Logic controller state restorer

By introducing data registration and comparison circuits into the logic controller, real-time detection and forced recovery to the predetermined normal state encoding, the security problem of the logic controller state machine vulnerable to attack is solved, and fast and reliable security protection is achieved.

CN120406291BActive Publication Date: 2025-09-02INSPUR SUZHOU INTELLIGENT TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510874194.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-06-26
Publication Date
2025-09-02
Estimated Expiration
2045-06-26

AI Technical Summary

Technical Problem

In the state machine detection and recovery of logic controllers, the state machine detection and recovery of memory storage depends on the normal state encoding for abnormal detection, which is susceptible to physical attacks and tampering, causing the detection mechanism to fail, and cannot effectively resist hardware-level threats such as abnormal voltage injection and power-on attacks.

Method used

The data storage circuit registers the previous normal state encoding of the state machine in real time and feeds it back to the state machine input terminal, and combines the comparison circuit to perform mutually exclusive detection of the front and rear state encodings. The recovery circuit forces the predetermined normal encoding to input the state machine when an abnormality is detected, so as to achieve rapid reset to the initial safe state.

Benefits of technology

It effectively prevents abnormal transfer of state machine caused by external attacks or hardware failures, improves the anti-interference ability and security protection level of the logic controller, and ensures that the system quickly returns to the initial safe state in abnormal situations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120406291B_ABST
    Figure CN120406291B_ABST
Patent Text Reader

Abstract

The present application provides a state restorer for a logic controller, which can be applied to the field of hardware security protection technology. The state restorer for the logic controller includes: a data register circuit configured to register the nth state code of a state machine in the logic controller and input the nth state code into the state machine to trigger the state machine to switch from the nth state code to the n+1th state code; a comparison circuit configured to compare the nth state code output by the data register circuit with the n+1th state code output by the state machine to obtain a control signal; and a recovery circuit configured to control the state machine to switch from the n+1th state code to a predetermined normal state code according to the control signal when the control signal indicates that the n+1th state code is an abnormal code.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of hardware security protection technology, and more specifically to a state restorer for a logic controller. Background Art

[0002] With the evolution of hardware attack technology, logic controllers are often faced with core security risks such as abnormal voltage injection, power-on phase attacks, and input and output interface side channel attacks.

[0003] Existing technologies typically use one-hot encoding in state machine detection and recovery of logic controllers. However, when using one-hot encoding, anomaly detection relies on the normal state code stored in the internal memory of the logic controller. If the internal memory is tampered with by a physical attack, the legitimate state code will be replaced, rendering the anomaly detection mechanism ineffective and unable to defend against hardware-level threats such as abnormal voltage injection and power-on attacks. Summary of the Invention

[0004] In view of the above problems, the present application provides a state restorer of a logic controller that improves anti-interference capability and safety protection level.

[0005] According to one aspect of the present application, a state restorer of a logic controller is provided, and the state restorer includes: a data register circuit, configured to register the nth state code of a state machine in the logic controller, and input the nth state code into the state machine to trigger the state machine to switch from the nth state code to the n+1th state code, where n is a positive integer greater than or equal to 1; a comparison circuit, configured to compare the nth state code output by the data register circuit with the n+1th state code output by the state machine to obtain a control signal; and a recovery circuit, configured to control the state machine to switch from the n+1th state code to a predetermined normal state code according to the control signal when the control signal indicates that the n+1th state code is an abnormal code. BRIEF DESCRIPTION OF THE DRAWINGS

[0006] The above contents and other objects, features and advantages of the present application will become more apparent through the following description of the embodiments of the present application with reference to the accompanying drawings.

[0007] Figure 1 FIG2 shows a structural diagram of a state restorer according to the first embodiment of the present application.

[0008] Figure 2 A schematic structural diagram of a state restorer according to a specific embodiment of the present application is shown.

[0009] Figure 3 A schematic diagram of the specific structure of a state restorer according to a specific embodiment of the present application is shown.

[0010] Figure 4 A schematic diagram of the specific structure of a state restorer according to another specific embodiment of the present application is shown.

[0011] Figure 5 A structural schematic diagram of a recovery circuit according to a specific embodiment of the present application is shown.

[0012] Figure 6 A specific structural schematic diagram of a recovery circuit according to a specific embodiment of the present application is shown.

[0013] Figure 7 A structural schematic diagram of a recovery circuit according to another specific embodiment of the present application is shown.

[0014] Figure 8 A schematic diagram of the specific structure of a recovery circuit according to another specific embodiment of the present application is shown.

[0015] Figure 9 FIG2 shows a structural diagram of a state restorer according to the second embodiment of the present application.

[0016] Figure 10 A schematic diagram of the specific structure of a state restorer according to the second embodiment of the present application is shown.

[0017] Figure 11 FIG. 4 shows a structural diagram of a state restorer according to a third embodiment of the present application.

[0018] Figure 12 A structural diagram of a password verification circuit according to a specific embodiment of the present application is shown.

[0019] Figure 13 A specific structural schematic diagram of a password verification circuit according to a specific embodiment of the present application is shown.

[0020] Figure 14 A specific structural schematic diagram of a ciphertext processing circuit according to a specific embodiment of the present application is shown.

[0021] Figure 15 A schematic structural diagram of a state restorer according to a fourth embodiment of the present application is shown.

[0022] Figure 16 A specific structural schematic diagram of a voltage detection circuit according to a specific embodiment of the present application is shown.

[0023] Figure 17 A schematic diagram of the specific structure of a voltage detection circuit according to another specific embodiment of the present application is shown.

[0024] Figure 18 A schematic diagram of the specific structure of a voltage detection circuit according to another specific embodiment of the present application is shown.

[0025] Figure 19 A schematic structural diagram of a state restorer according to a fifth embodiment of the present application is shown.

[0026] Figure 20 A schematic structural diagram of a state restorer according to a sixth embodiment of the present application is shown.

[0027] Figure 21 A schematic structural diagram of a state restorer according to the seventh embodiment of the present application is shown.

[0028] Figure 22 The figure shows a schematic diagram of the specific structure of the permission verification circuit according to a specific embodiment of the present application.

[0029] Figure 23 A schematic diagram of the specific structure of the permission verification circuit according to another specific embodiment of the present application is shown.

[0030] Figure 24 A schematic diagram of the specific structure of the permission verification circuit according to another specific embodiment of the present application is shown.

[0031] Figure 25 A schematic diagram of the architecture of a logic controller during operation according to a specific embodiment of the present application is shown.

[0032] Figure 26 A schematic diagram of the architecture of an interface isolation unit according to a specific embodiment of the present application is shown.

[0033] Figure 27 A schematic diagram showing the functional implementation of the status monitoring module and the status recovery module according to a specific embodiment of the present application is shown.

[0034] Figure 28 A schematic diagram of the architecture of an interface isolation unit according to a specific embodiment of the present application using an IO port random mapping method for data transmission is shown. DETAILED DESCRIPTION

[0035] Hereinafter, embodiments of the present application will be described with reference to the accompanying drawings. However, it should be understood that these descriptions are exemplary only and are not intended to limit the scope of the present application. In the detailed description below, for ease of explanation, many specific details are set forth to provide a comprehensive understanding of the embodiments of the present application. However, it is apparent that one or more embodiments may also be implemented without these specific details. In addition, in the following description, descriptions of known structures and technologies are omitted to avoid unnecessarily confusing the concepts of the present application.

[0036] The terms used herein are only for describing specific embodiments and are not intended to limit this application. The terms "comprise," "include," etc. used herein indicate the presence of the features, steps, operations, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, or components.

[0037] All terms used herein (including technical and scientific terms) have the meanings commonly understood by those skilled in the art unless otherwise defined. It should be noted that the terms used herein should be interpreted as having a meaning consistent with the context of this specification and should not be interpreted in an idealized or overly rigid manner.

[0038] When expressions such as "at least one of A, B, and C, etc." are used, they should generally be interpreted in accordance with the meaning commonly understood by those skilled in the art (for example, "a system having at least one of A, B, and C" should include but is not limited to a system having A alone, B alone, C alone, A and B, A and C, B and C, and / or A, B, C, etc.).

[0039] In the field of digital circuit design, logic controllers are widely used in key areas such as information security. They implement state machine logic through hardware description language. The state machine serves as the core control unit of the logic controller, completing functions such as instruction processing and data transmission through state code jumps.

[0040] However, with the evolution of hardware attack techniques, logic controllers are often exposed to core security risks such as abnormal voltage injection, power-up phase attacks, and input / output (IO) interface side-channel attacks. Abnormal voltage injection refers to the attacker injecting abnormal voltage through means such as electromagnetic interference, causing the state machine jump logic to be disrupted. Power-up phase attacks involve the use of logic tampering or illegal instruction injection to cause the logic controller to enter an untrusted state during startup. IO interface side-channel attacks involve probing internal data through input / output ports, resulting in the leakage of sensitive information such as keys.

[0041] In the design of a logic controller's state machine, each state needs to be encoded, and the system's intended functionality is achieved through transitions between states. In existing technologies, one-hot encoding is often used in logic controller state machines because it reduces the variance in decoded data between adjacent states, speeds up transitions, and occupies fewer register bits.

[0042] However, the use of one-hot encoding will result in a large number of irrelevant states. When the logic controller enters an irrelevant state, it is necessary to process the state in order to make the state machine run normally. The existing technology usually defines all irrelevant states. After the logic controller enters an irrelevant state due to an abnormality, it performs a jump process, that is, jumps to a normal state to restore the logic controller to normal. For example, if n is used to represent the number of states of the state machine, the number of effective codes using one-hot encoding is n, and the number of irrelevant state codes is 2. n -n. When n is larger, the number of irrelevant states increases, and thus the definition of irrelevant states occupies more logic resources, resulting in excessive consumption of logic controller resources.

[0043] Furthermore, in existing technologies, state machine detection and recovery in logic controllers require memory to store normal state codes to determine whether the state machine is abnormal. This involves pre-storing all valid state codes in memory, reading the memory data in real time and comparing it with the current state. Upon detecting an anomaly, the system triggers a jump to the pre-set normal state to achieve detection. However, if the memory is tampered with through a physical attack (such as laser injection or voltage glitch), the stored normal state codes are replaced with illegal values, rendering the abnormality detection mechanism ineffective. The recovery circuit then injects erroneous codes into the state machine, causing systemic failures.

[0044] In view of this, an embodiment of the present application provides a state restorer for a logic controller. The data register circuit stores the previous normal state code of the state machine in real time and feeds it back to the input of the state machine. The comparison circuit is used to perform mutual exclusivity detection on the previous state code and the current output state code to accurately identify whether the state code is abnormal. This can effectively avoid the phenomenon that attacks on the storage area lead to the inability to detect and recover faults. When an abnormal code is detected, the predetermined normal initial code stored in the memory is forcibly input into the state machine through the recovery circuit, so that the state machine can be quickly reset from an irrelevant state caused by an attack or fault to an initial safe state, effectively preventing abnormal state machine transfer caused by external injection attacks or hardware faults, thereby improving the system's anti-interference ability and security protection level.

[0045] Specifically, an embodiment of the present application provides a state restorer of a logic controller, comprising: a data register circuit, configured to register the nth state code of a state machine in the logic controller, and input the nth state code into the state machine to trigger the state machine to switch from the nth state code to the n+1th state code, where n is a positive integer greater than or equal to 1; a comparison circuit, configured to compare the nth state code output by the data register circuit and the n+1th state code output by the state machine to obtain a control signal; and a recovery circuit, configured to control the state machine to switch from the n+1th state code to a predetermined normal state code according to the control signal when the control signal indicates that the n+1th state code is an abnormal code.

[0046] Figure 1 FIG2 shows a structural diagram of a state restorer according to the first embodiment of the present application.

[0047] like Figure 1 As shown, the state restorer of the logic controller of this embodiment includes a data register circuit 110 , a comparison circuit 120 , and a restore circuit 130 .

[0048] Among them, the input end of the data register circuit 110 is connected to the second output end of the state machine 140; the output end of the data register circuit 110 is respectively connected to the first input end of the comparison circuit 120 and the first input end of the state machine 140, the first output end of the state machine 140 is connected to the second input end of the comparison circuit 120, the output end of the comparison circuit 120 is connected to the input end of the recovery circuit 130, and the output end of the recovery circuit 130 is connected to the second input end of the state machine 140.

[0049] In this embodiment, the logic controller may include, but is not limited to, a field programmable gate array (FPGA), and the state machine 140 is a sequential logic circuit stored in the logic controller for implementing specific functions.

[0050] In this embodiment, the data register circuit 110 is configured to register the nth state code of the state machine 140 in the logic controller, such as "00001" or "00010", and feed the nth state code back to the input terminal of the state machine 140 to trigger the state machine 140 to switch from the nth state code to the (n+1)th state code.

[0051] The nth state code represents the current state code, and the n+1th state code represents the next state code output by the state machine 140. The n+1th state code is a legal code for sequential transition when normal, such as "01000", and an irrelevant state code when abnormal, such as "10100".

[0052] In this embodiment, the comparison circuit 120 is configured to perform mutual exclusivity detection on each bit of the nth state code and the (n+1)th state code to obtain a control signal.

[0053] The control signal may represent a fault signal generated by the comparison circuit 120. In a specific embodiment, the fault signal error_sig being "1" may indicate that the n+1th state code is an abnormal code, and the fault signal error_sig being "0" may indicate that the n+1th state code is a normal code.

[0054] In this embodiment, the recovery circuit 130 is configured to control the state machine 140 to switch from the (n+1)th state code to a predetermined normal state code according to the control signal when the control signal indicates that the (n+1)th state code is an abnormal code.

[0055] In this embodiment, the exception code can represent the number of "1" in the status code. Such abnormal codes as "00000" for cnt=0 or "10100" for cnt=2 are usually caused by external attacks or hardware failures.

[0056] The predetermined normal state code may represent a system-defined initial state code, such as “00001” of a one-hot code, which is stored in the memory for the state machine 140 to restore the initial state.

[0057] In a specific embodiment, when the control signal is “1”, the predetermined normal code in the memory is input into the state machine 140 , causing the state machine 140 to switch from the abnormal (n+1)th state to the initial normal state.

[0058] Based on this, the embodiment of the present application uses a data register circuit to store the previous normal state code of the state machine in real time and feed it back to the state machine input terminal. In combination with a comparison circuit, the previous state code and the current output state code are mutually exclusive detected to accurately identify whether the state code is abnormal. This can effectively avoid the phenomenon that attacks on the storage area lead to the inability to detect and recover from faults. When an abnormal code is detected, the predetermined normal initial code stored in the memory is forcibly input into the state machine through the recovery circuit, so that the state machine can be quickly reset from an irrelevant state caused by an attack or fault to an initial safe state, effectively preventing abnormal state machine transfer caused by external injection attacks or hardware faults within the logic controller, thereby improving the system's anti-interference ability and security protection level.

[0059] According to an embodiment of the present application, the comparison circuit includes: multiple comparison sub-circuits and an output sub-circuit connected to the multiple comparison sub-circuits; the comparison sub-circuit is configured to compare the code values ​​located at the same bit position in the nth state code and the n+1th state code, and output a first comparison sub-signal; the output sub-circuit is configured to obtain a control signal based on the multiple first comparison sub-signals.

[0060] Figure 2A schematic structural diagram of a state restorer according to a specific embodiment of the present application is shown.

[0061] like Figure 2 As shown, in the state restorer of this specific embodiment, the comparison circuit 120 includes a plurality of comparison sub-circuits 121 and an output sub-circuit 122 .

[0062] Each comparison sub-circuit 121 includes a first input terminal, a second input terminal and an output terminal, the first input terminal is connected to the output terminal of the data register circuit 110, the second input terminal is connected to the first output terminal of the state machine 140, the output terminal is connected to the input terminal of the output sub-circuit 122, and the output terminal of the output sub-circuit 122 is connected to the input terminal of the recovery circuit 130.

[0063] In this embodiment, the comparison sub-circuit 121 is configured to compare the code values ​​at the same bit position in the nth state code and the n+1th state code, and output a first comparison sub-signal. The code value at the same bit position may represent the binary value at the same position in the nth state code and the n+1th state code.

[0064] In this embodiment, the first comparison sub-signal may represent a result signal output by the comparison sub-circuit 121 after comparing a single bit, indicating whether the bit has an abnormal transition. In a specific embodiment, a high level "1" in the first comparison sub-signal indicates that the bit is abnormal, and a low level "0" indicates that the bit is normal.

[0065] In this embodiment, the number of comparison subcircuits 121 is the same as the number of bits of the state code output by the state machine 140. For example, a 5-bit code corresponds to 5 comparison subcircuits 121, and each comparison subcircuit 121 is responsible for detecting the state validity of a 1-bit code.

[0066] The output sub-circuit 122 is configured to combine the comparison results of each bit to generate a control signal.

[0067] Based on this, the embodiments of the present application divide the comparison circuit into multiple comparison sub-circuits with the same number of state code bits, perform independent real-time comparison on each bit of the nth state code and the n+1th state code, and generate a control signal by integrating the comparison results of each bit through the output sub-circuit to realize bit-by-bit illegal state jump monitoring of the state machine, thereby improving the fault detection sensitivity and real-time response capability.

[0068] Figure 3 A schematic diagram of the specific structure of a state restorer according to a specific embodiment of the present application is shown.

[0069] like Figure 3As shown, taking one state code as an example, the comparison circuit 120 includes one comparison sub-circuit 121 and an output sub-circuit 122, and the data register circuit 110 includes one data register sub-circuit 111. The data register sub-circuit 111 can be configured as a D flip-flop.

[0070] The comparison sub-circuit 121 includes a first AND gate AND_1, a second AND gate AND_2, a first NOT gate NOT_1, and a data strobe SEL_1 electrically connected to the output terminals of the first and second AND gates AND_1 and AND_2. The output sub-circuit 122 includes a first OR gate OR_1, a pull-up resistor R_1, and a third AND gate AND_11.

[0071] A first input terminal of the first AND gate AND_1 is connected to the output terminal of the state machine 140 , and a second input terminal of the first AND gate AND_1 is connected to the output terminal of the data register sub-circuit 111 .

[0072] A first input terminal of the second AND gate AND_2 is connected to the output terminal of the first NOT gate NOT_1 , and a second input terminal of the second AND gate AND_2 is connected to the output terminal of the state machine 140 .

[0073] An input terminal of the first NOT gate NOT_1 is connected to an output terminal of the data register sub-circuit 111 .

[0074] The two enable terminals e1 and e2 of the data strobe SEL_1 are connected to the output terminals of the first and second AND gates AND_1 and AND_2, respectively. The two data terminals d1 and d2 of the data strobe SEL_1 are connected to a low level '0' and a high level '1', respectively.

[0075] An input terminal of the first OR gate OR_1 is connected to an output terminal of the data strobe SEL_1 , and an output terminal of the first OR gate OR_1 is connected to a first input terminal of a third AND gate AND_11 .

[0076] One end of the pull-up resistor R_1 is connected to the output of the first OR gate OR_1, and the other end is connected to the power output terminal. The pull-up resistor R_1 is configured to use the voltage signal V_in at the power output terminal to pull up the electrical signal indicating the first abnormal state output by the first OR gate OR_1 to a high level.

[0077] A second input terminal of the third AND gate AND_11 is connected to a power source that outputs a high-level signal “1”, and an output terminal thereof outputs a control signal.

[0078] In this embodiment, the nth state code Q[1] is the output from the data register subcircuit 111, i.e., the first bit value of the previous state. The n+1th state code Code[1] is the output from the state machine 140, i.e., the first bit value of the current state. The nth state code Q[1] and the n+1th state code Code[1] are input to the first AND gate AND_1. When the n+1th state code Code[1] = 1 and the nth state code Q[1] = 1, the first AND gate AND_1 outputs '1', indicating that the bit is normally maintained at a high level. Conversely, in other cases, the first AND gate AND_1 outputs '0'.

[0079] The first NOT gate NOT_1 negates Q[1] to generate NOT(Q[1]). NOT(Q[1]) and the n+1th state code Code[1] are input to the second AND gate AND_2. When the n+1th state code Code[1] = 1 and the nth state code Q[1] = 0, the second AND gate AND_2 outputs '1', indicating that the bit has illegally transitioned to a high level. Conversely, in other cases, the second AND gate AND_2 outputs '0'.

[0080] For data strobe SEL_1, when the output of the first AND gate AND_1 is 1, the first enable terminal e1 is 1, strobing the first data terminal d1 and outputting '0', indicating a normal state. When the output of the second AND gate AND_2 is 1, the second enable terminal e2 is 1, strobing the second data terminal d2 and outputting '1', indicating an abnormal state. When the outputs of the first and second AND gates AND_1 and AND_2 are both 0, data strobe SEL_1 has no output.

[0081] When data selector SEL_1 outputs '1', the first OR gate OR_1 outputs '1', indicating an abnormal bit. When data selector SEL_1 outputs '0', the first OR gate OR_1 outputs '0', indicating a normal bit. When data selector SEL_1 has no output, pull-up resistor R_1 pulls the output of the first OR gate OR_1 high to '1', ensuring that the abnormal signal is still triggered when the status code changes from 1 to 0.

[0082] Because the second input of the third AND gate AND_11 is fixed at a high level of '1', when the output of the first OR gate OR_1 is '1', the output of the third AND gate AND_11 is also '1', i.e., the fault signal error_sig = 1, indicating an abnormality. When the output of the first OR gate OR_1 is '0', the output of the third AND gate AND_11 is also '0', indicating no abnormality.

[0083] According to an embodiment of the present application, the data registration circuit includes multiple data registration sub-circuits. For the data registration sub-circuit corresponding to the i-th bit, the input end of the data registration sub-circuit is electrically connected to the output end of the state machine to obtain the code value of the i-th bit; the output end of the data registration sub-circuit is electrically connected to the input end of the state machine and the comparison sub-circuit corresponding to the i-th bit.

[0084] In this specific embodiment, the data register circuit includes a plurality of data register sub-circuits, the number of which is consistent with the number of state code bits of the state machine. For example, a 5-bit state code corresponds to 5 data register sub-circuits.

[0085] For the data register subcircuit corresponding to the i-th bit, the input end of the data register subcircuit is electrically connected to the output end of the state machine to obtain the code value of the i-th bit of the current state code in real time. The output end of the data register subcircuit is electrically connected to the input end of the state machine and the first input end of the comparison subcircuit corresponding to the i-th bit to provide the code value of the i-th bit of the n-th state code to the comparison subcircuit.

[0086] In this specific embodiment, the data register subcircuit is triggered by the rising edge of the system clock, stores the nth state code Code[i] into a register, and outputs the nth state code Q[i] = Code[i]. The stored nth state code Q[i] is fed back to the input of the state machine as the basis for generating the n+1th state code.

[0087] Based on this, the embodiments of the present application achieve precise bit-by-bit storage and feedback control of the state machine state by configuring the data register circuit into multiple data register sub-circuits that are consistent with the number of state code bits, with each sub-circuit independently registering a single bit of the state code. This bit-by-bit registration mechanism enables each bit value of the nth state code to be fed back to the state machine input in real time to trigger subsequent state transitions, while also providing an accurate bit-by-bit comparison benchmark for the comparison circuit, ensuring that when the state machine outputs the n+1th state code, abnormal jumps can be quickly identified through bit-by-bit comparison.

[0088] Figure 4 A schematic diagram of the specific structure of a state restorer according to another specific embodiment of the present application is shown.

[0089] like Figure 4As shown, taking 5 state codes as an example, the comparison circuit includes 5 comparison sub-circuits and an output sub-circuit, wherein each comparison sub-circuit includes a first AND gate such as AND_1, AND_3, AND_5, AND_7, and AND_9, a second AND gate such as AND_2, AND_4, AND_6, AND_8, and AND_10, a first NOT gate such as NOT_1 to NOT_5, and a data selector such as SEL_1 to SEL_5 electrically connected to the output ends of the first and second AND gates.

[0090] like Figure 4 As shown, the output sub-circuit includes a first OR gate OR_1 , a pull-up resistor R_1 , and a third AND gate AND_11 .

[0091] like Figure 4 As shown, the data register circuit includes five data register sub-circuits, and each data register sub-circuit 111 can be configured as a D flip-flop, such as DR_FF_1 to DR_FF_5.

[0092] In this specific embodiment, the state machine is used to transition between states and output a state code value, Code[4..0]. The five valid states using one-hot encoding are "00001," "00010," "00100," "01000," and "10000." The remaining states are irrelevant. Each bit of the state code value is output to the corresponding first and second AND gates.

[0093] Specifically, Code[4] is output to the first AND gate AND_1 and the second AND gate AND_2; Code[3] is output to the first AND gate AND_3 and the second AND gate AND_4; Code[2] is output to the first AND gate AND_5 and the second AND gate AND_6; Code[1] is output to the first AND gate AND_7 and the second AND gate AND_8; and Code[0] is output to the first AND gate AND_9 and the second AND gate AND_10. Furthermore, each bit of the state code value, such as Code[4] through Code[0], is also output to the data input terminals of the five data register sub-circuits DR_FF_1 through DR_FF_5.

[0094] The data register sub-circuits DR_FF_1 to DR_FF_5 are described using the data register sub-circuit DR_FF_1 as an example. The data output terminal Q of the data register sub-circuit DR_FF_1 is connected to the input terminal of the first AND gate AND_1, and is connected to the input terminal of the second AND gate AND_2 through the first NOT gate NOT_1. The connection relationship of the data register sub-circuits DR_FF_2 to DR_FF_5 is as follows: Figure 4 As shown, no further details are given.

[0095] Data strobes SEL_1 through SEL_5 are described using data strobe SEL_1 as an example. Data strobe SEL_1 is a two-way data strobe with enable terminals. Enable terminals e1 and e2 represent the enable terminals, while data terminals d1 and d2 represent the data terminals. Enable terminals e1 and e2 are connected to the outputs of the first and second AND gates AND_1 and AND_2, respectively. Data terminals d1 and d2 are connected to a low-level '0' and a high-level '1', respectively. At most one of the enable terminals e1 and e2 is active at a time; the other is inactive. This causes the data terminal corresponding to the active enable terminal to be output. When both enable terminals e1 and e2 are inactive, no data is output. Data strobes SEL_2 through SEL_5 function similarly to data strobe SEL_1, and their connection relationships are not further described.

[0096] The input terminals of the first OR gate OR_1 are respectively connected to the output terminals of the data selectors SEL_1 to SEL_5. The output terminal of the first OR gate OR_1 is connected to the first input terminal of the third AND gate AND_11. The second input terminal of the third AND gate AND_11 is connected to a high level. The output terminal of the third AND gate AND_11 is connected to the fault signal error_sig.

[0097] In this specific embodiment, when the state machine starts running, the data register sub-circuits DR_FF_1 to DR_FF_5 store the current state code value of the state machine.

[0098] When the state machine is running normally, for example, running to state 3, the code value of this state is "00100". The value temporarily stored and output by the data register sub-circuit DR_FF_1~DR_FF_5 is still "00100". At this time, the first AND gate AND_5 outputs a high level, and the second AND gate AND_6 outputs a low level, so that the enable terminal e1 of the data strobe SEL_3 is '1' and the enable terminal e2 is '0', so that the data strobe SEL_3 outputs '0'. At this time, due to the data strobe The enable terminals e2 of SEL_1, data strobe SEL_2, data strobe SEL_4, and data strobe SEL_5 are all '0', so data strobes SEL_1, data strobes SEL_2, data strobes SEL_4, and data strobes SEL_5 have no data output. At this time, the '0' output by data strobe SEL_3 passes through the first OR gate OR_1 and the third AND gate AND_11 to output the fault signal error_sig = '0', indicating that the state machine has no faults.

[0099] When an exception occurs during the operation of the state machine, for example, in state 3, an irrelevant state is entered due to an exception trigger. Assume that the state code value changes from the normal "00100" to the irrelevant state code value "10100", that is, the fourth bit Code[4] of the state code value jumps from '0' to '1'. At this time, the first input end of the first AND gate AND_1 and the second AND gate AND_2 is the current value '1', and the second input end of the first AND gate AND_1 and the second AND gate AND_2 has not yet entered the state due to the delay of the data register sub-circuit DR_FF_1. The row data is synchronized, so the input is still the previous value, which are the normal value '0' of Code[4] and the '1' after the normal value '0' passes through the first NOT gate NOT_1. At this time, the first AND gate AND_1 outputs a low level and the second AND gate AND_2 outputs a high level, so that the enable end e2 of the data selector SEL_1 is '1'. At this time, the data selector SEL_1 outputs '1', and passes through the first OR gate OR_1 and the third AND gate AND_11 to make the fault signal error_sig = '1', indicating that a fault has occurred in the state machine.

[0100] The state machine can be detected in any irrelevant state, that is, when the number of '1' bits in the state code value Code[4..0] cnt>1 or cnt=0. In addition, it can also be detected when cnt=1 but the state code value is unexpected. For example, when cnt=0, that is, when the state jumps from the normal state to the state code value "00000", it can also be detected. For example, when the state code value changes from the normal "00100" to the irrelevant state code value "00000", the first and second AND gates AND_5 and AND_6 both output '0', and the enable terminal e2 of the data strobe SEL_3 is '0', resulting in no output from the data strobe SEL_3. Similarly, the data strobes SEL_1, SEL_2, SEL_4, and SEL_5 also have no output, causing the first OR gate OR_1 to have no output. However, because the first input terminal of the third AND gate AND_11 is at a high level, the second input terminal of the third AND gate AND_11 is pulled up to a high level by a pull-up resistor, causing the state machine fault signal error_sig to equal '1'. Alternatively, since the state changes of the state machine have a predetermined sequence, for example, from state 1 to state 2, from state 2 to state 3, from state 3 to state 4, and from state 4 to state 5, the state code values ​​of states 1 to 5 are "00001", "00010", "00100", "01000", and "10000", respectively, when the state machine transitions between two states, for example, from the state code value "00100" of state 3 to the state code value "10000" of state 5, the data selector SEL_1 outputs "1" and the data selectors SEL_2 to SEL_5 output 0, thereby making the state machine fault signal error_sig = "1", that is, at this time cnt = 1 but the state code value is not the expected value. State machine fault can also be detected through this circuit.

[0101] According to an embodiment of the present application, the recovery circuit includes: a switching sub-circuit, a first end of the switching sub-circuit is electrically connected to a memory storing a predetermined normal state code, a second end of the switching sub-circuit is electrically connected to an input end of a state machine, and an enable end of the switching sub-circuit is electrically connected to an output end of a comparison circuit; the switching sub-circuit is configured to, when the control signal indicates that the n+1th state code is an abnormal code, turn on the first end and the second end according to the control signal to transmit the predetermined normal state code to the state machine.

[0102] Figure 5 A structural schematic diagram of a recovery circuit according to a specific embodiment of the present application is shown.

[0103] like Figure 5As shown, the recovery circuit includes a switch subcircuit 131, wherein a first end of the switch subcircuit 131 is electrically connected to a memory storing a predetermined normal state code, a second end of the switch subcircuit 131 is electrically connected to an input end of the state machine 140, and an enable end of the switch subcircuit 131 is electrically connected to an output end of the comparison circuit.

[0104] In this embodiment, the enable terminal of the switch sub-circuit 131 is directly connected to the fault signal error_sig output by the comparison circuit.

[0105] In this embodiment, the memory storing the predetermined normal state code State_1[4..0], such as a register or read-only memory (ROM) within the logic controller, can be used to store the one-hot initial code "00001" to ensure that the state machine can be restored to a known initial safe state in the event of an abnormality. Furthermore, the memory storing the predetermined normal state code can also be located external to the logic controller. This allows the memory internal to the logic controller to retrieve the normal state code value, such as the initial code "00001," from the external logic memory for restoration when the memory within the logic controller is in an unsafe state.

[0106] Figure 6 A specific structural schematic diagram of a recovery circuit according to a specific embodiment of the present application is shown.

[0107] like Figure 6 As shown, in this specific embodiment, Figure 5 The switch sub-circuit 131 in the embodiment can be configured as a tri-state buffer Tri. The enable terminal of the tri-state buffer Tri is directly connected to the fault signal error_sig, the input terminal is connected to the memory storing "00001", and the output terminal is connected to the input terminal of the state machine.

[0108] When the error signal error_sig = '1' connected to the enable terminal, the tri-state buffer Tri is turned on, and the predetermined normal code in the memory, such as "00001", is transferred to the state machine, overwriting the abnormal code. When the error signal error_sig = '0' connected to the enable terminal, the tri-state buffer Tri is in a high-impedance state, and the input of the state machine is driven by the data register circuit, which does not affect normal state transitions.

[0109] Based on this, the embodiment of the present application realizes a hardware-level rapid response to state machine abnormalities by having the enable end of the switch sub-circuit directly respond to the control signal output by the comparison circuit. When the control signal indicates that the n+1th state code is an abnormal code, the switch sub-circuit is immediately turned on and the one-hot initial code pre-stored in the memory is forcibly injected into the state machine input end, overwriting the abnormal code and resetting it to a known initial safe state; while in the normal state, the switch sub-circuit is in a high-impedance state and does not interfere with the normal drive of the state machine by the data storage circuit, which not only ensures a nanosecond recovery speed in the event of an abnormality, but also avoids interference with the normal operation of the state machine, and realizes security protection during the operation of the state machine with extremely low hardware overhead, effectively resisting state abnormalities caused by external attacks or hardware failures.

[0110] According to an embodiment of the present application, the recovery circuit includes: a logic sub-circuit, wherein the two input terminals of the logic sub-circuit are electrically connected to the reset terminal of the state machine and the output terminal of the comparison circuit respectively, and the output terminal of the logic sub-circuit is electrically connected to the enable terminal of the switch sub-circuit; a switch sub-circuit, wherein the first terminal of the switch sub-circuit is electrically connected to a memory storing a predetermined normal state code, and the second terminal of the switch sub-circuit is electrically connected to the input terminal of the state machine; the switch sub-circuit is configured to, when the control signal indicates that the n+1th state code is an abnormal code or the state machine is in a reset process, connect the first terminal and the second terminal to transmit the predetermined normal state code to the state machine.

[0111] Figure 7 A structural schematic diagram of a recovery circuit according to another specific embodiment of the present application is shown.

[0112] like Figure 7 As shown, in another specific embodiment, the recovery circuit includes a switch sub-circuit 131 and a logic sub-circuit 132 .

[0113] The switch subcircuit 131 includes a first terminal, a second terminal, and an enable terminal. The first terminal is electrically connected to a memory storing a predetermined normal state code, and the second terminal is electrically connected to an input terminal of the state machine 140. The logic subcircuit 132 includes a first input terminal, a second input terminal, and an output terminal. The first input terminal is electrically connected to the output terminal of the comparison circuit, the second input terminal is connected to the reset terminal of the state machine 140, and the output terminal is electrically connected to the enable terminal of the switch subcircuit 131.

[0114] In this specific embodiment, the enable terminal of switch subcircuit 131 receives two trigger signals through logic subcircuit 132: a fault signal (error_sig = '1') output by the comparison circuit, used for abnormal code detection; and a state machine reset signal, used to trigger the reset process. When either condition is met, switch subcircuit 131 turns on, transmitting the normal code to state machine 140. Only when both conditions are not met does switch subcircuit 131 assume a high impedance state, and state machine 140 is driven by the data register circuit.

[0115] Figure 8 A schematic diagram of the specific structure of a recovery circuit according to another specific embodiment of the present application is shown.

[0116] like Figure 8 As shown, Figure 7 The switch sub-circuit 131 can be configured as a tri-state buffer Tri, and the logic sub-circuit 132 can be configured as a third OR gate OR_3. The input of the tri-state buffer Tri is connected to a memory storing "00001," the output is connected to the input of the state machine, and the enable terminal is connected to the output of the third OR gate OR_3. The first input of the third OR gate OR_3 is connected to the fault signal error_sig output by the comparison circuit, and the second input of the third OR gate OR_3 is connected to the reset terminal of the state machine.

[0117] In this specific embodiment, when the comparator circuit detects a fault signal error_sig = '1', the third OR gate OR_3 outputs a high level, validating the enable terminal en of the tri-state buffer Tri. This outputs a normal state code value, such as the code value "00001" for state 1, to the state machine, thereby allowing the state machine to recover from the fault and resume operation from state 1. Furthermore, when the logic controller is reset or the system is locked, that is, when the reset terminal R of the state machine is high, the third OR gate OR_3 also outputs a high level, turning on the tri-state buffer Tri and outputting the code value for state 1 to the state machine, ensuring that the state machine can be reset in a system reset or locked state.

[0118] Based on this, the embodiments of the present application implement a dual safety trigger mechanism for the state machine through the coordinated design of the logic subcircuit and the switch subcircuit. When the control signal output by the comparison circuit indicates that the state machine has an abnormal code or the state machine is in the reset process, the logic subcircuit outputs a high level to enable the switch subcircuit, forcibly injecting the predetermined normal state code stored in the memory into the state machine input terminal, achieving a hardware-level rapid reset. During normal operation, the switch subcircuit is in a high-impedance state and does not interfere with the normal drive of the state machine by the data register circuit. This not only covers the abnormal detection and recovery during the operation of the state machine, but also ensures the initialization security during system startup or lock, effectively resisting external attacks, hardware failures, and the risk of uninitialized state, and improving the reliability and security of the system's full-cycle operation.

[0119] According to an embodiment of the present application, the state restorer also includes: a reset circuit, the first end of the reset circuit is used to receive a reset signal and a security control signal, the second end of the reset circuit is electrically connected to the reset end of the data register circuit and the reset end of the state machine, and the reset circuit is configured to perform a reset operation on the data register circuit and the state machine when the reset signal indicates that the state machine is in a reset process, or the security control signal indicates that the logic controller is in a locked state.

[0120] In this embodiment, the reset circuit can be used to synchronously reset the data register circuit and the state machine when the system is reset or locked.

[0121] Figure 9 FIG2 shows a structural diagram of a state restorer according to the second embodiment of the present application.

[0122] like Figure 9 As shown, the state restorer further includes a reset circuit 150 , a first end of the reset circuit 150 is used to receive a reset signal and a safety control signal, and a second end is electrically connected to a reset end of the data register circuit 110 and a reset end of the state machine 140 .

[0123] Reset circuit 150 is configured to trigger a reset when any of the following conditions are met: state machine 140 is in the reset process, or a security control signal indicates that the logic controller is in a locked state. The security control signal is typically active high. This security control signal can be generated by an external security monitoring module or internal control logic and is triggered when the system detects a security event, such as the persistence of an abnormal status code, an unauthorized access attempt, or the detection of a hardware failure requiring entry into protection mode.

[0124] Figure 10 A schematic diagram of the specific structure of a state restorer according to the second embodiment of the present application is shown.

[0125] like Figure 10 As shown, in this embodiment, the reset circuit 150 includes a second NOT gate NOT_21 and a second OR gate OR_2. One end of the second NOT gate NOT_21 is configured to receive the reset signal RSTn, and the other end is electrically connected to the first input of the second OR gate OR_2. The second input of the second OR gate OR_2 is configured to receive the security control signal lock_sig. The output of the second OR gate OR_2 is electrically connected to the reset terminals of multiple data register sub-circuits, such as DR_FF_1 through DR_FF_5, and the reset terminal of the state machine.

[0126] When the reset signal RSTn is '0' or the security control signal lock_sig is '1', the second OR gate OR_2 outputs '1', validating multiple data register sub-circuits such as DR_FF_1 through DR_FF_5 and the reset terminal R of the state machine. At this point, the state machine cannot operate. When the reset process completes, the reset signal RSTn is '1', and the security control signal lock_sig is '0', the state machine operates normally.

[0127] Based on this, in the embodiments of the present application, when the logic controller is reset or the safety control signal is valid, the OR gate outputs a high level and synchronously activates the reset terminal of the data register circuit and the state machine, forcing it into an initial safe state, effectively blocking abnormal state transitions or resisting security threats. When the reset process is completed and the lock signal is invalid, the reset circuit outputs a low level, and the state machine can operate normally based on the feedback from the data register circuit. This not only ensures the reliability of system startup initialization and runtime safety lock, but also avoids interference with the normal operation process, providing low-power, highly robust state security protection for the logic controller.

[0128] According to an embodiment of the present application, the security control signal is obtained by at least one of the following methods: verifying the cryptographic circuit in the logic controller, or detecting the output voltage of the logic controller.

[0129] In this embodiment, the security control signal lock_sig may be generated by at least one method such as cryptographic circuit verification and voltage detection.

[0130] In this embodiment, the cryptographic circuit verification may indicate functional correctness verification of the cryptographic algorithm module within the logic controller, generating a security control signal lock_sig = "1" when the verification fails, and generating a security control signal lock_sig = "0" when the verification succeeds.

[0131] For example, it can simultaneously detect the AES and SM4 symmetric encryption algorithms and the SHA256 and SM3 hashing algorithms. If the output of any algorithm is inconsistent with the standard value, a security control signal lock_sig = '1' is generated, locking the system.

[0132] In this embodiment, voltage detection may mean monitoring the power supply voltage of the logic controller, and generating a safety control signal lock_sig = "1" when the voltage is abnormal, such as when it is attacked by voltage injection; and generating a safety control signal lock_sig = "0" when the voltage is normal.

[0133] According to an embodiment of the present application, the state restorer also includes: a password verification circuit, which is configured to perform parallel verification on multiple password circuits of the logic controller when the logic controller is powered on to obtain a security control signal; wherein, when the verification of multiple password circuits is passed, a security control signal is generated for controlling the logic controller to be in an unlocked state; when the verification of any of the multiple password circuits is failed, a security control signal is generated for controlling the logic controller to be in a locked state.

[0134] In this embodiment, the password verification circuit can be used to initiate the password circuit verification process when the logic controller is powered on, that is, when the reset signal RSTn changes from valid to invalid. When the output results of all verified password circuits meet expectations, such as when multiple password circuits have all passed verification, the password verification circuit generates a security control signal, such as lock_sig = '0', to control the logic controller to be unlocked. At this point, the logic controller can operate normally, the data register circuit and the state machine can also operate according to normal procedures, and the system enters a safe and usable state. If any of the multiple password circuits fails verification, it indicates that the password circuit may have a functional anomaly, such as tampering or injection attack resulting in calculation errors. At this time, the password verification circuit generates a security control signal, such as lock_sig = '1', to control the logic controller to be locked. Once the lock signal is valid, the reset circuit will work in conjunction to reset the data register circuit and state machine, preventing the logic controller from performing abnormal or dangerous operations, preventing the spread of security threats, and ensuring system security.

[0135] Figure 11 FIG. 4 shows a structural diagram of a state restorer according to a third embodiment of the present application.

[0136] like Figure 11 As shown, in this embodiment, the state restorer further includes a password verification circuit 160, wherein the output end of the password verification circuit 160 is connected to the second input end of the reset circuit 150 for providing a security control signal.

[0137] According to an embodiment of the present application, a password verification circuit includes: multiple security comparison sub-circuits, wherein the first input terminals of the multiple security comparison sub-circuits are respectively electrically connected to the output terminals of the multiple password circuits, and the second input terminals of the multiple security comparison sub-circuits are respectively electrically connected to the output terminal of the ciphertext processing circuit; the security comparison sub-circuit is configured to: compare the encrypted data output by the password circuit and the ciphertext data output by the ciphertext processing circuit to obtain a second comparison sub-signal; a parallel verification sub-circuit, wherein the multiple input terminals of the parallel verification sub-circuit are respectively electrically connected to the output terminals of the multiple security comparison sub-circuits and a reset signal, and the output terminal of the parallel verification sub-circuit is used to output a security control signal; the parallel verification sub-circuit is configured to obtain a security control signal based on the second comparison sub-signals output by the multiple security comparison sub-circuits.

[0138] Figure 12 A structural diagram of a password verification circuit according to a specific embodiment of the present application is shown.

[0139] like Figure 12 As shown, in this specific embodiment, the password verification circuit includes multiple security comparison sub-circuits 161 and a parallel verification sub-circuit 162.

[0140] In this specific embodiment, the first input terminals of the plurality of security comparison sub-circuits 161 are respectively electrically connected to the output terminals of the plurality of cryptographic circuits 163 , and the second input terminals are electrically connected to the output terminal of the ciphertext processing circuit 164 .

[0141] The multiple input terminals of the parallel verification sub-circuit 162 are electrically connected to the output terminals of the multiple security comparison sub-circuits 161 and the reset signal RSEn, respectively, and the output terminal is used to output the security control signal lock_sig.

[0142] In this embodiment, the security comparison subcircuit 161 can be configured to compare the encrypted data output by the cryptographic circuit 163 with the ciphertext data output by the ciphertext processing circuit 164 one by one to obtain a second comparison sub-signal. The parallel verification subcircuit 162 can be configured to combine the second comparison sub-signals output by multiple security comparison subcircuits 161 to generate a security control signal.

[0143] In this specific embodiment, the cryptographic circuit 163 can be a hardware module that implements a cryptographic algorithm within a logic controller, used to encrypt or hash input data, for example, it can include a symmetric cryptographic algorithm module such as an AES module, an SM4 module, and a hash algorithm module such as a SHA256 module, an SM3 module, etc.

[0144] The input terminal of the cryptographic circuit 163 can receive test data, such as a random number or fixed plain text, and the output terminal is connected to the first input terminal of the security comparison sub-circuit 161 to output encrypted data.

[0145] The ciphertext processing circuit 164 may be used to provide a standard output value of a cryptographic algorithm as a benchmark for security comparison. Specific functions may include, for example, storing or generating standard ciphertext data.

[0146] Figure 13 A specific structural schematic diagram of a password verification circuit according to a specific embodiment of the present application is shown.

[0147] like Figure 13 As shown, in this specific embodiment, the cryptographic circuit may include an AES symmetric cryptographic algorithm module, an SM4 symmetric cryptographic algorithm module, a SHA256 hash algorithm module, and an SM3 hash algorithm module; the security comparison subcircuit may include comparators JMP_1 to JMP_4; the parallel verification subcircuit may include a fifth AND gate AND_61 and a fourth NOT gate NOT_61; and the ciphertext processing circuit includes a cryptographic table Cipher_Table stored in a read-only memory ROM.

[0148] Specifically, the AES symmetric encryption algorithm module has a first input connected to the logic controller's reset signal RSTn, and a second input connected to the AES plaintext data AES_P_in. The SM4 symmetric encryption algorithm module has a first input connected to the logic controller's reset signal RSTn, and a second input connected to the SM4 plaintext data SM4_P_in. The SHA256 hash algorithm module has a first input connected to the logic controller's reset signal RSTn, and a second input connected to the SHA256 plaintext data SHA256_in. The SM3 hash algorithm module has a first input connected to the logic controller's reset signal RSTn, and a second input connected to the SM3 plaintext data SM3_in.

[0149] The AES symmetric encryption algorithm module and the SM4 symmetric encryption algorithm module can be used to encrypt / decrypt the input data D_in and output the data ciphertext / plaintext; the SHA256 hash algorithm module and the SM3 hash algorithm module can be used to perform hash operations on the input data D_in and output the message digest value.

[0150] Comparator JMP_1's first input is connected to the encrypted data AES_C' output by the AES symmetric encryption algorithm module, and its second input is connected to the ciphertext data AES_C stored in the Cipher_Table. Comparator JMP_2's first input is connected to the encrypted data SM4_C' output by the SM4 symmetric encryption algorithm module, and its second input is connected to the ciphertext data SM4_C stored in the Cipher_Table. Comparator JMP_3's first input is connected to the encrypted data SHA256_H' output by the SHA256 hash algorithm module, and its second input is connected to the digest value SHA256_H stored in the Cipher_Table. Comparator JMP_4's first input is connected to the encrypted data SM3_H' output by the SM3 hash algorithm module, and its second input is connected to the digest value SM3_H stored in the Cipher_Table.

[0151] Comparators JMP_1 through JMP_4 can be used to compare the first input terminal and the second input terminal, respectively. When the first input terminal is equal to the value of the second input terminal, they output a high-level second comparison sub-signal. When the first input terminal is not equal to the value of the second input terminal, they output a low-level second comparison sub-signal. The second comparison sub-signals output by comparators JMP_1 through JMP_4 can serve as the detection results of the cryptographic algorithm.

[0152] The Cipher_Table can be configured in the logic controller's internal read-only memory (ROM) to store standard values ​​for cryptographic algorithm modules. For example, for AES plaintext data AES_P_in, the corresponding ciphertext data AES_C is stored. Similarly, the SM4 algorithm ciphertext data SM4_C is stored, along with the correct digest values ​​SHA256_H and SM3_H for the corresponding SHA256 and SM3 algorithms.

[0153] Specifically, taking comparator JMP_1 as an example, if the AES symmetric encryption algorithm module has not been tampered with, the encrypted data AES_C' output by the AES symmetric encryption algorithm module is consistent with the ciphertext data AES_C stored in the cipher table Cipher_Table, and the comparator JMP_1 output is '1'; if the AES symmetric encryption algorithm module is attacked, the encrypted data AES_C' is inconsistent with the ciphertext data AES_C, then the comparator JMP_1 output is '0'.

[0154] The inputs of the fifth AND gate AND_61 are respectively connected to the reset signal RSTn of the logic controller and the outputs of the comparators JMP_1 through JMP_4. The output of the fifth AND gate AND_61 is connected to the input of the fourth NOT gate NOT_61. The output of the fourth NOT gate NOT_61 outputs the safety control signal lock_sig.

[0155] Specifically, when the reset signal RSTn = '0' or any comparator JMP_i is '0', the fourth NOT gate NOT_61 outputs the security control signal lock_sig as '1', indicating that the logic controller is in the locked state and triggering the reset circuit. When the reset signal RSTn = '1' and comparators JMP_1 through JMP_4 are all '1', the fourth NOT gate NOT_61 outputs the security control signal lock_sig as '0', indicating that the logic controller is in the unlocked state.

[0156] In this specific embodiment, the above four cryptographic algorithms can be detected simultaneously when the logic controller is powered on, thereby shortening the startup time through parallel processing.

[0157] For example, when the logic controller is powered on and reset, the reset signal RSTn = '0'. After passing through the fifth AND gate AND_61 and the fourth NOT gate NOT_61, the security control signal lock_sig = '1' is output. After the logic controller is powered on and reset, the reset signal RSTn = '1'. The cryptographic algorithm module is functionally tested, using the AES symmetric cryptographic algorithm module as an example. The testing methods for the SM4, SHA256, and SM3 cryptographic algorithm modules are similar to those for AES.

[0158] When the encrypted data AES_C' equals the ciphertext data AES_C, comparator JMP_1 outputs a high level (AES_result = '1'), indicating that the AES symmetric encryption algorithm module is operating normally. The output value of the fifth AND gate AND_61 depends on the detection results of the other three encryption algorithm modules. When the encrypted data AES_C' does not equal the ciphertext data AES_C, indicating that the AES symmetric encryption algorithm module is operating abnormally, comparator JMP_1 outputs a low level to the fifth AND gate AND_61, which then passes through the fourth NOT gate NOT_61, setting the security control signal lock_sig = '1'.

[0159] Only after all four cryptographic algorithm modules have passed the test can the security control signal be invalidated, that is, lock_sig = '0', thereby unlocking the functional unit of the logic controller; when the above 1 to 4 cryptographic algorithm modules fail to be tested, the security control signal is still valid, that is, lock_sig = '1', indicating that the corresponding cryptographic algorithm module is operating abnormally and may have encountered attacks such as injection and tampering of the operation object. In this case, the functional unit of the logic controller cannot be unlocked, thereby protecting the logic controller.

[0160] Based on this, the embodiments of the present application realize parallel functional verification of the cryptographic circuit in the logic controller by configuring multiple security comparison sub-circuits and parallel verification sub-circuits in the cryptographic verification circuit. After the logic controller is powered on, the output of cryptographic algorithm modules such as AES and SM4 can be synchronously detected to be consistent with the standard value of the ciphertext processing circuit. When any algorithm verification fails, a lock signal is generated by logical aggregation of the reset signal and the comparison result to block abnormal circuit operation, effectively resist attacks such as algorithm module tampering and voltage injection, and ensure that the logic controller is unlocked and operated when the cryptographic function is complete and reliable.

[0161] According to an embodiment of the present application, the ciphertext processing circuit includes at least one of the following: a memory inside a logic controller, configured to store ciphertext data corresponding to the input data of multiple cryptographic circuits; a ciphertext processing circuit arranged outside the logic controller, the ciphertext processing circuit being configured to use an encryption algorithm corresponding to the multiple cryptographic circuits to encrypt the input data of each of the multiple cryptographic circuits to obtain ciphertext data corresponding to the input data of the multiple cryptographic circuits.

[0162] In another specific embodiment, in order to prevent security risks at startup due to leakage or tampering of the password table in the read-only memory ROM, when the logic controller starts, the ciphertext processing circuit can also be configured outside the logic controller, and a standard cryptographic algorithm can be run through an external device such as a host computer to dynamically generate ciphertext data.

[0163] Figure 14A specific structural schematic diagram of a ciphertext processing circuit according to a specific embodiment of the present application is shown.

[0164] In this specific embodiment, the cryptographic algorithm module of the logic controller can be tested by using data generated by a random number algorithm and passing the randomness test, and the AES symmetric cryptographic algorithm module test is used as an example for explanation. Figure 14 As shown, the ciphertext processing circuit may include a random number generator, a random number detection module, and an AES software algorithm module.

[0165] The output end of the random number generator is connected to the input end of the random number detection module, and can be used as an external independent hardware or software module to generate a random number sequence as input data of the cryptographic algorithm.

[0166] The output end of the random number detection module is connected to the input end of the password verification circuit and the input end of the AES software algorithm module respectively, and can be used to perform statistical tests on random numbers to ensure their randomness and prevent predictable data from being exploited by attacks.

[0167] The output end of the AES software algorithm module outputs the ciphertext data AES_C to the comparator JMP_1 in the password verification circuit, which can represent the standard AES algorithm running on the host computer and generates ciphertext data as a trusted module.

[0168] Specifically, when the logic controller is powered on, a random number generator external to the logic controller generates a set of random numbers. A random number detection module then checks the randomness of these random numbers. Only after they pass the randomness test can they be used as the plaintext data AES_P_in for the AES algorithm. If the randomness test requirements are not met, the set of random numbers is discarded, and the random number generator generates the next set of random numbers until the randomness test requirements are met. The AES software algorithm module, located in the host computer and serving as a trusted module on the user side, encrypts the plaintext data AES_P_in and outputs the correct ciphertext data AES_C, which is then sent to the second input of comparator JMP_1. Simultaneously, the plaintext data AES_P_in is sent to the AES symmetric encryption algorithm module within the logic controller, which encrypts the encrypted data AES_C' and transmits it to the first input of comparator JMP_1, allowing comparator JMP_1 to subsequently compare the ciphertext data AES_C with the encrypted data AES_C'.

[0169] The random number detection module uses the discrete transformation method to detect the randomness of the random sequence generated by the random number generator, specifically including: replacing 0 in the random sequence (such as 1011010...) with -1 to obtain a new sequence x k =(1,-1,1,1,-1,1,-1…),where k=1, 2,…, n represents the value of the kth bit in the new sequence, and the new sequence xk Perform a discrete transform according to the following formula (1):

[0170] (1);

[0171] Where L j represents the j-th component of the new sequence x k in the frequency domain. k represents the value of the k-th position in the new sequence x k . j represents the frequency domain index, ranging from 0 to n - 1. n represents the length of the random number of the new sequence. 2π(k - 1)j / n represents the phase factor, controlling the period of the cosine and sine functions. i is the imaginary unit.

[0172] Calculate the modulus of L j using the following formulas (2) - (4):

[0173] (2);

[0174] (3);

[0175] (4);

[0176] Where m j is the modulus of L j , representing the energy intensity of the new sequence x k at frequency domain j. a represents the sum of the real part accumulations, and b represents the sum of the imaginary part accumulations.

[0177] Set a threshold value , and count the number count of m j (j = 0, 1,..., n - 1) that is less than the threshold value such as m j <T. Set the detection passing rate Base. When ≥ Base, the detection passes, and it is considered that the set of random numbers meets the randomness requirements. Among them, the passing rate Base can be set in advance. For example, set Base = 90%. The larger the value, the higher the detection passing standard.

[0178] Based on this, the embodiments of the application implement the dynamicization and anti - attack performance of the password verification process by designing the ciphertext processing circuit as a dual - mode architecture of internal storage and external dynamic generation, and combining the verification data generated by the random number algorithm. The internal storage pre - stores standard ciphertext data, ensuring the fast execution of the verification process. The external ciphertext processing dynamically generates ciphertext by running the standard algorithm on the host computer, and cooperates with the random number detection module to perform discrete transform inspection on the input data to eliminate the risk of physical attack on the internal password table, effectively resisting side - channel attacks and algorithm tampering. The two schemes can be flexibly switched according to the security level requirements, providing full - cycle security protection for the state restorer from startup to operation.

[0179] According to an embodiment of the present application, the state restorer also includes: a voltage detection circuit, a first end of the voltage detection circuit is electrically connected to the voltage output end of the logic controller, and a second end of the voltage detection circuit is electrically connected to the safety control signal of the reset circuit; the voltage detection circuit is configured to detect the output voltage of the logic controller and obtain a safety control signal.

[0180] In this embodiment, the voltage detection circuit can be used to monitor the output voltage of the logic controller and generate a safety control signal by comparing it with a preset voltage upper limit and a preset voltage lower limit.

[0181] Figure 15 A schematic structural diagram of a state restorer according to a fourth embodiment of the present application is shown.

[0182] like Figure 15 As shown, the state restorer further includes a voltage detection circuit 170. A first terminal of the voltage detection circuit 170 is connected to the voltage output terminal of the logic controller to monitor the operating voltage in real time. A second terminal of the voltage detection circuit 170 is connected to the input terminal of the reset circuit 150 to output a security control signal lock_sig to the reset circuit 150 to control the lock or unlock state of the logic controller.

[0183] According to an embodiment of the present application, the voltage detection circuit includes: a first voltage comparison sub-circuit, which is configured to compare the output voltage of the logic controller with the voltage upper limit value and the voltage lower limit value respectively to obtain a safety control signal; wherein, when the output voltage is between the voltage upper limit value and the voltage lower limit value, a safety control signal for controlling the logic controller to be in a locked state is obtained; when the output voltage is not between the voltage upper limit value and the voltage lower limit value, a safety control signal for controlling the logic controller to be in an unlocked state is obtained.

[0184] In this embodiment, the upper voltage limit value may represent the minimum value of the normal operating voltage high level range, and the lower voltage limit value may represent the maximum value of the normal operating voltage low level range. The upper voltage limit value and the lower voltage limit value may be adjusted based on the variable resistor in the first voltage comparison subcircuit.

[0185] When the output voltage is detected to be outside the normal range, such as between the upper and lower voltage limits, the system is judged to be facing security risks such as voltage injection attack and power supply abnormality. At this time, the lock state safety control signal lock_sig = '1' is generated, triggering Figure 15The reset circuit 150 resets the data register circuit 110 and the state machine 140 to prevent abnormal voltages from causing timing errors, logic tampering, and other issues in the logic controller. When the output voltage is within the normal range, an unlocked security control signal, lock_sig = '0', is generated to ensure that the logic controller operates within a safe voltage environment.

[0186] Figure 16 A specific structural schematic diagram of a voltage detection circuit according to a specific embodiment of the present application is shown.

[0187] like Figure 16 As shown, in the voltage detection circuit in this specific embodiment, the first voltage comparison subcircuit includes a first voltage operational amplifier LM_1, a second voltage operational amplifier LM_2, a first resistor R1, a second resistor R2, a third resistor R3, a fourth resistor R4, a first adjustable resistor R_var_1, a second adjustable resistor R_var_2, and a sixth AND gate AND_71.

[0188] The system voltage VCC supplies power to the first voltage operational amplifier LM_1 and the second voltage operational amplifier LM_2 , and serves as a reference upper limit of a high voltage threshold.

[0189] The first end of the first adjustable resistor R_var_1 is connected to the system voltage VCC and the first end of the third resistor R3 respectively, and the second end is grounded. The adjustable end is connected to the '+' input end of the first voltage operational amplifier LM_1 to output the voltage upper limit Vref_H.

[0190] A first end of the second adjustable resistor R_var_2 is connected to the second end of the third resistor R3 , and the other end is grounded. The adjustable end is connected to the '-' input end of the second voltage operational amplifier LM_2 to output a voltage lower limit value Vref_L.

[0191] The test voltage signal V_in is generated from the voltage output of the logic controller. After current limiting by the fourth resistor R4, it is connected to the negative input of the first voltage operational amplifier LM_1 and the positive input of the second voltage operational amplifier LM_2. The output of the first voltage operational amplifier LM_1 is connected to the input of the first resistor R1, and the output of the first resistor R1 is connected to the first input of the sixth AND gate AND_71.

[0192] The output of the second voltage operational amplifier LM_2 is connected to the input of the second resistor R2, and the output of the second resistor R2 is connected to the second input of the sixth AND gate AND_71. The output of the sixth AND gate AND_71 outputs the security control signal lock_sig.

[0193] The first voltage operational amplifier LM_1 and the second voltage operational amplifier LM_2 are respectively used to compare the two input voltages. When the voltage value input to the '+' input terminal is greater than or equal to the voltage value input to the '-' input terminal, the voltage operational amplifier outputs a high level '1'; when the voltage value input to the '+' input terminal is less than the voltage value input to the '-' input terminal, the voltage operational amplifier outputs a low level '0'.

[0194] The first adjustable resistor R_var_1 and the second adjustable resistor R_var_2 can both be configured as variable resistance resistors. The high level range of the first adjustable resistor R_var_1 is Vref_H to VCC. The low level range of the second voltage operational amplifier LM_2 is 0 to Vref_L.

[0195] The first resistor R1, the second resistor R2, the third resistor R3, and the fourth resistor R4 can be used for current limiting. In a specific embodiment, R1 = R2 = 300Ω, R3 = R4 = 10KΩ. The specific resistance values ​​can be other values ​​without affecting the function of the circuit, and this application does not make specific limitations.

[0196] In this specific embodiment, the user can set the voltage upper limit and voltage lower limit respectively by adjusting the first adjustable resistor R_var_1 and the second adjustable resistor R_var_2, for example, setting the voltage upper limit Vref_H=4.6V and the voltage lower limit Vref_L=1.2V.

[0197] If the system voltage VCC = 5.0V, the normal voltage range of the system is 4.6~5.0V for high level and 0~1.2V for low level. The voltage range between 1.2~4.6V is determined to be an abnormal metastable voltage.

[0198] When the test voltage signal V_in of the input terminal is greater than 4.6V, the first voltage operational amplifier LM_1 outputs Vo1 = '0', the second voltage operational amplifier LM_2 outputs Vo2 = '1', and after passing through the sixth AND gate AND_71 , a low level '0' is output, ie, lock_sig = '0'.

[0199] When the test voltage signal V_in of the input terminal is ≤1.2V, the first voltage operational amplifier LM_1 outputs Vo1='1', the second voltage operational amplifier LM_2 outputs Vo2='0', and after passing through the sixth AND gate AND_71, a low level '0' is output. At this time, lock_sig='0'.

[0200] When 1.2V<V_in≤4.6V, the first voltage operational amplifier LM_1 outputs Vo1='1', the second voltage operational amplifier LM_2 outputs Vo2='1', and after passing through the sixth AND gate AND_71, a high level '1' is output, ie, lock_sig='1', to lock the functional unit of the logic controller.

[0201] Based on this, the voltage detection circuit in the embodiment of the present application monitors the output voltage of the logic controller in real time and compares it with the upper and lower voltage limits set by the adjustable resistor to generate a corresponding safety control signal to dynamically control the working state of the logic controller: when the output voltage is within the normal range, the output unlock signal ensures that the system operates stably under a safe voltage; when the voltage is not within the normal range, the output lock signal triggers the reset circuit to reset the data register circuit and the state machine, so as to effectively resist voltage injection attacks, power supply anomalies and other security risks, avoid timing errors or logic tampering in the logic controller, and improve the reliability and safety of the system in a voltage fluctuation environment through adaptive threshold adjustment and real-time protection mechanism.

[0202] According to an embodiment of the present application, the voltage detection circuit includes: a second voltage comparison sub-circuit, configured to compare the output voltage of the logic controller with the voltage upper limit value and the voltage lower limit value respectively to obtain a voltage comparison signal; a first timing circuit, configured to record the abnormal duration of the output voltage under the triggering of the voltage comparison signal when the voltage comparison signal indicates that the output voltage is between the voltage upper limit value and the voltage lower limit value; an alarm circuit, configured to compare the abnormal duration with a first predetermined duration to obtain a safety control signal, wherein, when the abnormal duration exceeds the first predetermined duration, a safety control signal for controlling the logic controller to be in a locked state is obtained; when the abnormal duration does not exceed the first predetermined duration, a safety control signal for controlling the logic controller to be in an unlocked state is obtained.

[0203] In this embodiment, the second voltage comparison subcircuit can be used to compare the output voltage with an upper voltage limit or a lower voltage limit to generate a voltage comparison signal. The first timing circuit can be used to record the abnormal duration when the voltage is within the abnormal range. The alarm circuit can be used to compare the abnormal duration with a predetermined duration to generate a safety control signal.

[0204] Figure 17 A schematic diagram of the specific structure of a voltage detection circuit according to another specific embodiment of the present application is shown.

[0205] like Figure 17As shown, in the voltage detection circuit in this specific embodiment, the second voltage comparison sub-circuit 172 includes a first voltage operational amplifier LM_1, a second voltage operational amplifier LM_2, a first resistor R1, a second resistor R2, a third resistor R3, a fourth resistor R4, a first adjustable resistor R_var_1, a second adjustable resistor R_var_2, and a sixth AND gate AND_71.

[0206] The circuit connection relationship among the first voltage operational amplifier LM_1, the second voltage operational amplifier LM_2, the first resistor R1, the second resistor R2, the third resistor R3, the fourth resistor R4, the first adjustable resistor R_var_1, and the second adjustable resistor R_var_2 in the second voltage comparison sub-circuit 172 can be referred to. Figure 16 , I will not go into details here.

[0207] The voltage detection circuit in this specific embodiment further includes a first timing circuit 173 and an alarm circuit 174 .

[0208] like Figure 17 As shown, the first timing circuit 173 may include a timer CNT, a clock terminal clk of the timer CNT is connected to the system clock CLK pin of the logic controller to time the high level duration of the input terminal, the input terminal is connected to the output terminal of the sixth AND gate AND_71, and the output terminal outputs the abnormal duration T_out.

[0209] like Figure 17 As shown, the alarm circuit 174 may include a comparator CMP_6, a first input terminal of the comparator CMP_6 is connected to the output terminal of the timer CNT to receive the abnormal duration T_out output by the timer CNT, a second input terminal receives a predetermined duration set by the user, such as a time threshold value Threshold, and an output terminal outputs a safety control signal lock_sig.

[0210] In this specific embodiment, the user can set the voltage upper limit and voltage lower limit respectively by adjusting the first adjustable resistor R_var_1 and the second adjustable resistor R_var_2, for example, setting the voltage upper limit Vref_H=4.6V and the voltage lower limit Vref_L=1.2V.

[0211] In addition, the user sets a time threshold, for example, setting Threshold=2 seconds, then the lock signal lock_sig is triggered to be valid when the duration of the metastable voltage is ≥2 seconds.

[0212] When the test voltage signal V_in at the input terminal exceeds 4.6V, the first voltage operational amplifier LM_1 outputs Vo1 = '0', the second voltage operational amplifier LM_2 outputs Vo2 = '1', and after passing through the sixth AND gate AND_71, it outputs a low level '0'. At this time, timer CNT does not count the R terminal, and the output timing time T_out = 0. Since 0 < Threshold = 2 seconds, the comparator CMP_6 outputs a low level, that is, lock_sig = '0'.

[0213] When the test voltage signal V_in at the input terminal is less than or equal to 1.2V, the first voltage operational amplifier LM_1 outputs Vo1 = '1', the second voltage operational amplifier LM_2 outputs Vo2 = '0', and after passing through the sixth AND gate AND_71, it outputs a low level '0'. The timer CNT also outputs T_out = 0. At this time, lock_sig = '0'.

[0214] When 1.2V<V_in≤4.6V, the first voltage operational amplifier LM_1 outputs Vo1='1', the second voltage operational amplifier LM_2 outputs Vo2='1', and after passing through the sixth AND gate AND_71, it outputs a high level '1'. At this time, the timer CNT times the R terminal and outputs the timing time T_out. When T_out is less than 2 seconds, the comparator CMP_6 outputs a low level; when T_out is greater than or equal to 2 seconds, the comparator CMP_6 outputs a high level. At this time, the safety control signal lock_sig='1' to lock the functional unit of the logic controller.

[0215] Based on this, in the embodiments of the present application, the voltage detection circuit can be used to implement intelligent monitoring and risk control of the logic controller's output voltage. Specifically, the second voltage comparison subcircuit can accurately identify the metastable voltage range based on the upper and lower voltage limits set by the adjustable resistor. When the voltage is detected to be in the abnormal range, the first timing circuit uses the system clock to accurately time the abnormal duration in milliseconds. Ultimately, the timing result is compared with the predetermined duration through the alarm circuit, and a safety control signal is generated only when the abnormal duration exceeds the limit, thereby filtering transient interference such as power supply glitches and reducing the false alarm rate.

[0216] According to an embodiment of the present application, the alarm circuit may further include a light emitting diode and a buzzer.

[0217] Figure 18 A schematic diagram of the specific structure of a voltage detection circuit according to another specific embodiment of the present application is shown.

[0218] like Figure 18As shown, the alarm circuit 174 also includes a light emitting diode LED, a buzzer BUZ and a fifth resistor R5, wherein the first end of the light emitting diode LED is respectively connected to the safety control signal lock_sig and the second end of the fifth resistor R5, the second end of the light emitting diode LED is grounded, the first end of the fifth resistor R5 is connected to the system voltage VCC, the first end of the buzzer BUZ is connected to the safety control signal lock_sig, and the second end of the buzzer BUZ is grounded.

[0219] In this specific embodiment, if the logic controller is in a normal state, the safety control signal lock_sig = '0', the voltage difference between the two ends of the light-emitting diode (LED) is 0V, and the buzzer (BUZ) does not emit light. If the logic controller is in an abnormal state, the safety control signal lock_sig = '1', driving the light-emitting diode (LED) to conduct forward, emitting light to indicate a voltage abnormality, and sounding the buzzer (BUZ), indicating that the logic controller's output voltage is abnormal, indicating a possible voltage injection attack.

[0220] Based on this, in an embodiment of the present application, the alarm circuit realizes a physical layer visual alarm of voltage anomaly through a hardware combination of a light-emitting diode, a buzzer and a fifth resistor. Under normal conditions, the LED and the buzzer are silent because there is no voltage difference between the two ends; when the voltage anomaly duration exceeds the predetermined threshold and triggers lock_sig='1', the system voltage drives the light-emitting diode to conduct forward and emit light after being limited by the fifth resistor, and at the same time, a voltage difference is formed at both ends of the buzzer and it sounds, using dual light and sound prompts to intuitively feedback the abnormal output voltage of the logic controller, effectively indicating possible voltage injection attacks or power failures, and providing a basis for rapid fault location for operation and maintenance personnel. The circuit design is simple and low-consumption, and only works in abnormal situations, taking into account both safety and power consumption control.

[0221] According to an embodiment of the present application, the state restorer also includes: an authority verification circuit, wherein the first data input terminal, the second data input terminal and the third data input terminal of the authority verification circuit are respectively used to receive verification information of the memory in the logic controller, the identity information output by the host computer and the security control signal, and the output terminal of the authority verification circuit is electrically connected to the enable terminal of the switch circuit; a switch circuit, wherein the first end of the switch circuit is electrically connected to the output terminal of the logic controller, and the second end of the switch circuit is electrically connected to the processor located outside the logic controller, and the switch circuit is configured to control the first end and the second end of the switch circuit to be conductive when the authority verification circuit outputs a verification signal indicating that the identity authentication is passed; wherein the authority verification circuit is configured to: when the verification is passed and the security control signal indicates that the logic controller is in an unlocked state, output a verification signal indicating that the identity authentication is passed; and when the duration of the verification passing is greater than the second predetermined time length, output a verification signal indicating that the identity authentication fails.

[0222] In this embodiment, the authority verification circuit can be used to authenticate the identity of the user, and control the interface to be turned on if the verification is passed, and control the interface to be turned off if the verification fails.

[0223] This prevents the operating object from reading key information stored inside the logic controller through the IO interface.

[0224] Figure 19 A schematic structural diagram of a state restorer according to a fifth embodiment of the present application is shown.

[0225] like Figure 19 As shown, the state restorer further includes an authority check circuit 180 and a switch circuit 190 .

[0226] In this embodiment, the first data input of the permission verification circuit 180 receives verification information stored in the read-only memory (ROM) within the logic controller, such as the authentication code Auth_code. The second data input of the permission verification circuit 180 receives identity information output by the host computer, such as the authentication code Code_in. The output of the permission verification circuit 180 is connected to the enable terminal of the switch circuit 190 to output a verification signal enable_sig. If the verification information received by the first data input matches the identity information received by the second data input, verification has passed.

[0227] A first end of the switch circuit 190 is electrically connected to an output end of the logic controller, such as an IO interface, for reading data IO(0) within the logic controller, such as a key or status information stored in a ROM. A second end of the switch circuit 190 is electrically connected to a processor external to the logic controller, such as an MCU or a host computer, for transmitting the logic controller data DATA(0) to an external system.

[0228] The enable terminal of the switch circuit 190 is used to receive a verification signal, enable_sig. If the verification signal is high, it indicates that the identity authentication has passed, and the first and second terminals of the switch circuit 190 are connected. If the verification signal is low, it indicates that the identity authentication has failed, and the first and second terminals of the switch circuit 190 are not connected.

[0229] In this embodiment, the verification information stored in the read-only memory ROM inside the logic controller is used to verify the identity information output by the host computer, and if the verification passes, a verification signal indicating that the identity authentication has passed is output; if the verification fails, a verification signal indicating that the identity authentication has failed is output.

[0230] Based on this, the embodiment of the present application constructs a secure data interaction barrier between the logic controller and the external processor through the collaborative design of the permission verification circuit and the switching circuit. The permission verification circuit compares the authentication code stored in the memory of the logic controller with the identity information input by the host computer, and outputs a high-level verification signal only when the two are consistent. The switching circuit is triggered by this signal to connect the IO interface between the logic controller and the outside, thereby realizing legal data interaction and improving the overall security of the system.

[0231] Figure 20 A schematic structural diagram of a state restorer according to a sixth embodiment of the present application is shown.

[0232] like Figure 20 As shown, in another embodiment, the control input terminal of the authority verification circuit 180 is connected to the security control signal lock_sig, and the security control signal lock_sig can be connected by a voltage detection circuit or a password verification circuit.

[0233] In this embodiment, the verification information stored in the memory inside the logic controller is used to verify the identity information output by the host computer, and when the verification passes and the security control signal indicates that the logic controller is in an unlocked state, a verification signal indicating that the identity authentication is passed is output.

[0234] Based on this, the embodiment of the present application compares the authentication code stored in the memory of the logic controller with the identity information input by the host computer, and outputs a conduction signal only when the verification is passed and the security control signal indicates that the logic controller is in an unlocked state. If the voltage is abnormal or the password verification fails, the interface cannot be turned on even if the identity information is correct, thereby avoiding the risks caused by the failure of a single security module and effectively resisting unauthorized access and complex attacks.

[0235] Figure 21 A schematic structural diagram of a state restorer according to the seventh embodiment of the present application is shown.

[0236] like Figure 21 As shown, in yet another embodiment, the input end of the permission check circuit 180 may further be connected to the clock signal CLK and the second predetermined time duration Time_in to determine the duration of the pass check.

[0237] In this embodiment, the identity information output by the host computer is verified using the verification information in the memory of the logic controller, and when the verification passes and the security control signal indicates that the logic controller is in an unlocked state, a verification signal indicating that the identity authentication is passed is output; when the duration of the verification passing is greater than the second predetermined time length, a verification signal indicating that the identity authentication fails is output.

[0238] Based on this, the embodiments of the present application further enhance the security of the logic controller's interaction with the outside world by introducing a second predetermined duration. When identity authentication is successful and the system is unlocked, the permission verification circuit outputs an authentication pass signal to enable data interaction. Once the authentication pass status persists for longer than the second predetermined duration, even if the identity and system status are correct, the authentication will be immediately deemed unsuccessful and the connection will be severed. This effectively prevents users from illegally staying for extended periods of time after authentication, stealing sensitive data, or tampering with the system. Dynamic time management enables refined control of access rights, significantly improving the system's ability to resist persistent attacks.

[0239] According to an embodiment of the present application, the authority verification circuit includes: a comparator, a first input end of the comparator is electrically connected to the memory in the logic controller, a second input end of the comparator is electrically connected to the upper computer, and an output end of the comparator is electrically connected to the trigger end of the timer and the first input end of the fourth AND gate; a third NOT gate, an input end of the third NOT gate is used to receive a security control signal, and an output end of the third NOT gate is electrically connected to the second input end of the fourth AND gate; a fourth AND gate, an output end of the fourth AND gate is electrically connected to the first input end of the fifth AND gate; a timer, an output end of the timer is electrically connected to the second input end of the fifth AND gate; and a fifth AND gate, an output end of the fifth AND gate is electrically connected to the enable end of the switch sub-circuit.

[0240] Figure 22 The figure shows a schematic diagram of the specific structure of the permission verification circuit according to a specific embodiment of the present application.

[0241] like Figure 22 As shown, the permission check circuit 180 of this specific embodiment includes a comparator JMP_5, a third NOT gate NOT_3, a fourth AND gate AND_12, a timer Timer, and a fifth AND gate AND_13.

[0242] In this embodiment, the first input terminal of comparator JMP_5 (terminal '2' of JMP_5) is connected to verification information stored in the memory inside the logic controller, such as the authentication code Auth_code. The second data input terminal of comparator JMP_5 (terminal '1' of JMP_5) is connected to identity information output by the host computer, such as the authentication code Code_in. The output terminal of comparator JMP_5 is connected to the trigger terminal E of the timer Timer and the first input terminal of the fourth AND gate AND_12.

[0243] When the identity information Code_in output by the host computer is consistent with the verification information Auth_code stored in the memory inside the logic controller, the comparator JMP_5 outputs a high level '1'; when the identity information Code_in output by the host computer is inconsistent with the verification information Auth_code stored in the memory inside the logic controller, the comparator JMP_5 outputs a low level '0'.

[0244] In this embodiment, an input terminal of the third NOT gate NOT_3 receives the safety control signal lock_sig, and an output terminal of the third NOT gate NOT_3 is connected to a second input terminal of the fourth AND gate AND_12.

[0245] An output terminal of the fourth AND gate AND_12 is connected to a first input terminal of a fifth AND gate AND_13 .

[0246] The trigger terminal E of the timer Timer receives the output of the comparator JMP_5. The timing setting terminal T of the timer Timer receives the second predetermined time length Time_in. The output terminal Q of the timer Timer is connected to the second input terminal of the fifth AND gate AND_13.

[0247] An output terminal of the fifth AND gate AND_13 is connected to the enable terminal of the switch circuit 190 to output the verification signal enable_sig.

[0248] In this specific embodiment, if the security control signal lock_sig = '1', indicating that the logic controller is in a locked state, the third NOT gate NOT_3 outputs '0', the fourth AND gate AND_12 outputs '0', the fifth AND gate AND_13 outputs '0', and the check signal enable_sig outputs '0', causing the switch circuit 190 to be blocked.

[0249] If the safety control signal lock_sig='0', indicating that the logic controller is in an unlocked state, the third NOT gate NOT_3 outputs '1', and the output of the fourth AND gate AND_12 depends on the result of the comparator JMP_5.

[0250] When comparator JMP_5 outputs '1' and safety control signal lock_sig outputs '0', timer Timer is triggered and begins counting based on the second predetermined time duration Time_in. If the timer has not expired, fifth AND gate AND_13 outputs '1', and check signal enable_sig outputs '1', turning on switch circuit 190. If the timer has expired, fifth AND gate AND_13 outputs '0', and check signal enable_sig outputs '0', turning off switch circuit 190.

[0251] Based on this, the embodiment of the present application uses a comparator to compare the identity information output by the upper computer with the verification information stored in the memory inside the logic controller in real time, and combines the lock status and time threshold of the logic controller to dynamically control the switching circuit. Only when "identity information matches", "system is not locked" and "has not exceeded the preset time" are met at the same time, a high-level enable signal is output to conduct data interaction. If any condition is not met, the interface is immediately blocked to integrate identity authentication, system status and time management into the hardware circuit, which not only realizes access control to key data of the logic controller, but also prevents session hijacking through a timed automatic disconnection mechanism, significantly improving the system's ability to resist physical attacks and prevent unauthorized access.

[0252] Figure 23 A schematic diagram of the specific structure of the permission verification circuit according to another specific embodiment of the present application is shown.

[0253] like Figure 23 As shown, the permission check circuit 180 of this embodiment includes a comparator JMP_5, a third NOT gate NOT_3, a fourth AND gate AND_12, a timer Timer, and a fifth AND gate AND_13. The switch circuit 190 of this embodiment includes n sets of bidirectional tri-state buffers Bi_Tri.

[0254] Each set of bidirectional tri-state buffers Bi_Tri consists of two tri-state buffers connected end-to-end, with an enable terminal en connected as the enable terminal of the bidirectional tri-state buffer Bi_Tri. One end of each Bi_Tri is connected to the input / output port line IO(n) of the logic controller, and the other end is connected to the data line Data(n) of an external module, such as a host computer. When the check signal enable_sig connected to the enable terminal is active high, the bidirectional tri-state buffer Bi_Tri is turned on, and data can be transferred from the input / output port line IO(n) of the logic controller to the data line Data(n) of an external module, such as a host computer, or from the data line Data(n) of an external module, such as a host computer, to the input / output port line IO(n) of the logic controller. When the check signal enable_sig connected to the enable terminal is inactive low, the n sets of bidirectional tri-state buffers Bi_Tri are blocked, and data exchange between IO(n) and Data(n) is impossible.

[0255] In this specific embodiment, when the logic controller is in the locked state, the safety control signal lock_sig is '1', which outputs '0' after passing through the third NOT gate NOT_3. Then, after passing through the fourth AND gate AND_12 and the fifth AND gate AND_13, the check signal enable_sig outputs '0'. As a result, the enable terminals en of the n bidirectional tri-state buffers Bi_Tri are set to '0', thereby blocking the n bidirectional tri-state buffers Bi_Tri.

[0256] When the logic controller is in the unlocked state, the security control signal lock_sig is '0' and outputs '1' after passing through the third NOT gate NOT_3. The value of the verification signal enable_sig depends on the identity information input by the user and the output of the timer Timer.

[0257] When the identity information Code_in output by the host computer matches the verification information Auth_code stored in the logic controller's internal memory, comparator JMP_5 outputs a high level, and the fourth AND gate AND_12 also outputs a high level. Furthermore, at this point, the E terminal of timer Timer is '1'. The timer begins operating after the user inputs the second predetermined duration Time_in. If the second predetermined duration has not yet elapsed, the timer Timer outputs a high level. Therefore, after passing through the fifth AND gate AND_13, the verification signal enable_sig is asserted, turning the enable terminal en = '1'. This controls the n bidirectional tri-state buffers Bi_Tri to conduct, allowing the external module to read data from or write data to the ROM.

[0258] When the identity information Code_in output by the host computer is inconsistent with the verification information Auth_code stored in the memory inside the logic controller, it may be an illegal access to the operation object. The comparator JMP_5 outputs a low level. After passing through the fourth AND gate AND_12 and the fifth AND gate AND_13, the verification signal enable_sig is invalid, making the enable terminal en = '0'. At this time, the n sets of bidirectional tri-state buffers Bi_Tri are blocked, and the external module cannot read or write the ROM area.

[0259] After data access is completed, the device automatically returns to the blocked state based on a second predetermined duration. When the second predetermined duration expires, the timer Timer outputs a low level, causing the fifth AND gate AND_13 to output a low level. The check signal enable_sig = '0', blocking the n bidirectional tri-state buffers Bi_Tri, thereby preventing unauthorized access and improving data security. The second predetermined duration can be flexibly set by the user based on the amount of data read or written each time.

[0260] Based on this, the embodiments of the present application only turn on the data channel through the three-state buffer when the "identity information matches", "the system is not locked" and "the predetermined time has not been exceeded", allowing the external module to read and write ROM data; when any condition is not met, the three-state buffer immediately enters the high-impedance state to block the interaction, and cooperates with the timed automatic blocking mechanism to effectively prevent unauthorized access, brute force cracking and session hijacking. While ensuring legal data interaction, the system's anti-attack capability is improved through hardware-level physical isolation, realizing full-cycle security protection of the key data of the logic controller.

[0261] Figure 24 A schematic diagram of the specific structure of the permission verification circuit according to another specific embodiment of the present application is shown.

[0262] like Figure 24 As shown, the permission check circuit 180 of this specific embodiment includes a comparator JMP_5, a third NOT gate NOT_3, a fourth AND gate AND_12, a timer Timer, and a fifth AND gate AND_13.

[0263] Since the tri-state buffer has a signal transmission delay, it will cause data transmission delay in high-speed data transmission applications. To reduce signal delay, in this specific embodiment, the switch circuit 190 can also be configured as n groups of line switching switches MUX_0 to MUX_n-1.

[0264] Each group of line switches (MUX) is connected to the logic controller's input / output port line IO(n) at one end and to the data line Data(n) of an external module, such as a host computer, at the other end. When the input verification signal enable_sig is active high, the switching segments of the n groups of line switches (MUX_0 to MUX_n-1) are connected to the '1' end, i.e., the data lines of the external module, such as Data(0) to Data(n-1), to reduce data transmission delay. When the input verification signal enable_sig is inactive low, the switching segments of the n groups of line switches (MUX_0 to MUX_n-1) are connected to the '2' end, i.e., the floating end, physically disconnecting the logic controller's input / output port lines IO(0) to IO(n-1) from the external module's data lines Data(0) to Data(n-1).

[0265] Based on this, the embodiment of the present application achieves the dual goals of low latency and high security in high-speed data transmission scenarios by configuring the switching circuit into multiple groups of line switching switches. By utilizing the high-speed switching characteristics of the line switching switch, when the check signal is at a high level, the line switching switch switching segment directly connects the logic controller input and output port lines and the external module data lines to eliminate the transmission delay of the three-state buffer; when the check signal is at a low level, the line switching switch switching segment is connected to the floating end to achieve physical-level electrical isolation. Combined with the triple condition verification of the authority verification circuit, it not only solves the delay bottleneck in high-speed transmission, but also effectively resists physical layer threats such as voltage injection and side channel attacks through hardware-level real-time switching and timed automatic blocking mechanisms, providing a hardware isolation solution that is both efficient and secure for high-speed data interaction.

[0266] Figure 25 A schematic diagram of the architecture of a logic controller during operation according to a specific embodiment of the present application is shown.

[0267] like Figure 25As shown, when the logic controller is started and running, the overall architecture of its security protection may include a password verification module, a functional unit, a voltage monitoring module, an interface isolation unit and an external module, wherein the password verification module may be configured with a password verification circuit, the voltage monitoring module may be configured with a voltage detection circuit, the interface isolation unit may be configured with an authority verification circuit and a switch circuit, the functional unit includes a status monitoring module and a status recovery module, the status monitoring module may be configured with a data storage circuit and a comparison circuit, and the status recovery module may be configured with a recovery circuit.

[0268] In this embodiment, the functional units of the logic controller are locked by default when power is off or the system is reset. When the logic controller is powered on, each cryptographic circuit in the password verification circuit is first checked to ensure the correct function of each cryptographic circuit. If each cryptographic circuit passes the functional verification, an unlock signal (lock_sig = '0') is generated to unlock the functional units of the logic controller, thereby enabling normal system operation. If any cryptographic circuit fails the functional verification, the unlock signal is invalid, and the functional unit and system cannot operate.

[0269] The state monitoring module monitors the state machine's operating status. If the state machine encounters an external injection attack and experiences an anomaly, that is, if the state machine enters an irrelevant state during operation, it generates a fault signal, error_sig. Upon receiving the fault signal, the state recovery module restores the state machine from the irrelevant state to its normal state, eliminating the fault and restoring normal operation.

[0270] The interface isolation unit can be configured with Figure 23 or Figure 24 The permission check circuit shown in FIG. , wherein the permission check circuit may include one or more components with on / off functions, such as a bidirectional tri-state buffer Bi_Tri or a line switch MUX, whose on / off state is controlled by an enable signal enable_sig, wherein the logic controller is in the blocked state. When the logic controller is unlocked, when the enable signal is valid, the interface isolation unit is turned on, and an external module (such as memory) can transfer data with the logic controller's internal storage area, such as ROM, via the logic controller's input / output port line IO, including the external module reading data from the ROM or writing data to the ROM. When the enable signal is invalid, the interface isolation unit is blocked, and the data transmission path between the ROM and the external module is blocked, and data transmission cannot be carried out.

[0271] The permission verification module can be used to authenticate the user's identity. Only when a legitimate user enters the correct instruction (such as a password) will the enable signal generated be a valid value, such as the verification signal enable_sig='1'; when an incorrect instruction is entered, the enable signal generated is an invalid value, such as the verification signal enable_sig='0', thereby preventing the operating object from reading the key information stored inside the logic controller through the input and output port lines IO of the logic controller.

[0272] The voltage monitoring module can be used to monitor the IO voltage range output by the logic controller. The high and low levels are determined by setting thresholds. When the monitored level is outside the threshold range and exceeds the set duration, it is determined that a metastable level has occurred, indicating that the system may have encountered a voltage injection attack. At this time, the security control signal is enabled, such as lock_sig = '1', to lock the functional units of the logic controller to prevent voltage injection attacks from damaging system functions and tampering with data.

[0273] Figure 26 A schematic diagram of the architecture of an interface isolation unit according to a specific embodiment of the present application is shown.

[0274] like Figure 26 As shown, in order to improve the integration of modules on the board and simplify the board-level structure, Figure 26 The interface isolation unit can also be set inside the logic controller.

[0275] Figure 27 A schematic diagram showing the functional implementation of the status monitoring module and the status recovery module according to a specific embodiment of the present application is shown.

[0276] like Figure 27 As shown, in this specific embodiment, the state machine consists of N states: State 1, State 2, ..., State n. State encoding uses a one-hot method, and there are N trigger conditions 1-n. When the logic controller is reset (e.g., RSTn = '0') or the safety control signal is valid (lock_sig = '1'), the state machine enters State 1. When the reset process ends (e.g., RSTn = '1'), the safety control signal is invalid (e.g., lock_sig = '0'), and trigger condition 1 occurs, the state machine enters State 2. With each subsequent trigger condition, the state machine enters the next state, cyclically transitioning until it returns to State 1. Abnormal trigger conditions, such as the injection of abnormal signals, can cause the state machine to enter an unrelated state, leading to failure.

[0277] In this specific embodiment, the state monitoring module is used to obtain the current state code value Code[n..0] (n=1, 2, …, N-1) of the state machine, where the number of states is N. It then detects the number of '1' bits cnt in Code[n..0]. When cnt=1 and the state code value is the expected value, the state machine is operating normally and outputs a fault signal error_sig='0', indicating an invalid state and no fault. When cnt=0 or cnt>1, the state code value is an irrelevant state code value, or when cnt=1 but the state code value is an unexpected value, the state machine is operating abnormally and outputs a fault signal error_sig='1', indicating a valid state and a fault. Subsequently, when the state recovery module detects the fault signal error_sig='1', it replaces the current irrelevant state code value with the known state code value State_Code[n], thereby recovering the state machine from the fault.

[0278] According to an embodiment of the present application, when the authority verification circuit outputs a verification signal indicating that the identity authentication has passed, the first end of the switch circuit and the second end of the switch circuit are controlled to be turned on, so that the logic controller can send a port mapping matrix to a processor outside the logic controller through the switch circuit; wherein the port mapping matrix indicates the mapping relationship between the bits of the data to be sent in the logic controller and the transmission port.

[0279] In this embodiment, because data is typically sent through a set of consecutive ports IO[n-1..0], there is a problem that the data is easily monitored and intercepted. The operating object can obtain continuous byte data through IO[n-1..0], resulting in information leakage. Therefore, a random matrix is ​​used to map the IO port numbers, and the byte data is transmitted bit by bit to IO ports with non-contiguous port numbers for transmission, making it more difficult for the operating object to intercept and analyze the data.

[0280] Figure 28 A schematic diagram of the architecture of an interface isolation unit according to a specific embodiment of the present application using an IO port random mapping method for data transmission is shown.

[0281] like Figure 28 As shown, in this specific embodiment, a random matrix can be established , (i, j = 0, 1, ..., n-1), randomly map the port number p (p = 0, 1, ..., n-1) of the original continuous port IO (p) to the matrix R ij The element r ij In order to prevent the port numbers from being repeated after mapping, it is necessary to map the port numbers 0 to n-1 to the matrix R. ij In the upper triangular elements or lower triangular elements of , which means mapping to R ij the upper triangular elements of ; or , which represents the lower triangular elements mapped to Rij.

[0282] According to the matrix R ij The mapped elements in are used to calculate the new port number after mapping according to the following formula (5):

[0283] Y p =(i+1)×(j+1), (p=0,1,…,n-1)(5);

[0284] Where Y p Represents the new port number, and p represents the port number of the original continuous port IO(p).

[0285] When data is sent to an external module, each bit is sent from the corresponding IO port according to the mapped port number; when the external module writes data to the logic controller, the mapped port number is obtained through the random matrix and the data is transmitted through the corresponding IO port. Taking the transmission of 1 byte data (8 bits) as an example, the data to be sent is Data[7..0], the original IO port number is 0~7, and the random matrix , (i, j = 0, 1, ..., 7). Randomly map port numbers 0 to 7 to R ij The upper triangular elements in, for example, the mapping relationship of the specific elements is: 56 =0, r 14 =1, r 25 =2, r 37 =3, r 45 =4, r 06 =5, r 67 =6, r 77 =7, the remaining unmapped elements r ij =0. According to formula (5), the new port number after mapping is: , Y1=10, Y2=18, Y3=32, Y4=30, Y5=7, Y6=56, Y7=64; then perform duplicate port detection, that is, if the mapped port number is repeated, the port number needs to be reassigned until the port number is not repeated. For example, if the original port number 0 is mapped to r 07 , port number 1 is mapped to r 13 When the port number after mapping is calculated according to formula (5), it is 8, then the port needs to be remapped, for example, mapping port number 1 to r 14, the mapped port number is 10, which does not overlap with 8, and this continues until the mapped port number does not overlap. Afterwards, bit Data(0) in the data Data is sent through port IO(42), Data(1) is sent through IO(10), ..., Data(7) is sent through IO(64).

[0286] Based on this, the embodiment of the present application establishes a dynamic mapping relationship between the data bits in the logic controller and the non-continuous IO ports through a random matrix, effectively solving the problem that data is easily monitored and intercepted in traditional continuous port transmission. Specifically, the upper triangle or lower triangle matrix mapping strategy is used to ensure the uniqueness of the port number, and a discrete new port number is generated by calculation, so that each bit of the byte data is dispersed to the non-continuous port for transmission. When data is transmitted in the form of bits through the non-continuous port after random mapping, the operating object needs to monitor multiple irregular ports at the same time to restore the data, which significantly increases the difficulty of interception analysis. Combined with the repeated port detection and dynamic update strategy, the ability to resist side channel attacks is further improved, and the security of the data transmission layer of the logic controller is enhanced.

[0287] The flowcharts and block diagrams in the accompanying drawings illustrate the possible implementation architecture, functions and operations of the systems, methods and computer program products according to various embodiments of the present application. In this regard, each box in the flowchart or block diagram can represent a module, program segment, or a part of code, and the above-mentioned module, program segment, or a part of code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in an order different from that marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram or flowchart, and the combination of the boxes in the block diagram or flowchart, can be implemented with a dedicated hardware-based system that performs the specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.

[0288] Those skilled in the art will appreciate that the features described in the various embodiments of this application may be combined and / or coupled in various ways, even if such combinations or couplings are not explicitly described in this application. In particular, the features described in the various embodiments of this application may be combined and / or coupled in various ways without departing from the spirit and teachings of this application. All such combinations and / or couplings fall within the scope of this application.

[0289] The embodiments of the present application have been described above. However, these embodiments are for illustrative purposes only and are not intended to limit the scope of the present application. Although each embodiment has been described separately above, this does not mean that the measures in each embodiment cannot be advantageously used in combination. Without departing from the scope of the present application, those skilled in the art may make various substitutions and modifications, and these substitutions and modifications should all fall within the scope of the present application.

Claims

1. A state restorer for a logic controller, characterized in that: The state restorer comprises: a data register circuit configured to register an nth state code of a state machine in a logic controller and input the nth state code to the state machine to trigger the state machine to switch from the nth state code to an n+1th state code, where n is a positive integer greater than or equal to 1; a comparison circuit configured to compare the nth state code output by the data register circuit with the (n+1)th state code output by the state machine to obtain a control signal; a recovery circuit configured to, when the control signal indicates that the (n+1)th state code is an abnormal code, control the state machine to switch from the (n+1)th state code to a predetermined normal state code according to the control signal; The recovery circuit comprises: a logic sub-circuit, wherein two input terminals of the logic sub-circuit are electrically connected to the reset terminal of the state machine and the output terminal of the comparison circuit respectively, and the output terminal of the logic sub-circuit is electrically connected to the enable terminal of the switch sub-circuit; The switch subcircuit, wherein a first terminal of the switch subcircuit is electrically connected to a memory storing the predetermined normal state code, and a second terminal of the switch subcircuit is electrically connected to an input terminal of the state machine; The switch subcircuit is configured to connect the first end and the second end to transmit the predetermined normal state code to the state machine when the control signal indicates that the n+1th state code is an abnormal code or the state machine is in a reset process.

2. The state restorer according to claim 1, characterized in that The comparison circuit includes: a plurality of comparison sub-circuits and an output sub-circuit connected to the plurality of comparison sub-circuits, wherein the number of the comparison sub-circuits is the same as the number of bits of the state code output by the state machine; The comparison sub-circuit is configured to compare the code value located at the same bit position in the nth state code and the n+1th state code, and output a first comparison sub-signal; The output sub-circuit is configured to obtain the control signal according to a plurality of the first comparison sub-signals.

3. The state restorer according to claim 2, characterized in that The data register circuit includes a plurality of data register sub-circuits, and the number of the data register sub-circuits is the same as the number of bits of the state code output by the state machine; For the data register sub-circuit corresponding to the i-th bit, the input end of the data register sub-circuit is electrically connected to the output end of the state machine to obtain the code value of the i-th bit, where i is a non-negative integer; The output end of the data register sub-circuit is electrically connected to the input end of the state machine and the comparison sub-circuit corresponding to the i-th bit.

4. The state restorer according to claim 2 or 3, characterized in that: The comparison sub-circuit includes: a first AND gate, a second AND gate, a first NOT gate, and a data strobe electrically connected to the output ends of the first AND gate and the second AND gate; A first input terminal of the first AND gate is electrically connected to the output terminal of the state machine, and a second input terminal is electrically connected to the output terminal of the data register sub-circuit; The input terminal and the output terminal of the first NOT gate are electrically connected to the output terminal of the data register sub-circuit and the first input terminal of the second AND gate respectively; The second input terminal of the second AND gate is electrically connected to the output terminal of the state machine.

5. The state restorer according to claim 2, characterized in that The output sub-circuit comprises: a first OR gate, wherein a plurality of input terminals of the first OR gate are electrically connected to the plurality of comparison sub-circuits respectively, and an output terminal of the first OR gate is electrically connected to a first input terminal of a third AND gate; a pull-up resistor, one end of which is electrically connected to the output end of the first OR gate and the other end of which is electrically connected to the power output end, the pull-up resistor being configured to pull up the electrical signal indicating the first abnormal state output by the first OR gate using the voltage signal at the power output end; A third AND gate, wherein the second input terminal of the third AND gate is electrically connected to a power supply outputting a high-level signal, so as to obtain the control signal according to the electrical signal output by the first OR gate and the high-level signal.

6. The state restorer according to claim 1, characterized in that The recovery circuit comprises: a switch subcircuit, wherein a first terminal of the switch subcircuit is electrically connected to a memory storing the predetermined normal state code, a second terminal of the switch subcircuit is electrically connected to an input terminal of the state machine, and an enable terminal of the switch subcircuit is electrically connected to an output terminal of the comparison circuit; The switch subcircuit is configured to, when the control signal indicates that the (n+1)th state code is an abnormal code, connect the first end and the second end according to the control signal to transmit the predetermined normal state code to the state machine.

7. The state restorer according to claim 1, characterized in that The state restorer further includes: A reset circuit, wherein a first end of the reset circuit is used to receive a reset signal and a safety control signal, and a second end of the reset circuit is electrically connected to a reset end of the data register circuit and a reset end of the state machine. The reset circuit is configured to reset the data register circuit and the state machine when the reset signal indicates that the state machine is in a reset process or the safety control signal indicates that the logic controller is in a locked state.

8. The state restorer according to claim 7, characterized in that The reset circuit includes: a second NOT gate and a second OR gate, One end of the second NOT gate is used to receive the reset signal, and the other end is electrically connected to the first input end of the second OR gate; The second input end of the second OR gate is used to receive the safety control signal, and the output end of the second OR gate is electrically connected to the reset end of the data register circuit and the reset end of the state machine.

9. The state restorer according to claim 7, characterized in that: The security control signal is obtained by at least one of the following methods: verifying the password circuit in the logic controller, or detecting the output voltage of the logic controller.

10. The state restorer according to claim 9, characterized in that: The state restorer further includes: a password verification circuit configured to perform parallel verification on the plurality of password circuits of the logic controller when the logic controller is powered on to obtain the security control signal; Among them, when the verification of multiple cryptographic circuits is passed, a security control signal is generated to control the logic controller to be in an unlocked state; when the verification of any cryptographic circuit among the multiple cryptographic circuits is failed, a security control signal is generated to control the logic controller to be in a locked state.

11. The state restorer according to claim 10, characterized in that: The password verification circuit includes: a plurality of security comparison sub-circuits, wherein each first input terminal of each of the plurality of security comparison sub-circuits is electrically connected to the output terminals of the plurality of cryptographic circuits, and each second input terminal of each of the plurality of security comparison sub-circuits is electrically connected to the output terminal of the ciphertext processing circuit; the security comparison sub-circuits are configured to compare the encrypted data output by the cryptographic circuit with the ciphertext data output by the ciphertext processing circuit to obtain a second comparison sub-signal; A parallel verification subcircuit, wherein the multiple input terminals of the parallel verification subcircuit are electrically connected to the output terminals of the multiple security comparison subcircuits and the reset signal respectively, and the output terminal of the parallel verification subcircuit is used to output the security control signal; the parallel verification subcircuit is configured to obtain the security control signal based on the second comparison sub-signals output by the multiple security comparison subcircuits.

12. The state restorer according to claim 11, characterized in that The ciphertext processing circuit includes at least one of the following: The memory inside the logic controller is configured to: store ciphertext data corresponding to input data of the plurality of cryptographic circuits; A ciphertext processing circuit is provided outside the logic controller, and the ciphertext processing circuit is configured to encrypt the input data of each of the multiple cipher circuits using an encryption algorithm corresponding to the multiple cipher circuits to obtain ciphertext data corresponding to the input data of the multiple cipher circuits.

13. The state restorer according to claim 12, characterized in that: The input data includes data generated by a random number algorithm and passing a randomness test.

14. The state restorer according to claim 9, characterized in that: The state restorer further includes: A voltage detection circuit, wherein a first end of the voltage detection circuit is electrically connected to the voltage output end of the logic controller, and a second end of the voltage detection circuit is electrically connected to the safety control signal of the reset circuit; the voltage detection circuit is configured to detect the output voltage of the logic controller and obtain the safety control signal.

15. The state restorer according to claim 14, characterized in that: The voltage detection circuit comprises: a first voltage comparison subcircuit configured to compare the output voltage of the logic controller with an upper voltage limit and a lower voltage limit, respectively, to obtain the safety control signal; wherein the upper voltage limit and the lower voltage limit are adjusted based on a variable resistor in the first voltage comparison subcircuit; Wherein, when the output voltage is between the voltage upper limit value and the voltage lower limit value, a safety control signal for controlling the logic controller to be in a locked state is obtained; when the output voltage is not between the voltage upper limit value and the voltage lower limit value, a safety control signal for controlling the logic controller to be in an unlocked state is obtained.

16. The state restorer according to claim 14, characterized in that The voltage detection circuit comprises: a second voltage comparison subcircuit configured to compare the output voltage of the logic controller with an upper voltage limit and a lower voltage limit, respectively, to generate a voltage comparison signal; wherein the upper voltage limit and the lower voltage limit are adjusted based on a variable resistor in the second voltage comparison circuit; a first timing circuit configured to, when the voltage comparison signal indicates that the output voltage is between the voltage upper limit and the voltage lower limit, record the abnormal duration of the output voltage under the triggering of the voltage comparison signal; The alarm circuit is configured to compare the abnormality duration with a first predetermined duration to obtain the safety control signal, wherein, when the abnormality duration exceeds the first predetermined duration, a safety control signal for controlling the logic controller to be in a locked state is obtained; when the abnormality duration does not exceed the first predetermined duration, a safety control signal for controlling the logic controller to be in an unlocked state is obtained.

17. The state restorer according to claim 1, characterized in that The state restorer further includes: An authority verification circuit, wherein the first data input terminal, the second data input terminal, and the third data input terminal of the authority verification circuit are respectively used to receive verification information from the memory in the logic controller, identity information output by the host computer, and a security control signal, and the output terminal of the authority verification circuit is electrically connected to the enable terminal of the switch circuit; The switch circuit has a first end electrically connected to the output end of the logic controller, and a second end electrically connected to a processor located outside the logic controller, wherein the switch circuit is configured to control the first end of the switch circuit and the second end of the switch circuit to be conductive when the authority verification circuit outputs a verification signal indicating that identity authentication has passed; In which, the authority verification circuit is configured to: output a verification signal indicating that identity authentication is passed when the verification passes and the security control signal indicates that the logic controller is in an unlocked state; and output a verification signal indicating that identity authentication is failed when the duration of the verification passing is greater than a second predetermined time length.

18. The state restorer according to claim 17, characterized in that: The authority verification circuit includes: a comparator, wherein a first input terminal of the comparator is electrically connected to the memory in the logic controller, a second input terminal of the comparator is electrically connected to the host computer, and an output terminal of the comparator is electrically connected to the trigger terminal of the timer and the first input terminal of the fourth AND gate; a third NOT gate, wherein an input end of the third NOT gate is used to receive the safety control signal, and an output end of the third NOT gate is electrically connected to the second input end of the fourth AND gate; The fourth AND gate, wherein the output terminal of the fourth AND gate is electrically connected to the first input terminal of the fifth AND gate; The timer, wherein the output terminal of the timer is electrically connected to the second input terminal of the fifth AND gate; The fifth AND gate has an output terminal electrically connected to the enable terminal of the switch circuit.

19. The state restorer according to claim 17, characterized in that: When the authority verification circuit outputs a verification signal indicating that identity authentication is passed, controlling the first end of the switch circuit and the second end of the switch circuit to be conductive, so that the logic controller can send a port mapping matrix to a processor outside the logic controller through the switch circuit; The port mapping matrix indicates the mapping relationship between the bits of the data to be sent and the transmission ports in the logic controller.

Citation Information

Patent Citations

  • Method for early alarming by-path attack in safety chip

    CN101382978A

  • State machine circuit and state adjustment method

    CN103346769A