Method, device and equipment for detecting encrypted IP (Internet Protocol) in running process of system on chip

By setting up a multi-level security detection architecture in the system on chip and using the enabled security strategy to detect encrypted IP, the problem of difficult to deal with hardware vulnerabilities and Trojans in the existing technology is solved, and flexible and reasonable hardware security response measures are achieved.

CN120145377APending Publication Date: 2025-06-13INST OF MICROELECTRONICS CHINESE ACAD OF SCI LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311694446.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-12-11
Publication Date
2025-06-13

AI Technical Summary

Technical Problem

The existing technology is difficult to achieve flexible and reasonable hardware vulnerabilities and Trojan response measures, and it is impossible to effectively deal with a variety of possible hardware security problems.

Method used

By obtaining the security policies enabled during the operation of the system on chip, setting up the security workflow for encrypted IP, including multi-level check nodes, using the security policies enabled to perform multi-level security detection on the working data of the encrypted IP to generate security detection results.

Benefits of technology

Real-time detection of encrypted IP is realized, and the impact of security policies on the system on chip is reduced through a multi-level security detection architecture, which improves the flexibility and efficiency of dealing with hardware vulnerabilities and Trojans.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120145377A_ABST
    Figure CN120145377A_ABST
Patent Text Reader

Abstract

The invention discloses a method, a device and equipment for detecting an encrypted IP (Internet Protocol) in an operation process of a system on chip, relates to the technical field of integrated circuit design, and aims to reduce the influence of execution of a security policy on the system on chip by designing a multi-level security detection architecture, realize flexible and reasonable emergency vulnerability and Trojan coping measures and improve the security of the system on chip. Therefore, the utilization efficiency of the system-on-chip resources is improved. The method comprises the steps that a security policy enabled to be opened in the running process of the system-on-chip is obtained, a security workflow of an encrypted IP is set according to the security policy enabled to be opened, multi-level check nodes arranged for working data are arranged on the security workflow, the working data of the encrypted IP during task execution are obtained at the multi-level check nodes, and the security workflow of the encrypted IP is set according to the multi-level check nodes. And performing multi-level security detection on the working data by using the enabled security policy, and generating a security detection result of the encrypted IP according to state response information fed back by the execution equipment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of integrated circuit design, and particularly to a method, device and equipment for detecting encrypted IP during the operation of a system on a chip. Background Art

[0002] With the continuous development of integrated circuit (IC) technology, the manufacturing scale and precision of chips have undergone huge changes, which pose a daunting challenge to the work requirements of IC manufacturers. To improve production efficiency and optimize costs, more and more IC manufacturers use third-party encrypted IP in the manufacturing process to simplify the production process. However, the security of third-party encrypted IP cannot be guaranteed. For example, there may be malicious designers or loopholes in the design work, which may lead to hardware trojans or hardware viruses in the actual use of encrypted IP.

[0003] In related technologies, encrypted IP can be detected for security using conventional detection means such as pre-silicon security verification technology and post-silicon security testing technology. However, considering that hardware trojans usually come with corresponding triggering conditions, conventional detection means are not sufficient to handle all potential working states. Moreover, conventional detection means are usually implemented based on known circuit structures. When there are no detailed details of third-party encrypted IP, it is difficult to implement detection, and it is impossible to achieve flexible and reasonable countermeasures against hardware vulnerabilities and trojans, and it is difficult to cope with various possible hardware security problems. Summary of the Invention

[0004] In view of this, the present application provides a method, device and equipment for detecting encrypted IP during the operation of a system on a chip, mainly aiming to solve the problem that the prior art cannot achieve flexible and reasonable countermeasures against hardware vulnerabilities and trojans and is difficult to cope with various possible hardware security problems.

[0005] According to the first aspect of the present application, a method for detecting encrypted IP during the operation of a system on a chip is provided, including:

[0006] Obtaining the enabled security policies during the operation of the system on a chip;

[0007] Setting the secure working process of the encrypted IP according to the enabled security policies, and multiple levels of inspection nodes for working data are arranged on the secure working process;

[0008] Obtaining the working data of the encrypted IP when performing tasks at the multiple levels of inspection nodes, and performing multi-level security detection on the working data using the enabled security policies;

[0009] Generating a security detection result of the encrypted IP according to the status response information fed back by the execution device.

[0010] Further, before enabling the security policies enabled during the operation of the system-on-chip, the method further includes:

[0011] Pre-configuring policy information, where the policy information includes different types of security policies, the detection mechanisms corresponding to the security policies, and the response measures corresponding to the security policies;

[0012] Receiving policy control information and changing the policy enabling state during the operation of the system-on-chip according to the policy control information.

[0013] Further, the obtaining of the security policies enabled during the operation of the system-on-chip includes:

[0014] In response to the change in the policy enabling state during the operation of the system-on-chip, traversing and reading the enabling states of each security policy in the policy information;

[0015] Obtaining the security policies enabled during the operation of the system-on-chip according to the enabling states of each security policy in the policy information.

[0016] Further, the setting of the security working process of the encryption IP according to the enabled security policies includes:

[0017] Obtaining the data flow direction of the encryption IP when executing a task, and determining at least one inspection node for data security detection in the data flow direction according to the enabled security policies;

[0018] Arranging multi-level detection mechanisms for the at least one inspection node to obtain the security working process of the encryption IP.

[0019] Further, after setting the security working process of the encryption IP according to the enabled security policies, the method further includes:

[0020] Controlling the encryption IP to execute a task according to the security working process, obtaining the permission priorities of the input and / or output interfaces when the encryption IP executes the task, where the permission priorities include the first priority for the input interface to receive data and the second priority for the output interface to send data;

[0021] Controlling the input interface of the encryption IP to receive the data to be processed according to the first priority when executing the task according to the permission priorities;

[0022] Controlling the output interface of the encryption IP to send the processed data according to the second priority when executing the task according to the permission priorities.

[0023] Further, obtaining the working data of the encrypted IP during task execution at the multi-level check node, and performing multi-level security detection on the working data by using the enabled security policy, including:

[0024] When the enabled security policy is the access monitoring policy, obtaining the ciphertext data output by the encrypted IP during task execution at the multi-level check node, counting the number of times the ciphertext data is read by the host before the operation is completed, and performing security detection on the ciphertext data by determining whether the number of reads is the set number;

[0025] When the enabled security policy is the timeout monitoring policy, obtaining the working time output by the encrypted IP during task execution at the multi-level check node, and determining whether the working time is within the set working time range to perform security detection on the working time;

[0026] When the enabled security policy is the data detection policy, obtaining the working information output by the encrypted IP during task execution at the multi-level check node, and performing security detection on the working time by comparing whether the working information is consistent with the expected result;

[0027] When the enabled security policy is the address detection policy, obtaining the working address output by the encrypted IP during task execution at the multi-level check node, and performing security detection on the working time by comparing whether the working address is within the preset address range;

[0028] When the enabled security policy is the flag bit detection policy, obtaining the flag bit output by the encrypted IP during task execution at the multi-level check node, and performing security detection on the working time by determining whether the flip of the flag bit meets the expected requirements;

[0029] When the enabled security policy is the module-level detection policy, obtaining the set interaction working conversion mechanism of the encrypted IP during task execution at the multi-level check node, and detecting whether there is an abnormal state jump behavior in the interaction module of the encrypted IP through the set interaction working conversion mechanism to perform security detection on the working time.

[0030] According to the second aspect of the present application, there is provided a detection device for an encrypted IP during the operation of a system on a chip, including:

[0031] An acquisition unit, configured to acquire the enabled security policy during the operation of the system on a chip;

[0032] A setting unit for setting a security working process of an encrypted IP according to the enabled security policy, where multiple levels of inspection nodes for arranging working data are set on the security working process;

[0033] A detection unit for obtaining the working data of the encrypted IP when performing a task at the multiple levels of inspection nodes, and performing multi-level security detection on the working data by using the enabled security policy;

[0034] A generation unit for generating a security detection result of the encrypted IP according to the status response information fed back by the execution device.

[0035] Further, the device further includes:

[0036] A configuration unit for pre-configuring policy information before obtaining the enabled security policy during the operation of the system-on-chip, where the policy information includes different types of security policies, the detection mechanisms corresponding to the security policies, and the response measures corresponding to the security policies;

[0037] A change unit for receiving policy control information and changing the policy enabling status during the operation of the system-on-chip according to the policy control information.

[0038] Further, the obtaining unit is specifically configured to, in response to the change of the policy enabling status during the operation of the system-on-chip, traverse and read the enabling status of each security policy in the policy information; and obtain the enabled security policy during the operation of the system-on-chip according to the enabling status of each security policy in the policy information.

[0039] Further, the setting unit is specifically configured to obtain the data flow direction of the encrypted IP when performing a task, and determine at least one inspection node for data security detection in the data flow direction according to the enabled security policy; and arrange a multi-level detection mechanism for the at least one inspection node to obtain the security working process of the encrypted IP.

[0040] Further, the device further includes:

[0041] A control unit for, after setting the security working process of the encrypted IP according to the enabled security policy, controlling the encrypted IP to perform a task according to the security working process, and obtaining the permission priorities of the input and / or output interfaces when the encrypted IP performs the task, where the permission priorities include the first priority for the input interface to receive data and the second priority for the output interface to send data;

[0042] The control unit is specifically configured to control the input interface to receive the data to be processed according to the first priority when the encrypted IP performs the task according to the permission priorities;

[0043] The control unit is specifically further configured to control the output interface of the encryption IP to send the processed data according to the second priority when the encryption IP executes a task based on the permission priority.

[0044] Further, the detection unit is specifically configured to:

[0045] When the enabled security policy is an access monitoring policy, obtain the ciphertext data output by the encryption IP when executing a task at the multi-level check node, count the number of times the ciphertext data is read by the host before the operation is completed, and perform a security check on the ciphertext data by determining whether the number of reads is a set number;

[0046] When the enabled security policy is a timeout monitoring policy, obtain the working time output by the encryption IP when executing a task at the multi-level check node, and determine whether the working time is within the set working time range to perform a security check on the working time;

[0047] When the enabled security policy is a data detection policy, obtain the working information output by the encryption IP when executing a task at the multi-level check node, and perform a security check on the working time by comparing whether the working information is consistent with the expected result;

[0048] When the enabled security policy is an address detection policy, obtain the working address output by the encryption IP when executing a task at the multi-level check node, and perform a security check on the working time by comparing whether the working address is within the preset address range;

[0049] When the enabled security policy is a flag bit detection policy, obtain the flag bit output by the encryption IP when executing a task at the multi-level check node, and perform a security check on the working time by determining whether the flip of the flag bit meets the expected requirements;

[0050] When the enabled security policy is a module-level detection policy, obtain the set interaction working conversion mechanism of the encryption IP when executing a task at the multi-level check node, and detect whether there is an abnormal state jump behavior in the interaction module of the encryption IP through the set interaction working conversion mechanism to perform a security check on the working time.

[0051] According to the third aspect of the present application, a detection device for an encryption IP during the operation of a system on a chip includes: a security policy control module, at least one encryption IP module, and a main control module;

[0052] The main control module is connected to the policy security control module and is used to control the enabling state of the security policy. The security policy control module is respectively connected to the at least one encryption IP module and is used to perform security detection on the encryption IP by using the enabled security policy when the encryption IP executes tasks.

[0053] According to a fourth aspect of the present application, there is provided a computer device, including a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the steps of the method described in the first aspect above are implemented.

[0054] According to a fifth aspect of the present application, there is provided a readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the method described in the first aspect above are implemented.

[0055] By means of the above technical solutions, for a detection method, device and equipment of an encryption IP during the operation of a system-on-chip provided by the present application, compared with the current conventional detection methods such as pre-silicon security verification technology and post-silicon security testing technology for security detection, the present application obtains the enabled security policy during the operation of the system-on-chip, sets the security working process of the encryption IP according to the enabled security policy. The security working process is provided with multi-level inspection nodes arranged for working data. The working data of the encryption IP when executing tasks is obtained at the multi-level inspection nodes, and the enabled security policy is used to perform multi-level security detection on the working data. According to the status response information fed back by the execution device, a security detection result of the encryption IP is generated. The entire process sets a complete security working process for the encryption IP to ensure that the encryption IP can be detected in real time during task execution. By designing a multi-level security detection architecture, the impact of executing the security policy on the system-on-chip is reduced, and flexible and reasonable emergency vulnerability and trojan response measures are realized, thereby improving the utilization efficiency of the system-on-chip resources.

[0056] The above description is only an overview of the technical solutions of the present application. In order to be able to understand the technical means of the present application more clearly, it can be implemented according to the content of the specification. And in order to make the above and other purposes, features and advantages of the present application more obvious and understandable, the specific embodiments of the present application are specifically listed below. BRIEF DESCRIPTION OF THE DRAWINGS

[0057] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The schematic embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation to the present application. In the drawings:

[0058] Figure 1 It is a flowchart of a method for detecting an encryption IP during the operation of a system-on-chip according to an embodiment of the present application;

[0059] Figure 2 is a schematic flowchart of a method for detecting an encrypted IP during the operation of a system - on - a - chip according to another embodiment of the present application;

[0060] Figure 3 is Figure 1 a schematic flowchart of a specific implementation manner of step 101 in

[0061] Figure 4 is Figure 1 a schematic flowchart of a specific implementation manner of step 102 in

[0062] Figure 5 is a schematic flowchart of a method for detecting an encrypted IP during the operation of a system - on - a - chip according to another embodiment of the present application;

[0063] Figure 6 is a circuit structure diagram inside the encrypted IP during the operation of a system - on - a - chip according to another embodiment of the present application;

[0064] Figure 7 is a flowchart block diagram of the detection process of the encrypted IP during the operation of a system - on - a - chip according to another embodiment of the present application;

[0065] Figure 8A is a flowchart block diagram of the part for obtaining control authority during the detection process of the encrypted IP according to another embodiment of the present application;

[0066] Figure 8B is a flowchart block diagram of the part for enabling a policy during the detection process of the encrypted IP according to another embodiment of the present application;

[0067] Figure 8C is a flowchart block diagram of the part for executing a policy during the detection process of the encrypted IP according to another embodiment of the present application;

[0068] Figure 9 is a schematic structural diagram of a device for detecting an encrypted IP during the operation of a system - on - a - chip according to an embodiment of the present application;

[0069] Figure 10 is a schematic structural diagram of a device of a computer device provided by an embodiment of the present invention. Specific embodiments

[0070] Now, the content of the present invention will be described with reference to several exemplary embodiments. It should be understood that these embodiments are described only to enable those of ordinary skill in the art to better understand and thus implement the content of the present invention, rather than to imply any limitation on the scope of the present invention.

[0071] As used herein, the term "comprising" and its variants are to be construed as open-ended terms meaning "including but not limited to". The term "based on" is to be construed as "at least partially based on". The terms "one embodiment" and "an embodiment" are to be construed as "at least one embodiment". The term "another embodiment" is to be construed as "at least one other embodiment".

[0072] In the related art, the security of encrypted IP can be detected by conventional detection means such as pre-silicon security verification technology and post-silicon security testing technology. However, at present, the pre-silicon security verification technology and post-silicon security testing technology have their limitations and are not sufficient to detect all the hardware Trojans and hardware vulnerabilities that may exist in the encrypted IP. When facing cross-module-level vulnerabilities, there are quite deficiencies in the cross-module state detection of the current processing means, and the multi-module state monitoring has still not been realized. At the same time, hardware Trojans usually come with corresponding trigger conditions, and conventional detection means are not sufficient to handle all potential working states. Moreover, conventional methods are usually implemented based on the known circuit structure, and the detection method is also restricted when there are no detailed details of the third-party IP. Even the currently advanced formal verification tools and related research teams cannot complete the detection of all research vulnerabilities. For example, using Security Path Verification (SPV) has deficiencies in the face of certain security vulnerabilities. In related research, a security framework and a multi-level response method have been proposed, but there is a lack of attention to bus content and cross-module hazards, and a more flexible and less impactful system framework has not been designed.

[0073] To solve this problem, this embodiment provides a method for detecting encrypted IP during the operation of a system-on-chip, as Figure 1 shown. This method is applied to the server for data security detection, and the method specifically includes the following steps:

[0074] 101. Obtain the security policy enabled during the operation of the system-on-chip.

[0075] In various applications, information security has begun to become the focus of attention of individual and enterprise users. From enterprises to individuals, they all hope that their security information or business privacy can be protected completely and reliably. However, in the key processes of information reading, transmission, processing, writing, etc. in the system-on-chip, encrypted IP is required to participate. Due to the key nature of encrypted IP, it is easily regarded as the target of hardware attacks.

[0076] To protect the secure and reliable operation of encrypted IP, embodiments of the present invention preset different types of security policies for different types of security errors. Here, the security policies are mainly set for encrypted IP, specifically including two major categories: the security policy of active inspection and the security policy of passive monitoring. For the security policy of active inspection, it can include data detection, address detection, flag bit detection, and module-level detection. For the security policy of passive monitoring, it can include access monitoring and timeout monitoring. By setting the enable status of different types of security policies, for example, enabling a certain security policy or disabling a certain security policy.

[0077] The execution subject of this embodiment can be a detection device or equipment for encrypted IP during the operation of the system-on-chip, and can be configured on the server side of data security detection. By enabling different security policies during the operation of the system-on-chip, it is possible to detect the operating status, interface information, and cross-module working mechanism of the encrypted IP.

[0078] 102. Set the secure working process of the encrypted IP according to the enabled security policy.

[0079] It can be understood that the enabled security policy can detect the encrypted IP during the operation of the system-on-chip. The specific detection content can be set in the working process of the encrypted IP according to the enabled security policy. For example, for the security policy of data detection, it can detect the input working information of the encrypted IP, and for the security policy of timeout monitoring, it can detect the working time of the encrypted IP.

[0080] Among them, there are multiple levels of inspection nodes arranged for the working data in the secure working process. Usually, there are multiple processing nodes involved in the working process of the encrypted IP. For example, a processing node for encrypting data, a processing node for storing data, etc. Here, the inspection nodes are equivalent to newly added processing nodes according to the enabled security policy, and can be deployed before and / or after the corresponding data processing nodes according to the enabled security policy. For example, if the enabled security policy needs to detect the stored data, the inspection node can be deployed after the processing node for storage. Also, for example, if the enabled security policy needs to detect the working time, the inspection node can be deployed before and after the corresponding working processing node.

[0081] It should be noted that there may be multiple enabled security policies at the same time. At this time, there are multiple inspection nodes for different security policies deployed in the secure working process of the encrypted IP. However, considering the dependency relationship between different processing nodes, there is a corresponding hierarchical dependency between the multiple inspection nodes, and thus the detection nodes arranged for the working data in the secure working process also have a multi-level relationship.

[0082] 103. Obtain the working data of the encrypted IP during task execution at the multi-level inspection node, and perform multi-level security detection on the working data using the enabled security policy.

[0083] In this embodiment, the multi-level inspection node can obtain the required working data according to the security policy when the encrypted IP executes the work task, and use the corresponding detection mechanism of the security policy to perform multi-level security detection on the working data.

[0084] For example, when the enabled security policy is timeout monitoring, the encryption and decryption tasks performed by the encrypted IP need to set an accurate working time range according to the operation cycle. The detection mechanism of timeout monitoring requires that all types of tasks of the encrypted IP must be accurately counted at startup and compared with the predetermined time range. When the working time does not meet the predetermined time range, a response measure is triggered. At this time, the inspection node obtains the working time when the encrypted IP executes the task, and the detection mechanism needs to determine whether the working time is within the predetermined time range to perform security detection on the encrypted IP.

[0085] Also for example, when the enabled security policy is data detection, the encrypted IP is required to output the gate ciphertext correctly and reliably during work. The detection mechanism of data detection requires actively checking the working information such as the complete plaintext, key, and initial vector input to the encrypted IP, and judging whether it is reliable by comparing whether the output content is consistent with the expected result. Otherwise, a response measure is triggered. At this time, the inspection node obtains the working information when the encrypted IP executes the task, and the detection mechanism needs to judge whether the content meets the expected result according to the working information to perform security detection on the encrypted IP.

[0086] 104. Generate the security detection result of the encrypted IP according to the status response information fed back by the execution device.

[0087] Among them, the execution device is equivalent to the functional module that executes the detection mechanism, and this functional module can feed back the corresponding status response information according to the detection result. Here, the status response information includes normal response and abnormal response. If the status response information triggers a response measure, it means that the current work of the encrypted IP is abnormal, the status response information is an abnormal response, and the generated security detection result of the encrypted IP is abnormal. If the status response information does not trigger a response measure, it means that the current work of the encrypted IP is currently secure, and the generated security detection result of the encrypted IP is normal.

[0088] For example, for the security policy of timeout monitoring in the above text, if the function module determines that the working time is not within the predetermined time range, the response measure triggered by the status response information is to roll back the encrypted IP to the initial state, re-execute the task, and report the abnormal information of the encryption time to the main control module. Also, for example, for the security policy of data detection in the above text, if the function module determines that the content of the working information does not meet the expected result, the response measure triggered by the status response information is to report to the main control module that the encrypted IP is unreliable and disable the work of the encrypted IP to ensure the accuracy of the encryption result of the encrypted IP.

[0089] The method for detecting an encrypted IP during the operation of a system-on-chip provided by the embodiments of the present application, compared with the current conventional detection methods such as pre-silicon security verification technology and post-silicon security testing technology in the prior art for security detection, the present application obtains the enabled security policies during the operation of the system-on-chip, sets the security work process of the encrypted IP according to the enabled security policies. The security work process is provided with multi-level check nodes for arranging working data. At the multi-level check nodes, the working data of the encrypted IP during task execution is obtained, and the enabled security policies are used to perform multi-level security detection on the working data. According to the status response information fed back by the execution device, a security detection result of the encrypted IP is generated. The whole process sets a complete security work process for the encrypted IP to ensure that the encrypted IP can be detected in real time during task execution. By designing a multi-level security detection architecture, the impact of executing the security policy on the system-on-chip is reduced, and flexible and reasonable emergency vulnerability and trojan response measures are realized, thereby improving the utilization efficiency of the system-on-chip resources.

[0090] In the above embodiment, considering the flexible control of the policy enabling state, further, as Figure 2 shown, before step 101, the method further includes the following steps:

[0091] 201. Pre-configure policy information.

[0092] 202. Receive policy control information, and change the policy enabling state during the operation of the system-on-chip according to the policy control information.

[0093] In this embodiment, the policy information can be configured in the security policy control module according to the detection requirements. In the initialization state, different types of security policies can be configured for different working types of encrypted IPs. Here, the policy information includes policy type, detection mechanism, and response measure. For example, for the policy type of address detection, the detection mechanism is to detect address errors, and the response measure is to report to the main control module that the current address is abnormal and disable the encrypted IP. For the policy type of module-level detection, the detection mechanism is to detect cross-module errors, and the response measure is to report module anomalies to the main control module and disable the work of the module.

[0094] Among them, the policy control information can be sent by the main control module to the security policy control module, so that the security policy control module controls the enabling status of different security policies according to the policy control information, and executes the enabled security policy for the corresponding encrypted IP. For example, if the policy control information is a security policy for enabling the flag bit detection for the first encrypted IP, then the security policy using the flag bit detection is used to perform security detection on the first encrypted IP. Also for example, if the policy control information is a security policy for enabling access monitoring for the second encrypted IP, then the security policy using access monitoring is used to perform security detection on the second encrypted IP.

[0095] Specifically, different types of security policies and the enabling status corresponding to the security policies are stored in the security policy control module. After receiving the policy control information sent by the main control module, the control word of the security policy is obtained by parsing the policy control information, and then the enabling status of each security policy is adjusted according to the control word of the security policy, and it is determined whether to use the security policy to detect the working data of the encrypted IP during task execution according to the enabling status.

[0096] Specifically, in the above embodiment, as Figure 3 shown, step 101 includes the following steps:

[0097] 301. In response to the change of the policy enabling status during the operation of the system on chip, traverse and read the enabling status of each security policy in the policy information.

[0098] 302. According to the enabling status of each security policy in the policy information, obtain the security policies enabled during the operation of the system on chip.

[0099] It can be understood that after receiving the policy control information, the policy information will update the policy enabling status in real time according to the policy control information. After the policy enabling status is updated, correspondingly, the enabling status of each security policy in the policy information will also be updated accordingly. By reading the enabling status of each security policy, the enabled security policies can be obtained, and then the working data of the encrypted IP during task execution can be securely detected according to the enabled security policies.

[0100] For the enabled security policies, inspection nodes can be set on the working process of the encrypted IP according to the detection mechanism of the security policy. The inspection nodes do not conflict with the working process of the encrypted IP, but are additional processing nodes added to the working process of the encrypted IP. Through the inspection nodes, the working data of the encrypted IP during task execution can be obtained. Specifically, in the above embodiment, as Figure 4 shown, step 102 includes the following steps:

[0101] 401. Obtain the data flow of the encrypted IP during task execution, and determine at least one inspection node for data security detection in the data flow according to the enabled security policy.

[0102] 402. Arrange a multi-level detection mechanism for the at least one inspection node to obtain the security workflow of the encrypted IP.

[0103] Among them, the encrypted IP needs to be connected to other modules during task execution, and the data interaction and communication between the encrypted IP and other system components can be realized through a bus interface, signal line connection or other communication mechanisms. That is to say, the encrypted IP has a data flow during task execution, and the enabled security policy needs to detect the working data in the data flow to ensure the security of the encrypted IP.

[0104] Exemplarily, the data flow of the encrypted IP during task execution is to receive the data sent by the main control module, encrypt the received data and then return it to the main control module. The enabled security policy needs to perform content detection on the received data. At this time, an inspection node can be set at the data reception position, and the received data can be obtained through the inspection node, and the received data can be subjected to content detection according to the detection mechanism.

[0105] It should be noted that there may be multiple enabled security policies at the same time. For multiple enabled security policies, multiple inspection nodes will be set in the data flow. Considering the data flow of the detection nodes, multiple detection nodes corresponding to the detection mechanisms to be detected can form a hierarchical relationship. Through the multi-level detection mechanism deployed in the data flow, the security workflow of the encrypted IP can be realized.

[0106] Considering that the data flow of the encrypted IP during task execution requires an interface to realize data input and output, further, in the above embodiment, as Figure 5 shown, after step 102, the following steps are further included:

[0107] 501. Control the encrypted IP to execute tasks according to the security workflow, and obtain the permission priority of the input and / or output interface of the encrypted IP during task execution.

[0108] 502. Control the input interface of the encrypted IP to receive the data to be processed according to the first priority during task execution according to the permission priority.

[0109] 503. Control the output interface of the encrypted IP to send the processed data according to the second priority during task execution according to the permission priority.

[0110] In this embodiment, during the process of the encryption IP executing a task, it can receive data to be processed through the input interface, and then after performing corresponding processing on the data to be processed, send the processed data through the output interface. Considering the data processing priority of the input and / or output interface, the permission priorities of the input and / or output interface when the encryption IP executes a task can be set in advance. Here, the permission priority includes the first priority for the input interface to receive data and the second priority for the output interface to send data. When the encryption IP executes a task, control the input interface to receive the data to be processed according to the first priority. Correspondingly, when the encryption IP executes a task, control the output interface to send the processed data according to the second priority. The first priority and the second priority can use the same priority. For example, the permission priorities for the input interface to receive the data to be processed and the output interface to send the processed data both use the priority: main control module > other interacting encryption IP modules > policy control module. Of course, the first priority and the second priority can also use different priorities, which are not limited here and can be set according to actual needs.

[0111] Specifically, at the multi-level check node, obtain the working data of the encryption IP when it executes a task. During the process of performing multi-level security detection on the working data using the enabled security policy, the detection mechanism of the security policy can be implemented according to the security work process corresponding to the enabled security policy.

[0112] When the enabled security policy is the access monitoring policy, obtain the ciphertext data output by the encryption IP when it executes a task at the multi-level check node, count the number of times the ciphertext data is read by the host before the operation is completed, and perform a security detection on the ciphertext data by judging whether the number of reads is the set number. Specifically, the plaintext, key, and initial vector input by the encryption IP when it executes a task need to be protected and cannot be maliciously accessed and eavesdropped. Therefore, the access monitoring policy requires that the output ciphertext of the encryption IP can only be read by the host once before all operations are completed. Any additional read behavior will be detected by the access monitoring policy and trigger a response measure. The response measure is to shield the output result of the current content and report an anomaly to the main control module, so as to ensure that the encryption is not leaked.

[0113] When the enabled security policy is the timeout monitoring policy, the working time output by the encrypted IP during task execution is obtained at the multi-level inspection node, and it is judged whether the working time is within the set working time range to perform security detection on the working time. Specifically, the encryption and decryption tasks performed by the encrypted IP need to set an accurate working time range according to the operation cycle. Therefore, the timeout monitoring policy requires that all types of tasks be accurately counted at startup and compared with the predetermined time range. When the working time does not match the predetermined time range, a response measure will be triggered. This response measure is to roll back the encrypted IP to its initial state, re-execute the task, and report the current working task exception to the main control module to ensure the accuracy of the encryption time.

[0114] When the enabled security policy is the data detection policy, the working information output by the encrypted IP during task execution is obtained at the multi-level inspection node, and the working time is security-detected by comparing whether the working information is consistent with the expected result. Specifically, when the encrypted IP executes a task, it is required to output correct and reliable ciphertext. Therefore, the data detection policy requires the active inspection mechanism to input complete working information such as plaintext, key, and initial vector to the encrypted IP, and judge reliability by comparing the consistency between the output content and the expected result. Otherwise, a response measure will be triggered. This response measure is to report that the current encrypted IP is unreliable to the main control module and disable the work of the encrypted IP to ensure the correctness of the encryption result of the encrypted IP, thereby completing the data detection of the bus-level security policy.

[0115] When the enabled security policy is the address detection policy, the working address output by the encrypted IP during task execution is obtained at the multi-level inspection node, and the working time is security-detected by comparing whether the working address is within the preset address range. Specifically, the input data of the encrypted IP needs to be stored in the register at the specified address, and the accuracy of the operation address needs to be ensured. Therefore, the address detection requires the active detection mechanism to input the corresponding working address when reading and writing the encrypted IP and compare it with the predetermined address range. When it is detected that the address change does not meet the expectation, a response measure will be triggered. This response measure is to report that the current working address of the encrypted IP is unreliable to the main control module and disable the work of the encrypted IP to ensure the reliability of the working address of the encrypted IP, and complete the address detection of the bus-level security policy.

[0116] When the enabled security policy is the flag bit detection policy, the flag bits output by the encrypted IP during task execution are obtained at the multi-level check node, and the security detection of the working time is performed by judging whether the flip of the flag bits meets the expected requirements. Specifically, the start and end states of the encryption and decryption of the encrypted IP rely on the control of the flag bits, and it is necessary to ensure that the control of the flag bits is stable enough. Therefore, the flag bit detection mechanism requires the encrypted IP to detect the flag bits while working. When the flip of the flag bits does not meet the expected requirements, a response measure is triggered. The response measure is to roll back the encrypted IP to the initial state, re-execute the task, and count an accident once. When multiple accidents occur continuously, the working state is considered unreliable, and the main control module is reported that the current work is abnormal, so as to ensure the correctness of the working state of the encrypted IP.

[0117] When the enabled security policy is the module-level detection policy, the working conversion mechanism set for interaction during the task execution of the encrypted IP is obtained at the multi-level check node, and whether there is an abnormal state jump behavior in the interaction module of the encrypted IP is detected through the set working conversion mechanism for interaction, so as to perform the security detection of the working time. Specifically, when the encrypted IP interacts with other modules, it is necessary to ensure not only the security of the encrypted IP itself but also the security of other modules. Therefore, the module-level detection requires that all modules interacting with the encrypted IP set a definite working conversion mechanism. When an abnormal state jump behavior occurs in other modules, such as entering an irrelevant / undefined / error state, resulting in the inability to execute the pre-designed work process sequentially, a response measure will be triggered. The response measure is to report to the main control module that the state of this module is unreliable and disable the work of this module, so as to ensure that the encrypted IP will not be invaded by cross-module errors, thereby completing the cross-module-level Trojan detection.

[0118] Further, as Figures 1-5 a specific implementation of the method, the embodiment of the present application provides a detection device for the encrypted IP during the operation of the system-on-chip. The device includes: a security policy control module, at least one encrypted IP module, and a main control module;

[0119] The main control module is connected to the policy security control module and is used to control the enabled state of the security policy. The security policy control module is respectively connected to the at least one encrypted IP module and is used to perform security detection on the encrypted IP using the enabled security policy when the encrypted IP executes a task.

[0120] In an actual application scenario, the above at least one encrypted IP module is illustrated by taking two encrypted IP cores, namely AES wrapper and FIFO wrapper, as an example. At this time, the internal circuit structure of the encrypted IP during the operation of the system-on-chip is as Figure 6 shown Figure 6It includes four modules, namely, a security policy control module, an AES wrapper module, a FIFO wrapper module, and a main control module.

[0121] The security policy control module includes a data storage sub-module, a policy enabling sub-module, an active check sub-module, and a response measure sub-module; the specific working process is as follows: the data storage sub-module stores the working data sent by the main control module as the working data for active check; the policy enabling sub-module receives the security policies configured by the main control module and triggers different security policies according to the enabling status of the security policies; the active check sub-module reads the stored working data according to the enabled security policies and detects at least one encryption IP module through the bus interface; the response measure sub-module determines whether to trigger an exception response based on the check feedback of the active check sub-module. If triggered, an interrupt exception report is sent to the main control module through the bus interface.

[0122] The AES wrapper module includes an input / output interface sub-module, a passive monitoring sub-module, a response measure sub-module, and an ASE encryption / decryption IP sub-module. The specific working process is as follows: the input / output interface sub-module selects the data received through the bus interface according to the permission priority. Here, the default order of permission priority is the main control module > FIFO wrapper module > security policy control module. At the same time, it determines the enabling status of the security policies in the passive monitoring sub-module according to the received policy enabling information. The ASE encryption / decryption IP sub-module is used to perform encryption and decryption operations on the data at the input interface and transmit it to the output interface. Correspondingly, the output interface sends data to the bus according to the permission priority. The passive monitoring sub-module determines the enabled security policies through the policy enabling information transmitted through the input interface. For example, it monitors the read / write status of the input / output interface or the working time of the AES encryption / decryption IP. The response measure sub-module determines whether to trigger a response based on the security policy output of the passive monitoring sub-module. If triggered, an interrupt exception report is sent to the main control module through the bus interface.

[0123] The FIFO wrapper module includes an active read / write sub-module, a data storage sub-module, a module-level check sub-module, and a response measure sub-module. The specific working process is as follows: The active read / write sub-module is used to receive the enabling information of the module-level security policy sent by the main control module and determine the single-signature read / write information, and then send the read / write data to the AES wrapper module. The data storage sub-module is responsible for receiving the pre-stored read / write data from the main control module as the working data for active read / write. The module-level check sub-module determines the enabling status of the security policy by receiving the enabling information sent by the active read / write sub-module. For example, it tracks the defense of the active read / write state machine, records the jump state of the state machine, compares whether it meets the preset conditions, and sends the status parameters to the response measure sub-module according to this status. The response measure sub-module determines whether to trigger a response according to the status parameters. If triggered, it reports an interrupt exception to the main control module via the bus interface;

[0124] The main control module includes a working control sub-module, a policy control sub-module, and an exception control sub-module. The specific working process is as follows: The working control main module controls the execution order of tasks of the encryption IP and sends the data to be processed to at least one encryption IP; The policy control sub-module sends the policy enabling information to the policy security controller; The exception control sub-module receives the exception information sent by the response measure sub-module and processes the encryption IP according to the exception information. For example, it disables the current encryption IP.

[0125] Combined with the internal circuit structure of the encryption IP during the operation of the system-on-chip in the above text, the detection process of the specific encryption IP is as Figure 7 shown Figure 7 The detection process in includes three parts. Part A is the control permission acquisition part, Part B is the policy enabling part, and Part C is the policy execution part. After the system starts, the stored data is initialized, and then the permission priorities of the input and / or output interfaces corresponding to the encryption IP are determined by reading the data of different modules. Specifically, it first judges whether it is read by the main control module, then judges whether it is read by the FIFO, and finally judges whether it is read by the policy security control module. According to the judgment results, the control permission acquisition part is controlled, as shown in 8A. Then, the security policy is enabled by judging whether the policy enabling is turned on. Specifically, after the security policy is started, it is judged whether different types of security policies are enabled respectively to complete the policy enabling part, as shown in 8B. If the security policy is not enabled, the encryption / decryption work is performed without the security policy and then the task ends, and the system stops running. If the security policy is enabled, the encryption IP is abnormally detected according to the enabled security policy. Specifically, different types of security policies correspond to different execution processes, and after the execution, it is judged whether an exception occurs. If so, an interrupt is sent, the task ends, and the system stops running. Otherwise, the task ends and the system stops running, completing the policy execution part, as shown in Figure 8C .

[0126] Further, as Figures 1-5 a specific implementation of the method, an embodiment of the present application provides a detection device for encrypted IP during the operation of a system on a chip, as Figure 9 shown. The device includes: an acquisition unit 61, a setting unit 62, a detection unit 63, and a generation unit 64.

[0127] The acquisition unit 61 is used to acquire the security policies enabled during the operation of the system on a chip;

[0128] The setting unit 62 is used to set the secure working process of the encrypted IP according to the enabled security policies, and multiple-level check nodes for arranging working data are set on the secure working process;

[0129] The detection unit 63 is used to acquire the working data of the encrypted IP when performing tasks at the multiple-level check nodes, and perform multi-level security detection on the working data by using the enabled security policies;

[0130] The generation unit 64 is used to generate a security detection result of the encrypted IP according to the status response information fed back by the execution device.

[0131] The detection device for encrypted IP during the operation of the system on a chip provided by the embodiment of the present invention, compared with the conventional detection methods such as pre-silicon security verification technology and post-silicon security testing technology used in the current prior art for security detection, the present application acquires the security policies enabled during the operation of the system on a chip, sets the secure working process of the encrypted IP according to the enabled security policies, multiple-level check nodes for arranging working data are set on the secure working process, acquires the working data of the encrypted IP when performing tasks at the multiple-level check nodes, performs multi-level security detection on the working data by using the enabled security policies, and generates a security detection result of the encrypted IP according to the status response information fed back by the execution device. A complete secure working process is set for the encrypted IP throughout the process, ensuring real-time detection of the encrypted IP when performing tasks, reducing the impact on the system on a chip caused by executing security policies by designing a multi-level security detection architecture, and implementing flexible and reasonable emergency vulnerability and trojan response measures, thereby improving the utilization efficiency of the system resources on the chip.

[0132] In a specific application scenario, the device further includes:

[0133] a configuration unit, which is used to pre-configure policy information before acquiring the security policies enabled during the operation of the system on a chip, and the policy information includes different types of security policies, the detection mechanisms corresponding to the security policies, and the response measures corresponding to the security policies;

[0134] A change unit, configured to receive policy control information and change the policy enabling state during the operation of the system-on-chip according to the policy control information.

[0135] In a specific application scenario, the obtaining unit is specifically configured to, in response to a change in the policy enabling state during the operation of the system-on-chip, traverse and read the enabling state of each security policy in the policy information; and obtain the security policies enabled during the operation of the system-on-chip according to the enabling state of each security policy in the policy information.

[0136] In a specific application scenario, the setting unit is specifically configured to obtain the data flow direction of the encryption IP during task execution, determine at least one inspection node for data security detection in the data flow direction according to the enabled security policies, and arrange a multi-level detection mechanism for the at least one inspection node to obtain the secure working process of the encryption IP.

[0137] In a specific application scenario, the device further includes:

[0138] A control unit, configured to, after setting the secure working process of the encryption IP according to the enabled security policies, control the encryption IP to execute tasks according to the secure working process, and obtain the permission priorities of the input and / or output interfaces when the encryption IP executes tasks, where the permission priorities include a first priority for the input interface to receive data and a second priority for the output interface to send data.

[0139] The control unit is specifically configured to control the input interface of the encryption IP to receive the data to be processed according to the first priority when the encryption IP executes tasks according to the permission priorities.

[0140] The control unit is further specifically configured to control the output interface of the encryption IP to send the processed data according to the second priority when the encryption IP executes tasks according to the permission priorities.

[0141] In a specific application scenario, the detection unit is specifically configured to:

[0142] When the enabled security policy is an access monitoring policy, obtain the ciphertext data output by the encryption IP during task execution at the multi-level inspection node, count the number of times the ciphertext data is read by the host before the operation is completed, and perform security detection on the ciphertext data by determining whether the number of reads is the set number of times.

[0143] When the enabled security policy is a timeout monitoring policy, obtain the working time output by the encryption IP during task execution at the multi-level inspection node, and determine whether the working time meets the set working time range to perform security detection on the working time.

[0144] When the enabled security policy is a data detection policy, obtain the working information output by the encrypted IP during task execution at the multi-level inspection node, and perform security detection on the working time by comparing whether the working information is consistent with the expected result;

[0145] When the enabled security policy is an address detection policy, obtain the working address output by the encrypted IP during task execution at the multi-level inspection node, and perform security detection on the working time by comparing whether the working address is within the preset address range;

[0146] When the enabled security policy is a flag bit detection policy, obtain the flag bit output by the encrypted IP during task execution at the multi-level inspection node, and perform security detection on the working time by judging whether the flip of the flag bit meets the expected requirements;

[0147] When the enabled security policy is a module-level detection policy, obtain the working conversion mechanism set for interaction by the encrypted IP during task execution at the multi-level inspection node, and detect whether there is an abnormal state jump behavior in the interaction module of the encrypted IP through the set working conversion mechanism for interaction, so as to perform security detection on the working time.

[0148] It should be noted that for other corresponding descriptions of each functional unit involved in the detection device for encrypted IP during the operation of the system-on-chip provided in this embodiment, reference can be made to Figures 1-5 the corresponding description in, which will not be elaborated here.

[0149] Based on the above method as Figures 1-5 shown, correspondingly, an embodiment of the present application further provides a storage medium, on which a computer program is stored, and when the program is executed by a processor, it implements the method for detecting encrypted IP during the operation of the system-on-chip as Figures 1-5 shown above.

[0150] Based on such an understanding, the technical solution of the present application can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.), and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in various implementation scenarios of the present application.

[0151] Based on the above method as Figures 1-5 shown, and Figure 9For the virtual device embodiments shown, to achieve the above object, an embodiment of the present application further provides an entity device for detecting encrypted IP during the operation of a system-on-chip. Specifically, it can be a computer, a smart phone, a tablet computer, a smart watch, a server, or a network device, etc. The entity device includes a storage medium and a processor; the storage medium is used to store a computer program; the processor is used to execute the computer program to implement the above-mentioned method for detecting encrypted IP during the operation of the system-on-chip as shown in Figures 1-5 the method for detecting encrypted IP during the operation of the system-on-chip as shown.

[0152] Optionally, the entity device may further include a user interface, a network interface, a camera, a radio frequency (RF) circuit, sensors, an audio circuit, a WI-FI module, etc. The user interface may include a display screen and an input unit such as a keyboard, etc. Optionally, the user interface may further include a USB interface, a card reader interface, etc. The network interface may optionally include a standard wired interface, a wireless interface (such as a WI-FI interface), etc.

[0153] In an exemplary embodiment, referring to Figure 10 , the above entity device includes a communication bus, a processor, a memory, and a communication interface, and may further include an input / output interface and a display device. Among them, each functional unit can complete mutual communication through the bus. The memory stores a computer program, and the processor is used to execute the program stored on the memory to implement the method for detecting encrypted IP during the operation of the system-on-chip in the above embodiment.

[0154] Those skilled in the art can understand that the structure of the entity device for detecting encrypted IP during the operation of the system-on-chip provided in this embodiment does not limit the entity device, and it may include more or fewer components, or combine some components, or have different component arrangements.

[0155] The storage medium may further include an operating system and a network communication module. The operating system is a program for managing the hardware and software resources of the entity device for detecting encrypted IP during the operation of the system-on-chip, and supports the operation of information processing programs and other software and / or programs. The network communication module is used to implement communication between components inside the storage medium, as well as communication with other hardware and software in the information processing entity device.

[0156] Through the description of the above embodiments, those skilled in the art can clearly understand that the present application can be implemented by means of software plus a necessary general hardware platform, or can also be implemented by hardware. By applying the technical solution of the present application, compared with the current existing methods, the present application sets up a complete security workflow for the encrypted IP, ensures that the encrypted IP can be detected in real time when performing tasks, reduces the impact on the system-on-chip caused by executing security policies by designing a multi-level security detection architecture, and realizes flexible and reasonable emergency vulnerability and trojan response measures, thereby improving the utilization efficiency of the system-on-chip resources.

[0157] Those skilled in the art can understand that the drawings are only schematic diagrams of a preferred implementation scenario, and the modules or processes in the drawings are not necessarily essential for implementing the present application. Those skilled in the art can understand that the modules in the devices in the implementation scenario can be distributed in the devices in the implementation scenario according to the description of the implementation scenario, or can be correspondingly changed and located in one or more devices different from this implementation scenario. The modules in the above implementation scenario can be combined into one module, or can be further split into multiple sub-modules.

[0158] The above serial numbers of the present application are only for description and do not represent the advantages or disadvantages of the implementation scenarios. The above disclosure is only several specific implementation scenarios of the present application. However, the present application is not limited thereto, and any changes that can be thought of by those skilled in the art should fall within the protection scope of the present application.

Claims

1. A method for detecting encrypted IP during the operation of a system on a chip, characterized in that, it includes: Obtain the security policies enabled during the operation of the system on a chip; Set the security work process of the encrypted IP according to the enabled security policies, and multiple levels of inspection nodes for arranging work data are set on the security work process; Obtain the work data of the encrypted IP when performing tasks at the multiple levels of inspection nodes, and perform multi-level security detection on the work data by using the enabled security policies; Generate a security detection result of the encrypted IP according to the status response information fed back by the execution device.

2. The method according to claim 1, characterized in that, Before obtaining the security policies enabled during the operation of the system on a chip, the method further includes: Pre-configure policy information, which includes different types of security policies, the detection mechanisms corresponding to the security policies, and the response measures corresponding to the security policies; Receive policy control information, and change the policy enabling status during the operation of the system on a chip according to the policy control information.

3. The method according to claim 1, characterized in that, The obtaining of the security policies enabled during the operation of the system on a chip includes: In response to the change of the policy enabling status during the operation of the system on a chip, traverse and read the enabling status of each security policy in the policy information; Obtain the security policies enabled during the operation of the system on a chip according to the enabling status of each security policy in the policy information.

4. The method according to claim 1, characterized in that, The setting of the security work process of the encrypted IP according to the enabled security policies includes: Obtain the data flow direction of the encrypted IP when performing tasks, and determine at least one inspection node for data security detection in the data flow direction according to the enabled security policies; Arrange multi-level detection mechanisms for the at least one inspection node to obtain the security work process of the encrypted IP.

5. The method according to claim 1, characterized in that, After setting the security work process of the encrypted IP according to the enabled security policies, the method further includes: Control the encrypted IP to perform tasks according to the security work process, obtain the permission priorities of the input and / or output interfaces when the encrypted IP performs tasks, and the permission priorities include the first priority for the input interface to receive data and the second priority for the output interface to send data; Control the input interface of the encrypted IP to receive the data to be processed according to the first priority when performing tasks according to the permission priorities; Control the output interface of the encrypted IP to send the processed data according to the second priority when performing tasks according to the permission priorities.

6. The method according to any one of claims 1-5, characterized in that, The obtaining of the work data of the encrypted IP when performing tasks at the multiple levels of inspection nodes, and performing multi-level security detection on the work data by using the enabled security policies includes: When the enabled security policy for enabling is an access monitoring policy, obtain the ciphertext data output by the encrypted IP during task execution at the multi-level inspection node, count the number of times the ciphertext data is read by the host before the operation is completed, and perform security detection on the ciphertext data by determining whether the number of reads is the set number; When the enabled security policy for enabling is a timeout monitoring policy, obtain the working time output by the encrypted IP during task execution at the multi-level inspection node, and determine whether the working time is within the set working time range to perform security detection on the working time; When the enabled security policy for enabling is a data detection policy, obtain the working information output by the encrypted IP during task execution at the multi-level inspection node, and perform security detection on the working time by comparing whether the working information is consistent with the expected result; When the enabled security policy for enabling is an address detection policy, obtain the working address output by the encrypted IP during task execution at the multi-level inspection node, and perform security detection on the working time by comparing whether the working address is within the preset address range; When the enabled security policy for enabling is a flag bit detection policy, obtain the flag bit output by the encrypted IP during task execution at the multi-level inspection node, and perform security detection on the working time by determining whether the flip of the flag bit meets the expected requirements; When the enabled security policy for enabling is a module-level detection policy, obtain the set interaction working conversion mechanism of the encrypted IP during task execution at the multi-level inspection node, and detect whether there is an abnormal state jump behavior in the interaction module of the encrypted IP through the set interaction working conversion mechanism to perform security detection on the working time.

7. A detection device for encrypted IP during the operation of a system on a chip, characterized in that, comprising: an acquisition unit for acquiring the security policy enabled during the operation of the system on a chip; a setting unit for setting the security working process of the encrypted IP according to the enabled security policy, and multi-level inspection nodes for arranging working data are set on the security working process; a detection unit for acquiring the working data of the encrypted IP during task execution at the multi-level inspection node, and performing multi-level security detection on the working data by using the enabled security policy; a generation unit for generating a security detection result of the encrypted IP according to the status response information fed back by the execution device.

8. A detection device for encrypted IP during the operation of a system on a chip, characterized in that, comprising: a security policy control module, at least one encrypted IP module, and a main control module; The main control module is connected to the policy security control module for controlling the enabling state of the security policy. The security policy control module is respectively connected to the at least one encrypted IP module for performing security detection on the encrypted IP by using the enabled security policy when the encrypted IP executes a task.

9. A computer device includes a memory and a processor, and the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method for detecting encrypted IP during the operation of the system-on-chip according to any one of claims 1 to 6.

10. A computer-readable storage medium, on which a computer program is stored, characterized in that when the computer program is executed by a processor, it implements the steps of the method for detecting encrypted IP during the operation of the system-on-chip according to any one of claims 1 to 6.