After the check passes, the instruction key is parsed. When decrypting, the circuit is also responsible for reading the current key from the electrically erasable programmable read-only memory, comparing the instruction key and the current key. If the keys are consistent, the decryption is successful, and the chip enable signal is output through the enable interface, and the chip enters normal working state. When encrypting, the circuit stores the new key parsed from the encryption instruction in the on-chip electrically erasable programmable read-only memory.

[0039] The electrically erasable programmable read-only memory is implemented using EEPROM, which can ensure that data is not lost after power failure and supports frequent repeated programming and erasing. It is used to store keys. The size of the EEPROM depends on the length of the key.

[0040] The synchronous serial peripheral interface circuit is connected to the chip pin through the SPI interface, and is also connected to the encryption and decryption circuit. The encryption and decryption circuit is connected to the electrically erasable programmable read-only memory and is connected to other circuits of the chip through the enable interface.

[0041] like Figure 3 As shown, the working process of the encryption and decryption module is: the chip is powered on and enters the decryption state. When the SPI module sends an operation instruction, the encryption and decryption module identifies the instruction type according to the protocol format. When receiving the decryption instruction, first judge the validity of the current instruction through the check bit. If the check bit is correct, parse the instruction key according to the instruction protocol, and read the key currently saved in the chip from the EEPROM at the same time. Compare the two keys. If the key match is unsuccessful, the decryption fails, the circuit does not generate a chip enable signal, and the chip circuit does not work. If the key match is successful, the decryption is successful, the circuit generates a chip enable signal, and the chip circuit works normally. If it is working normally, the encryption and decryption circuit receives an encryption instruction, and also performs instruction verification first. After the verification is successful, the new key is parsed, and the new key is written into the on-chip EEPROM, overwriting the old key, and re-encrypting. When the chip is powered on again, the new key needs to be used for decryption.

[0042] like Figure 4As shown, the encryption and decryption instructions form serial data in a certain format. The first part is the instruction header, which is used to identify the encryption instruction and the decryption instruction. The second part is the instruction length, which includes the length of all bytes including the instruction header and the check bit. The third part is the key. The fourth part is the check bit, which is used to check the bytes from the instruction header to the end of the key. The check method can adopt but is not limited to the cyclic redundancy check method.

[0043] From the above description, it can be seen that the beneficial effects of the present invention are: providing a dynamic chip encryption method and a device for implementing this method, which can realize multiple changes of the chip encryption key, solve the problem that the key cannot be changed after one injection, thereby realizing dynamic authorized use of the chip, authorized use by field, scene and time period, and other functions.

[0044] Although the embodiments of the present invention have been shown and described above, it is to be understood that the above embodiments are exemplary and are not to be construed as limitations of the present invention. A person skilled in the art may change, modify, replace and deform the above embodiments within the scope of the present invention.

Claims

1. A chip encryption method with dynamically configurable keys, characterized in that: The steps include: S1. First, input the initial key into the chip through the chip decryption instruction to activate the chip; S2, write the new key through the encryption instruction, save it to the chip memory, and perform the initial encryption of the chip; S3. Decryption is performed by writing the key into the decryption instruction.

2. The chip encryption method with dynamically configurable keys according to claim 1, characterized in that: In step S3, when using the chip, the user enters the correct key through the decryption instruction to activate the chip and enter the normal working state.

3. The chip encryption method with dynamically configurable keys according to claim 1, characterized in that: In step S3, the wrong key is written into the decryption instruction, and the chip decryption fails and cannot work.

4. The chip encryption method with dynamically configurable keys according to claim 1, characterized in that: In step S3, when encrypting again, the user needs to first enter the correct key to activate the chip through the decryption instruction, and then write the new key into the chip through the encryption instruction. The chip saves the new key and updates the chip encryption status. This method realizes dynamic encryption of the chip.

5. The chip encryption method with dynamically configurable keys according to claim 1, characterized in that: In step S1, before the chip is used, the chip is initially powered on and a factory initial key is built into the chip.

6. A chip encryption device with dynamically configurable keys, characterized in that: The chip encryption method with dynamically configurable keys as described in any one of claims 1 to 5 comprises a synchronous serial peripheral interface circuit, an electrically erasable programmable read-only memory, and an encryption and decryption circuit which are interconnected.

7. The chip encryption device with dynamically configurable keys according to claim 6, characterized in that: The synchronous serial port peripheral interface circuit adopts a high-speed full-duplex synchronous communication bus and full-duplex mode communication for data interaction between the chip memory and the peripheral main control circuit. The interaction protocol follows the SPI protocol.

8. The chip encryption device with dynamically configurable keys according to claim 6, characterized in that: The electrically erasable programmable read-only memory supports four operating modes: read mode, write mode, erase mode, and verify mode, and communicates with the encryption and decryption circuit using a parallel interface.

9. The chip encryption device with dynamically configurable keys according to claim 6, characterized in that: The encryption and decryption circuit is responsible for parsing the SPI instruction format and performing read, erase and write operations on the electrically erasable programmable read-only memory.

Citation Information

Patent Citations

  • Encryption chip and chip encryption method

    CN117932699A

  • Chip encryption method and device, chip decryption method and device, storage medium and chip

    CN118940328A