Uav chip sensitive data access control method based on trusted execution environment
By configuring a trusted execution environment in the drone chip and obfuscating power consumption, electromagnetic signals, and execution time in real time, the data leakage problem of drone chips under side-channel attacks is solved, achieving high-security multi-layer protection.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- SHANGHAI UNI SENTRY INTELLIGENT TECH CO LTD
- Filing Date
- 2025-06-20
- Publication Date
- 2026-08-04
AI Technical Summary
Existing drone chips, despite being equipped with a Trusted Execution Environment (TEE), cannot effectively protect against the leakage of physical layer features when facing side-channel attacks, resulting in a high risk of leakage of sensitive data during encryption processing.
By configuring a trusted execution environment in the drone chip and detecting the data encryption process, the core physical characteristics of side-channel attacks are dynamically interfered with through real-time obfuscation of power consumption, electromagnetic signals, and execution time. This includes random or directional simulated obfuscation, generating random or disguised physical characteristics of the target algorithm, thus increasing the difficulty of the attack.
It significantly improves the security of drone chips against side-channel attacks. Through obfuscation, it makes it difficult for attackers to deduce encryption keys or algorithm logic, providing multi-layered security protection and is suitable for high-security scenarios that need to resist advanced side-channel attacks.
Smart Images

Figure CN120705880B_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of drone security technology, specifically a method for controlling access to sensitive data of drone chips based on a trusted execution environment. Background Technology
[0002] With the increasing application of drones in military and civilian fields, the sensitive data stored in their chips (such as flight control commands, communication keys, and mission payload information) faces severe security threats. In existing technologies, Trusted Execution Environments (TEEs) confine sensitive operations to a secure world through logical isolation, effectively resisting unauthorized access and malicious code injection at the software layer. However, TEEs only address the logical security issues at the software layer and cannot protect against side-channel attacks that exploit physical layer characteristics.
[0003] The core of side-channel attacks lies in exploiting the correlation between encryption operations and physical characteristics: Regarding power consumption, the differences in current consumption for different logic operations on a chip create specific waveforms, allowing attackers to extract key-related information by analyzing the power consumption traces on power pins; regarding electromagnetic characteristics, signal transitions within the chip generate electromagnetic radiation, the frequency and intensity of which are directly related to the type of operation, allowing attackers to reconstruct the encryption process using near-field probes or spectrum analyzers; regarding time characteristics, the execution time of instructions corresponding to different encryption algorithms or key lengths exhibits patterns, allowing attackers to infer the algorithm type or key length by measuring response delays. In existing UAV chip protection solutions, TEE (Transmission Equipment) lacks effective countermeasures against these physical layer attacks, resulting in a high risk of sensitive data leakage during encryption processing.
[0004] This application provides a method for sensitive data access control of UAV chips based on a trusted execution environment to solve the above-mentioned technical problems. Summary of the Invention
[0005] This invention aims to address at least one of the technical problems existing in the prior art. To this end, this invention proposes a sensitive data access control method for UAV chips based on a trusted execution environment. After configuring a trusted execution environment for the UAV, this method detects whether the UAV chip is encrypting data. If data encryption is performed, the power consumption, electromagnetic signals, and execution time of the UAV chip are obfuscated in real time. The trusted execution environment isolates the processing space of sensitive data at the logical level, preventing unauthorized access. The real-time obfuscation dynamically interferes with the core physical characteristics of side-channel attacks, preventing attackers from deriving encryption keys or algorithm logic by monitoring the chip's physical signals. This invention, through the synergistic effect of power consumption, electromagnetic signals, and execution time, makes the chip exhibit highly unpredictable physical characteristics during the encryption process, significantly increasing the difficulty of side-channel attacks and providing multi-layered protection for the secure processing of sensitive UAV data.
[0006] To achieve the above objectives, a first aspect of the present invention provides a method for sensitive data access control of unmanned aerial vehicle (UAV) chips based on a trusted execution environment, comprising: Configure a trusted execution environment for the drone; Detect whether the drone chip is encrypting data; if yes, initiate real-time obfuscation of the side-channel characteristic parameters of the encryption process; the real-time obfuscation includes power consumption, electromagnetic signals, and execution time.
[0007] Preferably, the side-channel feature parameters are subjected to real-time obfuscation processing, including: When a confusing command is detected, the side channel characteristic parameters of the UAV chip are detected in real time; these side channel characteristic parameters include power consumption waveform, electromagnetic signal, and execution time. Randomly simulate and confuse the side-channel characteristic parameters.
[0008] Preferably, the power consumption waveform is subjected to random simulation obfuscation, including: Label the power consumption waveform as the base power consumption; Random power consumption is generated and dynamically superimposed on the base power consumption to complete the random simulation and obfuscation of power consumption.
[0009] Preferably, random simulated obfuscation of electromagnetic signals includes: Shielding electromagnetic signals; An electromagnetic confusion signal is generated and radiated into space to complete the random simulation confusion of the electromagnetic signal.
[0010] Preferably, the execution time is randomly simulated and obfuscated, including: Dynamically change the master clock frequency; Generate a random phase offset sequence, and perform phase modulation on the clock signal based on the random phase offset sequence; Initiate irrelevant tasks to change the time consumption distribution and achieve random simulation and obfuscation of execution time.
[0011] Preferably, the side-channel feature parameters are subjected to real-time obfuscation processing, including: When a confusing command is detected, the side channel characteristic parameters of the UAV chip are detected in real time; these side channel characteristic parameters include power consumption waveform, electromagnetic signal, and execution time. Directional simulation obfuscation is performed on the side-channel characteristic parameters.
[0012] Preferably, before performing targeted simulation obfuscation, a target algorithm is selected, including: Determine the underlying algorithm for data encryption; Encryption algorithms whose execution time is longer than that of the basic algorithm are integrated into an algorithm set; Select an encryption algorithm from the set of algorithms that has similar power consumption waveform and electromagnetic signal to the base algorithm as the target algorithm.
[0013] Preferably, an encryption algorithm with similar power consumption waveform and electromagnetic signal to the basic algorithm is selected from the algorithm set as the target algorithm, including: Extract the average memory usage of each encryption algorithm in the algorithm set during power consumption simulation and electromagnetic simulation; The reciprocal of the average memory usage was normalized and used as the weighting coefficient for power consumption simulation and electromagnetic simulation. The similarity of power consumption waveforms and electromagnetic signals between each encryption algorithm in the algorithm set and the basic algorithm is calculated; the similarity is weighted and calculated to obtain a comprehensive score, and the encryption algorithm with the highest comprehensive score is selected as the target algorithm.
[0014] Preferably, the side-channel characteristic parameters are subjected to targeted simulation obfuscation, including: Real-time monitoring of the actual power consumption in the power circuit of the drone chip, extraction of the target power consumption of the target algorithm when processing data; power consumption simulation based on the target power consumption and the actual power consumption, to achieve directional power consumption obfuscation of the power consumption waveform; Shielding electromagnetic signals; generating electromagnetic confusion signals according to the target algorithm's electromagnetic signals, radiating the electromagnetic confusion signals into space, and completing the directional simulation confusion of electromagnetic signals; The master clock frequency is dynamically changed based on the instruction cycle time data of the target algorithm; a random phase offset sequence is generated, and the clock signal is phase-modulated based on the random phase offset sequence; irrelevant tasks are started to change the time consumption distribution and achieve directional simulation obfuscation of execution time.
[0015] Preferably, during external simulation, power consumption simulation is performed based on the target power consumption and the actual power consumption, including: Extract the actual power consumption and the target power consumption; The power difference between the target power consumption and the actual power consumption is used as a power consumption analog quantity; the power consumption analog quantity is generated to achieve directional simulation obfuscation of the power consumption waveform.
[0016] Preferably, during internal simulation, power consumption simulation is performed based on the target power consumption and the actual power consumption, including: Extract the actual power consumption and target power consumption, as well as the power consumption consumed during directional hybrid simulation in real time, and mark it as additional power consumption. The difference between the target power consumption and the actual power consumption and the additional power consumption is used as the power consumption analog quantity; the power consumption analog quantity is generated to achieve directional simulation obfuscation of the power consumption waveform.
[0017] Compared with the prior art, the beneficial effects of the present invention are: 1. After configuring a trusted execution environment for a drone, this invention detects whether the drone chip is encrypting data. If data encryption is performed, the power consumption, electromagnetic signals, and execution time of the drone chip are obfuscated in real time. The trusted execution environment isolates the processing space of sensitive data at the logical level, preventing unauthorized access. The real-time obfuscation dynamically interferes with the core physical characteristics of side-channel attacks, preventing attackers from deriving encryption keys or algorithm logic by monitoring the chip's physical signals. This invention, through the synergistic effect of power consumption, electromagnetic signals, and execution time, makes the chip exhibit highly unpredictable physical characteristics during the encryption process, significantly increasing the difficulty of side-channel attacks and providing multi-layered protection for the secure processing of sensitive drone data.
[0018] 2. The real-time obfuscation processing of this invention can be random simulation obfuscation, specifically, randomly generated power consumption fluctuations are dynamically superimposed with the actual power consumption, making it impossible for attackers to detect the characteristic power consumption pattern of the encryption operation through the power supply pin; the electromagnetic obfuscation signal covers the actual electromagnetic radiation with broadband random noise, and combined with the active shielding array to cancel the leakage signal, which can eliminate the characteristic spectral lines of the encryption operation in a specific frequency band and resist near-field electromagnetic scanning attacks; dynamically changing the master clock frequency and generating a random phase offset sequence, combined with the parallel scheduling of unrelated tasks, makes the execution timing of the encryption instructions exhibit irregular changes, breaking the correlation between time characteristics and key operations, and preventing attackers from inferring the key by using execution time differences; the synergistic effect of the three in this invention significantly increases the difficulty for attackers to obtain sensitive information through the side channel, providing lightweight and highly generalizable security protection capabilities for UAV chips.
[0019] 3. The real-time obfuscation processing of this invention can be targeted simulation obfuscation. Through targeted simulation obfuscation, the power consumption, electromagnetic signals, and execution time characteristics of the actual encryption operation of the UAV chip can be accurately disguised as the characteristics of the target algorithm, achieving "active misleading" defense. The targeted obfuscation mechanism of this invention can transform side-channel attacks into "algorithm feature misjudgment". The key or algorithm model obtained by the attacker based on the analysis of the obfuscated parameters are all misleading results. Not only will they fail to crack the real encryption process, but they will also consume attack resources and deviate from the correct direction. It is especially suitable for high-security scenarios that need to resist advanced side-channel attacks, providing UAV chip sensitive data processing with a deep protection capability that is both targeted and deceptive. Attached Figure Description
[0020] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0021] Figure 1 This is a schematic diagram of the method steps of the drone chip sensitive data access control method according to an embodiment of the present invention; Figure 2 This is a schematic diagram of the method steps for random simulation obfuscation of power consumption waveforms in an embodiment of the present invention; Figure 3 This is a schematic diagram of the method steps for directional simulation obfuscation of power consumption waveforms in an embodiment of the present invention. Detailed Implementation
[0022] The technical solution of the present invention will be clearly and completely described below with reference to the embodiments. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0023] Please see Figure 1 The first aspect of this invention provides a method for sensitive data access control of unmanned aerial vehicle (UAV) chips based on a trusted execution environment, comprising: S100: Configures a trusted execution environment for drones; S200: Detects whether the UAV chip is encrypting data; if yes, it initiates real-time obfuscation processing of the side-channel characteristic parameters of the encryption process; the real-time obfuscation processing includes power consumption, electromagnetic signals, and execution time.
[0024] The chips in drones store a large amount of data, mainly including sensitive and non-sensitive data. Sensitive data includes flight control data, communication keys and protocol data, mission payload data, and system configuration data.
[0025] Flight control data is crucial for the normal flight and precise control of drones, directly affecting their ability to fly stably, safely, and according to preset requirements. Flight control data mainly includes flight attitude data (roll angle, pitch angle, yaw angle, etc.), flight trajectory data (coordinate information such as longitude, latitude, and altitude), and flight control system parameters (PID control parameters, motor response speed, propeller speed, etc.). If flight control data is leaked or tampered with, the drone may lose control or even be maliciously used, causing serious safety incidents.
[0026] Communication keys and protocol data are crucial for ensuring the security of UAV communication and the accuracy of data transmission, guaranteeing the confidentiality, integrity, and reliability of communication between the UAV and ground control stations or other equipment. Communication keys and protocol data mainly include encrypted communication keys and communication protocols. If the communication key is cracked or the protocol is maliciously exploited, the UAV's flight mission commands, real-time status information, and other communication data may be intercepted, tampered with, or forged, rendering the UAV unable to receive and execute control commands normally.
[0027] Mission payload data contains critical information about a drone's specific mission execution, directly impacting mission completion and application value. It serves as vital data support for drones to function across various fields. Mission payload data primarily includes mission instructions, sensor-collected data, and mission execution status. Leakage of mission payload data could lead to mission failure and, in certain scenarios, pose serious threats to security and privacy.
[0028] System configuration data is fundamental to the normal operation and functionality of an unmanned aerial vehicle (UAV) system. It determines the UAV's hardware and software configuration, function settings, and interaction methods with external devices, playing a crucial role in the overall performance and user experience. System configuration data mainly includes hardware configuration parameters, software configuration, and system security settings. If these parameters are tampered with, the UAV may malfunction, or even be compromised by security vulnerabilities that could lead to attacks.
[0029] To protect the data security within drone chips, Trusted Execution Environments (TEEs) are currently widely used in drones. TEEs employ architectures such as ARM TrustZone and RISC-V Privilege Levels, dividing the processor into secure and insecure worlds. The secure world runs a TEE operating system (such as OP-TEE or QTEE) responsible for handling sensitive tasks; the insecure world runs a regular operating system (such as Linux or RTOS) for handling non-sensitive business logic.
[0030] However, even if a drone is equipped with a Trusted Execution Environment (TEE), it may still be vulnerable to attacks that could lead to data leaks. This is because the TEE primarily addresses logical isolation and data confidentiality at the software level. During data processing, certain characteristic parameters can be used to analyze and crack encryption algorithms. By using the cracked encryption algorithms, intercepted data can be encrypted, resulting in data leakage.
[0031] Side-channel attacks, in particular, rely on the leakage of physical layer information to carry out attacks. This differs from the protection dimensions of the software layer of trusted execution environments, making it difficult for feasible execution environments to defend against side-channel attacks.
[0032] The core of a side-channel attack is to exploit the correlation between physical phenomena in cryptographic operations, such as time characteristics, power consumption characteristics, and electromagnetic characteristics, and the key or intermediate computation results. By measuring and analyzing this physical information, attackers can deduce the key information and thus crack the encrypted data. The principle of a side-channel attack is explained below: 1. Power Consumption Characteristic Analysis: When a drone chip performs key operations in a trusted execution environment (TEA), power consumption traces can be obtained by monitoring the power pins of the drone chip. By comparing the fluctuation patterns in the power consumption traces with known algorithms, the key (or private key) can be derived. Although the key is generated in the TEA, the power consumption characteristics are related to the computational logic, and the TEA cannot protect against this.
[0033] 2. Electromagnetic Feature Analysis: When a drone chip performs key operations in a Trusted Execution Environment (TEE), the electromagnetic signals emitted during chip read / write operations can be scanned using an electromagnetic probe. By comparing the frequency of these signals with the frequency of signals emitted by known encryption algorithms, the key (or private key) can be derived. Since the TEE does not provide electromagnetic shielding, it cannot protect against this type of attack.
[0034] 3. Time Feature Analysis: When the drone chip performs key operations in a trusted execution environment, the time difference in the drone's response to commands can be measured, and the key (or private key) can be inferred using the fixed time pattern of the encryption operation. The trusted execution environment cannot provide effective protection against this.
[0035] S200: Detect whether the drone chip is encrypting data; if yes, start real-time obfuscation processing of the side-channel characteristic parameters of the encryption process.
[0036] Real-time obfuscation primarily involves simulating obfuscation of the power consumption, electromagnetic signals, and execution time when the UAV chip processes sensitive data. This simulated obfuscation is implemented through an obfuscation control module connected to the UAV chip's security monitoring module (such as a trusted execution environment) to receive obfuscation commands. Upon receiving an obfuscation command, real-time obfuscation of the opposite channel characteristic parameters is initiated; otherwise, obfuscation is not initiated.
[0037] In a preferred embodiment, real-time obfuscation processing of the side-channel feature parameters includes: S110: When a confusing command is detected, the side channel characteristic parameters of the UAV chip are detected in real time; the side channel characteristic parameters include power consumption waveform, electromagnetic signal and execution time; S120: Randomly simulate and confuse the side channel characteristic parameters.
[0038] Please see Figure 2 In a preferred embodiment, random simulation obfuscation of the power consumption waveform includes: S121-1: Mark the power consumption waveform as the base power consumption; S121-2: Generate random power consumption, dynamically superimpose the random power consumption with the basic power consumption, and complete the random simulation and confusion of power consumption.
[0039] The confusion control module includes a power confusion unit, an electromagnetic confusion unit, and a time confusion unit.
[0040] The random simulation and obfuscation of the power consumption waveform is implemented by a power obfuscation unit, which includes a dynamic load regulator and an energy buffer. The dynamic load regulator consists of a programmable resistor / capacitor array, which simulates power consumption fluctuations by adjusting the load. The energy buffer includes supercapacitors or superinductors to compensate for sudden energy demands during obfuscation, preventing sudden voltage drops in the chip from affecting its normal operation.
[0041] When encrypting sensitive data in a drone chip, a programmable resistor / capacitor array is randomly adjusted by a dynamic load regulator. After the random adjustment, random power consumption is introduced. The random power consumption is then dynamically superimposed with the actual power consumption of the drone chip during encryption. When the power supply pin current of the drone chip is monitored, the power consumption obtained is the dynamically superimposed power consumption, and the actual power consumption of the drone chip during encryption cannot be obtained. In other words, the key cannot be derived from the power consumption analysis.
[0042] It is worth noting that the simulation process itself will generate a certain amount of energy consumption. However, since the simulated power consumption result is random, the power consumption detected by the power supply pin after the simulation does not need to be limited by its power consumption waveform. That is, its power consumption waveform does not need to be similar to other encryption algorithms. Therefore, the power consumption generated during the simulation process does not need to be considered.
[0043] It should be noted that the dynamic load regulator can be controlled based on the binary sequence output by the random number generator. If it is a programmable resistor array, the binary sequence corresponds to the on / off state of a certain resistor, such as "1010" indicating that resistors R1 and R3 are connected; if it is a programmable capacitor array, the binary sequence corresponds to the charging and discharging state of the capacitors, such as "011" indicating that capacitors C2 and C3 are connected and charging has started.
[0044] During the random adjustment process of the dynamic load regulator, the energy buffer monitors the power supply voltage in real time. When the dynamic load causes the power supply voltage to drop beyond a threshold (such as 5%), the supercapacitor (or super inductor) releases energy to provide instantaneous current compensation. When the load power consumption is lower than the average level, the supercapacitor (or super inductor) absorbs excess energy to maintain voltage stability.
[0045] After the encryption process of the drone chip is completed, the power obfuscation unit enters a low-power mode, the dynamic load regulator switches to a fixed load to avoid interfering with the normal operation of the chip, the random number generator pauses its output, and the energy buffer enters a charging state to reserve energy for the next obfuscation.
[0046] In a preferred embodiment, random simulation obfuscation of the electromagnetic signal includes: S122-1: Shielding electromagnetic signals; S122-2: Generate an electromagnetic confusion signal and radiate it into space to complete the random simulation confusion of the electromagnetic signal.
[0047] The random simulation of electromagnetic signal mixing is achieved by an electromagnetic mixing unit, which includes an electromagnetic radiation simulator and an active shielding array. The electromagnetic radiation simulator integrates a multi-channel radio frequency generator, which can generate electromagnetic signals of specific frequencies and intensities. The active shielding array consists of an antenna array and a digital signal processor (DSP), which cancels the chip's actual electromagnetic radiation by emitting inverted signals.
[0048] When encrypting sensitive data in a drone chip, an electromagnetic radiation simulator can randomly generate an electromagnetic obfuscation signal, which is then radiated into space through an antenna array. An active shielding array can generate a cancellation signal with the same amplitude but opposite phase to the real electromagnetic signal, based on the reverse phase information of the real electromagnetic signal. This cancellation signal suppresses the propagation of the real electromagnetic signal. Thus, during electromagnetic monitoring, the actual electromagnetic signal monitored is the generated obfuscated signal, making it impossible to deduce the key by analyzing the monitored signal.
[0049] In a preferred embodiment, random simulation obfuscation of the execution time includes: S123-1: Dynamically change the master clock frequency; S123-2: Generate a random phase offset sequence, and perform phase modulation on the clock signal based on the random phase offset sequence; S123-3: Start irrelevant tasks, change the time consumption distribution, and achieve random simulation obfuscation of execution time.
[0050] The timing obfuscation unit includes a timing obfuscator, an instruction pipeline jammer, and a parallel operation scheduler. The timing obfuscator contains a programmable clock divider and a phase adjuster, which can dynamically adjust the chip's main clock frequency to simulate the instruction cycle time of different algorithms. The instruction pipeline jammer inserts invalid instructions or repeats parts of the operation in the CPU pipeline, delaying the execution timing of sensitive instructions. The parallel operation scheduler utilizes the chip's multi-core or coprocessor resources to execute irrelevant operations in parallel with sensitive operations, changing the overall time consumption distribution.
[0051] Before time obfuscation, the parameters of the programmable clock divider are configured, mainly including the fluctuation range and change period of the clock frequency; the phase adjuster is initialized, setting the maximum range of phase offset and the random offset interval. When the UAV chip encrypts sensitive data, the master clock frequency is dynamically changed through the programmable clock divider, making the master clock frequency randomized; a random phase offset sequence is generated through the phase adjuster to modulate the clock signal, making the phase relationship between adjacent clock cycles randomized. The instruction pipeline jammer, based on the randomized clock, perturbs the encrypted instruction stream, further obscuring the timing characteristics of instruction execution; the parallel operation scheduler simultaneously starts unrelated tasks, changing the overall time consumption distribution at the system level, so that the time characteristics of the encryption operation are submerged in the time noise of multiple tasks.
[0052] It should be noted that random phase offset sequences can be either periodic or continuous. Periodic offsets are based on integer multiples of the clock period and are implemented using a programmable clock divider or counter. Each offset is an integer multiple of the fixed period (e.g., ±1 period, ±2 periods, etc.). The core idea is to introduce discrete, periodically controllable phase transitions at the edges (rising / falling edges) of the clock signal, with the offset repeating within a certain period. Continuous offsets generate continuous random offsets within the phase space (0-360°), adjusting the clock signal phase in real time using a phase modulator (e.g., a digital phase-locked loop (DLL) or an analog phase shifter). The core idea is continuous phase changes without a fixed period or step limitations; each offset can take any value within the range.
[0053] It is worth noting that during the operation of the time obfuscator, the temperature and power supply voltage of the drone chip are continuously monitored. If abnormal voltage fluctuations or excessive temperature are detected, the clock immediately reverts to the default clock configuration to ensure that clock frequency fluctuations do not cause malfunctions in the drone chip. This monitoring can be achieved through a temperature sensor located in the encryption operation area of the drone chip, as well as a voltage monitoring circuit that monitors the power supply voltage.
[0054] This embodiment uses a confusion control module to obfuscate the actual working performance of the drone chip from the perspectives of power consumption, electromagnetics, and time when the drone chip is performing sensitive data encryption processing, so as to make it difficult to deduce the key.
[0055] Example 2: Compared to Example 1, this example uses a confusion control module to process the power consumption, electromagnetic signals, and time of the UAV chip during encrypted data processing, thus concealing the true power consumption, electromagnetic signals, and time. At the same time, when using power consumption, electromagnetic signals, and time to derive the key, it will guide the derivation of other false keys.
[0056] In a preferred embodiment, real-time obfuscation processing of the side-channel feature parameters includes: S110: When a confusing command is detected, the side channel characteristic parameters of the UAV chip are detected in real time; the side channel characteristic parameters include power consumption waveform, electromagnetic signal and execution time; S120: Perform directional simulation obfuscation on the side channel characteristic parameters.
[0057] In addition to the power obfuscation unit, electromagnetic obfuscation unit, and time obfuscation unit, the obfuscation control module also includes a typical algorithm feature unit, which stores the power consumption waveform, electromagnetic signal, and execution time of a typical encryption algorithm.
[0058] After the obfuscation control module identifies the encryption algorithm used by the drone chip when performing sensitive data encryption processing, it uses this encryption algorithm as the base algorithm and extracts the power consumption waveform, electromagnetic signal and execution time of the base algorithm. This data can be obtained through pre-simulation.
[0059] The target algorithm is obtained by matching typical algorithm feature units based on power consumption waveform, electromagnetic signal, and execution time. The data corresponding to this target algorithm is the object to be simulated by the power consumption obfuscation unit, electromagnetic obfuscation unit, and time obfuscation unit.
[0060] In a preferred embodiment, before performing targeted simulation obfuscation, selecting a target algorithm includes: S121-1: Determine the basic algorithm corresponding to data encryption; S121-2: Integrate encryption algorithms whose execution time is longer than that of the basic algorithm into an algorithm set; S121-3: Select an encryption algorithm from the algorithm set that is similar to the power consumption waveform and electromagnetic signal of the base algorithm as the target algorithm.
[0061] When matching the target algorithm, the primary matching criterion is that its execution time must be greater than that of the base algorithm. This is because the time obfuscation unit can only achieve obfuscation by extending the actual execution time, not by shortening the execution time of the encryption algorithm. Therefore, it is necessary to ensure that the execution time of the target algorithm is greater than that of the base algorithm. Simultaneously, the power consumption waveform and electromagnetic signals are similar to the relevant data of the base algorithm. This minimizes data processing difficulty during simulation and improves simulation efficiency.
[0062] When matching encryption algorithms with similar power consumption waveforms and electromagnetic signals to the base algorithm, the similarity of power consumption waveforms can be compared first, followed by the similarity of electromagnetic signals. For example, encryption algorithms with execution times longer than the base algorithm can be integrated into Algorithm Set 1; the similarity between the power consumption waveforms of each encryption algorithm in Algorithm Set 1 and the power consumption waveform of the base algorithm can be compared to a pre-set similarity threshold. If the similarity is greater, the corresponding encryption algorithms can be integrated into Algorithm Set 2; the similarity between the electromagnetic signals of each encryption algorithm in Algorithm Set 2 and the electromagnetic signals of the base algorithm can be compared, and the algorithm with the highest similarity can be selected as the target algorithm. Conversely, the electromagnetic signals can be compared first, and encryption algorithms with similarity greater than a pre-set similarity threshold can be integrated into Algorithm Set 2. Then, the encryption algorithm with the highest power consumption waveform similarity can be selected as the target algorithm from the combined algorithms.
[0063] It should be noted that, since the electromagnetic signal simulation in this invention involves shielding before simulation, it has little correlation with real electromagnetic signals. Therefore, a data correlation between the electromagnetic signals of the basic algorithm and the electromagnetic signals of the target algorithm is not required. Furthermore, it is necessary to ensure that the parameters corresponding to the target algorithm can be simulated based on the parameters of the basic algorithm, and, if necessary (during internal simulation), the operating parameters of the obfuscation control module should also be considered.
[0064] In a preferred embodiment, an encryption algorithm similar in power consumption waveform and electromagnetic signal to the basic algorithm is selected from the algorithm set as the target algorithm, including: S121-3-1: Extract the average memory usage of each encryption algorithm in the algorithm set during power consumption simulation and electromagnetic simulation; S121-3-2: The reciprocal of the average memory usage is normalized and used as the weighting coefficient for power consumption simulation and electromagnetic simulation. S121-3-3: Calculate the similarity of power consumption waveforms and electromagnetic signals between each encryption algorithm in the algorithm set and the basic algorithm; calculate the comprehensive score by weighting the similarity with the weights, and select the encryption algorithm with the highest comprehensive score as the target algorithm.
[0065] The target algorithm can also be selected through a weighted calculation. Specifically, the average memory usage during power consumption simulation and electromagnetic simulation is tested, and the reciprocal of the average memory usage is normalized and used as the weight coefficient for both. The similarity of power consumption waveforms and electromagnetic signals between each encryption algorithm in the aforementioned algorithm set 1 and the basic algorithm is calculated. The similarity is then weighted with the weight coefficient to obtain a comprehensive index, and the encryption algorithm with the highest comprehensive index is selected as the target algorithm.
[0066] It is understandable that any unit in the obfuscation control unit, whether it's the power simulation unit, electromagnetic simulation unit, or time simulation unit, will consume power during operation. If the obfuscation control unit is an external simulation relative to the drone chip, meaning the simulation process doesn't require the drone chip, then the power consumption of the simulation process can be disregarded. However, if the simulation process is run by the drone chip, the power consumption required for the simulation will ultimately be reflected on the drone chip's power pins. Therefore, to simulate the characteristics of other encryption algorithms, the power consumption of the simulation process must be taken into account. That is, the power consumption measured on the drone chip's power pins includes both real power consumption and simulated power consumption. Real power consumption is the sum of the power consumption of the drone chip performing encryption operations and the power consumption of electromagnetic and time simulations. Simulated power consumption is the result of the power simulation unit. After the real and simulated power consumption are dynamically superimposed, they should resemble the power consumption waveforms of other encryption algorithms to achieve the obfuscation purpose.
[0067] Please see Figure 3 In a preferred embodiment, directional simulation obfuscation of the side-channel feature parameters includes: S122-1: Real-time monitoring of the actual power consumption in the power circuit of the UAV chip, extraction of the target power consumption of the target algorithm when processing data; power consumption simulation based on the target power consumption and the actual power consumption, to achieve directional power consumption obfuscation of the power consumption waveform; S122-2: Shielding electromagnetic signals; generating electromagnetic confusion signals according to the target algorithm's electromagnetic signals, radiating the electromagnetic confusion signals into space, and completing the directional simulation confusion of electromagnetic signals; S122-3: Dynamically change the master clock frequency based on the instruction cycle consumption data of the target algorithm; generate a random phase offset sequence, and perform phase modulation on the clock signal based on the random phase offset sequence; start irrelevant tasks to change the time consumption distribution and realize directional simulation obfuscation of execution time.
[0068] After the target algorithm is selected, obfuscation processing can be performed by the obfuscation control module when the drone chip encrypts sensitive data according to the basic algorithm. The power obfuscation unit in the obfuscation control module is responsible for obfuscating the power consumption waveform of the drone chip's power pins into the power consumption waveform when processing sensitive data using the target algorithm; the electromagnetic obfuscation unit actively shields the electromagnetic signals of sensitive data processed according to the basic algorithm, while simulating the electromagnetic radiation signal of the target algorithm and spreading it into space; the time obfuscation unit extends the time for the drone chip to process sensitive data according to the basic algorithm to the time for processing target data according to the target algorithm.
[0069] When the drone begins processing sensitive data, the obfuscation process starts, with the power obfuscation unit, electromagnetic obfuscation unit, and time obfuscation unit in the obfuscation control module operating synchronously. The typical algorithm feature unit in the obfuscation control module sends the power consumption waveform of the target algorithm to the power obfuscation unit, the electromagnetic signal to the electromagnetic obfuscation unit, and the execution time to the time obfuscation unit.
[0070] In a preferred embodiment, during external simulation, power consumption simulation is performed based on the target power consumption and the actual power consumption, including: S122-1-1: Extract the actual power consumption and the target power consumption; S122-1-2: Use the power difference between the target power consumption and the actual power consumption as a power consumption analog quantity; simulate and generate power consumption analog quantities to achieve directional simulation obfuscation of power consumption waveforms.
[0071] It's important to note that the obfuscation control module can be either externally simulated or internally simulated. The difference lies in whether the entire simulation process is run by the UAV chip. For external simulation, the obfuscation control module's simulation process is not run by the UAV chip, and its energy consumption will not affect the detection results of the UAV chip's power pins. If the obfuscation control module's simulation process is run by the UAV chip (i.e., internal simulation), then the energy consumption of the obfuscation control module's simulation process will also be reflected on the UAV chip's power pins. Therefore, this energy consumption needs to be considered when performing power consumption simulation to ensure that the simulation results are the same as or similar to the power consumption waveform of the target algorithm.
[0072] When the obfuscation control module detects that the drone chip is processing sensitive data, it controls the power obfuscation unit, electromagnetic obfuscation unit, and time obfuscation unit to operate.
[0073] When the obfuscation control module performs obfuscation using external simulation, each obfuscation unit can operate independently. The specific steps are as follows: Power obfuscation unit: Real-time monitoring of the actual power consumption in the power circuit of the drone chip. The actual power consumption refers to the power consumption of the drone chip when encrypting sensitive data using the basic algorithm. At the same time, it extracts the power consumption of the target algorithm when processing data. The power consumption of the target algorithm minus the actual power consumption is the required simulated power consumption. The dynamic load regulator uses programmable resistors / capacitors to simulate this power consumption to achieve power obfuscation.
[0074] Electromagnetic confusion unit: This unit monitors the actual electromagnetic signals on the surface of the drone chip in real time, converts them to the frequency domain using FFT, and extracts characteristic frequency components. The DSP performs amplitude inversion and 180° phase shift processing on the actual electromagnetic signals to generate control parameters for the cancellation signal. The near-field shielded antenna emits an inverted signal based on the weighting coefficients output by the DSP, creating an electromagnetic null region on the chip surface. Simultaneously, the electromagnetic radiation simulator generates an electromagnetic confusion signal based on the electromagnetic signals from the target algorithm, radiating this signal into space through a far-field interference antenna. The intensity of this electromagnetic confusion signal needs to cover the power spectral density of the actual electromagnetic radiation from the drone chip.
[0075] Timing Obfuscation Unit: When the UAV chip processes sensitive data, the main clock frequency is dynamically changed via a programmable clock divider based on the instruction cycle time data of the target algorithm. A phase adjuster is used to randomly adjust the clock signal phase, making the timing relationship between adjacent instruction cycles irregular, further increasing the difficulty of analysis for attackers. Real-time monitoring of the CPU pipeline: When a sensitive instruction is detected entering the decoding stage, 1-3 invalid instructions are randomly inserted before and after the sensitive instruction to delay its execution timing. Sensitive operations such as encryption rounds can also be repeatedly executed, retaining only the result of the last operation. Parallel Operation Scheduler: When an encryption operation starts, the parallel operation scheduler selects 1-3 tasks from the unrelated task queue and executes them in parallel with the sensitive operation.
[0076] It is worth noting that before the obfuscation control module performs the obfuscation operation, it is necessary to extract the power consumption waveform, electromagnetic signal, and execution time corresponding to the target algorithm. Since whether the data corresponding to these data is sensitive is irrelevant when deriving the key based on power consumption, electromagnetic signal, and execution time, the power consumption waveform, electromagnetic signal, and execution time of the target algorithm do not need to correspond to sensitive data. These parameters can be obtained by simulating pre-set simulated data using the target algorithm.
[0077] In a preferred embodiment, during internal simulation, power consumption simulation is performed based on the target power consumption and the actual power consumption, including: S122-2-1: Extract the actual power consumption and target power consumption, as well as the power consumption consumed during directional hybrid simulation in real time, and mark it as additional power consumption. S122-1-2: The power difference between the target power consumption and the actual power consumption and the additional power consumption is used as the power consumption analog quantity; the power consumption analog quantity is generated to realize the directional simulation obfuscation of the power consumption waveform.
[0078] When the obfuscation control module uses internal simulation for obfuscation, each obfuscation unit can operate independently. Compared to external simulation, the power obfuscation unit in internal simulation must consider the energy consumption of each obfuscation unit to ensure that the simulated power consumption waveform is consistent with the power consumption waveform of the target algorithm. The operating steps of the electromagnetic obfuscation unit and the time obfuscation unit remain basically unchanged. The specific operating steps of the power obfuscation unit are as follows: Power obfuscation unit: Real-time monitoring of the actual power consumption in the power circuit of the drone chip. This actual power consumption refers to the power consumption of the drone chip when using the basic algorithm to encrypt sensitive data, as well as the energy consumption corresponding to the operation of each obfuscation unit (which can be measured by an on-chip power sensor). At the same time, it extracts the power consumption of the target algorithm when processing data. The power consumption of the target algorithm minus the actual power consumption and the energy consumption of each obfuscation unit is the required simulated power consumption. The dynamic load regulator uses programmable resistors / capacitors to simulate this power consumption to achieve power obfuscation.
[0079] The above embodiments are only used to illustrate the technical methods of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical methods of the present invention without departing from the spirit and scope of the technical methods of the present invention.
Claims
1. A method for sensitive data access control of UAV chips based on a trusted execution environment, characterized in that, include: Configure a trusted execution environment for the drone; Detect whether the drone chip performs data encryption; if yes, initiate real-time obfuscation processing of the side-channel characteristic parameters of the encryption process; the real-time obfuscation processing includes power consumption, electromagnetic signals, and execution time; Real-time obfuscation processing of the side-channel feature parameters includes: When a confusing command is detected, the side channel characteristic parameters of the UAV chip are detected in real time; these side channel characteristic parameters include power consumption waveform, electromagnetic signal, and execution time. The side channel feature parameters are subjected to targeted simulation obfuscation; Before performing the targeted simulation obfuscation, a target algorithm is selected, including: Determine the underlying algorithm for data encryption; Encryption algorithms whose execution time is longer than that of the basic algorithm are integrated into an algorithm set; Select an encryption algorithm from the set of algorithms that has similar power consumption waveform and electromagnetic signal to the basic algorithm as the target algorithm; Directional simulation obfuscation of the side-channel feature parameters includes: Real-time monitoring of the actual power consumption in the power circuit of the drone chip, extraction of the target power consumption of the target algorithm when processing data; power consumption simulation based on the target power consumption and the actual power consumption, to achieve directional power consumption obfuscation of the power consumption waveform; The electromagnetic signals are shielded; an electromagnetic confusion signal is generated according to the electromagnetic signals of the target algorithm, and the electromagnetic confusion signal is radiated into space to complete the directional simulation confusion of the electromagnetic signals; The master clock frequency is dynamically changed based on the instruction cycle time data of the target algorithm; a random phase offset sequence is generated, and the clock signal is phase-modulated based on the random phase offset sequence; irrelevant tasks are started to change the time consumption distribution and realize the directional simulation obfuscation of execution time. During internal simulation, power consumption simulation is performed based on the target power consumption and the actual power consumption, including: Extract the actual power consumption and the target power consumption, as well as the power consumption consumed during the directional hybrid simulation in real time, and mark them as additional power consumption. The power difference between the target power consumption and the actual power consumption and the additional power consumption is used as a power consumption analog quantity; the power consumption analog quantity is generated by simulation to achieve directional simulation obfuscation of the power consumption waveform; Encryption algorithms with power consumption waveforms and electromagnetic signals similar to the base algorithm were selected from the algorithm set as target algorithms, including: Extract the average memory usage of each encryption algorithm in the algorithm set during power consumption simulation and electromagnetic simulation; The reciprocal of the average memory usage was normalized and used as the weighting coefficient for power consumption simulation and electromagnetic simulation. The similarity of power consumption waveforms and electromagnetic signals between each encryption algorithm in the algorithm set and the basic algorithm is calculated; the similarity is weighted and calculated to obtain a comprehensive score, and the encryption algorithm with the highest comprehensive score is selected as the target algorithm.
2. The method for sensitive data access control of UAV chips based on a trusted execution environment according to claim 1, characterized in that, Real-time obfuscation processing of the side-channel feature parameters includes: When a confusing command is detected, the side channel characteristic parameters of the UAV chip are detected in real time; these side channel characteristic parameters include power consumption waveform, electromagnetic signal, and execution time. The side channel characteristic parameters are randomly simulated and obfuscated.
3. The method for sensitive data access control of UAV chips based on a trusted execution environment according to claim 2, characterized in that, Randomly simulate and obfuscate the power consumption waveform, including: The power consumption waveform is labeled as the base power consumption; A random power consumption is generated, and the random power consumption is dynamically superimposed on the basic power consumption to complete the random simulation and obfuscation of power consumption.
4. The method for sensitive data access control of UAV chips based on a trusted execution environment according to claim 2, characterized in that, Randomly simulate and obfuscate the electromagnetic signal, including: Shield the electromagnetic signals; An electromagnetic confusion signal is generated and radiated into space to complete the random simulation confusion of the electromagnetic signal.
5. The method for sensitive data access control of UAV chips based on a trusted execution environment according to claim 2, characterized in that, Randomly simulated obfuscation of the execution time includes: Dynamically change the master clock frequency; A random phase offset sequence is generated, and the clock signal is phase modulated based on the random phase offset sequence; Initiate irrelevant tasks to change the time consumption distribution and achieve random simulation and obfuscation of execution time.
6. The method for sensitive data access control of UAV chips based on a trusted execution environment according to claim 1, characterized in that, During external simulation, power consumption simulation is performed based on the target power consumption and the actual power consumption, including: Extract the actual power consumption and the target power consumption; The power difference between the target power consumption and the actual power consumption is used as a power consumption analog quantity; the power consumption analog quantity is generated by simulation to achieve directional simulation obfuscation of the power consumption waveform.