Memory encryption dump method and device, communication equipment, chip and chip module

By obtaining preset dump information from the communication chip and encrypting the memory segment based on the encryption identifier, the problem of data leakage when the communication chip fails is solved, and the secure dumping of sensitive data and problem location are realized.

CN121980591APending Publication Date: 2026-05-05SPREADTRUM COMMUNICATION (SHANGHAI) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
SPREADTRUM COMMUNICATION (SHANGHAI) CO LTD
Filing Date
2026-01-29
Publication Date
2026-05-05

AI Technical Summary

Technical Problem

When communication chips fail, existing technologies lack encrypted dumping of sensitive memory data, leading to the risk of data leakage. In particular, the memory data of PHYCP cannot be dumped, making it difficult to locate the problem.

Method used

By obtaining the preset dump information of the memory to be dumped, the memory segment that needs to be encrypted is encrypted according to the encryption identifier, the sensitive data is encrypted and dumped using the preset key, and the encrypted data is written to the dump file to ensure the security of the sensitive data.

Benefits of technology

It enables encrypted dumping of the memory contents of communication chips, preventing the leakage of sensitive data, ensuring data security, and facilitating technicians to locate problems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121980591A_ABST
    Figure CN121980591A_ABST
Patent Text Reader

Abstract

The invention relates to a memory encryption dump method and device, communication equipment, a chip and a chip module. The method comprises the following steps: acquiring preset dump information of a to-be-dumped memory; the preset dump information comprises encryption identifiers corresponding to a plurality of memory segments; in response to the encryption identifier representing that encryption is needed, encrypting data in a memory segment needing to be encrypted based on a preset key to obtain encrypted data; and writing the encrypted data into the dump file. By adopting the method, the memory encryption dump can be realized, and the security of technical confidentiality or sensitive data is ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technology, and in particular to a memory encryption dumping method, apparatus, communication equipment, chip, and chip module. Background Technology

[0002] Different parts of a communication chip's software typically have different security levels. However, when a chip malfunctions or malfunctions, all memory data is often dumped for analysis by technical experts. This dumping process lacks security. Taking the Communication Part (CP) of a communication chip as an example, CP software is generally divided into Protocol Software Communication Part (PSCP) and Physical Layer Software Communication Part (PHYCP). PSCP may be open-source to customers, while PHYCP is a company trade secret, not only kept secret from customers but also prohibited from being viewed by non-PHYCP technical personnel. When CP software malfunctions, the on-site information is often dumped into a dump file for CP software technical experts to analyze and resolve the problem. Because dump files often contain all relevant memory data, including all running code and data, this complete dumping method easily leads to data leakage.

[0003] Therefore, in related technologies, when an anomaly occurs in the CP software, only the memory data of PSCP is dumped, while the memory data of PHYCP is not. However, the anomaly may originate from PHYCP, and when it is necessary to check PHYCP, the lack of dumping of PHYCP memory data makes it inconvenient to locate the problem. Summary of the Invention

[0004] Therefore, it is necessary to provide a memory encryption dumping method, apparatus, communication equipment, chip, and chip module that can realize encrypted dumping to address the above-mentioned technical problems.

[0005] Firstly, this application provides a method for encrypted memory dumping, including:

[0006] Obtain preset dump information for the memory to be dumped; the preset dump information includes encryption identifiers corresponding to multiple memory segments;

[0007] In response to the encryption identifier indicating that encryption is required, the data in the memory segment to be encrypted is encrypted based on a preset key to obtain encrypted data;

[0008] Write the encrypted data into a dump file.

[0009] In one embodiment, the method further includes: in response to the encryption identifier indicating that encryption is not required, writing data in the memory segment that does not require encryption into the dump file.

[0010] In one embodiment, encrypting the data in the memory segment to be encrypted based on a preset key to obtain encrypted data includes: obtaining the preset key from the secure storage area of ​​the device where the memory to be dumped is located; and encrypting the data in the memory segment to be encrypted based on the preset key to obtain the encrypted data.

[0011] In one embodiment, the preset key is stored in the firmware of the device, and the method further includes: in response to the device being started for the first time, writing the preset key in the firmware into the secure storage area and erasing the preset key in the firmware.

[0012] In one embodiment, the preset dump information further includes location information corresponding to multiple memory segments, and the step of encrypting the data in the memory segment to be encrypted based on the preset key to obtain encrypted data includes: obtaining target data from the memory segment to be encrypted according to the location information; and encrypting the target data based on the preset key to obtain the encrypted data.

[0013] In one embodiment, obtaining preset dump information of the memory to be dumped includes: obtaining the preset dump information from the shared memory segment of the memory to be dumped; the preset dump information further includes an index, a starting address, and a length.

[0014] Secondly, this application also provides a memory encryption dumping device, comprising:

[0015] The acquisition module is used to acquire preset dump information of the memory to be dumped; the preset dump information includes encryption identifiers corresponding to multiple memory segments;

[0016] An encryption module is used to encrypt data in a memory segment that needs to be encrypted based on a preset key in response to the encryption identifier indicating that encryption is required;

[0017] The first writing module is used to write the encrypted data into a dump file.

[0018] Thirdly, this application also provides a communication device, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the steps of the method provided in the first aspect.

[0019] Fourthly, this application also provides a chip including a processor and a communication interface, the processor being configured to cause the chip to perform the steps of the method provided in the first aspect.

[0020] Fifthly, this application also provides a chip module, including a communication module, a power module, a storage module, and a chip, wherein:

[0021] The power module is used to provide power to the chip module;

[0022] The storage module is used to store data and instructions;

[0023] The communication module is used for internal communication within the chip module, or for communication between the chip module and external devices.

[0024] The chip is used to perform the steps of the method provided in the first aspect above.

[0025] In a sixth aspect, this application also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the method provided in the first aspect.

[0026] In a seventh aspect, this application also provides a computer program product, including a computer program that, when executed by a processor, implements the steps of the method provided in the first aspect.

[0027] The aforementioned memory encryption dumping method, apparatus, communication device, chip, chip module, computer-readable storage medium, and computer program product acquire preset dumping information of the memory to be dumped; the preset dumping information includes encryption identifiers corresponding to multiple memory segments; in response to the encryption identifier indicating that encryption is required, the data in the memory segment to be encrypted is encrypted based on a preset key to obtain encrypted data; and the encrypted data is written to a dump file. It can be seen that, by pre-defining the encryption identifier of the memory segment to be encrypted as indicating that encryption is required, and by encrypting and dumping the data (such as PHYCP code and data) in the memory segment to be encrypted in the dumping information according to the encryption identifier in the preset dumping information, the encrypted dumping of sensitive data in the memory content is achieved, which can prevent the leakage of sensitive data and thus ensure the security of sensitive data. Attached Figure Description

[0028] To more clearly illustrate the technical solutions in the embodiments of this application or related technologies, the drawings used in the description of the embodiments of this application or related technologies will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.

[0029] Figure 1 This is a diagram illustrating the application environment of a memory encryption dumping method in one embodiment;

[0030] Figure 2 This is a flowchart illustrating a memory encryption dumping method in one embodiment;

[0031] Figure 3 This is a schematic diagram of the actual memory distribution of the CP software in one embodiment;

[0032] Figure 4 This is a schematic diagram of preset dump information of CP memory in one embodiment;

[0033] Figure 5 This is a schematic diagram of a dump file that has undergone selective encryption in one embodiment;

[0034] Figure 6 This is a schematic diagram illustrating the process of using a dump file in one embodiment;

[0035] Figure 7 This is a flowchart illustrating step 202 in one embodiment;

[0036] Figure 8 This is a flowchart illustrating step 202 in another embodiment;

[0037] Figure 9 This is a flowchart illustrating the memory encryption dumping method in another embodiment;

[0038] Figure 10 This is a structural block diagram of a memory encryption dump device in one embodiment;

[0039] Figure 11 This is an internal structure diagram of a communication device in one embodiment;

[0040] Figure 12 This is an internal structure diagram of a chip module in one embodiment. Detailed Implementation

[0041] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.

[0042] It should be noted that the terms "first," "second," etc., used in this application can be used to describe various elements, but these elements are not limited by these terms. These terms are only used to distinguish the first element from the second element. The terms "comprising" and "having," and any variations thereof, used in this application, are intended to cover non-exclusive inclusion. The term "multiple" used in this application refers to two or more. The term "and / or" used in this application refers to one of the embodiments, or any combination of multiple embodiments.

[0043] Explanation of terms used in the embodiments of this application:

[0044] System on Chip (SOC): A complete computing system that integrates multiple functions such as CPU, memory, and peripherals onto a single chip.

[0045] Double Data Rate Memory (DDR): A standard for computer main memory (RAM) that achieves high bandwidth by transmitting data on both the rising and falling edges of the clock cycle.

[0046] Communication Part (CP): In a communication chip or system, this is a dedicated processor section that is specifically responsible for handling all wireless communication baseband functions.

[0047] Application Part (AP): In a communication chip or system, this refers to the main processor part that runs user applications and a general operating system (such as Android).

[0048] Protocol Software Communication Part (PSCP): The software module in the CP software responsible for implementing the higher-level communication protocol stack (such as TCP / IP and signaling).

[0049] Physical Layer Software Communication Part (PHYCP): The core algorithm software module in the PHYCP software is responsible for implementing the underlying wireless signal processing (such as modulation / demodulation and coding), and is usually a trade secret.

[0050] Advanced Encryption Standard (AES): A widely used, secure, and efficient symmetric block cipher algorithm for encrypting and decrypting data.

[0051] Internal Random Access Memory (IRAM): This is usually the fastest but smallest memory in the system, and may be used to store the most critical code (such as the core loop of the PHYCP algorithm) or data with extremely high performance requirements.

[0052] In order to achieve encrypted dumping, this application proposes a memory encrypted dumping method. The key point is to encrypt and protect a specific part of the memory, so that unauthorized personnel cannot obtain the key information in the DUMP file by directly viewing it.

[0053] The memory encryption dumping method provided in this application embodiment can be applied to, for example... Figure 1 In the application environment shown, terminal 102 communicates with server 104 via a network. A data storage system can store the data that server 104 needs to process. The data storage system can be integrated onto server 104 or located on the cloud or other network servers. Terminal 102 can be, but is not limited to, various personal computers, laptops, smartphones, tablets, drones, low-altitude aircraft, IoT devices, and portable wearable devices. IoT devices can include smart speakers, smart TVs, smart air conditioners, smart in-vehicle devices, projection devices, etc. Portable wearable devices can include smartwatches, smart bracelets, head-mounted devices, etc. Head-mounted devices can be virtual reality (VR) devices, augmented reality (AR) devices, smart glasses, etc. Server 104 can be a standalone physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server providing cloud computing services.

[0054] In one exemplary embodiment, such as Figure 2 As shown, a memory encryption dump method is provided, which can be applied to... Figure 1 The following steps, 201 to 203, are used as examples of terminals or chips / chip modules with data processing capabilities. Specifically:

[0055] Step 201: Obtain the preset dump information of the memory to be dumped; the preset dump information includes the encryption identifiers corresponding to multiple memory segments.

[0056] Encryption indicates whether data in each memory segment needs to be encrypted. Preset dump information is information pre-set and stored in a fixed location based on historical experience and actual needs for dumping purposes. Preset dump information includes an encryption flag (is_enc), and may also include the memory segment's index, start address, and length. That is, the preset dump information contains multiple sets of corresponding memory segment indices, start addresses, lengths, and encryption flags.

[0057] Figure 3 This refers to the actual memory distribution of the CP software during operation. For the CP portion, such as... Figure 3As shown, the memory content on the left is dumped to the file content on the right under specific circumstances. Different parts of the memory are dumped separately, and encryption can be selected during processing. The memory examples on the left include columns for name or type (area), address range, and size. The dump column on the right represents the dump file, and the seqno column represents the sequence number; for example, dump_area1 represents the region or memory segment with sequence number 1 in the dump file. The left side shows the actual memory distribution during runtime, and the right side shows the arrangement of the memory content dumped to the file when an exception occurs. Each colored block represents a memory region; for example, PS memory represents a memory region dedicated to the protocol stack, and the arrows indicate the corresponding positions in the file where the memory region is dumped.

[0058] For example, the memory encryption dumping method of this application embodiment is triggered by a dumping event for the dumped memory. The dumping event can respond to various scenarios, such as being generated by software exceptions, debugging instructions, or scheduled tasks. Optionally, step 201 includes: in response to the dumping trigger of the memory to be dumped, obtaining preset dumping information of the memory to be dumped. For example, in response to an exception assertion (ASSERT) occurring in the software running on the CP, a dumping event is triggered. In response to the triggering of the dumping event, the preset dumping information corresponding to the memory to be dumped, i.e., the CP memory, is immediately obtained. This information is used to process each memory segment of the memory to be dumped separately according to its encryption setting, thereby achieving selective encryption dumping. The preset dumping information is then used to process the memory segments of the memory to be dumped separately. Figure 3 The memory area shown can be selectively encrypted and dumped.

[0059] Optionally, the preset dump information can be stored in the shared memory segment of the memory to be dumped; this part does not need to be encrypted. The preset dump information is determined during software initialization.

[0060] Optionally, the preset dump information of CP memory is as follows: Figure 4 As shown in the g_dump_info array, MAX_SEGMENT_NUM refers to the maximum number of memory segments. The encryption flag is_enc in the g_dump_info table determines whether each memory segment is encrypted during the dump. The encryption flag is_enc includes TRUE and FALSE; TRUE indicates that the segment needs encryption, and FALSE indicates that encryption is not required.

[0061] Step 202: In response to the encryption identifier indicating that encryption is required, the data in the memory segment to be encrypted is encrypted based on the preset key to obtain encrypted data.

[0062] The preset key is calculated during software version localization and stored on the device where the CP software runs. The data in the memory segment to be encrypted may include PHYCP code and data.

[0063] Step 203: Write the encrypted data to the dump file.

[0064] For example, during the dump, the memory segments of the file to be dumped are traversed according to preset dump information. Data in memory segments where is_enc=TRUE is encrypted and dumped to the dump file based on a preset key. Data in memory segments where is_enc=FALSE is directly saved to the dump file, resulting in a mixed dump file. Optionally, according to... Figure 4 According to the g_dump_info table, the PHYCP memory (PHYI Memory and PHY2 Memory corresponding to indices 2 and 3) and critical memory (PHY2 Memory (IRAM) corresponding to index 4) are encrypted and dumped (encrypted and dumped simultaneously). Shared memory, PSCP memory, etc. (indexes 0, 1, 5, 6) are not encrypted and are dumped directly.

[0065] In one possible implementation, the AES encryption algorithm is used to encrypt the data in the memory segment that needs encryption. AES is a highly secure, high-performance algorithm that supports a wide range of decryption methods and has widely supported hardware accelerator designs, CPU coprocessors, and software support. It uses the same key for both encryption and decryption, can be used to encrypt large amounts of data, and is suitable when the encryptor and decryptor are the same person. When dumping CP memory, for the selected memory segment to be encrypted, such as PHYCP memory, AES encryption is used. During dumping, the binary stream in PHYCP memory is read, encrypted using a preset key, and then the encrypted binary stream is stored in the dump file. During decryption, the binary stream in the file is read, decrypted using the original preset key, and stored in the original file location, allowing the actual memory content to be read. The encryption and decryption range can be based on preset dump information, such as selecting the PHYCP memory range. The preset encryption and decryption keys are only visible to specific personnel, such as PHYCP technicians, and their maintenance can be generated according to software version releases. The encryption part can be performed using an accelerator or a CPU coprocessor; AES has a standard algorithm.

[0066] In the above-described memory encryption dumping method, preset dumping information of the memory to be dumped is obtained; the preset dumping information includes encryption identifiers corresponding to multiple memory segments; in response to the encryption identifier indicating that encryption is required, the data in the memory segment to be encrypted is encrypted based on a preset key to obtain encrypted data; and the encrypted data is written to a dump file. It can be seen that this embodiment of the application, by pre-defining the encryption identifier of the memory segment to be encrypted as indicating that encryption is required, and by encrypting and dumping the data (such as PHYCP code and data) in the memory segment to be encrypted in the dumping information according to the encryption identifier in the preset dumping information, achieves encrypted dumping of sensitive data in memory content, which can prevent the leakage of sensitive data and thus ensure the security of sensitive data.

[0067] In one exemplary embodiment, the memory encryption dump method further includes: in response to an encryption identifier indicating that encryption is not required, writing data in the memory segment that does not require encryption into a dump file.

[0068] For example, when the encrypted identifier does not require encryption, the data in the memory segment corresponding to the encrypted identifier is directly written to the dump file. For instance, the PSCP memory and shared memory portions can be saved directly to the dump file without encryption, making it convenient for customers or PSCP module technical experts to perform analysis and processing.

[0069] Optionally, the method may also include dynamically adjusting the preset dump information. For example, during a CP software upgrade, its memory layout or the security level of each module may change, and the preset dump information can be adaptively updated to adapt to the new encryption strategy. Optionally, when a preset event is detected (such as abnormal access to a specific memory segment), the encryption flag of that memory segment can be dynamically modified to "encryption required" to enhance real-time protection. Optionally, different operating modes of the device correspond to different preset dump information. When the device is running in different operating modes (such as high-performance mode and security mode), different preset dump information can be used, and different encryption strategies can be implemented by dynamically switching the preset dump information.

[0070] Figure 5 The dump file, which has been selectively encrypted, is shown, where, for example... Figure 5 As shown, the part indicated by the arrow is encrypted, while the other parts are not encrypted.

[0071] The above selective encryption dump results in a hybrid dump file. For users of the dump, there are two usage scenarios: First, users without a key or who do not need decryption can directly use the original dump file to view the unencrypted portions. By design, only the unencrypted parts are visible, providing sufficient information for these users. For example, PSCP software developers can view the Shared Memory content and the code and data information of PS memory; these users do not need to view encrypted information such as PHYCP information. The second scenario involves users who need to view encrypted information and have the necessary permissions. These users need the key and must go through a decryption process to turn the encrypted file into an unencrypted one before they can view the encrypted code and data information.

[0072] The decryption process for a DUMP file by authorized personnel is as follows, where the key must be obtained beforehand:

[0073] First, the preset dump information is obtained. Then, the encryption flags of each memory segment are traversed. If the encryption flag indicates that encryption is not required (i.e., FALSE), the data in that memory segment is directly copied to the target dump file. Otherwise, the data in that memory segment is decrypted using a key and then copied to the target dump file. The processing procedure is as follows: Figure 6 As shown, for encrypted dump files, users without the key or permissions can use the file directly without decryption; while users with the key or permissions need to decrypt the file before using it.

[0074] Therefore, this embodiment, by pre-setting dump information (which includes encryption identifiers), selectively encrypts and dumps only the specific memory segments identified as needing encryption during the dumping process, while keeping other memory segments in plaintext. This ensures the security of sensitive data while maximizing the readability of non-sensitive data, thus guaranteeing both security and the validity of the dumped files, making it easier to locate problems.

[0075] In one exemplary embodiment, such as Figure 7 As shown, step 202 includes steps 701 and 702. Wherein:

[0076] Step 701: Obtain the preset key from the secure storage area of ​​the device where the memory to be dumped is located.

[0077] The secure storage area may include secure memory or one-time programmable memory based on TrustZone technology.

[0078] For example, a preset key is stored in the device's secure storage area, such as TrustZone. In response to an encrypted dump request, a key read request is initiated to the device's secure storage area via a secure hardware interface that ensures that only authenticated users can access the key and that the key remains protected throughout the transmission process. The preset key is read from the secure storage area and loaded into the protected cache within the encryption engine.

[0079] Step 702: Encrypt the data in the memory segment that needs to be encrypted based on the preset key to obtain encrypted data.

[0080] For example, the encryption engine uses a loaded preset key and a specified encryption algorithm (such as the Advanced Encryption Standard AES) to encrypt the data in the memory segment to be encrypted, obtaining encrypted data. The encrypted data (i.e., the ciphertext stream) is then written sequentially to the corresponding positions in the dump file, completing the encryption dump of that memory segment. After completion, the key copy and any intermediate computation data in the encryption engine cache are immediately cleared.

[0081] Therefore, by storing the key in a secure storage area, this embodiment can ensure hardware-level key security, prevent key leakage, quickly retrieve the key from the secure storage area, and perform calculations using a hardware encryption engine (such as an AES coprocessor), which significantly reduces the occupation of main CPU resources and greatly improves encryption speed.

[0082] In one exemplary embodiment, a preset key is stored in the device's firmware, and the method further includes: in response to the device's first boot, writing the preset key in the firmware to a secure storage area and erasing the preset key in the firmware.

[0083] For example, a preset key is generated and embedded in the device's firmware image file during device manufacturing or software release. In response to the initial power-on of the terminal device (e.g., a mobile phone), the preset key is read from a designated location in the firmware and written to a hardware-protected secure storage area, such as TrustZone, via a secure hardware channel. Immediately after the key is successfully written to the secure storage area, an erase operation is performed to erase the key from the firmware, thereby ensuring that the plaintext copy of the key in the firmware is completely destroyed and that the key is not exposed.

[0084] Optionally, when a system dump occurs, the key is retrieved and used for encryption. When decryption is required, the system recalculates the key for decryption.

[0085] Therefore, this embodiment also provides security protection for the key generation method. The key is calculated and stored in the version file when the software version is generated. Upon initial system startup, the key is stored in a secure system area such as TrustZone, and the original key storage area is cleared. This write-and-erase mechanism achieves secure storage and management of the key itself.

[0086] In one exemplary embodiment, the preset dump information also includes location information corresponding to multiple memory segments. The location information includes at least the start address and length of the memory segment.

[0087] like Figure 8 As shown, step 202 includes steps 801 and 802. Wherein:

[0088] Step 801: Obtain the target data from the memory segment that needs to be encrypted based on the location information.

[0089] For example, the location information is first parsed to obtain the starting address and length. Then, the location of the target memory segment in the memory to be dumped is located. Then, according to the length, the corresponding bytes of data are read continuously starting from the starting address to obtain the target data.

[0090] Step 802: Encrypt the target data based on the preset key to obtain encrypted data.

[0091] For example, after obtaining the target data, a preset key is acquired, and an encryption algorithm (e.g., AES encryption) is performed on the target data using the preset key to generate corresponding encrypted data. Then, the encrypted data is written to the storage location reserved for the corresponding memory segment in the dump file according to its logical order in memory, completing the encryption dump operation for that memory segment.

[0092] In this embodiment, writing data from memory segments that do not require encryption to a dump file may include: writing data from memory segments that do not require encryption to a dump file based on location information. If an encryption identifier indicates that a corresponding memory segment does not require encryption, then the data in that memory segment is read according to the starting address and length in the location information, and directly written to the dump file.

[0093] Therefore, this embodiment uses location information to perform encrypted dumping of memory segment data, which can ensure the accuracy of the encrypted object and thus guarantee the security of sensitive data.

[0094] In an exemplary embodiment, preset dump information (i.e., the array g_dump_info) is stored in a shared memory segment of the memory to be dumped. Step 201 includes: obtaining the preset dump information from the shared memory segment of the memory to be dumped; the preset dump information also includes an index, a starting address, and a length.

[0095] The shared memory segment is a public area reserved during system initialization, specifically for data exchange between modules within the CP software and between the CP and AP. Its address and length are determined during the system design phase. Data in the shared memory segment does not require encryption.

[0096] For example, when a dump event is triggered, the module responsible for performing the dump first determines the starting address of the shared memory segment in the memory to be dumped by querying the configuration table. Then, starting from that starting address, it reads the preset dump information stored there according to a predetermined data structure. This information exists in the form of a structure array, where each element corresponds to a memory segment, and each element contains an index, a starting address, a length, and an encryption identifier. Afterwards, the read information can be validated, such as checking whether the index is consecutive, whether the starting address is valid, and whether the length is valid. After passing the validation, it is used for encryption processing.

[0097] Therefore, this embodiment obtains preset dump information from the shared memory segment of the memory to be dumped, which can ensure the correct acquisition of information and ensure that subsequent selective encrypted dump operations can be performed based on correct and complete information.

[0098] The memory encryption dumping method of this application embodiment is described below through a specific example.

[0099] In a specific example, such as Figure 9 As shown, the memory encryption dump method includes the following steps:

[0100] Step 901: In response to the dump trigger event of the memory to be dumped, obtain the preset dump information of the memory to be dumped;

[0101] Step 902: Determine whether the data in the current memory segment of the memory to be dumped needs to be encrypted based on the encryption identifier in the preset dump information. If yes, proceed to step 903; otherwise, proceed to step 907.

[0102] Step 903: Obtain the preset key from the secure storage area of ​​the device where the memory to be dumped is located;

[0103] Step 904: Obtain the target data from the memory segment that needs to be encrypted based on the location information in the preset dump information;

[0104] Step 905: Encrypt the target data based on the preset key to obtain encrypted data;

[0105] Step 906: Write the encrypted data to the dump file and then execute step 908;

[0106] Step 907: Read the data in the memory segment that does not need to be encrypted according to the location information, write it to the dump file, and then execute step 908;

[0107] Step 908: Has the memory segment been traversed completely? If yes, proceed to step 909; otherwise, return to step 902.

[0108] Step 909: Output the dump file.

[0109] In summary, this application embodiment obtains a hybrid dump file through selective encryption and dumping. When using this file, if a technician has permission to view the encrypted content, they need to recalculate the key for decryption before viewing; if a technician does not have permission to view the encrypted content, they cannot view it through decryption. This achieves secure protection of technical secrets or sensitive data, preventing unauthorized personnel from viewing encrypted content. Simultaneously, all memory content is dumped, ensuring the integrity of the dump file and facilitating problem location and analysis by technicians.

[0110] It should be understood that although the steps in the flowcharts of the embodiments described above are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the embodiments described above may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages in other steps. It is understood that the steps in different embodiments can be freely combined as needed, and all non-contradictory solutions formed by such combinations are within the scope of protection of this application.

[0111] Based on the same inventive concept, this application also provides a memory encryption dumping apparatus for implementing the memory encryption dumping method described above. This apparatus can be applied to or integrated into a chip or chip module, for example. The solution provided by this apparatus is similar to the implementation scheme described in the above method; therefore, the specific limitations in one or more memory encryption dumping apparatus embodiments provided below can be found in the limitations of the memory encryption dumping method described above, and will not be repeated here.

[0112] In one exemplary embodiment, such as Figure 10 As shown, a memory encryption and dumping device is provided, comprising: an acquisition module 1001, an encryption module 1002, and a first writing module 1003, wherein:

[0113] The acquisition module 1001 is used to acquire the preset dump information of the memory to be dumped; the preset dump information includes the encryption identifiers corresponding to multiple memory segments;

[0114] The encryption module 1002 is used to encrypt the data in the memory segment to be encrypted based on a preset key in response to the encryption identifier indicating that encryption is required, so as to obtain encrypted data.

[0115] The first writing module 1003 is used to write encrypted data to a dump file.

[0116] In one embodiment, the apparatus further includes a second write module, configured to write data in a memory segment that does not require encryption to a dump file in response to an encryption identifier indicating that encryption is not required.

[0117] In one embodiment, the encryption module 1002 is specifically used to: obtain a preset key from the secure storage area of ​​the device where the memory to be dumped is located; and encrypt the data in the memory segment that needs to be encrypted based on the preset key to obtain encrypted data.

[0118] In one embodiment, the preset key is stored in the device's firmware, and the apparatus further includes a third writing module for writing the preset key in the firmware to a secure storage area and erasing the preset key in the firmware in response to the device's first boot.

[0119] In one embodiment, the preset dump information also includes location information corresponding to multiple memory segments. The encryption module 1002 is specifically used to: obtain target data from the memory segment to be encrypted according to the location information; and encrypt the target data based on the preset key to obtain encrypted data.

[0120] In one embodiment, the acquisition module 1001 is specifically used to: acquire preset dump information from the shared memory segment of the memory to be dumped; the preset dump information also includes an index, a starting address, and a length.

[0121] Regarding the modules / units included in the various devices and products described in the above embodiments, they can be software modules / units, hardware modules / units, or a combination of both. For example, for various devices and products applied to or integrated into a chip, all of their modules / units can be implemented using hardware methods such as circuits, or at least some modules / units can be implemented using software programs that run on a processor integrated within the chip, while the remaining (if any) modules / units can be implemented using hardware methods such as circuits; for various devices and products applied to or integrated into a chip module, all of their modules / units can be implemented using hardware methods such as circuits, and different modules / units can be located in the same component (e.g., chip, circuit module, etc.) or different components of the chip module, or at least some modules / units can be implemented using hardware methods such as circuits. The components can be implemented using software programs that run on the processor integrated within the chip module. The remaining (if any) modules / units can be implemented using hardware methods such as circuits. For various devices and products applied to or integrated into the terminal, each of its components / units can be implemented using hardware methods such as circuits. Different modules / units can be located in the same component (e.g., chip, circuit module, etc.) or in different components within the terminal. Alternatively, at least some modules / units can be implemented using software programs that run on the processor integrated within the terminal, while the remaining (if any) modules / units can be implemented using hardware methods such as circuits.

[0122] In one exemplary embodiment, a communication device is provided, which may be a terminal, and its internal structure diagram may be as follows. Figure 11 As shown, the communication device includes a processor, memory, input / output interfaces, and a communication interface. The processor and memory are connected via a system bus, and the communication interface is also connected to the system bus. The processor provides computing and control capabilities. The memory includes a non-volatile storage medium and internal memory. The non-volatile storage medium stores the operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs stored in the non-volatile storage medium. The communication interface is used for wired or wireless communication with external terminals; wireless communication can be achieved through Wi-Fi, mobile cellular networks, Near Field Communication (NFC), or other technologies. When the computer program is executed by the processor, it implements a memory encryption and dumping method.

[0123] Those skilled in the art will understand that Figure 11The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the communication device to which the present application is applied. Specific communication devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.

[0124] In one exemplary embodiment, a communication device is provided, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the steps in the above-described method embodiments.

[0125] Based on the same inventive concept, this application also provides a chip, including a processor and a communication interface; the communication interface is used to receive or send data; the processor is configured to cause the chip to perform the following steps:

[0126] Obtain preset dump information for the memory to be dumped; the preset dump information includes encryption identifiers corresponding to multiple memory segments;

[0127] In response to the encryption identifier indicating that encryption is required, the data in the memory segment to be encrypted is encrypted based on a preset key to obtain encrypted data;

[0128] Write the encrypted data into a dump file.

[0129] It is understood that the chip involved in the embodiments of this application may be a field-programmable gate array (FPGA), may be an application-specific integrated circuit (ASIC), may be a system on chip (SoC), may be a central processor unit (CPU), may be a network processor (NP), may be a digital signal processor (DSP), may be a microcontroller unit (MCU), may be a programmable logic device (PLD), or other integrated chips, etc.

[0130] Based on the same inventive concept, this application also provides a chip module, such as... Figure 12 As shown, the chip module includes a communication module, a power module, a storage module, and a chip. Among them:

[0131] The power module is used to provide power to the chip module; the storage module is used to store data and instructions; the communication module is used for internal communication within the chip module, or for communication between the chip module and external devices; this chip corresponds to the chip in the above chip embodiment.

[0132] The implementation method of this chip module can be found in the relevant content of the above chip embodiment, and will not be repeated here.

[0133] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon, which, when executed by a processor, implements the steps in the above method embodiments.

[0134] In one embodiment, a computer program product is provided, including a computer program that, when executed by a processor, implements the steps in the above method embodiments.

[0135] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, artificial intelligence (AI) processors, etc., and are not limited to these.

[0136] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this application.

[0137] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of this patent application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.

Claims

1. A method for encrypted memory dumping, characterized in that, The method includes: Obtain preset dump information for the memory to be dumped; the preset dump information includes encryption identifiers corresponding to multiple memory segments; In response to the encryption identifier indicating that encryption is required, the data in the memory segment to be encrypted is encrypted based on a preset key to obtain encrypted data; Write the encrypted data into a dump file.

2. The method according to claim 1, characterized in that, The method further includes: In response to the encryption identifier indicating that encryption is not required, the data in the memory segment that does not require encryption is written to the dump file.

3. The method according to claim 1, characterized in that, The process of encrypting data in the memory segment to be encrypted based on a preset key to obtain encrypted data includes: Obtain the preset key from the secure storage area of ​​the device where the memory to be dumped is located; The encrypted data is obtained by encrypting the data in the memory segment that needs to be encrypted based on the preset key.

4. The method according to claim 3, characterized in that, The preset key is stored in the firmware of the device, and the method further includes: In response to the device's first boot, the preset key in the firmware is written to the secure storage area, and the preset key in the firmware is erased.

5. The method according to any one of claims 1-4, characterized in that, The preset dump information also includes location information corresponding to multiple memory segments. The step of encrypting the data in the memory segment to be encrypted based on the preset key to obtain encrypted data includes: The target data is obtained from the memory segment that needs to be encrypted based on the location information; The target data is encrypted using the preset key to obtain the encrypted data.

6. The method according to claim 1, characterized in that, Obtaining the preset dump information of the memory to be dumped includes: The preset dump information is obtained from the shared memory segment of the memory to be dumped; the preset dump information also includes an index, a starting address, and a length.

7. A memory encryption dumping device, characterized in that, The device includes: The acquisition module is used to acquire preset dump information of the memory to be dumped; the preset dump information includes encryption identifiers corresponding to multiple memory segments; An encryption module is used to encrypt data in a memory segment that needs to be encrypted based on a preset key in response to the encryption identifier indicating that encryption is required; The first writing module is used to write the encrypted data into a dump file.

8. A communication device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 6.

9. A chip, characterized in that, The device includes a processor and a communication interface, wherein the processor is configured to cause the chip to perform the steps of the method described in any one of claims 1 to 6.

10. A chip module, characterized in that, This includes communication modules, power modules, storage modules, and chips, among which: The power module is used to provide power to the chip module; The storage module is used to store data and instructions; The communication module is used for internal communication within the chip module, or for communication between the chip module and external devices. The chip is used to perform the steps of the method according to any one of claims 1 to 6.