A method for securely storing device identity data based on dual-layer non-volatile storage
Patent Information
- Application Number
- CN202610737116.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-05-27
- Publication Date
- 2026-08-18
AI Technical Summary
单一存储方式存在以下问题:一是如果采用一次性可编程存储器,虽然数据不可篡改,但无法更新,难以存储设备的全生命周期状态数据;二是如果采用可多次擦写的非易失性存储器,虽然可以更新数据,但容易被非法篡改,安全性不足
[0015]本申请具有以下有益效果:
Abstract
Description
Technical Field
[0001] This application relates to the field of data storage technology, and in particular to a method for securely storing device identity data based on dual-layer non-volatile storage. Background Technology
[0002] Currently, device identity data is primarily stored in a single type of non-volatile memory. This single storage method has the following problems: First, if one-time programmable memory is used, although the data cannot be tampered with, it cannot be updated, making it difficult to store the device's entire lifecycle status data; second, if rewritable non-volatile memory is used, although the data can be updated, it is easily tampered with illegally, resulting in insufficient security.
[0003] Some existing technologies use software encryption to protect stored data, but software encryption is easily cracked and still poses security risks. Therefore, a device identity data storage solution that balances security and flexibility is needed. Summary of the Invention
[0004] The purpose of this application is to overcome the shortcomings of the prior art and provide a secure storage method for device identity data based on dual-layer non-volatile storage.
[0005] To achieve the above objectives, this application adopts the following technical solution: A method for securely storing device identity data based on dual-layer non-volatile storage includes the following steps: The device's basic identity data is physically solidified once and cannot be modified during operation. Store the device's entire lifecycle status data in a non-volatile, rewritable storage medium. The full lifecycle state data is protected by hardware encryption using a root key generated inside the chip. The root key is only generated and used inside the chip and does not leave the chip. The basic identity data and the full lifecycle status data are bound together using hardware encryption. All of the above steps are completed by pure hardware circuits, with no software processor involved in storage and encryption operations.
[0006] Furthermore, the non-volatile, rewritable storage medium is any one of ferroelectric random access memory, magnetoresistive random access memory, and resistive random access memory.
[0007] Furthermore, the ferroelectric random access memory supports nearly unlimited writes and does not lose data when power is off.
[0008] Furthermore, the basic identity data is written into a one-time programmable storage unit to complete the one-time physical solidification.
[0009] Furthermore, the basic identity data includes a preset identity identifier code, device serial number, and manufacturing timestamp.
[0010] Furthermore, the identity identifier is a 29-digit four-segment encoding structure, including a 2-digit country code, a 4-digit company name code, a 6-digit product model number, and a 17-digit serial number.
[0011] Furthermore, the full lifecycle status data includes at least one of usage records, maintenance logs, obsolescence status, and software upgrade records.
[0012] A secure storage system for device identity data based on dual-layer non-volatile storage includes: One-time fixed storage unit, non-volatile rewritable storage medium, hardware encryption module; All of the above modules are pure hardware integrated circuits, with no software processor involved in the entire process.
[0013] Furthermore, the root key used by the hardware encryption module is derived from the hardware fingerprint embedded in the one-time fixed storage unit.
[0014] A device equipped with a purely hardware storage system for implementing the above method. Beneficial effects
[0015] This application has the following beneficial effects: 1. It adopts a two-layer non-volatile storage architecture, which permanently stores basic identity data once and can be erased and rewritten multiple times to store full lifecycle status data, thus balancing the immutability of basic identity data and the updability of full lifecycle status data.
[0016] 2. All steps are completed by pure hardware circuits, with no software processor involved in storage and encryption operations, thus avoiding security risks caused by software vulnerabilities.
[0017] 3. Hardware encryption protection is used to protect the status data throughout the entire lifecycle using a root key generated inside the chip. The root key is only generated and used inside the chip and does not leave the chip, effectively preventing the data from being illegally decrypted.
[0018] 4. Basic identity data and full lifecycle status data are bound together by hardware encryption to ensure that the full lifecycle status data corresponds one-to-one with the basic identity data, making it difficult to forge or replace.
[0019] 5. Supports a variety of non-volatile, rewritable storage media, with good compatibility and applicability.
[0020] 6. Ferroelectric random access memory supports nearly unlimited write cycles and does not lose data when power is off, which can meet the storage needs of the entire device lifecycle. Detailed Implementation
[0021] The present application will now be described in detail with reference to specific embodiments.
[0022] This embodiment provides a method for securely storing device identity data based on dual-layer non-volatile storage, the specific steps of which are as follows: 1. The device's basic identification data (including a 29-bit four-segment identification code, device serial number, and manufacturing timestamp) is written into a one-time programmable storage unit, and then physically solidified using a physical fuse. Once solidified, the basic identification data cannot be modified during chip operation.
[0023] 2. Store the equipment's entire lifecycle status data (including usage records, maintenance logs, scrap status, and software upgrade records) into a ferroelectric random access memory (FRAM). FRAM supports virtually unlimited write cycles and is not lost even when power is off, meeting the storage needs throughout the equipment's entire lifecycle.
[0024] 3. The hardware encryption module uses a root key generated internally within the chip to provide hardware encryption protection for the entire lifecycle of state data. The root key is derived from a hardware fingerprint stored in a one-time fixed memory unit, and is generated and used only internally within the chip, never leaking out of the chip.
[0025] 4. The hardware encryption module binds basic identity data and full lifecycle status data using hardware encryption, generating a binding verification value. Each time the full lifecycle status data is read, the binding verification value is automatically verified to ensure the data has not been tampered with.
[0026] 5. All storage and encryption operations are performed by pure hardware circuitry, without the involvement of a software processor.
[0027] This embodiment also provides a secure storage system for device identity data based on dual-layer non-volatile storage, including a one-time fixed storage unit, a ferroelectric random access memory, and a hardware encryption module. All modules are implemented using pure hardware integrated circuits and connected via hardware wiring, with no software processor involved in the entire process.
Claims
1. A method for securely storing device identity data based on dual-layer non-volatile storage, characterized in that, Includes the following steps: The device's basic identity data is physically solidified once and cannot be modified during operation. Store the device's entire lifecycle status data in a non-volatile, rewritable storage medium. The full lifecycle state data is protected by hardware encryption using a root key generated inside the chip. The root key is only generated and used inside the chip and does not leave the chip. The basic identity data and the full lifecycle status data are bound together using hardware encryption. All of the above steps are completed by pure hardware circuits, with no software processor involved in storage and encryption operations.
2. The method according to claim 1, characterized in that, The non-volatile, rewritable storage medium is any one of ferroelectric random access memory, magnetoresistive random access memory, and resistive random access memory.
3. The method according to claim 2, characterized in that, The ferroelectric random access memory supports nearly unlimited writes and does not lose data when power is off.
4. The method according to claim 1, characterized in that, The basic identity data is written into a one-time programmable storage unit to complete the one-time physical solidification.
5. The method according to claim 1, characterized in that, The basic identity data includes a preset identity identifier code, device serial number, and manufacturing timestamp.
6. The method according to claim 5, characterized in that, The identity identifier is a 29-digit four-segment encoding structure, including a 2-digit country code, a 4-digit company name code, a 6-digit product model number, and a 17-digit serial number.
7. The method according to claim 1, characterized in that, The full lifecycle status data includes at least one of the following: usage records, maintenance logs, scrap status, and software upgrade records.
8. A secure storage system for device identity data based on dual-layer non-volatile storage, characterized in that, include: One-time fixed storage unit, non-volatile rewritable storage medium, hardware encryption module; All of the above modules are pure hardware integrated circuits, with no software processor involved in the entire process.
9. The system according to claim 8, characterized in that, The root key used by the hardware encryption module is derived from the hardware fingerprint embedded in the one-time fixed storage unit.
10. A device, characterized in that, A purely hardware storage system for implementing the method of any one of claims 1 to 9.