MCU information protection method and device, electronic equipment and readable storage medium

By implementing a multi-level information protection method in the MCU, including access control, debug key authentication, pre-execution verification, dynamic clock regulation and data encryption, the security challenges of the MCU in the Internet of Things and smart devices are solved, significantly improving its anti-attack capabilities and data security.

CN120162837APending Publication Date: 2025-06-17镁佳(北京)科技有限公司
View PDF 0 Cites 4 Cited by

Patent Information

Application Number
CN202510284159.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-11
Publication Date
2025-06-17

AI Technical Summary

Technical Problem

The widespread use of MCUs in the Internet of Things and smart devices poses severe security challenges and is vulnerable to physical, network and software attacks, resulting in data breaches and functional failures.

Method used

By implementing a multi-level information protection method in the MCU, including storage access verification based on access control list, interface protection for debugging key authentication, code protection for pre-execution verification and dynamic monitoring, power protection for dynamically regulating clock frequency and phase, and encryption measures for data transmission channels.

Benefits of technology

It effectively improves the data security and attack resistance of the MCU, prevents unauthorized data access, code injection attacks and power signal leakage, and ensures the normal operation and information security of the MCU.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120162837A_ABST
    Figure CN120162837A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of microcontrollers, and provides an MCU information protection method and device, electronic equipment and a readable storage medium, and the method comprises the steps: checking a storage access request according to an access control list; wherein the access control list comprises an authorized storage area and an authorized operation type corresponding to the authorized storage area; the storage access request is used for accessing a target storage area of the MCU; according to the debugging secret key, an interface debugging request is checked, and the interface debugging request is used for debugging a target debugging interface of the MCU; identifying a target code instruction of the MCU, and performing pre-execution verification and dynamic monitoring on the target code instruction; adjusting the clock frequency and the clock phase of the MCU according to the load change information and the power consumption change information of the MCU; and implementing encryption measures on the target data transmission channel of the MCU by using the encryption algorithm. According to the technical scheme provided by one or more embodiments of the invention, the data security and the anti-attack capability of the MCU can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the technical field of microcontrollers, and particularly to an information protection method, device, electronic device and readable storage medium for an MCU. Background Art

[0002] As a core component of modern electronic systems, the Microcontroller Unit (MCU) has been widely used in various fields from consumer electronics to industrial automation, automotive electronics, medical devices, etc. The development of the MCU has experienced a stage from simple embedded control to intelligentization with complex computing and communication functions.

[0003] Structurally, an MCU usually consists of a Central Processing Unit (CPU), a memory (including RAM and ROM), input / output interfaces (I / O), and various peripherals (such as timers, communication interfaces, etc.). The main features of the MCU include low power consumption, high performance, high integration, and programmability, which can meet the requirements of different application scenarios.

[0004] However, with the wide application of MCUs in the Internet of Things and intelligent devices, their security faces severe challenges. MCUs are vulnerable to various attacks, including physical attacks, network attacks, and software attacks. These attacks may lead to data leakage and function failure of the MCU, and even endanger the personal safety of users. Summary of the Invention

[0005] In view of this, one or more embodiments of the present disclosure provide an information protection method, device, electronic device and readable storage medium for an MCU, which can improve the data security and anti-attack ability of the MCU.

[0006] On the one hand, the present disclosure provides an information protection method for an MCU, the method includes: verifying a storage access request according to an access control list; wherein, the access control list includes an authorized storage area and an authorized operation type corresponding to the authorized storage area; the storage access request is used to access a target storage area of the MCU; verifying an interface debugging request according to a debugging key, the interface debugging request is used to debug a target debugging interface of the MCU; identifying a target code instruction of the MCU and performing pre-execution verification and dynamic monitoring on the target code instruction; adjusting the clock frequency and clock phase of the MCU according to the load change information and power consumption change information of the MCU; implementing an encryption measure on a target data transmission channel of the MCU by using an encryption algorithm.

[0007] On the other hand, the present disclosure also provides an information protection device for an MCU, the device comprising: a storage protection unit for verifying a storage access request according to an access control list; wherein the access control list includes an authorized storage area and an authorized operation type corresponding to the authorized storage area; the storage access request is used to access a target storage area of the MCU; an interface protection unit for verifying an interface debugging request according to a debugging key, the interface debugging request being used to debug a target debugging interface of the MCU; a code protection unit for identifying target code instructions of the MCU and performing pre-execution verification and dynamic monitoring on the target code instructions; a power protection unit for adjusting the clock frequency and clock phase of the MCU according to the load change information and power consumption change information of the MCU; a transmission protection unit for implementing encryption measures on a target data transmission channel of the MCU by using an encryption algorithm.

[0008] On the other hand, the present disclosure also provides an electronic device, the electronic device comprising a memory and a processor, the memory being used for storing a computer program, and when the computer program is executed by the processor, the information protection method of the above-mentioned MCU is implemented.

[0009] On the other hand, the present disclosure also provides a computer-readable storage medium, the computer-readable storage medium being used for storing a computer program, and when the computer program is executed by a processor, the information protection method of the above-mentioned MCU is implemented.

[0010] The technical solutions provided by one or more embodiments of the present disclosure are as follows. First, for the memory of the MCU, different access permissions and operation permissions are set for different storage areas, which can prevent unauthorized reading of the internal data of the MCU. Second, strict usage restrictions are imposed on the debugging interfaces of the MCU, and encryption authentication means are adopted to ensure that only legitimate devices and personnel can interact with the MCU through these debugging interfaces, thereby preventing the risk of illegal intrusion by external tools. Third, a verification step is introduced into the execution process of important code instructions of the MCU, which can identify and prevent possible code injection attacks and ensure the integrity and reliability of the code instructions. Fourth, by dynamically regulating the clock frequency and phase, the signal characteristics of the power supply side channel of the MCU can be effectively changed, reducing the possibility of sensitive information being carried in the power supply signal fluctuations and reducing the probability of information leakage caused by attacking the power supply signal. Finally, by using an encryption algorithm, the data transmission channel of the sensitive data stream can be encrypted, which can avoid eavesdropping and tampering of sensitive data, thereby effectively solving the information security problem.

[0011] The technical solution provided by one or more embodiments of the present disclosure constructs a comprehensive and in-depth information security protection system for the MCU at multiple levels through the combined action of five steps, which not only improves the ability of the MCU to resist various malicious attacks, but also ensures the normal operation of the MCU without being affected. BRIEF DESCRIPTION OF THE DRAWINGS

[0012] The features and advantages of the embodiments of the present disclosure will be more clearly understood by referring to the accompanying drawings. The drawings are schematic and should not be construed as limiting the present disclosure in any way. In the drawings:

[0013] Figure 1 A schematic diagram of the steps of the information protection method for the MCU in one embodiment of the present disclosure is shown;

[0014] Figure 2 A schematic diagram of the functional modules of the information protection device for the MCU in one embodiment of the present disclosure is shown;

[0015] Figure 3 A schematic diagram of the structure of an electronic device in one embodiment of the present disclosure is shown. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0016] To make the objectives, technical solutions and advantages of the embodiments of the present disclosure clearer, the technical solutions in the embodiments of the present disclosure will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present disclosure. Obviously, the described embodiments are some but not all of the embodiments of the present disclosure. All other embodiments obtained by those skilled in the art based on the embodiments of the present disclosure without creative efforts shall fall within the protection scope of the present disclosure.

[0017] Please refer to Figure 1 , the information protection method for the MCU provided by one embodiment of the present disclosure may include the following multiple steps.

[0018] S1: Check the storage access request according to the access control list. Wherein, the access control list includes an authorized storage area and an authorized operation type corresponding to the authorized storage area; the storage access request is used to access the target storage area of the MCU.

[0019] In this embodiment, by setting up an access control list, the system administrator can set strict read and write permissions in different storage areas of the MCU. The access control list can include sub-lists of multiple security levels. For example, the storage space of the MCU can be divided into multiple areas, such as a boot area, a firmware storage area, an application running area, and a data cache area. Each area can have an independent security level and be bound to different access permissions. In this way, when a storage access request from a certain user or process attempts to access data in a specific area, it can first verify whether the storage access request has the corresponding security level permissions. If not, this operation is immediately prohibited and an alarm mechanism is triggered. In this way, even if an attacker obtains partial storage access rights to the MCU, the possibility of their unauthorized reading of other stored data in the MCU can be minimized to the greatest extent.

[0020] In some embodiments, the checking of the storage access request according to the access control list includes: checking whether the address permission of the storage access request passes according to the access control list; if the address permission does not pass, prohibiting the storage access request; if the address permission passes, checking whether the operation permission of the storage access request passes according to the access control list; if the operation permission does not pass, prohibiting the storage access request; if the operation permission passes, responding to the storage access request.

[0021] Specifically, by using the access control list, the storage space of the MCU can be carefully hierarchically divided and strictly managed in terms of permissions, ensuring that the security of the internal information of the MCU is fully guaranteed.

[0022] First of all, it is necessary to define the storage areas and access levels to determine which parts or types of data need to be particularly protected. According to different importance levels, a hierarchical architecture can be established. For example, all program codes and their execution parameters are usually set as the data storage space with the highest sensitivity level; configuration information comes second; general operation logs or other low-risk contents can be regarded as the lowest-level objects. In some actual application examples, for the protection mechanism of the MCU memory, it may include setting corresponding different hierarchical access levels for the main program code segment, stack area, static data area, etc. independently. The high-level access permission may be: operations allowed only by the CPU core (such as reading, writing, and executing). The low-level access permission level may be: the peripheral hardware device can only perform fixed-formatted reading of messages. For example, in the application scenario of a certain MCU, the bootloader code block in the ROM will be classified into the highest privilege level 0, and no other external unit is allowed to directly modify its instruction sequence, while the text display buffer related to the human-machine interface for user interaction operations is placed at a relatively loose level 3, supporting necessary updates to be completed by the specified driver function.

[0023] Secondly, based on the results defined in the previous step, specific rights can be explicitly granted to different roles or components. This means creating a series of policies or protocols that automatically match and verify when a subject attempts to access a target resource. For example, referring to the formula L = f(U), where L represents the access permission label value, which can be a set of consecutive integer values within the range [0, 7], and U refers to the identity identification number of the entity initiating the request. The optimal choice depends on the security requirements and efficiency considerations of the actual system. The above relationship indicates that each participant can obtain a unique digital code based on its own characteristics to determine whether it can cross the corresponding barrier to obtain data. For example, in an embedded microcontroller environment, the central processing unit itself has full control, that is, f(CPU core ID) equals 0, allowing unrestricted manipulation of all address ranges within the instruction cycle; while for those action modules responsible for receiving external sensing signals and providing appropriate feedback, f(I / O port address) = 3, which means that such units can only search and update limited information records within a preset range without involving deep logical operation links.

[0024] In some embodiments, after the storage access request passes the detection, the storage access request can be monitored.

[0025] Specifically, even if a perfect static protection system is established for the memory of the MCU, real-time detection is still crucial to prevent damage events caused by unforeseen threats. Therefore, a monitoring subsystem is introduced to continuously track and analyze whether there is an illegal tendency in memory access activities and take prompt actions, which can reduce the impact degree of potential risks. In some actual application scenarios, such as in some high-level military MCU chips equipped with special security protection modules, this unit uses algorithms to regularly inspect the interaction conditions of each endpoint and identify whether there are behaviors beyond the normal scope by comparing historical patterns. If there is a suspected intrusion alarm, the locking process will be immediately triggered or the intensity of the existing isolation barrier level will be adjusted to prevent it. Monitoring the storage access request ensures that even if there is a situation of bypassing the previous two security measures, it can be contained in a short time.

[0026] In a practical application example, if the identifier ID of the storage access request is I, the target address Addr is A, and the read / write type Type is R or W, then this request is only allowed to pass when I exists in the corresponding permission list and the (A, Type) combination satisfies the rules in this form, where ID represents the access identifier, Addr represents the memory address, and R / W represents the read / write operation.

[0027] S2: Verify the interface debugging request according to the debugging key, where the interface debugging request is used to debug the target debugging interface of the MCU.

[0028] In this embodiment, in order to more effectively prevent illegal intrusion from external tools, a management policy for using a debugging interface based on role authentication can be introduced. A dedicated security key or certificate can be configured for the debugging interface, and it is required that each request to connect to the debugging interface provides the correct credentials. At the same time, clear usage permission rules can be defined for the debugging interface. For example, only devices within a certain specific IP address range are allowed to perform limited diagnostic debugging, and the access period is limited. All operation commands from external devices are strictly filtered to prevent any unauthorized attempts to change configuration registers or load low-level boot loaders and other operations. In some actual application scenarios, assume that a certain manufacturer wants to test the performance of its product. Then, it can obtain a temporary access license through early registration to perform limited debugging operations such as reading registers without the right to rewrite; while for other non-trusted entities, all debugging interface functions are directly blocked.

[0029] In some embodiments, the method for verifying an interface debugging request according to a debugging key includes: verifying whether the role permission of the interface debugging request passes; if the role permission does not pass, prohibiting the interface debugging request; if the role permission passes, verifying whether the debugging permission of the interface debugging request passes according to the debugging key; if the debugging permission does not pass, prohibiting the interface debugging request; if the debugging permission passes, responding to the interface debugging request.

[0030] Specifically, implementing strict access restrictions on the debugging interface can prevent external tools from illegally intruding into the MCU.

[0031] First, a debugging interface can be defined to determine which ports or protocols are designated for debugging purposes. At the same time, the connection method and parameter format of the debugging interface can be specified. For example, in a specific MCU architecture, only retaining the serial debugging (UART) channel and disabling unnecessary interfaces can reduce the attack surface. Each interface should have a unique identification code.

[0032] After that, an authentication mechanism needs to be introduced to ensure that only authorized users can access. This includes creating unique keys or tokens and requiring verification each time debugging is initiated. For example, in a specific example, different keys are assigned for different levels of access, and a symmetric encryption algorithm is used to ensure the security of the key during transmission. The formula E(M,k) represents the encryption result of data M and the private key k. This encryption process ensures the security and reliability of information transmission. The optimal value depends on the balance between the required security level and processing performance.

[0033] Furthermore, a fine-grained permission control system is implemented. It grants corresponding operation permissions according to the identity of the visitor. In an application scenario, all operations can be divided into several groups, and then user groups that can access these categories are assigned respectively. Specifically, it may limit whether a certain process can modify the register value or whether it is allowed to execute critical tasks such as reset instructions by setting read / write flags.

[0034] In some embodiments, after the interface debugging request passes the detection, the interface debugging request can be monitored, and the running log of the interface debugging request can be recorded.

[0035] Specifically, through the audit and monitoring component, all access activities can be tracked and an alarm response can be made to suspicious behaviors. This includes regularly reviewing the log records to promptly capture unforeseen situations for quickly adjusting the protection strategy. For example, record each debugging connection attempt and its result (failure or success), so as to quickly locate abnormal patterns to take appropriate measures to protect the kernel resources from unauthorized tampering. Throughout the process, always ensure that the access rules are strict enough without losing flexibility, so as to ensure the stable operation of the system while effectively preventing potential threats.

[0036] In a practical application example, if the role of the current user is Role, the provided key is Key, and there exists K(role) = True (indicating the set of keys that the role is authorized to use), the access permission is granted only when K(role).indexOf(Key)!== 1.

[0037] S3: Identify the target code instructions of the MCU, and perform pre-execution verification and dynamic monitoring on the target code instructions.

[0038] In this embodiment, for the security vulnerability problem that may be caused by malicious code injected from the outside, an instruction integrity detection mechanism is proposed as the third layer of protection means. Whenever an instruction sequence involving modifying system critical parameters or jumping to a special processing path is encountered, two verification actions can be performed. First, insert the result of an additional hash operation during the compilation to form a fingerprint signature file, which is saved in the on-chip Flash together with the source code. During the linear operation, use the hash algorithm to calculate the executed instructions again and compare them with the known legal version to confirm that they match before proceeding normally. Second, use the hardware-assisted method to monitor the output port of the CPU pipeline to ensure that the output content is normal. In a specific example, for example, before the RTOS scheduler needs to switch the current task state to the next active unit, it is necessary to verify according to the preset algorithm whether all relevant function call command strings to be issued have been tampered with, and enable the interrupt query mode to monitor any suspicious action signals that may cause sudden failure exceptions.

[0039] In this embodiment, the target code instruction refers to a code segment that may become an attack entry or have a great impact on the security and stability of the system. These often occur when performing sensitive operations such as data access control or hardware resource access. For example, any instruction in the MCU that changes the device encryption configuration will be considered a target code instruction. Identifying the target code instructions of the MCU can ensure that the subsequent steps only focus on the truly high-risk locations rather than all instructions, effectively improving the verification efficiency.

[0040] In some embodiments, the pre-execution verification and dynamic monitoring of the target code instruction include: before executing the target code instruction, calculating the expected hash value of the target code instruction; obtaining the pre-stored hash value of the target code instruction; determining whether to execute the target code instruction according to the comparison result of the expected hash value and the pre-stored hash value; during the execution of the target code instruction, monitoring the code running state of the target code instruction; when the code running state is an abnormal state, interrupting the execution process of the target code instruction.

[0041] Specifically, adding real-time verification steps during the execution of critical instructions can resist security vulnerabilities caused by code injection. Define verification rules, aiming to establish specific verification logics and conditions for the identified critical instructions, such as checking whether the call context or the input parameter format is normal.

[0042] To ensure accurately resisting the injection of illegal instructions, in an example scenario, it is assumed that a hash algorithm is used to calculate the expected hash value (hash_value_expected) of the instruction to be executed, and this value is compared with the pre-stored standard hash value. Only when the two are equal is it considered a legal instruction and allowed to continue execution. Here, the simple but effective mathematical formula expression hash_value_calculated = Hash(instruction_input) is used, where instruction_input represents an actual binary-form machine code instruction stream passed in for execution. For the selection of the hash function Hash(), the characteristics of strong collision resistance and fast processing speed should be considered first. For example, SHA-256 is very suitable for such security protection requirements. It can complete the integrity verification of large files in a short time, and at the same time greatly reduces the risk of the possibility of the same output result but corresponding to two completely different input data; the optimal choice of this method is obviously obtained based on the trade-off of specific application scenarios.

[0043] Pre - execution verification refers to immediately starting a verification program to detect the validity of the input before a critical instruction runs. If a non - compliant situation is found at this node, the command is prohibited from taking effect and a warning mechanism is triggered to remind relevant personnel to promptly troubleshoot the problem point. This can reduce the magnification of the impact of unexpected behaviors on the system.

[0044] In a practical application example, during operation, when the ID of an instruction on a certain critical path is ID, the version number Ver = V, and the expected signature SigExp = S, if S ≠ Hash(ID + V), an error alarm is immediately triggered and the task is interrupted. Here, ID represents the command code, V indicates the version information at the compilation time, and S is the calculated hash value for reference.

[0045] Dynamic monitoring means tracking the progress status of an instruction throughout its execution to quickly respond to possible sudden security threat events. Once an abnormal situation is detected, the current process can be immediately interrupted to prevent malicious activities from causing further damage.

[0046] In some embodiments, error - handling measures can also be established to clarify how to properly solve the problems of critical instruction instances that have passed the initial screening but still have issues. For example, an error can be reported after a certain number of retries, and then the attempt can be stopped or the associated service can be directly terminated to avoid greater losses. In the design of an information protection mechanism for an MCU, if a request to read or write a protected flash memory address range is identified as an abnormal source and a refusal response is caused, the number of attempts will be set to at most N (N >= 1 and N is a natural number) according to the established strategy to balance the contradiction between the fault diagnosis time and the speed of preventing the spread of attacks, and this event will be recorded to assist future traceability and auditing work.

[0047] S4: Adjust the clock frequency and clock phase of the MCU according to the load change information and power consumption change information of the MCU.

[0048] In this embodiment, in the face of the new challenges brought by power-side channel attacks, the application of dynamic clock frequency and phase regulation technology has become another powerful measure. The basic idea of this step is to randomize the working rate of the master oscillator and deliberately introduce small deviations when necessary, making it difficult for potential observers to predict the specific communication pattern, thereby achieving the effect of confusion. In addition, in cooperation with the intelligent temperature compensation module, it can automatically track environmental changes, adjust the output signal strength, and ensure that the overall performance always maintains the optimal level without overly revealing the characteristic frequency information to the monitoring and analysis device for identification. For example, the STM32 series of microcontrollers used in a highly reliable Internet of Things node has an RC clock source with an optional dynamic range that can continuously vary from 1 to 8 MHz according to the actual situation. Moreover, it also integrates an advanced PLL frequency multiplication circuit that can be adjusted in real time at the software level to generate more complex pulse patterns, making it more difficult to capture the energy distribution characteristics during the internal operation process.

[0049] In some embodiments, adjusting the clock frequency and clock phase of the MCU according to the load change information and power consumption change information of the MCU includes: obtaining the load change information and the power consumption change information of the MCU, where the load change information includes the processor occupancy rate; comparing the load change information with a load change threshold; comparing the power consumption change information with a power consumption change threshold; if the load change information exceeds the load change threshold, or the power consumption change information exceeds the power consumption change threshold, then adjusting the clock frequency and the clock phase of the MCU according to a preset algorithm.

[0050] Specifically, by using built-in sensors or monitoring software, the working condition of the MCU can be continuously monitored, parameters such as task requirements, CPU occupancy rate, and kernel status can be evaluated, and the power consumption fluctuation can be recorded by a power meter. During this process, ensure that the data sampling accuracy reaches the nanosecond level to accurately capture any subtle changes. For example, in one embodiment, a high-speed A / D conversion circuit can be used to achieve this goal, and at the same time, the maximum detection error is set not to exceed ±1% to ensure the accuracy of the result.

[0051] Comparing the detection result with a preset threshold can determine whether to adjust the clock frequency and clock phase of the MCU. For example, by comparing the current reading with the historical average value and the pre-set safety boundary, a significant difference can be found, which may mean that the MCU is suffering from a power-side channel attack. The formula for comparing the detection result with a preset threshold is expressed as D = |P(t) - P_0| / P_0 ≥ k, where P(t) represents the power consumption monitored in real time, P_0 represents the reference level, and k, as a sensitivity adjustment coefficient, is usually set between 0.1 and 2, and the optimal choice is determined according to the actual situation. This step aims to give an early warning of potential threats.

[0052] In a practical application example, if the power consumption ΔP exceeds the standard deviation by N times, it is determined that an abnormal situation has occurred: that is, when |ΔPmean(ΔPower)| > N * stdev(ΔPower), corresponding actions are taken to reduce the risk factor to a controllable range. Here, ΔP is the instantaneous power consumption increment, and N is used to set the threshold multiple parameter.

[0053] Dynamically adjusting the parameters of the clock signal can confuse external monitors. For example, the operating frequency f and the initial phase angle φ can be changed so that internal operations cannot be predicted and modeled, increasing the difficulty of reverse derivation.

[0054] In a practical application example, if an anomaly is detected, appropriate values are randomly selected from the set S(f_min, f_max) and the range [0°, 360°] as the clock frequency and clock phase. Here, f_min / f_max represents the allowable minimum / maximum limit.

[0055] S5: Use an encryption algorithm to implement encryption measures on the target data transmission channel of the MCU.

[0056] In this embodiment, in order to overcome the risk points that the existing solutions cannot well handle near-field wireless detection and man-in-the-middle hijacking, a combined strategy based on physical isolation + segmented encryption is adopted to enhance the security of the data stream. That is, for all message bodies entering and leaving the kernel, regardless of their length, they are all passed through a secretly negotiated algorithm and transformed into a series of scrambled character strings that only the other party can correctly parse and interpret. At each intermediate forwarding node along the way, re-encryption and decryption packaging are performed to update the secret key value until the target destination is reached. For example, in a typical industrial control system application scenario, before exchanging important parameters between the ARMCortex–M kernel and other peripheral devices, a series of complex public-private key pair negotiation processes must be carried out to establish a temporary shared secret. Subsequently, the content to be sent is segmented and packaged, and each frame is attached with an HMAC identifier and processed through the AES-GCM advanced block coding technology to ensure that the original form of sensitive data is not exposed throughout the process to avoid the risk of being intercepted and cracked.

[0057] In some embodiments, the use of an encryption algorithm to implement encryption measures on the target data transmission channel of the MCU includes: determining the encryption strength of the candidate data transmission channels of the MCU; determining the volume of the content transmitted by the candidate data transmission channels; if the encryption strength is greater than or equal to the minimum encryption limit and the volume of the content transmitted is greater than or equal to the minimum information scale, then determining the candidate data transmission channel as the target data transmission channel; using the encryption algorithm to implement encryption measures on the target data transmission channel.

[0058] In a practical application example, if the encryption strength level L ≥ M and the data volume D is greater than or equal to T, then the AES or a higher - specification algorithm is selected to ensure the security and reliability during the entire transmission process. Here, L refers to the scale of the key strength level, M sets the minimum encryption limit, D refers to the volume of the actual transmitted content, and T is the minimum information scale required to activate the high - level encryption mode.

[0059] It should be noted that multiple steps of this implementation method can be repeatedly executed until the MCU device is shut down or it is confirmed that there is no abnormality, so as to keep the entire protection mechanism of the MCU in an active state. During the loop, after each complete iteration, there will be a short pause, waiting for the next cycle to arrive before making another judgment. Such an internal information protection method for the MCU not only improves the ability to resist malicious attacks but also ensures that the normal operation is not affected.

[0060] For the technical solutions provided by one or more embodiments of the present disclosure, first, for the memory of the MCU, different access permissions and operation permissions are set for different storage areas, which can prevent the internal data of the MCU from being read without authorization. Second, strict usage restrictions are imposed on the debugging interfaces of the MCU, and encryption authentication means are adopted to ensure that only legitimate devices and personnel can interact with the MCU through these debugging interfaces, thereby preventing the risk of illegal intrusion by external tools. Third, a verification step is introduced during the execution process of important code instructions of the MCU, which can identify and prevent possible code injection attacks, ensuring the integrity and reliability of the code instructions. Fourth, by dynamically regulating the clock frequency and phase, the signal characteristics of the power - supply side channel of the MCU can be effectively changed, reducing the possibility of sensitive information being carried in the power - signal fluctuations and reducing the probability of information leakage caused by attacking the power signal. Finally, using encryption algorithms, the data - transmission channels of sensitive data streams can be encrypted, avoiding the eavesdropping and tampering of sensitive data, and thus effectively solving the information - security problem.

[0061] For the technical solutions provided by one or more embodiments of the present disclosure, through the combined action of five steps, a comprehensive and in - depth information - security protection system is constructed for the MCU at multiple levels, which not only improves the ability of the MCU to resist various malicious attacks but also ensures that the normal operation of the MCU is not affected.

[0062] Please refer to Figure 2 , the present disclosure also provides an information - protection device for an MCU, and the device includes:

[0063] A storage - protection unit 100, configured to verify a storage - access request according to an access - control list; wherein, the access - control list includes authorized storage areas and the authorized operation types corresponding to the authorized storage areas; the storage - access request is used to access a target storage area of the MCU;

[0064] The interface protection unit 200 is used to verify an interface debugging request according to a debugging key, and the interface debugging request is used to debug a target debugging interface of the MCU;

[0065] The code protection unit 300 is used to identify target code instructions of the MCU and perform pre-execution verification and dynamic monitoring on the target code instructions;

[0066] The power supply protection unit 400 is used to adjust the clock frequency and clock phase of the MCU according to the load change information and power consumption change information of the MCU;

[0067] The transmission protection unit 500 is used to implement an encryption measure on a target data transmission channel of the MCU by using an encryption algorithm.

[0068] In one embodiment, the storage protection unit 100 is specifically configured to verify whether the address permission of the storage access request passes according to the access control list; if the address permission does not pass, the storage access request is prohibited; if the address permission passes, it is verified according to the access control list whether the operation permission of the storage access request passes; if the operation permission does not pass, the storage access request is prohibited; if the operation permission passes, the storage access request is responded to.

[0069] In one embodiment, the interface protection unit 200 is specifically configured to verify whether the role permission of the interface debugging request passes; if the role permission does not pass, the interface debugging request is prohibited; if the role permission passes, it is verified according to the debugging key whether the debugging permission of the interface debugging request passes; if the debugging permission does not pass, the interface debugging request is prohibited; if the debugging permission passes, the interface debugging request is responded to.

[0070] In one embodiment, the code protection unit 300 is specifically configured to calculate an expected hash value of the target code instruction before executing the target code instruction; obtain a pre-stored hash value of the target code instruction; determine whether to execute the target code instruction according to a comparison result between the expected hash value and the pre-stored hash value; during the execution of the target code instruction, monitor the code running state of the target code instruction; when the code running state is an abnormal state, interrupt the execution process of the target code instruction.

[0071] In one embodiment, the power protection unit 400 is specifically configured to obtain the load change information and the power consumption change information of the MCU, where the load change information includes the processor occupancy rate; compare the load change information with a load change threshold; compare the power consumption change information with a power consumption change threshold; if the load change information exceeds the load change threshold, or the power consumption change information exceeds the power consumption change threshold, then adjust the clock frequency and the clock phase of the MCU according to a preset algorithm.

[0072] In one embodiment, the transmission protection unit 500 is specifically configured to determine the encryption strength of a candidate data transmission channel of the MCU; determine the volume of the transmission content of the candidate data transmission channel; if the encryption strength is greater than or equal to a minimum encryption limit, and the volume of the transmission content is greater than or equal to a minimum information scale, then determine the candidate data transmission channel as the target data transmission channel; and implement an encryption measure on the target data transmission channel by using the encryption algorithm.

[0073] In one embodiment, the storage protection unit 100 is further configured to monitor the storage access request after the storage access request passes the detection.

[0074] In one embodiment, the interface protection unit 200 is further configured to monitor the interface debugging request and record the operation log of the interface debugging request after the interface debugging request passes the detection.

[0075] Each unit described in the above embodiments can be specifically implemented by a computer chip or by a product with a certain function. A typical implementation device is a computer. Specifically, the computer can be, for example, a personal computer, a laptop computer, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or a combination of any of these devices.

[0076] For the convenience of description, the above devices are described by dividing them into various units according to functions. Of course, when implementing the present application, the functions of each unit can be implemented in one or more software and / or hardware.

[0077] Please refer to Figure 3 , the present disclosure further provides an electronic device, where the electronic device includes a memory and a processor, the memory is used to store a computer program, and when the computer program is executed by the processor, the information protection method of the above-mentioned MCU is implemented.

[0078] The present disclosure also provides a computer-readable storage medium for storing a computer program, which, when executed by a processor, implements the above-mentioned information protection method for the MCU.

[0079] Among them, the processor may be a central processing unit (CPU). The processor may also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. chips, or combinations of the above types of chips.

[0080] As a non-transitory computer-readable storage medium, the memory can be used to store non-transitory software programs, non-transitory computer-executable programs, and modules, such as the program instructions / modules corresponding to the methods in the embodiments of the present disclosure. The processor executes various functional applications and data processing of the processor by running the non-transitory software programs, instructions, and modules stored in the memory, that is, implements the methods in the above method embodiments.

[0081] The memory may include a program storage area and a data storage area. Among them, the program storage area can store an operating system and application programs required for at least one function; the data storage area can store data created by the processor, etc. In addition, the memory may include high-speed random access memory, and may also include non-transitory memory, such as at least one magnetic disk storage device, flash memory device, or other non-transitory solid-state storage devices. In some embodiments, the memory may optionally include a memory remotely provided with respect to the processor, and these remote memories may be connected to the processor through a network. Examples of the above networks include, but are not limited to, the Internet, enterprise intranets, local area networks, mobile communication networks, and combinations thereof.

[0082] Those skilled in the art can understand that to implement all or part of the processes in the above method embodiments, it can be completed by instructing relevant hardware through a computer program. The program can be stored in a computer-readable storage medium. When the program is executed, it can include the processes of the above method embodiments. Among them, the storage medium can be a magnetic disk, an optical disc, a read-only memory (ROM), a random access memory (RAM), a flash memory, a hard disk drive (HDD), or a solid-state drive (SSD), etc.; the storage medium can also include a combination of the above types of memories.

[0083] Each embodiment in this specification is described in a progressive manner. For the same or similar parts among the embodiments, reference can be made to each other. The key point of each embodiment is to illustrate the differences from other embodiments. In particular, for the embodiments of the device, equipment, and storage medium, since they are basically similar to the method embodiments, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiments.

[0084] The above description is only for the embodiments of the present application and is not intended to limit the present application. For those skilled in the art, various changes and modifications can be made to the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included within the scope of the claims of the present application.

[0085] Although the embodiments of the present disclosure have been described in conjunction with the accompanying drawings, those skilled in the art can make various modifications and variations without departing from the spirit and scope of the present disclosure, and such modifications and variations fall within the scope defined by the appended claims.

Claims

1. An information protection method for MCU, characterized in that: The method comprises: According to the access control list, the storage access request is checked; wherein the access control list includes the authorized storage area and the authorized operation type corresponding to the authorized storage area; the storage access request is used to access the target storage area of ​​the MCU; Verifying an interface debugging request according to a debugging key, wherein the interface debugging request is used to debug a target debugging interface of the MCU; Identify the target code instructions of the MCU, and perform pre-execution verification and dynamic monitoring on the target code instructions; Adjusting the clock frequency and clock phase of the MCU according to the load change information and power consumption change information of the MCU; Using an encryption algorithm, encryption measures are implemented on the target data transmission channel of the MCU.

2. The method according to claim 1, characterized in that The checking of the storage access request according to the access control list includes: According to the access control list, checking whether the address permission of the storage access request is passed; If the address permission is not passed, prohibiting the storage access request; If the address permission is passed, then checking whether the operation permission of the storage access request is passed according to the access control list; If the operation permission is not passed, prohibiting the storage access request; If the operation permission is granted, respond to the storage access request.

3. The method according to claim 1, characterized in that The checking the interface debugging request according to the debugging key includes: Check whether the role permission of the interface debugging request is passed; If the role permission is not passed, the interface debugging request is prohibited; If the role authority is passed, then checking whether the debugging authority of the interface debugging request is passed according to the debugging key; If the debugging permission is not passed, the interface debugging request is prohibited; If the debugging permission is granted, respond to the interface debugging request.

4. The method according to claim 1, characterized in that: The pre-execution verification and dynamic monitoring of the target code instructions include: Before executing the target code instruction, calculating an expected hash value of the target code instruction; Obtaining a pre-stored hash value of the target code instruction; Determining whether to execute the target code instruction according to a comparison result between the expected hash value and the pre-stored hash value; During the execution of the target code instructions, monitoring the code running status of the target code instructions; When the code running state is an abnormal state, the execution process of the target code instruction is interrupted.

5. The method according to claim 1, characterized in that The adjusting the clock frequency and clock phase of the MCU according to the load change information and the power consumption change information of the MCU includes: Acquire the load change information and the power consumption change information of the MCU, wherein the load change information includes a processor occupancy rate; comparing the load change information with a load change threshold; Comparing the power consumption change information with a power consumption change threshold; If the load change information exceeds the load change threshold, or the power consumption change information exceeds the power consumption change threshold, the clock frequency and the clock phase of the MCU are adjusted according to a preset algorithm.

6. The method according to claim 1, characterized in that The encryption algorithm is used to implement encryption measures on the target data transmission channel of the MCU, including: Determining the encryption strength of a candidate data transmission channel of the MCU; Determining the transmission content volume of the candidate data transmission channel; If the encryption strength is greater than or equal to the minimum encryption limit, and the volume of the transmitted content is greater than or equal to the minimum information size, determining the candidate data transmission channel as the target data transmission channel; The encryption algorithm is used to implement encryption measures on the target data transmission channel.

7. The method according to any one of claims 1 to 6, characterized in that: The method further comprises at least one of the following: After the storage access request passes the detection, monitoring the storage access request; After the interface debugging request passes the detection, the interface debugging request is monitored and a running log of the interface debugging request is recorded.

8. An information protection device for MCU, characterized in that: The device comprises: A storage protection unit, configured to check a storage access request according to an access control list; wherein the access control list includes an authorized storage area and an authorized operation type corresponding to the authorized storage area; and the storage access request is used to access a target storage area of ​​the MCU; An interface protection unit, used to check an interface debugging request according to a debugging key, wherein the interface debugging request is used to debug a target debugging interface of the MCU; A code protection unit, used for identifying the target code instructions of the MCU, and performing pre-execution verification and dynamic monitoring on the target code instructions; A power protection unit, used to adjust the clock frequency and clock phase of the MCU according to the load change information and power consumption change information of the MCU; The transmission protection unit is used to implement encryption measures on the target data transmission channel of the MCU using an encryption algorithm.

9. An electronic device, characterized in that: The electronic device comprises a memory and a processor, wherein the memory is used to store a computer program, and when the computer program is executed by the processor, the method according to any one of claims 1 to 7 is implemented.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium is used to store a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 7 is implemented.

Citation Information

Cited By

  • Data transmission method, server, readable storage medium and program product

    CN120743557A

  • Debugging method and device, electronic equipment and vehicle

    CN120915610A

  • Sensitive code isolation execution method based on strategy

    CN121071868A

  • Method for verifying access permission, integrated circuit system, and electronic device

    EP4715644A1