Chip, chip security verification method and device, electronic equipment and storage medium

By introducing in-chip security structure and power isolation areas into the chip, the chip data leakage and low yield rate are solved, and data security and high yield rate are achieved.

CN120148602APending Publication Date: 2025-06-13CHINA MOBILE M2M +2
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510340238.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-21
Publication Date
2025-06-13

AI Technical Summary

Technical Problem

In the prior art, removing some chips cannot ensure that the chip data is not leaked by hackers, and removing some chips will reduce the chip yield rate.

Method used

By introducing an in-chip security structure into the chip, including a test module and a power isolation area, the test module is connected to the off-chip security structure, and the external power supply is realized. The power isolation area isolates the internal power supply of the chip body to isolate the chip body.

Benefits of technology

It can still ensure data security after chip cutting, avoid hacker attacks, improve chip reliability and yield rate, and reduce production costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120148602A_ABST
    Figure CN120148602A_ABST
Patent Text Reader

Abstract

The invention provides a chip, a chip security verification method and device, electronic equipment and a storage medium, and belongs to the technical field of chip security, the chip comprises a chip main body and an on-chip security structure, the on-chip security structure comprises a test module which is connected with an off-chip security structure outside the chip so as to enable the test module to work under the condition of external power supply; the test module and the off-chip safety structure are disconnected after the chip is packaged; and the power supply isolation area is used for isolating internal power supply of the chip main body to the test module. Based on a power supply separation thought, the power supply isolation area is arranged to isolate a power supply system of the test module out of the chip, the test module and the off-chip safety structure are connected to realize that the outside of the chip supplies power to the on-chip safety structure, and a residual circuit generated by cutting and packaging is prevented from influencing normal functions of the chip. The chip is prevented from being recovered to a test state by a hacker through the exposed interconnection line at the cross section after the chip is cut, the data security of the chip is ensured, and the reliability and yield of the chip are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of chip security, and in particular, to a chip, a chip security verification method, a device, an electronic device, and a storage medium. Background Art

[0002] Physically destroying or removing the off-chip test circuit that is part of the chip is an important way to avoid critical data leakage and ensure chip security.

[0003] Currently, the main method of physically destroying or removing part of the chip is to arrange the off-chip test circuit to be removed in the chip outside the main functional area, make the fuse circuit in the scribe groove, and perform cutting along the scribe groove after testing, which can completely destroy and remove the target unit circuit in the chip.

[0004] However, after cutting the off-chip test circuit based on this removal method of the scribe lane functional circuit, the interconnection signal lines exposed at the cross-section may be hacked, causing the chip to return to the test state, thereby resulting in the leakage of chip data information. Moreover, the floating of the signal lines caused by cutting will damage the packaged chip itself, reducing the chip yield.

[0005] Therefore, it is necessary to optimize the chip structure to obtain a chip that can still ensure chip data security and cause no self-damage after cutting and removing part of the chip. Summary of the Invention

[0006] The present invention provides a chip, a chip security verification method, a device, an electronic device, and a storage medium, which are used to solve the defects in the prior art that removing part of the chip cannot ensure that the chip data information is not leaked by hacker attacks and removing part of the chip will reduce the chip yield, and to implement a chip solution that can still ensure data security and cause no self-damage after cutting and removing part of the chip.

[0007] The present invention provides a chip, including: a chip main body and an in-chip security structure, and the in-chip security structure includes: a test module, connected to an off-chip security structure outside the chip, so that the test module operates under external power supply; the connection between the test module and the off-chip security structure is disconnected after the chip is packaged; a power isolation area, used to isolate the internal power supply of the chip main body to the test module.

[0008] A chip provided according to the present invention, the test module includes a first output port and a first input port, the first output port is connected to the second input port of the off-chip security structure through a power signal line, and the first input port is connected to the second output port of the off-chip security structure through a power signal line, so that the test module realizes signal transmission under external power supply.

[0009] A chip provided according to the present invention, the off-chip security structure is connected to a test device, so that the test module realizes signal transmission under the power supply of the test device.

[0010] A chip provided according to the present invention, the test module includes more than two of the first output ports and the first input ports, the more than two first output interfaces and the second input interface are respectively connected through a power signal line, and the more than two first input ports and the second output interface are respectively connected through a power signal line.

[0011] A chip provided according to the present invention, the chip body includes a one-time programmable storage area for storing variable voltage configuration information generated when the chip is powered on for the first time; the variable voltage configuration information is used for the test module to generate a variable voltage signal.

[0012] The present invention also provides a chip security verification method based on any one of the above-mentioned chips, the chip security verification method includes: In response to a test security verification signal, send a first verification signal to an off-chip security structure outside the chip through a test module; Receive a second verification signal returned by the off-chip security structure through the test module; When the first verification signal and the second verification signal are consistent, pass the security verification, and the chip enters the test mode.

[0013] According to a chip security verification method provided by the present invention, the first verification signal is a variable voltage signal; the sending of the first verification signal to an off-chip security structure outside the chip through the test module includes: Based on the variable voltage configuration information and a random number, determine the variable voltage signal; the variable voltage configuration information is generated when the chip is powered on for the first time and stored in the one-time programmable storage area of the chip body; Send the variable voltage signal to the off-chip security structure through the test module.

[0014] The present invention also provides a chip security verification device based on any one of the above-mentioned chips, including: A signal sending module, configured to respond to a test security verification signal and send a first verification signal to an off-chip security structure outside the chip through a test module; A signal receiving module, configured to receive a second verification signal returned by the off-chip security structure through the test module; A signal verification module, configured to, when the first verification signal is consistent with the second verification signal, perform security verification, and the chip enters a test mode.

[0015] The present invention further provides an electronic device, including a memory, a processor, and a computer program stored on the memory and running on the processor. When the processor executes the computer program, the chip security verification method described in any one of the above is implemented.

[0016] The present invention further provides a non-transitory computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the chip security verification method described in any one of the above is implemented.

[0017] The present invention further provides a computer program product, including a computer program. When the computer program is executed by a processor, the chip security verification method described in any one of the above is implemented.

[0018] The chip, chip security verification method, device, electronic device, and storage medium provided by the present invention, through the idea of power separation, perform separate isolation processing on the power supply line of the on-chip security structure directly connected to the off-chip security structure to be cut inside the chip, and do not supply power to the on-chip security structure by the inside of the chip. Instead, power supply to the on-chip security structure is realized by the direct connection between the off-chip security structure and the test module, and the power supply system of the test module on the chip is isolated outside the chip. When the chip is cut and packaged, it can avoid the influence of the antenna effect caused by the residual circuit on the normal function of the chip, and can also prevent hackers from restoring the chip to the test state through the exposed interconnections at the cross-section of the test module after the chip is cut. Hacker attacks cannot be transmitted to the inside of the chip main body, ensuring the chip data security; moreover, the process of isolating the power supply of the chip main body to the test module by the power isolation area is completely compatible with the existing process, without the need to customize additional structures, and has high engineering feasibility, which can greatly improve the chip reliability and yield, and reduce the chip production cost. Description of the Drawings

[0019] In order to more clearly illustrate the technical solutions in the present invention or the prior art, the following will briefly introduce the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0020] Figure 1 It is one of the exemplary diagrams of cutting a chip in the related art.

[0021] Figure 2 It is the second of the exemplary diagrams of cutting a chip in the related art.

[0022] Figure 3 It is the third of the exemplary diagrams of cutting a chip in the related art.

[0023] Figure 4 It is one of the schematic diagrams of the structure of the chip provided by the present invention.

[0024] Figure 5 It is the second of the schematic diagrams of the structure of the chip provided by the present invention.

[0025] Figure 6 It is the schematic flowchart of the chip security verification method provided by the present invention.

[0026] Figure 7 It is the schematic diagram of the structure of the chip security verification device provided by the present invention.

[0027] Figure 8 It is the schematic diagram of the structure of the electronic device provided by the present invention. Detailed implementation manners

[0028] To make the objectives, technical solutions and advantages of the present invention clearer, the technical solutions in the present invention will be clearly and completely described below with reference to the accompanying drawings in the present invention. Apparently, the described embodiments are some but not all of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art without creative efforts based on the embodiments in the present invention belong to the scope of protection of the present invention.

[0029] It should be noted that in the description of the present invention, the term "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements but also includes other elements not explicitly listed, or further includes elements inherent to such process, method, article or device. For those of ordinary skill in the art, the specific meanings of the above terms in the present invention can be understood according to specific circumstances.

[0030] The terms "first", "second", etc. in the present invention are used to distinguish similar objects, rather than to describe a specific order or sequence. It should be understood that such used data can be interchanged under appropriate circumstances so that the embodiments of the present invention can be implemented in an order other than those illustrated or described herein, and the objects distinguished by "first", "second", etc. generally belong to the same category, and the number of objects is not limited. For example, the first object can be one or more.

[0031] The following will describe the chip, chip security verification method, device, electronic device and storage medium provided by the present invention in conjunction with Figures 1-8 the description.

[0032] In fields such as national defense and finance where data security is of great importance, in certain specific situations, it is necessary to physically destroy or remove part of the chip to completely avoid the leakage of key data in the chip. With the help of the fuse circuit, the removal of part of the chip circuit can be effectively achieved.

[0033] There are three main ways to physically destroy or remove part of the chip.

[0034] First, the method based on the scribe line functional circuit. By arranging the target unit circuit to be removed in the chip outside the main functional area of the chip and making the fuse in the scribe groove, after the wafer test (Chip Probing, CP) is completed through the probe, the wafer is cut along the scribe groove, and the target unit circuit in the chip can be completely destroyed and removed.

[0035] Figure 1 is one of the schematic diagrams of cutting chips in the related art. As Figure 1 shown, part C is the main chip, and part A is the off-chip security module to be cut and removed made in the scribe line (SL). Part A communicates with part C through metal signal lines. Based on security requirements, after the CP test, the entire wafer is cut, the chips are screened, and part A is cut off after the chip screening, so as to physically completely remove the circuit in the off-chip security module of part A.

[0036] Figure 2 is another schematic diagram of cutting chips in the related art. As Figure 2 shown, after cutting off part A as the off-chip security module, the remaining part C is obtained as the die to be finally packaged.

[0037] Figure 3 is the third schematic diagram of cutting chips in the related art. As Figure 3 shown, after the metal signal line between part A and part C is cut, it is exposed at the cross-section of part C (i.e., the main chip), which is easily affected by the outside world. Moreover, due to the loss of the drive of part A, the disconnected signal is in a floating state, and the charge generated during chip cutting is easily conducted from the cutting point to the gate of the MOS device, damaging the device and making it unable to work normally.

[0038] It can be seen that although the method based on the scribe lane functional circuit can effectively remove the off-chip test circuit, there are still some technical problems: (1) After scribe cutting, there may be residual circuits, resulting in antenna effects and affecting the normal function of the chip. After scribe cutting, the off-chip detection circuit and the in-chip verification circuit will have residual interconnection signal lines exposed at the cross-section, which are vulnerable to hacker attacks. Once the hacker cracks the signal function, the chip can be restored to the test state through the residual signal lines, resulting in the leakage of chip data information; (2) The residual circuit after cutting is in a floating state inside the chip, that is, a signal indeterminate state is formed. For CMOS devices, the indeterminate state of the input signal will cause logic punch-through and extremely high punch-through current, which is an unacceptable functional defect of the chip. Therefore, the scribe processing method that causes the signal line to float after cutting has risks, which will damage the chip, cause the chip to fail, and reduce the chip yield. There is data showing that about 4% of chip failures are caused during the chip slicing process.

[0039] Second, the method based on the special pad structure. The special pad structure adds an additional insulating layer material to the traditional pad, adds a metal layer on the insulating layer material, and drills holes in the two metal layers to fill with conductive materials. Then, during the test process, by applying an external high voltage to burn through the upper and lower layers, the signal path is cut off, and an irreversible process of controlling the chip port from on to off can be achieved, which is equivalent to achieving the complete destruction and removal of some circuits in the chip.

[0040] However, the method based on the special pad structure requires an additional metal layer overhead, resulting in a significant increase in chip cost, and the special pad structure needs to be customized, resulting in an increase in the failure rate and R & D cycle.

[0041] Third, the method based on the control of special fuse units. The special fuse unit enables and operates the mode through the configuration module, and uses the control circuit to generate a high voltage inside after packaging to achieve the function of burning through, thereby realizing the irreversible function of some circuits in the chip from on to off, and avoiding the influence on the chip during the packaging process.

[0042] However, although the special fuse unit can be made inside the chip, since all detection circuits and verification circuits are physically visible, with the improvement of attack technology levels, corresponding attack means may appear. For example, through a combination form of invasive attack plus side channel attack (Side Channel Attack, SCA), or electromagnetic attack plus side channel attack combination, the key signals in the circuit can be tampered with, resulting in the leakage of this part of information.

[0043] In view of this, the present invention provides a chip, a chip security verification method, device, electronic device and storage medium to solve at least one of the foregoing technical problems.

[0044] Figure 4 is one of the structural schematic diagrams of the chip provided by the present invention. As Figure 4 shown, the chip includes, but is not limited to, a chip main body 410 and an in-chip security structure 420. The in-chip security structure 420 includes a test module 421 and a power isolation area 422.

[0045] Among them, the test module 421 is connected to an out-of-chip security structure 430 outside the chip, so that the test module 421 operates under external power supply; the connection between the test module 421 and the out-of-chip security structure 430 is disconnected after the chip is encapsulated.

[0046] The power isolation area 422 is used to isolate the internal power supply of the chip main body 410 to the test module 421.

[0047] Specifically, the chip includes a chip main body 410 and an in-chip security structure 420. The chip main body 410 is the area on the chip for implementing the main functions. There is an out-of-chip security structure 430 (also called an out-of-chip test circuit, an out-of-chip security module, etc.) outside the chip. Before the chip is encapsulated, the out-of-chip security structure 430 is connected to the chip to assist in the testing, screening, etc. of the chip. When the chip is encapsulated after testing, the connection between the out-of-chip security structure 430 and the chip will be disconnected. For example, after the chip completes testing, the out-of-chip security structure 430 is cut, and the chip obtained as a bare die is encapsulated.

[0048] The in-chip security structure 420 is a structure specially set on the chip based on the design consideration of physical security (PhS), and includes a test module 421 (also called an in-chip inspection module, an in-chip verification circuit, etc.) and a power isolation area 422.

[0049] In the test steps that need to be carried out before the chip is encapsulated, the test module 421 is connected to the out-of-chip security structure 430 outside the chip through power signal lines, etc. for power connection and communication connection. The power supply of the test module 421 will be provided by components outside the chip through the out-of-chip security structure 430. At the same time, the power isolation area 422 in the in-chip security structure 420 wraps the test module 421 to isolate the test module 421 from the chip main body 410, realizing the functions of isolating the internal power supply of the chip main body 410 to the test module 421 and internal power interference.

[0050] When the chip is tested, the test module 421 will perform signal transmission and other operations under external power supply (that is, powered by components outside the chip).

[0051] When the chip test is completed and packaging is required, the connection between the test module 421 and the off-chip security structure 430 will be disconnected. For example, the connection is disconnected by cutting the power signal line between the test module 421 and the off-chip security structure 430, and a bare chip to be packaged, which consists of the chip body 410 and the on-chip security structure 420, is obtained.

[0052] After the chip is packaged, since the internal power supply between the test module 421 and the chip body 410 has been completely isolated by the power isolation region, and the external power supply between the test module 421 and the off-chip security structure 430 has also been cut off, the test module 421 will no longer receive internal or external power supply.

[0053] For the chip provided by the present invention, based on the idea of power separation, the power supply line of the on-chip security structure directly connected to the off-chip security structure to be cut inside the chip is separately isolated, and the on-chip security structure is not powered by the inside of the chip. Instead, the on-chip security structure is powered by the outside of the chip through the direct connection between the off-chip security structure and the test module. The power supply system of the test module on the chip is isolated outside the chip. When the chip is cut and packaged, it can avoid the influence of the antenna effect caused by the residual circuit on the normal function of the chip, and can also prevent hackers from restoring the chip to the test state through the exposed interconnections at the cross-section of the test module after the chip is cut. Hacker attacks cannot be transmitted to the inside of the chip body, ensuring the chip data security; moreover, the process of isolating the power supply of the chip body to the test module by the power isolation region is completely compatible with the existing process, without the need to customize additional structures, and has high engineering feasibility. It can greatly improve the chip reliability and yield, and reduce the chip production cost.

[0054] Figure 5 is the second structural schematic diagram of the chip provided by the present invention. As Figure 5 shown, the test module 421 includes a first output port 501 and a first input port 502. The first output port 501 is connected to the second input port 503 of the off-chip security structure 430 through a power signal line, and the first input port 502 is connected to the second output port 504 of the off-chip security structure 430 through a power signal line, so that the test module 421 can achieve signal transmission under the condition of external power supply.

[0055] Specifically, the test module 421 is connected to the off-chip security structure 430 through a power signal line, so that the power supply of the test module 421 is provided by the outside of the chip through the power signal line. The power is transmitted from the second output port 504 of the off-chip security structure 430 to the first input port 502 of the test module 421 through the power signal line. At the same time, multiple metal layers are included in the same chip, and reasonable metal layers can be flexibly used for power supply, and resources for signal line connection are reserved.

[0056] The test module 421 and the off-chip security structure 430 are connected through a power signal line. When the power supply of the test module 421 is provided externally to the chip, when the chip needs to send data to the off-chip security structure 430 during chip testing and related test preparation work, the chip can transmit a data signal through the first output port 501 of the test module 421, and the off-chip security structure 430 receives the data signal at the second input port 503. When the off-chip security structure 430 needs to send data to the chip, the off-chip security structure 430 can transmit a data signal through the second output port 504, and the test module 421 receives the data signal at the first input port 502, thereby realizing signal transmission of the test module under the condition of external power supply.

[0057] Optionally, both the first output port 501 and the first input port 502 of the test module 421 adopt high-voltage devices with anti-damage functions.

[0058] For the chip provided by the present invention, by using a power signal line to connect the input and output ports of the test module and the off-chip security structure, the probability of physical damage to the chip during the process of cutting the power signal line of the chip can be effectively reduced, and at the same time, the problem of generating indeterminate states inside the chip due to using logical signals for fusing during the process of controlling the cutting of the chip based on special fuse units is avoided, which helps to greatly improve the yield.

[0059] Based on the above embodiments, as an alternative embodiment, the off-chip security structure is connected to a test device so that the test module can realize signal transmission under the power supply of the test device.

[0060] Specifically, after isolating the internal power supply of the test module inside the chip in the power isolation area, the test module and the off-chip security structure are connected through a power signal line. At the same time, the off-chip security structure is connected to a test device for supplying power to the off-chip security structure and the test module, so as to realize signal transmission of the test module under the power supply of the test device.

[0061] It can be understood that the off-chip security structure will be cut off during chip packaging. Therefore, there is no separate power line, but the external test port of the off-chip security structure is connected to the test device, and power is supplied through the external test port, and the power is provided by the test device.

[0062] For the chip provided by the present invention, by connecting the test module and the off-chip security structure through a power signal line, and connecting the off-chip security structure to the test device, signal transmission and other operations of the test module under the external power supply of the test device are realized.

[0063] Based on the above embodiments, as an alternative embodiment, the test module includes more than two of the first output ports and the first input ports. The more than two first output interfaces and the second input interface are respectively connected by power signal lines, and the more than two first input ports and the second output interface are respectively connected by power signal lines.

[0064] Specifically, the number of the first output ports and the first input ports on the test module for connecting to the off-chip security structure is more than two. The more than two first output ports and one or more than two second input interfaces on the off-chip security structure are respectively connected by power signal lines, and the more than two first input ports and one or more than two second output ports on the off-chip security structure are respectively connected by power signal lines.

[0065] For the chip provided by the present invention, by providing more than two input / output ports on the test module and respectively connecting them to the input / output ports of the off-chip security structure through power signal lines, the power supply path between the test module and the off-chip security structure can be divided into multiple independent channels. Compared with only one power supply path between the test module and the off-chip security structure, it can reduce the occurrence of the situation where metal connection lines are overlapped due to process cutting, can greatly reduce the probability of defects occurring after chip cutting, and improve the yield rate of the chip.

[0066] Based on the above embodiments, as an alternative embodiment, the chip body includes a one-time programmable (OTP) storage area for storing variable voltage configuration information generated when the chip is powered on for the first time; the variable voltage configuration information is used for the test module to generate a variable voltage signal.

[0067] The variable voltage configuration information is pre-determined configuration information for the test module to generate a variable voltage under different conditions.

[0068] The one-time programmable storage design can store the configuration information generated after the chip is powered on for the first time, and the information after the chip is powered on for the second time and later cannot be overwritten and stored.

[0069] Specifically, when the chip is powered on, the main functional area of the chip body generates variable voltage configuration information and stores it in the OTP storage area on the chip body for the test module to read during the test security verification, and performs the security verification before the chip enters the test mode according to the variable voltage signal generated by reading the variable voltage configuration information.

[0070] For example, the variable voltage configuration information includes 25 levels of voltage information configured at intervals of 20 mV within the range of 0.7V to 1.2V. When the test module performs a safety check before the chip enters the test mode, it can read the variable voltage configuration information from the variable voltage configuration information according to the current chip status, current time, chip serial number (Serial Number, SN), etc., and then generate and output a variable voltage signal to the off-chip safety structure to determine whether the safety check before the chip enters the test mode passes based on the voltage signal returned by the off-chip safety structure.

[0071] The chip provided by the present invention stores the variable voltage configuration information generated when the chip is initially powered on in the one-time programmable storage area of the chip body, so that the test module can generate a variable voltage signal by reading the variable voltage configuration information and output the variable voltage signal to the off-chip safety structure outside the chip through the power signal line, so that in addition to the safety check in the conventional test mode, a safety check method based on voltage signal detection can also be performed according to the chip with optimized structure.

[0072] Figure 6 is a schematic flow chart of the chip safety check method provided by the present invention, as Figure 6 shown, the chip safety check method is implemented using the chip described in any of the above embodiments, including but not limited to steps 601 to 603.

[0073] Step 601: In response to the test safety check signal, send a first check signal to the off-chip safety structure outside the chip through the test module.

[0074] Step 602: Receive a second check signal returned by the off-chip safety structure through the test module.

[0075] Step 603: When the first check signal and the second check signal are consistent, pass the safety check, and the chip enters the test mode.

[0076] Specifically, when the chip is powered on, or when the test device requests the chip to enter the test mode, a test safety check signal is generated. After the chip responds to the test safety check signal, the test module generates a first check signal and sends the first check signal to the off-chip safety structure outside the chip connected to the test module. After receiving the first check signal, the off-chip safety structure returns the first check signal as the second check signal to the test module, and the test module receives this second check signal.

[0077] The test module makes a consistency judgment based on the first verification signal and the second verification signal to determine whether the first verification signal and the second verification signal are consistent. When the first verification signal and the second verification signal are consistent, the chip is complete and reliable, indicating that the safety inspection before the chip enters the test mode has passed, and the chip enters the test mode.

[0078] If the chip has completed the functional test before chip packaging and has been packaged, the connection between the test module in the chip and the off-chip security structure has been cut off. There is no situation where the off-chip security structure returns the first verification signal as the second verification signal to the test module after receiving the first verification signal. The second verification signal floats, and the test module will judge that the first verification signal and the second verification signal are inconsistent, indicating that the chip has completed the chip test and has been packaged. At this time, the safety verification fails and the chip cannot enter the test mode again.

[0079] The chip safety verification method provided by the present invention, through a chip optimized depending on the structure, that is, depending on the power separation idea, the power supply line of the on-chip security structure directly connected to the off-chip security structure to be cut in the chip is separately isolated, and the power supply system of the test module is isolated outside the chip. It can add a verification method for signal consistency detection other than the conventional verification means through the connection relationship between the test module and the off-chip security structure, which can improve the chip security and avoid data leakage after the chip is attacked.

[0080] Based on the above embodiments, as an optional embodiment, the first verification signal is a variable voltage signal; the sending of the first verification signal from the test module to the off-chip security structure outside the chip includes: Determining the variable voltage signal based on the variable voltage configuration information and a random number; the variable voltage configuration information is generated and stored in the one-time programmable storage area of the chip main body when the chip is powered on for the first time; Sending the variable voltage signal to the off-chip security structure through the test module.

[0081] Specifically, after responding to the test safety verification signal, the test module reads the variable voltage configuration information stored in the one-time programmable storage area of the chip main body, combines it with a random number to generate a variable voltage signal, and sends the variable voltage signal through the first output interface on the test module to the second input interface of the off-chip security structure through the power supply signal line. The off-chip security structure uses the variable voltage signal as the second verification signal and sends it back to the first input interface of the test module through the power supply signal line by the second output interface, and the test module performs consistency verification of the voltage signals on the variable voltage signal and the second verification signal.

[0082] If the variable voltage signal is consistent with the second verification signal, it indicates that the chip is complete and reliable, the security verification passes, and the chip enters the test mode. If the chip has been diced and packaged, the second verification signal floats, the variable voltage signal is inconsistent with the second verification signal, the security verification fails, and the chip cannot re-enter the test mode.

[0083] Optionally, determining the variable voltage signal based on the variable voltage configuration information and the random number includes: determining the variable voltage signal based on the variable voltage configuration information, the unique serial number (Serial Number, SN) of the chip, and the random number.

[0084] It should be noted that the specific method for obtaining the random number can be obtained through the random number generator in the chip, or can be generated by comprehensively considering factors such as the current state of the chip and the current time. The present invention does not limit this.

[0085] The chip security verification method provided by the present invention stores the variable voltage configuration information when the chip is first powered on in the one-time programmable storage area of the chip main body through a chip integrated security algorithm based on structural optimization, uses a random number to generate an independent variable voltage signal, and when the test module performs security verification for entering the test module, reads the variable voltage configuration information to generate a variable voltage signal, and adds a verification method for the consistency of the variable voltage signal through the connection relationship between the test module and the off-chip security structure. If a hacker attacks the chip, it is necessary to additionally restore the variable voltage signal sent by the test module. However, on the one hand, the variable voltage signal has no obvious physical characteristics, and it is difficult for hackers to determine the appropriate attack voltage. On the other hand, it is stored in the chip main body isolated from the power supply of the test module and is protected by an encrypted data bus and an encrypted memory, and cannot be detected by reverse means. This makes it basically impossible for the chip after cutting off the off-chip security structure to re-enter the test mode again, and hackers cannot find the attack target for side-channel attacks, increasing the difficulty of reverse attacks by hackers and improving the security and reliability of the chip.

[0086] Figure 7 is a schematic structural diagram of the chip security verification device provided by the present invention, as Figure 7 shown, the chip security verification device includes but is not limited to a signal sending module 701, a signal receiving module 702, and a signal verification module 703.

[0087] The signal sending module 701 is configured to respond to the test security verification signal and send a first verification signal to the off-chip security structure outside the chip through the test module.

[0088] The signal receiving module 702 is configured to receive the second verification signal returned by the off-chip security structure through the test module.

[0089] The signal verification module 703 is used to pass the security verification when the first verification signal is consistent with the second verification signal, and the chip enters the test mode.

[0090] Optionally, the chip security verification device is deployed on the chip body of the chip.

[0091] It should be noted that the chip security verification device provided by the present invention can execute the chip security verification method described in any of the above embodiments during specific operation, and this embodiment will not be elaborated here.

[0092] The chip security verification device provided by the present invention, by relying on a chip with an optimized structure, that is, relying on the power separation idea, separately isolates the power supply line of the in-chip security structure directly connected to the off-chip security structure to be cut inside the chip, and isolates the power supply system of the test module outside the chip. The chip can add a verification method for detecting signal consistency other than the conventional verification means through the connection relationship between the test module and the off-chip security structure, which can improve the chip security and prevent the chip from leaking data after being attacked.

[0093] Figure 8 is a schematic structural diagram of the electronic device provided by the present invention. As Figure 8 shown, the electronic device may include: a processor (Processor) 810, a communication interface (Communications Interface) 820, a memory (Memory) 830, and a communication bus 840. Among them, the processor 810, the communication interface 820, and the memory 830 complete mutual communication through the communication bus 840. The processor 810 can call the logical instructions in the memory 830 to execute the chip security verification method provided in any of the above embodiments. The chip security verification method includes but is not limited to the following steps: responding to the test security verification signal, sending a first verification signal to the off-chip security structure outside the chip through the test module; receiving a second verification signal returned by the off-chip security structure through the test module; when the first verification signal is consistent with the second verification signal, passing the security verification, and the chip enters the test mode.

[0094] In addition, when the logical instructions in the above-mentioned memory 830 are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROMs), random access memories (RAMs), magnetic disks, or optical discs that can store program codes.

[0095] On the other hand, the present invention also provides a computer program product. The computer program product includes a computer program that can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the chip security verification method provided in any of the above embodiments. The chip security verification method includes but is not limited to the following steps: responding to a test security verification signal, sending a first verification signal to an off-chip security structure outside the chip through a test module; receiving, through the test module, a second verification signal returned by the off-chip security structure; and when the first verification signal and the second verification signal are consistent, through security verification, the chip enters a test mode.

[0096] In yet another aspect, the present invention also provides a non-transitory computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements the chip security verification method provided in any of the above embodiments. The chip security verification method includes but is not limited to the following steps: responding to a test security verification signal, sending a first verification signal to an off-chip security structure outside the chip through a test module; receiving, through the test module, a second verification signal returned by the off-chip security structure; and when the first verification signal and the second verification signal are consistent, through security verification, the chip enters a test mode.

[0097] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. A person of ordinary skill in the art can understand and implement it without creative labor.

[0098] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on such an understanding, the essence of the above technical solution, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.

[0099] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of each embodiment of the present invention.

Claims

1. A chip, characterized in that: include: A chip body and an on-chip security structure, wherein the on-chip security structure includes: A test module connected to an off-chip safety structure outside the chip so that the test module works under external power supply; the connection between the test module and the off-chip safety structure is disconnected after the chip is packaged; The power isolation area is used to isolate the chip body from supplying power to the internal of the test module.

2. The chip according to claim 1, characterized in that: The test module includes a first output port and a first input port, the first output port is connected to the second input port of the off-chip safety structure through a power signal line, and the first input port is connected to the second output port of the off-chip safety structure through a power signal line, so that the test module can realize signal transmission when powered by an external power supply.

3. The chip according to claim 2, characterized in that: The off-chip safety structure is connected to a test device, so that the test module can realize signal transmission when the test device is powered.

4. The chip according to claim 2, characterized in that: The test module includes more than two of the first output ports and the first input ports, the more than two of the first output interfaces are connected to the second input interfaces via power signal lines, and the more than two of the first input ports are connected to the second output interfaces via power signal lines.

5. The chip according to any one of claims 1 to 4, characterized in that: The chip body includes a one-time programmable storage area for storing variable voltage configuration information generated when the chip is powered on for the first time; the variable voltage configuration information is used for the test module to generate a variable voltage signal.

6. A chip security verification method based on the chip according to any one of claims 1 to 5, characterized in that: The chip security verification method comprises: In response to the test safety verification signal, a first verification signal is sent to an off-chip safety structure outside the chip through the test module; Receiving, by the test module, a second verification signal returned by the off-chip security structure; When the first verification signal and the second verification signal are consistent, the chip enters the test mode after passing the safety verification.

7. The chip security verification method according to claim 6, characterized in that: The first verification signal is a variable voltage signal; the first verification signal is sent to an off-chip safety structure outside the chip through the test module, including: Determining the variable voltage signal based on variable voltage configuration information and a random number; the variable voltage configuration information is generated when the chip is powered on for the first time and stored in a one-time programmable storage area of ​​the chip body; The variable voltage signal is sent to the off-chip safety structure through the test module.

8. A chip security verification device based on the chip according to any one of claims 1 to 5, characterized in that: include: A signal sending module, used for responding to the test safety verification signal, and sending a first verification signal to an off-chip safety structure outside the chip through the test module; A signal receiving module, used for receiving a second verification signal returned by the off-chip security structure through the test module; The signal verification module is used to, when the first verification signal and the second verification signal are consistent, pass the safety verification and the chip enters the test mode.

9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and running on the processor, characterized in that: When the processor executes the computer program, the chip security verification method as described in any one of claims 6 to 7 is implemented.

10. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the chip security verification method as described in any one of claims 6 to 7 is implemented.

11. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the chip security verification method as described in any one of claims 6 to 7 is implemented.