Dual-core trusted security hardware system and control method thereof
By designing a dual-core trusted and secure hardware system in the industrial control system, and using the coordinated work of the control core and the trusted core, the problems of limited hardware resources and weak computing power of the industrial control system are solved, and a high-security trusted computing platform is realized.
Patent Information
- Application Number
- CN202411914470.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-24
- Publication Date
- 2025-05-27
AI Technical Summary
The hardware resources of the industrial control system are limited and the computing power is weak, and it is impossible to effectively realize trusted computing, resulting in insufficient information security defense capabilities.
Design a dual-core trusted and secure hardware system, including control cores and trusted cores, to interact data through the AXI bus. The control core is used to realize hardware function call and information management of industrial control equipment. The trusted core includes a trusted password module, which is used to generate a trusted metric root and provide trusted password services.
It effectively compensates for the problem of limited hardware resources and weak computing power of the industrial control system, greatly improves the security of the industrial control system, and realizes the dual-system architecture of a trusted computing platform.
Smart Images

Figure CN120046152A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of information security, and particularly to a dual-core trusted security hardware system and a control method thereof. Background Art
[0002] In the field of information security of industrial control systems, the inventors' known information security solutions for process control systems based on the concept of defense in depth can conduct systematic risk analysis and assessment of process control systems on the premise of ensuring physical security. Moreover, for different types of security threats, security measures with different characteristics are developed and deployed hierarchically in a targeted manner. However, the deep isolation and access control adopted by this solution require strict risk assessment and have relatively high requirements for the information security defense capabilities of on-site employees, and generally cannot meet the requirements. In another solution known to the inventors, for the three-level defense in depth system at the device level, system level, and management level, starting from the protection of the physical device level at the control site and expanding upward, the protection capabilities of the system are comprehensively improved. This solution is similar to the defense in depth concept provided above, starting from system vulnerabilities and security management, and using strict network security devices for hierarchical layout, but still does not fundamentally solve the drawbacks of traditional defense measures.
[0003] In summary, considering that industrial control systems have few hardware resources, their processing speed is slower than that of general-purpose computers, and their main frequency is low, and they cannot, like general-purpose computers, place some operations of trusted computing in the central processing unit (CPU) of general-purpose computers to complete control. There is an urgent need to design a new trusted security hardware architecture to make up for the deficiencies of limited hardware resources and weak computing power in industrial control systems. Summary of the Invention
[0004] The purpose of the present application is to provide a dual-core trusted security hardware system and a control method thereof, which can effectively make up for the deficiencies of limited hardware resources and weak computing power in industrial control systems, and thus greatly improve the security of industrial control systems.
[0005] To achieve the above object, the present application provides the following solutions:
[0006] In a first aspect, the present application provides a dual-core trusted security hardware system, including: a control core and a trusted core;
[0007] The control core conducts data interaction with the trusted core; the control core is used to implement hardware function calls and information management of industrial control devices;
[0008] The trusted core includes a trusted password module; the trusted password module is used to generate a trusted measurement root; the trusted core is used to provide trusted password services for the control core based on the trusted measurement root.
[0009] Optionally, the control core and the trusted core perform data interaction through the AXI bus.
[0010] Optionally, the control core is an ARM processing unit.
[0011] Optionally, the trusted core is an FPGA processing unit.
[0012] Optionally, the control core includes: a bus arbitration module, a trusted active logic control unit, a reconfigurable area, a secure storage module, and a backup and recovery module;
[0013] The bus arbitration module, the reconfigurable area, the secure storage module, and the backup and recovery module all perform information interaction with the trusted active logic control unit; the secure storage module performs data interaction with the trusted password module;
[0014] The secure storage module is used to store data; the stored data includes: a boot file, an operating system kernel, and upper-layer application code; the backup and recovery module is used to store backup and recovery resources;
[0015] The bus arbitration module is used to determine the bus protocol to be followed based on the operation information of the industrial control device; the trusted active logic control unit retrieves the data corresponding to the industrial control device stored in the secure storage module based on the followed bus protocol, and stores the retrieved data in the bus arbitration module; the trusted active logic control unit uses the trusted measurement root to measure whether the retrieved data is trustworthy; when the retrieved data is trustworthy, the trusted active logic control unit generates a control command based on the retrieved data; the reconfigurable area completes the hardware resource reconfiguration based on the control command; the trusted active logic control unit converts the control command into a control arbitration command, and releases the control right of the bus arbitration module based on the control arbitration command; the industrial control device obtains the control right of the bus arbitration module, and completes the trusted control of the reconfigured hardware resources based on the control right;
[0016] When the retrieved data is not trustworthy, the trusted active logic control unit retrieves the backup and recovery resources and performs a backup and recovery operation.
[0017] Optionally, the control core further includes: a controller unit;
[0018] The controller unit respectively performs information interaction with the bus arbitration module and the industrial control device; the controller unit is used to obtain the operation information, bus information, and hardware resource reconfiguration information of the industrial control device.
[0019] Optionally, the controller unit includes one or more of an I / O bus controller, an Ethernet controller, a MODBUS controller, a power controller, and a monitoring module.
[0020] Optionally, the control core further includes a bus interface; the bus interface is used to dock with the trusted password module or the bus module of the industrial device.
[0021] Optionally, the bus interface includes an SPI bus interface and / or an I 2 C bus interface; the bus module is a module with an SPI bus and / or an I 2 C bus.
[0022] In a second aspect, the present application provides a control method for a dual-core trusted security hardware system, including:
[0023] Determine the bus protocol to be followed based on the operation information of the industrial control device;
[0024] Retrieve data corresponding to the industrial control device based on the followed bus protocol;
[0025] Use the trusted measurement root to measure whether the retrieved data is trustworthy;
[0026] When the retrieved data is trustworthy, generate a control command based on the retrieved data; the control command is used to complete the reconstruction of hardware resources;
[0027] Convert the control command into a control arbitration command, release the control right based on the control arbitration command, and complete the trusted control of the reconstructed hardware resources based on the control right; the control right is the control right of the bus arbitration module;
[0028] When the retrieved data is untrustworthy, obtain backup resources and perform a backup recovery operation.
[0029] According to the specific embodiments provided by the present application, the present application has the following technical effects:
[0030] The present application provides a dual-core trusted security hardware system and its control method. By setting up a dual-system architecture of a control core and a trusted core to form a trusted computing platform for the industrial control system, and taking the trusted password module in the trusted core as a functional part of this dual-system architecture, it can effectively make up for the deficiencies of limited hardware resources and weak computing power in the industrial control system, and greatly improve the security of the industrial control system. Description of the Drawings
[0031] To more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the embodiments. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0032] Figure 1 The structural schematic diagram of a dual-core trusted security hardware system provided by an embodiment of the present application;
[0033] Figure 2 The flowchart of a control method for a dual-core trusted security hardware system provided by an embodiment of the present application. Detailed implementation manners
[0034] The following will clearly and completely describe the technical solutions in the embodiments of the present application with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present application.
[0035] To make the above objects, features, and advantages of the present application more obvious and understandable, the present application will be further described in detail below with reference to the drawings and specific implementation manners.
[0036] In an exemplary embodiment, the present application provides a dual-core trusted security hardware system (hereinafter simply referred to as the system), as Figure 1 shown, the system includes: a control core and a trusted core.
[0037] The control core and the trusted core perform data interaction. For example, the control core and the trusted core perform data interaction through the AXI bus.
[0038] The control core is used to implement the hardware function call and information management of industrial control devices.
[0039] The trusted core includes a trusted cryptography module (TCM). The trusted cryptography module is used to generate a trusted measurement root to provide the trusted root of the active immune trusted system. The trusted core is mainly used to establish and guarantee the trust source point, and provide a series of trusted computing functions such as integrity measurement, secure storage, trusted reporting, and cryptographic services, and provide trusted cryptographic services for the system.
[0040] In another exemplary embodiment of the present application, considering that the industrial control system has few hardware resources, its processing speed is slower than that of a general-purpose computer, and its main frequency is low. It is impossible to perform some operations of trusted computing in the CPU of a general-purpose computer like a general-purpose computer. To solve this problem, in this embodiment, a dual-core trusted security hardware architecture based on FPGA can be introduced. The FPGA is used as the processor of the trusted computing subsystem, and the trusted password module exists as a functional part in the hardware architecture. Based on this, the control core provided above in the present application can be an ARM processing unit, and the trusted core can be an FPGA processing unit. The ARM processing unit and the FPGA processing unit are arranged in the same chip and share the same storage unit.
[0041] In another exemplary embodiment of the present application, the control core includes: a bus arbitration module, a trusted active logic control unit, a reconfigurable area, a secure storage module, and a backup and recovery module.
[0042] The bus arbitration module, the reconfigurable area, the secure storage module, and the backup and recovery module all perform information interaction with the trusted active logic control unit. The secure storage module performs data interaction with the trusted password module.
[0043] The secure storage module is used to store data, which can be all files required for system startup and operation, such as package startup boot files, operating system kernels, and upper-layer application codes.
[0044] The backup and recovery module is used to store backup and recovery resources. The backup and recovery module is a protected system backup memory that encrypts and stores the executable codes of system boot and operating system, as well as the factory original configuration information, and realizes system self-recovery by loading the backup once any changes are detected.
[0045] The reconfigurable area is used to implement the hardware resource reconstruction of different industrial control devices and different bus interfaces, save hardware resources, and expand compatibility and flexibility.
[0046] The bus arbitration module is used to allocate external bus resources and determine the right to use bus resources. Among them, it is mainly used to determine the bus protocol followed based on the operation information of industrial control devices.
[0047] The reconfigurable area is used to implement the hardware resource reconstruction of different industrial control devices and different bus interfaces, save hardware resources, and expand compatibility and flexibility. Among them, the reconfigurable area completes the hardware resource reconstruction based on control commands.
[0048] The trusted active logic control unit is the information processing center of the control core, which is used to process the function calls and information management of each module in the control core. Among them, the trusted active logic control unit retrieves the data corresponding to the industrial control device stored in the secure storage module based on the bus protocol followed, and stores the retrieved data in the bus arbitration module. The trusted active logic control unit uses the root of trust measurement to measure whether the retrieved data is trustworthy. When the retrieved data is trustworthy, the trusted active logic control unit generates a control command based on the retrieved data. The trusted active logic control unit converts the control command into a control arbitration command, and releases the control right of the bus arbitration module based on the control arbitration command. The industrial control device obtains the control right of the bus arbitration module, and completes the trusted control of the reconfigured hardware resources based on the control right. When the retrieved data is untrustworthy, the trusted active logic control unit retrieves the backup and recovery resources and performs the backup and recovery operation.
[0049] In another exemplary embodiment of the present application, other interfaces and controller units may also be provided in the control core provided by the present application. The controller unit respectively performs information interaction with the bus arbitration module and the industrial control device. The controller unit is used to obtain the operation information, bus information, and hardware resource reconstruction information of the industrial control device.
[0050] The other interfaces are mainly reserved bus interfaces such as SPI, PCIe, I 2 C, etc., which are used to be compatible with bus modules or TCMs with SPI, PCIe, I 2 C, etc.
[0051] The controller unit includes one or more of: I / O bus controllers (such as low-speed bus controllers and high-speed bus controllers), Ethernet controllers, MODBUS controllers, power controllers, and monitoring modules.
[0052] Based on the above description, the controller unit is mainly used to interface with different industrial control devices. Through the controller logic that interfaces with the low-speed bus, high-speed bus, power management mechanism, and I / O devices, it obtains bus information and performs analysis and judgment, submits the judgment result to the trusted active logic control unit, and receives the control command sent by the trusted active logic control unit, and converts it into control arbitration commands for the bus, power supply, and I / O ports, so as to achieve trusted control of the bus, power supply, and I / O devices.
[0053] In the actual application process, the trusted active logic control unit, the reconfigurable area, the bus arbitration module, the backup and recovery module, the secure storage module, as well as other interfaces and controller units can be encapsulated to obtain the control core.
[0054] In summary, the dual-core trusted security hardware system provided by this application uses a hardware design method based on FPGA. The FPGA is used as a processing unit together with the processing unit of the industrial control system to form a dual-system architecture of the trusted computing platform of the industrial control system. Through the reconfigurable technology of the FPGA, different communication interfaces are reconfigured under limited hardware resources to support different industrial control devices. Compared with the known technology, the dual-core trusted security hardware architecture provided by this application has strong flexibility and compatibility, and can provide a feasible design method for establishing trusted computing in different industrial control systems.
[0055] Based on the above description, the working process of the dual-core trusted security hardware system provided by this application can be described as follows: Before the industrial control device starts the system, the trusted active logic control unit first verifies the integrity of the executable code in the secure storage module. Only when the verification passes, the trusted active logic control unit can grant the read / write right of the secure storage module to the industrial control device and allow it to start. Based on this, the startup steps of the industrial control device are as follows:
[0056] 1) After the system is powered on, the trusted active logic control unit is activated.
[0057] 2) The trusted active logic control unit obtains the control right of the bus arbitration module and the read / write control right of the secure storage module.
[0058] 3) Read the boot program, operating system kernel, and upper-layer application data into the data buffer in the bus arbitration module.
[0059] 4) The trusted active logic control unit obtains the control right of the trusted core and uses the trusted measurement root of the trusted core to measure the integrity of the boot program, operating system kernel, and upper-layer applications respectively.
[0060] 5) If the measurement result is trusted, the trusted active logic control unit releases the control right of the bus arbitration module, and the industrial control device obtains the control right of the bus arbitration module, reads the data in the data buffer of the bus arbitration module, decrypts and loads it into the memory, and starts the system.
[0061] 6) If the measurement fails, the trusted active logic control unit performs a system backup and recovery operation and reboots.
[0062] Furthermore, when the industrial control device starts the system, the trusted active logic control unit is in the main control position. If it is found that the content in the secure storage module fails the verification during startup, the trusted active logic control unit issues an instruction to occupy the bus for system backup and recovery. Among them, the system backup and recovery process includes:
[0063] (1) Read the backed-up content from the backup and recovery module, that is, the backup and recovery resources.
[0064] 2) Write the backup content into the data buffer in the bus arbitration module.
[0065] 3) Copy the data in the data buffer of the bus arbitration module to the secure storage module.
[0066] 4) The trusted active logic control unit sets the write protection of the secure storage module to ensure that the information therein cannot be modified, and the size of the backup data and the base address where the backup data is stored have been set in the bus arbitration module and are not made public.
[0067] 5) After the system backup and recovery are completed, the trusted active logic control unit grants the control right of the bus arbitration module to the industrial control device and reboots the system.
[0068] The trusted active control logic unit, bus arbitration, secure storage, backup and recovery and other modules are used to obtain the operating status information of the system, power supply and peripherals, and make control decisions based on this information to generate control commands.
[0069] Based on the same inventive concept, the embodiment of the present application also provides a control method for the dual-core trusted security hardware system involved above, as Figure 2 shown, the control method includes:
[0070] Step 200: Determine the bus protocol to be followed based on the operating information of the industrial control device.
[0071] Step 201: Retrieve the data corresponding to the industrial control device based on the bus protocol to be followed.
[0072] Step 202: Use the trusted measurement root to measure whether the retrieved data is trustworthy.
[0073] Step 203: When the retrieved data is trustworthy, generate a control command based on the retrieved data. The control command is used to complete the reconstruction of hardware resources.
[0074] Step 204: Convert the control command into a control arbitration command, release the control right based on the control arbitration command, and complete the trusted control of the reconstructed hardware resources based on the control right. The control right is the control right of the bus arbitration module.
[0075] Step 205: When the retrieved data is not trustworthy, obtain the backup resources and perform the backup and recovery operation.
[0076] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, database, or other medium used in the embodiments provided in this application can include at least one of non-volatile and volatile memories. Non-volatile memories can include read-only memory (ROM), magnetic tapes, floppy disks, flash memories, optical memories, high-density embedded non-volatile memories, resistive random-access memories (ReRAM), magnetoresistive random-access memories (MRAM), ferroelectric random-access memories (FRAM), phase change memories (PCM), graphene memories, etc. Volatile memories can include random access memory (RAM) or external cache memories, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc.
[0077] The databases involved in the embodiments provided in this application can include at least one of relational databases and non-relational databases. Non-relational databases can include distributed databases based on blockchain, etc., without limitation. The processors involved in the embodiments provided in this application can be general-purpose processors, central processors, graphics processors, digital signal processors, programmable logics, data processing logics based on quantum computing, etc., without limitation.
[0078] The technical features of the above embodiments can be combined arbitrarily. For the sake of concise description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification.
[0079] In this article, specific examples are used to elaborate on the principles and implementation manners of this application. The descriptions of the above embodiments are only used to help understand the method and its core idea of this application; at the same time, for those of ordinary skill in the art, according to the idea of this application, there will be changes in the specific implementation manners and application scopes. In summary, the content of this specification should not be construed as a limitation to this application.
Claims
1. A dual-core trusted and secure hardware system, characterized in that: The dual-core trusted security hardware system includes: a control core and a trusted core; The control core exchanges data with the trusted core; the control core is used to implement hardware function calls and information management of industrial control equipment; The trusted core includes a trusted cryptographic module; the trusted cryptographic module is used to generate a trusted measurement root; the trusted core is used to provide a trusted cryptographic service for the control core based on the trusted measurement root.
2. The dual-core trusted and secure hardware system according to claim 1, characterized in that: The control core and the trusted core exchange data via the AXI bus.
3. The dual-core trusted and secure hardware system according to claim 1, characterized in that: The control core is an ARM processing unit.
4. The dual-core trusted and secure hardware system according to claim 1, characterized in that: The trusted core is an FPGA processing unit.
5. The dual-core trusted and secure hardware system according to claim 1, characterized in that: The control core includes: a bus arbitration module, a trusted active logic control unit, a reconfigurable area, a secure storage module and a backup recovery module; The bus arbitration module, the reconfigurable area, the secure storage module and the backup recovery module all exchange information with the trusted active logic control unit; the secure storage module exchanges data with the trusted cryptographic module; The secure storage module is used to store data; the stored data includes: boot files, operating system kernel and upper application code; the backup and recovery module is used to store backup and recovery resources; The bus arbitration module is used to determine the bus protocol to be followed based on the operation information of the industrial control device; the trusted active logic control unit retrieves the data corresponding to the industrial control device stored in the security storage module based on the bus protocol to be followed, and stores the retrieved data in the bus arbitration module; the trusted active logic control unit uses the trusted measurement root to measure whether the retrieved data is credible; when the retrieved data is credible, the trusted active logic control unit generates a control command based on the retrieved data; the reconfigurable area completes the reconstruction of hardware resources based on the control command; the trusted active logic control unit converts the control command into a control arbitration command, and releases the control right of the bus arbitration module based on the control arbitration command; the industrial control device obtains the control right of the bus arbitration module, and completes the trusted control of the reconstructed hardware resources based on the control right; When the retrieved data is untrustworthy, the trusted active logic control unit retrieves the backup recovery resource and performs a backup recovery operation.
6. The dual-core trusted and secure hardware system according to claim 5, characterized in that: The control core also includes: a controller unit; The controller unit exchanges information with the bus arbitration module and the industrial control device respectively; the controller unit is used to obtain operation information, bus information and hardware resource reconstruction information of the industrial control device.
7. The dual-core trusted and secure hardware system according to claim 6, characterized in that: The controller unit includes: one or more of an I / O bus controller, an Ethernet controller, a MODBUS controller, a power supply controller and a monitoring module.
8. The dual-core trusted and secure hardware system according to claim 1, characterized in that: The control core also includes a bus interface; the bus interface is used to connect to the trusted cryptographic module or the bus module of the industrial device.
9. The dual-core trusted and secure hardware system according to claim 8, characterized in that: The bus interface includes an SPI bus interface and / or an I 2 C bus interface; the bus module has an SPI bus and / or I 2 C-bus module.
10. A control method for a dual-core trusted security hardware system, characterized in that: The control method comprises: Determine the bus protocol to be followed based on the operation information of the industrial control equipment; Retrieve data corresponding to industrial control equipment based on the bus protocol followed; Use the trusted measurement root to measure whether the retrieved data is trustworthy; When the retrieved data is credible, a control command is generated based on the retrieved data; the control command is used to complete the hardware resource reconstruction; Converting the control command into a control arbitration command, and releasing the control right based on the control arbitration command, and completing the trusted control of the reconstructed hardware resources based on the control right; the control right is the control right of the bus arbitration module; When the retrieved data is unreliable, obtain backup resources and perform backup and recovery operations.