Safety response sequence hardening circuit

CN122548801APending Publication Date: 2026-08-11陈立波
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-05-28
Publication Date
2026-08-11

AI Technical Summary

Technical Problem

[0003]本发明的目的在于提供一种安全响应控制电路,以解决现有技术中安全响应流程容易被外部干预,导致敏感数据泄露的问题

Benefits of technology

[0014]1. 采用固定硬件状态机固化安全响应的执行顺序,且安全响应流程不接受外部中断或修改,能够有效防止攻击者干预安全响应流程;

✦ Generated by Eureka AI based on patent content.
Patent Text Reader

Abstract

This invention discloses a security response control circuit, relating to the field of integrated circuit security technology. The circuit includes a fixed hardware state machine; the fixed hardware state machine fixes the execution order of the security response, completing the data saving operation before clearing the data. The security response process of the fixed hardware state machine does not accept external interruption or modification. This invention can effectively prevent external interference with the security response process, avoid the leakage of sensitive data during the security response process, and improve the system's security protection capabilities.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of integrated circuit security technology, and in particular to a security response control circuit and protection method. Background Technology

[0002] In high-security electronic systems, when a security attack or anomaly is detected, a security response process needs to be triggered to save important data and clear sensitive data to prevent leakage. In existing technologies, security response processes are mostly implemented using software control. However, software programs are easily tampered with or hijacked by attackers, leading to interruptions or modifications to the security response process, preventing the timely clearing of sensitive data, and ultimately causing data leakage. Furthermore, some existing solutions use rewritable hardware state machines to control the security response process. Attackers can alter the security response sequence by modifying the state machine's configuration, which also poses a significant security vulnerability. Summary of the Invention

[0003] The purpose of this invention is to provide a security response control circuit to solve the problem that the security response process in the prior art is easily interfered with by external parties, leading to the leakage of sensitive data.

[0004] To achieve the above objectives, the present invention adopts the following technical solution: 1. A security response control circuit, characterized in that it includes a fixed hardware state machine; the fixed hardware state machine fixes the execution order of the security response, and before clearing the data, it first completes the data saving operation; the security response process of the fixed hardware state machine does not accept external interruption or modification.

[0005] 2. The safety response control circuit according to claim 1, characterized in that the internal asynchronous communication circuit adopts a five-phase asynchronous handshake protocol and integrates an edge overlap detection circuit.

[0006] 3. The safety response control circuit according to claim 1, wherein the edge overlap detection circuit triggers a safety lock when the signal edge interval is less than a set threshold.

[0007] 4. The security response control circuit according to claim 1, wherein the data is security-related data, the saving operation includes writing the security log into a non-volatile storage area, and the saving unit is configured with an independent power supply circuit to ensure normal data writing in the event of a power failure.

[0008] 5. The safety response control circuit according to claim 1, characterized in that, after the safety response is triggered, all operations are automatically executed by hardware, without the need for software instruction scheduling.

[0009] 6. The safety response control circuit according to claim 1, characterized in that, after the safety response is completed, the circuit enters a permanent safety lock state, which can only be restored by external hardware reset.

[0010] 7. The security response control circuit according to claim 1, characterized in that, after the data clearing is completed, the power supplies of the cryptographic accelerator module, the inner physical unclonable function module, the one-time programmable memory unit readout circuit, the ferroelectric random access memory controller, and the side channel protection module are turned off in a preset order.

[0011] 8. A security response protection method, characterized in that it is applied to the circuit of claim 1, comprising: after triggering a security alarm, performing a data saving operation before clearing the data according to a fixed sequence, and then performing data clearing and module shutdown.

[0012] 9. A purely hardware-based security chip, characterized in that it integrates the security response control circuit as described in claim 1.

[0013] 10. A highly reliable embedded security system, characterized in that it is equipped with the pure hardware security chip as described in claim 9. Beneficial effects

[0014] 1. A fixed hardware state machine is used to solidify the execution order of security responses, and the security response process does not accept external interruption or modification, which can effectively prevent attackers from interfering with the security response process; 2. The security response process follows the order of "save first, then clear," which ensures that important data is saved in a timely manner and avoids the leakage of sensitive data. 3. Once a security response is triggered, all operations are executed automatically by hardware without the need for software instruction scheduling, thus improving the reliability of the security response; 4. The storage unit is equipped with an independent power supply circuit to ensure that data can be written normally in the event of a power failure, thereby improving the fault tolerance of the system. Detailed Implementation

[0015] The present invention will be further described in detail below with reference to specific embodiments.

[0016] The security response control circuit provided in this embodiment is based on a fixed hardware state machine that solidifies the execution order of security responses. The fixed hardware state machine is a state machine solidified through metal interconnects during chip manufacturing. Its state transition logic cannot be modified after manufacturing, effectively preventing attackers from tampering with the security response process.

[0017] The fixed hardware state machine executes the following security response sequence: upon receiving a security alarm signal, it first saves the data, then clears the data, and finally shuts down the relevant functional modules in a preset order. The entire security response process is designed to prevent external interruptions or modifications, ensuring that the security response is executed completely according to the predetermined sequence.

[0018] The internal asynchronous communication circuit employs a five-phase asynchronous handshake protocol, effectively preventing signal interference and timing attacks. It also integrates an edge overlap detection circuit; when the detected signal edge interval is less than a set threshold, it is determined to be an abnormal signal, triggering a security lockout.

[0019] Data saving operations include writing important data such as security logs and system status to non-volatile storage. The storage unit is equipped with an independent power supply circuit. When the main system power supply fails, the independent power supply circuit supplies power to the storage unit, ensuring that data can be written normally in the event of a power outage.

[0020] Once a security response is triggered, all operations are automatically executed by a fixed hardware state machine, eliminating the need for software instruction scheduling and avoiding security risks caused by software tampering. After the security response is completed, the circuit enters a permanent security lockout state, and all functional modules cease operation. Normal operation can only be restored through external hardware reset.

[0021] After the data is cleared, the fixed hardware state machine sequentially shuts down the power supplies to the cryptographic accelerator module, the inner-layer physical non-cloning function module, the one-time programmable memory unit readout circuit, the ferroelectric random access memory controller, and the side-channel protection module in a preset order. The side-channel protection module is the last unit to be shut down, ensuring that security monitoring continues until the very last moment.

[0022] The security response and protection method provided in this embodiment includes the following steps: 1. The security detection module detects a security attack or anomaly and sends a security alarm signal to the fixed hardware state machine; 2. Upon receiving a security alarm signal, the fixed hardware state machine initiates the security response process; 3. First, perform a data saving operation to write important data to non-volatile storage; 4. After the data is saved, perform a zeroing operation on sensitive data; 5. After the data is cleared, turn off the power to the cryptographic accelerator module, the inner physical non-cloning function module, the one-time programmable memory unit read circuit, the ferroelectric random access memory controller, and the side channel protection module in the preset order. 6. After the safety response process is completed, the circuit enters a permanent safety lockout state.

Claims

1. A safety response control circuit, characterized by, It includes a fixed hardware state machine; the fixed hardware state machine fixes the execution order of the security response, and the data saving operation is completed before clearing the data. The security response process of the fixed hardware state machine does not accept external interruption or modification.

2. The security response control circuit of claim 1, wherein, The internal asynchronous communication circuit adopts a five-phase asynchronous handshake protocol and integrates an edge overlap detection circuit.

3. The security response control circuit of claim 1, wherein, The edge overlap detection circuit triggers a safety lock when the signal edge interval is less than a set threshold.

4. The safety response control circuit according to claim 1, characterized in that, The data is security-related data, and the saving operation includes writing the security log to a non-volatile storage area. The saving unit is configured with an independent power supply circuit to ensure that the data is written normally in the event of a power failure.

5. The safety response control circuit according to claim 1, characterized in that, Once a security response is triggered, all operations are executed automatically by the hardware, without the need for software instruction scheduling.

6. The safety response control circuit according to claim 1, characterized in that, After the safety response is completed, the circuit enters a permanent safety lock state, which can only be restored by external hardware reset.

7. The safety response control circuit according to claim 1, characterized in that, After the data is cleared, the power supplies of the cryptographic accelerator module, the inner physical non-clonable function module, the one-time programmable memory unit readout circuit, the ferroelectric random access memory controller, and the side channel protection module are turned off in a preset order.

8. A security response protection method, characterized in that, The circuit described in claim 1 includes: after triggering a safety alarm, performing a data saving operation before clearing the data according to a fixed sequence, and then performing data clearing and module shutdown.

9. A purely hardware-based security chip, characterized in that, It integrates the safety response control circuit as described in claim 1.

10. A highly reliable embedded security system, characterized in that, It is equipped with the pure hardware security chip as described in claim 9.