Device and method for protecting data security of external memory, integrated circuit, radio device and terminal equipment
By embedding keys and mapping relationships in the chip, combined with access control, segmented configuration and encryption operations of external storage can be achieved, solving the problems of data leakage and tampering in external storage and improving data security and independence.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- CALTERAH SEMICON TECH (SHANGHAI) CO LTD
- Filing Date
- 2024-11-08
- Publication Date
- 2026-05-08
AI Technical Summary
If data in external storage is leaked or tampered with, it could seriously affect vehicle safety, and existing technologies are insufficient to effectively protect its confidentiality and integrity.
By embedding keys and mapping relationships in the chip, combined with access control, segmented configuration and encryption operations of external memory can be implemented to ensure data security.
It achieves efficient and secure protection of external storage data, prevents unauthorized access and tampering, and enhances the independence and security of data.
Smart Images

Figure CN121997388A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of automotive-grade data security technology, specifically to a device, method, integrated circuit, wireless device, and terminal equipment for protecting the data security of external storage devices. Background Technology
[0002] As automotive electronics become increasingly sophisticated, data security has become a critical issue. In particular, data stored in external system storage devices can have serious consequences for vehicle safety if leaked or altered. Summary of the Invention
[0003] To address the aforementioned technical problems, this application provides an apparatus, method, integrated circuit, wireless device, and terminal equipment for protecting the security of data in external storage devices. These devices are applicable to products such as board-level devices in automotive parts. By pre-installing keys, segmented configurations, and mapping relationships, and by combining mapping relationships with access control and other technical means, the confidentiality and integrity of data are ensured. This achieves an efficient and secure data protection mechanism, ensuring that data in external storage devices is not illegally accessed and / or tampered with.
[0004] This application provides an apparatus for protecting the security of data on an external storage device. The apparatus includes a chip and the external storage device. The chip includes an active security unit and a storage security management unit. The active security unit can be configured to have a built-in mapping relationship and at least one set of keys. The mapping relationship includes a mapping between external storage segments and the keys. When the chip is powered on, the active security unit can be configured to configure the storage security management unit with keys and configure the external storage segment mapping relationship based on the mapping relationship and the at least one set of keys. When the chip performs data read / write operations on the external storage device, the storage security management unit can be configured to automatically map the external storage device into segments based on the configuration and call the keys corresponding to different segments for decryption / encryption operations.
[0005] In some optional embodiments, the storage security management unit can be configured to automatically map the external storage into segments based on the configuration, and call the keys corresponding to different segments for decryption / encryption operations, including: the storage security management unit can be configured to locate the required segments based on the segment mapping configuration, and perform separate decryption or encryption operations on each segment based on the key configuration.
[0006] In some alternative embodiments, the keys corresponding to at least two segments are different. In some alternative embodiments, the chip includes at least two processors, and the at least two segments can be configured for different processors to perform data read and / or write operations.
[0007] In some optional embodiments, the storage security management unit may be configured to perform decryption / encryption operations on the external storage device based on a symmetric cryptographic algorithm.
[0008] In some optional embodiments, the symmetric cryptographic algorithm includes at least one of AES-XTS, AES-GCM, and SM4.
[0009] In some alternative embodiments, the storage security management unit may be configured to perform decryption / encryption operations on at least two segments in the external storage using different algorithms.
[0010] In some alternative embodiments, the external memory is non-volatile memory; and / or, the chip is a SoC chip.
[0011] In some optional embodiments, the chip includes an OTP module and an XIP module; wherein the active security unit is disposed in the OTP module and the storage security management unit is disposed in the XIP module; or, both the active security unit and the storage security management unit are disposed in the OTP module.
[0012] This application also provides a method for protecting the security of data in external memory, which can be applied to a SoC chip with external memory. The SoC chip has a built-in mapping relationship and at least one set of keys. The mapping relationship includes a mapping between external memory segments and the at least one set of keys. The external memory is pre-segmented based on the mapping relationship. The method includes: when the SoC chip performs data read / write operations on the external memory, based on the mapping relationship and the at least one set of keys, calling the keys corresponding to different segments to perform decryption / encryption operations on each segment of the external memory.
[0013] In some alternative embodiments, the SoC chip includes at least two processors, and at least two segments in the method can be configured for different processors to perform data read and / or write operations.
[0014] This application also provides an apparatus for protecting data security, which may include: a chip with at least one set of keys built in; and an external memory; wherein, when the chip performs write and / or read operations on the external memory, the at least one set of keys may be configured to perform segmented encryption and / or decryption operations on application layer data and / or the external memory.
[0015] In some optional embodiments, the chip includes a storage security management unit, which includes at least one set of key slots matching the at least one set of keys; wherein different key slots can be dynamically assigned different segmentation mapping relationships, and the chip performs dynamically segmented secure read and / or write operations on the external memory based on the mapping relationship and the keys.
[0016] In some alternative embodiments, the chip includes at least two processors, and at least two segments can be configured for different processors to perform data read and / or write operations.
[0017] In some alternative embodiments, each segment is encrypted and / or decrypted independently using an independent AES algorithm.
[0018] This application also provides an integrated circuit, which may include a radio frequency (RF) module, an analog signal processing module, and a digital signal processing module connected in sequence; the RF module may be configured to generate RF transmit signals and receive RF receive signals; the analog signal processing module may be configured to perform frequency down-conversion and analog-to-digital conversion on the RF receive signals to obtain digital signals; and the digital signal processing module may be configured to perform digital signal processing on the digital signals to perform target detection and / or wireless communication; wherein, when performing digital signal processing, the signal processing module may be configured to perform dynamically segmented secure read and / or write operations on external memory.
[0019] In some alternative embodiments, the integrated circuit is a millimeter-wave chip; and / or, the integrated circuit is a chip in the device described in any embodiment of this application.
[0020] This application also provides a wireless device, which may include: a carrier; an integrated circuit as described in any embodiment of this application, disposed on the carrier; an antenna, disposed on the carrier, or the antenna and the integrated circuit are integrated into a single device disposed on the carrier; wherein the integrated circuit is connected to the antenna and is used to transmit the radio frequency transmission signal and / or receive the radio frequency reception signal.
[0021] This application also provides a terminal device, which may include: a device body; and a wireless device disposed on the device body as described in any embodiment of this application; wherein the wireless device is used for target detection and / or communication to provide reference information to the operation of the device body. Attached Figure Description
[0022] The above and other objects, features and advantages of this application will become clearer from the following description of embodiments of this application with reference to the accompanying drawings.
[0023] Figure 1 This is a schematic diagram of the framework of a device for protecting the data security of an external storage device in an embodiment of this application;
[0024] Figure 2 This is a schematic diagram of a module for protecting the data security of an external storage device in one embodiment of this application;
[0025] Figure 3 This is a schematic diagram of a module for protecting the data security of an external storage device in one embodiment of this application. Detailed Implementation
[0026] To facilitate understanding of this application, a more complete description will be provided below with reference to the accompanying drawings. Preferred embodiments of this application are shown in the drawings. However, this application can be implemented in various forms and is not limited to the embodiments described herein. Rather, these embodiments are provided to provide a more thorough and complete understanding of the content of this application.
[0027] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs. The terminology used in this specification is for the purpose of describing particular embodiments only and is not intended to be limiting of the application.
[0028] like Figure 1 As shown, this application also provides a device for protecting data security, which is applicable to scenarios with high security requirements, especially scenarios where external data segments are managed and controlled by different parties. The device may include a chip 11 and an external memory 12, etc. The chip 11 may have at least one set of parameters such as keys and mapping relationships built in, so that when the chip 11 performs write and / or read operations on external data, it can perform segmented encryption and / or decryption operations on application layer data and / or external memory 11 based on the above-mentioned mapping relationships and key parameters. The mapping relationship may include the segmented configuration of external data and / or external memory, the mapping between segments and keys, the mapping of encryption / decryption algorithms for each segment, and the corresponding parameter information. That is, for external data and / or external memory, when performing read / write, encryption / decryption operations based on segments as the basic unit, not only can independent access to each segment be realized, allowing different segments to be accessed independently by different processors (such as CPUs), but it can also effectively prevent different CPUs from accessing unauthorized segment space, thereby effectively improving the independence and security of external data access.
[0029] In some optional embodiments, the chip 11 described above may include a storage security management unit (not shown in the figure), which may include at least one set of key slots matching at least one set of keys. Different key slots may be dynamically assigned mapping relationships with different segments. The chip 11 may perform dynamically segmented secure read and / or write operations on the external memory 12 based on the mapping relationship and the keys. The external memory 12 may be non-volatile memory (NVM) located outside the chip (die / chip), such as FLASH. By pre-setting multiple sets of key slots in the storage security management unit, and assigning different segment mapping relationships to each slot, different segments can be protected using different keys, thereby improving the security capabilities of different segments. Furthermore, by using a dynamic mapping method, real-time configuration changes can be supported during system operation, thereby enabling secure read and write of dynamic data.
[0030] Furthermore, since different segments can use independent keys for secure read and write operations, this not only further enhances the flexible configuration of security for each segment based on requirements, but also enables the flexibility and efficiency of independent read / write operations for each segment. That is, different segments can employ different security strategies (such as different keys, key levels, encryption / decryption algorithms, etc.), and there is no need for simultaneous encryption / decryption operations. In other words, by using a multi-segment structure, each segment can be independently encrypted and decrypted using symmetric algorithms such as AES, avoiding the need for simultaneous decryption of the entire segment, thereby improving the performance of some read operations.
[0031] Optionally, when multiple processors perform read / write operations on the same external memory or external data, for example, when chip 11 includes at least two processors, at least two segments can be configured for different processors to perform data read and / or write operations. That is, segment mapping can also be dynamically adjusted based on needs, thereby achieving dynamic segmentation of external data and / or external memory, improving the flexibility of data storage and access, and also improving the storage efficiency of external memory. In other words, due to the use of a multi-segment structure, for data read by different CPUs, the content can be mapped to different target CPU address spaces after decryption, through the mapping of multiple segments, thus preventing different CPUs from accessing other address spaces and thereby improving security.
[0032] In some optional embodiments, each segment is encrypted and / or decrypted independently using an independent AES algorithm (such as AES-XTS, AES-GCM, SM4, and other symmetric cryptographic algorithms) to effectively ensure a balance between system performance and security, thereby meeting the mandatory requirements of different needs for the algorithm.
[0033] For details, see Figure 1 As shown, for the chip 11 with an external memory 12, the chip 11 can be configured to pre-load firmware encryption key (Flashware Encryption Key, abbreviated as FEK), signature value, public key, segment configuration and other parameter information. Correspondingly, the memory 12 can be configured to pre-load encrypted firmware and can be configured to store encrypted segment data, etc.
[0034] When chip 11 accesses memory 12, it can decrypt memory 12 based on a preset FEK. Then, by calling preset segmentation configurations, signature values, and public keys, it can verify the encrypted segmented data stored in memory 12, thus ensuring confidentiality while quickly determining data integrity. Furthermore, by performing encryption and decryption through segmentation, the required segment can be quickly located and verified individually. For example, different segments in external memory 12 can be mapped using the aforementioned segmentation configuration to map different content to different segments. This means different segments can be read into different processor spaces, and it also ensures that different segments of data on different cores of the same processor are not accessed, thus preventing access beyond authorized limits.
[0035] In some alternative embodiments, the FEK can be configured as one or more keys. In this way, the external memory can be segmented, and each segment can be encrypted using a different FEK to further enhance its confidentiality. Optionally, while enabling faster location of specific segment content based on segmentation, each segment can be independently encrypted using keys of different strengths to meet security requirements.
[0036] like Figure 2 As shown, this application also provides a device for protecting the data security of an external memory, the device including a chip and an external memory (such as...). Figure 2 The NVM (Non-Volatile Memory) shown in the diagram may include an active security unit (such as...). Figure 2 The OTP shown) and storage security management unit (such as Figure 2The XIP unit shown is an example of such a unit. The active security unit may have pre-built mapping relationships and at least one set of key parameters. These mapping relationships may include the mapping between external storage segments and the at least one set of keys. When the chip powers on, the active security unit can configure the storage security management unit via the system bus, based on the aforementioned mapping relationships and key parameters, and configure the external memory segment mapping relationships. When the chip performs data read / write operations on the external memory, the storage security management unit can automatically map the external memory into segments and call the keys corresponding to different segments for decryption / encryption operations. Optionally, the storage security management unit can be configured to locate the required segments based on the segment mapping configuration and perform separate decryption or encryption operations on each segment based on the key configuration.
[0037] Specific examples Figure 2 As shown, mapping relationships and at least one set of key parameters can be preset in the chip's main security unit (such as an OTP unit or other similar units). For example, one, two, five, eight, or more sets of keys (such as Key1, Key2...Key n) can be preset. These keys can be used to manage the mapping relationship between external memory, external memory segments, and keys (Key1→Segment 1, Key 2→Segment 2...Key n→Segment n). The mapping relationship can be a mapping relationship between external memory segments and key configurations.
[0038] In actual operation, after the system is powered on, the main security unit can first perform key configuration and external storage segment mapping relationship configuration operations on the storage security management unit (such as the XIP unit or a similar unit) through the system bus. For example, the above-mentioned key, mapping relationship and related configuration information parameters can be stored in the Key storage subunit.
[0039] When the system reads external storage (such as NVE units or similar storage units), the system can automatically map the external storage into segments through the storage security management unit, and call the corresponding keys for different segments to decrypt using symmetric algorithms such as AES-XTS algorithm to achieve the corresponding read operation. That is, by segmenting, this embodiment can also locate the required segment relatively quickly and can verify the segment individually. In this embodiment, different cryptographic algorithms can also be used to implement encryption and / or decryption operations on different segments of the external storage. Among them, various symmetric cryptographic algorithms, including but not limited to AES (such as AES-XTS, AES-GCM, etc.) and SM4, can be used for the encryption algorithm used in XIP to ensure a balance between performance and security and meet the mandatory requirements of different regions for algorithms.
[0040] Optionally, different segments in the external storage can also be dynamically mapped using the above configuration to map different storage areas to different segments. That is, different external storage segment storage areas can be read into different processor spaces to effectively ensure that different cores of the same processor do not access different data beyond their authorized scope.
[0041] Optionally, a key set (such as a FEK) can be configured with one or more keys to enable encryption of different segments of the external storage using a different FEK for each segment, thereby further enhancing the confidentiality of each segment. Furthermore, by employing different key strengths for encryption of different segments, personalized requirements for integrity and security can be met, allowing for faster location of segment content.
[0042] It should be noted that for chips containing both OTP and XIP units, parameters such as keys, key segment mapping relationships, and related configurations can be partially or entirely pre-configured in the XIP unit, or partially or entirely pre-configured in the OTP unit based on requirements, or migrated between them during operation based on actual needs. For example, parameters such as keys and configuration relationships pre-configured in the XIP unit can be migrated to the OTP unit to facilitate setting a wider range of configuration relationships in the system.
[0043] like Figure 3 As shown in the embodiments of this application, a method and apparatus for improving the security of data stored on an external memory can be applied to products such as board-level equipment for automotive parts. By pre-installing encryption and signature verification mechanisms, the confidentiality and integrity of data stored on the external memory can be effectively improved.
[0044] In some optional embodiments, for systems comprising a SoC (System on Chip) chip and corresponding external memory (such as NVM), an encryption key can be pre-embedded in the SoC chip, which can then be used to load the external storage device. The system or apparatus may include a key packet generation backend, a key generator, and the SoC chip connected in sequence, and a firmware generation backend, a firmware programmer, and FLASH memory connected in sequence. The FLASH memory serves as external memory for the SoC chip and can be dynamically segmented for secure read / write operations by the SoC chip.
[0045] Specifically, the Flashware Generation Backend can be configured to generate and output encrypted flashware, and the Flashware Burner can be configured to burn the encrypted flashware into external flash memory. The KeyPackage Generation Backend can be configured to generate and output encrypted key packages, and the Key Provisoner can be configured to generate keys based on the encrypted key packages and install them into the SoC chip. That is, the firmware in external flash memory can be encrypted and signed using the backend's keys according to a pre-configured method on an external server. This key can be written into a designated area (such as XIP, TOP, etc.) inside the SoC using a key-based injection tool. Additionally, segmentation configurations, signature values, and other configuration information can also be written into the SoC in the same way.
[0046] Optionally, the XIP can include a built-in configuration of the mapping relationship between the keys and key segments in the FEK. Furthermore, different cryptographic algorithms can be used for encryption in this embodiment. For example, encryption algorithms that can be used in the XIP include, but are not limited to, various symmetric cryptographic algorithms such as AES and SM4, to ensure a balance between performance and security.
[0047] Furthermore, keys and configuration parameters in XIP can be migrated to OTP to accommodate a wider range of configuration relationships. In other words, the storage information between XIP and OTP can be flexibly migrated and stored based on actual needs.
[0048] This application also provides an integrated circuit, which may include a radio frequency (RF) module, an analog signal processing module, and a digital signal processing module connected in sequence. The RF module is configured to generate RF transmit signals and receive RF receive signals. The analog signal processing module is configured to down-convert and perform analog-to-digital conversion on the RF receive signals to obtain digital signals. The digital signal processing module is configured to perform digital signal processing on the digital signals for target detection and / or wireless communication. During digital signal processing, the signal processing module is configured to perform dynamically segmented secure read and / or write operations on an external memory. The integrated circuit may be a millimeter-wave chip; and / or, the integrated circuit may be a chip (such as a radar chip, UWB chip, etc.) in any embodiment of this application.
[0049] In an optional embodiment, the integrated circuit described above can be a millimeter-wave radar chip. The types of digital functional modules in the integrated circuit can be determined according to actual needs. For example, in a millimeter-wave radar chip, the data processing module can be used for tasks such as range Vidoff transformation, velocity Vidoff transformation, constant false alarm rate detection, direction of arrival detection, and point cloud processing to acquire information such as the target's distance, angle, velocity, shape, size, surface roughness, and dielectric properties.
[0050] Optionally, the integrated circuit may be an AiP (Antenna-In-Package) chip structure, an AoP (Antenna-On-Package) chip structure, or an AoC (Antenna-On-Chip) chip structure.
[0051] In an optional embodiment, the integrated circuit may be equivalent to the chip described in any embodiment of this application, that is, they may have the same structure and function, and may be combined with each other to form a cascaded structure. For the sake of simplicity, it will not be described in detail here, but it should be understood that the technology that those skilled in the art should know based on the content described in this application should be included within the scope of this application.
[0052] In one embodiment, this application also provides a wireless device, comprising: a carrier; an integrated circuit as described in any of the above embodiments, wherein the integrated circuit may be disposed on the carrier; and an antenna disposed on the carrier, or integrated with the integrated circuit as a single device disposed on the carrier (i.e., the antenna may be an antenna disposed in an AiP, AoP, or AoC structure); wherein the integrated circuit is connected to the antenna (i.e., the sensing chip or integrated circuit does not integrate an antenna, such as a conventional SoC), and is used to transmit and receive radio signals. The carrier may be a printed circuit board (PCB), and the first transmission line may be a PCB trace.
[0053] In one embodiment, this application also provides a terminal device, including: a device body; and a wireless device disposed on the device body as described in any of the above embodiments; wherein the wireless device can be used to implement functions such as target detection and / or wireless communication.
[0054] Specifically, based on the above embodiments, in one optional embodiment of this application, the wireless device may be disposed outside the device body or inside the device body. In other optional embodiments of this application, the wireless device may be partially disposed inside the device body and partially disposed outside the device body. This application does not limit the specific implementation; it may be determined according to the circumstances.
[0055] In an optional embodiment, the aforementioned device body can be a component or product applied in fields such as smart cities, smart homes, transportation, smart homes, consumer electronics, security monitoring, industrial automation, in-cabin detection (such as smart cockpits), medical devices, and healthcare. For example, the device body can be intelligent transportation equipment (such as automobiles, bicycles, motorcycles, ships, subways, trains, etc.), security equipment (such as cameras), liquid level / flow rate detection equipment, smart wearable devices (such as wristbands, glasses, etc.), smart home devices (such as robot vacuum cleaners, door locks, televisions, air conditioners, smart lights, etc.), various communication devices (such as mobile phones, tablets, etc.), as well as devices such as barriers, intelligent traffic lights, intelligent signs, traffic cameras, and various industrial robotic arms (or robots). It can also be various instruments for detecting vital signs parameters and various devices equipped with such instruments, such as in-cabin vital sign detection in automobiles, indoor personnel monitoring, smart medical devices, and consumer electronic devices.
[0056] The wireless device may be any of the wireless devices described in any embodiment of this application. The structure and working principle of the wireless device have been described in detail in the above embodiments, and will not be repeated here.
[0057] It should be noted that wireless devices can transmit and receive radio signals to achieve functions such as target detection and / or communication, thereby providing the device body with target detection information and / or communication information, and thus assisting or even controlling the operation of the device body.
[0058] For example, when the aforementioned equipment is applied to an advanced driver assistance system (ADAS), wireless devices (such as millimeter-wave radar or UWB devices) used as vehicle sensors can provide various functional safety guarantees for the ADAS system, such as automatic brake assist (AEB), blind spot detection warning (BSD), lane change assist warning (LCA), and rear cross traffic alert (RCTA).
[0059] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0060] The above-described embodiments merely illustrate preferred embodiments of the present invention and the technical principles employed. While the descriptions are specific and detailed, they should not be construed as limiting the scope of the invention. Those skilled in the art can make various obvious changes, readjustments, and substitutions without departing from the scope of protection of the present invention. Therefore, although the present invention has been described in detail through the above embodiments, the present invention is not limited to the above embodiments. Many other equivalent embodiments may be included without departing from the inventive concept, and the scope of protection of this patent is determined by the appended claims.
Claims
1. A device for protecting the data security of an external storage device, characterized in that, The device includes a chip and an external memory. The chip includes an active security unit and a storage security management unit; The active security unit can be configured to have a built-in mapping relationship and at least one set of keys, the mapping relationship including a mapping between external storage segments and the keys; When the chip is powered on, the active security unit can be configured to perform key configuration on the storage security management unit based on the mapping relationship and the at least one set of keys, as well as configure the external storage segment mapping relationship; as well as When the chip performs data read / write operations on the external memory, the storage security management unit can be configured to automatically map the external memory into segments based on the configuration, and call the keys corresponding to different segments to perform decryption / encryption operations.
2. The apparatus as claimed in claim 1, characterized in that, The storage security management unit can be configured to automatically map the external storage device into segments based on the configuration, and call the keys corresponding to different segments to perform decryption / encryption operations, including: The storage security management unit can be configured to locate the required segment based on the segment mapping configuration, and to perform separate decryption or encryption operations on each segment based on the key configuration.
3. The apparatus as described in claim 1 or 2, characterized in that, At least two segments correspond to different keys.
4. The apparatus according to any one of claims 1-3, characterized in that, The chip includes at least two processors, and at least two segments can be configured for different processors to perform data read and / or write operations.
5. The apparatus according to any one of claims 1-4, characterized in that, The storage security management unit can be configured to perform decryption / encryption operations on the external storage device based on symmetric cryptographic algorithms.
6. The apparatus according to any one of claims 1-5, characterized in that, The symmetric cryptographic algorithm includes at least one of AES-XTS, AES-GCM, and AES-SM4.
7. The apparatus according to any one of claims 1-6, characterized in that, The storage security management unit can be configured to perform decryption / encryption operations on at least two segments in the external storage using different algorithms.
8. The apparatus according to any one of claims 1-7, characterized in that, The external storage device is a non-volatile memory; and / or, The chip is a SoC chip.
9. The apparatus as described in any one of claims 1-8, characterized in that, The chip includes an OTP module and an XIP module; Wherein, the active security unit is located in the OTP module, and the storage security management unit is located in the XIP module; or, Both the active security unit and the storage security management unit are located in the OTP module.
10. A method for protecting the security of data on an external storage device, characterized in that, The invention is applied to a SoC chip with external memory, wherein the SoC chip has a built-in mapping relationship and at least one set of keys, the mapping relationship including a mapping between external memory segments and the at least one set of keys, and the external memory is pre-segmented based on the mapping relationship; The method includes: When the SoC chip performs data read / write operations on the external memory, based on the mapping relationship and the at least one set of keys, it calls the keys corresponding to different segments to perform decryption / encryption operations on each segment of the external memory.
11. The method as described in claim 10, characterized in that, The SoC chip includes at least two processors, and in the method, at least two segments can be configured for different processors to perform data read and / or write operations.
12. A device for protecting data security, characterized in that, include: The chip contains at least one set of keys. as well as External storage; When the chip performs write and / or read operations on the external memory, the at least one set of keys can be configured to perform segmented encryption and / or decryption operations on the application layer data and / or the external memory.
13. The apparatus as claimed in claim 12, characterized in that, The chip includes a storage security management unit, which includes at least one set of key slots that match the at least one set of keys; Different key slots can be dynamically assigned different segmentation mapping relationships. The chip performs dynamically segmented secure read and / or write operations on the external memory based on the mapping relationship and the key.
14. The apparatus as claimed in claim 12 or 13, characterized in that, The chip includes at least two processors, and at least two segments can be configured for different processors to perform data read and / or write operations.
15. The apparatus as claimed in any one of claims 12-14, characterized in that, Each segment is encrypted and / or decrypted independently using the AES algorithm.
16. An integrated circuit, characterized in that, It includes a radio frequency module, an analog signal processing module, and a digital signal processing module connected in sequence; The radio frequency module can be configured to generate radio frequency transmit signals and receive radio frequency receive signals; The analog signal processing module can be configured to perform frequency down-conversion and analog-to-digital conversion on the radio frequency received signal to obtain a digital signal; as well as The digital signal processing module can be configured to perform digital signal processing on the digital signal for target detection and / or wireless communication; The signal processing module, when performing digital signal processing, can be configured to perform secure read and / or write operations on external memory in dynamic segmentation.
17. The integrated circuit according to claim 16, characterized in that, The integrated circuit is a millimeter-wave chip; and / or, The integrated circuit is a chip in the device described in any one of claims 1-9 and 12-13.
18. A wireless device, characterized in that, include: Carrier; The integrated circuit as described in claim 16 or 17 is disposed on the carrier. An antenna is disposed on the carrier, or the antenna and the integrated circuit are integrated into a single device and disposed on the carrier. The integrated circuit is connected to the antenna and is used to transmit the radio frequency transmission signal and / or receive the radio frequency reception signal.
19. A terminal device, characterized in that, include: Equipment body; as well as The wireless device as described in claim 18 is disposed on the device body; The wireless device is used for target detection and / or communication to provide reference information for the operation of the device body.