State restorer of logic controller
By introducing data registration and comparison circuits into the logic controller, the abnormal coding of the state machine is detected and restored in real time, the abnormal detection failure problem caused by the memory being easily tampered in the prior art is solved, and efficient security protection and rapid recovery of the logic controller are achieved.
Patent Information
- Application Number
- CN202510874194.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-26
- Publication Date
- 2025-08-01
- Estimated Expiration
- 2045-06-26
AI Technical Summary
In the state machine detection and recovery of logic controllers, the prior art relies on the normal state encoding stored in the internal memory for abnormal detection, which is susceptible to physical attacks and tampering, resulting in the failure of the abnormal detection mechanism and cannot withstand hardware-level threats such as abnormal voltage injection and power-on attacks.
The data storage circuit records the previous normal state encoding of the state machine in real time and feeds it back to the state machine input terminal. Combined with the comparison circuit, the previous state encoding and the current output state encoding are mutually exclusively detected. The recovery circuit forces the predetermined normal initial encoding when an abnormality is detected, and the rapid reset of the state machine is achieved.
Effectively prevents abnormal transfer of state machine from external attacks or hardware failures, improves the anti-interference ability and security protection level of the logic controller, and ensures that the state machine quickly returns to the initial safe state.
Smart Images

Figure CN120406291A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of hardware security protection, and more specifically to a state restorer for a logic controller. Background Art
[0002] With the evolution of hardware attack technologies, logic controllers usually face core security risks such as abnormal voltage injection, power-on stage attacks, and input / output interface side channel attacks.
[0003] In the prior art, one-hot encoding is usually adopted in the state machine detection and restoration of logic controllers. However, when using one-hot encoding, abnormal detection depends on the normal state encoding stored in the internal memory of the logic controller. If the internal memory is physically attacked and tampered with, the legitimate state encoding will be replaced, resulting in the failure of the abnormal detection mechanism and the inability to resist hardware-level threats such as abnormal voltage injection and power-on attacks. Summary of the Invention
[0004] In view of the above problems, this application provides a state restorer for a logic controller that improves anti-interference ability and security protection level.
[0005] According to one aspect of this application, a state restorer for a logic controller is provided. The state restorer includes: a data register circuit configured to register the nth state encoding of the state machine in the logic controller and input the nth state encoding into the state machine to trigger the state machine to switch from the nth state encoding to the (n + 1)th state encoding, where n is a positive integer greater than or equal to 1; a comparison circuit configured to compare the nth state encoding output by the data register circuit and the (n + 1)th state encoding output by the state machine to obtain a control signal; and a restoration circuit configured to, when the control signal indicates that the (n + 1)th state encoding is an abnormal encoding, control the state machine to switch from the (n + 1)th state encoding to a predetermined normal state encoding according to the control signal. Brief Description of the Drawings
[0006] Through the following description of the embodiments of this application with reference to the drawings, the above content and other objects, features, and advantages of this application will become clearer.
[0007] Figure 1 Shows a schematic structural diagram of a state restorer according to the first embodiment of this application.
[0008] Figure 2 Shows a schematic structural diagram of a state restorer according to a specific embodiment of this application.
[0009] Figure 3 Shows a specific schematic structural diagram of a state restorer according to a specific embodiment of this application.
[0010] Figure 4 Shows a specific structural schematic diagram of a state restorer according to another specific embodiment of the present application.
[0011] Figure 5 Shows a structural schematic diagram of a recovery circuit according to a specific embodiment of the present application.
[0012] Figure 6 Shows a specific structural schematic diagram of a recovery circuit according to a specific embodiment of the present application.
[0013] Figure 7 Shows a structural schematic diagram of a recovery circuit according to another specific embodiment of the present application.
[0014] Figure 8 Shows a specific structural schematic diagram of a recovery circuit according to another specific embodiment of the present application.
[0015] Figure 9 Shows a structural schematic diagram of a state restorer according to the second embodiment of the present application.
[0016] Figure 10 Shows a specific structural schematic diagram of a state restorer according to the second embodiment of the present application.
[0017] Figure 11 Shows a structural schematic diagram of a state restorer according to the third embodiment of the present application.
[0018] Figure 12 Shows a structural schematic diagram of a password verification circuit according to a specific embodiment of the present application.
[0019] Figure 13 Shows a specific structural schematic diagram of a password verification circuit according to a specific embodiment of the present application.
[0020] Figure 14 Shows a specific structural schematic diagram of a ciphertext processing circuit according to a specific embodiment of the present application.
[0021] Figure 15 Shows a structural schematic diagram of a state restorer according to the fourth embodiment of the present application.
[0022] Figure 16 Shows a specific structural schematic diagram of a voltage detection circuit according to a specific embodiment of the present application.
[0023] Figure 17 Shows a specific structural schematic diagram of a voltage detection circuit according to another specific embodiment of the present application.
[0024] Figure 18 Shows a specific structural schematic diagram of a voltage detection circuit according to yet another specific embodiment of the present application.
[0025] Figure 19 Shows a schematic structural diagram of a status restorer according to the fifth embodiment of the present application.
[0026] Figure 20 Shows a schematic structural diagram of a status restorer according to the sixth embodiment of the present application.
[0027] Figure 21 Shows a schematic structural diagram of a status restorer according to the seventh embodiment of the present application.
[0028] Figure 22 Shows a schematic structural diagram of the specific structure of an authority verification circuit according to a specific embodiment of the present application.
[0029] Figure 23 Shows a schematic structural diagram of the specific structure of an authority verification circuit according to another specific embodiment of the present application.
[0030] Figure 24 Shows a schematic structural diagram of the specific structure of an authority verification circuit according to yet another specific embodiment of the present application.
[0031] Figure 25 Shows a schematic architecture diagram when a logic controller according to a specific embodiment of the present application is running.
[0032] Figure 26 Shows a schematic architecture diagram of an interface isolation unit according to a specific embodiment of the present application.
[0033] Figure 27 Shows a schematic diagram of the implementation of the functions of a status monitoring module and a status restoration module according to a specific embodiment of the present application.
[0034] Figure 28 Shows a schematic architecture diagram of an interface isolation unit using the random mapping method of IO ports for data transfer according to a specific embodiment of the present application. Detailed implementation manners
[0035] Hereinafter, embodiments of the present application will be described with reference to the accompanying drawings. However, it should be understood that these descriptions are merely exemplary and are not intended to limit the scope of the present application. In the following detailed description, for the sake of explanation, many specific details are set forth in order to provide a comprehensive understanding of the embodiments of the present application. However, obviously, one or more embodiments can also be implemented without these specific details. In addition, in the following description, descriptions of well-known structures and technologies are omitted to avoid unnecessarily confusing the concepts of the present application.
[0036] The terms used herein are merely for describing specific embodiments and are not intended to limit the present application. The terms "comprising", "including" and the like used herein indicate the presence of the described features, steps, operations and / or components, but do not preclude the presence or addition of one or more other features, steps, operations or components.
[0037] All terms used herein (including technical and scientific terms) have the meanings commonly understood by those skilled in the art, unless otherwise defined. It should be noted that the terms used herein should be interpreted as having a meaning consistent with the context of this specification, and should not be interpreted in an idealized or overly rigid manner.
[0038] In the case of using expressions such as "at least one of A, B, and C, etc.", generally, it should be interpreted according to the meaning commonly understood by those skilled in the art (for example, "a system having at least one of A, B, and C" should include, but not be limited to, a system having only A, only B, only C, having A and B, having A and C, having B and C, and / or having A, B, and C, etc.).
[0039] In the field of digital circuit design, logic controllers are widely used in key fields such as information security. It realizes the state machine logic through a hardware description language. As the core control unit of the logic controller, the state machine completes functions such as instruction processing and data transmission through state encoding jumps.
[0040] However, with the evolution of hardware attack technologies, logic controllers usually face core security risks such as abnormal voltage injection, power-on stage attacks, and input / output (IO) interface side-channel attacks. Among them, abnormal voltage injection refers to the attacker injecting abnormal voltage through means such as electromagnetic interference, resulting in disorder of the state machine jump logic. A power-on stage attack refers to using logic tampering or illegal instruction injection to make the logic controller enter an untrusted state when starting up. An IO interface side-channel attack refers to detecting internal data through input / output ports, causing leakage of sensitive information such as keys.
[0041] In the state machine design of a logic controller, each state needs to be encoded, and the expected functions of the system are completed through the transition between states. In the prior art, since the one-hot encoding method can reduce the change of decoded data between two adjacent states, improve the change speed, and occupy fewer register bits, the one-hot encoding method is often used in the state machine of logic controllers.
[0042] However, a large number of irrelevant states will occur when using the One-hot encoding method. When the logic controller enters an irrelevant state, it is necessary to process this state to enable the state machine to operate normally. The prior art usually defines all irrelevant states. After the logic controller enters an irrelevant state due to an exception, a jump process is performed, that is, after jumping to a normal state, the logic controller resumes normal operation. For example, if n represents the number of states of the state machine, the number of valid encodings using One-hot encoding is n, and the number of irrelevant state encodings is 2 n -n. The larger n is, the more irrelevant states there are, and thus the more logic resources are occupied by the definition of irrelevant states, resulting in excessive consumption of the resources of the logic controller.
[0043] In addition, in the prior art, the detection and recovery of the state machine in the logic controller need to rely on a memory to store the normal state encoding to determine whether the state machine is abnormal. By pre-storing all legal state encodings in the memory and reading the memory data in real time to compare with the current state, a jump to a preset normal state is triggered after an abnormality is found to achieve detection. However, if the memory is physically attacked and tampered with (such as laser injection, voltage glitch attack), and the stored normal state encoding is replaced with an illegal value, the abnormal detection mechanism will fail, and the recovery circuit will inject an incorrect encoding into the state machine, triggering a systematic failure.
[0044] In view of this, the embodiments of the present application provide a state restorer for a logic controller. The previous normal state encoding of the state machine is stored in real time through a data register circuit and fed back to the input end of the state machine. A comparison circuit is combined to perform exclusive detection on the previous state encoding and the current output state encoding to accurately identify whether the state encoding is abnormal, and it can well avoid the phenomenon that the storage area attack causes the inability to perform fault detection and fault recovery. When an abnormal encoding is detected, the predetermined normal initial encoding stored in the memory is forcibly input into the state machine through the recovery circuit, so that the state machine can be quickly reset from the irrelevant state caused by an attack or a fault to the initial safe state, effectively preventing the abnormal transfer of the state machine caused by external injection attacks or hardware failures, so as to improve the anti-interference ability and security protection level of the system.
[0045] Specifically, an embodiment of the present application provides a state restorer for a logic controller, including: a data storage circuit configured to store the nth state code of a state machine in the logic controller and input the nth state code into the state machine to trigger the state machine to switch from the nth state code to the (n + 1)th state code, where n is a positive integer greater than or equal to 1; a comparison circuit configured to compare the nth state code output by the data storage circuit and the (n + 1)th state code output by the state machine to obtain a control signal; a restoration circuit configured to, when the control signal indicates that the (n + 1)th state code is an abnormal code, control the state machine to switch from the (n + 1)th state code to a predetermined normal state code according to the control signal.
[0046] Figure 1 FIG. shows a schematic structural diagram of a state restorer according to a first embodiment of the present application.
[0047] As Figure 1 shown, the state restorer of the logic controller in this embodiment includes a data storage circuit 110, a comparison circuit 120, and a restoration circuit 130.
[0048] Among them, the input end of the data storage circuit 110 is connected to the second output end of the state machine 140; the output end of the data storage circuit 110 is respectively connected to the first input end of the comparison circuit 120 and the first input end of the state machine 140, the first output end of the state machine 140 is connected to the second input end of the comparison circuit 120, the output end of the comparison circuit 120 is connected to the input end of the restoration circuit 130, and the output end of the restoration circuit 130 is connected to the second input end of the state machine 140.
[0049] In this embodiment, the logic controller may include, but is not limited to, a field programmable gate array (FPGA), and the state machine 140 is a sequential logic circuit stored in the logic controller for implementing a specific function.
[0050] In this embodiment, the data storage circuit 110 is configured to store the nth state code of the state machine 140 in the logic controller, such as "00001", "00010", etc. And feedback the nth state code to the input end of the state machine 140 to trigger the state machine 140 to switch from the nth state code to the (n + 1)th state code.
[0051] The nth state code represents the current state code, and the (n + 1)th state code represents the next state code output by the state machine 140. When the (n + 1)th state code is normal, it is a legal code for sequential transfer, such as "01000", and when it is abnormal, it is an irrelevant state code, such as "10100".
[0052] In this embodiment, the comparison circuit 120 is configured to perform an exclusive detection on each bit of the nth state code and the (n + 1)th state code to obtain a control signal.
[0053] The control signal may represent a fault signal generated by the comparison circuit 120. In a specific embodiment, the fault signal error_sig being "1" may indicate that the n+1th state code is an abnormal code, and the fault signal error_sig being "0" may indicate that the n+1th state code is a normal code.
[0054] In this embodiment, the recovery circuit 130 is configured to control the state machine 140 to switch from the (n+1)th state code to a predetermined normal state code according to the control signal when the control signal indicates that the (n+1)th state code is an abnormal code.
[0055] In this embodiment, the exception code can represent the number of "1" in the status code. Such abnormal codes as "00000" for cnt=0 or "10100" for cnt=2 are usually caused by external attacks or hardware failures.
[0056] The predetermined normal state code may represent a system-defined initial state code, such as “00001” of a one-hot code, which is stored in the memory for the state machine 140 to restore the initial state.
[0057] In a specific embodiment, when the control signal is “1”, the predetermined normal code in the memory is input into the state machine 140 , causing the state machine 140 to switch from the abnormal (n+1)th state to the initial normal state.
[0058] Based on this, the embodiment of the present application uses a data register circuit to store the previous normal state code of the state machine in real time and feed it back to the state machine input terminal. In combination with a comparison circuit, the previous state code and the current output state code are mutually exclusive detected to accurately identify whether the state code is abnormal. This can effectively avoid the phenomenon that attacks on the storage area lead to the inability to detect and recover from faults. When an abnormal code is detected, the predetermined normal initial code stored in the memory is forcibly input into the state machine through the recovery circuit, so that the state machine can be quickly reset from an irrelevant state caused by an attack or fault to an initial safe state, effectively preventing abnormal state machine transfer caused by external injection attacks or hardware faults within the logic controller, thereby improving the system's anti-interference ability and security protection level.
[0059] According to an embodiment of the present application, the comparison circuit includes: multiple comparison sub-circuits and an output sub-circuit connected to the multiple comparison sub-circuits; the comparison sub-circuit is configured to compare the code values located at the same bit position in the nth state code and the n+1th state code, and output a first comparison sub-signal; the output sub-circuit is configured to obtain a control signal based on the multiple first comparison sub-signals.
[0060] Figure 2The structural schematic diagram of the state restorer according to a specific embodiment of the present application is shown.
[0061] As Figure 2 shown, in the state restorer of this specific embodiment, the comparison circuit 120 includes a plurality of comparison sub - circuits 121 and an output sub - circuit 122.
[0062] Each comparison sub - circuit 121 includes a first input terminal, a second input terminal, and an output terminal. The first input terminal is connected to the output terminal of the data register circuit 110, the second input terminal is connected to the first output terminal of the state machine 140, the output terminal is connected to the input terminal of the output sub - circuit 122, and the output terminal of the output sub - circuit 122 is connected to the input terminal of the restoration circuit 130.
[0063] In this embodiment, the comparison sub - circuit 121 is configured to compare the code values at the same bit position in the n - th state code and the (n + 1) - th state code, and output a first comparison sub - signal. Among them, the code values at the same bit position can represent the binary values at the same position in the n - th state code and the (n + 1) - th state code.
[0064] In this embodiment, the first comparison sub - signal can represent the result signal output after the comparison sub - circuit 121 compares a single bit, and is used to indicate whether there is an abnormal transition at this bit. In a specific embodiment, a high level "1" of the first comparison sub - signal indicates that this bit is abnormal, and a low level "0" indicates normal.
[0065] In this embodiment, the number of comparison sub - circuits 121 is the same as the number of bits of the state code output by the state machine 140. For example, a 5 - bit code corresponds to 5 comparison sub - circuits 121, and each comparison sub - circuit 121 is responsible for detecting the state legality of one bit of the code.
[0066] The output sub - circuit 122 is configured to synthesize the comparison results of each bit to generate a control signal.
[0067] Based on this, in the embodiment of the present application, by dividing the comparison circuit into a plurality of comparison sub - circuits with the same number of bits as the state code, independently and real - time comparing each bit of the n - th state code and the (n + 1) - th state code, and synthesizing the comparison results of each bit through the output sub - circuit to generate a control signal, the per - bit illegal state transition monitoring of the state machine is realized, and the fault detection sensitivity and real - time response ability are improved.
[0068] Figure 3 The specific structural schematic diagram of the state restorer according to a specific embodiment of the present application is shown.
[0069] As Figure 3As shown, taking one state encoding as an example, the comparison circuit 120 includes one comparison sub-circuit 121 and an output sub-circuit 122, and the data register circuit 110 includes one data register sub-circuit 111. Among them, the data register sub-circuit 111 can be configured as a D flip-flop.
[0070] The comparison sub-circuit 121 includes a first AND gate AND_1, a second AND gate AND_2, a first NOT gate NOT_1, and a data selector SEL_1 electrically connected to the output terminals of the first AND gate AND_1 and the second AND gate AND_2. The output sub-circuit 122 includes a first OR gate OR_1, a pull-up resistor R_1, and a third AND gate AND_11.
[0071] The first input terminal of the first AND gate AND_1 is connected to the output terminal of the state machine 140, and the second input terminal is connected to the output terminal of the data register sub-circuit 111.
[0072] The first input terminal of the second AND gate AND_2 is connected to the output terminal of the first NOT gate NOT_1, and the second input terminal is connected to the output terminal of the state machine 140.
[0073] The input terminal of the first NOT gate NOT_1 is connected to the output terminal of the data register sub-circuit 111.
[0074] The two enable terminals e1 and e2 of the data selector SEL_1 are respectively connected to the output terminals of the first AND gate AND_1 and the second AND gate AND_2. The two data terminals d1 and d2 of the data selector SEL_1 are respectively connected to the low level '0' and the high level '1'.
[0075] The input terminal of the first OR gate OR_1 is connected to the output terminal of the data selector SEL_1, and the output terminal of the first OR gate OR_1 is connected to the first input terminal of the third AND gate AND_11.
[0076] One end of the pull-up resistor R_1 is connected to the output terminal of the first OR gate OR_1, and the other end is connected to the power output terminal. The pull-up resistor R_1 is configured to use the voltage signal V_in of the power output terminal to pull up the electrical signal representing the first abnormal state output by the first OR gate OR_1 to a high level.
[0077] The second input terminal of the third AND gate AND_11 is connected to the power supply that outputs the high level signal "1", and the output terminal outputs a control signal.
[0078] In this specific embodiment, the n-th state code Q[1] is the output from the data register sub-circuit 111, that is, the value of the first bit storing the previous state. The (n + 1)-th state code Code[1] is the output from the state machine 140, that is, the value of the first bit of the current state. The n-th state code Q[1] and the (n + 1)-th state code Code[1] are input to the first AND gate AND_1. When the (n + 1)-th state code Code[1] = 1 and the n-th state code Q[1] = 1, the first AND gate AND_1 outputs '1', indicating that this bit normally maintains a high level. Conversely, in other cases, the first AND gate AND_1 outputs '0'.
[0079] The first NOT gate NOT_1 takes the inverse of Q[1] to generate NOT(Q[1]). NOT(Q[1]) and the (n + 1)-th state code Code[1] are input to the second AND gate AND_2. When the (n + 1)-th state code Code[1] = 1 and the n-th state code Q[1] = 0, the second AND gate AND_2 outputs '1', indicating that this bit illegally jumps to a high level. Conversely, in other cases, the second AND gate AND_2 outputs '0'.
[0080] For the data selector SEL_1, when the output of the first AND gate AND_1 is 1, the first enable terminal e1 = 1, the first data terminal d1 is selected, and the output is '0', indicating a normal state. When the output of the second AND gate AND_2 is 1, the second enable terminal e2 = 1, the second data terminal d2 is selected, and the output '1' indicates an abnormal state. When the outputs of both the first AND gate AND_1 and the second AND gate AND_2 are 0, the data selector SEL_1 has no output.
[0081] When the data selector SEL_1 outputs '1', the first OR gate OR_1 outputs '1', indicating the existence of an abnormal bit. When the data selector SEL_1 outputs '0', the first OR gate OR_1 outputs '0', indicating that this bit is normal. When the data selector SEL_1 has no output, the pull-up resistor R_1 pulls up the output of the first OR gate OR_1 to a high level '1' to ensure that when the state code jumps from 1 to 0, an abnormal signal can still be triggered.
[0082] Since the second input terminal of the third AND gate AND_11 is a fixed high level '1', when the output of the first OR gate OR_1 is '1', the output of the third AND gate AND_11 is '1', that is, the fault signal error_sig = 1, indicating the existence of an abnormality. When the output of the first OR gate OR_1 is '0', the output of the third AND gate AND_11 is '0', indicating no abnormality.
[0083] According to an embodiment of the present application, the data storage circuit includes a plurality of data storage sub - circuits. For the data storage sub - circuit corresponding to the i - th bit, the input end of the data storage sub - circuit is electrically connected to the output end of the state machine to obtain the code value of the i - th bit; the output end of the data storage sub - circuit is electrically connected to the input end of the state machine and the comparison sub - circuit corresponding to the i - th bit.
[0084] In this specific embodiment, the data storage circuit includes a plurality of data storage sub - circuits, and the number is the same as the number of bits of the state encoding of the state machine. For example, a 5 - bit state encoding corresponds to 5 data storage sub - circuits.
[0085] For the data storage sub - circuit corresponding to the i - th bit, the input end of the data storage sub - circuit is electrically connected to the output end of the state machine to obtain the code value of the i - th bit of the current state encoding in real time. The output end of the data storage sub - circuit is electrically connected to the input end of the state machine and the first input end of the comparison sub - circuit corresponding to the i - th bit to provide the code value of the i - th bit of the n - th state encoding to the comparison sub - circuit.
[0086] In this specific embodiment, the data storage sub - circuit is triggered at the rising edge of the system clock, stores the n - th state encoding Code[i] into the register, and outputs the n - th state encoding Q[i]=Code[i]. The stored n - th state encoding Q[i] is fed back to the input end of the state machine as the basis for generating the (n + 1) - th state encoding.
[0087] Based on this, the embodiment of the present application configures the data storage circuit as a plurality of data storage sub - circuits that are the same as the number of bits of the state encoding. Each sub - circuit independently stores the state code of one bit, realizing precise bit - by - bit storage and feedback control of the state of the state machine. This bit - by - bit storage mechanism enables each bit value of the n - th state encoding to be fed back to the input end of the state machine in real time to trigger subsequent state transitions, and at the same time provides an accurate bit - by - bit comparison benchmark for the comparison circuit, ensuring that when the state machine outputs the (n + 1) - th state encoding, abnormal jumps can be quickly identified through bit - by - bit comparison.
[0088] Figure 4 The specific structural schematic diagram of the state restorer according to another specific embodiment of the present application is shown.
[0089] As Figure 4As shown, taking a 5-state encoding as an example, the comparison circuit includes 5 comparison sub-circuits and an output sub-circuit. Among them, each comparison sub-circuit includes first AND gates such as AND_1, AND_3, AND_5, AND_7, AND_9, and also includes second AND gates such as AND_2, AND_4, AND_6, AND_8, AND_10. It also includes first NOT gates such as NOT_1~NOT_5, and also includes data selectors such as SEL_1~SEL_5 that are electrically connected to the output terminals of the first AND gates and the second AND gates.
[0090] As Figure 4 shown, the output sub-circuit includes a first OR gate OR_1, a pull-up resistor R_1, and a third AND gate AND_11.
[0091] As Figure 4 shown, the data register circuit includes 5 data register sub-circuits, and each data register sub-circuit 111 can be configured as a D flip-flop, such as DR_FF_1~DR_FF_5.
[0092] In this specific embodiment, the state machine is used to perform state transitions to output the state encoding value Code[4..0]. Its 5 legal states using One-hot encoding are respectively "00001", "00010", "00100", "01000", "10000", and the remaining states are don't care states. Each bit of the state encoding value is output to the corresponding first AND gate and second AND gate.
[0093] Specifically, Code[4] is output to the first AND gate AND_1 and the second AND gate AND_2; Code[3] is output to the first AND gate AND_3 and the second AND gate AND_4; Code[2] is output to the first AND gate AND_5 and the second AND gate AND_6; Code[1] is output to the first AND gate AND_7 and the second AND gate AND_8; Code[0] is output to the first AND gate AND_9 and the second AND gate AND_10. Also, each bit of the state encoding value such as Code[4]~Code[0] is also correspondingly output to the data input terminals of the 5 data register sub-circuits DR_FF_1~DR_FF_5.
[0094] For the data register sub-circuits DR_FF_1~DR_FF_5, taking the data register sub-circuit DR_FF_1 as an example for illustration. The data output terminal Q of the data register sub-circuit DR_FF_1 is connected to the input terminal of the first AND gate AND_1, and is connected to the input terminal of the second AND gate AND_2 through the first NOT gate NOT_1. The connection relationships of the data register sub-circuits DR_FF_2~DR_FF_5 are as Figure 4 shown and will not be elaborated further.
[0095] For data selectors SEL_1 to SEL_5, the data selector SEL_1 is taken as an example for illustration. The data selector SEL_1 is a 2-way data selector with an enable terminal. e1 and e2 represent the enable terminals, and d1 and d2 represent the data terminals. The enable terminals e1 and e2 are respectively connected to the output terminals of the first AND gate AND_1 and the second AND gate AND_2. The data terminals d1 and d2 are respectively connected to the low level '0' and the high level '1'. At most only 1 terminal of the enable terminals e1 and e2 is valid each time, and the other terminal is invalid, so that the data terminal corresponding to the valid enable terminal is output. When both enable terminals e1 and e2 are invalid, no output is performed. The functions of the data selectors SEL_2 to SEL_5 are the same as that of the data selector SEL_1, and the connection relationship will not be elaborated.
[0096] The input terminals of the first OR gate OR_1 are respectively connected to the output terminals of the data selectors SEL_1 to SEL_5. The output terminal of the first OR gate OR_1 is connected to the first input terminal of the third AND gate AND_11. The second input terminal of the third AND gate AND_11 is connected to the high level. The output terminal of the third AND gate AND_11 is connected to the fault signal error_sig.
[0097] In this specific embodiment, when the state machine starts to run, the current state encoding values of the state machine operation are stored by the data register sub-circuits DR_FF_1 to DR_FF_5 at this time.
[0098] When the state machine runs normally, for example, when it runs to state 3, the encoding value of this state is "00100", and the values temporarily stored and output by the data register sub-circuits DR_FF_1 to DR_FF_5 are still "00100". At this time, the first AND gate AND_5 outputs a high level, and the second AND gate AND_6 outputs a low level, so that the enable terminal e1 of the data selector SEL_3 is '1' and the enable terminal e2 is '0', so that the data selector SEL_3 outputs '0'. At this time, since the enable terminal e2 of the data selectors SEL_1, SEL_2, SEL_4, and SEL_5 is '0', the data selectors SEL_1, SEL_2, SEL_4, and SEL_5 have no data output; at this time, the '0' output by the data selector SEL_3 passes through the first OR gate OR_1 and the third AND gate AND_11 to output the fault signal error_sig = '0', indicating that the state machine has no fault.
[0099] When an exception occurs during the operation of the state machine, for example, when it enters an irrelevant state due to an exception in state 3. Assume that the state encoding value changes from the normal "00100" to the irrelevant state encoding value "10100", that is, the 4th bit Code[4] of the state encoding value jumps from '0' to '1'. At this time, the first input terminal of the first AND gate AND_1 and the second AND gate AND_2 is the current value '1', while the second input terminals of the first AND gate AND_1 and the second AND gate AND_2 have not yet synchronized the data due to the delay of the data register sub-circuit DR_FF_1. Therefore, the inputs are still the previous values, which are the normal value '0' of Code[4] and the value '1' after the normal value '0' of Code[4] passes through the first NOT gate NOT_1 respectively. At this time, the first AND gate AND_1 outputs a low level, and the second AND gate AND_2 outputs a high level, thus making the enable terminal e2 of the data selector SEL_1 '1'. At this time, the data selector SEL_1 outputs '1', and through the first OR gate OR_1 and the third AND gate AND_11, the fault signal error_sig = '1', indicating that a fault has occurred in the state machine.
[0100] When the state machine is in any irrelevant state, that is, the case where the number of bits '1' in the state encoding value Code[4..0], cnt > 1 or cnt = 0, can be detected; in addition, when cnt = 1 but the state encoding value is an unexpected value, it can also be detected. For example, when cnt = 0, that is, when the state jumps from the normal state to the state with the state encoding value of "00000", it can also be detected. For example, when the state encoding value changes from the normal "00100" to the irrelevant state encoding value "00000", at this time, the first AND gate AND_5 and the second AND gate AND_6 both output '0', and the enable terminal e2 of the data selector SEL_3 is '0', so that the data selector SEL_3 has no output. Similarly, the data selectors SEL_1, SEL_2, SEL_4, and SEL_5 also have no output, so that the first OR gate OR_1 has no output. However, since the first input terminal of the third AND gate AND_11 is at a high level, and the second input terminal of the third AND gate AND_11 is pulled up to a high level by a pull-up resistor, the state machine fault signal error_sig = '1'. Or, because the state change of the state machine has a predetermined order. For example, it changes from state 1 to state 2, from state 2 to state 3, from state 3 to state 4, from state 4 to state 5. The state encoding values of states 1 to 5 are "00001", "00010", "00100", "01000", and "10000" respectively. When the state machine has a jump of two states, such as jumping from the state encoding value "00100" of state 3 to the state encoding value "10000" of state 5, the data selector SEL_1 outputs "1", and the data selectors SEL_2 to SEL_5 output 0, so that the state machine fault signal error_sig = '1', that is, at this time cnt = 1 but the state encoding value is not the expected value, and the state machine fault can also be detected by this circuit.
[0101] According to an embodiment of the present application, the recovery circuit includes: a switch sub-circuit, the first end of the switch sub-circuit is electrically connected to a memory storing a predetermined normal state encoding, the second end of the switch sub-circuit is electrically connected to the input end of the state machine, and the enable end of the switch sub-circuit is electrically connected to the output end of the comparison circuit; the switch sub-circuit is configured to, when the control signal indicates that the (n + 1)th state encoding is an abnormal encoding, conduct the first end and the second end according to the control signal to transmit the predetermined normal state encoding to the state machine.
[0102] Figure 5 The structural schematic diagram of the recovery circuit according to a specific embodiment of the present application is shown.
[0103] As Figure 5As shown, the recovery circuit includes a switch sub-circuit 131. The first end of the switch sub-circuit 131 is electrically connected to the memory storing the predetermined normal state code. The second end of the switch sub-circuit 131 is electrically connected to the input end of the state machine 140. The enable end of the switch sub-circuit 131 is electrically connected to the output end of the comparison circuit.
[0104] In this embodiment, the enable end of the switch sub-circuit 131 is directly connected to the fault signal error_sig output by the comparison circuit.
[0105] In this embodiment, the memory storing the predetermined normal state code State_1[4..0], such as a register or read-only memory ROM inside the logic controller, can be used to store the One-hot initial code "00001" to ensure that the state machine can be restored to a known initial safe state during an exception. In addition, the memory storing the reserved normal state code can also be set outside the logic controller so that when the memory inside the logic controller is in an unsafe state, the normal state code value, such as the initial code "00001", can be obtained from outside the logic memory for recovery.
[0106] Figure 6 The specific structural schematic diagram of the recovery circuit according to a specific embodiment of the present application is shown.
[0107] As Figure 6 shown, in this specific embodiment, Figure 5 the switch sub-circuit 131 in can be configured as a tri-state buffer Tri. The enable end of the tri-state buffer Tri is directly connected to the fault signal error_sig, the input end is connected to the memory storing "00001", and the output end is connected to the input end of the state machine.
[0108] When it is detected that the fault signal error_sig = '1' connected to the enable end, it means that the tri-state buffer Tri is turned on, and the predetermined normal code in the memory, such as "00001", is transmitted to the state machine to overwrite the abnormal code. When it is detected that the fault signal error_sig = '0' connected to the enable end, the tri-state buffer Tri is in a high-impedance state, and the input end of the state machine is driven by the data register circuit without affecting the normal state transition.
[0109] Based on this, embodiments of the present application achieve a hardware-level fast response to state machine anomalies by directly responding to the control signal output by the comparison circuit at the enable end of the switch sub-circuit. When the control signal indicates that the (n + 1)-th state code is an abnormal code, the switch sub-circuit is immediately turned on and the pre-stored One-hot initial code in the memory is forcibly injected into the input end of the state machine, covering the abnormal code and resetting it to a known initial safe state; in the normal state, the switch sub-circuit is in a high-impedance state and does not interfere with the normal driving of the state machine by the data register circuit, ensuring both a nanosecond-level recovery speed during anomalies and avoiding interference with the normal operation of the state machine, achieving secure protection during the operation of the state machine with extremely low hardware overhead and effectively resisting state anomalies caused by external attacks or hardware failures.
[0110] According to an embodiment of the present application, the recovery circuit includes: a logic sub-circuit, two input ends of the logic sub-circuit are respectively electrically connected to the reset end of the state machine and the output end of the comparison circuit, and the output end of the logic sub-circuit is electrically connected to the enable end of the switch sub-circuit; a switch sub-circuit, a first end of the switch sub-circuit is electrically connected to a memory storing a predetermined normal state code, and a second end of the switch sub-circuit is electrically connected to the input end of the state machine; the switch sub-circuit is configured to turn on the first end and the second end when the control signal indicates that the (n + 1)-th state code is an abnormal code or the state machine is in a reset process, so as to transmit the predetermined normal state code to the state machine.
[0111] Figure 7 The structural schematic diagram of the recovery circuit according to another specific embodiment of the present application is shown.
[0112] As Figure 7 shown, in another specific embodiment, the recovery circuit includes a switch sub-circuit 131 and a logic sub-circuit 132.
[0113] Among them, the switch sub-circuit 131 includes a first end, a second end and an enable end, the first end is electrically connected to a memory storing a predetermined normal state code, and the second end is electrically connected to the input end of the state machine 140. The logic sub-circuit 132 includes a first input end, a second input end and an output end, the first input end is electrically connected to the output end of the comparison circuit, the second input end is connected to the reset end of the state machine 140, and the output end is electrically connected to the enable end of the switch sub-circuit 131.
[0114] In this specific embodiment, the enable end of the switch sub-circuit 131 receives two trigger signals through the logic sub-circuit 132, including: a fault signal error_sig = '1' output by the comparison circuit for abnormal code detection; a state machine reset signal for triggering during the reset process. When any one of the conditions is satisfied, the switch sub-circuit 131 is turned on to transmit the normal code to the state machine 140. Only when both conditions are not satisfied, the switch sub-circuit 131 is in a high impedance state and the state machine 140 is driven by the data register circuit.
[0115] Figure 8 Shows a specific structural schematic diagram of a recovery circuit according to another specific embodiment of the present application.
[0116] As Figure 8 shown, Figure 7 The switch sub - circuit 131 in can be configured as a tri - state buffer Tri, and the logic sub - circuit 132 can be configured as a third OR gate OR_3. Among them, the input end of the tri - state buffer Tri is connected to the memory storing "00001", the output end is connected to the input end of the state machine, and the enable end is connected to the output end of the third OR gate OR_3. The first input end of the third OR gate OR_3 is connected to the fault signal error_sig output by the comparison circuit, and the second input end of the third OR gate OR_3 is connected to the reset end of the state machine.
[0117] In this specific embodiment, when the fault signal error_sig = '1' output by the comparison circuit is detected, the third OR gate OR_3 outputs a high level, enabling the enable end en of the tri - state buffer Tri, so as to output the normal state encoding value, such as the encoding value "00001" of state 1, to the state machine, enabling the state machine to recover from the fault and restart running from state 1. In addition, when the logic controller is reset or the system is locked, that is, when the reset end R of the state machine is at a high level, the third OR gate OR_3 also outputs a high level to turn on the tri - state buffer Tri, and outputs the encoding value of state 1 to the state machine, ensuring that the state machine can be reset in the case of system reset or locked state.
[0118] Based on this, the embodiment of the present application realizes a dual - safety trigger mechanism for the state machine through the collaborative design of the logic sub - circuit and the switch sub - circuit. When the control signal output by the comparison circuit indicates that the state machine has an abnormal encoding or the state machine is in the reset process, the logic sub - circuit outputs a high level to enable the switch sub - circuit, and forcibly injects the pre - stored predetermined normal state encoding in the memory into the input end of the state machine, realizing a hardware - level fast reset. During normal operation, the switch sub - circuit is in a high - impedance state and does not interfere with the normal driving of the data storage circuit for the state machine, covering both the abnormal detection and recovery during the operation of the state machine and ensuring the initialization safety during system startup or locking, effectively resisting external attacks, hardware failures, and the risk of uninitialized states, and improving the reliability and security of the system during the full - cycle operation.
[0119] According to the embodiment of the present application, the state restorer further includes: a reset circuit, the first end of the reset circuit is used to receive a reset signal and a security control signal, the second end of the reset circuit is electrically connected to the reset end of the data storage circuit and the reset end of the state machine, and the reset circuit is configured to perform a reset operation on the data storage circuit and the state machine when the reset signal indicates that the state machine is in the reset process or the security control signal indicates that the logic controller is in the locked state.
[0120] In this embodiment, the reset circuit can be used to synchronously reset the data register circuit and the state machine during system reset or safety lock.
[0121] Figure 9 The structural schematic diagram of the state restorer according to the second embodiment of the present application is shown.
[0122] As Figure 9 shown, the state restorer further includes a reset circuit 150. The first end of the reset circuit 150 is used to receive a reset signal and a safety control signal, and the second end is electrically connected to the reset ends of the data register circuit 110 and the state machine 140 respectively.
[0123] The reset circuit 150 is configured to trigger a reset when any of the following conditions is satisfied: the state machine 140 is in a reset process, or the safety control signal indicates that the logic controller is in a locked state. Among them, the safety control signal is usually active high. This safety control signal can be generated by an external safety monitoring module or internal control logic and is triggered when the system detects a safety event, such as the continuous existence of an abnormal state code, an illegal access attempt, and detecting a hardware failure and needing to enter the protection mode, etc.
[0124] Figure 10 The specific structural schematic diagram of the state restorer according to the second embodiment of the present application is shown.
[0125] As Figure 10 shown, in this embodiment, the reset circuit 150 includes a second NOT gate NOT_21 and a second OR gate OR_2. One end of the second NOT gate NOT_21 is used to receive the reset signal RSTn, and the other end is electrically connected to the first input terminal of the second OR gate OR_2. The second input terminal of the second OR gate OR_2 is used to receive the safety control signal lock_sig, and the output terminal of the second OR gate OR_2 is electrically connected to the reset ends of a plurality of data register sub-circuits such as DR_FF_1~DR_FF_5 and the reset end of the state machine.
[0126] When the reset signal RSTn is '0', or the safety control signal lock_sig is '1', the second OR gate OR_2 outputs '1', and the reset ends R of a plurality of data register sub-circuits such as DR_FF_1~DR_FF_5 and the state machine are valid. At this time, the state machine cannot operate. When the reset process ends, when the reset signal RSTn is '1' and the safety control signal lock_sig is '0', the state machine runs normally.
[0127] Based on this, in the embodiments of the present application, when the logic controller is reset or the safety control signal is valid, the OR gate outputs a high level and synchronously activates the reset terminals of the data register circuit and the state machine, forcing them to enter the initial safety state, effectively blocking abnormal state transitions or resisting safety threats. When the reset process ends and the lock signal is invalid, the reset circuit outputs a low level, and the state machine can operate normally based on the feedback of the data register circuit, which not only ensures the reliability of the system startup initialization and runtime safety lock, but also avoids interfering with the normal workflow, providing a low-power and high-robustness state safety protection for the logic controller.
[0128] According to the embodiments of the present application, the safety control signal is obtained through at least one of the following methods: obtained after verifying the password circuit in the logic controller, obtained after detecting the output voltage of the logic controller.
[0129] In this embodiment, the safety control signal lock_sig can be generated through at least one of password circuit verification, voltage detection, etc.
[0130] In this embodiment, the password circuit verification can represent verifying the functional correctness of the password algorithm module in the logic controller. When the verification fails, the safety control signal lock_sig = "1" is generated, and when the verification is successful, the safety control signal lock_sig = "0" is generated.
[0131] For example, simultaneously detect the AES and SM4 symmetric encryption algorithms and the SHA256 and SM3 hashing algorithms. If the output of any algorithm is inconsistent with the standard value, generate the safety control signal lock_sig = '1' to lock the system.
[0132] In this embodiment, the voltage detection can represent monitoring the power supply voltage of the logic controller. When the voltage is abnormal, such as suffering from a voltage injection attack, the safety control signal lock_sig = "1" is generated, and when the voltage is normal, the safety control signal lock_sig = "0" is generated.
[0133] According to the embodiments of the present application, the state restorer further includes: a password verification circuit configured to, when the power-on of the logic controller is completed, perform parallel verification on multiple password circuits of the logic controller to obtain a safety control signal; wherein, when the verification of multiple password circuits passes, generate a safety control signal for controlling the logic controller to be in an unlocked state; when the verification of any one of the multiple password circuits fails, generate a safety control signal for controlling the logic controller to be in a locked state.
[0134] In this embodiment, the password verification circuit can be used to start the password circuit verification process when the logic controller is powered on and completed, that is, after the reset signal RSTn changes from valid to invalid. When the output results of all verified password circuits meet the expectations, such as when multiple password circuit verifications all pass, the password verification circuit generates a security control signal for controlling the logic controller to be in the unlocked state, such as lock_sig = '0'. At this time, the logic controller can operate various functions normally, and the data register circuit and the state machine can also work according to the normal process, and the system enters the safe and available state. As long as any one of the multiple password circuits fails the verification, it means that there may be a functional abnormality in the password circuit, such as being tampered with, suffering from an injection attack resulting in calculation errors, etc. At this time, the password verification circuit generates a security control signal for controlling the logic controller to be in the locked state, such as lock_sig = '1'. Once the lock signal takes effect, the reset circuit will work together to reset the data register circuit and the state machine, prevent the logic controller from performing abnormal or dangerous operations, prevent the spread of security threats, and ensure the security of the system.
[0135] Figure 11 FIG. shows a schematic structural diagram of a state restorer according to the third embodiment of the present application.
[0136] As Figure 11 shown, in this embodiment, the state restorer further includes a password verification circuit 160, wherein the output end of the password verification circuit 160 is connected to the second input end of the reset circuit 150 for providing a security control signal.
[0137] According to an embodiment of the present application, the password verification circuit includes: a plurality of security comparison sub-circuits, the first input ends of the plurality of security comparison sub-circuits are respectively electrically connected to the output ends of the plurality of password circuits, and the second input ends of the plurality of security comparison sub-circuits are electrically connected to the output end of the ciphertext processing circuit; the security comparison sub-circuit is configured to: compare the encrypted data output by the password circuit and the ciphertext data output by the ciphertext processing circuit to obtain a second comparison sub-signal; a parallel verification sub-circuit, the multiple input ends of the parallel verification sub-circuit are respectively connected to the output ends of the plurality of security comparison sub-circuits and the reset signal, and the output end of the parallel verification sub-circuit is used to output a security control signal; the parallel verification sub-circuit is configured to obtain a security control signal according to the second comparison sub-signals output by the plurality of security comparison sub-circuits.
[0138] Figure 12 FIG. shows a schematic structural diagram of a password verification circuit according to a specific embodiment of the present application.
[0139] As Figure 12 shown, in this specific embodiment, the password verification circuit includes a plurality of security comparison sub-circuits 161 and a parallel verification sub-circuit 162.
[0140] In this specific embodiment, the first input terminals of the multiple security comparison sub-circuits 161 are respectively electrically connected to the output terminals of the multiple cryptographic circuits 163, and the second input terminals are electrically connected to the output terminal of the ciphertext processing circuit 164.
[0141] The multiple input terminals of the parallel verification sub-circuit 162 are respectively electrically connected to the output terminals of the multiple security comparison sub-circuits 161 and the reset signal RSEn, and the output terminal is used to output the security control signal lock_sig.
[0142] In this specific embodiment, the security comparison sub-circuit 161 can be configured to compare the encrypted data output by the cryptographic circuit 163 with the ciphertext data output by the ciphertext processing circuit 164 one by one to obtain the second comparison sub-signal. The parallel verification sub-circuit 162 can be configured to generate a security control signal by combining the second comparison sub-signals output by the multiple security comparison sub-circuits 161.
[0143] In this specific embodiment, the cryptographic circuit 163 can be a hardware module that implements a cryptographic algorithm within a logic controller and is used to encrypt or hash input data. For example, it can include symmetric cryptographic algorithm modules such as the AES module and the SM4 module, as well as hash algorithm modules such as the SHA256 module and the SM3 module.
[0144] The input terminal of the cryptographic circuit 163 can receive test data, such as random numbers or fixed plaintext, and the output terminal is connected to the first input terminal of the security comparison sub-circuit 161 to output encrypted data.
[0145] The ciphertext processing circuit 164 can be used to provide the standard output value of the cryptographic algorithm as a benchmark for security comparison. Specific functions can include storing or generating standard ciphertext data.
[0146] Figure 13 The specific structural schematic diagram of the password verification circuit according to a specific embodiment of the present application is shown.
[0147] As Figure 13 shown, in this specific embodiment, the cryptographic circuit can include the AES symmetric cryptographic algorithm module, the SM4 symmetric cryptographic algorithm module, the SHA256 hash algorithm module, and the SM3 hash algorithm module. The security comparison sub-circuit can include comparators JMP_1 to JMP_4. The parallel verification sub-circuit can include the fifth AND gate AND_61 and the fourth NOT gate NOT_61. The ciphertext processing circuit includes the cipher table Cipher_Table stored in the read-only memory ROM.
[0148] Specifically, the first input terminal of the AES symmetric cipher algorithm module is connected to the reset signal RSTn of the logic controller, and the second input terminal is connected to the plaintext data AES_P_in of AES. The first input terminal of the SM4 symmetric cipher algorithm module is connected to the reset signal RSTn of the logic controller, and the second input terminal is connected to the plaintext data SM4_P_in of SM4. The first input terminal of the SHA256 hash algorithm module is connected to the reset signal RSTn of the logic controller, and the second input terminal is connected to the plaintext data SHA256_in of SHA256. The first input terminal of the SM3 hash algorithm module is connected to the reset signal RSTn of the logic controller, and the second input terminal is connected to the plaintext data SM3_in of SM3.
[0149] The AES symmetric cipher algorithm module and the SM4 symmetric cipher algorithm module can be used to encrypt / decrypt the input data D_in and output the ciphertext / plaintext of the data; the SHA256 hash algorithm module and the SM3 hash algorithm module can be used to perform a hash operation on the input data D_in and output the digest value of the message.
[0150] The first input terminal of the comparator JMP_1 is connected to the encrypted data AES_C’ output by the AES symmetric cipher algorithm module, and the second input terminal is connected to the ciphertext data AES_C stored in the cipher table Cipher_Table. The first input terminal of the comparator JMP_2 is connected to the encrypted data SM4_C’ output by the SM4 symmetric cipher algorithm module, and the second input terminal is connected to the ciphertext data SM4_C stored in the cipher table Cipher_Table. The first input terminal of the comparator JMP_3 is connected to the encrypted data SHA256_H’ output by the SHA256 hash algorithm module, and the second input terminal is connected to the digest value SHA256_H stored in the cipher table Cipher_Table. The first input terminal of the comparator JMP_4 is connected to the encrypted data SM3_H’ output by the SM3 hash algorithm module, and the second input terminal is connected to the digest value SM3_H stored in the cipher table Cipher_Table.
[0151] The comparators JMP_1 to JMP_4 can be used to compare the first input terminal and the second input terminal respectively. When the value of the first input terminal is equal to the value of the second input terminal, a high-level second comparison sub-signal is output; when the value of the first input terminal is not equal to the value of the second input terminal, a low-level second comparison sub-signal is output. The second comparison sub-signals output by the comparators JMP_1 to JMP_4 can be used as the detection results of the cipher algorithm.
[0152] The Cipher_Table can be configured in the read-only memory (ROM) area inside the logic controller to store the standard values calculated by the cryptographic algorithm module. For example, for the plaintext data AES_P_in of AES, the corresponding ciphertext data AES_C is stored; similarly, the ciphertext data SM4_C of the SM4 algorithm, and the correct digest values SHA256_H and SM3_H corresponding to the SHA256 and SM3 algorithms are stored.
[0153] Specifically, taking the comparator JMP_1 as an example, if the AES symmetric cryptographic algorithm module is not tampered with, the encrypted data AES_C' output by the AES symmetric cryptographic algorithm module is consistent with the ciphertext data AES_C stored in the Cipher_Table, and the output of the comparator JMP_1 is '1'; if the AES symmetric cryptographic algorithm module is attacked and the encrypted data AES_C' is inconsistent with the ciphertext data AES_C, then the output of the comparator JMP_1 is '0'.
[0154] The input terminals of the fifth AND gate AND_61 are respectively connected to the reset signal RSTn of the logic controller and the output terminals of the comparators JMP_1 to JMP_4. The output terminal of the fifth AND gate AND_61 is connected to the input terminal of the fourth NOT gate NOT_61, and the output terminal of the fourth NOT gate NOT_61 outputs the security control signal lock_sig.
[0155] Specifically, when the reset signal RSTn = '0' or any comparator JMP_i is '0', the security control signal lock_sig output by the fourth NOT gate NOT_61 is '1', indicating that the logic controller is in a locked state and triggers the reset circuit. When the reset signal RSTn = '1' and all comparators JMP_1 to JMP_4 are '1', the security control signal lock_sig output by the fourth NOT gate NOT_61 is '0', indicating that the logic controller is in an unlocked state.
[0156] In this specific embodiment, the above four cryptographic algorithms can be detected simultaneously when the logic controller is powered on, and the parallel processing method is used to shorten the startup time.
[0157] For example, when the logic controller is powered on and reset, the reset signal RSTn = '0', and the security control signal lock_sig = '1' is output after passing through the fifth AND gate AND_61 and the fourth NOT gate NOT_61. After the power-on reset of the logic controller is completed, the reset signal RSTn = '1', and the function test of the cryptographic algorithm module is performed. Taking the AES symmetric cryptographic algorithm module as an example for illustration, the detection methods of the SM4, SHA256, and SM3 cryptographic algorithm modules are similar to that of AES.
[0158] When the encrypted data AES_C’ = the ciphertext data AES_C, the comparator JMP_1 outputs a high level, that is, AES_result = ‘1’, indicating that the AES symmetric cipher algorithm module is operating normally. At this time, the output value of the fifth AND gate AND_61 depends on the detection results of the other 3 cipher algorithm modules. When the encrypted data AES_C’ ≠ the ciphertext data AES_C, it indicates that the AES symmetric cipher algorithm module is operating abnormally. The comparator JMP_1 outputs a low level to the fifth AND gate AND_61, and after passing through the fourth NOT gate NOT_61, the security control signal lock_sig = ‘1’.
[0159] Only after all the above 4 cipher algorithm modules pass the detection can the security control signal be invalidated, that is, lock_sig = ‘0’, so as to unlock the functional unit of the logic controller; when the above 1-4 cipher algorithm modules fail the detection, the security control signal remains in the valid state, that is, lock_sig = ‘1’, indicating that the corresponding cipher algorithm module is operating abnormally, and it may have encountered attacks such as injection and tampering of the operation object. In this case, the functional unit of the logic controller cannot be unlocked, thus protecting the logic controller.
[0160] Based on this, the embodiment of the present application realizes the parallel functional verification of the cipher circuit in the logic controller by configuring multiple security comparison sub-circuits and a parallel verification sub-circuit in the cipher verification circuit. It can synchronously detect the consistency between the outputs of cipher algorithm modules such as AES and SM4 and the standard values of the ciphertext processing circuit after the logic controller is powered on. When any algorithm verification fails, a locking signal is generated through the logical aggregation of the reset signal and the comparison result, blocking the operation of the abnormal circuit, effectively resisting attacks such as algorithm module tampering and voltage injection, and ensuring that the logic controller unlocks and operates in a state where the cipher function is complete and trustworthy.
[0161] According to the embodiment of the present application, the ciphertext processing circuit includes at least one of the following: a memory inside the logic controller, configured to store ciphertext data corresponding to the input data of multiple cipher circuits; a ciphertext processing circuit disposed outside the logic controller, and the ciphertext processing circuit is configured to use encryption algorithms corresponding to multiple cipher circuits to encrypt the input data of each of the multiple cipher circuits to obtain ciphertext data corresponding to the input data of the multiple cipher circuits.
[0162] In another specific embodiment, in order to prevent security risks during startup due to the leakage and tampering of the cipher table in the read-only memory ROM, when the logic controller starts up, the ciphertext processing circuit can also be configured outside the logic controller, and a standard cipher algorithm is run through an external device such as a host computer to dynamically generate ciphertext data.
[0163] Figure 14Shows a schematic structural diagram of a ciphertext processing circuit according to a specific embodiment of the present application.
[0164] In this specific embodiment, the cryptographic algorithm module of the logic controller can be detected by using data that passes the randomness test generated by a random number algorithm. Taking the detection of the AES symmetric cryptographic algorithm module as an example for illustration. As Figure 14 shown, the ciphertext processing circuit may include a random number generator, a random number detection module, and an AES software algorithm module.
[0165] The output end of the random number generator is connected to the input end of the random number detection module, and it can be an external independent hardware or software module to generate a random number sequence as the input data of the cryptographic algorithm.
[0166] The output end of the random number detection module is respectively connected to the input end of the password verification circuit and the input end of the AES software algorithm module, and it can be used to perform statistical tests on the random numbers to ensure their randomness and prevent predictable data from being attacked and utilized.
[0167] The output end of the AES software algorithm module outputs ciphertext data AES_C to the comparator JMP_1 in the password verification circuit, which can represent the standard AES algorithm running on the host computer and generate ciphertext data as a trusted module.
[0168] Specifically, when the logic controller is powered on and started, a group of random numbers is generated by a random number generator external to the logic controller. The random number detection module is used to detect the randomness of this group of random numbers. Only after passing the randomness detection can this random number be used as the plaintext data AES_P_in of the AES algorithm; when the randomness detection requirements are not met, this group of random numbers is discarded, and the random number generator generates the next group of random numbers until the randomness detection requirements are met. The AES software algorithm module is located on the host computer and is a trusted module on the user side. After encrypting the plaintext data AES_P_in, it outputs the correct ciphertext data AES_C and sends it to the second input end of the comparator JMP_1. At the same time, the plaintext data AES_P_in is sent to the AES symmetric cryptographic algorithm module in the logic controller, and after encryption, the encrypted data AES_C’ is transmitted to the first input end of the comparator JMP_1, so that the comparator JMP_1 performs subsequent comparison on the ciphertext data AES_C and the encrypted data AES_C’.
[0169] The random number detection module uses the method of discrete transformation to detect the randomness of the random sequence generated by the random number generator, specifically including: replacing 0 in the random sequence (such as 1011010…) with -1 to obtain a new sequence x k =(1, -1, 1, 1, -1, 1, -1…), where k = 1, 2, …, n represents the value of the kth bit in the new sequence, and the new sequence xk Perform a discrete transform according to the following formula (1):
[0170] (1);
[0171] Where L j represents the j-th component of the new sequence x k in the frequency domain. k represents the value of the k-th position in the new sequence x k . j represents the frequency domain index, ranging from 0 to n - 1. n represents the length of the random number of the new sequence. 2π(k - 1)j / n represents the phase factor, which controls the periods of the cosine and sine functions. i is the imaginary unit.
[0172] Calculate the modulus of L j using the following formulas (2) - (4):
[0173] (2);
[0174] (3);
[0175] (4);
[0176] Where m j is the modulus of L j , representing the energy intensity of the new sequence x k at frequency domain j. a represents the sum of real parts, and b represents the sum of imaginary parts.
[0177] Set a threshold value , and count the number count of m j (j = 0, 1,..., n - 1) that is less than the threshold value such as m j <T. Set the detection passing rate Base. When ≥Base, the detection passes, and it is considered that the group of random numbers meets the randomness requirements. Among them, the passing rate Base can be set in advance. For example, set Base = 90%. The larger the value, the higher the detection passing standard.
[0178] Based on this, the embodiments of the application realize the dynamicization and anti - attack of the password verification process by designing the ciphertext processing circuit as a dual - mode architecture of internal storage and external dynamic generation, and combining the verification data generated by the random number algorithm. The internal storage pre - stores standard ciphertext data to ensure the fast execution of the verification process. The external ciphertext processing dynamically generates ciphertext by running the standard algorithm on the host computer, and cooperates with the random number detection module to perform discrete transform inspection on the input data to eliminate the risk of physical attack on the internal password table, effectively resisting side - channel attacks and algorithm tampering. The two schemes can be flexibly switched according to the security level requirements, providing full - cycle security protection for the state restorer from startup to operation.
[0179] According to an embodiment of the present application, the state restorer further includes: a voltage detection circuit, a first end of the voltage detection circuit is electrically connected to a voltage output end of the logic controller, and a second end of the voltage detection circuit is electrically connected to a safety control signal of the reset circuit; the voltage detection circuit is configured to detect an output voltage of the logic controller and obtain a safety control signal.
[0180] In this embodiment, the voltage detection circuit can be used to monitor the output voltage of the logic controller, and generate a safety control signal by comparing it with a preset upper voltage limit value and a lower voltage limit value.
[0181] Figure 15 Fig. shows a schematic structural diagram of a state restorer according to a fourth embodiment of the present application.
[0182] As Figure 15 shown, the state restorer further includes a voltage detection circuit 170. A first end of the voltage detection circuit 170 is connected to a voltage output end of the logic controller to monitor the working voltage in real time. A second end of the voltage detection circuit 170 is connected to an input end of the reset circuit 150 to output a safety control signal lock_sig to the reset circuit 150, and control the locked or unlocked state of the logic controller.
[0183] According to an embodiment of the present application, the voltage detection circuit includes: a first voltage comparison sub-circuit, configured to compare the output voltage of the logic controller with an upper voltage limit value and a lower voltage limit value respectively to obtain a safety control signal; wherein, when the output voltage is between the upper voltage limit value and the lower voltage limit value, a safety control signal for controlling the logic controller to be in a locked state is obtained; when the output voltage is not between the upper voltage limit value and the lower voltage limit value, a safety control signal for controlling the logic controller to be in an unlocked state is obtained.
[0184] In this embodiment, the upper voltage limit value can represent the minimum value of the high level range of the normal working voltage, and the lower voltage limit value can represent the maximum value of the low level range of the normal working voltage. Among them, the upper voltage limit value and the lower voltage limit value can be adjusted based on a variable resistor in the first voltage comparison sub-circuit.
[0185] When it is detected that the output voltage exceeds the normal range, such as being between the upper voltage limit value and the lower voltage limit value, it is determined that the system may face security risks such as voltage injection attacks and power anomalies. At this time, a safety control signal lock_sig = '1' in the locked state is generated, triggering as Figure 15The reset circuit 150 shown performs a reset operation on the data register circuit 110 and the state machine 140, preventing problems such as timing errors and logic tampering in the logic controller caused by abnormal voltages. When the output voltage is within the normal range, a security control signal lock_sig = '0' in the unlocked state is generated to ensure that the logic controller operates in a safe voltage environment.
[0186] Figure 16 The specific structural schematic diagram of the voltage detection circuit according to a specific embodiment of the present application is shown.
[0187] As Figure 16 shown, in the voltage detection circuit in this specific embodiment, the first voltage comparison sub-circuit includes a first voltage operational amplifier LM_1, a second voltage operational amplifier LM_2, a first resistor R1, a second resistor R2, a third resistor R3, a fourth resistor R4, a first adjustable resistor R_var_1, a second adjustable resistor R_var_2, and a sixth AND gate AND_71.
[0188] The system voltage VCC supplies power to the first voltage operational amplifier LM_1 and the second voltage operational amplifier LM_2 respectively, and at the same time serves as the reference upper limit of the high voltage threshold.
[0189] The first end of the first adjustable resistor R_var_1 is connected to the system voltage VCC and the first end of the third resistor R3 respectively, the second end is grounded, and the adjustable end is connected to the '+' input terminal of the first voltage operational amplifier LM_1 to output the voltage upper limit value Vref_H.
[0190] The first end of the second adjustable resistor R_var_2 is connected to the second end of the third resistor R3, the other end is grounded, and the adjustable end is connected to the '-' input terminal of the second voltage operational amplifier LM_2 to output the voltage lower limit value Vref_L.
[0191] The voltage signal V_in of the test voltage comes from the voltage output terminal of the logic controller, and after being limited by the fourth resistor R4, it is respectively connected to the '-' input terminal of the first voltage operational amplifier LM_1 and the '+' input terminal of the second voltage operational amplifier LM_2. The output terminal of the first voltage operational amplifier LM_1 is connected to the input terminal of the first resistor R1, and the output terminal of the first resistor R1 is connected to the first input terminal of the sixth AND gate AND_71.
[0192] The output terminal of the second voltage operational amplifier LM_2 is connected to the input terminal of the second resistor R2, and the output terminal of the second resistor R2 is connected to the second input terminal of the sixth AND gate AND_71. The output terminal of the sixth AND gate AND_71 outputs the security control signal lock_sig.
[0193] The first voltage operational amplifier LM_1 and the second voltage operational amplifier LM_2 are respectively used to compare two input voltages. When the voltage value input at the ‘+’ input terminal is greater than or equal to the voltage value input at the ‘-’ input terminal, the voltage operational amplifier outputs a high level ‘1’; when the voltage value input at the ‘+’ input terminal is less than the voltage value input at the ‘-’ input terminal, the voltage operational amplifier outputs a low level ‘0’.
[0194] The first adjustable resistor R_var_1 and the second adjustable resistor R_var_2 can both be configured as resistors with variable resistance values. The high-level range of the first adjustable resistor R_var_1 is Vref_H~VCC. The low-level range of the second voltage operational amplifier LM_2 is 0~Vref_L.
[0195] The first resistor R1, the second resistor R2, the third resistor R3, and the fourth resistor R4 can be used for current limiting. In a specific embodiment, R1 = R2 = 300Ω, R3 = R4 = 10KΩ. The specific resistance values can be other values, which do not affect the function of the circuit, and are not specifically limited in this application.
[0196] In this specific embodiment, the user can set the upper voltage limit value and the lower voltage limit value by adjusting the first adjustable resistor R_var_1 and the second adjustable resistor R_var_2 respectively. For example, set the upper voltage limit value Vref_H = 4.6V and the lower voltage limit value Vref_L = 1.2V.
[0197] If the system voltage VCC = 5.0V, then the normal voltage range of the system is a high level of 4.6~5.0V and a low level of 0~1.2V. Then the voltage range between 1.2~4.6V is determined as an abnormal metastable voltage.
[0198] When the voltage signal V_in of the test voltage at the input terminal > 4.6V, the first voltage operational amplifier LM_1 outputs Vo1 = ‘0’, the second voltage operational amplifier LM_2 outputs Vo2 = ‘1’, and after passing through the sixth AND gate AND_71, a low level ‘0’ is output, that is, lock_sig = ‘0’.
[0199] When the voltage signal V_in of the test voltage at the input terminal ≤ 1.2V, the first voltage operational amplifier LM_1 outputs Vo1 = ‘1’, the second voltage operational amplifier LM_2 outputs Vo2 = ‘0’, and after passing through the sixth AND gate AND_71, a low level ‘0’ is output. At this time, lock_sig = ‘0’.
[0200] When 1.2V < V_in ≤ 4.6V, the first voltage operational amplifier LM_1 outputs Vo1 = '1', and the second voltage operational amplifier LM_2 outputs Vo2 = '1'. After passing through the sixth AND gate AND_71, a high level '1' is output, that is, lock_sig = '1', to lock the functional unit of the logic controller.
[0201] Based on this, the voltage detection circuit in the embodiment of the present application generates corresponding safety control signals to dynamically control the working state of the logic controller by monitoring the output voltage of the logic controller in real time and comparing it with the upper and lower voltage limit values set by the adjustable resistor: when the output voltage is within the normal range, an unlocking signal is output to ensure the stable operation of the system under a safe voltage; when the voltage is not within the normal range, a locking signal is output to trigger the reset circuit to reset the data storage circuit and the state machine, so as to effectively resist security risks such as voltage injection attacks and power anomalies, avoid timing errors or logic tampering of the logic controller, and improve the reliability and security of the system in a voltage fluctuation environment through adaptive threshold adjustment and real-time protection mechanisms.
[0202] According to an embodiment of the present application, the voltage detection circuit includes: a second voltage comparison sub-circuit configured to compare the output voltage of the logic controller with the upper voltage limit value and the lower voltage limit value respectively to obtain a voltage comparison signal; a first timing circuit configured to record the abnormal duration of the output voltage under the trigger of the voltage comparison signal when the voltage comparison signal indicates that the output voltage is between the upper voltage limit value and the lower voltage limit value; an alarm circuit configured to compare the abnormal duration with a first predetermined duration to obtain a safety control signal, wherein, when the abnormal duration exceeds the first predetermined duration, a safety control signal for controlling the logic controller to be in a locked state is obtained; when the abnormal duration does not exceed the first predetermined duration, a safety control signal for controlling the logic controller to be in an unlocked state is obtained.
[0203] In this embodiment, the second voltage comparison sub-circuit can be used to compare the output voltage with the upper voltage limit value or the lower voltage limit value to generate a voltage comparison signal. The first timing circuit can be used to record the abnormal duration when the voltage is in the abnormal range. The alarm circuit can be used to compare the abnormal duration with the predetermined duration to generate a safety control signal.
[0204] Figure 17 The specific structural schematic diagram of the voltage detection circuit according to another specific embodiment of the present application is shown.
[0205] As Figure 17As shown, in the voltage detection circuit of this specific embodiment, the second voltage comparison sub-circuit 172 includes a first voltage operational amplifier LM_1, a second voltage operational amplifier LM_2, a first resistor R1, a second resistor R2, a third resistor R3, a fourth resistor R4, a first adjustable resistor R_var_1, a second adjustable resistor R_var_2, and a sixth AND gate AND_71.
[0206] The circuit connection relationship among the first voltage operational amplifier LM_1, the second voltage operational amplifier LM_2, the first resistor R1, the second resistor R2, the third resistor R3, the fourth resistor R4, the first adjustable resistor R_var_1, and the second adjustable resistor R_var_2 in the second voltage comparison sub-circuit 172 can refer to Figure 16 , which will not be elaborated here.
[0207] In the voltage detection circuit of this specific embodiment, a first timing circuit 173 and an alarm circuit 174 are further included.
[0208] As Figure 17 shown, the first timing circuit 173 may include a timer CNT. The clock terminal clk of the timer CNT is connected to the system clock CLK pin of the logic controller for timing the duration of the high level at the input terminal. The input terminal is connected to the output terminal of the sixth AND gate AND_71, and the output terminal outputs an abnormal duration T_out.
[0209] As Figure 17 shown, the alarm circuit 174 may include a comparator CMP_6. The first input terminal of the comparator CMP_6 is connected to the output terminal of the timer CNT to access the abnormal duration T_out output by the timer CNT. The second input terminal accesses a preset duration set by the user, such as a time threshold Threshold, and the output terminal outputs a safety control signal lock_sig.
[0210] In this specific embodiment, the user can set the upper voltage limit value and the lower voltage limit value by adjusting the first adjustable resistor R_var_1 and the second adjustable resistor R_var_2 respectively. For example, the upper voltage limit value Vref_H = 4.6V and the lower voltage limit value Vref_L = 1.2V are set.
[0211] In addition, the user sets a time threshold, such as Threshold = 2 seconds. Then, when the duration of the metastable voltage ≥ 2 seconds, the lock signal lock_sig is triggered to be valid.
[0212] When the voltage signal V_in of the test voltage at the input end > 4.6V, the first voltage operational amplifier LM_1 outputs Vo1 = '0', the second voltage operational amplifier LM_2 outputs Vo2 = '1', and after passing through the sixth AND gate AND_71, a low level '0' is output. At this time, the timer CNT does not time the R end, and the output timing time T_out = 0. Since 0 < Threshold = 2 seconds, the comparator CMP_6 outputs a low level, that is, lock_sig = '0'.
[0213] When the voltage signal V_in of the test voltage at the input end ≤ 1.2V, the first voltage operational amplifier LM_1 outputs Vo1 = '1', the second voltage operational amplifier LM_2 outputs Vo2 = '0', and after passing through the sixth AND gate AND_71, a low level '0' is output. The timer CNT also outputs T_out = 0. At this time, lock_sig = '0'.
[0214] When 1.2V < V_in ≤ 4.6V, the first voltage operational amplifier LM_1 outputs Vo1 = '1', the second voltage operational amplifier LM_2 outputs Vo2 = '1', and after passing through the sixth AND gate AND_71, a high level '1' is output. At this time, the timer CNT times the R end, and the output timing time T_out. When T_out < 2 seconds, the comparator CMP_6 outputs a low level; when T_out ≥ 2 seconds, the comparator CMP_6 outputs a high level. At this time, the safety control signal lock_sig = '1' to lock the functional unit of the logic controller.
[0215] Based on this, in the embodiment of the present application, the intelligent monitoring and risk prevention and control of the output voltage of the logic controller can be realized through the voltage detection circuit. Specifically, the second voltage comparison sub-circuit can accurately identify the metastable voltage range based on the adjustable resistor to set the upper and lower voltage limits. When the detected voltage is in the abnormal range, the first timing circuit uses the system clock to accurately time the abnormal duration in milliseconds. Finally, the alarm circuit compares the timing result with the preset duration, and only generates a safety control signal when the abnormal duration exceeds the limit, thereby filtering out transient interferences such as power supply glitches and reducing the false alarm rate.
[0216] According to the embodiment of the present application, the alarm circuit may further include a light emitting diode and a buzzer.
[0217] Figure 18 Shows a specific structural schematic diagram of the voltage detection circuit according to another specific embodiment of the present application.
[0218] As Figure 18As shown in the figure, the alarm circuit 174 further includes a light-emitting diode LED, a buzzer BUZ, and a fifth resistor R5. Among them, the first end of the light-emitting diode LED is respectively connected to the security control signal lock_sig and the second end of the fifth resistor R5. The second end of the light-emitting diode LED is grounded. The first end of the fifth resistor R5 is connected to the system voltage VCC. The first end of the buzzer BUZ is connected to the security control signal lock_sig, and the second end of the buzzer BUZ is grounded.
[0219] In this specific embodiment, if the logic controller is in a normal state, the security control signal lock_sig = '0', and the voltage difference across the light-emitting diode LED is 0V and it does not emit light. The voltage difference across the buzzer BUZ is 0V and it does not sound. If it is in an abnormal state, the security control signal lock_sig = '1', driving the light-emitting diode LED to conduct forward, emitting light to indicate abnormal voltage, and making the buzzer BUZ sound, indicating that the output voltage of the logic controller is abnormal, indicating that a voltage injection attack may have occurred.
[0220] Based on this, in the embodiment of the present application, the alarm circuit realizes physical layer visual alarm of voltage abnormality through the hardware combination of a light-emitting diode, a buzzer, and a fifth resistor. In the normal state, the LED and the buzzer are silent because there is no voltage difference across them; when the abnormal voltage duration exceeds a predetermined threshold and triggers lock_sig = '1', the system voltage drives the light-emitting diode to conduct forward and emit light after being limited by the fifth resistor. At the same time, a voltage difference is formed across the buzzer and it sounds, visually feedbacking the abnormal output voltage of the logic controller by means of dual light and sound prompts, effectively indicating possible voltage injection attacks or power supply failures, providing a basis for rapid fault location for maintenance personnel, and the circuit design is simple and low-power, only working in the abnormal state, taking into account both security and power consumption control.
[0221] According to the embodiment of the present application, the status restorer further includes: an authority verification circuit, the first data input terminal, the second data input terminal, and the third data input terminal of the authority verification circuit are respectively used to receive the verification information of the internal memory of the logic controller, the identity information output by the upper computer, and the security control signal, and the output terminal of the authority verification circuit is electrically connected to the enable terminal of the switch circuit; a switch circuit, the first end of the switch circuit is electrically connected to the output end of the logic controller, and the second end of the switch circuit is electrically connected to a processor located outside the logic controller. The switch circuit is configured to control the first end and the second end of the switch circuit to conduct when the authority verification circuit outputs a verification signal indicating that the identity authentication is passed; among them, the authority verification circuit is configured to: output a verification signal indicating that the identity authentication is passed when the verification is passed and the security control signal indicates that the logic controller is in an unlocked state; and output a verification signal indicating that the identity authentication is not passed when the duration of the verification being passed is greater than a second predetermined duration.
[0222] In this embodiment, the permission verification circuit can be used to authenticate the user's identity, control the interface to conduct when the verification is passed, and control the interface to turn off when the verification fails.
[0223] Thus, it prevents the operation object from reading the key information stored inside the logic controller through the IO interface.
[0224] Figure 19 Fig. shows a schematic structural diagram of a state restorer according to the fifth embodiment of the present application.
[0225] As Figure 19 shown, the state restorer further includes a permission verification circuit 180 and a switch circuit 190.
[0226] In this embodiment, the first data input terminal of the permission verification circuit 180 accesses the verification information stored in the read-only memory ROM inside the logic controller, such as the authentication code Auth_code. The second data input terminal of the permission verification circuit 180 accesses the identity information output by the host computer, such as the authentication code Code_in. The output terminal of the permission verification circuit 180 is connected to the enable terminal of the switch circuit 190 to output a verification signal enable_sig. When the verification information accessed by the first data input terminal is the same as the identity information accessed by the second data input terminal, it indicates that the verification is passed.
[0227] The first end of the switch circuit 190 is electrically connected to the output terminal of the logic controller, such as the IO interface, for reading the internal data of the logic controller, such as the key, status information, etc. stored in the ROM. The second end of the switch circuit 190 is electrically connected to a processor located outside the logic controller, such as an MCU, a host computer, etc., to transmit the logic controller data DATA(0) to an external system.
[0228] The enable terminal of the switch circuit 190 is used to receive the verification signal enable_sig. If the verification signal is at a high level, it indicates that the identity authentication is passed, and the first end and the second end of the switch circuit 190 are conducted. If the verification signal is at a low level, it indicates that the identity authentication fails, and the first end and the second end of the switch circuit 190 are not conducted.
[0229] In this embodiment, the verification information stored in the read-only memory ROM inside the logic controller is used to verify the identity information output by the host computer, and when the verification is passed, a verification signal indicating that the identity authentication is passed is output; when the verification fails, a verification signal indicating that the identity authentication fails is output.
[0230] Based on this, embodiments of the present application construct a secure data interaction barrier between the logic controller and the external processor through the collaborative design of the permission verification circuit and the switch circuit. The permission verification circuit compares the authentication code stored in the memory of the logic controller with the identity information input by the host computer, and only outputs a high-level verification signal when the two are consistent. The switch circuit conducts the logic controller and the external IO interface under the trigger of this signal to achieve legal data interaction and improve the overall security of the system.
[0231] Figure 20 FIG. shows a schematic structural diagram of a state restorer according to a sixth embodiment of the present application.
[0232] As Figure 20 shown, in another embodiment, a security control signal lock_sig is connected to the control input terminal of the permission verification circuit 180, and the security control signal lock_sig can be connected by a voltage detection circuit or a password verification circuit.
[0233] In this embodiment, the identity information output by the host computer is verified by using the verification information stored in the memory inside the logic controller, and a verification signal indicating that the identity authentication is passed is output when the verification is passed and the security control signal indicates that the logic controller is in an unlocked state.
[0234] Based on this, embodiments of the present application compare the authentication code stored in the memory of the logic controller with the identity information input by the host computer, and only output a conduction signal when the verification is passed and the security control signal indicates that the logic controller is in an unlocked state. If the voltage is abnormal or the password verification fails, the interface cannot be conducted even if the identity information is correct, thus avoiding the risk caused by the failure of a single security module and effectively resisting unauthorized access and composite attacks.
[0235] Figure 21 FIG. shows a schematic structural diagram of a state restorer according to a seventh embodiment of the present application.
[0236] As Figure 21 shown, in yet another embodiment, a clock signal CLK and a second predetermined duration Time_in can also be connected to the input terminal of the permission verification circuit 180 to determine the duration of the passed verification.
[0237] In this embodiment, the identity information output by the host computer is verified by using the verification information in the memory of the logic controller, and a verification signal indicating that the identity authentication is passed is output when the verification is passed and the security control signal indicates that the logic controller is in an unlocked state. A verification signal indicating that the identity authentication fails is output when the duration of the passed verification is greater than the second predetermined duration.
[0238] Based on this, embodiments of the present application further enhance the security of the interaction between the logic controller and the outside by introducing a second predetermined duration. When the identity authentication is passed and the system is not locked, the permission verification circuit outputs an authentication passed signal to conduct data interaction; once the duration of the verified state exceeds the second predetermined duration, even if the identity and the system state are correct, it will immediately determine that the authentication fails and cut off the connection, effectively preventing users from illegally staying for a long time, stealing sensitive data or tampering with the system after the authentication is passed, and achieving refined control of access permissions through dynamic time-limit management, significantly enhancing the system's ability to resist persistent attacks.
[0239] According to an embodiment of the present application, the permission verification circuit includes: a comparator, the first input terminal of the comparator is electrically connected to the internal memory of the logic controller, the second input terminal of the comparator is electrically connected to the upper computer, and the output terminal of the comparator is electrically connected to the trigger terminal of the timer and the first input terminal of the fourth AND gate; a third NOT gate, the input terminal of the third NOT gate is used to receive a security control signal, and the output terminal of the third NOT gate is electrically connected to the second input terminal of the fourth AND gate; a fourth AND gate, the output terminal of the fourth AND gate is electrically connected to the first input terminal of the fifth AND gate; a timer, the output terminal of the timer is electrically connected to the second input terminal of the fifth AND gate; a fifth AND gate, the output terminal of the fifth AND gate is electrically connected to the enable terminal of the switch sub-circuit.
[0240] Figure 22 The specific structural schematic diagram of the permission verification circuit according to a specific embodiment of the present application is shown.
[0241] As Figure 22 shown, in the permission verification circuit 180 of this specific embodiment, it includes a comparator JMP_5, a third NOT gate NOT_3, a fourth AND gate AND_12, a timer Timer, and a fifth AND gate AND_13.
[0242] In this embodiment, the first input terminal (the '2' terminal of JMP_5) of the comparator JMP_5 accesses the verification information such as the authentication code Auth_code stored in the internal memory of the logic controller, and the second data input terminal (the '1' terminal of JMP_5) of the comparator JMP_5 accesses the identity information such as the authentication code Code_in output by the upper computer. The output terminal of the comparator JMP_5 is connected to the trigger terminal E of the timer Timer and the first input terminal of the fourth AND gate AND_12.
[0243] When the identity information Code_in output by the upper computer is consistent with the verification information Auth_code stored in the internal memory of the logic controller, the comparator JMP_5 outputs a high level '1'; when the identity information Code_in output by the upper computer is inconsistent with the verification information Auth_code stored in the internal memory of the logic controller, the comparator JMP_5 outputs a low level '0'.
[0244] In this embodiment, the input terminal of the third NOT gate NOT_3 receives the safety control signal lock_sig. The output terminal of the third NOT gate NOT_3 is connected to the second input terminal of the fourth AND gate AND_12.
[0245] The output terminal of the fourth AND gate AND_12 is connected to the first input terminal of the fifth AND gate AND_13.
[0246] The trigger terminal E of the timer Timer receives the output of the comparator JMP_5. The timing setting terminal T of the timer Timer is connected to the second preset duration Time_in. The output terminal Q of the timer Timer is connected to the second input terminal of the fifth AND gate AND_13.
[0247] The output terminal of the fifth AND gate AND_13 is connected to the enable terminal of the switch circuit 190 to output the verification signal enable_sig.
[0248] In this specific embodiment, if the safety control signal lock_sig = '1', it indicates that the logic controller is in the locked state. The third NOT gate NOT_3 outputs '0', the fourth AND gate AND_12 outputs '0', the fifth AND gate AND_13 outputs '0', and the verification signal enable_sig outputs '0', causing the switch circuit 190 to block.
[0249] If the safety control signal lock_sig = '0', it indicates that the logic controller is in the unlocked state. The third NOT gate NOT_3 outputs '1', and the output of the fourth AND gate AND_12 depends on the result of the comparator JMP_5.
[0250] When the comparator JMP_5 outputs '1' and the safety control signal lock_sig outputs '0', the timer Timer is triggered and starts timing based on the second preset duration Time_in. If the timing does not time out, the fifth AND gate AND_13 outputs '1', and the verification signal enable_sig outputs '1', causing the switch circuit 190 to conduct. If the timing times out, the fifth AND gate AND_13 outputs '0', and the verification signal enable_sig outputs '0', causing the switch circuit 190 to block.
[0251] Based on this, embodiments of the present application compare the identity information output by the host computer with the verification information stored in the memory inside the logic controller in real time through a comparator, and dynamically control the switch circuit in combination with the locked state of the logic controller and the time threshold. Only when the conditions of "matching identity information", "system not locked", and "not exceeding the preset time" are all met simultaneously, a high-level enable signal is output to conduct data interaction. If any condition is not met, the interface is immediately blocked, integrating identity authentication, system status, and aging management into the hardware circuit, which not only realizes access control of key data of the logic controller but also prevents session hijacking through a timed automatic disconnection mechanism, significantly enhancing the system's ability to resist physical attacks and prevent unauthorized access.
[0252] Figure 23 Fig. shows a schematic structural diagram of an authority verification circuit according to another specific embodiment of the present application.
[0253] As Figure 23 shown, in the authority verification circuit 180 of this specific embodiment, it includes a comparator JMP_5, a third NOT gate NOT_3, a fourth AND gate AND_12, a timer Timer, and a fifth AND gate AND_13. In the switch circuit 190 of this specific embodiment, it includes n groups of bidirectional tri-state buffers Bi_Tri.
[0254] Among them, each group of bidirectional tri-state buffers Bi_Tri is composed of 2 tri-state buffers. The 2 tri-state buffers are connected end to end, and the enable end en is connected as the enable end of the bidirectional tri-state buffer Bi_Tri. One end of each group of Bi_Tri is connected to the input / output port line IO(n) of the logic controller, and the other end is connected to the data line Data(n) of an external module such as the host computer. When the verification signal enable_sig accessed by the enable end is high-level valid, the bidirectional tri-state buffer Bi_Tri conducts, and data can move from the input / output port line IO(n) of the logic controller to the data line Data(n) of an external module such as the host computer, or move from the data line Data(n) of an external module such as the host computer to the input / output port line IO(n) of the logic controller; when the verification signal enable_sig accessed by the enable end is low-level invalid, the n groups of bidirectional tri-state buffers Bi_Tri are blocked, and data interaction cannot occur between IO(n) and Data(n).
[0255] In this specific embodiment, when the logic controller is in the locked state, the security control signal lock_sig is '1', which outputs '0' after passing through the third NOT gate NOT_3, and then outputs '0' after passing through the fourth AND gate AND_12 and the fifth AND gate AND_13, so that the verification signal enable_sig outputs '0', thereby making the enable end en of the n groups of bidirectional tri-state buffers Bi_Tri be '0', and thus blocking the n groups of bidirectional tri-state buffers Bi_Tri.
[0256] When the logic controller is in the unlocked state, the safety control signal lock_sig is '0', which outputs '1' after passing through the third NOT gate NOT_3. The value of the verification signal enable_sig depends on the user-entered identity information and the output of the timer Timer.
[0257] When the identity information Code_in output by the host computer is consistent with the verification information Auth_code stored in the memory inside the logic controller, the comparator JMP_5 outputs a high level. At this time, the fourth AND gate AND_12 outputs a high level. In addition, at this time, the E terminal of the timer Timer is '1'. After the user inputs the second preset duration Time_in, the timer starts to work. When the second preset duration has not elapsed, the timer Timer outputs a high level. Therefore, after passing through the fifth AND gate AND_13, the verification signal enable_sig becomes valid, making the enable terminal en = '1', controlling the conduction of n groups of bidirectional tri-state buffers Bi_Tri, and enabling the external module to read data from the ROM or write data to the ROM.
[0258] When the identity information Code_in output by the host computer is inconsistent with the verification information Auth_code stored in the memory inside the logic controller, it may be an illegal access by the operation object. The comparator JMP_5 outputs a low level. After passing through the fourth AND gate AND_12 and the fifth AND gate AND_13, the verification signal enable_sig becomes invalid, making the enable terminal en = '0'. At this time, n groups of bidirectional tri-state buffers Bi_Tri are blocked, and the external module cannot read or write the ROM area.
[0259] After the data access is completed, the blocking state is automatically set back according to the second preset duration. When the second preset duration has elapsed, the timer Timer outputs a low level, making the fifth AND gate AND_13 output a low level, and the verification signal enable_sig = '0', blocking n groups of bidirectional tri-state buffers Bi_Tri, thereby preventing illegal access and improving the security protection of data. Among them, the length of the second preset duration can be flexibly set by the user according to the different amounts of data read and written each time.
[0260] Based on this, in the embodiment of the present application, only when "identity information matches", "the system is not locked", and "the preset time is not exceeded", the data channel is conducted through the tri-state buffer, allowing the external module to read and write ROM data; when any condition is not met, the tri-state buffer immediately enters the high-impedance state to block the interaction. Cooperating with the timing automatic blocking mechanism, it effectively prevents unauthorized access, brute force cracking, and session hijacking. While ensuring legal data interaction, it improves the system's anti-attack ability through hardware-level physical isolation, realizing the full-cycle security protection of the key data of the logic controller.
[0261] Figure 24 The specific structural schematic diagram of the permission verification circuit according to another specific embodiment of the present application is shown.
[0262] As Figure 24 shown, in the permission verification circuit 180 of this specific embodiment, it includes a comparator JMP_5, a third NOT gate NOT_3, a fourth AND gate AND_12, a timer Timer, and a fifth AND gate AND_13.
[0263] Due to the signal transmission delay of the tri-state buffer, data transmission delay will be caused in the scenario of high-speed data transmission applications. In order to reduce the signal delay, in this specific embodiment, the switch circuit 190 can also be configured as n groups of line switching switches MUX_0~MUX_n-1.
[0264] One end of each group of line switching switches MUX is connected to the input / output port line IO(n) of the logic controller, and the other end is connected to the data line Data(n) of an external module such as a host computer. When the access verification signal enable_sig is high-level valid, the switching segments of the n groups of line switching switches MUX_0~MUX_n-1 are connected to the '1' end, that is, the data lines of the external module such as Data(0)~Data(n-1) ends, to reduce the data transmission delay. When the access verification signal enable_sig is low-level invalid, the switching segments of the n groups of line switching switches MUX_0~MUX_n-1 are connected to the '2' end, that is, the floating end, physically disconnecting the input / output port lines IO(0)~IO(n-1) ends of the logic controller and the data lines Data(0)~Data(n-1) ends of the external module.
[0265] Based on this, the embodiment of the present application realizes the dual goals of low delay and high security in the high-speed data transmission scenario by configuring the switch circuit as multiple groups of line switching switches. Utilizing the high-speed switching characteristics of the line switching switches, when the verification signal is high level, the switching segments of the line switching switches directly connect the input / output port lines of the logic controller and the data lines of the external module to eliminate the transmission delay of the tri-state buffer; while when the verification signal is low level, the switching segments of the line switching switches are connected to the floating end to achieve physical-level electrical isolation. Combining the triple-condition verification of the permission verification circuit, it not only solves the delay bottleneck in high-speed transmission, but also effectively resists physical layer threats such as voltage injection and side-channel attacks through the hardware-level real-time switching and timed automatic blocking mechanisms, providing a hardware isolation solution with both efficiency and security for high-speed data interaction.
[0266] Figure 25 The schematic diagram of the architecture when the logic controller runs according to the specific embodiment of the present application is shown.
[0267] As Figure 25As shown, when the logic controller is started and running, the overall architecture of its security protection may include a password verification module, a functional unit, a voltage monitoring module, an interface isolation unit, and an external module. Among them, the password verification module may be configured with a password verification circuit, the voltage monitoring module may be configured with a voltage detection circuit, the interface isolation unit may be configured with an authority verification circuit and a switch circuit, and the functional unit includes a status monitoring module and a status recovery module. The status monitoring module may be configured with a data storage circuit and a comparison circuit, and the status recovery module may be configured with a recovery circuit.
[0268] In this embodiment, the functional unit of the logic controller defaults to the locked state in the power-off and system reset states. When the logic controller is powered on and started, first, each password circuit in the password verification circuit is checked to ensure the correctness of the functions of each password circuit. When the function verification of each password circuit passes, an unlock signal, i.e., lock_sig = '0', is generated to unlock the functional unit of the logic controller, so that the system works normally. When the function verification of any password circuit fails, the unlock signal is invalid, and at this time, the functional unit cannot run and the system cannot work.
[0269] The status monitoring module can be used to monitor the operating status of the state machine. When the state machine encounters an external injection attack and becomes abnormal, that is, the state machine enters an irrelevant state during operation, a fault signal error_sig is generated afterwards. The status recovery module can be used to restore the state machine from the irrelevant state to the normal state after receiving the fault signal, thereby eliminating the fault and enabling the state machine to resume normal operation.
[0270] The interface isolation unit may be configured with a Figure 23 or Figure 24 as shown in the authority verification circuit. Among them, the authority verification circuit may include one or more groups of components with conduction / blocking functions, such as a bidirectional tri-state buffer Bi_Tri or a line switching switch MUX, and its conduction / blocking state is controlled by an enable signal enable_sig. Among them, it is in the blocking state when the logic controller is locked. In the unlocked state of the logic controller, when the enable signal is valid, the interface isolation unit conducts, and the external module (such as memory) can transmit data with the internal storage area of the logic controller, such as ROM, through the input / output port line IO of the logic controller, including the external module reading data from the ROM or writing data to the ROM. When the enable signal is invalid, the interface isolation unit blocks, and at this time, the data transmission path between the ROM and the external module is blocked and data transmission cannot be performed.
[0271] The permission verification module can be used to authenticate the identity of users. Only when a legitimate user inputs a correct instruction (such as a password), a valid enabling signal is generated, such as the verification signal enable_sig = '1'; when an incorrect instruction is input, the generated enabling signal is an invalid value, such as the verification signal enable_sig = '0', thereby preventing the operation object from reading the key information stored inside the logic controller through the input / output port lines IO of the logic controller.
[0272] The voltage monitoring module can be used to monitor the IO voltage range output by the logic controller. By setting thresholds, the high-level and low-level ranges are determined. When the monitored level is outside the threshold range and exceeds the set duration, it is determined that a metastable level has occurred, indicating that the system may have encountered a voltage injection attack. At this time, the safety control signal is made valid, such as lock_sig = '1', to lock the functional unit of the logic controller and prevent the voltage injection attack from damaging the system function, tampering with data, etc.
[0273] Figure 26 The schematic diagram of the architecture of the interface isolation unit according to a specific embodiment of the present application is shown.
[0274] As Figure 26 shown, in order to improve the integration of modules on the board and simplify the board-level structure, Figure 26 the interface isolation unit in
[0275] Figure 27 The schematic diagram of the function implementation of the state monitoring module and the state recovery module according to a specific embodiment of the present application is shown.
[0276] As Figure 27 shown, in this specific embodiment, the state machine consists of N states such as state 1, state 2,..., state n, and the state encoding adopts the One-hot method. Additionally, there are N trigger conditions 1~n; when the logic controller is reset, such as RSTn = '0', or the safety control signal is valid, lock_sig = '1', the state machine enters state 1; when the reset process ends, such as RSTn = '1', and the safety control signal is invalid, such as lock_sig = '0' and trigger condition 1 occurs, it enters state 2; thereafter, each time a trigger condition is generated, the state machine enters the next state until it returns to state 1 and then cycles through the state transition. If there is an abnormal trigger condition, such as injecting an abnormal signal, it may cause the state machine to enter an irrelevant state, resulting in a failure.
[0277] In this specific embodiment, the status monitoring module is used to obtain the current status encoding value Code[n..0] (n = 1, 2,..., N - 1) of the state machine, where the number of states is N. Then, it detects the number of bits '1' in Code[n..0], denoted as cnt. When cnt = 1 and the status encoding value is the expected value, it indicates that the state machine is operating normally. At this time, the fault signal error_sig = '0' is output, which is an invalid state, indicating no fault. When cnt = 0 or cnt > 1, it means that the status encoding value is the encoding value of an irrelevant state, or when cnt = 1 but the status encoding value is not the expected value, it indicates that the state machine is operating abnormally. At this time, the fault signal error_sig = '1' is output, which is a valid state, indicating a fault. Subsequently, when the status recovery module detects that the fault signal error_sig = '1', it replaces the current irrelevant state encoding value with the known state encoding value State_Code[n], enabling the state machine to resume operation from the fault.
[0278] According to an embodiment of the present application, in the case where the permission verification circuit outputs a verification signal indicating that the identity authentication is passed, the first end and the second end of the control switch circuit are turned on, so that the logic controller can send the port mapping matrix to a processor outside the logic controller through the switch circuit; wherein, the port mapping matrix indicates the mapping relationship between the bit positions of the data to be sent within the logic controller and the transmission ports.
[0279] In this embodiment, since data is usually sent through a group of consecutive port IO[n - 1..0], the problem is that the data is easily eavesdropped and intercepted. The operating object can obtain consecutive byte data through IO[n - 1..0], resulting in information leakage. Therefore, a random matrix is used to map the IO port numbers, and the byte data is transmitted to non - consecutive IO ports for sending in the form of bit positions, thereby increasing the difficulty for the operating object to intercept and analyze the data.
[0280] Figure 28 The schematic diagram of the architecture of the interface isolation unit adopting the IO port random mapping method for data transfer according to a specific embodiment of the present application is shown.
[0281] As Figure 28 shown, in this specific embodiment, a random matrix , (i, j = 0, 1,..., n - 1) can be established, and the port numbers p (p = 0, 1,..., n - 1) of the original consecutive ports IO(p) are randomly mapped to the elements r ij in the matrix R ij . To prevent the phenomenon of duplicate port numbers after mapping, the port numbers 0 to n - 1 need to be mapped to the upper triangular elements or lower triangular elements in the matrix R ij , that is , representing mapping to R ij for the upper triangular elements; or , representing mapping to the lower triangular elements of Rij.
[0282] According to the mapped elements in matrix R ij , calculate the new port numbers after mapping according to the following formula (5):
[0283] Y p =(i + 1)×(j + 1), (p = 0, 1, …, n - 1) (5);
[0284] In the formula, Y p represents the new port number, and p represents the port number of the original consecutive port IO(p).
[0285] When data Data is sent to an external module, each bit is sent from the corresponding IO port according to the mapped port number; when the external module writes data to the logic controller, the mapped port number is obtained through the random matrix, and data is transmitted through the corresponding IO port. Taking the transmission of 1-byte data (8 bits) as an example, the data to be sent is Data[7..0], and the original IO port numbers are 0 to 7, and the random matrix , (i, j = 0, 1, …, 7). Randomly map the port numbers 0 to 7 to the upper triangular elements in R ij , for example, the mapping relationship of specific elements is: r 56 = 0, r 14 = 1, r 25 = 2, r 37 = 3, r 45 = 4, r 06 = 5, r 67 = 6, r 77 = 7, and the remaining unmapped elements r ij = 0. According to formula (5), the new port numbers after mapping are: , Y1 = 10, Y2 = 18, Y3 = 32, Y4 = 30, Y5 = 7, Y6 = 56, Y7 = 64; then perform duplicate port detection, that is, if there are duplicate port numbers after mapping, the port numbers need to be re-allocated until the port numbers are not repeated. For example, if the original port number 0 is mapped to r 07 , and the port number 1 is mapped to r 13 and the port numbers calculated according to formula (5) are both 8, then the ports need to be remapped. For example, map the port number 1 to r 14, the mapped port number is 10, which does not duplicate with 8, until the mapped port numbers do not duplicate. After that, bit Data(0) in Data is sent through port IO(42), Data(1) is sent through IO(10), …, Data(7) is sent through IO(64).
[0286] Based on this, the embodiments of the present application establish a dynamic mapping relationship between the data bit positions in the logic controller and the discontinuous IO ports through a random matrix, effectively solving the problem that data is easily intercepted and monitored in traditional continuous port transmission. Specifically, the upper triangular or lower triangular matrix mapping strategy is used to ensure the uniqueness of the port numbers, and discrete new port numbers are generated through calculation, so that each bit of the byte data is scattered to discontinuous ports for transmission. When the data is transmitted through the discontinuous ports after random mapping in bit form, the operating object needs to monitor multiple irregular ports simultaneously to restore the data, significantly increasing the difficulty of interception and analysis. Combining the repeated port detection and dynamic update strategy further improves the anti-side channel attack ability and realizes the security enhancement of the data transmission layer of the logic controller.
[0287] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present application. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code, and the above-mentioned module, program segment, or part of code includes one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order from that marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram or flowchart, as well as the combinations of blocks in the block diagram or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.
[0288] Those skilled in the art can understand that the features described in the various embodiments of the present application can be combined and / or combined in various ways, even if such combinations or combinations are not explicitly described in the present application. In particular, without departing from the spirit and teachings of the present application, the features described in the various embodiments of the present application can be combined and / or combined in various ways. All such combinations and / or combinations fall within the scope of the present application.
[0289] The embodiments of the present application have been described above. However, these embodiments are for illustrative purposes only and are not intended to limit the scope of the present application. Although the embodiments have been described separately above, this does not mean that the measures in each embodiment cannot be used advantageously in combination. Without departing from the scope of the present application, those skilled in the art can make various substitutions and modifications, and all such substitutions and modifications should fall within the scope of the present application.
Claims
1. A state restorer for a logic controller, characterized in that, The state restorer includes: A data register circuit configured to register the nth state code of the state machine in the logic controller and input the nth state code into the state machine to trigger the state machine to switch from the nth state code to the (n + 1)th state code, where n is a positive integer greater than or equal to 1; A comparison circuit configured to compare the nth state code output by the data register circuit and the (n + 1)th state code output by the state machine to obtain a control signal; A restoration circuit configured to, when the control signal indicates that the (n + 1)th state code is an abnormal code, control the state machine to switch from the (n + 1)th state code to a predetermined normal state code according to the control signal.
2. The state restorer according to claim 1, characterized in that The comparison circuit includes: a plurality of comparison sub - circuits and an output sub - circuit connected to the plurality of comparison sub - circuits, and the number of the comparison sub - circuits is the same as the number of bits of the state code output by the state machine; The comparison sub - circuit is configured to compare the code values at the same bit position in the nth state code and the (n + 1)th state code and output a first comparison sub - signal; The output sub - circuit is configured to obtain the control signal according to the plurality of first comparison sub - signals.
3. The state restorer according to claim 2, wherein The data register circuit includes a plurality of data register sub - circuits, and the number of the data register sub - circuits is the same as the number of bits of the state code output by the state machine; For the data register sub - circuit corresponding to the ith bit position, the input end of the data register sub - circuit is electrically connected to the output end of the state machine to obtain the code value of the ith bit position, where i is a non - negative integer; The output end of the data register sub - circuit is electrically connected to the input end of the state machine and the comparison sub - circuit corresponding to the ith bit position.
4. The state restorer according to claim 2 or 3, characterized in that, The comparison sub - circuit includes: a first AND gate, a second AND gate, a first NOT gate, and a data selector electrically connected to the output ends of the first AND gate and the second AND gate; The first input end of the first AND gate is electrically connected to the output end of the state machine, and the second input end is electrically connected to the output end of the data register sub - circuit; The input end and the output end of the first NOT gate are respectively electrically connected to the output end of the data register sub - circuit and the first input end of the second AND gate; The second input end of the second AND gate is electrically connected to the output end of the state machine.
5. The state restorer according to claim 2, wherein The output sub - circuit includes: A first OR gate, a plurality of input ends of the first OR gate are respectively electrically connected to the plurality of comparison sub - circuits, and the output end of the first OR gate is electrically connected to the first input end of a third AND gate; A pull - up resistor, one end of which is electrically connected to the output end of the first OR gate and the other end is electrically connected to the power output end. The pull - up resistor is configured to pull up the electrical signal representing the first abnormal state output by the first OR gate by using the voltage signal of the power output end; A third AND gate, the second input end of the third AND gate is electrically connected to a power supply outputting a high - level signal, so as to obtain the control signal according to the electrical signal output by the first OR gate and the high - level signal.
6. The state restorer according to claim 1, characterized in that, The restoration circuit includes: A switching sub - circuit, a first end of the switching sub - circuit is electrically connected to a memory storing the predetermined normal state code, a second end of the switching sub - circuit is electrically connected to an input end of the state machine, and an enabling end of the switching sub - circuit is electrically connected to an output end of a comparison circuit; The switching sub - circuit is configured to, when the control signal indicates that the (n + 1)th state code is an abnormal code, conduct the first end and the second end according to the control signal to transmit the predetermined normal state code to the state machine.
7. The state restorer according to claim 1, characterized in that, The recovery circuit includes: A logic sub - circuit, two input ends of the logic sub - circuit are respectively electrically connected to a reset end of the state machine and an output end of the comparison circuit, and an output end of the logic sub - circuit is electrically connected to an enabling end of the switching sub - circuit; The switching sub - circuit, a first end of the switching sub - circuit is electrically connected to a memory storing the predetermined normal state code, and a second end of the switching sub - circuit is electrically connected to an input end of the state machine; The switching sub - circuit is configured to, when the control signal indicates that the (n + 1)th state code is an abnormal code or the state machine is in a reset process, conduct the first end and the second end to transmit the predetermined normal state code to the state machine.
8. The state restorer according to claim 1, characterized in that, The state restorer further includes: A reset circuit, a first end of the reset circuit is used to receive a reset signal and a safety control signal, a second end of the reset circuit is electrically connected to a reset end of the data register circuit and a reset end of the state machine, and the reset circuit is configured to perform a reset operation on the data register circuit and the state machine when the reset signal indicates that the state machine is in a reset process or the safety control signal indicates that the logic controller is in a locked state.
9. The state restorer according to claim 8, wherein The reset circuit includes: a second NOT gate and a second OR gate, One end of the second NOT gate is used to receive the reset signal, and the other end is electrically connected to a first input end of the second OR gate; A second input end of the second OR gate is used to receive the safety control signal, and an output end of the second OR gate is electrically connected to a reset end of the data register circuit and a reset end of the state machine.
10. The state restorer according to claim 8, characterized in that, The safety control signal is obtained by at least one of the following methods: obtained after verifying a password circuit in the logic controller, obtained after detecting an output voltage of the logic controller.
11. The state restorer according to claim 10, wherein, The state restorer further includes: A password verification circuit, configured to, when power - on of the logic controller is completed, perform parallel verification on a plurality of the password circuits of the logic controller to obtain the safety control signal; Wherein, when a plurality of the password circuits pass the verification, a safety control signal for controlling the logic controller to be in an unlocked state is generated; when any one of the plurality of password circuits fails the verification, a safety control signal for controlling the logic controller to be in a locked state is generated.
12. The state restorer according to claim 11, characterized in that, The password verification circuit includes: Multiple security comparison sub-circuits, with the first input terminals of the multiple security comparison sub-circuits respectively electrically connected to the output terminals of the multiple cryptographic circuits, and the second input terminals of the multiple security comparison sub-circuits electrically connected to the output terminal of the ciphertext processing circuit; the security comparison sub-circuit is configured to: compare the encrypted data output by the cryptographic circuit and the ciphertext data output by the ciphertext processing circuit to obtain a second comparison sub-signal; A parallel verification sub-circuit, with multiple input terminals of the parallel verification sub-circuit respectively electrically connected to the output terminals of the multiple security comparison sub-circuits and the reset signal, and the output terminal of the parallel verification sub-circuit is used to output the security control signal; the parallel verification sub-circuit is configured to obtain the security control signal according to the second comparison sub-signals output by the multiple security comparison sub-circuits.
13. The state restorer according to claim 12, characterized in that, The ciphertext processing circuit includes at least one of the following: The memory inside the logic controller, which is configured to: store the ciphertext data corresponding to the input data of the multiple cryptographic circuits; The ciphertext processing circuit arranged outside the logic controller, and the ciphertext processing circuit is configured to use the encryption algorithms corresponding to the multiple cryptographic circuits to encrypt the input data of the multiple cryptographic circuits respectively to obtain the ciphertext data corresponding to the input data of the multiple cryptographic circuits.
14. The state restorer according to claim 13, characterized in that, 15. The state restorer according to claim 10, wherein 16. The state restorer according to claim 15, characterized in that, 17. The state restorer according to claim 15, characterized in that, The alarm circuit is configured to compare the abnormal duration with a first predetermined duration to obtain the safety control signal, where, when the abnormal duration exceeds the first predetermined duration, a safety control signal for controlling the logic controller to be in a locked state is obtained; when the abnormal duration does not exceed the first predetermined duration, a safety control signal for controlling the logic controller to be in an unlocked state is obtained.
18. The state restorer according to claim 1, characterized in that The state restorer further includes: The permission verification circuit, the first data input terminal, the second data input terminal and the third data input terminal of the permission verification circuit are respectively used to receive the verification information in the memory of the logic controller, the identity information output by the host computer and the safety control signal, and the output terminal of the permission verification circuit is electrically connected to the enable terminal of the switch circuit; The switch circuit, the first end of the switch circuit is electrically connected to the output end of the logic controller, the second end of the switch circuit is electrically connected to a processor located outside the logic controller, and the switch circuit is configured to control the first end and the second end of the switch circuit to conduct when the permission verification circuit outputs a verification signal indicating that the identity authentication is passed; Wherein, the permission verification circuit is configured to: output a verification signal indicating that the identity authentication is passed when the verification is passed and the safety control signal indicates that the logic controller is in an unlocked state; and output a verification signal indicating that the identity authentication is not passed when the continuous duration of the verification passing is greater than a second predetermined duration.
19. The state restorer according to claim 18, wherein The permission verification circuit includes: A comparator, the first input terminal of the comparator is electrically connected to the memory of the logic controller, the second input terminal of the comparator is electrically connected to the host computer, and the output terminal of the comparator is electrically connected to the trigger terminal of the timer and the first input terminal of the fourth AND gate; A third NOT gate, the input terminal of the third NOT gate is used to receive the safety control signal, and the output terminal of the third NOT gate is electrically connected to the second input terminal of the fourth AND gate; The fourth AND gate, the output terminal of the fourth AND gate is electrically connected to the first input terminal of the fifth AND gate; The timer, the output terminal of the timer is electrically connected to the second input terminal of the fifth AND gate; The fifth AND gate, the output terminal of the fifth AND gate is electrically connected to the enable terminal of the switch circuit.
20. The state restorer according to claim 18, characterized in that, When the permission verification circuit outputs a verification signal indicating that the identity authentication is passed, control the first end and the second end of the switch circuit to conduct, so that the logic controller can send a port mapping matrix to a processor outside the logic controller through the switch circuit; Wherein, the port mapping matrix indicates the mapping relationship between the bit positions of the data to be sent in the logic controller and the transmission ports.
Citation Information
Patent Citations
Method for early alarming by-path attack in safety chip
CN101382978A
State machine circuit and state adjustment method
CN103346769A
Self-checking method of multimode redundancy dual-state machine supporting logic built-in self-testing
CN119002344A
Integrated circuit
JP2006300650A
Reconfigurable state machine
US20060062036A1