Verification device and method
By designing a central processing unit, volatile memory, non-volatile memory and related circuits in the verification device, the firmware data is quickly and efficiently verified during power-on, and the problem of low firmware verification efficiency in the prior art affecting the startup speed is solved.
Patent Information
- Application Number
- CN202411398908.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-11-30
- Filing Date
- 2024-10-09
- Publication Date
- 2025-05-30
AI Technical Summary
Under the demand for rapid startup, due to the access speed of non-volatile memory and the efficiency of the central processing unit to execute verification programs, the firmware verification efficiency is low, which affects the startup speed.
A verification device is designed, including a central processing unit, a volatile memory, a non-volatile memory, a first direct memory access circuit and a verification circuit. The unverified firmware data is moved to the volatile memory by reading instructions from the non-volatile memory through the first direct memory access circuit, and the data is verified by the verification circuit upon receiving the trigger signal.
It realizes faster and more efficient verification of firmware data during booting, reduces dependence on central processing units, and improves boot speed.
Smart Images

Figure CN120066591A_ABST
Abstract
Description
Technical Field
[0001] Embodiments of the present invention are mainly related to a verification technology, and particularly to a verification technology for verifying firmware data in a volatile memory. Background Art
[0002] In a system with a non-volatile memory, firmware is usually stored in the non-volatile memory. According to the concept and implementation of the root of trust (RoT) in security, the firmware stored in the non-volatile memory must be successfully verified before it can be executed by the central processing unit (CPU).
[0003] However, under the requirement of fast boot-up, limited by the access speed of the non-volatile memory itself and the low efficiency of the central processing unit in executing the verification program to verify the firmware, the boot-up speed will be affected.
[0004] Therefore, how to more efficiently and quickly verify the firmware when the device boots up will be a research topic worthy of study. Summary of the Invention
[0005] In view of the above problems of the prior art, embodiments of the present invention provide a verification device and method.
[0006] According to an embodiment of the present invention, a verification device is provided. The verification device includes a central processing unit, a volatile memory, a non-volatile memory, a first direct memory access circuit, and a verification circuit. The central processing unit can enter a waiting mode after the verification device is powered on and reset. The non-volatile memory can store a plurality of instructions and an unverified firmware data. The first direct memory access circuit can read a first instruction from the non-volatile memory and, according to the first instruction, move the unverified firmware data from the non-volatile memory to the volatile memory. After receiving a trigger signal from the first direct memory access circuit, the verification circuit can be used to verify the unverified firmware data stored in the volatile memory.
[0007] In some embodiments, the first instruction may include a source location, a target location, and a data size corresponding to the unverified firmware data.
[0008] In some embodiments, the verification circuit may include a second direct memory access circuit. In addition, the second direct memory access circuit can read a second instruction from the non-volatile memory and, according to the second instruction, read the unverified firmware data from the volatile memory.
[0009] In some embodiments, the second direct memory access circuit may further obtain a verification key according to a second instruction. In addition, the verification circuit may select a verification method according to the second instruction, and verify the unverified firmware data in the volatile memory according to the verification method and the verification key.
[0010] In some embodiments, after the verification circuit successfully verifies the unverified firmware data, the verification circuit may send a release signal to the central processing unit. After receiving the release signal, the central processing unit may execute the verified unverified firmware data stored in the volatile memory.
[0011] In some embodiments, the second instruction may include a target location, a data size, a key location corresponding to the unverified firmware data, and a verification method to be selected.
[0012] According to an embodiment of the present invention, a verification method is provided. The above verification method is applicable to a verification device. The above verification method may include the following steps. After the above verification device is powered on and reset, a central processing unit of the above verification device enters a waiting mode; through a first direct memory access circuit of the above verification device, a first instruction is read from a non-volatile memory of the above verification device; through the first direct memory access circuit, according to the first instruction, an unverified firmware data is moved from the non-volatile memory to a volatile memory of the above verification device; and through a verification circuit, after receiving a trigger signal from the first direct memory access circuit, the unverified firmware data stored in the volatile memory is verified.
[0013] Regarding other additional features and advantages of the present invention, those skilled in the art can make some modifications and refinements according to the verification device and method disclosed in the implementation method of this case without departing from the spirit and scope of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS
[0014] Figure 1 FIG. is a block diagram showing a verification device 100 according to an embodiment of the present invention.
[0015] Figure 2 FIG. is a flowchart of the verification method according to an embodiment of the present invention.
[0016] REFERENCE NUMERALS:
[0017] 100: Verification device
[0018] 110: Central processing unit
[0019] 120: First DMA circuit
[0020] 130: Verification circuit
[0021] 131: Second DMA circuit
[0022] 140: Volatile memory
[0023] 150: Non-volatile memory
[0024] 160: Key storage circuit
[0025] S210 - S240: Steps Detailed implementation manner
[0026] What is described in this section is the preferred way to implement the present invention, aiming to illustrate the spirit of the present invention rather than to limit the protection scope of the present invention. The protection scope of the present invention shall be subject to the scope defined by the appended claims.
[0027] Figure 1 To show a block diagram of a verification device 100 according to an embodiment of the present invention. As Figure 1 shown, the verification device 100 may include a central processing unit (CPU) 110, a first direct memory access (DMA) circuit 120, a verification circuit 130, a volatile memory 140, a non-volatile memory 150, and a key storage circuit 160. Note that, in Figure 1 the block diagram shown, it is only for convenience of illustrating the embodiments of the present invention, but the present invention is not limited to Figure 1 this. Other elements may also be included in the verification device 100.
[0028] According to an embodiment of the present invention, the verification device 100 can be applied in a micro controller unit (MCU), a microprocessor unit (MPU), or a device having a similar component architecture to the verification device 100.
[0029] According to an embodiment of the present invention, the central processing unit 110 can be used to execute the verified firmware data. In addition, after the verification device 100 is powered on and reset, the central processing unit 110 can first enter a waiting mode.
[0030] According to an embodiment of the present invention, the first direct memory access circuit 120 can be used to move unverified firmware data (e.g., firmware program code) from the non-volatile memory 150 to the volatile memory 140 according to instructions (e.g., the first instruction) obtained from the non-volatile memory 150. In addition, the first direct memory access circuit 120 can trigger the verification circuit 130 to perform a verification operation.
[0031] According to an embodiment of the present invention, the verification circuit 130 may include a second direct memory access circuit 131. The second direct memory access circuit 131 can read the unverified firmware data stored in the volatile memory 140 and obtain the key stored in the key storage circuit 160 according to instructions (e.g., the second instruction) obtained from the non-volatile memory 150. The verification circuit 130 can verify the unverified firmware data according to the instructions obtained by the second direct memory access circuit 131.
[0032] According to an embodiment of the present invention, the volatile memory 140 may be a random access memory (RAM), but the present invention is not limited thereto. The volatile memory 140 can be used to store unverified firmware data from the non-volatile memory 150.
[0033] According to an embodiment of the present invention, the non-volatile memory 150 may be a flash memory, a read only memory (ROM), but the present invention is not limited thereto. The non-volatile memory 150 can be used to store a plurality of instructions and unverified firmware data.
[0034] According to an embodiment of the present invention, the key storage circuit 160 can be used to store the key required for the verification operation to be performed by the verification circuit 130.
[0035] According to an embodiment of the present invention, when the verification device 100 is powered on and reset, the central processing unit 110 will enter a waiting mode. That is to say, in the present invention, the central processing unit 110 may not need to perform the relevant operations for verifying the firmware data. After the firmware data is verified, the central processing unit 110 can execute the firmware data.
[0036] In addition, after the verification device 100 is powered on and reset, the first direct memory access circuit 120 can obtain a first instruction from the non-volatile memory 150, and move the unverified firmware data from the non-volatile memory 150 to the volatile memory 140 according to the first instruction. The first instruction can be pre-stored in a reserved space of the non-volatile memory 150. That is, after the verification device 100 is powered on and reset, the first direct memory access circuit 120 can obtain the first instruction from this reserved space. According to an embodiment of the present invention, the first instruction may include a source location corresponding to the unverified firmware data (i.e., the location in the non-volatile memory 150 where this unverified firmware data is stored), a target location (i.e., the location in the volatile memory 140 where this unverified firmware data is stored), and a data size (i.e., the size of this unverified firmware data), but the present invention is not limited thereto.
[0037] In addition, after the first direct memory access circuit 120 moves the unverified firmware data from the non-volatile memory 150 to the volatile memory 140, the first direct memory access circuit 120 can send a trigger signal to the verification circuit 130 to trigger the verification circuit 130 to start the verification operation.
[0038] After the verification circuit 130 receives the trigger signal from the first direct memory access circuit 120, the second direct memory access circuit 131 can obtain a second instruction from the non-volatile memory 150, and according to the second instruction, read the unverified firmware data stored in the volatile memory 140. The second instruction can be pre-stored in a reserved space of the non-volatile memory 150. That is, after the verification circuit 130 receives the trigger signal, the second direct memory access circuit 131 can obtain the second instruction from this reserved space. According to an embodiment of the present invention, the second instruction may include a target location corresponding to the unverified firmware data (i.e., the location in the volatile memory 140 where this unverified firmware data is stored), a data size (i.e., the size of this unverified firmware data), a key location (i.e., the location in the key storage circuit 160 where the key is stored), and a verification method to be selected (i.e., the verification method for verifying the unverified firmware data), but the present invention is not limited thereto. The second direct memory access circuit 131 can also obtain the key for the verification operation from the key storage circuit 160 according to the second instruction.
[0039] After the second direct memory access circuit 131 reads the unverified firmware data and obtains the key, the verification circuit 130 can verify the unverified firmware data stored in the volatile memory 140 according to the verification method (e.g., Elliptic Curve Digital Signature Algorithm (ECDSA), but the present invention is not limited thereto) and the key indicated by the second instruction.
[0040] After the verification circuit 130 successfully verifies the unverified firmware data stored in the volatile memory 140, the verification circuit 130 can send a release signal to the central processing unit 110. After the central processing unit 110 receives the release signal, the central processing unit can leave the wait mode and start executing the verified firmware data stored in the volatile memory 110.
[0041] Figure 2 It is a flowchart of a verification method according to an embodiment of the present invention. The verification method can be applied to the verification device 100. As Figure 2 shown, in step S210, after the verification device 100 is powered on and reset, a central processing unit of the verification device 100 can enter a wait mode.
[0042] In step S220, a first direct memory access circuit of the verification device 100 can read a first instruction from a non-volatile memory of the verification device 100.
[0043] In step S230, the first direct memory access circuit of the verification device 100 can move an unverified firmware data from the non-volatile memory of the verification device 100 to a volatile memory of the verification device 100 according to the first instruction.
[0044] In step S240, after a verification circuit of the verification device 100 receives a trigger signal from the first direct memory access circuit, the verification circuit of the verification device 100 will verify the unverified firmware data stored in the volatile memory.
[0045] According to an embodiment of the present invention, in the verification method, the first instruction may include a source location, a target location, and a data size corresponding to the unverified firmware data.
[0046] According to an embodiment of the present invention, in the verification method, a second direct memory access circuit of the verification circuit of the verification device 100 can read a second instruction from the non-volatile memory of the verification device 100. Then, the second direct memory access circuit of the verification circuit of the verification device 100 can read the unverified firmware data from the volatile memory of the verification device 100 according to the second instruction.
[0047] According to an embodiment of the present invention, in the verification method, the second direct memory access circuit of the verification circuit of the verification device 100 can obtain a verification key according to the second instruction. Then, the verification circuit of the verification device 100 can select a verification method according to the second instruction and verify the unverified firmware data stored in the volatile memory of the verification device 100 according to the verification method and the verification key.
[0048] According to an embodiment of the present invention, in the verification method, when the verification circuit of the verification device 100 successfully verifies the unverified firmware data described above, the verification circuit of the verification device 100 transmits a release signal to the central processing unit of the verification device 100. Subsequently, when the central processing unit of the verification device 100 receives the release signal, the central processing unit of the verification device 100 can execute the verified unverified firmware data stored in the volatile memory.
[0049] According to an embodiment of the present invention, in the verification method, the second instruction may include a target location, a data size, a key location, and a verification method to be selected corresponding to the unverified firmware data described above.
[0050] According to the verification method proposed by the embodiment of the present invention, when the verification device is powered on, the unverified firmware data can be verified in the volatile memory of the verification device. In addition, according to the verification method proposed by the embodiment of the present invention, the verification device can perform the operation of verifying firmware data without passing through the central processing unit. Therefore, when the verification device is powered on, the verification method proposed by the embodiment of the present invention can perform the operation of verifying firmware data more efficiently and quickly to meet the requirement of fast startup.
[0051] The serial numbers in this specification and the claims, such as "first", "second", etc., are only for convenience of description and there is no sequential precedence relationship between them.
[0052] The steps of the methods and algorithms disclosed in the specification of the present invention can be directly applied to hardware, software modules, or a combination of both by executing a processor. A software module (including executable instructions and related data) and other data can be stored in a data memory, such as a random access memory (RAM), flash memory, read-only memory (ROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), register, hard disk, portable hard disk, compact disc read-only memory (CD-ROM), DVD, or any other computer-readable storage media format in the prior art in this field. A storage medium can be coupled to a machine device, for example, a computer / processor (for the sake of illustration, represented as a processor in this specification). The above-mentioned processor can read information (such as program code) from and write information to the storage medium. A storage medium can integrate a processor. An application-specific integrated circuit (ASIC) includes a processor and a storage medium. A user device includes an application-specific integrated circuit. In other words, the processor and the storage medium are included in the user device in a way that does not directly connect to the user device. In addition, in some embodiments, any suitable computer program product includes a readable storage medium, where the readable storage medium includes program code related to one or more disclosed embodiments. In some embodiments, the computer program product may include packaging materials.
[0053] The above paragraphs are described at multiple levels. Obviously, the teachings herein can be implemented in various ways, and any specific architecture or function disclosed in the examples is only a representative situation. According to the teachings herein, any person skilled in the art should understand that each level disclosed herein can be implemented independently or two or more levels can be combined and implemented.
[0054] Although the present disclosure has been disclosed as above with embodiments, it is not intended to limit the present disclosure. Any person skilled in the art can make some modifications and refinements without departing from the spirit and scope of the present disclosure. Therefore, the protection scope of the invention shall be subject to the scope defined by the appended claims.
Claims
1. A verification device, characterized in that: include: A central processing unit enters a waiting mode after the verification device is powered on and reset; a volatile memory; a non-volatile memory storing a plurality of instructions and an unverified firmware data; a first direct memory access circuit, reading a first instruction from the non-volatile memory, and moving the unverified firmware data from the non-volatile memory to the volatile memory according to the first instruction; as well as A verification circuit is used to verify the unverified firmware data stored in the volatile memory after receiving a trigger signal from the first direct memory access circuit.
2. The verification device according to claim 1, characterized in that: The first instruction includes a source location, a target location and a data size corresponding to the unverified firmware data.
3. The verification device according to claim 1, characterized in that: The verification circuit includes a second direct memory access circuit, wherein the second direct memory access circuit reads a second instruction from the non-volatile memory, and reads the unverified firmware data from the volatile memory according to the second instruction.
4. The verification device according to claim 3, characterized in that: The second direct memory access circuit further obtains a verification key according to the second instruction, and the verification circuit selects a verification method according to the second instruction, and verifies the unverified firmware data according to the verification method and the verification key.
5. The verification device according to claim 4, characterized in that: When the verification circuit successfully verifies the unverified firmware data, the verification circuit transmits a release signal to the central processing unit, and after the central processing unit receives the release signal, the central processing unit executes the verified unverified firmware data stored in the volatile memory.
6. The verification device according to claim 3, characterized in that: The second instruction includes a target location corresponding to the unverified firmware data, a data size, a key location, and a verification method to be selected.
7. A verification method, characterized in that: A verification device is applicable, comprising: After the verification device is powered on and reset, a central processing unit of the verification device enters a waiting mode; Reading a first instruction from a non-volatile memory of the verification device through a first direct memory access circuit of the verification device; By means of the first direct memory access circuit, according to the first instruction, an unverified firmware data is moved from the non-volatile memory to a volatile memory of the verification device; and The unverified firmware data stored in the volatile memory is verified by a verification circuit after receiving a trigger signal from the first direct memory access circuit.
8. The verification method according to claim 7, characterized in that: Also includes: Reading a second instruction from the non-volatile memory through a second direct memory access circuit of the verification circuit; and The unverified firmware data is read from the volatile memory according to the second instruction through the second direct memory access circuit.
9. The verification method according to claim 8, characterized in that: Also includes: Obtaining a verification key according to the second instruction through the second direct memory access circuit; and A verification method is selected through the verification circuit according to the second instruction, and the unverified firmware data is verified according to the verification method and the verification key.
10. The verification method according to claim 9, characterized in that: Also includes: When the verification circuit successfully verifies the unverified firmware data, a release signal is transmitted to the central processing unit through the verification circuit; and After the central processing unit receives the release signal, the verified unverified firmware data stored in the volatile memory is executed by the central processing unit.