OTP key storage method and system, medium and program product
By encrypting the OTP key using the physical non-clone function PUF and the national secret algorithm SM4 in the SoC chip, the OTP key storage security problem is solved and the secure storage of the key is realized.
Patent Information
- Application Number
- CN202510803115.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-16
- Publication Date
- 2025-08-12
AI Technical Summary
In the prior art, OTP keys are stored in plain text or encrypted in SoC chips and are insecure, and there is a risk of being leaked by reverse engineering.
The physically uncloned function PUF is used as the encryption key, and the OTP key is encrypted using the national secret algorithm SM4, and the encrypted key is stored in the OTP. The SM4 register is configured through the ATE machine or CPU to perform the encryption phase.
Eliminate the risk of key plaintext storage being leaked and enhances the security of OTP key storage.
Smart Images

Figure CN120474689A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of key storage, and in particular to an OTP key storage method, system, medium and program product. Background Art
[0002] With the rapid development of IoT (Internet of Things) and artificial intelligence technologies, the security and reliability of chip data storage are becoming increasingly important. This has led to the widespread application of OTP (One-Time Programmable) devices in embedded SoC (System on Chip) chips. As a non-volatile memory device, OTP is a one-time programmable device with high reliability, strong stability, and radiation resistance. Once programmed, data is permanently stored for the life of the OTP, immune to external interference and tampering. In existing technologies, the key stored in the OTP is plain text and not encrypted, or the encryption method is not secure, posing the risk of leakage through reverse engineering. Summary of the Invention
[0003] The purpose of the present invention is to overcome the deficiencies of the prior art and to provide an OTP key storage method, system, medium and program product.
[0004] The object of the present invention is achieved through the following technical solutions: In a first aspect, the present invention provides: an OTP key storage method for a SoC security system, comprising the following steps: During the initialization phase, the load board of the test equipment is powered on, and then the external global reset of the chip is released; During the encryption phase, the key programming test sequence is run, using the physically unclonable function (PUF) as the encryption key for each key. Each key is encrypted using the national secret algorithm and the encrypted key is stored in the OTP. During the testing phase, a root key test is performed to determine whether the root key test passes. If the root key test passes, the chip is judged to be a good product and other chip tests are continued. If the root key test fails, the chip is judged to be a defective product.
[0005] Preferably, the SoC security system includes: CPU component, the CPU component is connected to the AHB2CFG component, the AHB2CFG component is connected to the CFG_ARB component, the CFG_ARB component is connected to the ATE_RW_REG component and the CFG_DEC component; the ATE_RW_REG component is connected to the TAP_CTRL component, the TAP_CTRL component is connected to the JTAG component; the CFG_DEC component is connected to the OTP_CTRL component, the TRNG component and the SM4 component, the OTP_CTRL component is connected to the PUF_OTP component, the TRNG component and the SM4 component, and the TRNG component is connected to the SM4 component; The CPU component is used to control the operation process, implement security policies and manage keys of the SoC security system; The AHB2CFG component is used to convert the AHB bus into a configuration register bus; The CFG_ARB component is used to perform polling arbitration operations on different register operation masters. In the ATE test scenario, only the ATE_RW_REG component is allowed to read and write SoC registers. The ATE_RW_REG component is used to convert the JTAG bus protocol into a SoC private register read and write control bus. During ATE testing, the registers of the components required for the test are configured through the JTAG component. The CFG_DEC component is used to decode register read and write addresses and route register read and write requests to various target components; The TAP_CTRL component is used to implement the JTAG protocol according to the JTAG signal and communicate with the ATE_RW_REG component; The JTAG component is used to physically connect the JTAG pin to the ATE machine; The OTP_CTRL component is used to implement read and write operations, rights management and CPU command processing of the PUF_OTP component; The TRNG component is used to generate true random numbers; The SM4 component is used to encrypt and decrypt data; The PUF_OTP component is used to store chip PUF value, chip ID information, simulated IP verification value, firmware information and various keys.
[0006] Preferably, the encryption stage further comprises the following steps: The SM4 component initiates a request to the TRNG component to obtain a random number as the plaintext of the root key and temporarily stores this random number in the SM4 component; The SM4 component reads the PUF value of the PUF_OTP component as the encryption key and temporarily stores it in the SM4 component; The SM4 component uses the PUF value to encrypt the plaintext of the root key and writes the encrypted root key into the root key area of the OTP_CTRL component; After the OTP_CTRL component operation is completed, the SM4 component automatically clears the process information temporarily stored in the hardware and returns the result of the successful completion of the command to the SM4 status register; The test equipment reads the successful completion status value of the SM4 status register, confirming that the encrypted root key has been written to the OTP_CTRL component and the encryption is complete.
[0007] Preferably, the testing equipment is an ATE machine or a CPU.
[0008] Preferably, when the test device is an ATE machine, the encryption phase is performed by configuring the SM4 register through the JTAG component; when the test device is a CPU, the encryption phase is performed directly by configuring the SM4 register through the CPU.
[0009] A second aspect of the present invention provides: an OTP key storage system for implementing any of the above-mentioned OTP key storage methods, comprising: Initialization module, used to power on the load board of the test equipment and then release the external global reset of the chip; The encryption phase module is used to run the key programming test sequence, use the physical unclonable function PUF as the encryption key for each key, encrypt each key using the national secret algorithm, and store the encrypted key in the OTP; The test phase module is used to perform root key testing to determine whether the root key test passes. If the root key test passes, the chip is judged to be good and other chip tests are continued. If the root key test fails, the chip is judged to be defective.
[0010] A third aspect of the present invention provides: a computer-readable storage medium, wherein the computer-readable storage medium stores computer-executable instructions, and when the computer-executable instructions are loaded and executed by a processor, any of the above-mentioned OTP key storage methods is implemented.
[0011] A fourth aspect of the present invention provides: a computer program product comprising instructions, which, when running on a terminal, enables the terminal to execute any one of the above-mentioned OTP key storage methods.
[0012] The beneficial effects of the present invention are: 1) SM4 is configured on an ATE machine or CPU, and a physically unclonable function (PUF) is used for encryption and triggering OTP programming, eliminating the risk of key plaintext storage being leaked in existing solutions. BRIEF DESCRIPTION OF THE DRAWINGS
[0013] Figure 1 This is the functional block diagram of the SoC security system. DETAILED DESCRIPTION
[0014] The following will clearly and completely describe the technical solutions of the present invention in conjunction with the embodiments. Obviously, the embodiments described are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative work shall fall within the scope of protection of the present invention.
[0015] See Figure 1 The first aspect of the present invention provides: an OTP key storage method for a SoC security system, comprising the following steps: During the initialization phase, the load board of the test equipment is powered on, and then the external global reset of the chip is released; During the encryption phase, the key programming test sequence is run, using the physically unclonable function (PUF) as the encryption key for each key. Each key is encrypted using the national secret algorithm and the encrypted key is stored in the OTP. During the testing phase, a root key test is performed to determine whether the root key test passes. If the root key test passes, the chip is judged to be a good product and other chip tests are continued. If the root key test fails, the chip is judged to be a defective product.
[0016] In this embodiment, a PUF is used as the encryption key for each key in the OTP. Each key is encrypted using the national secret algorithm SM4 and stored in the OTP. This ensures encrypted key storage, eliminating the risk of key leakage through reverse engineering and other means, significantly enhancing key storage security. PUF (Physically Unclonable Function) is a recently emerging technology. PUFs are designed based on subtle variations in wafer fabrication processes. These manufacturing variations result in the values stored in the PUF being truly random and unpredictable. An ideal physically unclonable function (PUF) has a Hamming weight of 50%, meaning that the probability of a 0 or 1 appearing in each PUF physical cell is equal. These properties make PUFs ideal for use as physical fingerprints or root keys for chips.
[0017] In some embodiments, the SoC security system includes: CPU component, the CPU component is connected to the AHB2CFG component, the AHB2CFG component is connected to the CFG_ARB component, the CFG_ARB component is connected to the ATE_RW_REG component and the CFG_DEC component; the ATE_RW_REG component is connected to the TAP_CTRL component, the TAP_CTRL component is connected to the JTAG component; the CFG_DEC component is connected to the OTP_CTRL component, the TRNG component and the SM4 component, the OTP_CTRL component is connected to the PUF_OTP component, the TRNG component and the SM4 component, and the TRNG component is connected to the SM4 component; The CPU component is used to control the operation process, implement security policies and manage keys of the SoC security system; The AHB2CFG component is used to convert the AHB bus into a configuration register bus; The CFG_ARB component is used to perform polling arbitration operations on different register operation masters. In the ATE test scenario, only the ATE_RW_REG component is allowed to read and write SoC registers. The ATE_RW_REG component is used to convert the JTAG bus protocol into a SoC private register read and write control bus. During ATE testing, the registers of the components required for the test are configured through the JTAG component. The CFG_DEC component is used to decode register read and write addresses and route register read and write requests to various target components; The TAP_CTRL component is used to implement the JTAG protocol according to the JTAG signal and communicate with the ATE_RW_REG component; The JTAG component is used to physically connect the JTAG pin to the ATE machine; The OTP_CTRL component is used to implement read and write operations, rights management and CPU command processing of the PUF_OTP component; The TRNG component is used to generate true random numbers; The SM4 component is used to encrypt and decrypt data; The PUF_OTP component is used to store chip PUF value, chip ID information, simulated IP verification value, firmware information and various keys.
[0018] In some embodiments, the encryption stage further includes the following steps: The SM4 component initiates a request to the TRNG component to obtain a random number as the plaintext of the root key and temporarily stores this random number in the SM4 component; The SM4 component reads the PUF value of the PUF_OTP component as the encryption key and temporarily stores it in the SM4 component; The SM4 component uses the PUF value to encrypt the plaintext of the root key and writes the encrypted root key into the root key area of the OTP_CTRL component; After the OTP_CTRL component operation is completed, the SM4 component automatically clears the process information temporarily stored in the hardware and returns the result of the successful completion of the command to the SM4 status register; The test equipment reads the successful completion status value of the SM4 status register, confirming that the encrypted root key has been written to the OTP_CTRL component and the encryption is complete.
[0019] In some embodiments, the testing equipment is an ATE machine or a CPU.
[0020] In this embodiment, the present invention provides two OTP key programming methods: ATE (Automatic Test Equipment) programming and CPU programming. CPU programming is similar to ATE programming, differing in that the CPU configures the SM4 registers to implement the programming process, while ATE programming uses JTAG to configure the SM4 registers.
[0021] In some embodiments, when the test device is an ATE machine, the encryption phase is executed by configuring the SM4 register through the JTAG component; when the test device is a CPU, the encryption phase is executed by directly configuring the SM4 register through the CPU.
[0022] A second aspect of the present invention provides: an OTP key storage system for implementing any of the above-mentioned OTP key storage methods, comprising: Initialization module, used to power on the load board of the test equipment and then release the external global reset of the chip; The encryption phase module is used to run the key programming test sequence, use the physical unclonable function PUF as the encryption key for each key, encrypt each key using the national secret algorithm, and store the encrypted key in the OTP; The test phase module is used to perform root key testing to determine whether the root key test passes. If the root key test passes, the chip is judged to be good and other chip tests are continued. If the root key test fails, the chip is judged to be defective.
[0023] A third aspect of the present invention provides: a computer-readable storage medium, wherein the computer-readable storage medium stores computer-executable instructions, and when the computer-executable instructions are loaded and executed by a processor, any of the above-mentioned OTP key storage methods is implemented.
[0024] A fourth aspect of the present invention provides: a computer program product comprising instructions, which, when running on a terminal, enables the terminal to execute any one of the above-mentioned OTP key storage methods.
[0025] The foregoing description is merely a preferred embodiment of the present invention. It should be understood that the present invention is not limited to the form disclosed herein and should not be construed as excluding other embodiments. Rather, the present invention can be used in various other combinations, modifications, and environments and can be modified within the scope of the concept described herein through the above teachings or techniques or knowledge in the relevant field. Modifications and variations made by those skilled in the art that do not depart from the spirit and scope of the present invention are intended to be protected by the appended claims.
Claims
1. An OTP key storage method, characterized in that: For SoC security system, including the following steps: During the initialization phase, the load board of the test equipment is powered on, and then the external global reset of the chip is released; During the encryption phase, the key programming test sequence is run, using the physically unclonable function (PUF) as the encryption key for each key. Each key is encrypted using the national secret algorithm and the encrypted key is stored in the OTP. During the testing phase, a root key test is performed to determine whether the root key test passes. If the root key test passes, the chip is judged to be a good product and other chip tests are continued. If the root key test fails, the chip is judged to be a defective product.
2. The OTP key storage method according to claim 1, wherein: The SoC security system includes: CPU component, the CPU component is connected to the AHB2CFG component, the AHB2CFG component is connected to the CFG_ARB component, the CFG_ARB component is connected to the ATE_RW_REG component and the CFG_DEC component; the ATE_RW_REG component is connected to the TAP_CTRL component, the TAP_CTRL component is connected to the JTAG component; the CFG_DEC component is connected to the OTP_CTRL component, the TRNG component and the SM4 component, the OTP_CTRL component is connected to the PUF_OTP component, the TRNG component and the SM4 component, and the TRNG component is connected to the SM4 component; The CPU component is used to control the operation process, implement security policies and manage keys of the SoC security system; The AHB2CFG component is used to convert the AHB bus into a configuration register bus; The CFG_ARB component is used to perform polling arbitration operations on different register operation masters. In the ATE test scenario, only the ATE_RW_REG component is allowed to read and write SoC registers. The ATE_RW_REG component is used to convert the JTAG bus protocol into a SoC private register read and write control bus. During ATE testing, the registers of the components required for the test are configured through the JTAG component. The CFG_DEC component is used to decode register read and write addresses and route register read and write requests to various target components; The TAP_CTRL component is used to implement the JTAG protocol according to the JTAG signal and communicate with the ATE_RW_REG component; The JTAG component is used to physically connect the JTAG pin to the ATE machine; The OTP_CTRL component is used to implement read and write operations, rights management and CPU command processing of the PUF_OTP component; The TRNG component is used to generate true random numbers; The SM4 component is used to encrypt and decrypt data; The PUF_OTP component is used to store chip PUF value, chip ID information, simulated IP verification value, firmware information and various keys.
3. The OTP key storage method according to claim 1, wherein: The encryption phase further comprises the following steps: The SM4 component initiates a request to the TRNG component to obtain a random number as the plaintext of the root key and temporarily stores this random number in the SM4 component; The SM4 component reads the PUF value of the PUF_OTP component as the encryption key and temporarily stores it in the SM4 component; The SM4 component uses the PUF value to encrypt the plaintext of the root key and writes the encrypted root key into the root key area of the OTP_CTRL component; After the OTP_CTRL component operation is completed, the SM4 component automatically clears the process information temporarily stored in the hardware and returns the result of the successful completion of the command to the SM4 status register; The test equipment reads the successful completion status value of the SM4 status register, confirming that the encrypted root key has been written to the OTP_CTRL component and the encryption is complete.
4. The OTP key storage method according to any one of claims 1 to 3, characterized in that: The testing equipment is an ATE machine or a CPU.
5. The OTP key storage method according to claim 4, wherein: When the test device is an ATE machine, the encryption phase is executed by configuring the SM4 register through the JTAG component; when the test device is a CPU, the encryption phase is executed by directly configuring the SM4 register through the CPU.
6. An OTP key storage system, characterized in that: The method for implementing the OTP key storage method according to any one of claims 1 to 5 comprises: Initialization module, used to power on the load board of the test equipment and then release the external global reset of the chip; The encryption phase module is used to run the key programming test sequence, use the physical unclonable function PUF as the encryption key for each key, encrypt each key using the national secret algorithm, and store the encrypted key in the OTP; The test phase module is used to perform root key testing to determine whether the root key test passes. If the root key test passes, the chip is judged to be good and other chip tests are continued. If the root key test fails, the chip is judged to be defective.
7. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer-executable instructions, and when the computer-executable instructions are loaded and executed by the processor, the OTP key storage method according to any one of claims 1 to 5 is implemented.
8. A computer program product comprising instructions, characterized in that: When the computer program product is run on a terminal, the terminal is enabled to execute the OTP key storage method according to any one of claims 1 to 5.