End-to-end protection method, system and device of system on chip and storage medium

By generating and verifying check codes for bus interface signals in the system-on-chip, the problem of insufficient data transmission security in SoC is solved, achieving protection and reliability of the entire data transmission path and improving system security.

CN121008957APending Publication Date: 2025-11-25CALTERAH SEMICON TECH (SHANGHAI) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410651124.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-05-23
Publication Date
2025-11-25

AI Technical Summary

Technical Problem

Existing System-on-Chip (SoC) lacks system-level end-to-end protection during data transmission, resulting in insufficient security and making it difficult to ensure the reliability and integrity of data transmission.

Method used

A system-level end-to-end protection scheme based on bus interface signals is adopted. By generating signals and check codes at the transmitting end of the on-chip system and performing multiple checks at the bus and receiving ends, the integrity and reliability of the signals on the transmission path are ensured.

Benefits of technology

It achieves protection of the entire data transmission path, improves the security of the on-chip system, can quickly locate abnormal problems in the transmission process, and ensures the reliability and integrity of data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121008957A_ABST
    Figure CN121008957A_ABST
Patent Text Reader

Abstract

The invention discloses an end-to-end protection method, system and device for a system on chip, and a storage medium. The method comprises the following steps: a first sending end in the system on chip generates a first signal, obtains a corresponding first check code, and sends the first signal and the first check code to a first bus; the first bus receives the first signal and the first check code, and forwards the first signal and the first check code to a first receiving end in the system on chip under the condition that the first check code is verified to be correct according to the first signal; and the first receiving end receives the first signal and the first check code, and executes processing for the first signal under the condition that the first check code is verified to be correct according to the first signal. The scheme of the invention is a system-level end-to-end protection scheme based on the bus interface signal of the system-on-chip, the protection of a full data transmission path is realized, and the security and the error positioning accuracy of the system-on-chip are further improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the chip field, and in particular to an end-to-end protection method, system, device and storage medium of a system on chip. BACKGROUND

[0002] With the continuous evolution of chip design, the functional safety related design is paid more and more attention when developing a system on chip (SoC). The end-to-end protection inside the SoC is also particularly important. It is the direction of safety improvement in the SoC field to propose a system-level end-to-end protection scheme. SUMMARY

[0003] The present application provides an end-to-end protection method, system, electronic device and storage medium of a system on chip, proposes a system-level end-to-end protection scheme of a system on chip based on a bus interface signal, realizes the protection of the whole data transmission path, and further improves the security of the system on chip.

[0004] The present application provides an end-to-end protection method of a system on chip, comprising:

[0005] The first sending end in the system on chip generates a first signal and acquires a corresponding first check code, and sends the first signal and the first check code to the first bus;

[0006] The first bus receives the first signal and the first check code, and forwards the first signal and the first check code to the first receiving end in the system on chip in the case that the first check code is verified to be correct according to the first signal;

[0007] The first receiving end receives the first signal and the first check code, and performs processing on the first signal in the case that the first check code is verified to be correct according to the first signal.

[0008] The present application also provides a system on chip, comprising:

[0009] The first sending end, the first bus and the first receiving end;

[0010] The first sending end is configured to generate a first signal and acquire a corresponding first check code, and send the first signal and the first check code to the first bus;

[0011] The first bus is configured to receive the first signal and the first check code, and forward the first signal and the first check code to the first receiving end in the system on chip in the case that the first check code is verified to be correct according to the first signal;

[0012] The first receiving end is configured to receive the first signal and the first check code, and perform processing on the first signal in a case where the first check code is verified to be correct according to the first signal.

[0013] The application further provides an electronic device, comprising:

[0014] one or more processors;

[0015] a storage device configured to store one or more programs,

[0016] When the one or more programs are executed by the one or more processors, the one or more processors implement the end-to-end protection method of the system on chip as described in any of the embodiments of the application.

[0017] The application further provides a computer readable storage medium having a computer program stored thereon, wherein the program, when executed by a processor, implements the end-to-end protection method of the system on chip as described in any of the embodiments of the application.

[0018] Other features and advantages of the application will be described in the following description, and in part will become apparent from the description, or be learned from the practice of the application. Other advantages of the application can be realized and obtained by the structure particularly pointed out in the specification and claims of the application. BRIEF DESCRIPTION OF DRAWINGS

[0019] The accompanying drawings are included to provide a further understanding of the application, and constitute a part of the specification, illustrate the application, and are used to explain the technical solutions of the application together with the embodiments of the application, and do not constitute a limitation on the technical solutions of the application.

[0020] Figure 1 A flowchart of an end-to-end protection method of a system on chip provided by the embodiments of the application;

[0021] Figure 2 A schematic structural diagram of a system on chip provided by the embodiments of the application;

[0022] Figure 3 Another schematic structural diagram of a system on chip provided by the embodiments of the application;

[0023] Figure 4 A schematic diagram of a parity check generation module provided by the embodiments of the application;

[0024] Figure 5 A schematic diagram of a parity check detection module provided by the embodiments of the application;

[0025] Figure 6 A schematic diagram of an 8-bit ECC generation module provided by the embodiments of the application;

[0026] Figure 7 An 8-bit ECC check module schematic diagram provided for an embodiment of the present application;

[0027] Figure 8 A 32-bit ECC generation module schematic diagram provided for an embodiment of the present application;

[0028] Figure 9 A 32-bit ECC check module schematic diagram provided for an embodiment of the present application;

[0029] Figure 10 Another on-chip system structure schematic diagram provided for an embodiment of the present application;

[0030] Figure 11 Another on-chip system structure schematic diagram provided for an embodiment of the present application. DETAILED DESCRIPTION

[0031] The present application describes a plurality of embodiments, but the description is exemplary rather than limiting, and it will be apparent to those of ordinary skill in the art that more embodiments and implementations can be within the scope of the embodiments described in the present application. Although a number of possible combinations of features have been set forth in the drawings and discussed above, many other combinations of the disclosed features are possible. Unless specifically intended otherwise, any feature or element of any embodiment can be used with any other feature or element of any other embodiment, or in any other embodiment, or in a new embodiment.

[0032] The present application includes and contemplates combinations of features and elements known to those of ordinary skill in the art. The embodiments, features and elements disclosed in the present application can also be combined with any conventional features or elements to form unique inventive solutions that are defined by the claims. Any feature or element of any embodiment can also be combined with features or elements from other inventive solutions to form another unique inventive solution that is defined by the claims. Therefore, it should be understood that any feature shown and / or discussed in the present application can be implemented alone or in any suitable combination. Embodiments are, therefore, not to be limited by other than as set forth in the claims and their equivalents. Moreover, various modifications and changes can be made within the scope of the claims.

[0033] Furthermore, in describing representative embodiments, the specification can have presented the method and / or process as a particular sequence of steps. However, to the extent that the method or process depends on the performance of certain steps, the method or process is not limited to the order of steps presented nor to performing some specific steps before other specific steps, unless the description clearly indicates otherwise. Other steps can be performed, or the described performance of steps can be modified, without departing from the spirit and scope of the present application. Accordingly, the presently described method steps shall not be interpreted as a requirement to perform this implementation in the precise order illustrated.

[0034]

[0035] Information security has been an important issue with the development of computer technology, involving data transmission security, data storage security, and further required device, chip data security, and many other aspects. SoC provides hardware support for various applications and products, and its chip security requirements are gradually increasing.

[0036] The bus is a bridge inside the system on a chip, and cooperates to complete the data interaction, operation control, time synchronization, power management and other functions between multiple components / modules in the system. The components / modules included in the system on a chip are defined from the perspective of data transmission, including the sending end and the receiving end. A component / module can act as a sending end and a receiving end. From the perspective of interaction with the bus and the ability to control data transmission, it includes master and slave devices. A component / module can act as a master device and a slave device. The master device can act as a sending end and a receiving end. The slave device can act as a sending end and a receiving end. It is not limited to a specific aspect.

[0037] Embodiments of the present application provide an end-to-end protection scheme for a system on a chip, which is implemented based on bus interface signals inside the system on a chip and is a system-level end-to-end protection scheme.

[0038] Embodiments of the present application provide an end-to-end protection method for a system on a chip, as shown in Figure 1

[0039] Step 110, a first sending end in the system on a chip generates a first signal and obtains a corresponding first check code, and sends the first signal and the first check code to a first bus;

[0040] Step 120, the first bus receives the first signal and the first check code, and forwards the first signal and the first check code to the first receiving end in the system on a chip in the case that the first check code is verified to be correct according to the first signal; ​

[0041] Step 130, the first receiving end receives the first signal and the first check code, and in the case of verifying that the first check code is correct according to the first signal, performs processing on the first signal.

[0042] It can be seen that the first signal in the SoC is sent from the first sending end, correctly received and processed by the first receiving end, not only checked at the first receiving end, but also checked during the transmission to the first bus, so that the first signal is checked multiple times on the entire transmission path, ensuring transmission reliability and being able to quickly locate the problem when a check exception occurs.

[0043] In some example embodiments, the first bus includes an Advanced High-Performance Bus (AHB);

[0044] The first check code is transmitted to the first bus through a USER signal; and the first check code is transmitted to the first receiving end through a USER signal.

[0045] The USER signal is a user-defined signal defined in the AMBA5 protocol, and in the embodiment scheme of the present application, the USER signal is used to carry the check code, so that the check code scheme based on the bus transmission signal does not affect the existing AMBA5 protocol implementation, and has good protocol compatibility. In the AMBA5 protocol, the DATA signal is usually an integer multiple of 8 bits, such as 8, 16, or 32, etc. In comparison, the USER signal does not have this bit number constraint, and the corresponding USER signal bit width can be determined according to the actual bit width of the check code, which can save transmission resources to the greatest extent.

[0046] In some example embodiments, the method further includes:

[0047] Step 140, the first bus receives the first signal and the first check code, and in the case of verifying that the first check code is correct according to the first signal, sends the first signal and the first check code to a bus-bridging bridge in the system on a chip;

[0048] Step 150, the bus-bridging bridge receives the first signal and the first check code, and in the case of verifying that the first check code is correct according to the first signal, performs bus protocol conversion on the first signal to obtain a second signal and acquires a corresponding second check code, and sends the second signal and the second check code to a second receiving end in the system on a chip;

[0049] Step 160, the second receiving end receives the second signal and the second check code, and in the case of verifying that the second check code is correct according to the second signal, performs processing on the second signal.

[0050] It can be seen that when the first signal is bridged and forwarded through the bus bridge, the bus bridge also performs signal checking to ensure the security of the bridging path and to locate the exception.

[0051] In some example embodiments, the method further comprises:

[0052] In step 170, the second sending end in the system on chip generates a second signal and acquires a corresponding second check code, and sends the second signal and the second check code to the bus bridge;

[0053] In step 180, the bus bridge receives the second signal and the second check code, and in the case that the second check code is verified to be correct according to the second signal, converts the second signal into a first signal through bus protocol conversion and acquires a corresponding first check code, and forwards the first signal and the first check code to the first bus in the system on chip;

[0054] In step 190, the first bus receives the first signal and the first check code, and in the case that the first check code is verified to be correct according to the first signal, forwards the first signal and the first check code to the first receiving end in the system on chip;

[0055] In step 1100, the first receiving end receives the first signal and the first check code, and in the case that the first check code is verified to be correct according to the first signal, performs processing on the first signal.

[0056] It can be understood that the bus bridge realizes the mutual conversion of two bus protocol signals. For example, the AHB2APB bridge can convert the AHB bus signal into the APB bus signal, and can also convert the APB bus signal into the AHB bus signal.

[0057] In some example embodiments, the bus bridge comprises an advanced high-performance bus to advanced peripheral bus (AHB2APB) bridge.

[0058] The first bus sends the first check code to the bus bridge, comprising that the first bus transmits the first check code to the AHB2APB bridge through a USER signal.

[0059] That is, the first check code is transmitted from the first bus to the AHB2APB bridge through a USER signal. In some example embodiments, the first signal comprises HADDR and HWDATA, and the USER signal comprises HAUSER and HWUSER.

[0060] The bus bridge transmits the second check code to the second receiving end, including that the AHB2APB bridge transmits the second check code to the second receiving end through a USER signal.

[0061] That is, the second check code is transmitted from the AHB2APB bridge to the second receiving end through a USER signal, and in some example embodiments, the second signal includes PADDR and PWDATA, and the USER signal includes PAUSER and PWUSER.

[0062] The second sending end transmits the second check code to the bus bridge, including that the second sending end transmits the second check code to the AHB2APB bridge through a USER signal.

[0063] That is, the second check code is transmitted from the second sending end to the AHB2APB bridge through a USER signal, and in some example embodiments, the second signal includes PRDATA, and the USER signal includes PRUSER.

[0064] The bus bridge transmits the first check code to the first bus, including that the AHB2APB bridge transmits the first check code to the first bus through a USER signal.

[0065] That is, the first check code is transmitted from the bus bridge to the first bus through a USER signal, and in some example embodiments, the first signal includes HRDATA, and the USER signal includes HRUSER.

[0066] In some example embodiments, the first signal includes an AHB address signal (HADDR), an AHB write data signal (HWDATA), or an AHB read data signal (HRDATA), and the first check code includes an error checking and correction (ECC) code, which is generated according to the first signal.

[0067] At this time, the first signal is also referred to as an ECC protected signal, and accordingly, in some example embodiments, the USER signal carrying the first check code includes a HAUSER signal, a HWUSER signal, and an HRUSER signal.

[0068] In some example embodiments, the first signal includes a signal other than an AHB address signal (HADDR), an AHB write data signal (HWDATA), an AHB read data signal (HRDATA), and a USER signal in an AHB bus protocol, and the first check code includes a parity check code, which is generated according to the first signal.

[0069] At this time, the first signal is also referred to as a parity protection signal; accordingly, the signal carrying the first check code is determined according to the specific first signal. For example, the first signal is HTRANSCHK, the corresponding first check signal is HTRANS, the first signal is HSELxCHK, the corresponding first check signal is HSELx, and so on.

[0070] In some example embodiments, the second signal includes: an APB address signal (PADDR), an APB write data signal (PWDATA), or an APB read data signal (PRDATA); and the second check code includes: an error checking and correction (ECC) code, which is generated according to the second signal.

[0071] At this time, the second signal is also referred to as an ECC protection signal; accordingly, in some example embodiments, the USER signal carrying the second check code includes: a PAUSER signal, a PWUSER signal, and a PRUSER signal.

[0072] In some example embodiments, the second signal includes: a signal other than the APB address signal (PADDR), the APB write data signal (PWDATA), the APB read data signal (PRDATA), and the USER signal in the APB bus protocol; and the second check code includes: a parity check code, which is generated according to the second signal.

[0073] At this time, the second signal is also referred to as a parity protection signal; accordingly, the signal carrying the second check code is determined according to the specific second signal. For example, the second signal is PSELxCHKb, the corresponding first check signal is PSELx, the first signal is PREADYCHK, the corresponding first check signal is PREADY, and so on.

[0074] In some example embodiments, the AHB bus protocol is: an AMBA5 protocol, and the APB bus protocol is: an AMBA5 protocol. That is, the AMBA5 protocol includes the AHB bus protocol and the APB bus protocol.

[0075] In some example embodiments, the AMBA5 protocol is used to connect and manage system components such as processor cores, memory controllers, peripherals, and the like in a SoC system, and following the protocol can ensure effective integration of IP cores (components / modules) of different sources in the SoC to achieve the function of the design chip. Taking the case of a master device (Master) in a SoC accessing an AHB peripheral (Peripheral) as an example, the master device is the first sending end, sends the first signal HADDR or HWDATA to the peripheral, and generates the first check code ECC code accordingly; or, the AHB peripheral is the first sending end, sends the first signal HRDATA to the master device, and generates the first check code ECC code accordingly.

[0076] That is, when the first signal HADDR is sent, the ECC code (bit) is transmitted through the HAUSER signal, when the first signal HWDATA is sent, the ECC code (bit) is transmitted through the HWUSER signal, and when the first signal HRDATA is sent, the ECC code (bit) is transmitted through the HRUSER signal.

[0077] In some example embodiments, when a signal (parity protection signal) other than the AHB address signal (HADDR), the AHB write data signal (HWDATA), the AHB read data signal (HRDATA) and the USER signal in the AHB bus protocol is sent in the SoC system, the first check code is a parity check code. For example, taking the case of a master device (Master) in an SoC accessing a peripheral device (Peripheral) as an example, the master device is a first sending end, and the first signal HTRANSCHK is sent to the peripheral device, and a first check code corresponding thereto, i.e., a parity check code, is generated and carried in the signal HTRANS, and the bit width is 1.

[0078] In some example embodiments, the first sending end is an AHB master device, and the first signal includes an AHB address signal HADDR or an AHB write data signal HWDATA; and the first check code is generated according to the first signal.

[0079] In some example embodiments, the first sending end is an AHB peripheral device, and the first signal includes an AHB read data signal HRDATA; and the first check code is generated according to the first signal.

[0080] In some example embodiments, the first sending end is an AHB storage device, which includes a storage medium, and the first signal includes an AHB read data signal HRDATA; and the first check code is read from the storage medium.

[0081] In some example embodiments, in the case where the first sending end is an AHB storage device, the first sending end in the SoC system generates a first signal and acquires a corresponding first check code, and sends the first signal and the first check code to a first bus, including:

[0082] The AHB storage device generates a first signal by reading data from the storage medium, and reads a corresponding first check code from the storage medium;

[0083] In the case where the first check code is verified to be correct according to the first signal, the first signal and the first check code are sent to the first bus.

[0084] In some example embodiments, the first sending end is an AHB master device, the first receiving end is an AHB storage device, and the first signal is HWDATA;

[0085] The ECC code corresponding to the first signal is generated according to the HWDATA by byte;

[0086] Correspondingly, the AHB storage device performs processing for the first signal, including:

[0087] The data corresponding to the HWDATA and the ECC code are written into the AHB storage device by byte.

[0088] In some example embodiments, the ECC code corresponding to the first signal is generated according to the HWDATA by word;

[0089] Correspondingly, the AHB storage device performs processing for the first signal, including:

[0090] The data corresponding to the HWDATA and the ECC code are written into the AHB storage device by word.

[0091] In some example embodiments, the ECC code corresponding to the first signal is generated according to the HWDATA by byte;

[0092] Correspondingly, the AHB storage device performs processing for the first signal, including:

[0093] According to the address corresponding to the HWDATA, the to-be-stored data are read by word;

[0094] According to the new byte or half-word data corresponding to the HWDATA, the corresponding byte or half-word data in the to-be-stored data are replaced, and a new ECC code is generated by word;

[0095] The replaced to-be-stored data and the new ECC code are written into the AHB storage device by word.

[0096] It can be seen that when writing data, the AHB storage device acts as a receiving end, and when receiving and storing data, the received ECC code or the data corresponding to the HWDATA signal and the new ECC code are written together; when reading out data, as a sending end, the ECC code is read out together and verified, and then the HRDATA signal is sent to the data requester. Thus, from data writing to reading, the whole cycle is protected, and when an error occurs in any verification link, the problem can be accurately located in which link.

[0097] In some example embodiments, the second sending end is an APB peripheral, and the second signal includes an APB read data signal PRDATA; and the second check code is generated according to the second signal.

[0098] Or,

[0099] The second sending end is an APB storage device including a storage medium, and the second signal includes an APB read data signal PRDATA; and the second check code is read from the storage medium.

[0100] In some example embodiments, the storage medium in the AHB storage device and the APB storage device includes any of the following types: SRAM, DRAM, ROM, FLASH. Alternatively, other types of storage medium can also be used.

[0101] In some example embodiments, taking the case of a master device accessing an APB peripheral in a SoC as an example, the master device is the first sending end, sends a first signal HADDR or HWDATA to an AHB2APB bridge, and a first check code ECC code is generated accordingly; the AHB2APB bridge sends a second signal PADDR or PWDATA to a second receiving end, and a second check code ECC code is generated accordingly; or, the APB peripheral is the second sending end, sends a second signal PRDATA to the AHB2APB bridge, and a second check code ECC code is generated accordingly, and the AHB2APB bridge sends a first signal HRDATA to the master device, and a first check code ECC code is generated accordingly.

[0102] That is, when the first signal HADDR is sent, the ECC code (bit) is transmitted through the HAUSER signal, when the first signal HWDATA is sent, the ECC code (bit) is transmitted through the HWUSER signal, and when the first signal HRDATA is sent, the ECC code (bit) is transmitted through the HRUSER signal; when the second signal PADDR is sent, the ECC code (bit) is transmitted through the PAUSER signal, when the second signal PWDATA is sent, the ECC code (bit) is transmitted through the PWUSER signal, and when the second signal PRDATA is sent, the ECC code (bit) is transmitted through the PRUSER signal.

[0103] In some example embodiments, when a signal (a parity protection signal) other than the APB address signal (PADDR), the APB write data signal (PWDATA), the APB read data signal (PRDATA), and the USER signal in the APB bus protocol is sent in a SoC system, the second check code is a parity check code.

[0104] In some example embodiments, the first sending end is an AHB master device, the second receiving end is an APB storage device, the first signal is HWDATA, and the second signal is PWDATA.

[0105] The ECC code corresponding to the second signal is generated according to the PWDATA by byte.

[0106] Correspondingly, the APB storage device performs processing for the second signal, including:

[0107] The data corresponding to the PWDATA and the ECC code are written into the APB storage device by byte.

[0108] In some example embodiments, the ECC code corresponding to the second signal is generated according to the PWDATA by word.

[0109] Correspondingly, the APB storage device performs processing for the second signal, including:

[0110] The data corresponding to the PWDATA and the ECC code are written into the APB storage device by word.

[0111] In some example embodiments, the ECC code corresponding to the second signal is generated according to the PWDATA by byte.

[0112] Correspondingly, the APB storage device performs processing for the second signal, including:

[0113] According to the address corresponding to the PWDATA, the to-be-stored data are read by word.

[0114] According to the new byte or half-word data corresponding to the PWDATA, the corresponding byte or half-word data in the to-be-stored data are replaced, and a new ECC code is generated by word.

[0115] The replaced to-be-stored data and the new ECC code are written into the APB storage device by word.

[0116] It can be seen that, when writing data, the APB storage device acts as a receiving end, and when receiving and storing data, the received ECC code or the data corresponding to the PWDATA signal and a new ECC code are written together; when reading out data, the APB storage device acts as a sending end, and the ECC code is read out together and verified, and then the PRDATA signal is sent to a data requester. Thus, from data writing to data reading, the whole cycle is protected, and when an error occurs in any verification link, the problem can be accurately located in which link.

[0117] The application also provides an on-chip system, as shown in Figure 2 The application also provides an on-chip system, as shown in

[0118] a first sending end 210, a first bus 220 and a first receiving end 230;

[0119] the first sending end 210 is configured to generate a first signal and obtain a corresponding first check code, and send the first signal and the first check code to the first bus 220;

[0120] the first bus 220 is configured to receive the first signal and the first check code, and in a case where it is verified according to the first signal that the first check code is correct, forward the first signal and the first check code to the first receiving end 230 in the system on chip;

[0121] the first receiving end 230 is configured to receive the first signal and the first check code, and in a case where it is verified according to the first signal that the first check code is correct, perform processing on the first signal.

[0122] In some example embodiments, further comprising: a bus bridge 240 and a second receiving end 250;

[0123] the first bus 220 is further configured to receive the first signal and the first check code, and in a case where it is verified according to the first signal that the first check code is correct, send the first signal and the first check code to the bus bridge 240;

[0124] the bus bridge 240 is configured to receive the first signal and the first check code, and in a case where it is verified according to the first signal that the first check code is correct, perform bus protocol conversion on the first signal to obtain a second signal and obtain a corresponding second check code, and send the second signal and the second check code to the second receiving end in the system on chip;

[0125] the second receiving end 250 is configured to receive the second signal and the second check code, and in a case where it is verified according to the second signal that the second check code is correct, perform processing on the second signal.

[0126] In some example embodiments, further comprising: a second sending end 260 configured to generate a second signal and obtain a corresponding second check code, and send the second signal and the second check code to the bus bridge 240;

[0127] the bus bridge 240 is further configured to receive the second signal and the second check code, and in a case where it is verified according to the second signal that the second check code is correct, perform bus protocol conversion on the second signal to obtain a first signal and obtain a corresponding first check code, and forward the first signal and the first check code to the first bus in the system on chip;

[0128] The first bus 220 is further configured to receive the first signal and the first check code, and forward the first signal and the first check code to the first receiving end in the system on chip if the first check code is verified to be correct according to the first signal.

[0129] In some example embodiments, the first bus comprises an Advanced High-Performance Bus (AHB), and the bus bridge comprises an AHB to AHB2APB bridge.

[0130] The first sending end comprises an AHB master.

[0131] The first receiving end comprises one or more of an AHB slave and an AHB storage device.

[0132] The second receiving end comprises one or more of an APB slave and an APB storage device.

[0133] In some example embodiments, the first sending end comprises one or more of an AHB slave and an AHB storage device, and the first receiving end comprises an AHB master.

[0134] In some example embodiments, the second sending end comprises one or more of an APB slave and an APB storage device, and the first receiving end comprises an AHB master.

[0135] In some example embodiments, the SoC comprises one or more first sending ends and one or more first receiving ends.

[0136] In some example embodiments, the SoC comprises one or more second sending ends and one or more second receiving ends.

[0137] In some example embodiments, the AHB master comprises a CPU, an MCU, a DMA, a GPU, a DSP, or the like.

[0138] In some example embodiments, the system on chip further comprises an error collection module 270.

[0139] The first bus 220 is further configured to send an error notification signal to the error collection module 270 if the first check code is verified to be incorrect according to the first signal.

[0140] and / or,

[0141] The first receiving end 230 is further configured to send an error notification signal to the error collection module 270 if the first check code is verified to be incorrect according to the first signal.

[0142] In some example embodiments, the second receiving end 250 is further configured to send an error notification signal to the error collection module 270 in case that the first check code is verified to be incorrect according to the first signal.

[0143] In some example embodiments, the bus adapter 240 is further configured to send an error notification signal to the error collection module 270 in case that the first check code is verified to be incorrect according to the first signal.

[0144] In some example embodiments, the first sending end comprises an AHB master device, and the first receiving end comprises one or more of an APB peripheral device and an APB storage device, and the first receiving end 230 is further configured to send the sending end identifier corresponding to the first check code to the error collection module 270 through an HMaster signal.

[0145] In some example embodiments, the second sending end comprises one or more of an APB peripheral device and an APB storage device, and the first receiving end comprises an AHB master device.

[0146] The first receiving end 230 is further configured to send the sending end identifier corresponding to the first check code to the error collection module 270 through an HBUSE signal.

[0147] It can be understood that, in some example embodiments, the error notification signal is an HMaster signal or an HBUSE signal, and the error collection module 270 can know which first / second sending end has data with check failure according to the sending end identifier carried by the HMaster signal or the HBUSE signal.

[0148] In some example embodiments, the first / second receiving end can also send the receiving end identifier to the error collection module 270 through a related signal. In some example embodiments, the first bus and the bus adapter can also send the sending end or receiving end identifier to the error collection module 270 through a related signal to notify the check error. In the case of no conflict, the available signal in the AHB bus protocol or the APB bus protocol can be selected, which is not limited to a specific aspect.

[0149] In some example embodiments, the first bus 220 comprises a first check module configured to verify the correctness of the first check code according to the first signal, and generate the error notification signal in case of verification failure.

[0150] In some example embodiments, the first receiving end 230 comprises a first verification module configured to verify the correctness of the first check code according to the first signal; and generate the error notification signal in case of verification failure.

[0151] In some example embodiments, the bus bridge 240 comprises a first verification module configured to verify the correctness of the first check code according to the first signal; and generate the error notification signal in case of verification failure.

[0152] In some example embodiments, the bus bridge 240 further comprises a second verification module configured to verify the correctness of the second check code according to the second signal; and generate the error notification signal in case of verification failure.

[0153] In some example embodiments, the second receiving end 250 comprises a second verification module configured to verify the correctness of the second check code according to the second signal; and generate the error notification signal in case of verification failure.

[0154] In some example embodiments, the first bus 220 comprises two first verification modules.

[0155] One of the first verification modules is arranged at the input port of the first bus 220, and the other is arranged at the output port of the first bus 220.

[0156] In some example embodiments, the first sending end 210 comprises a first check code acquisition module configured to acquire the first check code corresponding to the first signal.

[0157] In some example embodiments, the second sending end 260 comprises a second check code acquisition module configured to acquire the second check code corresponding to the second signal.

[0158] It should be noted that the sending end and the receiving end in the embodiments of the present application are dynamic concepts. When the overall function of the SoC is running, a component / module can be both a sending end and a receiving end. Therefore, the component / module can comprise a verification module and a check code acquisition module.

[0159] The embodiments of the present application further provide an SoC, which comprises the above-mentioned sending end and receiving end. Figure 3The system shown, including AHB Master module: AHB Master 1, AHB Master 2, AHB bus module: ABH Bus, AHB peripheral module: AHB Peripheral, AHB memory module: AHB Memory, AHB to APB protocol conversion bridge: AHB 2APB Bridge, APB peripheral module: APB Peripheral, APB memory module: APB Memory, each module description as shown in Table 1:

[0160] Table 1 - the main module type in the protection structure of the end-to-end on-chip system

[0161]

[0162]

[0163] Wherein the AHB Master module, AHB peripheral module, AHB memory module are connected with AHB bus module, they are connected through AHB bus. In the two ends of the bus increase different protection module, as shown in Table 2. According to the direction of AHB bus signal, the output end increases HOPG module, for generating parity signal. In the input end increases HOPC module, for parity check. But HADDR, HWDATA, HRDATA output end increases HASG, HWSG, HRSG module respectively, for generating ECC check bit. In their input end increases HASC, HWSC, HRSC module, for ECC check.

[0164] Figure 3 Also includes AHB to APB protocol conversion bridge, connected to the AHB bus module, for converting AHB protocol into APB protocol. Module APB peripheral module and APB memory module, connected to the AHB to APB protocol conversion bridge. AHB to APB protocol conversion bridge and AHB bus module through AHB bus connection, these AHB bus protection mechanism with the above.

[0165] The AHB-to-APB protocol conversion bridge is connected with the APB peripheral module and the APB memory module through the APB bus. According to the direction of the APB bus signal, a POPG module is added at the output end for generating a parity check signal. A POPC module is added at the input end for parity check. PASG, PWSG and PRSG modules are added at the output ends of PADDR, PWDATA and PRDATA respectively for generating ECC check bits. PASC, PWSC and PRSC modules are added at the input ends of them for ECC check. According to the direction of the APB bus signal, a POPG module is added at the output end for generating a parity check signal. A POPC module is added at the input end for parity check. PASG, PWSG and PRSG modules are added at the output ends of PADDR, PWDATA and PRDATA respectively for generating ECC check bits. PASC, PWSC and PRSC modules are added at the input ends of them for ECC check. The protection modules are shown in Table 2:

[0166] Table 2 - Protection module types

[0167]

[0168]

[0169]

[0170] It should be noted that the protection modules in Table 2 include specific implementation modules corresponding to the first check module for performing first check code verification or the second check module for performing second check code verification, and also include first check code acquisition modules for acquiring first check codes or second check code acquisition modules for acquiring second check codes. For example, the first check module includes a parity check detection module or an ECC detection module, and the second check module includes a parity check detection module or an ECC detection module, and each specific detection module in Table 2 corresponds to a different specific detection target signal. For example, the first check code acquisition module includes a SECDED check code generation module or a parity check generation module, and the second check code acquisition module includes a SECDED check code generation module or a parity check generation module, and each specific generation module in Table 2 corresponds to a different specific check code.

[0171] Table 3 is a list of signals in the AHB bus for parity check protection, and the corresponding parity check generation module (first check code acquisition module) is shown in Table 4. Figure 4 DWIDTH is a bit width parameter of the signal to be checked, and Table 4 is a list of signals of the parity check generation module. Figure 5Table 5 is a signal list of the parity check detection module (first check module). Table 6 is a signal list of the AHB bus protected by ECC, and the SECDED (Single Error Correction Double Error Detection) mode is adopted. The HADDR, HWDATA and HRDATA signals in the AHB bus are protected by ECC, and the ECC check code is generated in 8-bit units. The generated ECC signal bits are transmitted through the HAUSER, HWUSER and HRUSER signals in the AHB protocol. Figure 6 Table 7 is a signal list of the 8-bit ECC generation module (first check code acquisition module).

[0172] Figure 7 Table 8 is a signal list of the 8-bit ECC detection module (first check module).

[0173] Table 3 is a signal list of the AHB bus protected by parity check.

[0174]

[0175] Note: The Ceil() function represents an integer greater than or equal to.

[0176] Table 4 is a signal list of the parity check generation module.

[0177] Signal name Bits Input / Output Signal interpretation Data_i DWIDTH Input Input data, DWIDTH <= 8 Data_o DWIDTH Output Output data, DWIDTH <= 8 Parity_o 1 Output Parity bit

[0178] Table 5 is a signal list of the parity check detection module (first check module). Table 6 is a signal list of the AHB bus protected by ECC, and the SECDED (Single Error Correction Double Error Detection) mode is adopted. The HADDR, HWDATA and HRDATA signals in the AHB bus are protected by ECC, and the ECC check code is generated in 8-bit units. The generated ECC signal bits are transmitted through the HAUSER, HWUSER and HRUSER signals in the AHB protocol.

[0179]

[0181]

[0182] Table 6 is a signal list of the AHB bus protected by ECC.

[0183] Signal name Signal name used for ECC bits HADDR HAUSER HWDATA HWUSER HRDATA HRUSER

[0184] Table 7 is a signal list of the 8-bit ECC generation module (first check code acquisition module).

[0185] Signal name Bits Input / Output Signal interpretation Data_i 8 Input Input data, Data_o 8 Output Output data, Ecc_o 5 Output Ecc check bit

[0186] Table 8 is a signal list of the 8-bit ECC detection module (first check module).

[0187] Signal name Bits Input / Output Signal interpretation Data_i 8 Input Input data Ecc_i 5 Input Ecc check bit Data_o 5 Output Output data Ecc_Err_s_o 1 Output 1-bit error flag Ecc_Err_d_o 1 Output 2-bit error flag

[0188] Table 9 is a signal list of the APB bus protected by parity check, and the parity check mode is the same as that of the AHB bus. The corresponding parity check generation module (second check code acquisition module) is as follows:Figure 4 The parity check detection module (second check module) is as shown in Figure 5 .

[0189] Table 10 is the signal protected by ECC in the APB bus, using single error correction double error detection (SECDED) mode. The PADDR, PWDATA and PRDATA signals in the APB bus are protected by ECC, and an 8-bit ECC check code is generated. The generated ECC signal bits are transmitted through the PAUSER, PWUSER and PRUSER signals in the APB protocol. The 8-bit ECC check code generation module (second check code acquisition module) is as shown in Figure 6 . The 8-bit ECC detection module (second check module) is as shown in Figure 7 .

[0190] After the AHB bus passes through the AHB to APB protocol conversion bridge, the HADDR signal becomes PADDR, and the corresponding HAUSER signal becomes PAUSER; the HWDATA signal becomes PWDATA, and the corresponding HWUSER signal becomes PWUSER; the PRDATA signal becomes HRDATA, and the corresponding PRUSER signal becomes HRUSER.

[0191] Table 9-APB bus signals protected by parity check

[0192]

[0193] Note: The Ceil() function represents an integer greater than or equal to.

[0194] Table 10-APB bus signals protected by ECC

[0195] Signal name Signal name used for ECC bits PADDR PAUSER PRDATA PRUSER PWDATA PWUSER

[0196] The embodiment of the application also provides an end-to-end protection method of a system on chip, comprising:

[0197] When the AHB master module initiates write transmission, an ECC check code is generated according to HWDATA, and the ECC check code is transmitted through HWUSER, and is transmitted to the AHB storage module together with HWDATA;

[0198] After passing through the AHB bus, HWDATA and HWUSER are subjected to ECC inspection and are forwarded;

[0199] When reaching the AHB storage module, HWDATA and HWUSER are subjected to ECC inspection and are stored in the memory.

[0200] When reading data, the data in the memory and the corresponding ECC check code are taken out, checked first, and then transmitted to the AHB master module through HRDATA and HRUSER respectively;

[0201] Similarly, when passing through the AHB bus, the ECC check is performed on HRDATA and HRUSER together, and then forwarded;

[0202] When the data reaches the AHB master module, the ECC check is performed on HRDATA and HRUSER together.

[0203] The embodiment of the application further provides an end-to-end protection method of a system on chip, comprising:

[0204] When the AHB master module initiates a write transmission, the ECC check code is generated according to HWDATA, and the ECC check code is transmitted through HWUSER and transmitted to the APB storage module together with HWDATA;

[0205] Similarly, when passing through the AHB bus, the ECC check is performed on HWDATA and HWUSER together, and then forwarded;

[0206] When passing through the AHB to APB protocol conversion bridge, the ECC check is performed on HWDATA and HWUSER together. Meanwhile, HWDATA and HWUSER are converted into PWDATA and PWUSER signals respectively;

[0207] When reaching the APB storage module, the ECC check is performed on PWDATA and PWUSER together, and stored in the memory;

[0208] When reading data, the data in the memory and the corresponding ECC check code are taken out, checked first, and then transmitted to the AHB master module through PRDATA and PRUSER respectively;

[0209] Similarly, when passing through the AHB to APB protocol conversion bridge, the ECC check is performed on PRDATA and PRUSER together. Meanwhile, PRDATA and PRUSER are converted into HRDATA and HRUSER signals respectively;

[0210] Similarly, when passing through the AHB bus, the ECC check is performed on HRDATA and HRUSER together, and then forwarded;

[0211] When the data reaches the AHB master module, the ECC check is performed on HRDATA and HRUSER together.

[0212] In some example embodiments, the memory includes, but is not limited to, SRAM, eFlash, and can also be a register-based data storage unit, and the protection method is the same as above. In some example embodiments, when the memory is a ROM, the ECC check code needs to be generated according to the protection mechanism above when writing data for the first time, and stored in the ROM together with the data.

[0213] In some example embodiments, when the AHB master module transmits data to the AHB storage module or the APB storage module, the ECC protection bits are added byte by byte, and transmission and storage are performed. This method can meet the high performance requirement, but it is relatively wasteful of resources and storage space.

[0214] In some example embodiments, byte protection and byte storage, and byte protection and word storage are also provided, as shown in Table 11.

[0215] Byte protection and byte storage, that is, the ECC check code is generated byte by byte, and checked on the link, and stored byte by byte when reaching the memory. The word in the system is usually 32 bits wide. Figure 8 is a 32-bit ECC generation module, and Table 12 is a corresponding 32-bit ECC generation module signal list. Figure 9 is a 32-bit ECC detection module, and Table 13 is a corresponding 32-bit ECC detection module signal list.

[0216] Sometimes the system needs to support byte, half-word and word read and write, and byte protection and word storage only supports word read and write. At this time, the byte protection and word storage method can be used. When data is transmitted on the bus, the ECC check code is generated byte by byte, and transmitted. When reaching the memory, the data in the memory is first read out and subjected to ECC check, then the new byte or half-word replaces the covered byte or half-word, and the ECC check code is generated according to 32 bits, and finally written into the memory. This function is completed by the MWSG module in Figure 10 .

[0217] When reading data, the ECC detection is first performed word by word, which is completed by the MRSC module in Figure 10 , and then the ECC check code is generated byte by byte and transmitted to the AHB master module.

[0218] In some example embodiments, the AHB protocol also supports 64-bit, 128-bit and 256-bit data width transmission, and if higher data width storage is used, the protection mechanism of 64-bit, 128-bit and 256-bit data width can also be used, which is similar to the protection mechanism of 32-bit data width.

[0219] Table 11-AHB / APB memory full-path protection mechanism

[0220]

[0221] As can be seen, different protection and storage methods have different advantages, and can be flexibly selected according to the application needs of the SoC.

[0222] Table 12 - 32-bit ECC Generation Module Signal List

[0223]

[0224]

[0225] Table 13-32-bit ECC Detection Module Signal List

[0226] Signal name Bits Input / Output Signal interpretation Data_i 32 Input Input data Ecc_i 7 Input Ecc check bit Data_o 32 Output Output data Ecc_Err_s_o 1 Output 1-bit error flag Ecc_Err_d_o 1 Output 2-bit error flag

[0227] This application also provides an on-chip system, such as... Figure 11 As shown, Figure 3 The error signals Parity_Err_o, Ecc_Err_s_o, and Ecc_Err_d_o output by the parity check module and the ECC check module are sent to the error collection module (Error_Collection). For example... Figure 11 As shown, in order to facilitate the location of the error source, the tag signal of the data source (first sender / second sender) can be sent to the error collection module at the same time when collecting error signals.

[0228] For all AHB master modules, each AHB master module is numbered (sender identifier) ​​using the HMaster signal. At the AHB peripheral or AHB memory, the received HMaster signal, along with the error signal, is sent to the error collection module. This allows the error collection module to identify which AHB master module the erroneous data originated from.

[0229] All AHB peripherals or AHB memories are numbered (transmitter identifiers) and recorded in HBUSER. All APB peripherals and APB memories are also numbered (transmitter identifiers) and recorded in PBUSER. At the AHB master module, the received HBUSER signal, along with the error signal, is sent to the error collection module. The collection module can then identify which AHB or APB slave module the erroneous data originated from.

[0230] It can be seen that the SoC-implemented end-to-end protection scheme provided in the application realizes security protection and verification on the whole signal transmission path, fully meets the safety requirements of a chip for vehicle use. The check code obtaining module and / or the check code verification module are added to the sub-modules involved in data interaction in the system on chip, a system-level protection measure is provided, and specific application identification is not required. The generality of the SoC is significantly improved, and the complexity of application development is reduced. In some example implementations, the full-path security protection and verification can quickly and accurately identify the link with security risks and timely alarm, and realize the security monitoring of the whole process. The reliable application of the chip for vehicle use is guaranteed in the increasingly complex application environment full of security challenges, and a feasible security infrastructure is laid for intelligent vehicles, autonomous driving and other products or applications.

[0231] The application also provides an electronic device, comprising:

[0232] one or more processors;

[0233] a storage device configured to store one or more programs,

[0234] When the one or more programs are executed by the one or more processors, the one or more processors implement the end-to-end protection method of the system on chip as described in any embodiment of the application.

[0235] The application also provides a computer-readable storage medium having a computer program stored thereon, and the program is executed by a processor to implement the end-to-end protection method of the system on chip as described in any embodiment of the application.

[0236] The end-to-end protection scheme of the system on chip provided in the embodiments of the application is a system-level end-to-end protection scheme, and the end-to-end protection is based on bus interface signals, realizing the protection of the whole data transmission path and further improving the security of the system on chip. In some example embodiments, the check code is transmitted by using the user-defined USER signal in the AMBA5 protocol, realizing the transmission of the check code and saving the signal transmission resources on the premise of ensuring the protocol compatibility.

[0237] Those of ordinary skill in the art will realize and understand that all or some of the steps in the methods disclosed above and the functional modules / units in the systems and devices can be implemented as software, firmware, hardware, and appropriate combinations thereof. In hardware implementation, the division between the functional modules / units mentioned in the above description does not necessarily correspond to the division of physical components; for example, one physical component can have multiple functions, or one function or step can be performed by several physical components in cooperation. Some or all of the components can be implemented as software executed by a processor, such as a digital signal processor or a microprocessor, or as hardware, or as an integrated circuit, such as an application-specific integrated circuit. Such software can be distributed on computer-readable media, which can include computer storage media (or non-transitory media) and communication media (or transitory media). As is well known to those of ordinary skill in the art, the term computer storage media includes volatile and non-volatile, removable and non-removable media implemented in any method or technology for storage of information such as computer readable instructions, data structures, program modules or other data. Computer storage media includes, but is not limited to, RAM, ROM, EEPROM, flash memory or other memory technology, CD-ROM, digital versatile disks (DVD) or other optical disk storage, magnetic cassettes, magnetic tapes, magnetic disk storage or other magnetic storage devices, or any other medium which can be used to store the desired information and which can be accessed by a computer. Furthermore, it is common and well understood by those of ordinary skill in the art that communication media typically embodies computer readable instructions, data structures, program modules or other data in a modulated data signal such as a carrier wave or other transport mechanism and can include any information delivery media.

Claims

1. An end-to-end protection method for a system-on-a-chip, characterized in that, include: The first transmitting end in the on-chip system generates a first signal and obtains the corresponding first check code, and sends the first signal and the first check code to the first bus; The first bus receives the first signal and the first check code, and if the first check code is verified to be correct according to the first signal, it forwards the first signal and the first check code to the first receiving end in the on-chip system. The first receiving end receives the first signal and the first verification code. If the first verification code is verified to be correct based on the first signal, the first receiving end performs processing on the first signal.

2. The end-to-end protection method according to claim 1, characterized in that, The first bus includes: Advanced High Performance Bus (AHB); The first verification code is transmitted to the first bus via the USER signal; the first verification code is transmitted to the first receiving end via the USER signal.

3. The end-to-end protection method according to claim 1 or 2, characterized in that, The method further includes: The first bus receives the first signal and the first check code, and if the first check code is verified to be correct according to the first signal, it sends the first signal and the first check code to the bus bridge in the system on the chip. The bus bridge receives the first signal and the first check code. If the first check code is verified to be correct according to the first signal, the first signal is converted into a second signal by bus protocol and the corresponding second check code is obtained. The second signal and the second check code are then sent to the second receiving end of the on-chip system. The second receiving end receives the second signal and the second verification code. If the second verification code is verified to be correct based on the second signal, the second receiving end performs processing on the second signal.

4. The end-to-end protection method according to claim 3, characterized in that, The bus bridge includes: an Advanced High Performance Bus to Advanced Peripheral Bus (AHB2APB) bridge; The first bus sends the first check code to the bus adapter bridge, including: the first bus transmits the first check code to the AHB2APB adapter bridge through the USER signal; The bus adapter bridge sends the second verification code to the second receiving end, including: the AHB2APB adapter bridge transmits the second verification code to the second receiving end through the USER signal.

5. The end-to-end protection method according to claim 2, characterized in that, The first transmitting end is an AHB master device, and the first signal includes: an AHB address signal HADDR or an AHB write data signal HWDATA; the first checksum is generated based on the first signal; or, The first transmitting end is an AHB peripheral, and the first signal includes: the AHB read data signal HRDATA; the first checksum is generated based on the first signal; or, The first transmitting end is an AHB storage device, including a storage medium, and the first signal includes: an AHB read data signal HRDATA; the first check code is read from the storage medium.

6. The end-to-end protection method according to claim 5, characterized in that, When the first transmitting end is an AHB storage device, the first transmitting end in the on-chip system generates a first signal and obtains the corresponding first checksum, and sends the first signal and the first checksum to the first bus, including: The AHB storage device reads data from the storage medium to generate a first signal, and reads the corresponding first check code from the storage medium; If the first check code is verified to be correct based on the first signal, the first signal and the first check code are sent to the first bus.

7. The end-to-end protection method according to claim 5, characterized in that, When the first signal is HADDR, the USER signal carrying the first check code is the HAUSER signal; When the first signal is HWDATA, the USER signal carrying the first check code is the HWUSER signal. When the first signal is HRDATA, the USER signal carrying the first check code is the HRUSER signal.

8. The end-to-end protection method according to claim 2, characterized in that, The first transmitting end is an AHB master device, the first receiving end is an AHB storage device, and the first signal is HWDATA; The first check code corresponding to the first signal is an error detection and correction ECC code, which is generated byte by byte according to the HWDATA; The AHB storage device performs processing on the first signal, including: Write the data corresponding to HWDATA and the ECC code into the AHB storage device byte by byte; or, The first check code corresponding to the first signal is an error detection and correction ECC code, which is generated word by word according to the HWDATA; The AHB storage device performs processing on the first signal, including: Write the data corresponding to HWDATA and the ECC code word by word into the AHB storage device; or, The first check code corresponding to the first signal is an error detection and correction ECC code, which is generated byte by byte according to the HWDATA; The AHB storage device performs processing on the first signal, including: Read the data to be stored word by word according to the address corresponding to HWDATA; Based on the new byte or half-word data corresponding to the HWDATA, the corresponding byte or half-word data in the data to be stored is replaced, and a new ECC code is generated word by word. The replaced data to be stored and the new ECC code are written word by word into the AHB storage device.

9. The end-to-end protection method according to claim 4, characterized in that, When the second signal is PADDR, the USER signal carrying the second check code is the PAUSER signal; When the second signal is PWDATA, the USER signal carrying the second check code is the PWUSER signal; When the second signal is PRDATA, the USER signal carrying the second check code is the PRUSER signal.

10. A system-on-a-chip, characterized in that, include: A first transmitter, a first bus, and a first receiver; The first transmitting end is configured to generate a first signal and obtain the corresponding first check code, and send the first signal and the first check code to the first bus; The first bus is configured to receive the first signal and the first check code, and, if the first check code is verified to be correct according to the first signal, forward the first signal and the first check code to the first receiving end in the on-chip system. The first receiving end is configured to receive the first signal and the first verification code, and, if the first verification code is verified to be correct based on the first signal, to perform processing on the first signal.

11. The system-on-a-chip according to claim 10, characterized in that, It also includes: a bus adapter bridge and a second receiver; The first bus is further configured to receive the first signal and the first check code, and, if the first check code is verified to be correct according to the first signal, send the first signal and the first check code to the bus bridge. The bus bridge is configured to receive the first signal and the first check code, and if the first check code is verified to be correct according to the first signal, convert the first signal into a second signal by bus protocol and obtain the corresponding second check code, and send the second signal and the second check code to the second receiving end of the on-chip system. The second receiving end is configured to receive the second signal and the second verification code, and, if the second verification code is verified to be correct based on the second signal, to perform processing on the second signal.

12. The system-on-a-chip according to claim 10 or 11, characterized in that, It also includes: an error collection module; The first bus is further configured to send an error notification signal to the error collection module if the first check code is found to be incorrect based on the first signal. And / or, The first receiving end is further configured to send an error notification signal to the error collection module if the first check code is found to be incorrect based on the first signal.

13. The system-on-a-chip according to claim 12, characterized in that, The first transmitting end includes: an AHB master device; the first receiving end includes one or more of the following: an AHB peripheral device, an AHB storage device; the first receiving end is further configured to send the first transmitting end identifier corresponding to the first check code to the error collection module via the HMaster signal; or, The first transmitting end includes one or more of the following: AHB peripherals, AHB storage devices; the first receiving end includes: an AHB master device; The first receiving end is further configured to send the first sending end identifier corresponding to the first check code to the error collection module via the HBUSE signal.

14. The system-on-a-chip according to claim 11, characterized in that, The bus bridge is further configured to send an error notification signal to the error collection module if the first check code is found to be incorrect based on the first signal. And / or, The second receiving end is further configured to send an error notification signal to the error collection module if the second check code is found to be incorrect based on the second signal. The first transmitting end includes an AHB master device; the bus bridge includes an Advanced High Performance Bus to Advanced Peripheral Bus (AHB2APB) bridge; the second receiving end includes one or more of the following: APB peripherals and APB storage devices.

15. An electronic device, characterized in that, include: One or more processors; Storage device for storing one or more programs. When the one or more programs are executed by the one or more processors, the one or more processors implement the end-to-end protection method for a system-on-chip as described in any one of claims 1-9.

16. A computer-readable storage medium having a computer program stored thereon, characterized in that, When executed by the processor, the program implements the end-to-end protection method for the on-chip system as described in any one of claims 1-9.