Security monitoring method and microprocessor architecture

CN122286749BActive Publication Date: 2026-09-08PHYTIUM TECH CO LTD +1
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202610694553.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2026-05-20
Publication Date
2026-09-08
Estimated Expiration
2046-05-20

AI Technical Summary

Technical Problem

但是,环形振荡器通常是基于典型工艺参数或按照其他特定工艺角设计的,然而在实际使用过程中,受工作电压和工作环境温度等因素的影响,环形振荡器所处的工艺角会发生变化,进而导致环形振荡器的工作频率发生变化,工作频率不稳定的基准频率源会导致无法对被监控模块进行有效、准确的安全监测

Benefits of technology

[0016] In some implementations, there are multiple monitored modules and one security monitoring module; or, there are multiple monitored modules, with one security monitoring module corresponding to each monitored module. Based on this implementation, a single security monitoring module can be deployed in the microprocessor architecture to centrally monitor multiple monitored modules, or multiple security monitoring modules can be distributed in the microprocessor architecture to monitor different modules respectively. This allows the microprocessor architecture design to be flexibly chosen based on a comprehensive consideration of monitoring real-time performance, module independence, hardware resource overhead, and wiring complexity, thereby meeting diverse security monitoring needs while optimizing the overall area efficiency and architectural rationality of the microprocessor architecture.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122286749B_ABST
    Figure CN122286749B_ABST
Patent Text Reader

Abstract

The application provides a safety monitoring method and a microprocessor architecture. The method is applied to the microprocessor architecture, and the microprocessor architecture comprises a processor core and a safety monitoring module. The safety monitoring module comprises a ring oscillator with adjustable inverter stage number. The method comprises the following steps: when the safety monitoring module detects that a process angle of the ring oscillator changes, adjusting the inverter stage number of the ring oscillator according to the process angle currently taken by the ring oscillator and the working frequency of the monitored module, so that the working frequency of the ring oscillator is consistent with the working frequency of the monitored module. The monitored module comprises any module in the microprocessor architecture, and the ring oscillator is used as a reference frequency source for safety monitoring of the monitored module. The above method can provide a stable reference frequency inside the microprocessor architecture, thereby improving the accuracy and effectiveness of safety monitoring of the monitored module.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technology, and in particular to a security monitoring method and microprocessor architecture. Background Technology

[0002] In the field of chip design, to detect physical attacks such as voltage spikes in real time, it is usually necessary to compare the operating frequency of the monitored module with a reference frequency source. Therefore, obtaining an oscillator that can output a stable frequency that can accurately match the operating frequency of the monitored module is crucial for achieving accurate and safe monitoring of the monitored module.

[0003] In existing technologies, ring oscillators are typically used as such reference frequency sources. However, ring oscillators are usually designed based on typical process parameters or according to other specific process angles. However, in actual use, the process angle of the ring oscillator will change due to factors such as operating voltage and ambient temperature, which in turn will cause the operating frequency of the ring oscillator to change. An unstable reference frequency source will make it impossible to perform effective and accurate safety monitoring of the monitored module. Summary of the Invention

[0004] To address the aforementioned technical issues, this application provides a security monitoring method and a microprocessor architecture that can provide a stable reference frequency within the microprocessor architecture, thereby improving the accuracy and effectiveness of security monitoring of the monitored module.

[0005] This application provides a security monitoring method applied to a microprocessor architecture, the microprocessor architecture including a processor core and a security monitoring module, the security monitoring module including a ring oscillator with adjustable inverter stages; the method includes: when the security monitoring module detects a change in the process corner of the ring oscillator, adjusting the inverter stages of the ring oscillator according to the current process corner of the ring oscillator and the operating frequency of the monitored module, so that the operating frequency of the ring oscillator is consistent with the operating frequency of the monitored module; wherein the monitored module includes any module in the microprocessor architecture, and the ring oscillator is used as a reference frequency source for security monitoring of the monitored module.

[0006] A second aspect of this application provides a microprocessor architecture including a processor core and a security monitoring module, the security monitoring module including a ring oscillator with adjustable inverter stages, the microprocessor architecture being configured to implement the aforementioned security monitoring method.

[0007] The safety monitoring method provided in this application employs a ring oscillator with adjustable inverter stages within the safety monitoring module. Furthermore, the safety monitoring module can detect the current process corner. When a change in the current process corner is detected, the inverter stages of the ring oscillator are adjusted according to the current process corner and the operating frequency of the monitored module, so that the operating frequency of the ring oscillator matches the operating frequency of the monitored module. The aforementioned ring oscillator is then used as a reference frequency source for safety monitoring of the monitored module.

[0008] Security monitoring of monitored modules typically involves comparing the module's operating frequency with that of a ring oscillator. When the deviation of the monitored module's operating frequency from the ring oscillator's frequency exceeds a set threshold, the module is considered under attack. Therefore, ensuring the stability of the ring oscillator's operating frequency is fundamental for accurate attack monitoring. In the above scheme, even if the process angle of the ring oscillator changes, the operating frequency of the ring oscillator remains consistent with that of the monitored module, providing a stable reference frequency source for security monitoring. This avoids misinterpreting an attack as a significant difference between the monitored module's and ring oscillator's frequencies due to the ring oscillator's own frequency instability, thus improving the accuracy and effectiveness of security monitoring of the monitored module.

[0009] In some implementations, the security monitoring module sends an interrupt signal to the processor core when it detects that the operating frequency of the monitored module deviates from the operating frequency of the ring oscillator by more than a set offset threshold; the interrupt signal indicates that the monitored module has malfunctioned. In this implementation, by adjusting the number of inverter stages of the ring oscillator based on the process angle of the ring oscillator, the operating frequency of the ring oscillator and the monitored module are made consistent, thus ensuring the stability of the ring oscillator's operating frequency. Based on this, if the operating frequency of the monitored module deviates from the operating frequency of the ring oscillator by more than a set offset threshold, it can be determined that the monitored module has been attacked, and therefore, an anomaly can be concluded. Therefore, this implementation can effectively and accurately detect anomalies in the monitored module. When an anomaly is detected in the monitored module, the security monitoring module promptly reports the anomaly to the processor core via an interrupt, so that the processor core can handle the anomaly and ensure the security of the monitored module.

[0010] In some implementations, the safety monitoring module adjusts the number of inverter stages of the ring oscillator based on the current process angle of the ring oscillator and the operating frequency of the monitored module. This includes: the safety monitoring module determining a target number of inverter stages based on the operating frequencies of the ring oscillator at different process angles and with different numbers of inverter stages. The target number of inverter stages is the number of inverter stages that makes the operating frequency of the ring oscillator consistent with the operating frequency of the monitored module at the current process angle of the ring oscillator; and the safety monitoring module adjusting the number of inverter stages of the ring oscillator to the target number of inverter stages. In this implementation, a mapping relationship is pre-determined for the operating frequency of the ring oscillator under different process angles and different inverter stages. Based on this, when the current process angle of the ring oscillator and the operating frequency of the monitored module are determined, the number of inverter stages that make the operating frequency of the ring oscillator consistent with the operating frequency of the monitored module under the current process angle can be determined by either reverse calculation or querying the mapping relationship. This implementation allows the safety monitoring module to quickly determine the target inverter stage for adjusting the ring oscillator stage and to adjust the inverter stage of the ring oscillator, thereby enabling rapid calibration of the ring oscillator frequency when the process angle of the ring oscillator changes.

[0011] In some implementations, the safety monitoring module includes an inverter stage register. The safety monitoring module adjusts the inverter stage of the ring oscillator to the target inverter stage, including: the safety monitoring module writes the target inverter stage to the inverter stage register, so that the ring oscillator adjusts its inverter stage according to the target inverter stage stored in the inverter stage register. This implementation sets up a dedicated inverter stage register in the safety monitoring module for configuring the inverter stage of the ring oscillator. This inverter stage register provides a stable and controllable interface for configuring the inverter stage of the ring oscillator. Through this inverter stage register, reliable and standardized transmission of inverter stage configuration information from the control unit to the ring oscillator is achieved, making the adjustment of the inverter stage of the ring oscillator easier to control and implement.

[0012] In some implementations, the ring oscillator includes multiple inverters connected in series and an inverter selection link. The safety monitoring module writes the target inverter stage number into the inverter stage number register, so that the ring oscillator adjusts the inverter stage number according to the target inverter stage number stored in the inverter stage number register. This includes: the safety monitoring module writes the target inverter stage number into the inverter stage number register, so that the inverter selection link selects a target number of series inverters from the multiple series inverters to form an oscillation loop; wherein the target number corresponds to the target inverter stage number. In this implementation, by selecting the oscillation loop in the long inverter chain of the ring oscillator through the inverter selection link, the actual number of inverters participating in the oscillation can be changed directly and efficiently. This achieves a precise and reliable response to the configuration value in the inverter stage number register at the hardware level, providing a practical physical basis for dynamically and flexibly adjusting the inverter stage number of the ring oscillator, and enabling efficient inverter stage adjustment with a simple hardware structure.

[0013] In some implementations, the method further includes: the safety monitoring module counting the number of oscillations of the ring oscillator and determining the operating frequency of the ring oscillator based on the counting results; the safety monitoring module determining the process angle of the ring oscillator based on the operating frequency of the ring oscillator and the operating frequency of the ring oscillator at each process angle. In this implementation, the safety monitoring module determines the change in the operating frequency of the ring oscillator by counting oscillations, and then determines the process angle of the ring oscillator based on the operating frequency of the ring oscillator at each process angle. This allows the safety monitoring module to automatically and accurately sense the process angle change of the ring oscillator without relying on external factors, thus creating conditions for fully automatic ring oscillator frequency calibration.

[0014] In some implementations, the method further includes: the security monitoring module receiving an enable signal sent by the processor core, the enable signal being used to enable the security monitoring module to perform security monitoring on the monitored module; wherein the enable signal includes the operating frequency information of the monitored module. Based on this implementation, the processor core can flexibly control the security monitoring module's security monitoring enable by sending an enable signal to the security monitoring module, thereby facilitating a balance between system performance and system security monitoring. For example, when higher system performance is required, the processor core can disable the security monitoring module to save energy and computing resources; when higher system security is required, the processor core can enable the security monitoring module.

[0015] In some implementations, the microprocessor architecture further includes a security element, an on-chip network, and memory, wherein the processor core, the security element, and the memory are connected via the on-chip network. Based on this implementation, multiple modules within the microprocessor architecture can be treated as monitored modules, enabling the security monitoring module to perform security monitoring on these modules and improve the overall security of the microprocessor architecture.

[0016] In some implementations, there are multiple monitored modules and one security monitoring module; or, there are multiple monitored modules, with one security monitoring module corresponding to each monitored module. Based on this implementation, a single security monitoring module can be deployed in the microprocessor architecture to centrally monitor multiple monitored modules, or multiple security monitoring modules can be distributed in the microprocessor architecture to monitor different modules respectively. This allows the microprocessor architecture design to be flexibly chosen based on a comprehensive consideration of monitoring real-time performance, module independence, hardware resource overhead, and wiring complexity, thereby meeting diverse security monitoring needs while optimizing the overall area efficiency and architectural rationality of the microprocessor architecture. Attached Figure Description

[0017] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of this application. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.

[0018] Figure 1 This is a schematic diagram of a microprocessor architecture provided in an embodiment of this application.

[0019] Figure 2 This is a schematic diagram of the structure of a security monitoring module provided in an embodiment of this application. Detailed Implementation

[0020] In the field of integrated circuit security monitoring technology, in order to achieve real-time security monitoring of key modules inside the processor (such as cryptographic engines, memory controllers, etc.) and prevent external physical attacks (such as clock or voltage spike injection), the common practice of related technologies is to deploy a ring oscillator as a reference frequency source, compare its operating frequency with the operating frequency of the monitored module, and if the frequency deviation between the two exceeds the preset range, it is determined that there is an attack or anomaly.

[0021] The aforementioned ring oscillator typically consists of an odd number of inverters connected in series to form a closed-loop structure, and its oscillation frequency is determined by the number of inverter stages and the single-stage delay.

[0022] However, this solution does not perform ideally when applied to the security monitoring of microprocessors manufactured using advanced processes and requiring extremely high monitoring accuracy (e.g., the error between the operating frequency of the ring oscillator and the operating frequency of the monitored module must be less than ±1%). The main reason is the inherent process variation in semiconductor manufacturing, primarily manifested in significant differences in transistor speeds at different process corners, such as ff-corner (fast process corner), tt-corner (typical process corner), and ss-corner (slow process corner). For example, a 47-stage ring oscillator optimized for a typical process corner may, on some chips, have a reduced single-stage delay due to the transistors operating at a fast process corner, resulting in a final operating frequency as high as 925MHz, a deviation of over 35% from the target frequency of 685MHz; while on other chips operating at a slow process corner, its operating frequency may only be 560MHz, a deviation close to -20%. This severe frequency mismatch directly leads to the failure of the safety monitoring baseline, which may misreport normal process deviations as attacks, generating a large number of false alarms, or may fail to effectively detect real, small-amplitude aggressive frequency shifts due to the severe deviation of the baseline frequency itself, resulting in missed alarms and seriously weakening the effectiveness of safety monitoring.

[0023] The inventors of this application have discovered that the root cause of the above-mentioned problem lies in the fact that the above-mentioned scheme fixes the key variable of the oscillation level of the ring oscillator during the physical design stage, thus making it lose its ability to adjust when faced with uncontrollable single-stage delay changes introduced by the manufacturing process.

[0024] The formula for the operating frequency of a ring oscillator is: f_osc = 1 / (2 N T_delay) Where N is the effective number of inverter stages, and T_delay is the average delay of a single-stage inverter. When T_delay varies over a wide range (e.g., ±30%) due to different process angles, if N remains constant, the operating frequency f_osc of the ring oscillator will inevitably fluctuate significantly, making it impossible to stabilize at a preset target frequency.

[0025] To address the aforementioned technical problems, this application provides a novel safety monitoring method. This method introduces a process corner detection mechanism and a dynamic stage adjustment mechanism to transform the originally fixed inverter stage of the ring oscillator into a configurable parameter. This significantly improves the stability of the ring oscillator's operating frequency under cross-process corner conditions without significantly increasing hardware complexity, thereby achieving more accurate and effective safety monitoring.

[0026] Specifically, security monitoring of a monitored module typically involves comparing its operating frequency with that of a ring oscillator. If the deviation of the monitored module's operating frequency from the ring oscillator's frequency exceeds a set threshold, the monitored module is considered to be under attack. In existing technologies, because the number of inverter stages in a ring oscillator is fixed, its oscillation frequency changes when the process angle of the ring oscillator changes. This can lead to a significant difference between the monitored module's operating frequency and the ring oscillator's operating frequency due to changes in the ring oscillator's process angle, mistakenly identifying the monitored module as under attack, thus resulting in a false security detection.

[0027] The security monitoring method provided in this application introduces a process corner detection mechanism and a dynamic level adjustment mechanism, which can ensure that the operating frequency of the ring oscillator is consistent with the operating frequency of the monitored module even when the process corner of the ring oscillator changes. This provides a stable reference frequency source for security monitoring, thus avoiding the misinterpretation that the operating frequency of the monitored module is being attacked due to a large difference between the operating frequency of the ring oscillator and the operating frequency of the ring oscillator caused by the instability of the ring oscillator's own operating frequency. Therefore, it can improve the accuracy and effectiveness of security monitoring of the monitored module.

[0028] The technical solutions of the embodiments of this application will be described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of this application.

[0029] Figure 1 A schematic diagram of a microprocessor architecture that can implement the security monitoring method provided in this application is shown.

[0030] The microprocessor architecture 100 includes at least one processor core 110 and one or more security monitoring modules 120.

[0031] Processor core 110 can be a central processing unit core, a microcontroller core, or a dedicated processor core.

[0032] The microprocessor architecture also includes a security element 130, an on-chip network 131, and a memory 132, among which the processor core 110, the security element 130, and the memory 132 are all interconnected through the on-chip network 131.

[0033] Any one or more of the following modules in the microprocessor architecture described above, such as processor core 110, security element 130, on-chip network 131, and memory 132, can be used as monitored modules, and security monitoring of the monitored modules can be performed by security monitoring module 120.

[0034] The security monitoring module 120 can communicate with the processor core 110 through the on-chip network 131, receive the enable signal sent by the processor core 110, and start to perform security monitoring of the monitored module.

[0035] The monitored module typically has its own operating clock domain, and its operating frequency f_target can be fixed or dynamically adjustable. The safety monitoring module 120 internally includes a ring oscillator 121 with an adjustable inverter stage. The operating frequency of the ring oscillator 121 is used as a reference frequency for safety monitoring. The safety monitoring module 120 is also configured to compare this reference frequency with the operating frequency of the monitored module to detect whether an anomaly has occurred in the monitored module.

[0036] In the embodiments of this application, a security monitoring module refers to a hardware logic unit that can be integrated into a microprocessor architecture to perform security monitoring and control of specific functional modules through frequency monitoring. For example, a security monitoring module may include, but is not limited to: a dedicated hardware circuit controlled by a state machine or microcontroller, a sensor module containing configurable registers and interrupt generators, or a hardware and software co-operated monitoring unit, etc., whose core function is to provide a calibrable frequency reference and perform frequency comparison.

[0037] In some embodiments, the number of monitored modules within the microprocessor architecture can be multiple, while the number of security monitoring modules can be only one. In this embodiment, a single security monitoring module provides frequency reference and comparison services to multiple monitored modules in turn using time-division multiplexing or multiplexing to achieve security monitoring of multiple monitored modules. Alternatively, a single security monitoring module can also perform security monitoring on multiple monitored modules simultaneously. This embodiment can save chip area.

[0038] In other embodiments, the microprocessor architecture contains multiple monitored modules, with a dedicated security monitoring module for each monitored module. In this embodiment, each security monitoring module operates independently, continuously monitoring its corresponding module. This approach offers the highest level of real-time performance and independence, with each monitoring point operating independently, but it occupies more chip area.

[0039] The two security monitoring modules mentioned above can be flexibly selected, or different security monitoring module configurations can be used for different areas within the same microprocessor architecture. This helps to solve the problem of how to efficiently deploy security monitoring functions in complex system architectures, so as to meet diverse security needs while taking into account the area efficiency of chip design and the rationality of system architecture.

[0040] For example, in a microprocessor architecture that includes a cryptographic engine and a storage controller, separate security monitoring modules can be provided for each. This way, even if an attack on the storage controller affects its local clock, it won't interfere with the independent monitoring of the cryptographic engine. Conversely, in a resource-constrained microprocessor architecture, a single centralized security monitoring module might be used to periodically scan the frequency status of the cryptographic engine and storage controller.

[0041] Furthermore, the security monitoring module corresponding to the monitored module can be installed either inside or outside the monitored module. When the security monitoring module is installed outside the monitored module, it is preferred to install it close to the monitored module.

[0042] The security monitoring method provided in this application embodiment can be applied to, for example... Figure 1 The aforementioned microprocessor architecture can be specifically executed by the security monitoring module within that microprocessor architecture.

[0043] Specifically, the security monitoring method provided in this application includes: When the safety monitoring module detects a change in the process angle of the ring oscillator, it adjusts the number of inverter stages of the ring oscillator according to the current process angle of the ring oscillator and the operating frequency of the monitored module, so that the operating frequency of the ring oscillator is consistent with the operating frequency of the monitored module.

[0044] The monitored module includes any module in the microprocessor architecture, and the ring oscillator after being adjusted by the inverter stage is used as the reference frequency source for safety monitoring of the monitored module.

[0045] In some embodiments, the trigger condition for detecting a change in the process corner of the ring oscillator can be the initial process corner detection performed during system power-on initialization, or periodic process corner detection performed during system operation. For example, after the safety monitoring module powers on, a process corner detection process is first executed to obtain the current process corner state of the chip; this is considered a "process corner change" detection (from unknown to known). After the system starts running, process corner detection can be performed every certain period of time (e.g., every second) or according to instructions from the processor core. If the new detection result is different from the previously stored process corner state, it is determined that the process corner has changed, triggering a readjustment process for the inverter stage of the ring oscillator.

[0046] In some embodiments, the number of oscillations of the ring oscillator can be counted, and then based on the oscillation count and the clock frequency of the ring oscillator, the result can be calculated using the formula f_osc_measured = f_clk. (Count / K) calculates the operating frequency f_osc_measured of the ring oscillator.

[0047] Where f_clk represents the clock frequency of the ring oscillator, Count represents the number of oscillations of the ring oscillator, and K is a constant coefficient related to the gate time and the reference clock (for example, if the gate time is 65535 clock cycles, then K=65535).

[0048] After obtaining the operating frequency of the ring oscillator, the operating angle of the ring oscillator can be determined by combining the operating frequency range under different process angles.

[0049] In the embodiments of this application, the operating frequency of the monitored module is known, and the inverter stage of the ring oscillator can be adjusted using the operating frequency of the monitored module as the target frequency so that its operating frequency is consistent with the target frequency.

[0050] Furthermore, in the embodiments of this application, the operating frequency of the ring oscillator is consistent with the operating frequency of the monitored module, which means that the difference between the two operating frequencies is within a set difference range. It is not necessary for the two to be equal. The difference range can be flexibly set according to the needs, such as 10MHz or 5%.

[0051] In some embodiments, adjusting the number of inverter stages of a ring oscillator to match the target frequency can be achieved in various ways. For example, the ring oscillator can be tested at different process angles and with different numbers of inverter stages to determine the optimal number of inverter stages for different target frequencies and process angles, and a table of inverter stages and process angle frequencies can be constructed. Based on this, once the process angle of the ring oscillator is determined, the number of inverter stages that enable the ring oscillator to achieve the target operating frequency at the current process angle can be directly determined by looking up the table.

[0052] In other embodiments, the frequency mathematical model of the ring oscillator, f_osc = 1 / (2), can be used. (2 OSC_STAGE+1) Tinv_delay calculates the inverter stage number, where OSC_STAGE is the inverter stage number parameter and Tinv_delay is the typical inverter delay value at the current process angle. Based on the known target frequency f_target and the current process angle, the required OSC_STAGE value can be calculated in reverse using the above formula.

[0053] In other embodiments, the number of inverter stages of the ring oscillator can be fine-tuned and the actual operating frequency measured and compared with the target frequency. Adjustments can then be made according to the direction of the deviation until the deviation falls within the allowable range.

[0054] In this embodiment, the number of inverter stages of the ring oscillator can be adjusted by software or hardware. By combining the above-mentioned determination of the target stage value for adjusting the number of inverter stages of the ring oscillator, the number of inverter stages of the ring oscillator can be adjusted to the target stage value by software or hardware, so that the operating frequency of the ring oscillator is consistent with the operating frequency of the monitored module.

[0055] Based on this, the ring oscillator can be used as a reference frequency source for the safe detection of the monitored module.

[0056] As described above, the safety monitoring method provided in this application employs a ring oscillator with adjustable inverter stages within the safety monitoring module. Furthermore, the safety monitoring module can detect the current process corner. When a change in the current process corner is detected, the inverter stages of the ring oscillator are adjusted according to the current process corner and the operating frequency of the monitored module, so that the operating frequency of the ring oscillator matches the operating frequency of the monitored module. The aforementioned ring oscillator is then used as a reference frequency source for safety monitoring of the monitored module.

[0057] Security monitoring of monitored modules typically involves comparing the module's operating frequency with that of a ring oscillator. When the deviation of the monitored module's operating frequency from the ring oscillator's frequency exceeds a set threshold, the module is considered under attack. Therefore, ensuring the stability of the ring oscillator's operating frequency is fundamental for accurate attack monitoring. In the above scheme, even if the process angle of the ring oscillator changes, the operating frequency of the ring oscillator remains consistent with that of the monitored module, providing a stable reference frequency source for security monitoring. This avoids misinterpreting an attack as a significant difference between the monitored module's and ring oscillator's frequencies due to the ring oscillator's own frequency instability, thus improving the accuracy and effectiveness of security monitoring of the monitored module.

[0058] In another embodiment, the provided security monitoring method further includes: When the security monitoring module detects that the operating frequency of the monitored module deviates from the operating frequency of the ring oscillator by more than a set offset threshold, it sends an interrupt signal to the processor core; this interrupt signal indicates that an abnormality has occurred in the monitored module.

[0059] Specifically, once the operating frequency f_osc of the ring oscillator has been calibrated to match the operating frequency f_target of the monitored module through the aforementioned safety monitoring method, the operating frequencies of the two under normal conditions should remain almost identical or nearly identical. This almost identical or nearly identical frequency can be represented by the frequency offset between the two being less than a set offset threshold.

[0060] If the monitored module is subjected to external attacks (such as voltage glitches or clock tampering) or internal faults, the measured actual operating frequency f_measured of the monitored module may deviate from f_target momentarily or continuously, resulting in the offset of f_measured relative to the operating frequency f_osc of the ring oscillator being greater than the set offset threshold. At this time, the security monitoring module can consider that the monitored module has malfunctioned.

[0061] In this situation, the security monitoring module sends an interrupt signal to the processor core to inform it that an anomaly has occurred in the monitored module.

[0062] This processing method enables real-time security monitoring of the monitored modules during the operation of the microprocessor architecture. When an anomaly is detected in the monitored module, the processor core is notified in a timely manner via an interrupt, so that the abnormal situation can be detected and handled promptly.

[0063] In some embodiments, see Figure 2 As shown, the safety monitoring module includes an APB interface module, an interrupt management module, a process corner detection logic module, a dynamic level configuration module, a frequency comparison module, a frequency counting module, and a ring oscillator.

[0064] The APB interface module is the interface between the security monitoring module and the outside world for data and information transmission, and it can realize register reading and writing, status monitoring, and configuration management functions.

[0065] The interrupt management module is used to send interrupt signals to the processor core. These interrupt signals can be interrupts due to the number of oscillations of the ring oscillator or abnormal interrupts when an anomaly is detected in the monitored module. The processor core can also configure the interrupt function of the security monitoring module through this interrupt management module.

[0066] The process corner detection logic module is used to measure the operating frequency of the ring oscillator, determine the current process corner, and calculate the number of inverter stages of the ring oscillator by combining the current process corner and the operating frequency of the monitored module. Inside the process corner detection logic module, there is a process corner recording register reg[1:0] corner_reg, used to store the current process corner status. For example, 00 represents the SS process corner, 01 represents the TT process corner, and 10 represents the FF process corner.

[0067] The dynamic stage configuration module has an inverter stage register reg[6:0] osc_stage_reg, which stores the inverter stage values ​​that need to be configured for the ring oscillator. In addition, the dynamic stage configuration module can also set a calibration control signal register reg[2:0] calib_ctrl, which stores the calibration control mode information for the ring oscillator. For example, bit1 indicates manual configuration of the inverter stage, and bit0 indicates automatic configuration of the inverter stage.

[0068] The frequency comparison module is used to compare the operating frequency of the ring oscillator with the operating frequency of the monitored module. When it is detected that the deviation of the operating frequency of the monitored module relative to the operating frequency of the ring oscillator is greater than the set deviation threshold, such as greater than 3%, the frequency comparison module sets the interrupt flag bit, that is, sets the interrupt flag bit to be valid. When the interrupt management module detects that the interrupt flag bit is valid, it sends an interrupt signal to the processor core.

[0069] The frequency counting module and the ring oscillator can be integrated or configured separately. The frequency counter counts the number of oscillations of the ring oscillator and feeds the counting result back to the process corner detection logic module, enabling the process corner detection logic module to determine the process corner of the ring oscillator based on the received counting result.

[0070] Based on the structure of the aforementioned safety monitoring module, the process corner detection logic module determines the current process corner of the ring oscillator and, based on the current process corner and the operating frequency of the monitored module, determines the number of inverter stages in the ring oscillator. This inverter stage value is then written into the inverter stage register in the dynamic stage configuration module. The ring oscillator is configured according to this inverter stage number to ensure its operating frequency matches that of the monitored module. Furthermore, the frequency comparison module acquires the operating frequency of the monitored module and compares it with the operating frequency of the ring oscillator. When the deviation of the monitored module's operating frequency from the ring oscillator's operating frequency exceeds a set offset threshold, an interrupt flag is set. Upon detecting that the interrupt flag is set, the interrupt management module sends an interrupt signal to the processor core.

[0071] In this embodiment, a dedicated frequency comparison module is used to compare the operating frequency of the ring oscillator with that of the monitored module, which can improve the accuracy of frequency change detection and increase the efficiency of anomaly detection.

[0072] In other embodiments, the criterion for determining whether the operating frequency of the monitored module deviates from the operating frequency of the ring oscillator by a set offset threshold is not limited to a single fixed offset threshold, but can also employ multi-level thresholds. For example, a "warning threshold" and a "critical anomaly threshold" can be set to trigger different levels of interruption, respectively.

[0073] In another embodiment, the safety monitoring module adjusts the number of inverter stages of the ring oscillator based on the current process angle of the ring oscillator and the operating frequency of the monitored module, specifically including: The safety monitoring module determines the target inverter stage based on the operating frequency of the ring oscillator at different process angles and at different inverter stages.

[0074] The target inverter stage is the number of inverter stages that, under the current process angle of the ring oscillator, makes the operating frequency of the ring oscillator consistent with the operating frequency of the monitored module.

[0075] Specifically, for a given ring oscillator, its operating frequency at a specific process angle and with a specific number of inverter stages can be known in advance through simulation and testing. Therefore, as long as the current process angle A and the target frequency F are known, the inverter stage N that outputs the frequency closest to F at process angle A can be found from the known data; N is the target inverter stage.

[0076] For example, for a ring oscillator whose inverter stage parameter OSC_STAGE supports dynamic configuration of 38-63 stages, its operating frequency under different process angles and different inverter stages can be determined by simulation or testing, resulting in the dynamic frequency configuration table shown in Table 1.

[0077] Table 1 In the table above, OSC_STAGE is the inverter stage parameter, and its relationship with the number of physical inverters is: Number of inverters = 2 OSC_STAGE + 1.

[0078] By consulting the dynamic frequency configuration table above, the target inverter stage that makes the operating frequency of the ring oscillator consistent with the operating frequency of the monitored module can be determined under the current process angle of the ring oscillator.

[0079] For example, assuming the operating frequency of the monitored module is 685MHz and the ring oscillator is at the ff process corner, the target inverter stage number to make the operating frequency of the ring oscillator consistent with the operating frequency of the monitored module can be determined by consulting the dynamic frequency configuration table mentioned above. The target inverter stage number is 63 stages.

[0080] Based on the determined target inverter stage number, the safety monitoring module adjusts the inverter stage number of the ring oscillator to match the target inverter stage number.

[0081] For details, see Figure 2 The safety monitoring module structure shown in the diagram is as follows: when the process corner detection logic module determines the current process corner of the ring oscillator, and determines the target inverter stage of the ring oscillator according to the current process corner of the ring oscillator and the operating frequency of the monitored module through the above-mentioned table lookup method, the target inverter stage value is written into the inverter stage register in the dynamic stage configuration module.

[0082] Then, the ring oscillator adjusts its own inverter stage number according to the target inverter stage number stored in the inverter stage number register.

[0083] In this embodiment, the ring oscillator includes multiple inverters connected in series and an inverter selection link. The ring oscillator adjusts its own inverter stage number according to the target inverter stage number stored in the inverter stage register. Specifically, the inverter selection link selects a target number of inverters from the multiple inverters connected in series to form an oscillation loop; wherein the target number corresponds to the target inverter stage number.

[0084] In this embodiment, the ring oscillator with adjustable inverter stages employs a long chain containing a large number (e.g., corresponding to the maximum number of stages, such as 127 stages) of series inverters, with taps leading out at different nodes of this long chain (i.e., the output of each stage inverter). Furthermore, the ring oscillator includes an inverter selection link composed of multiplexers, which connects the loop closure point to different tap nodes. This ensures that the continuous inverters from the initial inverter input to the selected tap node form an effective oscillation loop, while the inverters not included in the loop are bypassed.

[0085] For example, suppose a ring oscillator with adjustable inverter stages includes an inverter chain consisting of 127 inverters INV1, INV2, ..., INV127 connected in series. The inverter selection chain includes a multiplexer MUX. The multiple data inputs of the MUX are connected to the output nodes after an odd number of inverters in the inverter chain (e.g., the outputs of INV1, INV3, INV5, ..., INV127, to ensure the total number of stages in the loop is odd). The select terminal SEL of the MUX is driven by the decoded value of the inverter stage register. The output of the MUX serves as the oscillator output and is simultaneously fed back to the input of the first inverter, INV1, forming a closed loop.

[0086] Assuming the value in the inverter stage register is 63, the selection logic might decode to select the output of the 127th inverter (INV127). In this case, the oscillation loop contains 127 inverters from INV1 to INV127, with a stage number of 127. When the value in the inverter stage register is 47, the output of the 95th inverter is selected, with a stage number of 95. When the value in the inverter stage register is 38, the output of the 77th inverter is selected, with a stage number of 77. This design allows a single physical structure to flexibly adapt to various stage configurations. The implementation of the above multiplexer link is not limited to a single large MUX; it can also be formed by cascading multiple smaller MUXs.

[0087] Based on the above ring oscillator structure, when the safety monitoring module writes the target inverter stage number into the inverter stage number register, the inverter selection link in the ring oscillator selects the target number of series inverters corresponding to the target inverter stage number from multiple series inverters according to the target inverter stage number stored in the inverter stage number register to form an oscillation loop, thereby realizing the adjustment of the inverter stage number of the ring oscillator.

[0088] By employing the aforementioned ring oscillator structure including an inverter selection link, the solution in this embodiment can directly and efficiently respond to inverter stage configuration commands at the hardware level.

[0089] The security monitoring method disclosed in another embodiment also includes: The safety monitoring module counts the number of oscillations of the ring oscillator and determines the operating frequency of the ring oscillator based on the counting results; The safety monitoring module determines the process angle of the ring oscillator based on its operating frequency and the operating frequency of the ring oscillator at each process angle.

[0090] Specifically, when a ring oscillator operates at a known, fixed number of stages (e.g., the default 47 stages), its operating frequency f_osc is entirely determined by the inverter delay at the current process corner. Since the delay varies significantly across different process corners, the measured f_osc will fall within distinctly different frequency ranges. By simulating or testing, the typical frequency ranges corresponding to a specific number of stages of the ring oscillator at the ff, tt, and ss process corners can be determined. The measured frequency can then be compared with these ranges to infer the current process corner.

[0091] Specifically, when determining the process angle of a ring oscillator, firstly, the ring oscillator with a known number of stages (e.g., 47) is started oscillating at that fixed number of stages. Simultaneously, a coarse counter is enabled to count the output signal of the ring oscillator. A fixed gate time T_gate is set, and at the end of the gate time T_gate, the value Count of the coarse counter is read. The result is calculated according to the formula f_osc_measured = f_clk. (Count / K) can be used to calculate the measured frequency of the ring oscillator, where K is a constant coefficient related to the gate time (for example, if the gate time is 65535 signal cycles, then K = 65535).

[0092] After obtaining the measured frequency f_osc_measured, it is compared with a preset frequency threshold to determine the process angle. For example, based on the typical characteristics of a 47-stage ring oscillator, the following can be preset: If f_osc_measured > 700MHz, then it is determined to be the ff process corner; If 650MHz ≤ f_osc_measured ≤ 700MHz, then it is determined to be a time-to-time (TT) process corner. If f_osc_measured < 650MHz, then it is determined to be an SS process corner.

[0093] The aforementioned thresholds of 650MHz and 700MHz can be adjusted based on actual simulation and test data.

[0094] The processing method described above enables the automatic and real-time inference of the process angle state of the ring oscillator during operation.

[0095] In other embodiments, a counting threshold comparison interruption function can be set for the coarse counter. That is, corresponding oscillation number thresholds are set for the thresholds of 650MHz and 700MHz. When the oscillation number count result counted by the coarse counter exceeds the oscillation number threshold range, an interrupt signal is output. At this time, the safety monitoring module can determine that the operating frequency of the ring oscillator has exceeded the operating frequency range under a specific process angle, which proves that the process angle of the ring oscillator has changed. At this time, the safety monitoring module can execute the processing of the safety monitoring method in the above embodiments, readjust the inverter stage of the ring oscillator, and make the operating frequency of the ring oscillator consistent with the operating frequency of the monitored module again.

[0096] By adopting the above-mentioned process angle detection method based on frequency measurement, the scheme of this embodiment enables the entire frequency calibration process of the ring oscillator to be free from the need for additional process angle detection tools or methods, and has the ability to automatically sense process angle changes, thereby improving the efficiency of ring oscillator frequency calibration.

[0097] In another embodiment, in order to enable the security monitoring function to be flexibly managed and triggered by the system, the security monitoring method provided in this embodiment further includes: the security monitoring module receiving an enable signal sent by the processor core, the enable signal being used to enable the security monitoring module to perform security monitoring on the monitored module; wherein, the enable signal includes the operating frequency information of the monitored module.

[0098] In this embodiment, the operation of the security monitoring module is controlled by the processor core. The processor core can dynamically enable or disable security monitoring of a specific module based on system operating status, security policies, or power management requirements. For example, when running high-security tasks, the security monitoring module can be enabled to monitor the cryptographic engine; when the system is in hibernation, the security monitoring module can be disabled to save power.

[0099] The enable signal sent by the processor core to the security monitoring module carries the identification information of the monitored module and may also include the operating frequency information of the monitored module. This allows the security monitoring module to more directly determine the operating frequency required by the ring oscillator when it receives the enable signal.

[0100] In some embodiments, the enable signal sent by the processor core to the security monitoring module can be achieved by the processor core writing configuration values ​​to one or more registers. For example, the processor core can write a specific value (the identifier of the monitored module and / or the operating frequency of the monitored module) to the register via the APB bus to initiate the security monitoring module to perform security monitoring on the monitored module. When the security monitoring module detects that data has been written to the aforementioned register, it reads the value in the register and starts the security monitoring program.

[0101] The following section uses the example of security monitoring of the cryptographic engine in a microprocessor architecture to detail the complete process of the security monitoring method provided in this application.

[0102] Suppose a high-performance cryptographic engine module is integrated into a microprocessor architecture chip, with a normal operating frequency of 685MHz.

[0103] 1. Chip power-on initialization phase: The processor core first writes the target frequency value of 685MHz (or the corresponding code) to the configuration register of the security monitoring module located near the cryptographic engine via the APB bus, and enables the security monitoring module to start performing security monitoring work.

[0104] 2. Automatic Calibration Phase: The safety monitoring module first configures the ring oscillator to the default 47 stages, starts oscillation, and enables the coarse counter to begin counting. Then, the coarse counter counts the ring oscillator output within a 10-microsecond gate time, measuring a frequency of 920MHz. Based on a preset threshold (920MHz > 700MHz), the logic determines the current process corner to be ff and writes this result to the process corner recording register.

[0105] 3. Stage Adjustment Phase: The safety monitoring module queries the internally stored dynamic frequency configuration table based on the process corner record register (value ff) and the target frequency register (value 685 MHz) to obtain the target inverter stage value of 63. It then writes the value 63 into the inverter stage register.

[0106] 4. Hardware Response and Loop Switching: When the ring oscillator hardware detects a change in the value of the inverter stage register, its internal inverter selection link switches the oscillation loop closure point to the output of the 127th stage inverter. The ring oscillator immediately restarts oscillation in a new 63-stage (corresponding to 127 inverters) mode.

[0107] 5. Verification and Monitoring Readiness (Optional): The security monitoring module can remeasure the adjusted frequency to confirm that it is approximately 694MHz, with an error within +1.3% of the target 685MHz, meeting the requirements. Subsequently, it enables the frequency comparison module to continuously compare the calibrated ring oscillator operating frequency with the operating frequency sampled from the cryptographic engine in real time.

[0108] 6. Attack Detection and Response: When an attacker attempts to disrupt the cryptographic engine's operation by injecting a low-voltage glitch into its power pin, the glitch causes a momentary increase in the internal circuitry delay of the cryptographic engine, briefly causing its operating frequency to drop from 685MHz to 650MHz. The frequency comparison module immediately detects that the frequency offset exceeds the preset ±4% threshold in the next comparison cycle (e.g., after 1 millisecond). (Normal fluctuations should be around ±1%).

[0109] 7. Interrupt Triggering and Defense: The frequency comparison module immediately sets the interrupt flag. Upon detecting this, the interrupt management module generates a high-priority interrupt signal and sends it to the processor core. The processor core responds to the interrupt, queries the interrupt source, and confirms an abnormal frequency of the cryptographic engine. The defense mechanism is then triggered: it immediately freezes writes to all critical status registers of the cryptographic engine; records the timestamp of the current attack event, the process corner status (ff), and the measured frequency deviation (Δf=35MHz) in the security log buffer; and forcibly resets the cryptographic engine module, clearing any potentially corrupted key data within it.

[0110] In this scenario, the security monitoring method provided in this application overcomes the problem of inaccurate security monitoring reference frequency caused by differences in manufacturing processes, providing the cryptographic engine with a highly accurate reference frequency at any process angle. When an attack occurs, the system can quickly detect it and trigger an automated defense response, significantly improving the chip's proactive defense capability against physical attacks and protecting the user's payment keys and transaction security.

[0111] Another embodiment of this application also provides a microprocessor architecture, the specific structure of which can be found in [reference needed]. Figure 1 As shown. The microprocessor architecture includes a processor core and a security monitoring module, which includes a ring oscillator with adjustable inverter stages. In this embodiment, the microprocessor architecture is configured to implement the security monitoring method described in the above embodiments. The specific processing steps and technical effects achieved by the microprocessor architecture in implementing the above security monitoring method can be found in the detailed description in the above method embodiments, and will not be repeated here.

[0112] Those skilled in the art will understand that this microprocessor architecture can be designed using hardware description languages ​​such as Verilog or VHDL and ultimately manufactured as an integrated circuit chip.

[0113] In addition to the methods and devices described above, embodiments of this application may also be computer program products, which include computer program instructions that, when executed by a processor, cause the processor to perform the steps of the security monitoring method described in any of the above embodiments of this specification.

[0114] The computer program product can be written in any combination of one or more programming languages ​​to perform the operations of the embodiments of this application. The programming languages ​​include object-oriented programming languages ​​such as Java and C++, as well as conventional procedural programming languages ​​such as C or similar languages. The program code can be executed entirely on the user's computing device, partially on the user's computing device, as a standalone software package, partially on the user's computing device and partially on a remote computing device, or entirely on a remote computing device or server.

[0115] Furthermore, embodiments of this application may also be storage media storing a computer program thereon, which, when executed by a processor, implements the steps of the security monitoring method described in any of the above embodiments of this specification.

[0116] For the foregoing method embodiments, in order to simplify the description, they are all described as a series of actions. However, those skilled in the art should understand that this application is not limited to the described order of actions, because according to this application, some steps can be performed in other orders or simultaneously. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily essential to this application.

[0117] It should be noted that the various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. Similar or identical parts between embodiments can be referred to interchangeably. For apparatus embodiments, since they are basically similar to method embodiments, the description is relatively simple; relevant parts can be referred to the descriptions in the method embodiments.

[0118] The steps in the methods of the various embodiments of this application can be adjusted, merged, or deleted in order according to actual needs, and the technical features described in each embodiment can be replaced or combined.

[0119] The modules and sub-modules in the various embodiments of the present application's devices and terminals can be merged, divided, and deleted according to actual needs.

[0120] It should be understood that the disclosed terminals, devices, and methods can be implemented in other ways, given the several embodiments provided in this application. For example, the terminal embodiments described above are merely illustrative. For instance, the division of modules or sub-modules is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple sub-modules or modules may be combined or integrated into another module, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be indirect coupling or communication connection through some interfaces, devices, or modules, and may be electrical, mechanical, or other forms.

[0121] The modules or submodules described as separate components may or may not be physically separate. The components that constitute a module or submodule may or may not be physical modules or submodules; that is, they may be located in one place or distributed across multiple network modules or submodules. Some or all of the modules or submodules can be selected to achieve the purpose of this embodiment's solution, depending on actual needs.

[0122] Furthermore, the functional modules or sub-modules in the various embodiments of this application can be integrated into one processing module, or each module or sub-module can exist physically separately, or two or more modules or sub-modules can be integrated into one module. The integrated modules or sub-modules described above can be implemented in hardware or in the form of software functional modules or sub-modules.

[0123] Those skilled in the art will further recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of the various examples have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0124] The steps of the methods or algorithms described in conjunction with the embodiments disclosed herein can be implemented directly by hardware, a software unit executed by a processor, or a combination of both. The software unit can be located in random access memory (RAM), main memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium known in the art.

[0125] Finally, it should be noted that in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0126] The above description of the disclosed embodiments enables those skilled in the art to make or use this application. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of this application. Therefore, this application is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A safety monitoring method, characterized in that, Applied to a microprocessor architecture, the microprocessor architecture includes a processor core and a security monitoring module, the security monitoring module including a ring oscillator with adjustable inverter stages; The method includes: The security monitoring module periodically performs process corner detection on the ring oscillator or performs process corner detection on the ring oscillator according to the instructions of the processor core. When a change in the process corner of the ring oscillator is detected, the number of inverter stages of the ring oscillator is adjusted according to the current process corner of the ring oscillator, the operating frequency of the ring oscillator at different process corners and with different inverter stages, and the operating frequency of the monitored module, so that the operating frequency of the ring oscillator is consistent with the operating frequency of the monitored module. The process corner of the ring oscillator is one of a fast process corner, a typical process corner, and a slow process corner, which are determined based on the inherent process variations of the microprocessor architecture in semiconductor manufacturing. The monitored module includes any module in the microprocessor architecture, and the ring oscillator is used as a reference frequency source for security monitoring of the monitored module, so as to determine that the monitored module is under attack when the operating frequency of the monitored module deviates from the operating frequency of the ring oscillator by more than a set offset threshold is detected.

2. The method according to claim 1, characterized in that, The method further includes: When the security monitoring module detects that the operating frequency of the monitored module deviates from the operating frequency of the ring oscillator by more than a set offset threshold, it sends an interrupt signal to the processor core; the interrupt signal indicates that the monitored module has malfunctioned.

3. The method according to claim 1, characterized in that, The safety monitoring module adjusts the number of inverter stages of the ring oscillator based on the current process angle of the ring oscillator, the operating frequency of the ring oscillator at different process angles and with different inverter stages, and the operating frequency of the monitored module. This adjustment includes: The safety monitoring module determines the target inverter stage based on the operating frequency of the ring oscillator when it is in different process angles and uses different inverter stages. The target inverter stage is the number of inverter stages that makes the operating frequency of the ring oscillator consistent with the operating frequency of the monitored module under the current process angle of the ring oscillator. The safety monitoring module adjusts the number of inverter stages of the ring oscillator to the target number of inverter stages.

4. The method according to claim 3, characterized in that, The security monitoring module includes an inverter stage register; The safety monitoring module adjusts the number of inverter stages of the ring oscillator to the target number of inverter stages, including: The safety monitoring module writes the target inverter stage number into the inverter stage number register, so that the ring oscillator adjusts the inverter stage number according to the target inverter stage number stored in the inverter stage number register.

5. The method according to claim 4, characterized in that, The ring oscillator includes multiple inverters connected in series and an inverter selection link; The safety monitoring module writes the target inverter stage number into the inverter stage number register, so that the ring oscillator adjusts the inverter stage number according to the target inverter stage number stored in the inverter stage number register, including: The security monitoring module writes the target inverter stage number into the inverter stage number register, so that the inverter selection link selects a target number of series inverters from the plurality of series inverters to form an oscillation loop; wherein the target number corresponds to the target inverter stage number.

6. The method according to claim 1, characterized in that, The safety monitoring module performs process corner detection on the ring oscillator, including: The safety monitoring module counts the number of oscillations of the ring oscillator and determines the operating frequency of the ring oscillator based on the counting results; The safety monitoring module determines the process angle of the ring oscillator based on the ring oscillator's operating frequency and its operating frequency at various process angles.

7. The method according to any one of claims 1 to 6, characterized in that, The method further includes: The security monitoring module receives an enable signal sent by the processor core, and the enable signal is used to enable the security monitoring module to perform security monitoring on the monitored module. The enable signal includes the operating frequency information of the monitored module.

8. The method according to any one of claims 1 to 6, characterized in that, The microprocessor architecture also includes a security element, an on-chip network, and a memory, wherein the processor core, the security element, and the memory are connected via the on-chip network.

9. The method according to any one of claims 1 to 6, characterized in that, The number of monitored modules is multiple, and the number of security monitoring modules is one; or, The number of monitored modules is multiple, and a security monitoring module is set up for each monitored module.

10. A microprocessor architecture, characterized in that, The system includes a processor core and a security monitoring module, the security monitoring module including a ring oscillator with adjustable inverter stages, and the microprocessor architecture is configured to implement the security monitoring method as described in any one of claims 1 to 9.

Citation Information

Patent Citations

  • Method for monitoring FPGA hardware Trojan horse in real time based on ring oscillators

    CN110348254A

  • Ring oscillator

    CN119814001A

  • All-digital PVT sensor based on ring oscillator

    CN122043196A