Chip system, inter-chip communication method and electronic equipment
By using preset keys to encrypt data in the chip system, the problems of low inter-chip communication efficiency and insufficient data security are solved, and high real-time and high security inter-chip communication is achieved.
Patent Information
- Application Number
- CN202311826060.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-27
- Publication Date
- 2025-06-27
AI Technical Summary
The existing inter-chip communication efficiency is low, and high real-time inter-chip secure transmission cannot be achieved. Data is easily tampered with and stolen, affecting the implementation of multi-chip system functions.
A chip system is adopted, wherein the first chip pre-stores a preset key corresponding to the second chip, encrypts the target data before transmitting data through the first security module, generates a session key, and communicates through the encrypted data.
It realizes high real-time inter-chip secure communication, avoids data tampering and theft, ensures the reliability of the data on the receiving end, and thus omits the data verification and permission configuration process, improving communication efficiency.
Smart Images

Figure CN120217397A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of chips, and in particular, to a chip system, a chip - to - chip communication method, and an electronic device. Background Art
[0002] With the development of the semiconductor field, the communication between chips needs to restrict the data access permission through the Memory Protect Unit (MPU) in the chip to ensure the security of data interaction. For example: every time data is transmitted or accessed between chips, different access space permissions need to be set for different data. Or, currently, in order to ensure the communication security between chips, the received interaction information can also be temporarily stored in the Static Random Access Memory (SRAM), and then the General - Purpose Processor (CPU) calls a security module (such as: crypto) to perform encryption, decryption, and integrity operations on the received data, and the data interaction will continue only after the operations pass.
[0003] Although the above - mentioned methods ensure the security of data transmission, the permission configuration through the MPU or the interaction information needs to be temporarily stored in the SRAM, resulting in low efficiency and unable to complete high - real - time inter - chip secure transmission. Moreover, the data transmitted between chips is also extremely vulnerable to tampering and theft, directly affecting the realization of the functions of the multi - chip system.
[0004] Therefore, how to achieve high - real - time secure communication between chips is an urgent problem to be solved. Summary of the Invention
[0005] Embodiments of this application provide a chip system, a chip - to - chip communication method, and an electronic device to achieve high - real - time secure communication between chips.
[0006] In a first aspect, embodiments of this application provide a chip system. The system includes a first chip and a second chip. The first chip pre - stores a preset key corresponding to the second chip. The first chip includes a first bus, a first security module, and a first transmission interface. The first security module is connected to the first bus, and the first transmission interface is communicatively connected to the first bus through the first security module. The first security module is configured to: obtain target data for the second chip and the preset key from the first bus; generate a first session key corresponding to the target data based on the preset key; encrypt the target data based on the first session key to obtain encrypted target data. The first transmission interface is configured to: send the encrypted target data to the second chip.
[0007] The current communication efficiency between chips is low, and it is impossible to complete the secure inter-chip transmission with high real-time performance. Moreover, the data transmitted between chips is extremely vulnerable to tampering and theft, which directly affects the realization of the functions of the multi-chip system. In response to this, the embodiments of the present application provide a chip system that can achieve secure inter-chip communication with high real-time performance. Among them, the chip system includes a first chip and a second chip. The first chip can be a master chip, and the second chip can be one of a slave chip, a dumb chip, a security chip, or other master chips connected to the master chip. The first chip pre-stores a preset key corresponding to the second chip, and the preset key can be used to encrypt the data transmitted between the first chip and the second chip. The first chip includes a first bus, a first security module, and a first transmission interface. The first security module is disposed between the first bus and the first transmission interface, so that each time the first chip transmits data to the second chip through the first transmission interface, it needs to pass through the first security module. The first security module can generate a session key for encrypting the target data based on the preset key before the first chip transmits the target data to the second chip through the first transmission interface, and encrypt the target data based on the first session key. After the target data is encrypted, the first transmission interface will send the encrypted target data to the second chip. Therefore, the data transmitted between the first chip and the second chip is encrypted data, which can greatly avoid the tampering and theft of inter-chip communication, and can ensure that the data received by the second chip is reliable. Thus, after the second chip decrypts the encrypted target data, it can further omit the process of verifying the target data or configuring permissions, etc., and can directly process the decrypted target data by the second chip, thereby realizing secure inter-chip communication with high bandwidth and high real-time performance.
[0008] In a possible implementation manner, the second chip includes a second bus, a second security module, and a second transmission interface. The second security module is connected to the second bus, and the second transmission interface is communicatively connected to the second bus through the second security module; the second chip pre-stores the same preset key as that in the first chip; the second transmission interface is configured to: receive the encrypted target data sent by the first chip; the second security module is configured to: determine a second session key based on the preset key pre-stored in the second chip; decrypt the encrypted target data based on the second session key, and obtain and transmit the target data to the second bus for data processing.
[0009] In an embodiment of the present application, after the second chip receives the encrypted target data sent from the first chip through the second transmission interface, it needs to transmit the encrypted target data to the second security module, and the second security module can decrypt the encrypted target data. Among them, the same preset key as that in the first security module is also pre-stored in the second security module. Therefore, a secure channel can be formed between the second security module and the first security module on the sending end (i.e., the first chip side), ensuring that the receiving end (i.e., the second chip side) can directly generate a matching session key based on the same preset key to decrypt the encrypted target data. This method can achieve inter-chip secure communication between the first chip and the second chip and reduce communication latency.
[0010] In a possible implementation manner, the first chip further includes a first key management module, and the first key management module is respectively connected to the first bus and the first security module; the first key management module pre-stores the preset key corresponding to the second chip; the first key management module is configured to: send the preset key to the first security module.
[0011] In an embodiment of the present application, the first chip further includes a first key management module for storing a preset key, where the preset key corresponds to the second chip. When the first chip initiates an interaction with the second chip, the first security module will obtain the preset key corresponding to the second chip from the first key management module, thereby ensuring the security of the key and guaranteeing subsequent inter-chip secure communication. The first key management module may be an electronic fuse, or other non-volatile storage devices that protect the chip, and can be directly or indirectly connected to the first bus and the first security module.
[0012] In a possible implementation manner, the first chip further includes a random number generation module, and the random number generation module is connected to the first bus; the random number generation module is configured to: generate a target random number for the target data, and send the target random number to the first security module and the second security module; the first security module is specifically configured to: generate the first session key corresponding to the target data based on the preset key and the target random number.
[0013] In an embodiment of the present application, in order to further improve the security of inter-chip communication, the first chip further includes a random number generation module, which can generate a unique target random number for the receiving end (i.e., the second chip) for each session. The target random number can jointly generate a session key with the preset key, increasing the difficulty of being cracked, thereby ensuring the security of the target data and reducing latency.
[0014] In a possible implementation manner, the above-mentioned second security module is specifically configured to: obtain the above-mentioned target random number, and determine the above-mentioned second session key based on the preset key prestored in the above-mentioned second chip and the above-mentioned target random number.
[0015] In the embodiment of the present application, after the random number generation module generates the target random number, it synchronously configures the target random number into the second security module, so that the second security module can generate the second session key for decryption based on the target random number and the preset key prestored in the second chip, thereby ensuring the communication security between chips.
[0016] In a possible implementation manner, the above-mentioned first chip and the above-mentioned second chip are encapsulated together; or, the above-mentioned first chip and the above-mentioned second chip are separately encapsulated.
[0017] In the embodiment of the present application, both the first chip and the second chip can be dies. The first chip and the second chip can be encapsulated together, that is, a stacked die chip composed of multiple dies is formed. The first chip and the second chip can also be separately encapsulated individual chips.
[0018] In a possible implementation manner, the above-mentioned system includes multiple above-mentioned second chips. The above-mentioned first chip prestores the above-mentioned preset keys respectively corresponding to the multiple above-mentioned second chips, and the preset keys corresponding to each above-mentioned second chip are different.
[0019] In the embodiment of the present application, the chip system may include multiple second chips, and the corresponding first chip also prestores multiple preset keys corresponding one-to-one with the second chips, so that when the first chip communicates with the second chip, the communication security with any one of the second chips can be ensured.
[0020] In a second aspect, an inter-chip communication method is provided in an embodiment of the present application, which is applied to a chip system. The chip system includes a first chip and a second chip. The first chip prestores a preset key corresponding to the second chip; the first chip includes a first bus, a first security module, and a first transmission interface. The first security module is connected to the first bus, and the first transmission interface is communicatively connected to the first bus through the first security module; the method includes: obtaining, by the first security module in the first chip, target data for the second chip and the preset key from the first bus; generating a first session key corresponding to the target data based on the preset key; encrypting the target data based on the first session key to obtain encrypted target data; and sending the encrypted target data to the second chip through the first transmission interface.
[0021] In a possible implementation manner, the second chip includes a second bus, a second security module, and a second transmission interface. The second security module is connected to the second bus, and the second transmission interface is communicatively connected to the second bus through the second security module. The second chip pre-stores the same preset key as that in the first chip. The method further includes: receiving, through the second transmission interface in the second chip, the encrypted target data sent by the first chip; determining, by the second security module in the second chip, a second session key based on the preset key pre-stored in the second chip; decrypting the encrypted target data based on the second session key, and obtaining and transmitting the target data to the second bus for data processing.
[0022] In a possible implementation manner, the first chip further includes a first key management module. The first key management module is respectively connected to the first bus and the first security module. The first key management module pre-stores the preset key corresponding to the second chip. The method further includes: sending, through the first key management module, the preset key to the first security module.
[0023] In a possible implementation manner, the first chip further includes a random number generation module. The random number generation module is connected to the first bus. The method further includes: generating, through the random number generation module, a target random number for the target data, and sending the target random number to the first security module and the second security module. The generating the first session key corresponding to the target data based on the preset key includes: generating, based on the preset key and the target random number, the first session key corresponding to the target data.
[0024] In a possible implementation manner, the determining, by the second security module in the second chip, a second session key based on the preset key pre-stored in the second chip includes: obtaining, by the second security module in the second chip, the target random number, and determining the second session key based on the preset key pre-stored in the second chip and the target random number.
[0025] In a possible implementation manner, the first chip and the second chip are co-packaged together; or, the first chip and the second chip are respectively packaged.
[0026] In a possible implementation manner, the system includes multiple second chips. The first chip pre-stores the preset keys respectively corresponding to the multiple second chips, and the preset keys corresponding to each second chip are different.
[0027] In a third aspect, an embodiment of the present application provides an electronic device, which includes a circuit board and a chip system as in the first aspect above; the circuit board is electrically connected to the chip system.
[0028] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium for storing computer software instructions used for the electronic device provided in the third aspect above, which includes a program for executing the design in the second aspect above.
[0029] It should be understood that the inter-chip communication method provided in the second aspect of the present application and the electronic device provided in the third aspect are consistent with the technical solutions in the first aspect of the present application. For the specific content and beneficial effects, reference can be made to the chip system provided in the first aspect above, and details will not be elaborated here. Description of the Drawings
[0030] To more clearly illustrate the technical solutions in the embodiments of the present application or the background art, the drawings required for use in the embodiments of the present application or the background art will be described below.
[0031] Figure 1 It is a schematic structural diagram of an existing inter-chip structure provided by an embodiment of the present application.
[0032] Figure 2 It is another schematic structural diagram of an existing inter-chip structure provided by an embodiment of the present application.
[0033] Figure 3 It is a schematic structural diagram of a chip system provided by an embodiment of the present application.
[0034] Figure 4 It is another schematic structural diagram of a chip system provided by an embodiment of the present application.
[0035] Figure 5 It is yet another schematic structural diagram of a chip system provided by an embodiment of the present application.
[0036] Figure 6 It is a schematic packaging diagram of a chip system provided by an embodiment of the present application.
[0037] Figure 7 It is another schematic packaging diagram of a chip system provided by an embodiment of the present application.
[0038] Figure 8 It is a schematic flowchart of an inter-chip communication method provided by an embodiment of the present application. Detailed Embodiments
[0039] The embodiments of the present application will be described below with reference to the drawings in the embodiments of the present application.
[0040] In the description, claims and drawings of the present application, terms such as "first" and "second" are used to distinguish different objects, rather than to describe a specific order. In addition, the terms "comprise" and "have" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device that comprises a series of steps or units is not limited to the listed steps or units, but optionally further comprises steps or units not listed, or optionally further comprises other steps or units inherent to these processes, methods, products or devices.
[0041] It should be understood that in the present application, "at least one (item)" means one or more, and "a plurality" means two or more. "And / or" is used to describe the association relationship of associated objects, indicating that three relationships may exist. For example, "A and / or B" may mean: only A exists, only B exists, and both A and B exist at the same time. Among them, A and B may be singular or plural. The character " / " generally means that the associated objects before and after are in an "or" relationship. "At least one (piece) of the following" or its similar expression means any combination of these items, including any combination of single item (piece) or plural items (pieces). For example, at least one (piece) of a, b or c may mean: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, c may be single or plural.
[0042] Reference to "embodiment" in this context means that a particular feature, structure or characteristic described in connection with the embodiment may be included in at least one embodiment of the present application. The phrase appears in various places in the specification does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment mutually exclusive with other embodiments. It is explicitly and implicitly understood by those skilled in the art that the embodiments described herein may be combined with other embodiments.
[0043] As used in this specification, the terms "component", "module", "system", etc. are used to denote computer-related entities, hardware, firmware, combinations of hardware and software, software, or software in execution. For example, a component can be, but is not limited to, a process running on a processor, a processor, an object, an executable, an execution thread, a program, and / or a computer. By way of illustration, both an application running on a computing device and the computing device can be components. One or more components can reside within a process and / or an execution thread, and a component can be located on one computer and / or distributed between two or more computers. Further, these components can execute from various computer-readable media storing various data structures. A component can communicate, for example, by signals according to one or more data packets (e.g., data from two components interacting with another component among a local system, a distributed system, and / or a network, such as data interacting with other systems via signals over the Internet) through local and / or remote processes.
[0044] First, for the convenience of understanding the embodiments of the present application, the technical problems to be solved and the applicable application scenarios of the embodiments of the present application are specifically analyzed below.
[0045] With the development of the semiconductor field, according to different requirements and application scenarios, chips can be divided into: master chip mode, slave chip mode, and dummy chip mode. Among them, the chips belonging to the master chip mode include a general-purpose processor (central processing unit, CPU), which can be self-booted based on the built-in flash memory (Flash) and security information. The chips belonging to the slave chip mode include a CPU, but there is no built-in Flash inside, and external loading of security assets (such as: firmware information, configuration information, initialization information, test information, etc.) is required for program startup. For example: obtaining security assets from the master chip based on inter-chip communication to achieve secure startup. The chips belonging to the dummy chip mode neither have a CPU nor a built-in Flash. Therefore, the dummy chip needs to rely more on inter-chip communication to obtain security assets to achieve secure startup. Therefore, information interaction needs to be completed between the master and slave, and between the master and dummy chips. The information interaction between chips is not only used to transmit security assets, but also can be used to transmit other interaction data, such as: sensitive information such as processing data, status data, and operation logs. The embodiments of the present application do not make specific limitations on this.
[0046] Currently, the transmission between chips is basically in plain text. The plain text transmission data is often obtained or tampered with by other third parties for the assets stored, processed, and transmitted in the base station. Or the access permission of data is restricted through the memory protection unit (MPU) inside the chip to ensure the security of data interaction. Please refer to the attached Figure 1 , Figure 1 which is a schematic structural diagram of an existing inter-chip provided by the embodiments of the present application. AsFigure 1 As shown, every time data is transmitted between chips or data access is performed, the address protection unit needs to set corresponding access space permissions for different data. Or, cooperate with the security chip to encrypt and transmit data, use the security chip to implement the secure startup of the slave chip or dummy chip, or transmit other sensitive information. Please refer to the appendix Figure 2 , Figure 2 FIG. is a schematic structural diagram of another existing inter-chip structure provided by an embodiment of the present application. As Figure 2 shown, a secure channel needs to be constructed between the chip side and the security chip to ensure the security of the transmission between the chip side and the security chip. This secure channel can be used for inter-chip identity authentication and key negotiation.
[0047] However, the interaction information between chips is in plain text, which is easily tampered with and stolen. If the MPU is used to limit the data access coming in through the transmission interface, different access permissions need to be configured each time different access space permissions are set, and high-real-time inter-chip secure transmission cannot be completed. If the security chip is used for data transmission between chips, the interaction information between chips each time needs to be temporarily stored in the static random access memory inside the receiving side, and then encrypted and decrypted and integrity operations are performed by relevant modules. Only the data that passes the decryption verification will be processed by the processor. This method has low bandwidth and low efficiency, and it is also difficult to meet scenarios with high real-time requirements.
[0048] In response to this, an embodiment of the present application provides a chip system that can achieve high-real-time inter-chip secure communication. Among them, the chip system includes a first chip and a second chip. The first chip can be the main chip at the sending end, and the second chip can be one of the slave chip, dummy chip, security chip or other main chips connected to the main chip at the receiving end. The data transmitted between the first chip and the second chip is encrypted data. The security modules for encryption and decryption are respectively connected to the transmission interface and the bus, which is equivalent to building a secure channel between the first chip and the second chip. The encrypted transmission of data during transmission can greatly avoid the communication between chips being tampered with and stolen, and can ensure that the data received by the second chip is reliable. Moreover, before the encrypted data received at the receiving end is transmitted to the chip-side bus, it passes through the security module and is decrypted, which can further omit the process of temporarily storing and verifying the security of the data or the process of configuring permissions, etc., and can enable the second chip to directly process the decrypted target data, thereby realizing high-bandwidth and high-real-time inter-chip secure communication. Among them, the specific implementation method can refer to the relevant description in the following embodiments, and the embodiments of the present application will not be elaborated here.
[0049] To better understand the embodiments of the present application, please refer to the appendix Figure 3 , Figure 3 FIG. is a schematic structural diagram of a chip system provided by an embodiment of the present application.
[0050] As Figure 3 shown, the above chip system includes a first chip and a second chip. The first chip includes a first bus (Main bus), a first security module, and a first transmission interface. The first security module is connected to the first bus, and the first transmission interface is communicatively connected to the first bus through the first security module. That is, the first security module is disposed between the first bus and the first transmission interface.
[0051] The first chip is used for: establishing secure communication with the second chip and sending encrypted target data to the second chip. The first chip may be the chip or die belonging to the master chip mode mentioned above Figure 1 , but there is no need to set an address protection module between the bus and the transmission interface in the first chip.
[0052] The second chip is used for: decrypting the received encrypted target data to obtain the target data, and performing data processing on the target data. The second chip may be the chip, security chip or die belonging to the master chip mode, slave chip mode, dummy chip mode mentioned above Figure 1 - Figure 2 , and this application does not make specific limitations thereto.
[0053] Among them, as shown above Figure 3 , the first security module in the first chip is a hardware module for encryption and decryption. For example: it can encrypt the data output by the first bus to ensure that the data sent from the first transmission interface outside the first chip is ciphertext to ensure the security of inter-chip communication, and it can also be called a Security link (SECL). Exemplarily, the first security module is used for: obtaining the target data for the second chip and the above-mentioned preset key from the first bus; generating a first session key corresponding to the target data based on the preset key; wherein, the first chip pre-stores a preset key corresponding to the second chip.
[0054] It can be understood that the preset key may be a key pre-stored in the first chip, used to encrypt all or part of the data interacting with the second chip. The preset key may be pre-stored in a separate key management module, electronic fuse or non-volatile memory inside the first chip, and may also be stored in the first security module for encryption and decryption. This application does not make specific limitations thereto, and the embodiments of this application do not make specific limitations either. Correspondingly, the first security module can obtain the preset key from the first bus, can also directly obtain the preset key from other functional modules (such as: key management module, electronic fuse, non-volatile memory, etc.), and can also obtain it from inside the first security module after obtaining the target data for the second chip.
[0055] It can also be understood that each time the first chip initiates an interaction with the second chip, before the first security module transmits the target data to the first transmission interface, it will encrypt the target data. Among them, the first security module can generate a first session key corresponding to the above-mentioned target data based on the obtained preset key, and encrypt the target data that needs to be transmitted currently based on this first session key. If the first chip also needs to transmit another target data to the second chip, the first security module will generate a first session key corresponding to the other target data again based on the preset key, and encrypt the other target data that needs to be transmitted next based on the first session key corresponding to the other target data. Among them, the first session keys corresponding to each target data are all different.
[0056] The data transmitted between the first chip and the second chip are all data encrypted by the first security module. This is equivalent to building a secure channel between the first chip and the second chip, which can greatly avoid the communication between chips being tampered with and stolen, and can ensure that the data received by the second chip is reliable, so that the second chip can directly process the received secure target data.
[0057] In addition, the first chip further includes a processor and a random access memory, which are respectively used for processing and storing target data, etc. In this regard, the embodiments of the present application do not make specific limitations.
[0058] In some other embodiments, the first security module can generate a first session key corresponding to the above-mentioned target data based on the type of the target data and the preset key, that is, different types of target data generate different first session keys. In this regard, the embodiments of the present application do not make specific limitations.
[0059] The first transmission interface (interface, INTF) is a transmission interface that follows a transmission interface communication protocol such as a relevant interface communication protocol. The first transmission interface can send the target data encrypted by the first security module to the second chip.
[0060] In some embodiments, the second chip includes a second bus, a second security module, and a second transmission interface. The second security module is connected to the second bus, and the second transmission interface is communicatively connected to the second bus through the second security module; the second chip pre-stores the same preset key as that in the first chip; the second transmission interface is used to: receive the encrypted target data sent by the first chip; the second security module is used to: determine a second session key based on the preset key pre-stored in the second chip; decrypt the encrypted target data based on the second session key, obtain and transmit the target data to the second bus for data processing.
[0061] As described above Figure 3 As shown, the second chip includes a second bus, a second security module, and a second transmission interface. The second security module is disposed between the second bus and the second transmission interface, such that all data transmitted through the second transmission interface needs to pass through the second security module before reaching the second bus and then being transmitted to the processor in the second chip through the second bus.
[0062] The second transmission interface (interface, INTF) in the second chip is also a transmission interface that follows a relevant transmission interface communication protocol. This second transmission interface can receive the encrypted target data sent by the first chip.
[0063] The second security module is a hardware module for encryption and decryption. For example, it can decrypt the data output by the second transmission interface to ensure that the data transmitted to the second bus is secure and not tampered with, so as to ensure the security of inter-chip communication. In addition, the second security module and the first security module in the first chip together constitute the secure communication between chips, which can also be referred to as a security link (Security link, SECL). Exemplarily, the second security module is used to: obtain the encrypted target data sent by the first chip through the second transmission interface; determine a second session key based on a pre-stored preconfigured key in the second chip; decrypt the encrypted target data based on the second session key to obtain the decrypted target data, and the second security module can transmit the decrypted target data to the second bus for data processing.
[0064] It should be noted that the pre-stored preconfigured key in the second chip is the same as the pre-stored preconfigured key in the first chip. It can also be understood that the first chip and the second chip share a same preconfigured key, which can be referred to as a preconfigured shared key (PSK). It can also be understood that the preconfigured key can be pre-set and mutually matched keys before the first chip and the second chip leave the factory.
[0065] In addition, the preconfigured key can be pre-stored in a separate key management module, an electronic fuse, or a non-volatile memory, etc. inside the second chip, or can also be stored in the second security module for encryption and decryption. This application does not make specific limitations on this, and the embodiments of this application do not make specific restrictions. Correspondingly, the second security module can obtain the preconfigured key from the second bus, or can directly obtain the preconfigured key from other functional modules (such as: key management module, electronic fuse, non-volatile memory, etc.), or can also obtain it from inside the second security module after obtaining the encrypted target data sent by the first chip.
[0066] It can be understood that when the second chip receives the encrypted target data, it will first determine the second session key corresponding to the target data based on the same preset key. Only when the second session key is the same as or matches the first session key can the encrypted target data be successfully decrypted based on the second session key. When the second session key is different from or does not match the first session key, the encrypted target data cannot be successfully decrypted or the decryption is incorrect. This can ensure the reliability of the target data after successful decryption, enabling the processor in the second chip to directly process the decrypted target data.
[0067] In some embodiments, the above-mentioned first chip further includes a first key management module, which is respectively connected to the above-mentioned first bus and the above-mentioned first security module; the first key management module pre-stores the above-mentioned preset key corresponding to the second chip; the first key management module is configured to: send the preset key to the first security module.
[0068] Please refer to the attached Figure 4 , Figure 4 FIG. is a schematic structural diagram of another chip system provided by an embodiment of the present application. As Figure 4 described, the first chip further includes a first key management module for storing a preset key, where the preset key corresponds to the second chip. When the first chip initiates an interaction with the second chip, the first security module will obtain the preset key corresponding to the second chip from the first key management module, thereby ensuring the security of the key and guaranteeing subsequent secure inter-chip communication. The first key management module may be an electronic fuse, or other non-volatile storage devices for protecting the chip.
[0069] In addition, it should be noted that the first key management module may be directly or indirectly connected to the above-mentioned first bus and the above-mentioned first security module. For example: the first key management module may be directly connected to the first bus, or the first bus is connected to the first key management module through other functional modules, that is, the first key management module is indirectly connected to the first bus.
[0070] In other embodiments, as Figure 4 shown, the second chip also includes a second key management module, which is configured to be directly or indirectly connected to the above-mentioned second bus and the above-mentioned second security module; the second key management module pre-stores the above-mentioned preset key corresponding to the second chip; the second key management module is configured to: send the preset key to the second security module.
[0071] In some embodiments, the first chip further includes a random number generation module, which is connected to the first bus; the random number generation module is configured to: generate a target random number for the target data and send the target random number to the first security module and the second security module; specifically, the first security module is configured to: generate the first session key corresponding to the target data based on the preset key and the target random number.
[0072] Please refer to the appendix Figure 5 , Figure 5 FIG. is a schematic structural diagram of another chip system provided by an embodiment of the present application. As Figure 5 described, in order to further improve the security of inter-chip communication, the first chip further includes a random number generation module, which is connected to the first bus, and the random number can be transmitted through the first bus. The random number generation module can generate a unique target random number for the receiving end (i.e., the second chip) during each session, and the target random number can be configured into the first security module and the second security module as an IV value, so as to jointly generate a session key with the preset key, improving the security level and thus ensuring the security of the target data.
[0073] In addition, it should be noted that the connection between the random number generation module and the first bus means that the random number generation module is directly or indirectly connected to the first bus, that is, the random number generation module can be directly connected to the first bus or indirectly connected to the first bus through other functional modules. In this regard, the embodiments of the present application do not make specific limitations.
[0074] In other embodiments, the second chip may also include a random number generation module directly or indirectly connected to the second bus, which can be configured into the first security module and the second security module as an IV value when the second chip transmits data to the first chip.
[0075] In some embodiments, the second security module is specifically configured to: obtain the target random number and determine the second session key based on the preset key pre-stored in the second chip and the target random number.
[0076] It can be understood that after the random number generation module generates the target random number, it will synchronously configure the target random number into the second security module. For example: after being configured into the first security module, it is sent to the second chip through the first transmission interface and configured into the second security module, so that the second security module can generate the second session key for decryption based on the target random number and the preset key pre-stored in the second chip, thereby ensuring the communication security between the chips.
[0077] In some embodiments, the first chip and the second chip are co-packaged together; or, the first chip and the second chip are respectively packaged.
[0078] Please refer to the attached Figure 6 , Figure 6 which is a schematic diagram of the packaging of a chip system provided by an embodiment of the present application. As Figure 6 shown in (1) therein, both the first chip and the second chip can be bare dies (Dies). The first chip and the second chip can be co-packaged together through technologies such as multi-Die co-packaging. That is, the first chip and the second chip are stacked through inter-chip wiring and packaged together, thus forming a co-packaged chip with multiple Dies. As Figure 6 shown in (2) therein, the first chip and the second chip can also be separately packaged individual chips, but the chips can also be communicatively connected through a transmission interface. The embodiments of the present application are applicable to most multi-chip or multi-Die chip systems, ensuring the inter-chip communication security in the chip system.
[0079] In some embodiments, the above system includes multiple above-mentioned second chips. The above-mentioned first chip pre-stores the above-mentioned preset keys respectively corresponding to the multiple above-mentioned second chips, and the preset keys corresponding to each above-mentioned second chip are different.
[0080] Please refer to the attached Figure 7 , Figure 7 which is another schematic diagram of the packaging of a chip system provided by an embodiment of the present application. As Figure 7 shown in (1) and (2) therein, the chip system may include multiple second chips, and each of the multiple second chips can be any one of the chips, security chips or bare dies (Dies) mentioned above Figure 1 - Figure 2 belonging to the master chip mode, slave chip mode, dummy chip mode or other chip modes. Correspondingly, in order to ensure the communication security between the first chip and any one of the second chips, the first chip pre-stores multiple preset keys corresponding one-to-one with the second chips, so that when the first chip communicates with any one of the second chips, the data transmitted can be encrypted to ensure the communication security with any one of the second chips.
[0081] In summary, the embodiment of the present application provides a chip system that can achieve high-real-time secure communication between chips. Among them, the chip system includes a first chip and a second chip. The first chip can be a master chip, and the second chip can be one of a slave chip, a dumb chip, a security chip, or other master chips connected to the master chip. The first chip pre-stores a preset key corresponding to the second chip, and the preset key can be used to encrypt the data transmitted between the first chip and the second chip. The first chip includes a first bus, a first security module, and a first transmission interface. The first security module is disposed between the first bus and the first transmission interface, so that each time the first chip transmits data to the second chip through the first transmission interface, it needs to pass through the first security module. The first security module can generate a session key for encrypting the target data based on the preset key before the first chip transmits the target data to the second chip through the first transmission interface, and encrypt the target data based on the first session key. After the target data is encrypted, the first transmission interface will send the encrypted target data to the second chip. Therefore, the data transmitted between the first chip and the second chip is encrypted data, which can greatly avoid the communication data between chips from being tampered with and stolen. In addition, since the inter-chip data is encrypted, it can be ensured that the data received by the second chip is reliable. Therefore, after the second chip decrypts the encrypted target data, it can omit the process of verifying the target data or configuring permissions, etc., and can directly process the decrypted target data by the second chip, so as to achieve high-bandwidth and high-real-time inter-chip secure communication.
[0082] Next, in combination with the inter-chip communication method provided in the present application, taking the example of a first chip connected to a second chip, the technical problems proposed in the present application will be specifically analyzed and solved.
[0083] Please refer to Figure 8 , Figure 8 which is a schematic flowchart of an inter-chip communication method provided by an embodiment of the present application.
[0084] The inter-chip communication method can be applied to a chip system. The chip system includes a first chip and a second chip. The first chip pre-stores a preset key corresponding to the second chip; the first chip includes a first bus, a first security module, and a first transmission interface. The first security module is connected to the first bus, and the first transmission interface is communicatively connected to the first bus through the first security module.
[0085] The first chip involved in the inter-chip communication method is equivalent to the first chip as described above Figure 3 shown, and the first chip can be used to support the implementation of the relevant content of steps S101 - S104. The second chip involved is equivalent to the above Figure 3The second chip shown can be used to support the implementation of the relevant content in steps S105 - S107. Among them, the method includes:
[0086] Step S101: Obtain target data and a preset key for the second chip.
[0087] Specifically, when the first chip needs to interact with the second chip, the first security module in the first chip can obtain the target data and the preset key for the second chip from the first bus to encrypt the target data.
[0088] Optionally, the above - mentioned first chip further includes a first key management module. The first key management module is directly or indirectly connected to the first bus and the first security module respectively; the first key management module pre - stores the preset key corresponding to the second chip; the method further includes: sending the preset key to the first security module through the first key management module. The first security module will obtain the preset key corresponding to the second chip from the first key management module, thereby ensuring the security of the key and guaranteeing subsequent secure inter - chip communication.
[0089] Step S102: Generate a first session key corresponding to the target data based on the preset key.
[0090] Specifically, the first security module generates a first session key corresponding to the target data based on the preset key pre - stored in the first chip. This first session key is used to encrypt the target data sent to the second chip.
[0091] Optionally, the above - mentioned first chip further includes a random number generation module. The random number generation module is directly or indirectly connected to the first bus; the method further includes: generating a target random number for the target data through the random number generation module, and sending the target random number to the first security module and the second security module; the generating of the first session key corresponding to the target data based on the preset key includes: generating the first session key corresponding to the target data based on the preset key and the target random number. The random number generation module can generate a unique target random number for each session for the receiving end (i.e., the second chip). This target random number can jointly generate a session key with the preset key, further improving the security of inter - chip communication.
[0092] Step S103: Encrypt the target data based on the first session key to obtain the encrypted target data.
[0093] Specifically, before sending the target data, the first security module encrypts the target data based on the first session key to obtain the encrypted target data. The specific encryption method for the target data in the embodiments of the present application is not specifically limited. For example, it can support up to 256-bit encryption, decryption, and authentication capabilities.
[0094] Step S104: Send the encrypted target data to the second chip.
[0095] Specifically, the first chip can send the encrypted target data to the second chip through the first transmission interface. Among them, the embodiments of the present application do not specifically limit the first transmission interface. For example, it can be a serial communication interface or a parallel communication interface.
[0096] Step S105: Receive the encrypted target data sent by the first chip through the second transmission interface in the second chip.
[0097] Specifically, the second chip includes a second bus, a second security module, and a second transmission interface. The second security module is connected to the second bus, and the second transmission interface is communicatively connected to the second bus through the second security module; the second chip pre-stores the same preset key as that in the first chip. Receive the encrypted target data sent by the first chip through the second transmission interface in the second chip; decrypt the received encrypted target data to obtain the target data, and perform data processing on the target data. It can be understood that the decryption method in the second chip corresponds to the encryption method in the first chip.
[0098] Step S106: Determine the second session key based on the preset key pre-stored in the second chip through the second security module in the second chip.
[0099] Specifically, the second security module can form a secure channel with the first security module on the sending end (i.e., the first chip side) to ensure that the receiving end (i.e., the second chip side) can directly generate a matching session key based on the same preset key to decrypt the encrypted target data. Exemplarily, after the second chip receives the encrypted target data sent by the first chip through the second transmission interface, it needs to transmit the encrypted target data to the second security module, and the second security module can decrypt the encrypted target data. Among them, the second security module also pre-stores the same preset key as that in the first security module. Therefore, the second security module can determine the second session key based on the preset key pre-stored in the second chip.
[0100] Optionally, determining the second session key by the second security module in the second chip based on the preset key pre-stored in the second chip includes: obtaining the target random number by the second security module in the second chip, and determining the second session key based on the preset key pre-stored in the second chip and the target random number.
[0101] Step S107: Decrypt the encrypted target data based on the second session key, obtain the target data, and transmit the target data to the second bus for data processing.
[0102] Specifically, the second security module may decrypt the encrypted target data based on the second session key, obtain the decrypted target data, and transmit the decrypted target data to the second bus so that the processor can perform data processing on it.
[0103] Optionally, the first chip and the second chip are co-packaged together; or, the first chip and the second chip are packaged separately.
[0104] Optionally, the system includes multiple second chips, the first chip pre-stores the preset keys respectively corresponding to the multiple second chips, and the preset keys corresponding to each second chip are different.
[0105] The embodiment of the present application provides an inter-chip communication method that can achieve high real-time performance. The method is applied to a chip system, which includes a first chip and a second chip. The first chip can be the main chip at the sending end, and the second chip can be one of the slave chip, dummy chip, security chip or other main chips connected to the main chip at the receiving end. The data transmitted between the first chip and the second chip are all encrypted data. The security modules for encryption and decryption are respectively connected to the transmission interface and the bus, which is equivalent to building a secure channel between the first chip and the second chip. When the data is transmitted, it is encrypted transmission, which can greatly avoid the communication between the chips from being tampered with and stolen, and can ensure that the data received by the second chip is reliable. Moreover, before the encrypted data is transmitted to the chip-side bus at the receiving end, it passes through the security module and is decrypted, which can further omit the process of temporarily storing and verifying the security of the data or the process of configuring permissions, etc., and can enable the second chip to directly perform data processing on the decrypted target data, so as to achieve high-bandwidth and high-real-time inter-chip secure communication.
[0106] In addition, the embodiment of the present application provides an electronic device, which includes a circuit board and a chip system as described in any of the foregoing embodiments; the circuit board is electrically connected to the chip system.
[0107] An embodiment of the present application further provides a computer-readable storage medium. Computer program code is stored in the computer-readable storage medium. When the above-mentioned processor executes the computer program code, the computer is caused to execute the method in any of the foregoing embodiments.
[0108] An embodiment of the present application further provides a computer program product. When the computer program product runs on a computer, the computer is caused to execute the method in any of the foregoing embodiments.
[0109] It should be noted that, for the foregoing method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that the present application is not limited by the described action sequence, because according to the present application, some steps may be adopted in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily essential to the present application.
[0110] In several embodiments provided by the present application, it should be understood that the disclosed device can be implemented in other ways. For example, the device embodiments described above are only illustrative. For example, the above-mentioned unit division is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed mutual coupling or direct coupling or communication connection can be through some interfaces. The indirect coupling or communication connection of the device or unit can be in an electrical or other form.
[0111] The units described above as separate components may or may not be physically separated. The components shown as units may or may not be physical units, that is, they may be located in one place, or may be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0112] In addition, each functional unit in the embodiments of the present application can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of a software functional unit.
[0113] If the above integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc., specifically, the processor in the computer device) to execute all or part of the steps of the above methods in various embodiments of this application. Among them, the aforementioned storage medium can include: various media that can store program codes, such as USB flash drives, mobile hard disks, magnetic disks, optical discs, read-only memory (ROM), or random access memory (RAM).
[0114] As described above, the above embodiments are only used to illustrate the technical solutions of this application, rather than to limit them; although this application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of various embodiments of this application.
Claims
1. A chip system, characterized in that, The system includes a first chip and a second chip. The first chip pre-stores a preset key corresponding to the second chip. The first chip includes a first bus, a first security module, and a first transmission interface. The first security module is connected to the first bus, and the first transmission interface is communicatively connected to the first bus through the first security module. The first security module is configured to: obtain target data for the second chip and the preset key from the first bus. Generate a first session key corresponding to the target data based on the preset key. Encrypt the target data based on the first session key to obtain the encrypted target data. The first transmission interface is configured to: send the encrypted target data to the second chip.
2. The system according to claim 1, characterized in that, The second chip includes a second bus, a second security module, and a second transmission interface. The second security module is connected to the second bus, and the second transmission interface is communicatively connected to the second bus through the second security module. The second chip pre-stores the same preset key as that in the first chip. The second transmission interface is configured to: receive the encrypted target data sent by the first chip. The second security module is configured to: determine a second session key based on the preset key pre-stored in the second chip. Decrypt the encrypted target data based on the second session key, and obtain and transmit the target data to the second bus for data processing.
3. The system according to claim 1 or 2, characterized in that, The first chip further includes a first key management module, which is respectively connected to the first bus and the first security module. The first key management module pre-stores the preset key corresponding to the second chip. The first key management module is configured to: send the preset key to the first security module.
4. The system according to any one of claims 1 to 3, characterized in that The first chip further includes a random number generation module, which is connected to the first bus. The random number generation module is configured to: generate a target random number for the target data, and send the target random number to the first security module and the second security module. Specifically, the first security module is configured to: generate the first session key corresponding to the target data based on the preset key pre-stored in the second chip and the target random number.
5. The system according to claim 4, wherein Specifically, the second security module is configured to: obtain the target random number, and determine the second session key based on the preset key pre-stored in the second chip and the target random number.
6. The system according to any one of claims 1-5, characterized in that, The first chip and the second chip are co-packaged together; or, the first chip and the second chip are respectively packaged.
7. The system according to any one of claims 1-6, characterized in that The system includes multiple second chips. The first chip pre-stores preset keys respectively corresponding to the multiple second chips, and the preset keys corresponding to each second chip are different.
8. A method for inter-chip communication, characterized in that, Applied to a chip system, the chip system includes a first chip and a second chip, and the first chip pre-stores a preset key corresponding to the second chip; the first chip includes a first bus, a first security module, and a first transmission interface, the first security module is connected to the first bus, and the first transmission interface is communicatively connected to the first bus through the first security module; the method includes: Obtaining, by the first security module in the first chip, target data for the second chip and the preset key from the first bus; Generating a first session key corresponding to the target data based on the preset key; Encrypting the target data based on the first session key to obtain encrypted target data; Sending the encrypted target data to the second chip through the first transmission interface.
9. The method according to claim 1, wherein The second chip includes a second bus, a second security module, and a second transmission interface, the second security module is connected to the second bus, and the second transmission interface is communicatively connected to the second bus through the second security module; The second chip pre-stores the same preset key as that in the first chip; The method further includes: Receiving, by the second transmission interface in the second chip, the encrypted target data sent by the first chip; Determining a second session key by the second security module in the second chip based on the preset key pre-stored in the second chip; decrypting the encrypted target data based on the second session key, and obtaining and transmitting the target data to the second bus for data processing.
10. An electronic device, characterized in that, The electronic device includes a circuit board and the chip system according to any one of claims 1-7 above; the circuit board is electrically connected to the chip system.