Electronic seal RISC-V processing method for realizing data stream integrity
By using LLVM compiler and dedicated hardware modules in the RISC-V processor for data flow integrity verification, the problem of weak prevention of memory data flow attacks and large performance overhead of protection solutions is solved, and efficient data flow integrity protection and comprehensive data security guarantees are achieved.
Patent Information
- Application Number
- CN202510034598.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-09
- Publication Date
- 2025-05-27
AI Technical Summary
The prior art has weakened the ability to prevent memory data flow attacks from RISC-V processors, and the existing data flow integrity protection schemes have high performance overhead or high resource consumption, making it difficult to widely use in resource-constrained electronic seal systems.
By using the LLVM compiler to perform value flow analysis, identifying information is allocated to the memory instructions in the target program, arriving definition set information is generated, and the data flow integrity verification instruction is inserted into the target program, and data flow integrity verification is used to perform data flow integrity verification using a dedicated hardware verification module.
It realizes efficient data flow integrity protection in the RISC-V architecture, reduces analysis complexity and verification overhead, is suitable for resource-constrained electronic sealing systems, and provides comprehensive data security guarantees.
Smart Images

Figure CN120046199A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of power system safety technology, and in particular to an electronic seal RISC-V processing method for achieving data flow integrity. Background Art
[0002] In the field of power system security, electronic seals, as a key device for protecting equipment integrity, are of great significance for preventing illegal operations and protecting equipment safety. With the rapid development of the power Internet of Things, low-power processors based on the RISC-V architecture are increasingly widely used in electronic seal systems due to their open source characteristics, low power consumption advantages, and high cost performance. However, in practical applications, the data security protection mechanism of RISC-V processors is relatively weak, especially in preventing memory data stream attacks. Existing data stream integrity protection schemes mainly rely on software implementation, such as static analysis and runtime verification based on the LLVM compiler, but such schemes often introduce significant performance overhead. In addition, although some hardware-assisted security solutions can provide strong protection capabilities, their complex implementation mechanisms and high hardware resource overhead make them difficult to be widely used in resource-constrained electronic seal systems.
[0003] At present, the data flow integrity protection schemes commonly used in the industry mainly include lightweight verification methods based on physical unclonable functions and non-control data attack detection methods based on program dependency graphs. Although these schemes have shown certain protection effects in specific application scenarios, they still have many limitations. For example, although the scheme based on physical unclonable functions has good lightweight characteristics, its security depends to a large extent on the stability of physical characteristics, and it is difficult to cope with complex data flow attacks. Although the scheme based on program dependency graphs can analyze the control flow and data flow relationship of the program more comprehensively, its implementation complexity is high and the runtime overhead is large, which makes it difficult to meet the strict requirements of the electronic seal system for real-time performance and resource consumption. Summary of the invention
[0004] In view of the above-mentioned problems, the present invention is proposed.
[0005] Therefore, the present invention provides an electronic seal RISC-V processing method for achieving data flow integrity, which can solve the problems mentioned in the background technology.
[0006] To solve the above technical problems, the present invention provides the following technical solutions: an electronic seal RISC-V processing method for realizing data flow integrity, comprising: using an LLVM compiler to perform value flow analysis on a target program, assigning identification information to memory instructions in the target program, and generating arrival definition set information of the memory instructions;
[0007] Inserting a data flow integrity verification instruction into the target program, wherein the data flow integrity verification instruction is used to transmit the identification information to the data flow integrity verification module when the program is executed;
[0008] Based on the arrival definition set information, the data flow integrity verification module performs data flow integrity verification on the memory read and write operations of the target program.
[0009] As a preferred solution of the electronic seal RISC-V processing method for realizing data flow integrity described in the present invention, the data flow integrity verification includes: recording the identification information of the write operation and its target address to the arrival definition table; obtaining the identification information of the read operation and its target address; retrieving the arrival definition table to obtain the write operation identification information corresponding to the target address; if the write operation identification information belongs to the arrival definition set of the read operation, the read operation verification passes; if the write operation identification information does not belong to the arrival definition set of the read operation, a data flow integrity violation exception is triggered.
[0010] As a preferred solution of the electronic seal RISC-V processing method for realizing data flow integrity described in the present invention, the data flow integrity verification also includes storing the data flow integrity verification request to be verified into the DFI request FIFO queue; the data flow integrity verification request includes instruction identification information, operation type information and target address information; the verification request is read from the DFI request FIFO queue in a first-in-first-out order; if the DFI request FIFO queue is full, suspending instruction submission until there is a vacancy in the queue.
[0011] As a preferred solution of the electronic seal RISC-V processing method for realizing data flow integrity described in the present invention, the data flow integrity verification also includes recording verified memory read operation information in a dynamic redundant load pruning buffer; for a new memory read operation, retrieving the dynamic redundant load pruning buffer; if the target address and identification information of the new memory read operation are the same as a record in the buffer, then skipping the verification of the memory read operation, otherwise performing verification and storing the verification result in the buffer.
[0012] As a preferred solution of the electronic seal RISC-V processing method for realizing data flow integrity described in the present invention, wherein: the data flow integrity verification also includes configuring an arrival definition table cache, an arrival definition graph cache and an arrival definition set cache; the arrival definition table cache stores a mapping between the most recently accessed target address and write operation identification information; the arrival definition graph cache stores data dependencies between instructions; the arrival definition set cache stores the arrival definition set of the read operation; if the cache misses, the main memory is accessed to obtain the corresponding information.
[0013] As a preferred solution of the electronic seal RISC-V processing method for realizing data flow integrity described in the present invention, wherein: the instruction identification information adopts ID i Indicates, where i is the instruction number; the operation type information includes a read operation identifier R and a write operation identifier W; the target address information is in the form of Addr m Indicates, where m is the memory address number; the DFI request is represented by a triple (ID i ,Op,Addr m ), where Op∈R,W.
[0014] As a preferred solution of the electronic seal RISC-V processing method for realizing data stream integrity described in the present invention, wherein:
[0015] To further solve the above technical problems, the present invention provides the following technical solutions: a system for electronic seal RISC-V processing to realize data flow integrity, comprising: the LLVM compiler performs static analysis on the target program, including: constructing a control flow graph and identifying basic block boundaries; analyzing data dependencies between instructions; generating memory alias analysis results; allocating memory instruction identification information based on the analysis results; and establishing a program dependency graph at the basic block granularity.
[0016] A computer device comprises a memory and a processor, wherein the memory stores a computer program, and wherein when the processor executes the computer program, the steps of the electronic seal RISC-V processing method for achieving data stream integrity as described above are implemented.
[0017] A computer-readable storage medium having a computer program stored thereon, characterized in that when the computer program is executed by a processor, the steps of the electronic seal RISC-V processing method for achieving data stream integrity as described above are implemented.
[0018] Beneficial effects of the present invention: The present invention realizes an efficient data flow integrity protection mechanism in the RISC-V architecture by integrating LLVM compiler static analysis, customized instruction insertion and dedicated hardware verification module. The static analysis module generates arrival definition set information through value flow analysis, which significantly reduces the analysis complexity compared with the traditional full program analysis method; the instruction insertion module uses lightweight customized RISC-V instructions to transmit DFI information, minimizing the insertion overhead; the integrity verification module effectively reduces the blocking effect of the verification process on the processor core through the DFI request FIFO queue buffer mechanism and dynamic redundant load pruning technology. At the same time, the three-level dedicated DFI cache (arrival definition table cache, arrival definition graph cache and arrival definition set cache) structure of the present invention further reduces memory access delay by caching frequently accessed verification data. This software and hardware collaborative design enables the present invention to provide comprehensive data flow integrity protection for the electronic seal system while maintaining low hardware resource overhead (the average performance loss is significantly lower than the DFI solution based on software implementation), and is particularly suitable for application in resource-constrained RISC-V architecture electronic seal systems. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other accompanying drawings can be obtained based on these accompanying drawings without paying creative work.
[0020] Figure 1 It is a flow chart of the overall method in the present invention;
[0021] Figure 2 This is a flow chart of DFI verification of RVDFIES in the present invention;
[0022] Figure 3 A diagram of a computer device in the present invention. DETAILED DESCRIPTION
[0023] In order to make the above-mentioned purposes, features and advantages of the present invention more obvious and easy to understand, the specific implementation methods of the present invention are described in detail below in conjunction with the drawings of the specification. Obviously, the described embodiments are part of the embodiments of the present invention, but not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary persons in the art without creative work should fall within the scope of protection of the present invention.
[0024] In the following description, many specific details are set forth to facilitate a full understanding of the present invention, but the present invention may also be implemented in other ways different from those described herein, and those skilled in the art may make similar generalizations without violating the connotation of the present invention. Therefore, the present invention is not limited to the specific embodiments disclosed below.
[0025] Example 1, reference Figure 1 , as an embodiment of the present invention, provides an electronic seal RISC-V processing method for achieving data stream integrity.
[0026] Figure 1 An overall flow chart of an electronic seal RISC-V processing method for realizing data flow integrity is shown, including: S1: using the LLVM compiler to perform value flow analysis on the target program, assigning identification information to the memory instructions in the target program, and generating arrival definition set information of the memory instructions;
[0027] S2: inserting a data flow integrity verification instruction into the target program, the data flow integrity verification instruction is used to transmit identification information to the data flow integrity verification module when the program is executed;
[0028] S3: Based on the arrival definition set information, the data flow integrity verification module performs data flow integrity verification on the memory read and write operations of the target program.
[0029] It should be noted that this method first uses the LLVM compiler to perform value flow analysis on the target program, assigns identification information to memory instructions and generates arrival definition set information. Compared with traditional full-program analysis, this LLVM-based static analysis method significantly reduces the complexity of analysis by limiting the analysis scope to memory instructions and their related data flows. Subsequently, the method inserts data flow integrity verification instructions into the target program. These verification instructions use a customized RISC-V instruction format and are specifically used to transmit identification information to the verification module when the program is executed. This lightweight instruction insertion method avoids the problem of inserting a large amount of auxiliary code in traditional methods and minimizes the insertion overhead. Finally, the method verifies the memory read and write operations of the target program based on the arrival definition set information generated in the early stage through the data flow integrity verification module. The verification module uses a hardware acceleration mechanism to transfer the verification logic from the processor core to dedicated hardware for execution, effectively reducing the impact of the verification process on the main processing pipeline. This design concept of software and hardware collaboration, while achieving strict data flow integrity protection, makes this solution particularly suitable for deployment in resource-constrained RISC-V architecture electronic seals through optimized static analysis, lightweight instruction insertion, and hardware accelerated verification. It can provide strong data security protection while maintaining low system overhead.
[0030] This method determines the data dependency between memory instructions through static analysis, and combines lightweight instruction instrumentation and hardware accelerated verification. It not only solves the problem of high performance overhead of traditional software DFI solutions, but also avoids the defect of high resource consumption of pure hardware solutions. It achieves a good balance between performance and resource overhead while ensuring verification accuracy. Especially in resource-constrained scenarios such as RISC-V architecture electronic seals, the advantages of this solution are more prominent.
[0031] Furthermore, the data flow integrity verification includes: recording the identification information of the write operation and its target address to the arrival definition table; obtaining the identification information of the read operation and its target address; searching the arrival definition table to obtain the write operation identification information corresponding to the target address; if the write operation identification information belongs to the arrival definition set of the read operation, the read operation verification passes; if the write operation identification information does not belong to the arrival definition set of the read operation, a data flow integrity violation exception is triggered.
[0032] It should be noted that this embodiment focuses on the basic process of data flow integrity verification. In the RISC-V electronic seal system, in order to ensure the integrity of the data flow, the present invention designs an efficient verification mechanism. The verification mechanism first records the identification information of the write operation and its target address to the arrival definition table. This recording mechanism enables the system to accurately track the most recent write operation of each memory location. When performing a read operation, the system obtains the identification information and target address of the read operation, and retrieves the arrival definition table to obtain the write operation identification information corresponding to the target address. Subsequently, the system compares the retrieved write operation identification information with the arrival definition set of the read operation. If the write operation identification information belongs to the arrival definition set of the read operation, it indicates that the read operation accesses a legitimate data source and the verification passes; conversely, if the write operation identification information does not belong to the arrival definition set of the read operation, it indicates that the data may be illegally modified or there is a data flow anomaly, and the system will trigger a data flow integrity violation anomaly.
[0033] The key point of this verification mechanism is that it adopts a lightweight verification process, which significantly reduces the verification overhead by quickly retrieving and comparing operations to the definition table. Compared with the traditional full-program analysis method, this solution limits the verification scope to the actual memory access operation, avoiding redundant checks. Especially in resource-constrained scenarios such as RISC-V electronic seals, this lightweight verification mechanism not only ensures the strict requirements of data flow integrity, but also minimizes performance impact. Practice has shown that while maintaining the same security strength, the performance overhead of this verification mechanism is only about 50% of that of the traditional software DFI solution. In addition, this solution accelerates the verification process through hardware, which can detect and respond to data flow anomalies more quickly than pure software implementation solutions, thereby improving the real-time performance and reliability of the system.
[0034] It should be noted that this data flow integrity verification mechanism is not only applicable to conventional memory read and write operations, but can also effectively prevent complex attack scenarios such as buffer overflow, data replay, etc. Through strict arrival definition set verification, the system can ensure that each memory read operation accesses a legitimate data source, thereby providing comprehensive data flow integrity protection for the electronic seal system.
[0035] Furthermore, the data flow integrity verification also includes storing the data flow integrity verification request to be verified into the DFI request FIFO queue; the data flow integrity verification request includes instruction identification information, operation type information and target address information; reading the verification request from the DFI request FIFO queue in a first-in-first-out order; if the DFI request FIFO queue is full, suspending instruction submission until there is a vacancy in the queue.
[0036] Furthermore, the data flow integrity verification also includes recording verified memory read operation information in a dynamic redundant load pruning buffer; for a new memory read operation, retrieving the dynamic redundant load pruning buffer; if the target address and identification information of the new memory read operation are the same as a record in the buffer, then skipping the verification of the memory read operation, otherwise performing verification and storing the verification result in the buffer.
[0037] It should be noted that the focus here is on the system performance optimization mechanism. In order to solve the performance bottleneck problem that may occur when the RISC-V electronic seal system performs data flow integrity verification, the present invention designs a two-level performance optimization mechanism.
[0038] The first level of optimization uses the DFI request FIFO queue mechanism. Specifically, the system stores the data flow integrity verification request to be verified into the DFI request FIFO queue. Each verification request contains three key elements: instruction identification information, operation type information, and target address information. The system processes verification requests in a first-in-first-out order. This design ensures the consistency of the verification order and the program execution order. When the DFI request FIFO queue reaches the preset capacity limit, the system will suspend instruction submission until there is a vacancy in the queue. This back pressure mechanism can effectively prevent the loss or overwriting of verification requests. Compared with the traditional synchronous verification scheme, the FIFO queue mechanism allows the processor core to continue to execute subsequent instructions after submitting the verification request, significantly reducing the waiting time of the processor.
[0039] The second level optimization introduces a dynamic redundant load pruning mechanism. The system records verified memory read operation information in a dynamic redundant load pruning buffer. When encountering a new memory read operation, the buffer is searched first. If the target address and identification information of the new read operation are the same as a record in the buffer, the verification process can be skipped directly. Otherwise, the full verification process is executed and the results are stored in the buffer. This optimization mechanism is particularly suitable for repeated memory access patterns that frequently appear in loop structures, and can significantly reduce redundant verification operations.
[0040] The collaborative work of the two-level optimization mechanism greatly improves system performance. Experimental data shows that in a typical electronic seal application scenario, the DFI request FIFO queue can reduce processor waiting time by an average of 40%, while the dynamic redundant load pruning mechanism reduces the number of verifications by an average of 35%. This performance improvement is more significant in loop-intensive programs, where the verification overhead can be reduced by up to 60%. It is worth noting that these optimizations do not affect the security of verification, because the FIFO queue ensures the correctness of the verification order, and dynamic redundant load pruning only skips repeated verifications that confirm security.
[0041] The optimization mechanism of the present invention breaks through the limitation of the traditional DFI solution that is difficult to balance performance and security. Through clever queue management and redundancy identification, the system performance is significantly improved while ensuring the integrity of verification, which is particularly suitable for the resource-constrained RISC-V electronic seal system. This optimization strategy of software and hardware collaboration not only solves the problem of high verification overhead, but also provides a scalable performance optimization paradigm, providing new design ideas for similar security verification systems.
[0042] Furthermore, data flow integrity verification also includes configuring the arrival definition table cache, the arrival definition graph cache and the arrival definition set cache; the arrival definition table cache stores the mapping between the most recently accessed target address and the write operation identification information; the arrival definition graph cache stores the data dependencies between instructions; the arrival definition set cache stores the arrival definition sets of read operations; if the cache misses, the main memory is accessed to obtain the corresponding information.
[0043] It should be noted that the design and implementation of the three-level DFI cache structure is mainly described here. Aiming at the performance bottleneck problem caused by frequent memory access during the data flow integrity verification process in the RISC-V electronic seal system, the present invention designs a three-level dedicated cache structure, including an arrival definition table cache, an arrival definition graph cache, and an arrival definition set cache.
[0044] First, the arrival definition table cache is specifically used to store the mapping relationship between the recently accessed target address and the write operation identification information. This layer of cache uses a direct mapping method to map the memory address to the cache line according to the modulus division method. Each cache line contains the target address, write operation identification, and valid bit information. When the system performs a write operation, the relevant information will update the arrival definition table cache and the main memory at the same time; when performing a read operation verification, the system will first query the cache, significantly reducing the frequency of accessing the main memory.
[0045] Secondly, the arrival definition graph cache stores the data dependencies between instructions. This level of cache adopts a two-level associative structure and uses an improved LRU (least recently used) replacement strategy, which not only records direct data dependencies but also includes transitive dependencies. This design enables the system to quickly determine whether there is data dependency between any two instructions, avoiding the overhead of repeatedly building a dependency graph.
[0046] Thirdly, the arrival definition set cache stores the arrival definition set information of the read operation. Considering the variable size of the arrival definition set, this layer of cache adopts a fully associative structure and uses an improved FIFO replacement strategy. In addition to storing the arrival definition set, the cache line also contains an access frequency counter for dynamically adjusting the cache replacement strategy. When the cache misses, the system accesses the main memory to obtain the complete arrival definition set information and updates the cache content according to the access pattern.
[0047] The collaborative work of the three-level cache structure significantly improves the verification efficiency. Experimental data shows that in a typical electronic seal application scenario, this cache structure can reduce the number of main memory accesses by 75% on average. Especially in program segments with strong locality, the cache hit rate can reach more than 90%, reducing the verification delay from hundreds of clock cycles to single-digit cycles. In addition, this multi-level cache structure also shows good scalability. By adjusting the size and association of each level of cache, it can flexibly adapt to application requirements of different scales.
[0048] The three-level cache structure of the present invention breaks through the limitation of large memory access delay in traditional DFI implementation. Through special cache design and optimized replacement strategy, this solution significantly improves verification performance while minimizing hardware overhead. Especially in the resource-constrained RISC-V electronic seal system, this cache-based optimization strategy provides a solution that takes into account both performance and resource efficiency. Compared with the prior art, this solution not only reduces verification delay, but also provides better performance predictability, providing reliable protection for electronic seal applications with high real-time requirements.
[0049] It is worth noting that the design of this multi-level cache structure fully considers the characteristics of the electronic seal system. Through the hierarchical cache and targeted optimization of different types of verification data, the hardware resource usage is minimized while ensuring the verification efficiency. This balanced design makes this solution particularly suitable for deployment in resource-constrained embedded systems, providing a practical reference solution for similar application scenarios.
[0050] Furthermore, the instruction identification information uses ID i Indicates, where i is the instruction number; the operation type information includes the read operation identifier R and the write operation identifier W; the target address information uses Addr m Indicates, where m is the memory address number; DFI request is represented as a triple (ID i ,Op,Addr m ), where Op∈R,W.
[0051] Furthermore, the LLVM compiler performs static analysis on the target program including: building a control flow graph and identifying basic block boundaries; analyzing data dependencies between instructions; generating memory alias analysis results; allocating memory instruction identification information based on the analysis results; and establishing a program dependency graph at the basic block granularity.
[0052] It should be noted that the basic information representation method and static analysis process are mainly described here. In order to ensure the accuracy and efficiency of data flow integrity verification in the RISC-V electronic seal system, the present invention designs a standardized information representation method and a complete static analysis mechanism.
[0053] In terms of information representation, the present invention adopts a formalized triple representation method. Specifically, the instruction identification information is represented by ID i Indicated by , where i is the instruction number. This continuous numbering method facilitates tracking the instruction dependencies during program execution. The operation type information uses R and W to identify read operations and write operations respectively. This binary division not only ensures the completeness of the representation, but also reduces storage overhead. The target address information uses Addr m Indicates that m is the memory address number. Based on the above basic elements, the data flow integrity verification request is standardized into a triple (ID i ,Op,Addr m ), where Op∈R, W. This formal representation method not only provides a unified interface specification, but also simplifies the implementation of verification logic.
[0054] The triplet representation method of the present invention adopts a carefully designed encoding format. Specifically, the instruction identifier ID iIt uses a 32-bit unsigned integer representation, where the upper 8 bits are the basic block number, the middle 16 bits are the function number, and the lower 8 bits are the sequence number within the block. This hierarchical encoding method facilitates the rapid location of the scope and context information of the instruction; the operation type Op is encoded in 1-bit binary, where the read operation R is 0 and the write operation W is 1, which minimizes the storage overhead; the address information Addr m It uses the system word length (32 bits or 64 bits) and contains the memory segment identifier and the offset information within the segment. i ,Op,Addr m ) requires only 9 bytes of storage space on a 32-bit system and 13 bytes on a 64-bit system, which not only enables compact data representation, but also facilitates fast processing and comparison operations at the hardware level, fully meeting application requirements in resource-constrained scenarios.
[0055] In terms of static analysis, the present invention implements a comprehensive program analysis process based on the LLVM compiler. First, the system builds a control flow graph and identifies basic block boundaries. This step provides a basic framework for subsequent data flow analysis. Subsequently, the system analyzes the data dependencies between instructions, paying special attention to the dependencies between memory operation instructions. On this basis, the system generates memory alias analysis results, which are crucial for accurately identifying different instructions that may access the same memory location. Based on the above analysis results, the system assigns unique identification information to each memory instruction, and finally establishes a program dependency graph at the basic block granularity.
[0056] The present invention adopts a basic block granularity analysis strategy instead of traditional instruction-level analysis. This granularity selection achieves a good balance between analysis accuracy and efficiency. Experimental data show that compared with instruction-level analysis, basic block granularity analysis reduces static analysis time by an average of 65%, while losing less than 5% of analysis accuracy. This optimization effect is particularly significant when processing large programs, and can reduce the analysis time from hours to minutes.
[0057] The design of the present invention breaks through the limitation of low efficiency of static analysis in traditional DFI implementation. Through standardized information representation and optimized static analysis process, the solution significantly improves the analysis efficiency while ensuring the accuracy of analysis. Especially in resource-constrained scenarios such as RISC-V electronic seals, this lightweight static analysis solution provides a practical solution. Compared with the prior art, this solution not only improves the analysis efficiency, but also provides more accurate dependency information for the verification process, thereby improving the overall verification performance.
[0058] It is worth noting that the design of this static analysis solution fully considers the characteristics of the electronic seal system, and significantly reduces the runtime verification overhead by completing most of the analysis work at the compilation stage. This design idea makes this solution particularly suitable for use in scenarios with high real-time requirements, and provides a design paradigm for similar systems.
[0059] In summary, the present invention realizes an efficient data flow integrity verification mechanism by integrating a dedicated hardware module and an improved micro-architecture into the RISC-V architecture. First, the performance overhead of data flow integrity verification is significantly reduced through the hardware acceleration mechanism; second, the dynamic redundant load pruning technology is used to further optimize the system performance; finally, the dedicated DFI cache structure is used to achieve efficient protection of key data. This enables the system to provide strong data security protection for electronic seals while maintaining low hardware resource consumption.
[0060] Embodiment 2 is an embodiment of the present invention, which provides an electronic seal RISC-V processing system for realizing data flow integrity, including:
[0061] The static analysis module is used to perform value flow analysis on the target program using the LLVM compiler, assign identification information to the memory instructions in the target program, and generate the arrival definition set information of the memory instructions;
[0062] An instruction insertion module, used for inserting a data flow integrity verification instruction into a target program, wherein the data flow integrity verification instruction is used for transmitting identification information to the data flow integrity verification module when the program is executed;
[0063] The integrity verification module is used to verify the data flow integrity of the memory read and write operations of the target program based on the arrival definition set information.
[0064] Example 3, reference Figure 3, is an embodiment of the present invention, which is different from the previous embodiment in that: if the function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium, including several instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), disk or optical disk and other media that can store program codes.
[0065] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as an ordered list of executable instructions for implementing logical functions, and can be embodied in any computer-readable medium for use by an instruction execution system, device or apparatus (such as a computer-based system, a system including a processor, or other system that can fetch instructions from an instruction execution system, device or apparatus and execute instructions), or in conjunction with such instruction execution systems, devices or apparatuses. For the purposes of this specification, "computer-readable medium" can be any device that can contain, store, communicate, propagate or transmit a program for use by an instruction execution system, device or apparatus, or in conjunction with such instruction execution systems, devices or apparatuses.
[0066] More specific examples of computer-readable media (a non-exhaustive list) include the following: an electrical connection with one or more wires (electronic device), a portable computer disk case (magnetic device), a random access memory (RAM), a read-only memory (ROM), an erasable and programmable read-only memory (EPROM or flash memory), an optical fiber device, and a portable compact disk read-only memory (CDROM). In addition, the computer-readable medium may even be a paper or other suitable medium on which the program is printed, since the program may be obtained electronically, for example, by optically scanning the paper or other medium, followed by editing, deciphering or, if necessary, processing in another suitable manner, and then stored in a computer memory.
[0067] It should be understood that the various parts of the present invention can be implemented by hardware, software, firmware or a combination thereof. In the above-mentioned embodiments, a plurality of steps or methods can be implemented by software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented by hardware, as in another embodiment, it can be implemented by any one of the following technologies known in the art or their combination: a discrete logic circuit having a logic gate circuit for implementing a logic function for a data signal, a dedicated integrated circuit having a suitable combination of logic gate circuits, a programmable gate array (PGA), a field programmable gate array (FPGA), etc.
[0068] Example 4, reference Figure 2 , which is an embodiment of the present invention, provides an electronic seal RISC-V processing system for realizing data flow integrity. The system integrates specialized hardware modules and improved micro-architecture in the RISC-V architecture to realize complete data flow integrity verification while maintaining low performance overhead. The main principles are described as follows:
[0069] RISC-V architecture extension: The present invention proposes an extension of the RISC-V architecture to support DFI functionality by adding customized instructions and hardware modules. These customized instructions are used to transmit DFI-related information between the processor core and the DFI verification module.
[0070] DFI verification module: Design a dedicated DFI verification module that accelerates simple execution logic in a lightweight manner, alleviating the DFI burden on the processor pipeline and thus reducing performance overhead.
[0071] Hardware Resource Optimization: Further reduce performance loss and improve security by proposing a series of enhancements, including support for function returns and library protection, dynamic redundant load pruning, and a dedicated DFI cache.
[0072] The connection relationship of each component and its working principle:
[0073] Information transmission and instrumentation: DFI-related information (such as instruction ID (identifier), type and target address) is encoded and transmitted to the DFI verification module through customized RISC-V instructions (such as custom0). This information is used to perform DFI checks in the DFI verification module.
[0074] DFI request FIFO queue: To reduce core blocking caused by the busy DFI verification module, a FIFO queue buffer is introduced to temporarily store DFI requests until the DFI verification module is available.
[0075] Dynamic Redundant Load Pruning Buffer: A lightweight hardware design is proposed to dynamically prune redundant DFI requests at runtime, reducing unnecessary DFI verification and thus reducing performance overhead.
[0076] Dedicated DFI cache: To reduce memory access latency, three dedicated caches (arrival definition table, arrival definition graph, and arrival definition set cache) are designed to store data that needs to be frequently accessed during the DFI verification process.
[0077] The overall workflow of the robot is as follows: first, static analysis and arrival definition set generation are performed, and the target program is statically analyzed using the LLVM compiler infrastructure and the LLVM-based static value flow analysis (framework. A unique ID is assigned to each memory instruction, and an arrival definition set is generated for each read instruction. Then, a customized RISC-V instruction is inserted into the target program to send the DFI request and related information to the DFI verification module at runtime. During program execution, the core triggers a DFI request whenever a memory instruction that needs to be verified is submitted. The DFI request is sent to the DFI controller for verification, including checking the instruction ID, type, and target address.
[0078] On this basis, the read and write operations are processed. For write operations, the DFI controller updates the arrival definition table to record the instruction ID of the latest write target address. For read operations, the DFI controller reads the instruction ID of the latest write target address from the arrival definition table and checks whether it is in the arrival definition set of the read instruction. If the arrival definition set of the read operation contains the ID of the write operation, the DFI verification passes; if not, a DFI violation exception is triggered. The DFI request FIFO is introduced to reduce the core blocking caused by the busy DFI verification module. Finally, a dynamic redundant load trimming buffer is implemented to reduce unnecessary DFI verification and reduce performance overhead.
[0079] It is important to note that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit the present invention. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solutions of the present invention may be modified or replaced by equivalents without departing from the spirit and scope of the technical solutions of the present invention, which should all be included in the scope of the claims of the present invention.
Claims
1. A RISC-V processing method for electronic seals to achieve data flow integrity, characterized in that: include: Performing value flow analysis on a target program using an LLVM compiler, assigning identification information to memory instructions in the target program, and generating arrival definition set information of the memory instructions; Inserting a data flow integrity verification instruction into the target program, wherein the data flow integrity verification instruction is used to transmit the identification information to the data flow integrity verification module when the program is executed; Based on the arrival definition set information, the data flow integrity verification module performs data flow integrity verification on the memory read and write operations of the target program.
2. The electronic seal RISC-V processing method for realizing data flow integrity as claimed in claim 1, characterized in that: The data flow integrity verification includes: recording the identification information of the write operation and its target address to the arrival definition table; obtaining the identification information of the read operation and its target address; searching the arrival definition table to obtain the write operation identification information corresponding to the target address; if the write operation identification information belongs to the arrival definition set of the read operation, the read operation verification passes; if the write operation identification information does not belong to the arrival definition set of the read operation, a data flow integrity violation exception is triggered.
3. The electronic seal RISC-V processing method for realizing data flow integrity as claimed in claim 1, characterized in that: The data flow integrity verification also includes storing a data flow integrity verification request to be verified into a DFI request FIFO queue; the data flow integrity verification request includes instruction identification information, operation type information and target address information; reading the verification request from the DFI request FIFO queue in a first-in-first-out order; If the DFI request FIFO queue is full, instruction submission is suspended until a vacancy appears in the queue.
4. The electronic seal RISC-V processing method for realizing data flow integrity as claimed in claim 3, characterized in that: The data flow integrity verification also includes recording verified memory read operation information in a dynamic redundant load pruning buffer; for a new memory read operation, retrieving the dynamic redundant load pruning buffer; if the target address and identification information of the new memory read operation are the same as a record in the buffer, skipping the verification of the memory read operation, otherwise performing verification and storing the verification result in the buffer.
5. The electronic seal RISC-V processing method for realizing data flow integrity as claimed in claim 4, characterized in that: The data flow integrity verification also includes configuring an arrival definition table cache, an arrival definition graph cache, and an arrival definition set cache; the arrival definition table cache stores a mapping between the most recently accessed target address and the write operation identification information; the arrival definition graph cache stores data dependencies between instructions; The arrival definition set cache stores the arrival definition set of the read operation; if the cache misses, the main memory is accessed to obtain the corresponding information.
6. The electronic seal RISC-V processing method for realizing data flow integrity as claimed in claim 5, characterized in that: The instruction identification information adopts ID i Indicates, where i is the instruction number; the operation type information includes a read operation identifier R and a write operation identifier W; the target address information is in the form of Addr m Indicates, where m is the memory address number; the DFI request is represented by a triple (ID i ,Op,Addr m ), where Op∈R,W.
7. The electronic seal RISC-V processing method for realizing data flow integrity as claimed in claim 6, characterized in that: The LLVM compiler performs static analysis on the target program, including: constructing a control flow graph, identifying basic block boundaries; analyzing data dependencies between instructions; generating memory alias analysis results; allocating memory instruction identification information based on the analysis results; and establishing a program dependency graph at the basic block granularity.
8. A system using the electronic seal RISC-V processing method for realizing data stream integrity as claimed in any one of claims 1 to 7, characterized in that: include: A static analysis module, used to perform value flow analysis on a target program using an LLVM compiler, assign identification information to memory instructions in the target program, and generate arrival definition set information of the memory instructions; An instruction insertion module, used for inserting a data flow integrity verification instruction into the target program, wherein the data flow integrity verification instruction is used for transmitting the identification information to the data flow integrity verification module when the program is executed; An integrity verification module is used to perform data flow integrity verification on the memory read and write operations of the target program based on the arrival definition set information.
9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the electronic seal RISC-V processing method for realizing data stream integrity described in any one of claims 1 to 7 are implemented.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the electronic seal RISC-V processing method for realizing data stream integrity described in any one of claims 1 to 7 are implemented.