Alarm control method of security chip and electronic equipment
By using clock signal detection and feedback signal sampling in the security chip, and improving it to a single-input single-output structure, the problem of the sensor module output being vulnerable to attack is solved, thus improving the security and alarm accuracy of the security chip.
Patent Information
- Application Number
- CN202511119297.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-11
- Publication Date
- 2025-11-11
AI Technical Summary
The sensor module output of existing security chips is easily compromised by attacks that can fix the value, causing it to fail to trigger an alarm and resulting in low security.
Using a clock signal as the detection signal, the sensing module responds to the detection signal by outputting a feedback signal. The detection signal and feedback signal are sampled by sampling the clock signal, and the alarm is determined based on the level. The structure is improved to a single input and single output to enhance safety.
This improves the security of the security chip, reduces the risk of it being attacked and failing to alarm, and enhances the accuracy and reliability of alarms.
Smart Images

Figure CN120932370A_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to the field of security chip technology, and in particular to an alarm control method and electronic device for a security chip. Background Technology
[0002] With the development of security and sensing technologies, security chips with integrated sensing functions have been widely used in environmental security monitoring and anomaly detection, data security protection, identity authentication and access control, system integrity assurance, and dynamic security response.
[0003] Currently, the sensor module output in security chips is dual-channel. It doesn't alarm when the sensor output is 10, but alarms when it outputs other values. However, the sensor module output can be easily manipulated to a fixed value, thus preventing alarms from triggering and resulting in low security for the security chip. Summary of the Invention
[0004] To solve the above-mentioned technical problems, or at least partially solve them, this disclosure provides an alarm control method and electronic device for a security chip.
[0005] A first aspect of this disclosure provides an alarm control method for a security chip, the security chip including a sensing module and a control module, wherein the method includes:
[0006] The control module outputs a detection signal to the sensing module, wherein the detection signal is a clock signal;
[0007] The sensing module outputs a feedback signal in response to the detection signal, wherein, in the absence of an event triggering an alarm, the feedback signal is a signal obtained by processing the detection signal according to a preset clock processing method;
[0008] When the alarm function of the sensing module is enabled, the control module samples the detection signal based on the sampling clock signal to obtain a first level and samples the feedback signal based on the sampling clock signal to obtain a second level, and determines whether to alarm based on the first level and the second level.
[0009] A second aspect of this disclosure provides an alarm control device for a security chip, the security chip including a sensing module and a control module, wherein the device includes:
[0010] The first output module is used for the control module to output a detection signal to the sensing module, wherein the detection signal is a clock signal;
[0011] The second output module is used for the sensing module to output a feedback signal in response to the detection signal, wherein, in the absence of an event that triggers an alarm, the feedback signal is a signal obtained by processing the detection signal according to a preset clock processing method;
[0012] The first determining module is configured to, when the alarm function of the sensing module is enabled, have the control module sample the detection signal based on the sampling clock signal to obtain a first level and sample the feedback signal based on the sampling clock signal to obtain a second level, and determine whether to trigger an alarm based on the first level and the second level.
[0013] A third aspect of this disclosure provides an electronic device that includes an alarm control device for the security chip described in the second aspect.
[0014] The technical solution provided in this disclosure has the following advantages compared with the prior art:
[0015] In this embodiment, the control module outputs a detection signal to the sensing module, wherein the detection signal is a clock signal; the sensing module responds to the detection signal by outputting a feedback signal, wherein, in the absence of an alarm-triggered event, the feedback signal is a signal obtained by processing the detection signal according to a preset clock processing method; when the alarm function of the sensing module is enabled, the control module samples the detection signal based on the sampling clock signal to obtain a first level and samples the feedback signal based on the sampling clock signal to obtain a second level, and determines whether to trigger an alarm based on the first level and the second level. It can be seen that by adopting the above technical solution, the sensing module is improved from dual-output in related technologies to single-input single-output, allowing the control module to input a detection signal to the sensing module and the sensing module to output a feedback signal. This enables the control module to collect and detect the detection signal and the feedback signal to determine whether an alarm-triggered event has occurred, and then to trigger an alarm when an alarm-triggered event is determined to have occurred. Since the detection signal is a more complex clock signal that is not easily attacked or modified, and since the detection signal is output by the control module, if it is modified, it can be easily detected by the control module. Furthermore, the feedback signal is a more complex signal output in response to the more complex detection signal that is not easily attacked or modified. Therefore, compared with related technologies, the embodiments disclosed in this disclosure can make the security chip less susceptible to attack and prevent it from triggering an alarm, thereby improving security. Attached Figure Description
[0016] The accompanying drawings, which are incorporated in and form a part of this specification, illustrate embodiments consistent with this disclosure and, together with the description, serve to explain the principles of this disclosure.
[0017] To more clearly illustrate the technical solutions in the embodiments of this disclosure or the prior art, the accompanying drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, for those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0018] Figure 1 This is a schematic diagram of the structure of a security chip provided by related technologies;
[0019] Figure 2 It is a timing diagram of various signals in a security chip provided by related technologies;
[0020] Figure 3 This is a flowchart of an alarm control method for a security chip provided in an embodiment of this disclosure;
[0021] Figure 4 This is a schematic diagram of the structure of a security chip provided in an embodiment of this disclosure;
[0022] Figure 5 This is a timing diagram of various signals in a security chip provided in an embodiment of this disclosure;
[0023] Figure 6 This is a schematic diagram of the structure of an alarm control device for a security chip provided in an embodiment of this disclosure. Detailed Implementation
[0024] To better understand the above-mentioned objectives, features, and advantages of this disclosure, the solutions disclosed herein will be further described below. It should be noted that, unless otherwise specified, the embodiments and features described herein can be combined with each other.
[0025] Numerous specific details are set forth in the following description in order to provide a full understanding of this disclosure, but this disclosure may also be implemented in other ways different from those described herein; obviously, the embodiments in the specification are only some, and not all, of the embodiments of this disclosure.
[0026] With the development of security and sensing technologies, security chips with integrated sensing functions have been widely used in the following fields: I. Environmental safety monitoring and anomaly detection: (1) Basic physical parameter monitoring: Real-time detection of environmental parameters such as temperature, humidity, and light intensity to ensure the safety of the operating environment of equipment or systems. (2) Intrusion and danger identification: Identifying abnormal states such as children left in vehicles or illegal intrusions through radar or optical sensors, triggering alarms or linkage protection measures. II. Data security protection: (1) End-to-end encrypted transmission: Hardware-level encryption of sensitive data (such as biometrics and location information) collected by sensors to prevent tampering or theft during transmission. (2) Localized data processing: Data analysis is completed directly within the chip through edge computing and deep learning algorithms, reducing the security risks caused by relying on external systems. III. Identity authentication and access control: (1) Device identity binding: Storing unique device identifiers and keys to ensure that only authorized devices can access the system or network, preventing counterfeit terminal access. (2) User identity verification: Chips integrating biometric sensors such as fingerprints and voiceprints can encrypt and store user feature data and complete verification for unlocking or access control. IV. System Integrity Assurance: (1) Firmware Secure Boot: Verify firmware signature through chip to prevent unauthorized software or malicious code from loading, ensuring a trustworthy operating environment for the device. (2) Operation Log Protection: Encrypt and store sensor operation records and alarm events to prevent logs from being tampered with or deleted, meeting audit and traceability requirements. V. Dynamic Security Response: (1) Linkage Control: When an anomaly (such as high temperature or intrusion) is detected, automatically trigger power outage, lockout, or notify a third-party security system to form a closed-loop protection. (2) Adaptive Strategy Adjustment: Dynamically adjust sensor sampling frequency or encryption strength according to environmental risk level to balance security and energy efficiency. The technological development trend is to further integrate AI algorithms and low-power design, improve detection accuracy through multimodal sensing collaboration (such as radar + infrared), and support new protection technologies such as quantum encryption to cope with advanced attacks.
[0027] Figure 1 This is a schematic diagram of the structure of a security chip provided by related technologies. Figure 2 This is a timing diagram of various signals in a security chip provided by related technologies. For example... Figure 1 and Figure 2As shown, current security chips include a sensor module (SENSOR) and a control module (CTRL). EN is the enable signal; a high enable signal will generate an alarm. TEST_EN is the test enable signal; a high test enable signal will always trigger an alarm. It is used to detect whether the sensor module is working. OUT and OUTN are dual-channel output signals, with OUT and OUTN being opposite. DIG_CLK is the sampling clock signal for sampling OUT and OUTN. As shown in Table 1, if OUTN is 0 and OUT is 1, there is no alarm (DIG_ALM is low); other combinations trigger an alarm (DIG_ALM is high). However, a stable output signal that does not trigger an alarm is inherently insecure, as it can be easily attacked to a fixed value, thus preventing alarm generation. Furthermore, an alarm requires the enable signal to be on; if the enable signal is off, there will be no alarm. However, the enable signal is a single signal, which can be easily attacked to a disabled state, preventing alarm generation. Therefore, the security of the security chip is relatively low.
[0028] Table 1
[0029]
[0030] In view of this, this disclosure provides an alarm control method and electronic device for a security chip. The alarm control method for the security chip will be described in detail below.
[0031] Figure 3 This is a flowchart illustrating an alarm control method for a security chip according to an embodiment of this disclosure. The method can be executed by a security chip, which includes a sensing module and a control module. This security chip can be understood, for example, as an eSE (eSecurity Detection and Separation) chip, or a combination chip integrating eSE and eSIM, but is not limited thereto. Figure 3 As shown, the method provided in this embodiment includes the following steps:
[0032] S110, The control module outputs a detection signal to the sensing module, wherein the detection signal is a clock signal.
[0033] For example, Figure 4 This is a schematic diagram of the structure of a security chip provided in an embodiment of this disclosure. Figure 5 This is a timing diagram of various signals in a security chip provided in an embodiment of this disclosure. For example... Figure 4 and Figure 5 As shown in this application, the control module (i.e., SENSOR) can output a detection signal CLK_IN to the sensing module (i.e., CTRL).
[0034] Regarding whether the frequency of the detection signal is fixed: In some embodiments, the frequency of the detection signal is fixed.
[0035] In some embodiments, the frequency of the detection signal is not fixed. In some examples, the frequency of the detection signal is updated once every preset time interval, i.e., the frequency of the detection signal is updated periodically. In other examples, the frequency of the detection signal is updated in response to a user-set frequency update command. In still other embodiments, the frequency of the detection signal output by the control module to the sensor module is different at least twice after the alarm function of the sensor module is enabled. Further optionally, the frequency of the detection signal output to the sensor module is different each time the alarm function of the sensor module is enabled, or the frequency of the detection signal output to the sensor module after enabling the alarm function this time is different from the frequency of the detection signal output to the sensor module after enabling the alarm function last time. In still other embodiments, the frequency of the detection signal output by the control module to the sensor module is different at least twice after power-on. Further optionally, the frequency of the detection signal output to the sensor module is different each time after power-on, or the frequency of the detection signal output to the sensor module after power-on this time is different from the frequency of the detection signal output to the sensor module after power-on last time.
[0036] It is understandable that by setting the frequency of the detection signal to be variable, the detection signal can be varied, which in turn will also make the feedback signal more variable. This increases the difficulty for attackers to modify the detection signal and feedback signal to prevent alarms, thereby improving the security of the security chip.
[0037] Regarding the specific value of the frequency of the detection signal: In some embodiments, the frequency of the sampling clock signal is a positive integer multiple of the frequency of the detection signal, and the phase difference between the sampling clock signal and the detection signal is greater than 0.
[0038] Specifically, the exact multiple of the "frequency of the sampling clock signal" to the "frequency of the detection signal" can be set by those skilled in the art according to specific circumstances, and is not limited here. For example, the "frequency of the sampling clock signal" is m times the "frequency of the detection signal," where m is greater than or equal to 1 and less than or equal to 100. Figure 5 As shown, m = 1, meaning the frequency of the sampling clock signal DIG_CLK is the same as the frequency of the detection signal CLK_IN. Of course, m can also be 2, 3, 4 or 5, etc., but is not limited to this.
[0039] Specifically, the specific value of the phase difference can be set by those skilled in the art according to the actual situation, and is not limited here. In some examples, the phase difference is greater than or equal to one-eighth of the period of the detection signal and less than or equal to three-eighths of the period of the detection signal, or the phase difference is greater than or equal to five-eighths of the period of the detection signal and less than or equal to seven-eighths of the period of the detection signal. For example, the phase difference is equal to one-quarter of the period of the detection signal (e.g., Figure 5(as shown), but not limited to these examples. In some other examples, the phase difference is greater than or equal to one-eighth of the sampling clock signal period and less than or equal to three-eighths of the sampling clock signal period, or the phase difference is greater than or equal to five-eighths of the sampling clock signal period and less than or equal to seven-eighths of the sampling clock signal period, for example, the phase difference is equal to one-quarter of the sampling clock signal period, etc., but not limited to these examples.
[0040] It should be noted that the "phase difference between the sampling clock signal and the detection signal" can be fixed or variable. In some examples, the phase difference is updated periodically after a preset time interval. In other examples, the phase difference is updated in response to a user-defined phase difference update command. In still other embodiments, the phase difference is different after at least two activations of the sensor module's alarm function; further optionally, the phase difference is different each time the sensor module's alarm function is activated, or the phase difference after the current activation of the sensor module's alarm function is different from the previous activation. In yet another embodiment, the phase difference of the control module is different after at least two power-ups; further optionally, the phase difference is different each time the module is powered on, or the phase difference after the current power-up is different from the previous power-up. This further increases the difficulty for an attacker to modify the detection signal and feedback signal to prevent an alarm, thereby improving the security of the security chip.
[0041] It is understandable that by setting the frequency of the sampling clock signal to an integer multiple of the frequency of the detection signal, and by having a phase difference between the sampling clock signal and the detection signal, it is less likely that the sampling of the detection signal based on the sampling clock signal will occur at the rising or falling edge of the detection signal, thereby improving the accuracy of the sampling of the detection signal and thus improving the accuracy of the alarm.
[0042] Specifically, there are various implementation methods for generating detection signals. Typical examples are described below, but they do not constitute a limitation of this disclosure.
[0043] In some embodiments, optionally, the control module outputs a detection signal to the sensing module, including: generating a random number, wherein the frequency of the sampling clock signal is a positive integer multiple of the random number; and generating a detection signal with a random number of frequency.
[0044] Specifically, a detection signal with a random frequency is generated based on the phase difference between the sampling clock signal and the detection signal being greater than 0. The phase difference can be randomly selected from the following ranges: greater than or equal to one-eighth of the detection signal's period and less than or equal to three-eighths of the detection signal's period; or a phase difference greater than or equal to five-eighths of the detection signal's period and less than or equal to seven-eighths of the detection signal's period; greater than or equal to one-eighth of the sampling clock signal's period and less than or equal to three-eighths of the sampling clock signal's period; or a phase difference greater than or equal to five-eighths of the sampling clock signal's period and less than or equal to seven-eighths of the sampling clock signal's period.
[0045] Understandably, the above-mentioned method of generating detection signals can increase the randomness of the detection signal frequency, thereby increasing the unpredictability of the detection signal and further increasing the difficulty for attackers to modify the detection signal and feedback signal to prevent alarms, thus improving the security of the security chip.
[0046] In another example, optionally, the control module outputs a detection signal to the sensing module, including: removing candidate parameter pairs used in the previously generated detection signal from multiple candidate parameter pairs, wherein a candidate parameter pair includes a frequency (the frequency of the sampling clock signal is an integer multiple of that frequency) and a phase difference (greater than 0); randomly selecting a target parameter pair from the remaining candidate parameter pairs; and generating a detection signal based on the target parameter pair.
[0047] S120, the sensing module responds to the detection signal and outputs a feedback signal. In the absence of an event that triggers an alarm, the feedback signal is a signal obtained by processing the detection signal according to a preset clock processing method.
[0048] In this application, after the security chip completes initialization, if no alarm-triggered event occurs, the sensing module can process the detection signal according to a preset clock processing method, and no alarm is needed. If an alarm-triggered event occurs, the sensing module will not process the detection signal according to the preset clock processing method, and an alarm should be triggered. Of course, in some other embodiments, the sensing module has a self-test function, and the security chip performs a self-test of the sensing module during power-on initialization. See also, for examples... Figure 4 and Figure 5 After the security chip is powered on, it will perform a self-test during the initialization process, as follows: the level of the test enable signal TEST_EN output by the control module to the sensing module is an effective level (for example, a high level as shown in the figure), which enables the self-test function of the sensing module. At this time, the sensing module does not process the detection signal in any way so as to trigger an alarm (the alarm signal DIG_ALM is high).
[0049] Optionally, the preset clock processing method includes inversion. It is understood that inverting the detection signal is simple to operate and ensures that the detection signal and feedback signal have the same frequency. Thus, by setting the frequency of the "sampling clock signal" to an integer multiple of the "detection signal frequency," and ensuring a phase difference between the sampling clock signal and the detection signal, it is less likely that sampling of the detection signal based on the sampling clock signal will occur at the rising or falling edge of the detection signal. Similarly, it is less likely that sampling of the feedback signal based on the sampling clock signal will occur at the rising or falling edge of the feedback signal, thereby improving the accuracy of sampling the detection and feedback signals, and consequently improving the accuracy of the alarm. Of course, in other embodiments, the preset clock processing method may also include frequency division, frequency multiplication, or phase shifting, but is not limited to these.
[0050] S130. When the alarm function of the sensing module is enabled, the control module samples the detection signal based on the sampling clock signal to obtain a first level and samples the feedback signal based on the sampling clock signal to obtain a second level, and determines whether to alarm based on the first level and the second level.
[0051] Specifically, there are various ways to enable the sensing module. The following are typical examples, but they do not constitute a limitation of this disclosure.
[0052] In some embodiments, the step of enabling the alarm function of the sensing module includes: the control module outputting at least two enable signals to the sensing module; if the at least two enable signals meet the preset enable conditions, the sensing module activates the alarm function.
[0053] Specifically, the number of enable signals can be set by those skilled in the art according to the actual situation, and is not limited here. For example, the number of enable signals is n, where n = 2, 3, or 4, etc., but is not limited to this.
[0054] Understandably, the more enable signals there are, the more difficult it is for an attacker to disable the enable signals, and thus the less likely it is to enable the alarm function. This helps to improve the security of the security chip.
[0055] In some examples, at least two enable signals are level signals, and the total number of at least two enable signals is n, such that the encoded values of at least two enable signals have 2. n The preset enable conditions include: the current encoded values of at least two enable signals are preset encoded values, wherein the preset encoded values are 2 of the current encoded values of at least two enable signals. n Any (2) of the encoded values n -1) encoded values.
[0056] Specifically, each enable signal is either high or low; therefore, at least two enable signals have 2 encoded values. n A combination. See also, for examples. Figure 4 and Figure 5 Both EN and ENN are enable signals. EN and ENN have four encoded values: 00, 01, 10, and 11, where 0 represents a low level and 1 represents a high level.
[0057] Specifically, those skilled in the art can refer to 2 n Randomly select (2) from the encoded values n -1) is used as the preset encoding value. For example, as shown in Table 2, the preset encoding values are 00, 10 and 11. If the current encoding value composed of EN and ENN is 01 (i.e. EN is low and ENN is high), the alarm function is enabled. If the current encoding value composed of EN and ENN is 00, 10 or 11, the alarm function is enabled.
[0058] Table 2
[0059]
[0060] Understandably, by changing the alarm function enable control to multi-enable signal control, which has multiple combinations of encoded values, only one of which disables the alarm function, attackers will find it difficult to find the encoded value that disables the alarm function. This reduces the risk that the sensor module will fail to alarm after being attacked, thereby improving the reliability and security of the security chip.
[0061] Of course, in other embodiments, the alarm function can also be controlled by a single enable signal.
[0062] Specifically, the detection signal and feedback signal can be sampled at the rising edge and / or falling edge of the sampling clock signal to obtain the first level and the second level.
[0063] In some embodiments, determining whether to alarm based on a first level and a second level includes: determining a first reference level based on a detection signal and a preset clock processing method, wherein the first reference level refers to the processed level corresponding to the first level when the detection signal is processed based on the preset clock processing method; if the second level is the same as the first reference level, no alarm is triggered; if the second level is different from the first reference level, an alarm is triggered.
[0064] Specifically, in some examples, if the preset clock processing method is inversion, the first level can be inverted to obtain the first reference level. Of course, in other examples, the detection signal can also be processed by a preset clock to obtain a reference signal, and the level at time T can be sampled from the reference signal to obtain the first reference level, where time T is the time corresponding to the first level in the detection signal.
[0065] Specifically, as mentioned above, after the security chip completes initialization, if no alarm-triggered event occurs, the sensing module can process the detection signal according to a preset clock processing method. The feedback signal is then obtained by processing the detection signal according to this preset clock processing method. Therefore, if no alarm-triggered event occurs, the second level and the first reference level should be the same. Based on this, if the second level and the first reference level are the same, it indicates that the sensing module has processed the detection signal according to the preset clock processing method, and no alarm-triggered event has occurred; in this case, no alarm is needed. If the second level and the first reference level are different, it indicates that the sensing module has not processed the detection signal according to the preset clock processing method, and an alarm-triggered event has occurred; in this case, an alarm should be triggered.
[0066] For example, see [link to previous article] Figure 5 The default clock processing method is inversion. The alarm is determined by the detection signal CLK_IN and the feedback signal CLK_OUT. The truth table is shown in Table 3. If CLK_OUT is the inversion of CLK_IN, no alarm is triggered. If CLK_OUT is not the inversion of CLK_IN, an alarm is triggered.
[0067] Table 3
[0068]
[0069] Optionally, before determining the first reference level based on the detection signal and a preset clock processing method, the method further includes: determining whether the detection signal transmitted between the sensing module and the control module has been modified; if not modified, determining the first reference level based on the detection signal and the preset clock processing method; if modified, triggering an alarm. This further improves the accuracy of the alarm.
[0070] In one example, this can be achieved by comparing the original set values of the detection signal (such as frequency, duty cycle, phase, etc.) to verify whether the detection signal transmitted between the sensing module and the control module matches the expected value, thereby determining whether it has been modified. For example, a second reference level is determined, where the second reference level is the level corresponding to time T if the detection signal has not been modified; if the first level is different from the second reference level, it indicates that the detection signal has been modified by an attacker; if the first level is the same as the second reference level, it indicates that the detection signal has not been modified.
[0071] In this embodiment, the sensing module is improved from a dual-output design in related technologies to a single-input, single-output design. This allows the control module to input a detection signal to the sensing module, and the sensing module to output a feedback signal. The control module can then collect and detect both the detection and feedback signals to determine if an alarm-triggered event has occurred, and trigger an alarm when such an event is confirmed. Because the detection signal is a more complex clock signal, making it less susceptible to attack and modification, and because the detection signal is output by the control module and any modification to it is easily detected by the control module, and because the feedback signal is a more complex signal output in response to the more complex detection signal, making it less vulnerable to attack and modification, this embodiment, compared to related technologies, makes the security chip less susceptible to attacks that could prevent alarms from being triggered, thereby improving security.
[0072] The alarm control method of the security chip provided in this disclosure will be explained in detail below with a specific example. See also... Figure 4 and Figure 5 After the security chip powers on, it performs a self-test during the initialization phase. The self-test switch is the test enable signal TEST_EN. Each sensor module in the security chip has a self-test function. When the self-test is enabled, an alarm will definitely occur, indicating that the sensor module exists and is in normal working condition. After the self-test is completed, the security chip starts working and will not perform a self-test again; that is, it will perform a self-test once every time it powers on. After the self-test is completed, the alarm function of the sensor module is enabled by software or hardware. If an action that can trigger an alarm occurs, an alarm signal DIG_ALM is output. After the security chip detects the alarm, it will take corresponding actions to protect the data stored in the security chip. The alarm function of the sensor module depends on alarm enable and alarm output. Therefore, the embodiments of this disclosure strengthen the control methods for alarm enable and alarm output. Specifically, an ENN is added to make the sensor module less likely to be turned off (single signal enable is easy to turn off); the alarm output method is modified by changing the stable output to a clock output, and comparing CLK_OUT and CLK_IN on both the rising and falling edges of DIG_CLK. This reduces the possibility of the alarm not sounding after being attacked and proves that the sensor module exists and is always in a normal working state (the original dual outputs were both stable signals, which could not prove that the sensor module existed and was still working normally after the self-test was completed).
[0073] In this embodiment, the dual-channel output of the sensing module is changed to a single-input, single-output configuration. The input is replaced with an adjustable-frequency clock signal. After processing by the sensing module according to a preset method, the output is sent to the control module and compared with the input to check if it meets expectations. If it does not meet expectations, an alarm is triggered. Furthermore, the alarm enable is changed to dual-channel control. The dual-channel enable signal has four combinations, three of which are enable signals and only one is disable signal, reducing the risk of the sensing module shutting down after an attack. This improves the reliability and security of the security chip.
[0074] Figure 6 This is a schematic diagram of the structure of an alarm control device for a security chip provided in this disclosure embodiment. The alarm control device for the security chip can be understood as the aforementioned electronic device or a functional module within the aforementioned electronic device. For example... Figure 6 As shown, the alarm control device of this security chip includes:
[0075] The first output module 610 is used for the control module to output a detection signal to the sensing module, wherein the detection signal is a clock signal;
[0076] The second output module 620 is used for the sensing module to output a feedback signal in response to the detection signal, wherein, in the absence of an event triggering an alarm, the feedback signal is a signal obtained by processing the detection signal according to a preset clock processing method;
[0077] The first determining module 630 is used to, when the alarm function of the sensing module is enabled, have the control module sample the detection signal based on the sampling clock signal to obtain a first level and sample the feedback signal based on the sampling clock signal to obtain a second level, and determine whether to alarm based on the first level and the second level.
[0078] Optionally, the frequency of the detection signal output by the control module to the sensing module is different at least twice after power-on.
[0079] Optionally, the frequency of the sampling clock signal is a positive integer multiple of the frequency of the detection signal, and the phase difference between the sampling clock signal and the detection signal is greater than 0.
[0080] The first output module 610 is specifically used to generate random numbers, wherein the frequency of the sampling clock signal is a positive integer multiple of the random number;
[0081] The detection signal is generated at a frequency of the random number.
[0082] Optionally, the preset clock processing method includes inversion.
[0083] Optionally, the first determining module 630 includes a first determining unit, used to determine whether an alarm is triggered based on the first level and the second level. Specifically, the first determining unit is used to determine a reference level based on the detection signal and the preset clock processing method. The reference level refers to the processed level corresponding to the first level when the detection signal is processed based on the preset clock processing method.
[0084] If the second level is the same as the reference level, no alarm will be triggered; if the second level is different from the reference level, an alarm will be triggered.
[0085] Optionally, the device further includes a first enabling module for enabling the alarm function of the sensing module. Specifically, the first enabling module is used for the control module to output at least two enabling signals to the sensing module.
[0086] If at least two enable signals meet the preset enable conditions, the sensing module will activate the alarm function.
[0087] Optionally, both of the at least two enable signals are level signals, and the total number of the at least two enable signals is n, such that the encoded values of the at least two enable signals have 2. n indivual;
[0088] The preset enable condition includes: the current encoded value of the at least two enable signals is a preset encoded value, wherein the preset encoded value is 2 of the at least two enable signals. n Any (2) of the encoded values n -1) encoded values.
[0089] The apparatus provided in this embodiment can execute the methods of any of the above embodiments, and its execution method and beneficial effects are similar, so they will not be described again here.
[0090] This disclosure also provides an electronic device, which includes an alarm control device for the security chip described in any of the above embodiments.
[0091] For example, the electronic devices in the embodiments of this disclosure may include, but are not limited to, mobile terminals such as mobile phones, laptops, digital broadcast receivers, PDAs (personal digital assistants), PADs (tablet computers), PMPs (portable multimedia players), in-vehicle terminals (e.g., in-vehicle navigation terminals), and fixed terminals such as digital TVs and desktop computers.
[0092] Electronic devices may include processing units (such as central processing units, graphics processing units, etc.) that can perform various appropriate actions and processes based on programs stored in read-only memory (ROM) or loaded from storage devices into random access memory (RAM). RAM also stores various programs and data required for the operation of the electronic device. The processing unit, ROM, and RAM are interconnected via a bus. Input / output (I / O) interfaces are also connected to the bus.
[0093] Typically, the following devices can be connected to the I / O interface: input devices such as touchscreens, touchpads, keyboards, mice, cameras, microphones, accelerometers, gyroscopes, etc.; output devices such as liquid crystal displays (LCDs), speakers, vibrators, etc.; storage devices such as magnetic tapes, hard drives, etc.; and communication devices. Communication devices allow electronic devices to communicate wirelessly or wiredly with other devices to exchange data.
[0094] Regarding the flowcharts and block diagrams in the accompanying drawings, each block may represent a module, segment, or portion of code containing one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.
[0095] It should be noted that, in this document, relational terms such as "first" and "second" are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
[0096] The above description is merely a specific embodiment of this disclosure, enabling those skilled in the art to understand or implement it. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of this disclosure. Therefore, this disclosure is not to be limited to the embodiments described herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. An alarm control method for a security chip, characterized in that, The security chip includes a sensing module and a control module, wherein the method includes: The control module outputs a detection signal to the sensing module, wherein the detection signal is a clock signal; The sensing module outputs a feedback signal in response to the detection signal, wherein, when no alarm-triggered event occurs, the feedback signal is a signal obtained by processing the detection signal according to a preset clock processing method; When the alarm function of the sensing module is enabled, the control module samples the detection signal based on the sampling clock signal to obtain a first level and samples the feedback signal based on the sampling clock signal to obtain a second level, and determines whether to alarm based on the first level and the second level.
2. The method according to claim 1, characterized in that, The frequency of the detection signal output by the control module to the sensing module is different at least twice after power-on.
3. The method according to claim 2, characterized in that, The frequency of the sampling clock signal is a positive integer multiple of the frequency of the detection signal, and the phase difference between the sampling clock signal and the detection signal is greater than 0.
4. The method according to claim 3, characterized in that, The control module outputs a detection signal to the sensing module, including: Generate random numbers, wherein the frequency of the sampling clock signal is a positive integer multiple of the random numbers; The detection signal is generated at a frequency of the random number.
5. The method according to claim 1, characterized in that, The preset clock processing method includes inversion.
6. The method according to claim 1, characterized in that, The process of determining whether to trigger an alarm based on the first and second voltage levels includes: Based on the detection signal and the preset clock processing method, a first reference level is determined, wherein the first reference level refers to the processed level corresponding to the first level when the detection signal is processed based on the preset clock processing method; If the second level is the same as the first reference level, no alarm will be triggered; if the second level is different from the first reference level, an alarm will be triggered.
7. The method according to claim 1, characterized in that, The steps to enable the alarm function of the sensing module include: The control module outputs at least two enable signals to the sensing module; If at least two enable signals meet the preset enable conditions, the sensing module will activate the alarm function.
8. The method according to claim 7, characterized in that, The at least two enable signals are both level signals, and the total number of the at least two enable signals is n, such that the encoded values of the at least two enable signals have 2. n indivual; The preset enable condition includes: the current encoded value of the at least two enable signals is a preset encoded value, wherein the preset encoded value is 2 of the at least two enable signals. n Any (2) of the encoded values n -1) encoded values.
9. An alarm control device for a security chip, characterized in that, include: The security chip includes a sensing module and a control module, wherein the device includes: The first output module is used for the control module to output a detection signal to the sensing module, wherein the detection signal is a clock signal; The second output module is used for the sensing module to output a feedback signal in response to the detection signal, wherein, in the absence of an event that triggers an alarm, the feedback signal is a signal obtained by processing the detection signal according to a preset clock processing method; The first determining module is configured to, when the alarm function of the sensing module is enabled, have the control module sample the detection signal based on the sampling clock signal to obtain a first level and sample the feedback signal based on the sampling clock signal to obtain a second level, and determine whether to trigger an alarm based on the first level and the second level.
10. An electronic device, characterized in that, include: The alarm control device for the security chip as described in claim 9.