Data analysis and bit stream configuration method and system for preventing Starbleed vulnerability attack

The method and system analyze FPGA bitstreams to detect and prevent Starbleed attacks by verifying WBSTAR register conditions and state machine status, ensuring secure bitstream processing.

CN120316784AActive Publication Date: 2025-07-15ZHONGKEXIN MAGNETIC TECH (ZHUHAI) CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510795828.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-16
Publication Date
2025-07-15
Estimated Expiration
2045-06-16

AI Technical Summary

Technical Problem

The existing technology has incomplete protection mechanisms when preventing Starbleed vulnerability attacks, and cannot effectively protect FPGA encrypted bitstreams.

Method used

By obtaining the register data in the configuration bitstream, using the pre-built packet type analysis circuit module to parse the bit domain data, identify the current register address, and determine whether the state machine is IDLE state, packet type, length and configuration operations meet the vulnerability combination judgment criteria, and trigger a vulnerability warning to prevent attacks.

Benefits of technology

It realizes effective prevention of Starbleed vulnerability attacks, ensures the security of FPGA encrypted bitstreams, and prevents data leakage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120316784A_ABST
    Figure CN120316784A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of vulnerability attack prevention, in particular to a data analysis and bit stream configuration method and system for preventing Starbleed vulnerability attacks, and the method comprises the steps: judging whether a current register address is a WBSTAR register address or not, if not, transmitting register data to a post-stage circuit, if yes, judging whether a state machine is in an IDLE state or not, and if not, transmitting the register data to the post-stage circuit; and if the packet type, the packet data length and the packet configuration operation conform to the vulnerability combination judgment standard, performing data transmission on the register data to the post-stage circuit, if the packet type, the packet data length and the packet configuration operation conform to the vulnerability combination judgment standard, and if the packet type, the packet data length and the packet configuration operation do not conform to the vulnerability combination judgment standard, triggering a vulnerability warning. According to the method and the device, the problem of imperfect defense mechanism of the current Starbleed vulnerability attack can be solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of vulnerability attack prevention, and particularly to a data parsing and bitstream configuration method and system for preventing Starbleed vulnerability attacks. Background Art

[0002] With the wide application of FPGA (Field Programmable Gate Array) in the fields of aerospace, industrial control, communication, and artificial intelligence, its security issues have become increasingly prominent. The FPGA realizes program configuration and operation by loading the bitstream designed by the user.

[0003] There is a hardware security vulnerability named Starbleed in the FPGA. This vulnerability is hidden in the WBSTAR register configuration of the FPGA. The attacker first determines the data position of the write WBSTAR configuration instruction, and then controls the data length written to the WBSTAR register by rewriting the ciphertext information corresponding to this data position. By using the FPGA itself as a decryption circuit and making it write the decrypted bitstream into the WBSTAR register, the attacker can achieve the purpose of cracking the encrypted bitstream of the FPGA after reading.

[0004] Currently, the main method for preventing Starbleed vulnerability attacks is to confuse the position of the WBSTAR register configuration instruction in the configuration bitstream, so that the attacker cannot rewrite the packet data length of the WBSTAR register, thereby realizing the function of protecting the FPGA encrypted bitstream. For example, a method and device for defending against the StarBleed vulnerability (authorized announcement number: CN111967014B). This invention first decrypts the initial ciphertext to obtain the plaintext, determines a random number according to a preset random number selection strategy, and then performs operations such as replacing the configuration instructions in the plaintext and confusing the data in the HMAC signature area according to the random number. Finally, the confused plaintext is encrypted to obtain the confused ciphertext. However, this method does not fundamentally solve the Starbleed vulnerability problem. Therefore, there is a problem of imperfect prevention mechanism in currently preventing Starbleed vulnerability attacks. Summary of the Invention

[0005] The present invention provides a data parsing and bitstream configuration method and system for preventing Starbleed vulnerability attacks, and its main purpose is to solve the problem of imperfect prevention mechanism in currently preventing Starbleed vulnerability attacks.

[0006] To achieve the above object, a data parsing and bitstream configuration method for preventing Starbleed vulnerability attacks provided by the present invention includes: Obtain the register data in the configuration bitstream, and use the pre-built packet type parsing circuit module to perform bit-field data parsing on the register data to obtain bit-field parsing data. Among them, the bit-field parsing data includes: packet type valid data, packet length valid data, read / write valid flag, and register address valid data; Identify the current register address according to the register address valid data; Judge whether the current register address is the preset WBSTAR register address; If the current register address is not the WBSTAR register address, transfer the register data to the subsequent circuit; If the current register address is the WBSTAR register address, judge whether the state machine in the pre-built packet read / write control circuit module is in the preset IDLE state; If the state machine in the packet read / write control circuit module is not in the IDLE state, transfer the register data to the subsequent circuit; If the state machine in the packet read / write control circuit module is in the IDLE state, determine the packet type, packet data length, and packet configuration operation according to the packet type valid data, packet length valid data, and read / write valid flag respectively; Judge whether the packet type, packet data length, and packet configuration operation meet the preset vulnerability combination determination criteria. The vulnerability combination determination criteria refer to that the packet type is packet type 1, the packet data length is greater than 1, and the packet configuration operation is a write operation; If the packet type, packet data length, and packet configuration operation do not meet the vulnerability combination determination criteria, transfer the register data to the subsequent circuit; If the packet type, packet data length, and packet configuration operation meet the vulnerability combination determination criteria, trigger a vulnerability warning to complete the data parsing and bitstream configuration for preventing Starbleed vulnerability attacks.

[0007] Optionally, the using the pre-built packet type parsing circuit module to perform bit-field data parsing on the register data to obtain bit-field parsing data includes: Identify the configuration application scenario of the configuration bitstream; Select a target selector circuit in the multi-level selector circuit of the pre-built packet type parsing circuit module according to the configuration application scenario; Use the target selector circuit to input the register data into the combination gate circuit in the packet type parsing circuit and perform bit-field bit value comparison to obtain bit-field parsing data.

[0008] Optionally, the configuration application scenarios include: JTAG interface input data configuration application scenario, SPI interface input data configuration application scenario, BPI interface input data configuration application scenario, SMAP interface input data configuration application scenario, SRL interface input data configuration application scenario, ICAP interface input data configuration application scenario.

[0009] Optionally, after using the pre-built packet type parsing circuit module to perform bit field data parsing on the register data to obtain bit field parsing data, the method further includes: Input the packet type valid data and packet length valid data into the pre-built packet length counter module.

[0010] Optionally, after inputting the packet type valid data and packet length valid data into the pre-built packet length counter module, the method further includes: Input the packet type valid data, packet length valid data, and read / write valid flag into the pre-built packet read / write control circuit module, and the packet read / write control circuit module contains a state machine.

[0011] Optionally, after inputting the packet type valid data, packet length valid data, and read / write valid flag into the pre-built packet read / write control circuit module, the method further includes: Input the packet type valid data, packet length valid data, read / write valid flag, and register address valid data into the pre-built Starbleed detection circuit module.

[0012] Optionally, the judging whether the state machine in the pre-built packet read / write control circuit module is a preset IDLE state includes: If the state machine is a preset WDC state, when receiving a preset type 2 data packet, it jumps to the preset WRPD state and judges whether the packet length counter module generates a preset packet count end flag, where the WDC state means that the read / write valid flag is a write operation, the packet type corresponding to the packet type valid data is data packet type 1, and the packet data length corresponding to the packet length valid data is 0, and the WRPD state means that the packet read / write control circuit module has received the register address valid data, the type 2 data packet corresponding to the WBSTAR register address is being transmitted, and the read / write valid flag is a write operation; When the packet length counter module generates a packet count end flag, the state machine is in the IDLE state; If the state machine is in the preset RDC state, when receiving a Type 2 data packet, it jumps to the preset RDPD state and determines whether the packet length counter module generates a packet count end flag. Herein, the RDC state means that the read / write valid flag is a read operation, the packet type corresponding to the valid packet type data is data packet type 2, and the packet data length corresponding to the valid packet length data is 0. The RDPD state means that the packet read / write control circuit module has received the valid register address data, the Type 2 data packet corresponding to the WBSTAR register address is being transmitted, and the read / write valid flag is a read operation; When the packet length counter module generates a packet count end flag, the state machine is in the IDLE state.

[0013] Optionally, determining whether the packet length counter module generates a preset packet count end flag includes: Identifying the packet data length of the Type 2 data packet; Using a preset 27-bit width to perform a countdown on the packet data length of the Type 2 data packet to obtain a decreasing count value; Determining whether the decreasing count value is equal to 0; If the decreasing count value is not equal to 0, the packet length counter module does not generate a packet count end flag; If the decreasing count value is equal to 0, the packet length counter module generates a packet count end flag.

[0014] Optionally, after triggering the vulnerability warning, the method further includes: Triggering a lock signal according to the vulnerability warning; Locking the state machine in the IDLE state according to the lock signal and performing a configuration stop operation, where the configuration stop operation includes: stopping the configuration of the subsequent circuit, stopping the write operation of configuring the WBSTAR register, and stopping the read operation of configuring the WBSTAR register.

[0015] To achieve the above object, the present invention further provides a data parsing and bitstream configuration system for preventing Starbleed vulnerability attacks, including: A current register address judgment module, configured to obtain register data in a configuration bitstream, perform bit-field data parsing on the register data by using a pre-constructed packet type parsing circuit module to obtain bit-field parsing data, where the bit-field parsing data includes: valid packet type data, valid packet length data, read / write valid flag, valid register address data; identify the current register address according to the valid register address data; determine whether the current register address is a preset WBSTAR register address; if the current register address is not the WBSTAR register address, transmit the register data to the subsequent circuit; The IDLE state judgment module is used to judge whether the state machine in the pre-built packet read / write control circuit module is in the preset IDLE state if the current register address is the address of the WBSTAR register; if the state machine in the packet read / write control circuit module is not in the IDLE state, the register data is transmitted to the subsequent circuit for data transmission. The vulnerability combination determination criterion determination module is used to determine the packet type, packet data length, and packet configuration operation according to the packet type valid data, packet length valid data, and read / write valid flag respectively if the state machine in the packet read / write control circuit module is in the IDLE state; judge whether the packet type, packet data length, and packet configuration operation meet the preset vulnerability combination determination criterion, where the vulnerability combination determination criterion means that the packet type is packet type 1, the packet data length is greater than 1, and the packet configuration operation is a write operation; if the packet type, packet data length, and packet configuration operation do not meet the vulnerability combination determination criterion, the register data is transmitted to the subsequent circuit for data transmission. The trigger vulnerability warning module is used to trigger a vulnerability warning if the packet type, packet data length, and packet configuration operation meet the vulnerability combination determination criterion.

[0016] To solve the above problems, the present invention also provides an electronic device, which includes: A memory storing at least one instruction; and a processor that executes the instruction stored in the memory to implement the data parsing and bitstream configuration method for preventing Starbleed vulnerability attacks described above.

[0017] To solve the above problems, the present invention also provides a computer-readable storage medium, in which at least one instruction is stored, and the at least one instruction is executed by a processor in an electronic device to implement the data parsing and bitstream configuration method for preventing Starbleed vulnerability attacks described above.

[0018] To solve the problems described in the background art, the present invention determines the Starbleed vulnerability attack through the current register address, whether the state machine is in the IDLE state, and the vulnerability combination determination criteria. First, it is necessary to obtain the register data in the configuration bitstream, and then use the pre-stage circuit to perform bit-field data parsing on the register data to obtain bit-field parsed data. Among them, the bit-field parsed data includes: packet type valid data, packet length valid data, read / write valid flag, and register address valid data. Since the Starbleed vulnerability attack needs to simultaneously meet the three conditions that the current register address is the WBSTAR register address, the state machine is in the IDLE state, and the packet type, packet data length, and packet configuration operation meet the vulnerability combination determination criteria, therefore, the current register address can be identified according to the register address valid data first, and it is judged whether the current register address is the WBSTAR register address. If the current register address is not the WBSTAR register address, it means that there is no Starbleed vulnerability attack, and the register data is directly transmitted to the post-stage circuit. If the current register address is the WBSTAR register address, the compliance determination of the second condition is continued, and it is judged whether the state machine in the packet read / write control circuit is in the IDLE state. If the state machine of the packet read / write control circuit is not in the IDLE state, it means that there is no Starbleed vulnerability attack, and the register data is directly transmitted to the post-stage circuit. If the state machine of the packet read / write control circuit is in the IDLE state, the compliance determination of the third condition needs to be carried out. First, the packet type, packet data length, and packet configuration operation are determined according to the packet type valid data, packet length valid data, and read / write valid flag respectively, and then it is judged whether the packet type, packet data length, and packet configuration operation meet the vulnerability combination determination criteria. Among them, the vulnerability combination determination criteria mean that the packet type is packet type 1, the packet data length is greater than 1, and the packet configuration operation is a write operation. If the packet type, packet data length, and packet configuration operation do not meet the vulnerability combination determination criteria, it means that there is no Starbleed vulnerability attack, and the register data is directly transmitted to the post-stage circuit. If the packet type, packet data length, and packet configuration operation meet the vulnerability combination determination criteria, a vulnerability warning is triggered. Therefore, the present invention can solve the problem that the current defense mechanism against the Starbleed vulnerability attack is imperfect. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] Figure 1 FIG. is a schematic flowchart of a data parsing and bitstream configuration method for preventing Starbleed vulnerability attacks provided by an embodiment of the present invention; Figure 2 FIG. is a flowchart of Starbleed vulnerability data parsing provided by an embodiment of the present invention; Figure 3 FIG. is a flowchart of state judgment of a state machine provided by an embodiment of the present invention; Figure 4 The functional block diagram of the data parsing and bitstream configuration system for preventing Starbleed vulnerability attacks provided by an embodiment of the present invention; Figure 5 The structural schematic diagram of an electronic device for implementing the data parsing and bitstream configuration method for preventing Starbleed vulnerability attacks provided by an embodiment of the present invention.

[0020] Explanation of the reference numerals: 1. Electronic device; 10. Processor; 11. Memory; 12. Bus.

[0021] The implementation, functional features, and advantages of the objectives of the present invention will be further described with reference to the embodiments and the accompanying drawings. Detailed implementation manners

[0022] It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.

[0023] An embodiment of the present application provides a data parsing and bitstream configuration method for preventing Starbleed vulnerability attacks. The execution subject of the data parsing and bitstream configuration method for preventing Starbleed vulnerability attacks includes, but is not limited to, at least one of electronic devices such as a server, a terminal, etc. that can be configured to execute the method provided by the embodiment of the present application. In other words, the data parsing and bitstream configuration method for preventing Starbleed vulnerability attacks can be executed by software or hardware installed on a terminal device or a server device, and the software can be a blockchain platform. The server includes, but is not limited to: a single server, a server cluster, a cloud server, or a cloud server cluster, etc.

[0024] Referring to Figure 1 As shown, it is a flowchart of the data parsing and bitstream configuration method for preventing Starbleed vulnerability attacks provided by an embodiment of the present invention. In this embodiment, the data parsing and bitstream configuration method for preventing Starbleed vulnerability attacks includes: S1. Obtain the register data in the configuration bitstream, and use a pre-built packet type parsing circuit module to perform bit domain data parsing on the register data to obtain bit domain parsing data, where the bit domain parsing data includes: packet type valid data, packet length valid data, read / write valid flag, and register address valid data.

[0025] It is understandable that the configuration bitstream refers to the bitstream designed by the user for loading and running the FPGA program, and the configuration bitstream contains the complete internal configuration status, wiring, logic resources, IO settings, and register data of the FPGA. The register data refers to the data in the configuration bitstream of the FPGA used to initialize, control, and configure the internal registers of the FPGA. For example: WBSTAR register data, FDRI register data, etc.

[0026] Further, the pre-stage circuit is used to receive configuration data of different interfaces (such as: JTAG interface, SPI interface, BPI interface, SMAP interface, SRL interface, ICAP interface), and input the interface configuration data into the packet type parsing circuit module for packet type parsing. The packet type parsing circuit module refers to a circuit module used to parse the valid data of different bit fields in the register data of the configuration bitstream, such as: packet type valid data, packet length valid data, read / write valid flag, register address valid data, etc.

[0027] Specifically, the JTAG interface refers to a general test and debugging interface. The SPI interface refers to a serial peripheral interface, and the read and write data of the SPI interface are independently controlled by different signals. The BPI interface refers to the general term for parallel peripheral interfaces. The SMAP interface refers to a loading configuration interface used to configure the FPGA, which quickly loads configuration data through a parallel data bus. The SRL interface refers to a serial peripheral interface, and its read and write data share a signal control. The ICAP interface refers to an internal configuration access port provided by the FPGA to users.

[0028] Further, the bit field data parsing refers to identifying the valid data of each bit field in the register data. The bit field parsed data refers to the valid data of each bit field in the register data obtained after bit field data parsing. The packet type valid data refers to the valid data in the register data used to indicate the packet type. The packet length valid data refers to the valid data in the register data used to indicate the packet data length. The read / write valid flag refers to the valid flag in the register data used to indicate the packet read / write operator. The register address valid data refers to the valid data in the register data used to indicate the register address.

[0029] In the embodiment of the present invention, the bit field data parsing of the register data by using the pre-built packet type parsing circuit module to obtain the bit field parsed data includes: Identifying the configuration application scenario of the configuration bitstream; Selecting a target selector circuit in the multi-level selector circuit of the pre-built packet type parsing circuit module according to the configuration application scenario; The register data is input into a combinational gate circuit in the packet type parsing circuit by using the target selector circuit, and bit field bit value comparison is performed to obtain bit field parsing data.

[0030] It can be understood that the configuration application scenario refers to the configuration application mode of interface configuration data of various types. The multi-stage selector circuit is used to effectively select and output interface configuration data of various types. Since there will not be two configuration application scenarios existing simultaneously during the process of inputting register data into the packet type parsing circuit module by using the previous-stage circuit, therefore, an effective circuit can be selected in the multi-stage selector circuit to input the interface configuration data of a specific configuration application scenario into the packet type parsing circuit. Each stage circuit in the multi-stage selector circuit has a one-to-one correspondence with various types of interface configuration data.

[0031] Furthermore, the target selector circuit refers to the circuit corresponding to the configuration application scenario. The combinational gate circuit refers to the circuit in the packet type parsing circuit used to identify valid data of each bit field in the register data, such as XOR, XNOR, AND and other combinational gate circuits. By comparing the bit values of different bit fields in the register data through the combinational gate circuit, the bit field parsing data is obtained.

[0032] In the embodiment of the present invention, the configuration application scenarios include: JTAG interface input data configuration application scenario, SPI interface input data configuration application scenario, BPI interface input data configuration application scenario, SMAP interface input data configuration application scenario, SRL interface input data configuration application scenario, ICAP interface input data configuration application scenario.

[0033] In the embodiment of the present invention, after the bit field data of the register data is parsed by using the pre-built packet type parsing circuit module to obtain the bit field parsing data, the method further includes: Input the packet type valid data and the packet length valid data into the pre-built packet length counter module.

[0034] It can be understood that the packet length counter module can perform a countdown on the packet data length.

[0035] It should be understood that after the packet type valid data and the packet length valid data are input into the pre-built packet length counter module, the method further includes: Input the packet type valid data, the packet length valid data, and the read / write valid flag into the pre-built packet read / write control circuit module, and the packet read / write control circuit module contains a state machine.

[0036] It is understandable that the packet read / write control circuit module is responsible for generating status flags during the data packet configuration process. The functional implementation of this circuit module depends on a state machine. The state machine can generate state jumps based on valid data of the packet type, read / write valid flags, and the end flag of packet length counting. At the start and end of normal bitstream configuration, the state machine will stop at the IDLE state.

[0037] Further, after inputting the valid data of the packet type, the valid data of the packet length, and the read / write valid flag into the pre-built packet read / write control circuit module, the method further includes: Inputting the valid data of the packet type, the valid data of the packet length, the read / write valid flag, and the valid data of the register address into the pre-built Starbleed detection circuit module.

[0038] It is understandable that the Starbleed detection circuit module is a circuit module that detects the Starbleed vulnerability based on data such as the valid data of the packet type, the valid data of the packet length, the read / write valid flag, and the valid data of the register address. When the Starbleed detection circuit module determines that there is a Starbleed vulnerability, it will trigger a reset operation of the system and simultaneously block the read / write operations of the WBSTAR register to prevent data leakage.

[0039] Further, the Starbleed vulnerability data parsing process composed of the front-stage circuit, the packet type parsing circuit module, the packet read / write control circuit module, the packet length counter module, the Starbleed detection circuit module, and the rear-stage circuit can be referred to Figure 2 as shown.

[0040] S2. Identify the current register address according to the valid data of the register address.

[0041] It is interpretable that the current register address refers to the register address indicated in the register data.

[0042] S3. Determine whether the current register address is the preset WBSTAR register address.

[0043] It is understandable that the WBSTAR register address refers to the register address indicated in the WBSTAR register. The WBSTAR register refers to the warm start initial address register, which is used to store the boot address data and can realize the initial address for reading data from the external storage chip after a warm start reset inside the chip.

[0044] If the current register address is not the WBSTAR register address, then execute S4. Transmit the register data to the rear-stage circuit.

[0045] It can be understood that the post-stage circuit refers to a circuit module that further performs subsequent logic or control operations on the register data attacked through the Starbleed vulnerability.

[0046] Furthermore, since the Starbleed vulnerability is hidden in the WBSTAR register configuration of the FPGA, when the current register address is not the WBSTAR register address, it means that there will be no Starbleed vulnerability. Therefore, the register data is directly transmitted to the post-stage circuit.

[0047] If the current register address is the WBSTAR register address, then execute S5 to determine whether the state machine in the pre-built packet read / write control circuit module is in the preset IDLE state.

[0048] It can be understood that the state machine is used to indicate the configuration state of the packet read / write control circuit module during the configuration of the register data, and can generate state jumps according to the valid data of the packet type, the read / write valid flag, and the packet length count end flag. The IDLE state refers to the initial state or the end state of the state machine. At the start or end of configuring the configuration bitstream, when parsing the NOOP data in the configuration bitstream, or when the address register finishes data configuration, the state machine will be in the IDLE state.

[0049] In the embodiment of the present invention, determining whether the state machine in the pre-built packet read / write control circuit module is in the preset IDLE state includes: If the state machine is in the preset WDC state, when receiving the preset type 2 data packet, jump to the preset WRPD state and determine whether the packet length counter module generates the preset packet count end flag. Wherein, the WDC state means that the read / write valid flag is a write operation, the packet type corresponding to the valid data of the packet type is data packet type 1, and the packet data length corresponding to the valid data of the packet length is 0. The WRPD state means that the packet read / write control circuit module has received the valid data of the register address, the type 2 data packet corresponding to the WBSTAR register address is being transmitted, and the read / write valid flag is a write operation; When the packet length counter module generates the packet count end flag, the state machine is in the IDLE state; If the state machine is in the preset RDC state, when receiving a Type 2 data packet, it jumps to the preset RDPD state and determines whether the packet length counter module generates a packet count end flag. Among them, the RDC state means that the read / write valid flag is a read operation, the packet type corresponding to the packet type valid data is Data Packet Type 2, and the packet data length corresponding to the packet length valid data is 0. The RDPD state means that the packet read / write control circuit module has received the register address valid data, the Type 2 data packet corresponding to the WBSTAR register address is being transmitted, and the read / write valid flag is a read operation; When the packet length counter module generates a packet count end flag, the state machine is in the IDLE state.

[0050] Furthermore, the WDC state is valid when the read / write valid flag is a write operation, the packet type corresponding to the packet type valid data is Data Packet Type 1, and the packet data length corresponding to the packet length valid data is 0. When the state machine is in the WDC state, it indicates that the combinational gate circuit will receive a Type 2 data packet, and after receiving the Type 2 data packet, it jumps to the WRPD state. The Type 2 data packet refers to a data packet with a packet type of Data Packet Type 2. The WRPD state is in the state process of transmitting the data packet corresponding to the register address after determining the register address valid data and performing a write operation. When the packet length counter module generates a packet count end flag, it will jump back to the IDLE state from the WRPD state.

[0051] Specifically, the data structure of the Type 1 data packet is as follows:

[0052] Interpretably, in the 32-bit double word of the Type 1 data packet, the 31-to-29 bit field indicates the data packet type, the 28-to-27 bit field indicates the packet read / write operator, 01 is a read operation, 10 is a write operation, 00 is empty, and 11 is reserved. The 26-to-13 bit field indicates the register address to be configured, the 12-to-11 bit field is reserved, and the 10-to-0 bit field is the data length that the register address needs to be configured, in units of double words. When the data length that the register address needs to be configured exceeds the range that can be indicated by 11 bits, it is necessary to follow and configure a Type 2 data packet after the Type 1 data packet, and the 10-to-0 bit field of the Type 1 data packet needs to be filled with all 0s, and only the Type 2 data packet indicates the data length. For example: when configuring the data packet of the FDRI register, only the Type 2 data packet indicates the data length.

[0053] Furthermore, the data structure of the Type 3 data packet is as follows:

[0054] It is understandable that in the 32-bit double word of the Type 2 data packet, the 31- to 29-bit field indicates the data packet type, the 28- to 27-bit field indicates the packet read / write operator, and the packet read / write operator is the same as that of the Type 1 data packet. The 26- to 0-bit field is the data length required to configure the register address, which extends the 11-bit data length of the Type 1 data packet, and the 27-bit data length can meet the range of the longest data of the register address.

[0055] Specifically, the packet length counter module can count down the packet data length. As a whole, it is a 27-bit down counter that can count down the packet data length of the Type 1 data packet or the Type 2 data packet. The count end flag indicates the flag when the packet length counter counts down to 0.

[0056] Furthermore, the RDC state is valid when the read / write valid flag is a read operation, the packet type corresponding to the valid data of the packet type is the data packet type 1, and the packet data length corresponding to the valid data of the packet length is 0. When the state machine is in the WDC state, it will indicate that the combinational gate circuit will receive the Type 2 data packet, and after receiving the Type 2 data packet, it will jump to the RDPD state. The RDPD state is in the state process of transmitting the data packet corresponding to the register address and performing a read operation after determining the valid data of the register address. When the packet length counter module generates the packet count end flag, it will jump back to the IDLE state from the WRPD state.

[0057] Specifically, the state judgment flowchart of the state machine can be referred to Figure 3 as shown.

[0058] In the embodiment of the present invention, determining whether the packet length counter module generates a preset packet count end flag includes: identifying the packet data length of the Type 2 data packet; using a preset 27-bit width to count down the packet data length of the Type 2 data packet to obtain a decremented count value; judging whether the decremented count value is equal to 0; if the decremented count value is not equal to 0, the packet length counter module does not generate a packet count end flag; if the decremented count value is equal to 0, the packet length counter module generates a packet count end flag.

[0059] It is understandable that the decreasing count value refers to the count value during the countdown process of the packet data length. When performing a countdown on the packet data length of a type 1 data packet, a 11-bit width is used for the countdown. When performing a countdown on the packet data length of a type 2 data packet, a 27-bit width is used for the countdown. When the decreasing count value is 0, a packet count end flag is generated, indicating that the register configuration data of the register address has ended the configuration. At this time, the packet count end flag is output to the packet read / write control circuit module and the Starbleed detection circuit module.

[0060] If the state machine in the packet read / write control circuit module is not in the IDLE state, then execute S6, and transfer the register data to the subsequent circuit.

[0061] It is understandable that in the FPGA configuration bitstream implemented based on the SRAM process, the FDRI register data refers to the user configuration data written to the SRAM. Among them, the SRAM refers to a static data random access memory. As long as the memory maintains power supply, the data stored inside can remain constant. The FDRI register refers to the configuration data register written to the SRAM.

[0062] Furthermore, each double word in the FDRI register data is generated by a specific specification. There is a certain probability that some bit fields in the FDRI register data will be the same as the value of the WBSTAR register address, thus causing a false trigger of the Starbleed error vulnerability warning. To avoid this kind of situation, the configuration of the FDRI register data and the WBSTAR register data is distinguished by judging whether the state machine is in the IDLE state. First, during the configuration of the FDRI register data packet, the state machine of the packet read / write control circuit module has gone through the WDC state and received a type 2 data packet, and then jumped to the WRPD state. The WRPD state indicates that the FDRI register data packet is being received. At this time, it is in the state of writing to the FDRI register. Although the data of the write operation at this time may happen to be the same as the data value configured for the WBSTAR register after being rewritten by the attacker, since it is not writing data to the WBSTAR register, it can be determined that the configuration bitstream at this time is a non-attack bitstream, and the state machine must be in a non-IDLE state.

[0063] Specifically, by judging whether the state machine in the packet read / write control circuit module is in the IDLE state, not only can the situation of false triggering of the Starbleed error vulnerability warning be excluded to avoid data face collision, but also it can inform the system that before the WBSTAR register address is obtained, the packet length counter module has generated a count end flag, the previous register address configuration has ended normally, and the state machine has jumped back to the IDLE state, avoiding the influence of the previously generated configuration problems on the judgment of the Starbleed error vulnerability.

[0064] If the state machine in the packet read / write control circuit module is in the IDLE state, then execute S7, and respectively determine the packet type, the packet data length, and the packet configuration operation according to the packet type valid data, the packet length valid data, and the read / write valid flag.

[0065] S8. Determine whether the packet type, the packet data length, and the packet configuration operation conform to the preset vulnerability combination determination criteria.

[0066] Specifically, the vulnerability combination determination criteria mean that the packet type is data packet type 1, the packet data length is greater than 1, and the packet configuration operation is a write operation.

[0067] It can be understood that since the packet data length configured in the WBSTAR register is 1, and the WBSTAR register only stores the last written double-word data. An attacker can rewrite the packet data length of the WBSTAR register to be greater than 1, and write the ciphertext content of the configuration bitstream into the WBSTAR register, thereby replacing the original legitimate bitstream, causing the modified encrypted bitstream to fail the HMAC verification. The system configuration will automatically reset the FPGA, but the data in the WBSTAR register will not be reset, so it can be read out after being decrypted, resulting in the leakage of the user's encrypted bitstream.

[0068] Furthermore, in the configuration bitstream of the chip, only the packet data length of the FDRI register is greater than 1, and the packet data length of the WBSTAR register must be 1. When the attacker rewrites the bitstream, the packet data length of the WBSTAR register needs to be rewritten to be greater than 1 first. In order not to affect the write configuration operation, the read / write operation in the data packet of the rewritten WBSTAR register is still a write operation, and the configured data packet is a type 1 data packet. Therefore, when the packet data length of the WBSTAR register is greater than 1, the packet configuration operation is a write operation, the packet type is data packet type 1, and it satisfies that the current register address is the WBSTAR register address and the state machine is in the IDLE state, it can be determined that the current bitstream configuration process is an abnormal register configuration process, and the configuration bitstream has been maliciously tampered with by the attacker, and the Starbleed detection circuit module can trigger a vulnerability warning.

[0069] If the packet type, the packet data length, and the packet configuration operation do not conform to the vulnerability combination determination criteria, then execute S9, and transfer the register data to the subsequent circuit.

[0070] If the packet type, the packet data length, and the packet configuration operation conform to the vulnerability combination determination criteria, then execute S10, trigger a vulnerability warning, and complete the data parsing and bitstream configuration for preventing Starbleed vulnerability attacks.

[0071] In the embodiment of the present invention, after the vulnerability warning is triggered, the method further includes: Trigger a lock signal according to the vulnerability warning; Lock the state machine in the IDLE state according to the lock signal, and perform a configuration stop operation, where the configuration stop operation includes: stopping the configuration of the subsequent circuit, stopping the write operation of the WBSTAR register, and stopping the read operation of the WBSTAR register.

[0072] It can be understood that when the current register address is the WBSTAR register address, the state machine is in the IDLE state and meets the vulnerability combination determination criteria, it is necessary to stop the configuration process of all subsequent circuits and prohibit any read and write operations on the WBSTAR register to protect data security.

[0073] Further, when receiving the PROGRAM_B global reset signal from outside the system, the packet read / write control circuit module will release the locked state of the state machine, and the packet length counter module, the packet type parsing circuit module, and the Starbleed detection circuit module will be reset again. At this time, the FPGA resumes the initial configuration state and waits for reconfiguration. The PROGRAM_B refers to the global reset pin, and the global reset pin can clear all configuration information inside the FPGA, making the FPGA return to the initial state and wait for reconfiguration.

[0074] To solve the problems described in the background art, the present invention determines the Starbleed vulnerability attack through the current register address, whether the state machine is in the IDLE state, and the vulnerability combination determination criteria. First, it is necessary to obtain the register data in the configuration bitstream, and then use the pre-stage circuit to perform bit-field data parsing on the register data to obtain bit-field parsed data. Among them, the bit-field parsed data includes: packet type valid data, packet length valid data, read / write valid flag, and register address valid data. Since the Starbleed vulnerability attack needs to simultaneously meet the three conditions that the current register address is the WBSTAR register address, the state machine is in the IDLE state, and the packet type, packet data length, and packet configuration operation meet the vulnerability combination determination criteria, it is possible to first identify the current register address according to the register address valid data and determine whether the current register address is the WBSTAR register address. If the current register address is not the WBSTAR register address, it means that there is no Starbleed vulnerability attack, and the register data is directly transmitted to the post-stage circuit. If the current register address is the WBSTAR register address, the compliance determination of the second condition is continued, and it is determined whether the state machine in the packet read / write control circuit is in the IDLE state. If the state machine of the packet read / write control circuit is not in the IDLE state, it means that there is no Starbleed vulnerability attack, and the register data is directly transmitted to the post-stage circuit. If the state machine of the packet read / write control circuit is in the IDLE state, the compliance determination of the third condition needs to be performed. First, the packet type, packet data length, and packet configuration operation are determined according to the packet type valid data, packet length valid data, and read / write valid flag respectively, and then it is determined whether the packet type, packet data length, and packet configuration operation meet the vulnerability combination determination criteria. Among them, the vulnerability combination determination criteria mean that the packet type is packet type 1, the packet data length is greater than 1, and the packet configuration operation is a write operation. If the packet type, packet data length, and packet configuration operation do not meet the vulnerability combination determination criteria, it means that there is no Starbleed vulnerability attack, and the register data is directly transmitted to the post-stage circuit. If the packet type, packet data length, and packet configuration operation meet the vulnerability combination determination criteria, a vulnerability warning is triggered. Therefore, the present invention can solve the problem that the current defense mechanism against the Starbleed vulnerability attack is imperfect.

[0075] As Figure 4 shown, it is a functional module diagram of a data parsing and bitstream configuration system for preventing Starbleed vulnerability attacks provided by an embodiment of the present invention.

[0076] The data parsing and bitstream configuration system 100 for preventing Starbleed vulnerability attacks according to the present invention can be installed in an electronic device. According to the functions achieved, the data parsing and bitstream configuration system 100 for preventing Starbleed vulnerability attacks can include a current register address determination module 101, an IDLE state determination module 102, a vulnerability combination determination criterion determination module 103, and a trigger vulnerability warning module 104. The modules in the present invention can also be referred to as units, which refer to a series of computer program segments that can be executed by an electronic device processor and can complete fixed functions, and are stored in the memory of the electronic device.

[0077] The current register address determination module 101 is configured to obtain the register data in the configuration bitstream, perform bit-field data parsing on the register data by using a pre-built packet type parsing circuit module to obtain bit-field parsing data, where the bit-field parsing data includes: packet type valid data, packet length valid data, read / write valid flag, and register address valid data; identify the current register address according to the register address valid data; determine whether the current register address is a preset WBSTAR register address; if the current register address is not the WBSTAR register address, then transmit the register data to the subsequent circuit for data transmission; The IDLE state determination module 102 is configured to, if the current register address is the WBSTAR register address, determine whether the state machine in the pre-built packet read / write control circuit module is a preset IDLE state; if the state machine in the packet read / write control circuit module is not in the IDLE state, then transmit the register data to the subsequent circuit for data transmission; The vulnerability combination determination criterion determination module 103 is configured to, if the state machine in the packet read / write control circuit module is in the IDLE state, determine the packet type, packet data length, and packet configuration operation according to the packet type valid data, packet length valid data, and read / write valid flag respectively; determine whether the packet type, packet data length, and packet configuration operation meet the preset vulnerability combination determination criterion, where the vulnerability combination determination criterion means that the packet type is packet type 1, the packet data length is greater than 1, and the packet configuration operation is a write operation; if the packet type, packet data length, and packet configuration operation do not meet the vulnerability combination determination criterion, then transmit the register data to the subsequent circuit for data transmission; The trigger vulnerability warning module 104 is configured to trigger a vulnerability warning if the packet type, packet data length, and packet configuration operation meet the vulnerability combination determination criterion.

[0078] Specifically, each module in the data parsing and bitstream configuration system 100 for preventing Starbleed vulnerability attacks in the embodiments of the present invention adopts the same as the above-mentioned Figure 1The technical means are the same as those of the data parsing and bitstream configuration method for preventing Starbleed vulnerability attacks described in [reference], and can produce the same technical effects, which will not be elaborated here.

[0079] As Figure 5 shown, it is a schematic structural diagram of an electronic device for implementing a data parsing and bitstream configuration method for preventing Starbleed vulnerability attacks provided by an embodiment of the present invention.

[0080] The electronic device 1 may include a processor 10, a memory 11, and a bus 12, and may further include a computer program stored in the memory 11 and executable on the processor 10, such as a data parsing and bitstream configuration method program for preventing Starbleed vulnerability attacks.

[0081] Among them, the memory 11 includes at least one type of readable storage medium, and the readable storage medium includes flash memory, mobile hard disk, multimedia card, card-type memory (such as SD or DX memory, etc.), magnetic memory, magnetic disk, optical disk, etc. In some embodiments, the memory 11 may be an internal storage unit of the electronic device 1, such as the mobile hard disk of the electronic device 1. In other embodiments, the memory 11 may also be an external storage device of the electronic device 1, such as a plug-in mobile hard disk, a Smart Media Card (SMC), a Secure Digital (SD) card, a Flash Card, etc. equipped on the electronic device 1. Further, the memory 11 also includes the internal storage unit of the electronic device 1 and the external storage device. The memory 11 can not only be used to store application software installed in the electronic device 1 and various types of data, such as the code of the data parsing and bitstream configuration method program for preventing Starbleed vulnerability attacks, but also be used to temporarily store data that has been output or will be output.

[0082] In some embodiments, the processor 10 may be composed of an integrated circuit. For example, it may be composed of a single packaged integrated circuit, or may be composed of multiple packaged integrated circuits with the same or different functions, including one or more central processing units (CPUs), microprocessors, digital processing chips, graphics processors, and combinations of various control chips, etc. The processor 10 is the control core (Control Unit) of the electronic device, connecting various components of the entire electronic device through various interfaces and circuits, and by running or executing programs or modules stored in the memory 11 (such as the data parsing and bitstream configuration method program for preventing Starbleed vulnerability attacks, etc.), and calling the data stored in the memory 11, to perform various functions of the electronic device 1 and process data.

[0083] The bus 12 may be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus, etc. This bus 12 can be divided into an address bus, a data bus, a control bus, etc. The bus 12 is set to enable connection communication between the memory 11 and at least one processor 10, etc.

[0084] Figure 5 Only the electronic device with components is shown. Those skilled in the art can understand that, Figure 5 the shown structure does not constitute a limitation on the electronic device 1, and it may include fewer or more components than shown, or combine certain components, or have a different component arrangement.

[0085] For example, although not shown, the electronic device 1 may further include a power supply (such as a battery) for supplying power to each component. Preferably, the power supply can be logically connected to the at least one processor 10 through a power management device, so as to implement functions such as charge management, discharge management, and power consumption management through the power management device. The power supply may also include any components such as one or more DC or AC power supplies, a recharge device, a power failure detection circuit, a power converter or inverter, and a power status indicator. The electronic device 1 may also include various sensors, a Bluetooth module, a Wi-Fi module, etc., which will not be elaborated here.

[0086] Furthermore, the electronic device 1 may further include a network interface. Optionally, the network interface may include a wired interface and / or a wireless interface (such as a WI-FI interface, a Bluetooth interface, etc.), which is generally used to establish a communication connection between the electronic device 1 and other electronic devices.

[0087] Optionally, the electronic device 1 may further include a user interface, which may be a display, an input unit (such as a keyboard), and optionally, the user interface may also be a standard wired interface or a wireless interface. Optionally, in some embodiments, the display may be an LED display, a liquid crystal display, a touch liquid crystal display, and an OLED (Organic Light-Emitting Diode) toucher, etc. Among them, the display may also be appropriately referred to as a display screen or a display unit, which is used to display the information processed in the electronic device 1 and to display a visual user interface.

[0088] The data parsing and bitstream configuration method program for preventing Starbleed vulnerability attacks stored in the memory 11 of the electronic device 1 is a combination of multiple instructions. When running in the processor 10, it can achieve: Obtain the register data in the configuration bitstream, and use a pre-built packet type parsing circuit module to perform bit field data parsing on the register data to obtain bit field parsing data, where the bit field parsing data includes: packet type valid data, packet length valid data, read / write valid flag, and register address valid data; Identify the current register address according to the register address valid data; Determine whether the current register address is a preset WBSTAR register address; If the current register address is not the WBSTAR register address, then transmit the register data to the subsequent circuit; If the current register address is the WBSTAR register address, then determine whether the state machine in the pre-built packet read / write control circuit module is in a preset IDLE state; If the state machine in the packet read / write control circuit module is not in the IDLE state, then transmit the register data to the subsequent circuit; If the state machine in the packet read / write control circuit module is in the IDLE state, then determine the packet type, packet data length, and packet configuration operation according to the packet type valid data, packet length valid data, and read / write valid flag respectively; Determine whether the packet type, packet data length, and packet configuration operation meet a preset vulnerability combination determination standard, where the vulnerability combination determination standard means that the packet type is packet type 1, the packet data length is greater than 1, and the packet configuration operation is a write operation; If the packet type, packet data length, and packet configuration operation do not meet the vulnerability combination determination standard, then transmit the register data to the subsequent circuit; If the packet type, packet data length, and packet configuration operation meet the vulnerability combination determination criteria, a vulnerability warning is triggered, and the data parsing and bitstream configuration for preventing Starbleed vulnerability attacks are completed.

[0089] Specifically, the specific implementation method of the above instructions by the processor 10 can refer to Figures 1 to 5 the description of the relevant steps in the corresponding embodiment, which will not be elaborated here.

[0090] Furthermore, if the modules / units integrated in the electronic device 1 are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. The computer-readable storage medium can be volatile or non-volatile. For example, the computer-readable medium can include: any entity or device capable of carrying the computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disc, computer memory, read-only memory (ROM, Read-Only Memory).

[0091] The present invention also provides a computer-readable storage medium storing a computer program, which when executed by a processor of an electronic device, can implement: Obtain register data in the configuration bitstream, perform bit-field data parsing on the register data using a pre-built packet type parsing circuit module to obtain bit-field parsing data, where the bit-field parsing data includes: packet type valid data, packet length valid data, read / write valid flag, register address valid data; Identify the current register address according to the register address valid data; Determine whether the current register address is a preset WBSTAR register address; If the current register address is not the WBSTAR register address, transmit the register data to the subsequent circuit; If the current register address is the WBSTAR register address, determine whether the state machine in the pre-built packet read / write control circuit module is in a preset IDLE state; If the state machine in the packet read / write control circuit module is not in the IDLE state, transmit the register data to the subsequent circuit; If the state machine in the packet read / write control circuit module is in the IDLE state, determine the packet type, packet data length, and packet configuration operation according to the packet type valid data, packet length valid data, and read / write valid flag respectively; Determine whether the packet type, packet data length, and packet configuration operation meet a preset vulnerability combination determination criteria, where the vulnerability combination determination criteria refer to the packet type being packet type 1, the packet data length being greater than 1, and the packet configuration operation being a write operation; If the packet type, packet data length, and packet configuration operation do not meet the vulnerability combination determination criteria, the register data will be transferred to the subsequent circuit. If the packet type, packet data length, and packet configuration operation meet the vulnerability combination determination criteria, a vulnerability warning will be triggered to complete the data parsing and bitstream configuration for preventing Starbleed vulnerability attacks.

[0092] In several embodiments provided by the present invention, it should be understood that the disclosed devices, systems, and methods can be implemented in other ways. For example, the system embodiments described above are merely illustrative, and there may be other partitioning methods in actual implementation.

[0093] The modules described as separate components may or may not be physically separated. The components shown as modules may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0094] In addition, in each embodiment of the present invention, the functional modules can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above integrated units can be implemented in the form of hardware or in the form of hardware plus software functional modules.

[0095] For those skilled in the art, it is obvious that the present invention is not limited to the details of the above exemplary embodiments, and without departing from the spirit or basic characteristics of the present invention, the present invention can be implemented in other specific forms.

[0096] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical solutions of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the technical solutions of the present invention.

Claims

1. A data parsing and bitstream configuration method for preventing Starbleed vulnerability attacks, characterized in that The method includes: Obtain the register data in the configuration bitstream, and use a pre-built packet type parsing circuit module to perform bit-field data parsing on the register data to obtain bit-field parsed data. Among them, the bit-field parsed data includes: packet type valid data, packet length valid data, read / write valid flag, and register address valid data; Identify the current register address according to the register address valid data; Determine whether the current register address is a preset WBSTAR register address; If the current register address is not the WBSTAR register address, transfer the register data to the subsequent circuit; If the current register address is the WBSTAR register address, determine whether the state machine in the pre-built packet read / write control circuit module is in a preset IDLE state; If the state machine in the packet read / write control circuit module is not in the IDLE state, transfer the register data to the subsequent circuit; If the state machine in the packet read / write control circuit module is in the IDLE state, determine the packet type, packet data length, and packet configuration operation according to the packet type valid data, packet length valid data, and read / write valid flag respectively; Determine whether the packet type, packet data length, and packet configuration operation meet the preset vulnerability combination determination criteria. The vulnerability combination determination criteria refer to that the packet type is packet type 1, the packet data length is greater than 1, and the packet configuration operation is a write operation; If the packet type, packet data length, and packet configuration operation do not meet the vulnerability combination determination criteria, transfer the register data to the subsequent circuit; If the packet type, packet data length, and packet configuration operation meet the vulnerability combination determination criteria, trigger a vulnerability warning to complete the data parsing and bitstream configuration for preventing Starbleed vulnerability attacks.

2. The data parsing and bitstream configuration method for preventing Starbleed vulnerability attacks according to claim 1, characterized in that The step of using the pre-built packet type parsing circuit module to perform bit-field data parsing on the register data to obtain bit-field parsed data includes: Identify the configuration application scenario of the configuration bitstream; Select a target selector circuit in the multi-level selector circuit of the pre-built packet type parsing circuit module according to the configuration application scenario; Use the target selector circuit to input the register data into the combination gate circuit in the packet type parsing circuit and perform bit-field bit value comparison to obtain bit-field parsed data.

3. The data parsing and bitstream configuration method for preventing Starbleed vulnerability attacks according to claim 2, characterized in that, The configuration application scenarios include: JTAG interface input data configuration application scenario, SPI interface input data configuration application scenario, BPI interface input data configuration application scenario, SMAP interface input data configuration application scenario, SRL interface input data configuration application scenario, ICAP interface input data configuration application scenario.

4. The data parsing and bitstream configuration method for preventing Starbleed vulnerability attacks as claimed in claim 1, wherein After using the pre-built packet type parsing circuit module to perform bit-field data parsing on the register data to obtain bit-field parsed data, the method further includes: Input the packet type valid data and packet length valid data into a pre-built packet length counter module.

5. The data parsing and bitstream configuration method for preventing Starbleed vulnerability attacks according to claim 4, characterized in that After inputting the packet type valid data and packet length valid data into the pre-built packet length counter module, the method further includes: Input the packet type valid data, packet length valid data, and read / write valid flag into a pre-built packet read / write control circuit module, which contains a state machine.

6. The data parsing and bitstream configuration method for preventing Starbleed vulnerability attacks according to claim 5, characterized in that After inputting the packet type valid data, packet length valid data, and read / write valid flag into the pre-built packet read / write control circuit module, the method further includes: Input the packet type valid data, packet length valid data, read / write valid flag, and register address valid data into a pre-built Starbleed detection circuit module.

7. The data parsing and bitstream configuration method for preventing Starbleed vulnerability attacks according to claim 6, characterized in that, The determination of whether the state machine in the pre-built packet read / write control circuit module is in a preset IDLE state includes: If the state machine is in the preset WDC state, when receiving a preset type 2 data packet, jump to the preset WRPD state and determine whether the packet length counter module generates a preset packet count end flag. Here, the WDC state means that the read / write valid flag is a write operation, the packet type corresponding to the packet type valid data is data packet type 1, and the packet data length corresponding to the packet length valid data is 0. The WRPD state means that the packet read / write control circuit module has received the register address valid data, the type 2 data packet corresponding to the WBSTAR register address is being transmitted, and the read / write valid flag is a write operation; When the packet length counter module generates a packet count end flag, the state machine is in the IDLE state; If the state machine is in the preset RDC state, when receiving a type 2 data packet, jump to the preset RDPD state and determine whether the packet length counter module generates a packet count end flag. Here, the RDC state means that the read / write valid flag is a read operation, the packet type corresponding to the packet type valid data is data packet type 2, and the packet data length corresponding to the packet length valid data is 0. The RDPD state means that the packet read / write control circuit module has received the register address valid data, the type 2 data packet corresponding to the WBSTAR register address is being transmitted, and the read / write valid flag is a read operation; When the packet length counter module generates a packet count end flag, the state machine is in the IDLE state.

8. The data parsing and bitstream configuration method for preventing Starbleed vulnerability attacks according to claim 7, characterized in that The determination of whether the packet length counter module generates a preset packet count end flag includes: Identify the packet data length of the type 2 data packet; Perform a countdown on the packet data length of the type 2 data packet using a preset 27-bit width to obtain a decremented count value; Determine whether the decremented count value is equal to 0; If the decremented count value is not equal to 0, the packet length counter module has not generated a packet count end flag; If the decremented count value is equal to 0, the packet length counter module generates a packet count end flag.

9. The data parsing and bitstream configuration method for preventing Starbleed vulnerability attacks according to claim 7, characterized in that, After triggering the vulnerability warning, the method further includes: Trigger a lock signal according to the vulnerability warning; Lock the state machine in the IDLE state according to the lock signal and perform a configuration stop operation, where the configuration stop operation includes: stopping the configuration of the subsequent circuit, stopping the write operation of the WBSTAR register configuration, and stopping the read operation of the WBSTAR register configuration.

10. A data parsing and bitstream configuration system for preventing Starbleed vulnerability attacks, characterized in that The system includes: The current register address judgment module is used to obtain the register data in the configuration bitstream, and use the pre-built packet type parsing circuit module to perform bit-field data parsing on the register data to obtain bit-field parsing data. Among them, the bit-field parsing data includes: packet type valid data, packet length valid data, read / write valid flag, and register address valid data; identify the current register address according to the register address valid data; determine whether the current register address is the preset WBSTAR register address; if the current register address is not the WBSTAR register address, then transmit the register data to the subsequent circuit for data transmission; The IDLE state judgment module is used to, if the current register address is the WBSTAR register address, determine whether the state machine in the pre-built packet read / write control circuit module is the preset IDLE state; if the state machine in the packet read / write control circuit module is not in the IDLE state, then transmit the register data to the subsequent circuit for data transmission; The vulnerability combination determination criterion determination module is used to, if the state machine in the packet read / write control circuit module is in the IDLE state, determine the packet type, packet data length, and packet configuration operation according to the packet type valid data, packet length valid data, and read / write valid flag respectively; determine whether the packet type, packet data length, and packet configuration operation meet the preset vulnerability combination determination criterion, where the vulnerability combination determination criterion means that the packet type is data packet type 1, the packet data length is greater than 1, and the packet configuration operation is a write operation; if the packet type, packet data length, and packet configuration operation do not meet the vulnerability combination determination criterion, then transmit the register data to the subsequent circuit for data transmission; The trigger vulnerability warning module is used to trigger a vulnerability warning if the packet type, packet data length, and packet configuration operation meet the vulnerability combination determination criterion.

Citation Information

Patent Citations

  • Method and device for defending StarBleed vulnerabilities

    CN111967014A

  • System and method for detecting malicious attempts to discover vulnerabilities in a web application

    US20230114298A1