Algorithm configuration method and device based on dynamic loading and FPGA reconstruction
Through the algorithm configuration method of dynamic loading and FPGA reconstruction, the problem of traditional encryption algorithm curing is solved that the hardware is susceptible to risks and inconvenience of updates is achieved, and the flexible update of encryption algorithms and data security enhancement is achieved, adapting to the flexibility and scalability requirements of modern application scenarios.
Patent Information
- Application Number
- CN202510646099.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-20
- Publication Date
- 2025-07-08
- Estimated Expiration
- 2045-05-20
AI Technical Summary
Traditional encryption algorithms are easily exposed to risks on hardware or firmware, are inconvenient and inflexible to update, and are difficult to meet the requirements of flexibility and scalability in modern application scenarios.
The algorithm configuration method based on dynamic loading and FPGA reconstruction is adopted, and the dynamic library is configured to be stored in external memory through Linux system algorithms. The ARM processor and FPGA algorithm processing module are used to realize the dynamic configuration and update of the encryption algorithm, separate the algorithm and the cryptographic module, and dynamic configuration algorithm is used to meet different usage needs.
It realizes flexible and reliable updates of encryption algorithms, enhances data security and algorithm confidentiality, and adapts to the needs of rapidly changing application scenarios.
Smart Images

Figure CN120281564A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer technology, and particularly to an algorithm configuration method and device based on dynamic loading and FPGA reconfiguration. Background Art
[0002] With the rapid development of information technology, network security issues have become increasingly prominent, and the forms and complexity of network attacks have been continuously increasing. Against this background, deploying encryption modules at key positions in network devices has become one of the important means to protect data security. The encryption module encrypts the data transmitted in the network to ensure that even if the data is intercepted, the attacker cannot easily interpret its content, thus effectively guaranteeing the security and integrity of information.
[0003] However, the traditional method of directly solidifying the encryption algorithm into the cryptographic module has obvious limitations. First of all, once the algorithm is solidified on the hardware or firmware, it is easily exposed to potential risks. Whether through physical access or software vulnerabilities, these key algorithms may face the risk of leakage, resulting in reduced security. Secondly, when it is necessary to replace the encryption algorithm according to new security standards or to deal with new types of attacks, the update process of the solidification method is particularly inconvenient. Since the algorithm is statically fixed, any update usually requires reprogramming the hardware or replacement, which not only increases the cost but also may lead to an extended system downtime and affect business continuity.
[0004] In addition, modern application scenarios have higher and higher requirements for flexibility and scalability, especially in fields such as cloud computing and the Internet of Things (IoT), and the ability to quickly respond to changes is crucial.
[0005] Therefore, how to provide a method and device that can flexibly and reliably configure algorithm parameters according to different usage requirements of the cryptographic module is a technical problem that those skilled in the art urgently need to solve. Summary of the Invention
[0006] In view of the above research status, the present invention provides an algorithm configuration method and device based on dynamic loading and FPGA reconfiguration, adopting a more flexible technical solution to realize the dynamic configuration and update of the encryption algorithm, and also enhancing the data security to ensure the confidentiality and integrity of the algorithm.
[0007] The present invention provides an algorithm configuration method based on dynamic loading and FPGA reconfiguration, including the following steps:
[0008] S1: Store the Linux system algorithm configuration dynamic library and algorithm files in an external memory;
[0009] S2: Retrieve and cache the algorithm configuration dynamic library in the external memory through the hardware connection interface, which is used to parse the processing logic of the algorithm file and perform the read and cache operations on the algorithm file;
[0010] S3: Perform a partial reconfiguration operation on the FPGA according to the bitstream of the algorithm file. The reconfigured FPGA is used to implement the encryption operation on the service data;
[0011] S4: After the configuration is completed, unload the algorithm configuration dynamic library and clear the cached algorithm file.
[0012] Preferably, the algorithm configuration dynamic library includes the processing logic for reading, decrypting, and algorithm configuration of the algorithm file.
[0013] Preferably, the S2 includes the following steps:
[0014] S211: Read the algorithm configuration dynamic library from the external memory and store it in the RAM cache after passing the crc check;
[0015] S212: Call the algorithm reading function in the algorithm configuration dynamic library to read the algorithm file in the external memory;
[0016] S213: Call the algorithm decryption interface in the algorithm configuration dynamic library to check and decrypt the algorithm file. If the check and decryption pass, store the decrypted algorithm file in the RAM cache.
[0017] Preferably, the S1 further includes: storing the memory configuration file in the external memory to check whether the external memory environment meets the requirements for retrieving the algorithm configuration dynamic library.
[0018] Preferably, the S2 further includes the following steps:
[0019] S221: Read the memory configuration file and parse the content of the configuration file; obtain the device information of the FPGA;
[0020] S222: According to the content of the configuration file and the device information, check whether the memory category of the external memory is correct and / or whether the stored target configuration information matches; if the check passes, perform the retrieval operation of the algorithm configuration dynamic library; if the check fails, output an alarm signal and return to S221.
[0021] Preferably, before retrieving the algorithm configuration dynamic library in the external memory through the hardware connection interface in the S2, the following steps are further included:
[0022] S201: Monitor the hot plug of the hardware connection interface. If it is detected that the external memory is connected, enter S202;
[0023] S202: Determine whether the external memory is a legal memory. If it is legal, proceed to S2; if it is not legal, output an alarm signal and return to S201.
[0024] Preferably, S3 includes the following steps:
[0025] S31: Send an algorithm configuration request to the FPGA. After receiving the algorithm configuration request reply fed back by the FPGA, proceed to S32;
[0026] S32: Transmit the bitstream of the algorithm file to the FPGA in segments. And after each segment of the bitstream is transmitted, receive and judge the transmission reply result fed back by the FPGA;
[0027] S33: If the transmission reply result is abnormal, re-transmit the bitstream of the current segment of the algorithm file to the FPGA, receive and judge the transmission reply result fed back by the FPGA, and return to S33; if the transmission reply result is normal, transmit the bitstream of the next segment of the algorithm file to the FPGA until the algorithm file is transmitted completely.
[0028] The present invention also provides an encryption device according to the algorithm configuration method based on dynamic loading and FPGA reconfiguration, including an algorithm dedicated memory and an encryption module; wherein,
[0029] The algorithm dedicated memory is used as an external memory to store the Linux system algorithm configuration dynamic library and the algorithm file;
[0030] The encryption module includes an ARM processor and an FPGA algorithm processing module;
[0031] The ARM processor retrieves and caches the algorithm configuration dynamic library in the external memory to the RAM through a hardware connection interface, uses the algorithm configuration dynamic library to parse the processing logic of the algorithm file, reads and caches the algorithm file to the RAM; and after the configuration is completed, unloads the algorithm configuration dynamic library and clears the cached algorithm file;
[0032] The FPGA algorithm processing module performs a partial reconfiguration operation on the FPGA according to the bitstream of the algorithm file, and the reconfigured FPGA is used to implement the encryption operation of the service data in the service system.
[0033] Preferably, the external interfaces of the ARM processor include a USB interface and a QSPI interface; the USB interface is used to connect the algorithm dedicated memory; the QSPI interface is used to connect the FPGA algorithm processing module.
[0034] Preferably, the encryption module further includes an interaction module for indicating the status of the algorithm configuration process and outputting the external interface connection information of the ARM processor.
[0035] The present invention has the following beneficial effects compared with the prior art:
[0036] In the present invention, the algorithm and its configuration information are stored in a dedicated memory, and an ARM architecture microprocessor is used to monitor the connection status of the storage device, parse the configuration file, read and dynamically load the algorithm configuration dynamic library based on the embedded Linux system. Then, the decrypted algorithm bitstream is sent to the FPGA algorithm processing module through the QSPI interface, and the FPGA performs local reconstruction according to the received bitstream, thereby realizing a specific encryption function. The present invention separates the algorithm from the cipher module and adopts a dynamic configuration algorithm, which can flexibly change the algorithm and configuration logic according to the usage scenario, and also achieves the security protection of key data such as the algorithm. BRIEF DESCRIPTION OF THE DRAWINGS
[0037] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of the present invention, and those of ordinary skill in the art can obtain other drawings according to the provided drawings without creative efforts.
[0038] Figure 1 It is a flowchart of an algorithm configuration method based on dynamic loading and FPGA reconstruction provided by an embodiment of the present invention;
[0039] Figure 2 It is a processing flowchart of injecting an algorithm into the FPGA provided by an embodiment of the present invention;
[0040] Figure 3 It is an interaction diagram of the FPGA receiving the algorithm file bitstream provided by an embodiment of the present invention;
[0041] Figure 4 It is a structural diagram of an encryption device provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0042] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art without creative efforts based on the embodiments of the present invention belong to the scope of protection of the present invention.
[0043] An algorithm configuration method based on dynamic loading and FPGA reconstruction disclosed in the first aspect of the embodiment of the present invention is asFigure 1 As shown in the figure, it includes the following steps:
[0044] S1: Store the Linux system algorithm configuration dynamic library and algorithm files in an external memory.
[0045] S2: Retrieve and cache the algorithm configuration dynamic library in the external memory through a hardware connection interface for parsing the processing logic of the algorithm files and performing the read and cache operations on the algorithm files.
[0046] S3: Perform a partial reconfiguration operation on the FPGA according to the bitstream of the algorithm file. The reconfigured FPGA is used to implement the encryption operation of service data.
[0047] S4: After the configuration is completed, unload the algorithm configuration dynamic library and clear the cached algorithm files.
[0048] It should be noted that Linux system dynamic loading is a mechanism in which a program dynamically loads a.so shared library (Shared Object, shared dynamic link library) as needed during runtime, loads it into memory to expand the original functions, and can unload it from memory in a timely manner when it is no longer needed.
[0049] FPGA partial reconfiguration means that without affecting its normal operation, some logic resources of the FPGA are reconfigured to implement the encryption function of service data.
[0050] In one embodiment, the algorithm configuration dynamic library includes the processing logic for reading, decrypting, and algorithm configuration of the algorithm files.
[0051] In one embodiment, S2 includes the following steps:
[0052] S211: Use the dlopen function to load the algorithm configuration dynamic library from the external storage, and store it in the RAM cache after passing the crc check.
[0053] S212: Use the dlsym function to call the algorithm reading function in the algorithm configuration dynamic library to read the algorithm files in the external memory.
[0054] S213: Call the algorithm decryption interface in the algorithm configuration dynamic library to perform verification and decryption on the algorithm files. If the verification and decryption are passed, store the decrypted algorithm files in the RAM cache. The algorithm files need to be decrypted and restored before configuring the FPGA.
[0055] In one embodiment, use the dlclose function to unload the algorithm configuration dynamic library and overwrite and clear the RAM cache during the algorithm configuration process. When the password module is in a non-working state, it does not save algorithm-related files. Only the algorithm is dynamically injected during runtime, and all algorithm-related programs in the MCU will be cleared after the injection is completed.
[0056] In one embodiment, S1 further includes: storing the memory configuration file into an external memory for checking whether the external memory environment meets the requirements for retrieving the algorithm configuration dynamic library. The memory configuration file is used to describe information such as the dedicated memory manufacturer ID, memory type, disk manufacturing time, target device type, etc.
[0057] In this embodiment, as Figure 2 shown, S2 further includes the following steps:
[0058] S221: Read the memory configuration file, parse the content of the configuration file; obtain the device information of the FPGA;
[0059] S222: According to the content of the configuration file and the device information, check whether the memory category of the external memory is correct and / or whether the stored target configuration information matches; if the check passes, perform the operation of retrieving the algorithm configuration dynamic library; if the check fails, control the status indicator to output an alarm signal and return to S221.
[0060] It should be noted that the target configuration information can be configured according to the usage scenario, such as configuration batch, algorithm, key activation time, number of the external memory, etc.
[0061] In one embodiment, as Figure 2 shown, before retrieving the algorithm configuration dynamic library in the external memory through the hardware connection interface in S2, the following steps are further included:
[0062] S201: Retrieve the algorithm configuration dynamic library in the external memory through the USB interface, monitor the hot plugging of the USB interface using netlink, and if the external memory is detected to be connected, enter S202;
[0063] S202: Determine whether the external memory is a legal memory by reading the pid and vid. If it is legal, enter S2; if it is not legal, control the status indicator to output an alarm signal and return to S201.
[0064] In one embodiment, the injection software communicates with the FPGA algorithm processing module through QSPI, and the communication interaction process is as Figure 3 shown. S3 includes the following steps:
[0065] S31: Send a request to query the FPGA number to the FPGA. After receiving the corresponding number feedback from the FPGA, judge its legality. If it is legal, send an algorithm configuration request to the FPGA. After receiving the algorithm configuration request reply feedback from the FPGA, enter S32;
[0066] S32: Transmit the bitstream of the algorithm file to the FPGA in segments, and after each segment of the bitstream is transmitted, receive and judge the transmission response result feedback by the FPGA;
[0067] S33: If the transmission response result is abnormal, re-transmit the bitstream of the current segment of the algorithm file to the FPGA, receive and judge the transmission response result feedback by the FPGA, and return to S33; if the transmission response result is normal, transmit the bitstream of the next segment of the algorithm file to the FPGA until the algorithm file is transmitted completely. During the transmission process, control the indicator light according to the configuration status for status indication.
[0068] As shown in Table 1, it is the protocol format of the algorithm configuration command request:
[0069] Command Word Data Length Data Content 1 Byte 4 Bytes N Bytes
[0070] As shown in Table 2, it is the description of the command word in the protocol format of the algorithm configuration command request:
[0071] Command Word Description 0x05 Middle Segment of Configuration Algorithm Bitstream 0x85 First Segment of Configuration Algorithm Bitstream 0x45 Last Segment of Configuration Algorithm Bitstream 0x06 Algorithm Information File
[0072] In the protocol format of the algorithm configuration command request, the data length represents the number of bytes of the data content segment; the data content represents the actual data to be sent; the response data length is 1 byte, and the response value of 0x01 indicates that the FPGA has successfully received the data.
[0073] The second aspect of the embodiments of the present invention provides an encryption device according to the algorithm configuration method based on dynamic loading and FPGA reconstruction provided in the first aspect of the embodiments, as Figure 4 shown, including a dedicated algorithm memory and an encryption module; wherein,
[0074] The dedicated algorithm memory stores the Linux system algorithm configuration dynamic library and the algorithm file as an external memory;
[0075] The encryption module includes an ARM processor and an FPGA algorithm processing module;
[0076] The ARM processor retrieves and caches the algorithm configuration dynamic library in the external memory to the RAM through the hardware connection interface, uses the algorithm configuration dynamic library to parse the processing logic of the algorithm file, reads and caches the algorithm file to the RAM; and, after the configuration is completed, unloads the algorithm configuration dynamic library and clears the cached algorithm file;
[0077] The FPGA algorithm processing module performs a partial reconstruction configuration operation on the FPGA according to the bitstream of the algorithm file, and the reconstructed FPGA is used to implement the encryption operation of the service data in the service system.
[0078] It should be noted that the ARM processor implements the injection software based on the embedded Linux system, which is used to monitor the connection status of the dedicated storage device, parse the configuration file, read and load the dynamic library of the algorithm configuration, dynamically load the dynamic library of the algorithm configuration to complete a series of processes such as algorithm verification, decryption, and distribution, indicate the status of the injection process, and unload the dynamic library and clean the data cache after the configuration is completed.
[0079] A configuration file is stored on both the external memory and the ARM processor, and the target configuration information of the password module is stored in the configuration file. After the main program of the ARM processor detects the insertion of the external memory, it will first read the configuration information of the memory and compare it with the password module to check for a match.
[0080] Among them, the ARM processor can be an MCU.
[0081] In one embodiment, the external interfaces of the ARM processor include a USB interface and a QSPI interface; the USB interface is used to connect to the algorithm-specific memory; the QSPI interface is used to connect to the FPGA algorithm processing module, and the algorithm bitstream is sent to the FPGA algorithm processing module through the QSPI interface.
[0082] In one embodiment, the encryption module further includes an interaction module for indicating the status of the algorithm configuration process and outputting the connection information of the external interfaces of the ARM processor.
[0083] The above has introduced in detail an algorithm configuration method and device based on dynamic loading and FPGA reconfiguration provided by the present invention. Specific examples are used in this article to elaborate on the principle and implementation manner of the present invention. The description of the above embodiments is only used to help understand the method and its core idea of the present invention; at the same time, for those of ordinary skill in the art, according to the idea of the present invention, there will be changes in the specific implementation manner and application scope. In summary, the content of this specification should not be construed as a limitation to the present invention.
[0084] In this article, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or also includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "including a..." does not exclude the existence of additional identical elements in the process, method, article or device including the said element.
Claims
1. An algorithm configuration method based on dynamic loading and FPGA reconfiguration, characterized in that, It includes the following steps: S1: Store the Linux system algorithm configuration dynamic library and algorithm files in an external memory; S2: Retrieve and cache the algorithm configuration dynamic library in the external memory through a hardware connection interface for parsing the processing logic of the algorithm files and performing read and cache operations on the algorithm files; S3: Perform a partial reconfiguration operation on the FPGA according to the bitstream of the algorithm files, and the reconfigured FPGA is used to implement encryption operations on service data; S4: After the configuration is completed, unload the algorithm configuration dynamic library and clear the cached algorithm files.
2. The algorithm configuration method based on dynamic loading and FPGA reconfiguration according to claim 1, characterized in that, The algorithm configuration dynamic library includes the processing logic for reading, decrypting, and algorithm configuration of algorithm files.
3. The algorithm configuration method based on dynamic loading and FPGA reconstruction according to claim 1, wherein The S2 includes the following steps: S211: Read the algorithm configuration dynamic library from the external storage, and store it in the RAM cache after passing the crc check; S212: Call the algorithm reading function in the algorithm configuration dynamic library to read the algorithm files in the external memory; S213: Call the algorithm decryption interface in the algorithm configuration dynamic library to perform verification and decryption on the algorithm files. If the verification and decryption pass, store the decrypted algorithm files in the RAM cache.
4. The algorithm configuration method based on dynamic loading and FPGA reconfiguration according to claim 1, wherein The S1 further includes: storing a memory configuration file in the external memory for checking whether the external memory environment meets the requirements for retrieving the algorithm configuration dynamic library.
5. The algorithm configuration method based on dynamic loading and FPGA reconfiguration according to claim 4, wherein, The S2 further includes the following steps: S221: Read the memory configuration file, parse the content of the configuration file; obtain the device information of the FPGA; S222: According to the content of the configuration file and the device information, check whether the memory category of the external memory is correct and / or whether the stored target configuration information matches; if the check passes, perform the retrieval operation of the algorithm configuration dynamic library; If the check fails, output an alarm signal and return to S221.
6. The algorithm configuration method based on dynamic loading and FPGA reconfiguration according to claim 1, wherein Before retrieving the algorithm configuration dynamic library in the external memory through the hardware connection interface in the S2, the following steps are further included: S201: Perform hot-plug monitoring on the hardware connection interface. If it is detected that the external memory is connected, enter S202; S202: Determine whether the external memory is a legal memory. If it is legal, enter S2; if it is not legal, output an alarm signal and return to S201.
7. A method for algorithm configuration based on dynamic loading and FPGA reconfiguration according to claim 1, characterized in that, The S3 includes the following steps: S31: Send an algorithm configuration request to the FPGA, and enter S32 after receiving the algorithm configuration request reply feedback from the FPGA; S32: Transmit the bitstream of the algorithm files to the FPGA in segments, and after each segment of the bitstream is transmitted, receive and judge the transmission reply result feedback from the FPGA; S33: If the transmission reply result is abnormal, re-transmit the bitstream of the current segment of the algorithm files to the FPGA, receive and judge the transmission reply result feedback from the FPGA, and return to S33; If the transmission reply result is normal, transmit the bitstream of the next segment of the algorithm files to the FPGA until the algorithm files are transmitted completely.
8. An encryption device for an algorithm configuration method based on dynamic loading and FPGA reconfiguration according to any one of claims 1-7, characterized in that, It includes an algorithm-specific memory and an encryption module; wherein, The algorithm-specific memory is used as an external memory to store the Linux system algorithm configuration dynamic library and algorithm files; The encryption module includes an ARM processor and an FPGA algorithm processing module; The ARM processor retrieves and caches the algorithm configuration dynamic library in the external memory to the RAM through the hardware connection interface, uses the algorithm configuration dynamic library to parse the processing logic of the algorithm file, reads the algorithm file and caches it to the RAM; and, after the configuration is completed, unloads the algorithm configuration dynamic library and clears the cached algorithm file; The FPGA algorithm processing module performs a partial reconfiguration operation on the FPGA according to the bitstream of the algorithm file, and the reconfigured FPGA is used to implement the encryption operation of the service data in the service system.
9. The encryption device according to claim 8, wherein, The external interfaces of the ARM processor include a USB interface and a QSPI interface; the USB interface is used to connect to the algorithm dedicated memory; the QSPI interface is used to connect to the FPGA algorithm processing module.
10. The encryption device according to claim 8, characterized in that The encryption module further includes an interaction module, which is used to indicate the status of the algorithm configuration process and output the connection information of the external interface of the ARM processor.
Citation Information
Patent Citations
Method and system for realizing safe algorithm and decryption algorithm by means of reconfigurable processor
CN108616348A
Portable mobile terminal encryptor
CN109495259A
Method and apparatus for protecting dynamic libraries
US20160275019A1
Field programmable gate arrays
US6356637B1