Dynamic encryption method and system for protecting data privacy of SoC chip

By identifying and applying encryption policies for multiple storage areas in the SoC chip and converting encryption policies during data migration, the problem of privacy leakage when data is migrated between multiple storage areas is solved, ensuring the security and integrity of data during storage and transmission.

CN120632917BActive Publication Date: 2025-10-17OPTEK MICROELECTRONICS CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511123547.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-08-12
Publication Date
2025-10-17
Estimated Expiration
2045-08-12

AI Technical Summary

Technical Problem

When data in SoC chips is migrated or mapped between multiple storage intervals, it is easy to lose its original encryption state or fall into untrusted areas, resulting in data privacy leakage.

Method used

By identifying the encryption policies of multiple storage areas of the SoC chip, and encrypting and storing data according to the encryption policy of the target storage area when writing data, encryption migration conversion is performed during data migration to ensure that the encryption policy is migrated as the data flows, and using the DMA controller to transfer data through the AXI bus to ensure that the data remains encrypted during storage and transmission.

Benefits of technology

It achieves full-process encryption coverage, improves the security and integrity of SoC chip data, and avoids the risk of data losing encryption protection during migration.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120632917B_ABST
    Figure CN120632917B_ABST
Patent Text Reader

Abstract

The application provides a dynamic encryption method and system for protecting data privacy of an SoC chip, and relates to the technical field of data processing. The method comprises the following steps: identifying a plurality of storage areas of the SoC chip; when to-be-written data is written into a first storage area, performing encryption storage based on a first encryption strategy; if it is detected that the to-be-written data is migrated to a second storage area, performing encryption migration conversion mechanism analysis based on a second encryption strategy and the first encryption strategy; and performing encryption according to a migration encryption strategy, and then migrating storage to the second storage area, and updating a label of the to-be-written data to a register under the second storage area. The application solves the technical problem that data privacy of the SoC chip is leaked due to the fact that the data is easily lost in the original encryption state or falls into a non-trusted area when being migrated or mapped among a plurality of storage areas in the prior art, realizes migration of the encryption strategy along with data flow, ensures full-process encryption coverage, and improves the security of data of the SoC chip.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of data processing, and particularly relates to a dynamic encryption method and system for protecting data privacy of an SoC chip. BACKGROUND

[0002] In an SoC chip, data is often migrated or mapped between multiple storage areas (such as SRAM, Cache, eFlash, DDR, register groups, etc.) to adapt to processor access, DMA operation, power consumption optimization and other scheduling requirements. When data is migrated from one storage area to another, if the target storage area adopts a different encryption strategy from the source storage area, or the target storage area itself lacks necessary encryption capability, the original encryption state may be lost in the migration process. The data may be stored in plaintext or in an unexpected encrypted form in the new location. In addition, the data may even accidentally fall into some lower security level or untrusted area inside the SoC, which is vulnerable to attacks or risks. Once the data loses effective encryption protection or is stored in an untrusted area, it is extremely easy to be accessed, stolen or tampered with by unauthorized entities inside the SoC, thus exposing sensitive information and causing serious privacy leakage risks and potential data security problems.

[0003] In summary, the prior art has the technical problem of SoC chip data privacy leakage due to the fact that data is easily lost in the original encryption state or falls into an untrusted area when migrated or mapped between multiple storage areas. SUMMARY

[0004] The purpose of the present application is to provide a dynamic encryption method and system for protecting data privacy of an SoC chip, to solve the technical problem of SoC chip data privacy leakage in the prior art due to the fact that data is easily lost in the original encryption state or falls into an untrusted area when migrated or mapped between multiple storage areas.

[0005] In view of the above problems, the present application provides a dynamic encryption method and system for protecting data privacy of an SoC chip.

[0006] In a first aspect, the application provides a dynamic encryption method for protecting data privacy of an SoC chip, which is implemented by a dynamic encryption system for protecting data privacy of an SoC chip. The dynamic encryption method for protecting data privacy of an SoC chip comprises the following steps: identifying a plurality of storage areas of an SoC chip, wherein the plurality of storage areas comprise a plurality of encryption policies; when data to be written is written into a first storage area, encrypting and storing the data to be written based on a first encryption policy corresponding to the first storage area, wherein the first storage area is any storage area of the plurality of storage areas; if it is detected that the data to be written is migrated to a second storage area, performing encryption migration conversion mechanism analysis based on a second encryption policy corresponding to the second storage area and the first encryption policy corresponding to the first storage area, and obtaining a migration encryption policy, wherein the second storage area is another storage area of the plurality of storage areas different from the first storage area; and migrating and storing the data to be written to the second storage area after encrypting the data to be written according to the migration encryption policy, and updating a tag of the data to be written to a register under the second storage area.

[0007] Optionally, the plurality of storage areas of the SoC chip perform data transmission through an AXI bus-based DMA controller.

[0008] Optionally, it is determined whether the first encryption policy and the second encryption policy are compatible; if the first encryption policy and the second encryption policy are compatible, the data to be written is multiplexed or encrypted by using the first encryption policy or the second encryption policy.

[0009] Optionally, if the first encryption policy and the second encryption policy are incompatible, encryption algorithm types, key systems, security levels and access domain parameters of the first encryption policy and the second encryption policy are identified; a compatible encryption policy set is constructed according to the encryption algorithm types, the key systems, the security levels and the access domain parameters of the first encryption policy and the second encryption policy; and each compatible encryption policy in the compatible encryption policy set is filtered, and a compatible encryption policy that simultaneously satisfies a first compatible condition and a second compatible condition is set as the migration encryption policy.

[0010] Optionally, the compatible encryption policy that simultaneously satisfies the first compatible condition and the second compatible condition is set as the migration encryption policy, wherein the first compatible condition is that the compatible encryption policy is identified and processed by the second storage area, and the second compatible condition is that the compatible encryption policy is identified and processed by the first storage area.

[0011] Optionally, if the number of compatible encryption strategies that meet both the first compatibility condition and the second compatibility condition is multiple, a compatibility test index is set, the compatibility test index including policy encryption efficiency, policy decryption efficiency, policy analysis delay, resource occupancy rate and policy invocation cost corresponding to each storage area; the compatible encryption strategies that meet both the first compatibility condition and the second compatibility condition are tested according to the compatibility test index, and the compatibility test data of the first storage area and the compatibility test data of the second storage area are obtained; the multiple compatibility test scores are obtained according to the compatibility test data of the first storage area and the compatibility test data of the second storage area; the first compatible encryption strategy that meets both the first compatibility condition and the second compatibility condition is set as the migration encryption strategy by screening among the multiple compatibility test scores.

[0012] Optionally, multiple compatibility judgment mechanisms are constructed, the multiple compatibility judgment mechanisms including encryption algorithm type matching judgment, key system consistency judgment, encryption mode consistency judgment, key access control domain matching judgment, and ciphertext format and header structure alignment judgment; when the results of each item in the multiple compatibility judgment mechanisms are returned as passed, a result that the first encryption strategy and the second encryption strategy are compatible is output; when at least one result in the multiple compatibility judgment mechanisms is returned as not passed, a result that the first encryption strategy and the second encryption strategy are incompatible is output.

[0013] Optionally, if it is detected that the to-be-written data is migrated from the second storage area to the first storage area; the to-be-written data is encrypted by reusing the migration encryption strategy and then stored in the first storage area, and the label of the to-be-written data is updated to the register under the first storage area.

[0014] Optionally, if it is detected that the to-be-written data is simultaneously migrated to multiple second storage areas, wherein the multiple second storage areas are multiple storage areas different from the first storage area in the multiple storage areas, and the multiple second storage areas are not the same; multiple migration encryption strategies corresponding to the multiple second storage areas are generated; the to-be-written data is encrypted according to the multiple migration encryption strategies and then respectively stored in the multiple second storage areas, and the label of the to-be-written data is synchronously updated to the registers under the multiple second storage areas.

[0015] In a second aspect, the present application also provides a dynamic encryption system for protecting data privacy of an SoC chip, for executing the dynamic encryption method for protecting data privacy of an SoC chip as described in the first aspect, wherein the dynamic encryption system for protecting data privacy of an SoC chip comprises: a storage area identification module, configured to identify a plurality of storage areas of the SoC chip, the plurality of storage areas comprising a plurality of encryption policies; a data encryption storage module, configured to, when to-be-written data is written into a first storage area, encrypt and store the to-be-written data based on a first encryption policy corresponding to the first storage area, wherein the first storage area is any storage area of the plurality of storage areas; a data migration encryption module, configured to, if it is detected that the to-be-written data is migrated to a second storage area, analyze an encryption migration conversion mechanism based on a second encryption policy corresponding to the second storage area and the first encryption policy corresponding to the first storage area, and obtain a migration encryption policy, wherein the second storage area is another storage area of the plurality of storage areas different from the first storage area; and a migration encryption storage module, configured to, after encrypting the to-be-written data according to the migration encryption policy, migrate and store the to-be-written data to the second storage area, and update a label of the to-be-written data to a register under the second storage area.

[0016] The one or more technical solutions provided in the present application have at least the following beneficial effects:

[0017] By identifying a plurality of storage areas of an SoC chip, the plurality of storage areas comprising a plurality of encryption policies; when to-be-written data is written into a first storage area, encrypting and storing the to-be-written data based on a first encryption policy corresponding to the first storage area, wherein the first storage area is any storage area of the plurality of storage areas; if it is detected that the to-be-written data is migrated to a second storage area, analyzing an encryption migration conversion mechanism based on a second encryption policy corresponding to the second storage area and the first encryption policy corresponding to the first storage area, and obtaining a migration encryption policy, wherein the second storage area is another storage area of the plurality of storage areas different from the first storage area; and after encrypting the to-be-written data according to the migration encryption policy, migrating and storing the to-be-written data to the second storage area, and updating a label of the to-be-written data to a register under the second storage area. That is, by identifying the encryption policies of the plurality of storage areas, and encrypting and storing the to-be-written data according to the encryption policy of the target storage area when the to-be-written data is written, and by performing migration encryption conversion according to the encryption policies of the migration-in and migration-out storage areas when the data is migrated, the encryption policy is migrated along with the data flow, full-process encryption coverage is ensured, and the security and integrity of the data of the SoC chip are improved.

[0018] The above description is only a summary of the technical solutions of the present application. In order to make the technical means of the present application more clearly understood and implemented according to the content of the specification, and in order to make the above and other purposes, characteristics and advantages of the present application more obvious and easy to understand, the specific embodiments of the present application are described below. It should be understood that the content described in this section is not intended to identify the key or important features of the embodiments of the present application, nor is it intended to limit the scope of the present application. Other features of the present application will become apparent from the following description. BRIEF DESCRIPTION OF DRAWINGS

[0019] In order to more clearly illustrate the technical solutions in the present application or the prior art, the following will briefly introduce the drawings needed to be used in the embodiments or the prior art description. Obviously, the drawings in the following description are only exemplary, and other drawings can be obtained by the provided drawings without creative labor for those skilled in the art.

[0020] Figure 1 The flowchart of the dynamic encryption method for protecting the data privacy of the SoC chip of the present application.

[0021] Figure 2 The structure diagram of the dynamic encryption system for protecting the data privacy of the SoC chip of the present application.

[0022] Explanation of reference signs: storage area identification module 11, data encryption storage module 12, data migration encryption module 13, migration encryption storage module 14. DETAILED DESCRIPTION

[0023] The present application provides a dynamic encryption method and system for protecting the data privacy of the SoC chip, which solves the technical problem of data privacy leakage of the SoC chip in the prior art due to the loss of original encryption state or falling into a non-trusted area when data is migrated or mapped between multiple storage areas. By identifying the encryption strategies of multiple storage areas and encrypting the data to be written according to the encryption strategy of the target storage area when writing, and by migrating and encrypting the data according to the encryption strategies of the migrated and migrated storage areas when migrating, the encryption strategy is migrated with the data flow, ensuring full-process encryption coverage and improving the security and integrity of the SoC chip data.

[0024] Below, the technical solutions in the present application will be described clearly and completely with reference to the drawings. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments of the present application. It should be understood that the present application is not limited by the example embodiments described herein. Based on the embodiments of the present application, all other embodiments obtained by those of ordinary skill in the art without creative work fall within the scope of protection of the present application. In addition, it should be noted that, for the convenience of description, only parts related to the present application are shown in the drawings, not all.

[0025] Embodiment one, please refer to the attached Figure 1 The present application provides a dynamic encryption method for protecting data privacy of a SoC chip, wherein the dynamic encryption method for protecting data privacy of a SoC chip is executed by a dynamic encryption system for protecting data privacy of a SoC chip, and specifically includes the following steps:

[0026] Identify a plurality of storage areas of the SoC chip, wherein the plurality of storage areas include a plurality of encryption strategies.

[0027] Further, the present application further includes the following steps:

[0028] The plurality of storage areas of the SoC chip perform data transmission through an AXI bus-based DMA controller.

[0029] Specifically, there are a plurality of storage areas inside the SoC chip for storing data written by the user. The SoC chip contains a plurality of storage areas (such as SRAM, Cache, eFlash, DDR, register group, etc.), and different storage areas may adopt different encryption strategies due to their different characteristics (such as access speed, security, power consumption, cost). For example, SRAM and Cache adopt lighter encryption to optimize performance, while eFlash and DDR adopt stronger encryption to protect stored firmware or sensitive data. SRAM is a static random access memory, which is a fast and short-term memory type, and is usually used for caching. Cache is a cache memory, which is located between the CPU and the main memory (such as DDR), and is used to temporarily store data and instructions that the CPU may need to access in the near future, so as to reduce the delay of accessing the main memory and improve the processing speed. eFlash is an embedded flash memory, a non-volatile memory, which does not lose data after power failure, and is commonly used to store firmware, operating system or user data, with relatively slow read and write speed. DDR is a double data rate synchronous dynamic random access memory, which is a commonly used main memory (RAM) in SoC, with large capacity but slower access speed than Cache, and needs to be refreshed regularly. The register group is a storage area for storing small data, which is usually used to store the values of registers for direct access by the CPU or other processing units.

[0030] When data is migrated from one storage area to another, the DMA controller needs to perform encryption migration conversion according to the encryption policies of the source and target storage areas. Assuming that data is migrated from Cache to eFlash, the DMA controller checks the encryption policies of the source and target storage areas and re-encrypts the data according to the required encryption level of the target storage area (eFlash). After the data migration is completed, it is ensured that the data is stored according to the encryption policy of the target storage area, and the tag information of the data is updated to facilitate subsequent access control and permission management.

[0031] Inside the SoC chip, multiple storage areas do not exist in isolation and need to frequently exchange data. When data needs to be transmitted between multiple storage areas, a DMA controller is used to coordinate data transmission. The DMA controller transmits data through the AXI bus, meaning that data can be directly migrated from one storage area to another without the intervention of the CPU. The DMA controller is a direct memory access controller, a hardware component that allows peripherals (or memory regions) to directly transmit data with the system memory or other memory regions without the continuous intervention of the CPU, improving data transmission efficiency and freeing up CPU resources. The AXI bus provides a high-bandwidth transmission path, allowing multiple storage areas to efficiently transmit data in parallel. For example, when data is migrated from Cache to DDR, the DMA controller controls the speed and order of data transmission through the AXI bus, ensuring that data is not lost during transmission.

[0032] The DMA controller first configures the source and destination storage areas for data transmission and sets parameters such as data size, transmission mode (single or continuous), transmission direction, etc. Once the configuration is complete, the DMA controller controls the transmission of data from the source storage area to the target storage area through the AXI bus. The DMA controller optimizes the data transmission process according to factors such as transmission rate, bus bandwidth, etc., ensuring efficient data transmission. After data transmission is complete, the DMA controller will notify the CPU that the data has been successfully migrated from one storage area to another. For example, set the DMA controller to specify SRAM as the data source and DDR as the data destination; configure the AXI bus to ensure that data can be transmitted from SRAM to DDR through the AXI bus; start the DMA controller for data transmission; monitor the data transmission process to ensure that data is successfully migrated to DDR. Data is migrated from SRAM to DDR, with a transmission data volume of 100KB. After the DMA controller is started, the data transmission process takes about 10 milliseconds, with a data transmission rate of 10MB / s (based on the bandwidth of the AXI bus). The DMA controller successfully transmits data from SRAM to DDR, and the transmission process does not have data loss or errors.

[0033] By encrypting data based on different storage area encryption strategies, the data is kept encrypted during storage and transmission, effectively avoiding the risk of encryption failure. By using an AXI bus-based DMA controller, the data migration process does not depend on the CPU, avoiding resource occupation of the CPU and improving the efficiency of data transmission.

[0034] When the to-be-written data is written into the first storage area, the to-be-written data is encrypted based on the first encryption strategy corresponding to the first storage area, wherein the first storage area is any storage area of the plurality of storage areas.

[0035] Specifically, according to the to-be-written data, any one of the plurality of storage areas is selected as a target storage location, i.e., a first storage area. The first storage area is any one of the storage areas in the SoC chip, depending on specific requirements. For example, temporary data requiring fast access can be stored in SRAM or Cache, and data requiring persistent storage can be stored in eFlash.

[0036] When the to-be-written data is written into the first storage area, the first encryption strategy corresponding to the first storage area is obtained. Each storage area can have different encryption requirements, and the encryption strategy of the first storage area determines which encryption algorithm and strength to use. The first encryption strategy refers to the data storage encryption requirements and mechanisms for the first storage area. Different storage areas use different encryption algorithms, encryption strengths, or encryption methods. For example, for high-performance storage areas (such as SRAM or Cache), a lighter encryption strategy is used, such as the AES-128 encryption algorithm, to balance encryption strength and performance; for more secure storage areas (such as eFlash or DDR), a stronger encryption strategy is used, such as the AES-256 encryption algorithm, to ensure higher security of the data when stored.

[0037] After the to-be-written data is encrypted according to the first encryption strategy, the encrypted to-be-written data is written into the first storage area. Encrypted storage ensures that data is not exposed to unauthorized access during storage. For example, if SRAM is selected as the first storage area, the to-be-written data (100KB) is encrypted using the AES-128 encryption algorithm. The AES-128 encryption algorithm encrypts each 128-bit data group. After 100KB of data is encrypted using AES-128, the size remains unchanged (the encryption algorithm itself does not change the data size, but increases the computational overhead). When using AES-128 for encryption, the average encryption time is 15 milliseconds. The encrypted data is written into SRAM, and the data writing process into SRAM is completed within 10 milliseconds. Since SRAM has high access speed, it is suitable for storing high-frequency access data.

[0038] By defining specific encryption policies for each storage area, the encryption protection of data during storage is ensured. Even if the storage area is read by unauthorized access, the data cannot be decrypted, avoiding the risk of data leakage. That is, after the input information is entered, other unauthorized access readers read encrypted information, and the input information cannot be inferred by reading the information.

[0039] If it is detected that the to-be-written data is migrated to a second storage area, a second encryption policy corresponding to the second storage area is analyzed based on a first encryption policy corresponding to the first storage area, and a migration encryption policy is obtained, wherein the second storage area is another storage area different from the first storage area in the plurality of storage areas.

[0040] Further, the present application further comprises the following steps:

[0041] It is judged whether the first encryption policy and the second encryption policy are compatible; if the first encryption policy and the second encryption policy are compatible, the to-be-written data is multiplexed or encrypted using the first encryption policy or the second encryption policy.

[0042] Specifically, the first encryption policy and the second encryption policy correspond to the encryption scheme adopted when the data is stored in the first storage area and the second storage area, respectively. The compatibility of the first encryption policy (encryption policy of the source storage area) and the second encryption policy (encryption policy of the target storage area) is judged. Compatibility judgment is usually checked in multiple dimensions, including encryption algorithm type matching judgment (judging whether the same encryption algorithm or compatible encryption algorithm is used), key system consistency judgment (checking whether the key system of the two is consistent, such as whether both use symmetric encryption or asymmetric encryption), encryption mode consistency judgment (judging whether the encryption mode of the two is consistent), key access control domain matching judgment (ensuring that the access control of the key between the two storage areas is consistent, that is, whether the original key can be accessed and used in the target storage area), ciphertext format and header structure alignment judgment (checking whether the data format of the source storage area and the target storage area is consistent, ensuring that the ciphertext header and the encryption data format will not be wrong during migration) and the like.

[0043] Only when the compatibility judgment of multiple dimensions is passed, the first encryption policy and the second encryption policy are considered compatible. If the first encryption policy and the second encryption policy are completely compatible, reuse any encryption policy to encrypt the data to be written, without re-encryption. Reuse generally refers to if two policies are completely the same, the data can remain in the current encryption state without additional processing. Encryption refers to a kind of conversion encryption operation, that is, without decrypting the original data, the current ciphertext is re-encrypted or encapsulated using the related information (such as a new key, a new IV) of the second policy, to generate a ciphertext that meets the requirements of the second policy. The goal of reuse or encryption is to keep the ciphertext structure unchanged or predictable, and to avoid the data to be written in a decrypted state in the new area. IV (initialization vector) is a key parameter in cryptography for enhancing encryption security, especially indispensable in block cipher mode (such as CBC, CTR).

[0044] When it is detected that the data is about to be migrated from the first storage area (such as Cache) to the second storage area (such as SRAM), the encryption policy mapping table built-in in the multiple storage areas of the SoC chip is queried to obtain the second encryption policy (assuming AES-128-CBC, using key K2) corresponding to the second storage area (SRAM). The encryption policy currently applied by the first storage area (Cache) (assuming AES-128-CBC, using key K1) is compared. The compatibility judgment mechanism is started: check the algorithm type (both are AES, match); key system (both are symmetric key, match); encryption mode (both are CBC, match); key access control domain (the access permission of K1 and K2 partially overlaps, such as both allowing CPU access, match); ciphertext format and header structure (both are CBC mode, need IV initialization vector and possible padding information, enough information can be extracted from the CBC ciphertext header of Cache to construct the required header of SRAM). If all judgment mechanisms pass, it is judged as compatible. Process using the first encryption policy (K1, CTR) or the second encryption policy (K2, CBC). If reuse is selected, and mode conversion is feasible, dynamically adjust during transmission, such as before writing to SRAM, using K2 and new IV2, based on the original CBC ciphertext, generate a ciphertext that meets the CBC mode, without complete decryption. If direct encryption is selected, and the policies are completely the same (such as both are AES-128-CBC, only the key is different), directly use K2 and new IV2 to re-encrypt the current ciphertext. The whole process is completed by the hardware encryption engine to ensure low delay.

[0045] Exemplarily, it is assumed that the size of the data block to be migrated is 16KB. The first storage area is Cache, and the AES-128-CBC strategy (key K1, IV1) is applied. The second storage area is SRAM, and the AES-128-CBC strategy (key K2, IV2) is applied. It is detected that the data needs to be migrated from Cache to SRAM. The strategy table is queried to obtain the SRAM strategy. The compatibility judgment is started: the algorithm AES is matched; the symmetric key is matched; the encryption mode CBC is matched; the keys K1 and K2 are allowed to be accessed by the CPU, and the domain is matched; the header information (IV and possible padding information) of Cache and SRAM can be parsed and converted, and it is judged to be compatible. The reuse of the second strategy (K2, CBC) is performed, that is, the ciphertext conversion is performed. The hardware encryption engine receives the CBC ciphertext (16KB) from Cache, reads the CBC ciphertext data block from Cache through the AXI bus, reads K1 and IV1, reads K2 and IV2, in the hardware encryption engine, the data block is decrypted in the CBC mode using the key K1 and the correct IV1, and the plaintext block is obtained. A secure and unpredictable IV2 is generated for new encryption, and the padding of the source data is verified and removed (such as PKCS#7). A brand new IV2 is generated by TRNG (prohibition of reuse of IV1 or IV2), the plaintext is refilled (such as PKCS#7) using the key K2 and the new IV2 in the target strategy, the CBC ciphertext block is obtained, and the IV2 is recorded or stored. The padded plaintext is encrypted in the CBC mode using K2 and IV2 to generate new CBC ciphertext. After the conversion is completed, the 16KB ciphertext in the CBC mode is generated, which includes the new IV2 and the converted ciphertext block, and the IV2 (written in the ciphertext header) and the generated CBC ciphertext block are written into SRAM through the AXI bus. The time consumption is decryption (1024 blocks x 100ns) + encryption (1024 blocks x 100ns) = 204.8μs.

[0046] Through multi-dimensional compatibility judgment, it is ensured that the data can maintain the encrypted state during the migration process, and unauthorized access is avoided in the target storage area. Through the reuse of the encryption strategy, repeated encryption operations can be avoided, the consumption of system resources is reduced, the data migration efficiency is improved, and especially in the frequent migration scenario.

[0047] Further, the application further includes the following steps:

[0048] A plurality of compatibility judgment mechanisms are constructed, including encryption algorithm type matching judgment, key system consistency judgment, encryption mode consistency judgment, key access control domain matching judgment, and ciphertext format and header structure alignment judgment. When the results of each item in the plurality of compatibility judgment mechanisms are all passed, a result that the first encryption strategy and the second encryption strategy are compatible is output. When at least one result in the plurality of compatibility judgment mechanisms is not passed, a result that the first encryption strategy and the second encryption strategy are incompatible is output.

[0049] Specifically, the compatibility judgment mechanism is a mechanism for checking whether two encryption strategies can successfully cooperate. By comparing the compatibility of encryption algorithms, key systems, encryption modes, key access controls, and ciphertext formats, it is ensured that encrypted data can be migrated between different storage areas without data leakage, incorrect decryption, or unreadability due to incompatible encryption strategies. Encryption algorithm type matching judgment checks whether the encryption algorithms used by the two encryption strategies are consistent or compatible. Common encryption algorithms include symmetric encryption algorithms (such as AES) and asymmetric encryption algorithms (such as RSA). If the algorithms used by the two are incompatible, the data may not be correctly decrypted during migration.

[0050] Key system consistency judgment is used to determine whether the key systems used by the source storage area and the target storage area are consistent, such as both being symmetric keys or both being asymmetric keys, and whether the key management methods are compatible (such as key length, derivation method, etc.). Encryption mode (such as ECB, CBC, CFB, etc.) determines how data is grouped and processed during encryption. If the source storage area and the target storage area use different encryption modes, the data may not be correctly decrypted or the decrypted result may be incorrect during migration.

[0051] Key access control domain match judgment is used to determine whether the access control of the key in different storage areas is consistent, to ensure that the key can be accessed correctly in the target storage area. For example, if the key K1 of the first policy allows CPU access, and the key K2 of the second policy also allows CPU access, then the control domain matches. If K1 is only CPU accessible, and K2 is only a specific security module accessible, then it may not match, unless there is a mechanism to allow cross-domain access or conversion. The ciphertext format and header structure alignment judgment is used to ensure that the ciphertext format and encryption header structure of the source storage area and the target storage area are aligned, so as to keep the data structure consistent when migrating data, and avoid errors caused by format mismatch. Check the ciphertext generated by the two policies, whether the data format, the structure and position of the header information (such as initialization vector IV, authentication tag, padding information, etc.) are compatible. For example, two CBC mode ciphertexts, both of which contain IV in the header, and the length and position of IV are the same, then they are aligned. If one uses IV and the other uses Nonce, or the header information format is completely different, then they may not be aligned.

[0052] When all the compatibility judgments in the multiple compatibility judgment mechanisms pass, it is considered that the first encryption policy and the second encryption policy are compatible. If they are compatible, the output is the result of compatibility. If the first encryption policy and the second encryption policy are completely compatible, either encryption policy can be reused to encrypt the data to be written, without the need for re-encryption. The purpose of reusing encryption is to reduce repeated encryption operations, improve efficiency, and ensure that the data always remains encrypted during migration. If it is considered that reusing the encryption policy will cause performance problems or other situations that do not meet the requirements, the data can be re-encrypted. The encryption operation here is based on the first encryption policy or the second encryption policy, to ensure that the data meets the encryption requirements of the target storage area.

[0053] When one of the multiple compatibility judgment mechanisms results in a failure, it is considered that the first encryption policy and the second encryption policy are not compatible, indicating that direct reuse or simple conversion is not feasible. By constructing a comprehensive and detailed compatibility judgment mechanism, it is ensured that only when the encryption policies of the two storage areas are highly matched in multiple dimensions such as algorithm, key, mode, access permission and ciphertext structure, efficient data migration processing (such as reuse or encryption) is allowed, avoiding errors (such as decryption failure, data corruption) or more complex and time-consuming processing (such as complete decryption and re-encryption) that may occur when the policies are incompatible.

[0054] Further, the present application further comprises the following steps:

[0055] If the first encryption policy and the second encryption policy are incompatible, identify the encryption algorithm type, key system, security level, and access domain parameters of the first encryption policy and the second encryption policy; construct a compatible encryption policy set according to the encryption algorithm type, key system, security level, and access domain parameters of the first encryption policy and the second encryption policy; and screen each compatible encryption policy in the compatible encryption policy set, and set the compatible encryption policy that meets the first compatibility condition and the second compatibility condition as a migration encryption policy.

[0056] Further, the present application further comprises the following steps:

[0057] The compatible encryption policy that meets the first compatibility condition and the second compatibility condition is set as a migration encryption policy, wherein the first compatibility condition is that the compatible encryption policy is identified and encrypted and decrypted by the second storage area, and the second compatibility condition is that the compatible encryption policy is identified and encrypted and decrypted by the first storage area.

[0058] Specifically, when one of the multiple compatibility judgment mechanisms fails, it is determined that the first encryption policy and the second encryption policy are incompatible, and the encryption algorithm type, key system, security level, and access domain parameters of the first encryption policy and the second encryption policy are identified. The encryption algorithm type refers to the encryption technology used (such as AES, RSA, etc.), and different encryption algorithms may have different security, computational efficiency, and applicable scenarios. The key system defines the generation, storage, and use of keys in encryption, including symmetric encryption (such as AES) and asymmetric encryption (such as RSA). The security level represents the strength of the encryption policy or the ability to protect data from attacks. A higher security level means using stronger encryption algorithms and more complex key management systems. The access domain parameter refers to the range or area in which the keys and encrypted resources in the encryption policy can be accessed. Different storage areas may have different access control policies to ensure that encrypted resources can only be accessed by authorized components or modules.

[0059] Deeply analyze the specific details of the first encryption policy and the second encryption policy, and clearly record all the differences between them in the encryption algorithm type (such as AES and RSA), the key system (such as symmetric and asymmetric), the security level (such as AES-128 for medium, RSA-OAEP for high), and the access domain parameter (such as K1 allowing core 0 access, K3 allowing core 1 and DMA access).

[0060] According to the encryption algorithm type, key system, security level and access domain parameters of the first and second encryption strategies, a compatible encryption strategy set is constructed. The compatible encryption strategy set contains all possible encryption strategies, which can be seamlessly migrated between the source storage area and the target storage area. When constructing the compatible encryption strategy, it is evaluated whether each encryption strategy is suitable for data migration according to the encryption algorithm type, key system, security level and access domain parameters. Only those encryption strategies that can meet the encryption requirements of the target storage area and the source storage area are included. Extract what encryption algorithms are used by the two strategies (such as one is AES and the other is RSA), what key system is based on (such as one is based on symmetric key and the other is based on asymmetric key), the respective security level requirements (such as one is high security and one is medium security), and their access domain parameters (such as which processors or security domains are allowed to access), according to which the rule engine is predefined. The rule engine stores a variety of possible intermediate encryption strategies. According to the parameters of the first and second encryption strategies, those strategies that can be understood and processed by the first storage area (i.e. the first storage area supports the decryption of the strategy) and at the same time can be understood and processed by the second storage area (i.e. the second storage area supports the encryption or storage of the strategy) are screened out. For example, if the first strategy is AES-128-CBC (symmetric) and the second strategy is RSA-OAEP (asymmetric), find a strategy that supports symmetric encryption and has a security level not lower than the lowest requirement of the two, or find a certain hybrid mode strategy.

[0061] The first compatible condition means that the compatible encryption strategy must be recognized by the target storage area (second storage area) and be able to perform correct encryption and decryption processing; the second compatible condition means that the compatible encryption strategy must be recognized by the source storage area (first storage area) and be able to perform correct encryption and decryption processing. Only the encryption strategy that meets both conditions can be selected as the migration encryption strategy. The encryption strategy that meets the screening condition will be selected as the migration encryption strategy for the migration of the data to be written between the source storage area and the target storage area, ensuring that the data always remains encrypted during the migration process and can be correctly decrypted after the migration.

[0062] Through multiple compatibility judgment mechanisms, the compatibility of the encryption strategy can be evaluated, avoiding encryption conflicts or incorrect decryption during data migration. Even if the original encryption strategy is not compatible, a compatible encryption strategy set can be constructed according to the encryption algorithm type, key system, access domain, etc., providing a flexible solution. By selecting the appropriate migration encryption strategy, it is ensured that the data always remains encrypted during the migration process and can be correctly decrypted in the target storage area.

[0063] Further, the present application further comprises the following steps:

[0064] If the number of compatible encryption strategies satisfying the first compatibility condition and the second compatibility condition simultaneously is multiple, a compatibility test index is set, and the compatibility test index includes policy encryption efficiency, policy decryption efficiency, policy analysis delay, resource occupancy rate, and policy call cost corresponding to each storage area; the compatible encryption strategies satisfying the first compatibility condition and the second compatibility condition simultaneously are tested according to the compatibility test index, and the compatibility test data of the first storage area and the compatibility test data of the second storage area are obtained; the multiple compatibility test scores are obtained according to the compatibility test data of the first storage area and the compatibility test data of the second storage area; the first compatible encryption strategy satisfying the first compatibility condition and the second compatibility condition simultaneously is set as the migration encryption strategy by screening among the multiple compatibility test scores.

[0065] Specifically, if the number of compatible encryption strategies satisfying the first compatibility condition and the second compatibility condition simultaneously is multiple, further selection is performed to evaluate the advantages and disadvantages of these strategies based on the compatibility test index. The compatibility test index is set to evaluate the performance of different compatible encryption strategies in the data migration process, including policy encryption efficiency, policy decryption efficiency, policy analysis delay, resource occupancy rate, and policy call cost corresponding to each storage area. The policy encryption efficiency is used to measure the speed or efficiency of the encryption operation, that is, the time required for the encryption process; the policy decryption efficiency is used to measure the speed or efficiency of the decryption operation, that is, the time required for the decryption process; the policy analysis delay is the time required for analyzing encrypted data, including data header analysis, ciphertext processing, etc.; the resource occupancy rate is the system resources consumed when the encryption strategy is executed, such as memory and CPU occupancy; and the policy call cost is the calculation cost required for each call of the encryption or decryption operation, including the complexity of the encryption algorithm.

[0066] The compatibility test is performed on all encryption strategies that meet the first compatibility condition and the second compatibility condition, and the encryption efficiency, decryption efficiency, parsing time delay, resource occupancy rate and calling cost of each strategy are calculated. Each encryption strategy is tested in the source storage area (the first storage area) and the target storage area (the second storage area), and the corresponding compatibility test data is obtained, reflecting the actual performance of the encryption strategy on different storage areas. According to the test data, a compatibility test score is assigned to each encryption strategy, which comprehensively reflects the performance of each index. For example, assuming that the data to be migrated is migrated from Cache to eFlash, and there are multiple compatible encryption strategies, including AES-128-CBC, AES-256-CBC and RSA-2048, etc. Among them, the strategy encryption efficiency of AES-128-CBC is 15 ms for encrypting 100 KB data, the strategy decryption efficiency is 10 ms for decrypting 100 KB data, the strategy parsing time delay is 5 ms for parsing time, the resource occupancy rate is 10%, and the strategy calling cost is low (relatively simple operation); the strategy encryption efficiency of AES-256-CBC is 20 ms for encrypting 100 KB data, the strategy decryption efficiency is 15 ms for decrypting 100 KB data, the strategy parsing time delay is 8 ms for parsing time, the resource occupancy rate is 15%, and the strategy calling cost is medium; the strategy encryption efficiency of RSA-2048 is 100 ms for encrypting 100 KB data, the strategy decryption efficiency is 120 ms for decrypting 100 KB data, the strategy parsing time delay is 50 ms for parsing time, the resource occupancy rate is 50%, and the strategy calling cost is high (due to asymmetric encryption). AES-128-CBC performs well in the source storage area and the target storage area, with high encryption efficiency and decryption efficiency, and low resource occupancy rate and calling cost, and the score is 0.91; AES-256-CBC provides stronger security than AES-128-CBC, but also increases the encryption time, decryption time and resource occupancy, and the score is 0.77; RSA-2048 is asymmetric encryption, and the decryption and encryption time is longer, and the resource occupancy and calling cost is higher, so the efficiency is inferior to AES algorithm, and the score is 0.42.

[0067] The compatibility test score refers to giving a score according to the test results of different compatible encryption strategies through multiple tests, to evaluate their performance in the source storage area and the target storage area. The encryption strategy with a high score represents better performance in terms of performance, efficiency and resource consumption. Among all compatible encryption strategies, on the basis of the first compatible encryption strategy that meets the first compatibility condition and the second compatibility condition, the encryption strategy with the highest compatibility test score is selected as the final migration encryption strategy.

[0068] By using the compatibility test index, the most optimal encryption strategy is selected according to the encryption efficiency, resource consumption and other factors, so as to improve the overall efficiency of data migration. In a variety of compatible encryption strategies, the most suitable solution is selected to ensure that the data remains encrypted during the migration process, while not sacrificing system performance and resource efficiency.

[0069] According to the migration encryption strategy, the to-be-written data is encrypted and then stored in the second storage area, and the label of the to-be-written data is updated in the register under the second storage area.

[0070] Specifically, the to-be-written data is encrypted according to the finally determined migration encryption strategy. The migration encryption strategy not only meets the basic compatibility requirements of the first storage area and the second storage area (i.e. both ends can recognize and process), but also passes the compatibility test and is considered to be the relatively optimal choice in terms of performance and resource occupation, including the encryption algorithm (such as AES), the key (which may be a new key or a specific converted key), the encryption mode (such as CBC), the initialization vector (IV) and all necessary encryption parameters. The to-be-written data is encrypted using the migration encryption strategy to ensure that the data is not exposed to unauthorized access during the migration process and remains encrypted in the target storage area. The to-be-written data may already exist in a certain encrypted state in the first storage area, and now needs to be reprocessed (may be decrypted and then encrypted, or directly converted to an encrypted state) according to the migration encryption strategy before being written to the data block of the second storage area.

[0071] The encrypted to-be-written data is stored in the second storage area, which is performed through the DMA controller or through the direct access bus (such as AXI bus) to ensure fast and error-free migration of data from the source storage area to the target storage area. During the migration process, the data remains encrypted during transmission to avoid data leakage or tampering. After the data is migrated to the target storage area, the data label is updated, which contains some meta information about the data, such as the encryption method of the data, the storage location, the access permission, etc. The purpose of updating the label is to ensure that the target storage area can correctly identify and manage the newly stored data. The data label will be stored in the register under the second storage area. By updating the label, the target storage area ensures correct access control and management of the migrated data. After the data is successfully migrated to the second storage area, the label is updated and stored in the register of the target storage area, and the data storage process is completed.

[0072] The tag is metadata used to identify and track data, used to identify the current encryption state of the data block, the encryption policy used, key identification, access rights, integrity check information, etc. When the data block is migrated to the second storage area, its associated tag also needs to be updated to reflect the migration encryption policy it now applies and its new state in the second storage area. The updated tag information is written to a dedicated register set inside or closely associated with the second storage area. The registers are usually accessed by the encryption management unit or storage controller for quick query and management of encrypted data stored in the second storage area. Through encryption migration, the data remains encrypted throughout the migration process, ensuring that sensitive data is not exposed to unauthorized access.

[0073] Further, the present application also includes the following steps:

[0074] If it is detected that the to-be-written data is to be migrated back to the first storage area from the second storage area, the to-be-written data is encrypted and migrated to the first storage area by reusing the migration encryption policy, and the tag of the to-be-written data is updated to the register under the first storage area.

[0075] Specifically, if it is detected that the to-be-written data needs to be migrated back to the first storage area from the second storage area, i.e., the data needs to be migrated back to the original storage area or the first storage area after being migrated to the second storage area. When the data is migrated back to the first storage area, the migration encryption policy that has been applied before is reused to encrypt the to-be-written data. The purpose of reusing the migration encryption policy is to ensure that the encryption state of the data during the migration back is maintained without re-encryption. By reusing the migration encryption policy, the data can avoid re-encryption operation, thereby improving the efficiency and speed of the migration process.

[0076] After the data is encrypted, it is migrated back to the first storage area, ensuring that the data is not exposed to unauthorized access during the migration process, and ensuring that the data is kept encrypted in the target storage area. After the data migration is completed, the tag of the to-be-written data is also updated. After the tag is updated, the tag information is synchronized to the register of the first storage area, ensuring that the encryption method, storage location, access rights, etc. of the data are correctly stored and managed in the target storage area. The purpose of updating the tag is to ensure that the data is correctly managed and accessed in the first storage area, avoiding security or management problems due to the lack of meta-information. After the data is encrypted and successfully migrated to the first storage area, the tag is updated and stored in the register. The data storage process is completed, ensuring the security and integrity of the data.

[0077] By reusing the migration encryption strategy, the encrypted data always remains encrypted during the migration process, avoiding data exposure to unauthorized access and ensuring data confidentiality and integrity. By detecting the data migration process and reusing the previous encryption strategy, data can be efficiently migrated between different storage areas, ensuring that the encryption state is not lost during migration.

[0078] Further, the present application further comprises the following steps:

[0079] If it is detected that the to-be-written data needs to be migrated to multiple second storage areas simultaneously, in addition to the source storage area (first storage area), the data also needs to be migrated to multiple target storage areas. Each second storage area is a different storage area, and multiple second storage areas each have different encryption strategies, access controls, performance requirements, etc. Each target storage area (multiple second storage areas) has a corresponding encryption strategy, i.e., multiple second migration encryption strategies, to ensure that the data in each target storage area can be correctly encrypted and meet the security requirements of each storage area.

[0080] Specifically, if it is detected that the to-be-written data needs to be migrated to multiple second storage areas simultaneously, in addition to the source storage area (first storage area), the data also needs to be migrated to multiple target storage areas. Each second storage area is a different storage area, and multiple second storage areas each have different encryption strategies, access controls, performance requirements, etc. Each target storage area (multiple second storage areas) has a corresponding encryption strategy, i.e., multiple second migration encryption strategies, to ensure that the data in each target storage area can be correctly encrypted and meet the security requirements of each storage area.

[0081] Similar to the migration process of the aforementioned single second storage area, the to-be-written data is encrypted according to multiple migration encryption strategies, and the data of each storage area is encrypted according to its corresponding encryption strategy. The encrypted data is stored in each target storage area, ensuring that the data remains encrypted during the migration process and meets the security requirements of each storage area. After the data migration is complete, the label of the to-be-written data is updated, and the label information is synchronized to the register corresponding to each second storage area. For each target second storage area, a copy of the data is encrypted using the migration encryption strategy generated specifically for it. This encrypted data copy is written to the corresponding second storage area through the data bus (such as AXI), i.e., independent encryption and writing operations are performed on each target storage area. Simultaneous with data encryption and migration is the updating of the label. After each data copy is written to the corresponding second storage area, the data label in the register associated with that storage area must be updated immediately. The label state must be consistent with the actual storage location and encryption state of the data, and the update operation must follow the data write operation without significant delay.

[0082] By encrypting the data according to the encryption requirements of each target storage area, it is ensured that the encryption state is always maintained during the data migration process, preventing data leakage or tampering. By synchronously updating the label and storing it in the register of each storage area, it is ensured that the target storage area can correctly identify and manage the data, efficiently complete the data storage task, and reduce the delay and performance loss during the migration process.

[0083] In summary, the dynamic encryption method for protecting the data privacy of the SoC chip provided in the present application has the following beneficial effects:

[0084] By identifying a plurality of storage areas of the SoC chip, the plurality of storage areas include a plurality of encryption strategies; when the to-be-written data is written into a first storage area, the to-be-written data is encrypted and stored based on a first encryption strategy corresponding to the first storage area, wherein the first storage area is any storage area of the plurality of storage areas; if it is detected that the to-be-written data is migrated to a second storage area, a migration encryption strategy is obtained by analyzing an encryption migration conversion mechanism based on a second encryption strategy corresponding to the second storage area and the first encryption strategy corresponding to the first storage area, wherein the second storage area is another storage area of the plurality of storage areas different from the first storage area; the to-be-written data is encrypted and then migrated and stored in the second storage area according to the migration encryption strategy, and the label of the to-be-written data is updated to the register under the second storage area. That is, by identifying the encryption strategies of the plurality of storage areas, and encrypting and storing the to-be-written data according to the encryption strategy of the target storage area when writing, and performing migration encryption conversion according to the encryption strategies of the migration-in and migration-out storage areas when migrating data, the encryption strategy is migrated with the data flow, ensuring full-process encryption coverage, and improving the security and integrity of the data of the SoC chip.

[0085] Embodiment Two, based on the same inventive concept as the dynamic encryption method for protecting the data privacy of the SoC chip in the aforementioned Embodiment One, the present application also provides a dynamic encryption system for protecting the data privacy of the SoC chip, please refer to the attached Figure 2 , the dynamic encryption system for protecting the data privacy of the SoC chip comprises:

[0086] The storage area identification module 11 is used for identifying a plurality of storage areas of an SoC chip, and the plurality of storage areas include a plurality of encryption strategies; the data encryption storage module 12 is used for, when to-be-written data is written into a first storage area, performing encrypted storage on the to-be-written data based on a first encryption strategy corresponding to the first storage area, wherein the first storage area is any storage area of the plurality of storage areas; the data migration encryption module 13 is used for, if it is detected that the to-be-written data is migrated to a second storage area, performing encryption migration conversion mechanism analysis on a second encryption strategy corresponding to the second storage area and the first encryption strategy corresponding to the first storage area, and obtaining a migration encryption strategy, wherein the second storage area is another storage area of the plurality of storage areas different from the first storage area; and the migration encryption storage module 14 is used for performing encrypted migration storage of the to-be-written data to the second storage area according to the migration encryption strategy, and updating a label of the to-be-written data to a register under the second storage area.

[0087] Further, the storage area identification module 11 in the dynamic encryption system for protecting data privacy of an SoC chip is further used for: the plurality of storage areas of the SoC chip performing data transmission through a DMA controller based on an AXI bus.

[0088] Further, the data migration encryption module 13 in the dynamic encryption system for protecting data privacy of an SoC chip is further used for: judging whether the first encryption strategy and the second encryption strategy are compatible; if the first encryption strategy and the second encryption strategy are compatible, multiplexing or encrypting the to-be-written data by using the first encryption strategy or the second encryption strategy.

[0089] Further, the data migration encryption module 13 in the dynamic encryption system for protecting data privacy of an SoC chip is further used for: constructing a plurality of compatibility judgment mechanisms, the plurality of compatibility judgment mechanisms including encryption algorithm type matching judgment, key system consistency judgment, encryption mode consistency judgment, key access control domain matching judgment, and ciphertext format and header structure alignment judgment; when each result in the plurality of compatibility judgment mechanisms returns as passed, outputting a result that the first encryption strategy and the second encryption strategy are compatible; and when at least one result in the plurality of compatibility judgment mechanisms returns as not passed, outputting a result that the first encryption strategy and the second encryption strategy are incompatible.

[0090] Further, the data migration encryption module 13 in the dynamic encryption system for protecting data privacy of an SoC chip is further configured to: set a compatible encryption strategy that satisfies both the first compatibility condition and the second compatibility condition as the migration encryption strategy, wherein the first compatibility condition is that the compatible encryption strategy is identified and encrypted and decrypted by the second storage area, and the second compatibility condition is that the compatible encryption strategy is identified and encrypted and decrypted by the first storage area.

[0091] Further, the data migration encryption module 13 in the dynamic encryption system for protecting data privacy of an SoC chip is further configured to: if there are multiple compatible encryption strategies that satisfy both the first compatibility condition and the second compatibility condition, set a compatibility test index, wherein the compatibility test index includes a strategy encryption efficiency, a strategy decryption efficiency, a strategy analysis delay, a resource occupancy rate, and a strategy calling cost corresponding to each storage area; test the compatible encryption strategies that satisfy both the first compatibility condition and the second compatibility condition according to the compatibility test index, to obtain compatibility test data of the first storage area and compatibility test data of the second storage area; obtain multiple compatibility test scores according to the compatibility test data of the first storage area and the compatibility test data of the second storage area; and select, from the multiple compatibility test scores, a first compatible encryption strategy that satisfies both the first compatibility condition and the second compatibility condition, and set the first compatible encryption strategy as the migration encryption strategy.

[0092] Further, the data migration encryption module 13 in the dynamic encryption system for protecting data privacy of an SoC chip is further configured to: if the first encryption strategy and the second encryption strategy are incompatible, identify an encryption algorithm type, a key system, a security level, and an access domain parameter of the first encryption strategy and the second encryption strategy; construct a compatible encryption strategy set according to the encryption algorithm type, the key system, the security level, and the access domain parameter of the first encryption strategy and the second encryption strategy; and select, from the compatible encryption strategy set, a compatible encryption strategy that satisfies both the first compatibility condition and the second compatibility condition, and set the compatible encryption strategy as the migration encryption strategy.

[0093] Further, the data migration encryption module 13 in the dynamic encryption system for protecting data privacy of an SoC chip is further configured to: if it is detected that the to-be-written data is migrated from the second storage area to the first storage area; and multiplex the migration encryption strategy to encrypt and migrate the to-be-written data to the first storage area, and update a tag of the to-be-written data to a register under the first storage area.

[0094] Further, the dynamic encryption system for protecting data privacy of an SoC chip further comprises a simultaneous migration encryption module, configured to: if it is detected that the to-be-written data is simultaneously migrated to a plurality of second storage areas, wherein the plurality of second storage areas are a plurality of storage areas different from the first storage area among the plurality of storage areas, and the plurality of second storage areas are different from each other; generate a plurality of migration encryption strategies corresponding to the plurality of second storage areas; and migrate and store the to-be-written data to the plurality of second storage areas respectively after encrypting the to-be-written data according to the plurality of migration encryption strategies, and simultaneously update a tag of the to-be-written data to a register under the plurality of second storage areas.

[0095] The various embodiments in the specification are described in a progressive manner, and each embodiment focuses on the difference from other embodiments. The foregoing Figure 1 The dynamic encryption method for protecting data privacy of an SoC chip and the specific examples in Embodiment One are also applicable to the dynamic encryption system for protecting data privacy of an SoC chip in the present embodiment. Through the foregoing detailed description of the dynamic encryption method for protecting data privacy of an SoC chip, those skilled in the art can clearly know the dynamic encryption system for protecting data privacy of an SoC chip in the present embodiment. Therefore, for the sake of brevity of the specification, no further detailed description is given herein.

[0096] The above description of the disclosed embodiments enables a person skilled in the art to implement or use the present application. Various modifications to these embodiments will be apparent to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present application. Therefore, the present application will not be limited to the embodiments shown herein, but will conform to the widest scope consistent with the principles and novel features disclosed herein.

[0097] Obviously, for those skilled in the art, without departing from the principles of the present application, the present application can be improved and modified in several ways, and these improvements and modifications also fall within the protection scope of the present application.

Claims

1. A dynamic encryption method for protecting SoC chip data privacy, characterized in that: include: Identifying a plurality of storage areas of the SoC chip, the plurality of storage areas including a plurality of encryption policies; When the data to be written is written into the first storage area, the data to be written is encrypted and stored based on the first encryption policy corresponding to the first storage area, wherein the first storage area is any storage area of ​​the multiple storage areas; If it is detected that the data to be written is migrated to a second storage area, performing an encryption migration conversion mechanism analysis based on a second encryption policy corresponding to the second storage area and a first encryption policy corresponding to the first storage area to obtain a migration encryption policy, wherein the second storage area is another storage area among the multiple storage areas that is different from the first storage area; Encrypting the data to be written according to the migration encryption policy and then migrating the data to the second storage area, and updating the tag of the data to be written to the register under the second storage area; The encryption migration conversion mechanism analysis is performed based on the second encryption policy corresponding to the second storage area and the first encryption policy corresponding to the first storage area, further comprising: Determining whether the first encryption policy and the second encryption policy are compatible; If the first encryption policy and the second encryption policy are compatible, multiplexing or encrypting the data to be written using the first encryption policy or the second encryption policy; If the first encryption policy and the second encryption policy are incompatible, the following steps are performed: Identify the encryption algorithm type, key system, security level, and access domain parameters of the first encryption policy and the second encryption policy; Constructing a compatible encryption policy set according to the encryption algorithm type, key system, security level, and access domain parameters of the first encryption policy and the second encryption policy; The compatible encryption policies in the compatible encryption policy set are screened, and compatible encryption policies that satisfy both the first compatibility condition and the second compatibility condition are set as migration encryption policies.

2. The dynamic encryption method for protecting SoC chip data privacy according to claim 1, characterized in that: A compatible encryption policy that satisfies both the first compatibility condition and the second compatibility condition is set as a migration encryption policy, wherein the first compatibility condition is that the compatible encryption policy is recognized and encrypted and decrypted by the second storage area, and the second compatibility condition is that the compatible encryption policy is recognized and encrypted and decrypted by the first storage area.

3. The dynamic encryption method for protecting SoC chip data privacy according to claim 1, characterized in that: Screening each compatible encryption policy in the compatible encryption policy set further includes: If there are multiple compatible encryption policies that meet both the first compatibility condition and the second compatibility condition, compatibility test indicators are set, wherein the compatibility test indicators include policy encryption efficiency, policy decryption efficiency, policy parsing latency, resource occupancy, and policy call cost corresponding to each storage area; Testing the compatible encryption policy that satisfies both the first compatibility condition and the second compatibility condition according to the compatibility test indicator, and obtaining compatibility test data of the first storage area and compatibility test data of the second storage area; Obtaining a plurality of compatibility test scores based on the compatibility test data in the first storage area and the compatibility test data in the second storage area; The multiple compatibility test scores are screened, and a first compatible encryption policy that satisfies both the first compatibility condition and the second compatibility condition is set as a migration encryption policy.

4. The dynamic encryption method for protecting SoC chip data privacy according to claim 1, characterized in that: The method for determining whether the first encryption policy and the second encryption policy are compatible includes: Construct multiple compatibility judgment mechanisms, including encryption algorithm type matching judgment, key system consistency judgment, encryption mode consistency judgment, key access control domain matching judgment, and ciphertext format and header structure alignment judgment; When each result of the multiple compatibility judgment mechanisms is returned as passed, outputting a result that the first encryption policy and the second encryption policy are compatible; When at least one result of the multiple compatibility judgment mechanisms is returned as failure, a result indicating that the first encryption policy and the second encryption policy are incompatible is output.

5. The dynamic encryption method for protecting SoC chip data privacy according to claim 1, characterized in that: After setting the compatible encryption policy that satisfies both the first compatibility condition and the second compatibility condition as the migration encryption policy, the method further includes: If it is detected that the data to be written is migrated back from the second storage area to the first storage area; The data to be written is encrypted by reusing the migration encryption strategy and then migrated and stored in the first storage area, and the tag of the data to be written is updated in the register under the first storage area.

6. The dynamic encryption method for protecting SoC chip data privacy according to claim 1, characterized in that: The dynamic encryption method for protecting SoC chip data privacy includes: If it is detected that the data to be written is migrated to a plurality of second storage areas at the same time, wherein the plurality of second storage areas are a plurality of storage areas among the plurality of storage areas that are different from the first storage area, and the plurality of second storage areas are different; generating a plurality of migration encryption policies corresponding to the plurality of second storage areas; The data to be written is encrypted according to the multiple migration encryption strategies and then migrated and stored in the multiple second storage areas respectively. At the same time, the tags of the data to be written are synchronously updated to the registers under the multiple second storage areas.

7. The dynamic encryption method for protecting SoC chip data privacy according to claim 1, characterized in that: The multiple storage areas of the SoC chip perform data transmission via a DMA controller based on an AXI bus.

8. A dynamic encryption system for protecting SoC chip data privacy, characterized in that: The steps for implementing the dynamic encryption method for protecting SoC chip data privacy according to any one of claims 1 to 7, wherein the dynamic encryption system for protecting SoC chip data privacy comprises: A storage area identification module, configured to identify a plurality of storage areas of the SoC chip, wherein the plurality of storage areas include a plurality of encryption policies; a data encryption storage module, configured to encrypt and store the data to be written based on a first encryption policy corresponding to the first storage area when the data to be written is written into the first storage area, wherein the first storage area is any storage area of ​​the multiple storage areas; a data migration encryption module configured to, upon detecting that the data to be written is migrated to a second storage area, perform an encryption migration conversion mechanism analysis based on a second encryption policy corresponding to the second storage area and a first encryption policy corresponding to the first storage area, and obtain a migration encryption policy; wherein the second storage area is another storage area among the multiple storage areas that is different from the first storage area; The migration encryption storage module is used to encrypt the data to be written according to the migration encryption policy and then migrate and store it to the second storage area, and at the same time update the label of the data to be written to the register under the second storage area.

Citation Information

Patent Citations

  • Data processing method and apparatus, and system chip

    CN111386513A

  • Hybrid encryption and decryption system and method based on hierarchical layer division and secret-in-secret distribution

    CN115174261A