Circuit, encryption device and method supporting dynamic switching of active metrics and cryptographic services
By integrating measurement and cryptographic operation logic into a single processing core in a trusted computing platform, and by using control circuits and power management units to dynamically switch modes, the power consumption waste and bus conflict problems in traditional dual-module solutions are solved, thereby improving system energy efficiency and simplifying bus design.
Patent Information
- Application Number
- CN202611132279.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-07-29
- Publication Date
- 2026-08-25
AI Technical Summary
In traditional trusted computing platforms, the independent deployment of the active measurement module and the cryptographic service module leads to wasted power consumption and bus conflicts, reducing resource utilization efficiency.
The measurement and cryptographic operation logics are integrated into a single processing core. The control circuit dynamically switches modes according to the system state, and the power management unit implements power consumption management to ensure that measurement is executed first.
While ensuring reliable measurement, the system's energy efficiency has been improved, bus design has been simplified, and power consumption waste and bus conflicts have been reduced.
Smart Images

Figure CN122633014A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of trusted computing hardware technology, and in particular to a dynamic switching circuit, encryption device, and method that supports active measurement and cryptographic services. Background Technology
[0002] Trusted computing platforms, designed to establish a trust chain during startup and support cryptographic services during runtime, typically employ a hardware architecture where the Trusted Platform Control Module (TPCM) and Trusted Cryptographic Module (TCM) are deployed independently and physically embedded. The TPCM performs proactive integrity measurements on the firmware before the central processing unit (CPU) powers on, while the TCM handles subsequent commercial cryptographic operations. In this dual-module approach, the proactive measurement and cryptographic service functions are handled by two separate physical chips connected via a fixed board-level bus and continuously powered throughout the system's lifecycle. Because the proactive measurement and cryptographic service modules are independent and always online, idle modules continue to consume power and occupy the shared bus even during startup (when only measurement tasks are needed) or runtime (when only cryptographic services are required). This results in unnecessary energy consumption and bus access conflicts, reducing resource utilization efficiency. Summary of the Invention
[0003] This invention provides a circuit, encryption device, and method that supports dynamic switching between active measurement and cryptographic services to solve the problems of power consumption waste and bus conflicts caused by dual-module resident operation, while improving energy efficiency and simplifying bus design while ensuring that trusted measurement is executed first.
[0004] In a first aspect, embodiments of this application provide a dynamic switching circuit that supports active measurement and cryptographic services, including: The processing core integrates selectable measurement operation logic and cryptographic operation logic. The measurement operation logic is used to perform integrity measurement operations in active measurement mode, and the cryptographic operation logic is used to perform cryptographic operations in cryptographic service mode. A control circuit, connected to the processing core, is used to acquire state information representing the working stage of the system, and generate a mode selection signal according to a preset switching strategy to control the processing core to switch between the active measurement mode and the cryptographic service mode. An I / O router, connected to the processing core and the control circuit, is controlled by the mode selection signal to dynamically route external bus signals to the communication interface corresponding to the current working mode. A power management unit, connected to the processing core and the control circuit, is used to supply power to the processing core and the control circuit before the host computing unit in the power-on sequence, and to implement power consumption management for unused arithmetic logic in the processing core according to the current working mode. The control circuit, in response to the status information indicating the system startup phase, controls the processing core to enter the active measurement mode, and in response to the status information indicating the measurement completion, controls the processing core to switch to the cryptographic service mode.
[0005] In some embodiments, the control circuit includes: A status signal acquisition sub-circuit is used to acquire the status information representing the working stage of the system from the system bus. The status information includes system power-on timing signals, CPU startup stage identifiers, and trust measurement completion status flags. The mode determination logic sub-circuit is connected to the state signal acquisition sub-circuit and is used to perform logical combination and condition judgment on the state information according to the preset switching strategy to generate a mode switching indication signal. A mode selection signal generation sub-circuit, connected to the mode determination logic sub-circuit, is used to generate the mode selection signal according to the mode switching indication signal and output it to the processing core and the I / O router.
[0006] In some embodiments, the mode determination logic sub-circuit is configured as follows: When the status signal acquisition sub-circuit acquires a valid system power-on timing signal and a valid CPU startup phase identifier, it outputs a switching indication signal to enter the active measurement mode. When the trusted measurement completion status flag is valid and a password service request exists, a switching indication signal for entering password service mode is output.
[0007] In some embodiments, the control circuit further includes a security state isolation sub-circuit, which is connected to the mode determination logic sub-circuit. When the mode determination logic sub-circuit generates a mode switching indication signal, the security key register and key cache image inside the processing core are first saved to an isolated storage area independent of the host access domain, and the corresponding security context is restored from the isolated storage area after the mode switching is completed, so as to ensure the secure isolation of the operating states between the active measurement mode and the cryptographic service mode.
[0008] In some embodiments, the control circuit is further configured to perform a handshake and coordination with the host CPU; when the control circuit is ready to switch to the cryptographic service mode in response to the status information indicating that the measurement is completed, it first sends a measurement pass credential to the host CPU and waits for the host CPU to return a reset release signal. After confirming that the host CPU has been released from the reset, it controls the I / O router to switch the external bus path from the active measurement communication interface to the cryptographic service communication interface.
[0009] In some embodiments, the control circuit is further configured to: In the cryptographic service mode, the system periodically receives dynamic trusted measurement trigger commands from the host. In response to the dynamic trusted measurement trigger commands, the processing core is controlled to temporarily switch from the cryptographic service mode to the active measurement mode to perform measurement operations on the runtime components in the system memory, and automatically switches back to the cryptographic service mode after the measurement is completed.
[0010] In some embodiments, the processing core further includes anti-attack redundancy verification logic, which is configured as follows: In active measurement mode, different hash algorithms are used to perform two measurement operations on the same firmware code segment to be measured, and the two measurement results are cross-compared to resist transient fault injection attacks targeting a single measurement operation.
[0011] In some embodiments, the dynamic switching circuit supporting active measurement and cryptographic services is a single system-on-a-chip (SoC). The SoC's package integrates an active shielding layer that covers the physical layout area of the processing core, the control circuit, and the I / O router, and is electrically connected to the control circuit. This active shielding layer is used to send a forced reset signal to the control circuit to clear all security states inside the processing core when a physical probe intrusion is detected.
[0012] In some embodiments, the power management unit includes: a first power rail and a control sub-circuit connected to the first power rail; the control sub-circuit includes a first filter capacitor, a second filter capacitor, a first resistor, a second resistor, a third resistor, and a first field-effect transistor, a second field-effect transistor, and a third field-effect transistor; The first filter capacitor and the second filter capacitor are connected in parallel between the first power rail and ground, configured to filter out power supply noise from the first power rail. The gate of the first field-effect transistor is connected to the first power rail through the first resistor, the source is grounded, and the drain is connected to the TPCM in-situ detection signal terminal. It is configured to pull down the TPCM in-situ detection signal when the first power rail is powered on, so as to provide the control circuit with a power status indication during the system startup phase. The gate of the second field-effect transistor is connected to the TPCM measurement completion indication signal terminal, the drain is connected to the first power rail through the second resistor, and the source is grounded. It is configured to respond to the TPCM measurement completion indication signal to turn on ground when the measurement is completed, thereby feeding back the power ready confirmation signal corresponding to the measurement completion state to the control circuit. The gate of the third field-effect transistor is connected to the first power rail through the third resistor, the drain is connected to the QSPI channel switching input signal terminal, and the source is grounded. It is configured to pull down the QSPI channel switching input signal when the first power rail is powered on, so as to force the I / O router to be locked in the default off safe state in the initial stage of power-on.
[0013] Secondly, embodiments of this application provide an encryption device that performs authentication encryption based on a dynamic switching circuit supporting active measurement and cryptographic services as described in any one of the embodiments of this application.
[0014] Thirdly, embodiments of this application provide a method for supporting dynamic switching between active measurement and cryptographic services, executed by a processing core. The processing core is the processing core of the dynamic switching circuit supporting active measurement and cryptographic services as described in any one of the embodiments of this application, and the processing core is configured as follows: Receive the mode selection signal generated by the control circuit; When the mode selection signal indicates entry into active measurement mode, a first routing control signal is generated to control the I / O router to route the external bus signal to the active measurement communication interface, and the measurement operation logic is activated to perform integrity measurement operation on the target firmware. At the same time, a first power management signal is output to the power management unit to suppress the power consumption of the cryptographic operation logic. When the mode selection signal indicates entry into the cryptographic service mode, a second routing control signal is generated to control the I / O router to route the external bus signal to the cryptographic service communication interface, and to activate the cryptographic operation logic to perform cryptographic operations. At the same time, a second power management signal is output to the power management unit to suppress the power consumption of the measurement operation logic. The mode selection signal is generated by the control circuit based on the system power-on timing signal and the measurement completion status flag.
[0015] In some embodiments, activating the measurement operation logic to perform an integrity measurement operation on the target firmware includes: The target firmware is divided into multiple data blocks, and each data block is read sequentially. The SM3 hash algorithm is used to calculate the block hash value for each data block. Each block hash value is used as a leaf node, and the parent node hash value is calculated layer by layer according to the preset binary Merkle tree structure until the root hash value is generated. The root hash value is compared with the pre-stored reference root hash value. If they match, the measurement is considered successful; otherwise, the measurement is considered unsuccessful.
[0016] In some embodiments, the step of using each block hash value as a leaf node and calculating the parent node hash value layer by layer according to a preset binary Merkle tree structure until the root hash value is generated includes: When the number of nodes in the current layer to be calculated is even, the hash values of two adjacent nodes are concatenated and then the SM3 hash operation is performed to obtain the hash value of the parent node of the previous layer. When the number of nodes in the current layer to be calculated is odd, the hash value of the last node is copied to generate a matching node. The last node and the matching node are concatenated and then SM3 hash operation is performed to obtain the hash value of the parent node of the previous layer. Repeat the above layer-by-layer calculation process until only one target node remains, and use the target node as the root hash value; In this process, the SM3 hash operation at each layer is executed in a pipelined manner by the hardware hash accelerator in the metric operation logic.
[0017] The aforementioned scheme, comprising a dynamic switching circuit, encryption device, and method supporting active measurement and cryptographic services, includes: a processing core integrating selectable measurement and cryptographic operation logic, wherein the measurement logic performs integrity measurement operations in active measurement mode and the cryptographic operation logic performs cryptographic operations in cryptographic service mode; a control circuit connected to the processing core, used to acquire status information representing the system's operating phase and generate a mode selection signal according to a preset switching strategy, controlling the processing core to switch between active measurement mode and cryptographic service mode; an I / O router connected to the processing core and the control circuit, controlled by the mode selection signal to dynamically route external bus signals to the communication interface corresponding to the current operating mode; and a power management unit connected to the processing core and the control circuit, used to supply power to the processing core and the control circuit before the host computing unit in the power-on sequence, and to implement power consumption management for unused operation logic in the processing core according to the current operating mode; wherein the control circuit, in response to status information indicating the system startup phase, controls the processing core to enter active measurement mode, and in response to status information indicating measurement completion, controls the processing core to switch to cryptographic service mode. In the aforementioned circuit, the computational logic required for active measurement and cryptographic services is integrated into a single processing core at the physical layer. A control circuit is introduced to collect system power-on timing, measurement completion flags, and other operational status information, dynamically generating a mode selection signal. This signal synchronously acts on the processing core and the I / O router, enabling the processing core to switch between active measurement mode and cryptographic service mode as needed, and dynamically routing bus signals to the communication interface corresponding to the current mode. Finally, the power management unit powers on before the host to ensure priority execution of measurement, and manages the power consumption of unused computational logic in a single mode. Thus, the same processing core can time-division multiplex measurement and cryptographic functions, and bus paths are dynamically allocated according to the operating mode. This ensures that trusted measurement is initiated before the host, thereby improving system energy efficiency and simplifying bus access control design. Attached Figure Description
[0018] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the description of the embodiments of the present invention will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0019] Figure 1 This is a schematic block diagram of a dynamic switching circuit supporting active measurement and cryptographic services in one embodiment of the present invention; Figure 2 This is a schematic block diagram of the control circuit in one embodiment of the present invention; Figure 3 This is a circuit diagram of a power management unit in one embodiment of the present invention; Figure 4 This is a flowchart illustrating a method for supporting dynamic switching between proactive measurement and cryptographic services in one embodiment of the present invention; Figure 5 yes Figure 4 A schematic diagram of the implementation process of step S20; Figure 6 yes Figure 5 A schematic diagram of the implementation process of step S22. Detailed Implementation
[0020] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0021] It should be understood that, when used in this specification and the appended claims, the term "comprising" indicates the presence of the described features, integrals, steps, operations, elements, and / or components, but does not exclude the presence or addition of one or more other features, integrals, steps, operations, elements, components, and / or collections thereof. It should also be understood that, as used in this specification and the appended claims, the term "and / or" refers to any combination of one or more of the associated listed items and all possible combinations, and includes such combinations.
[0022] Furthermore, in the description of this invention and the appended claims, the terms "first," "second," "third," etc., are used only to distinguish descriptions and should not be construed as indicating or implying relative importance.
[0023] References to "one embodiment" or "some embodiments" as described in this specification mean that one or more embodiments of the invention include a specific feature, structure, or characteristic described in connection with that embodiment. Therefore, the phrases "in one embodiment," "in some embodiments," "in other embodiments," "in still other embodiments," etc., appearing in different parts of this specification do not necessarily refer to the same embodiment, but rather mean "one or more, but not all, embodiments," unless otherwise specifically emphasized. The terms "comprising," "including," "having," and variations thereof mean "including but not limited to," unless otherwise specifically emphasized.
[0024] It should be understood that the sequence number of each step in the following embodiments does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.
[0025] To illustrate the technical solution of the present invention, specific embodiments are described below.
[0026] In this embodiment of the invention, during the startup phase, the Trusted Platform Control Module (TPCM) performs active integrity measurement on the firmware to establish a trust chain; during the runtime phase, the Trusted Cryptographic Module (TCM) provides commercial cryptographic services (such as encryption / decryption, signature verification, etc.). Traditional solutions deploy the TPCM and TCM as two independent physical chips, both connected to the host via a board-level bus and continuously powered throughout the system's operating cycle. This dual-module resident solution has the following technical problems: First, during the startup phase, only the measurement module operates while the cryptographic module is idle; during the runtime phase, only the cryptographic module operates while the measurement module is idle. The idle module constantly consumes static and dynamic power, resulting in a reduction in overall system energy efficiency, especially significantly impacting power-sensitive embedded devices; Second, both modules are connected to a shared bus (such as SPI, I...). 2 (C, etc.) If both modules access the bus simultaneously, arbitration conflicts are likely to occur, requiring additional bus arbitration logic and increasing design complexity. Thirdly, each module has its own independent secure storage and key resources, increasing chip area and cost. Therefore, there is an urgent need for a hardware solution that can ensure the priority execution of trusted metrics while eliminating redundant power consumption and bus conflicts.
[0027] To address the aforementioned issues, this application proposes a dynamic switching circuit, encryption device, and method supporting active measurement and cryptographic services. This circuit integrates measurement and cryptographic operation logic into a single processing core. A control circuit dynamically generates a mode selection signal based on the system's operating phase (startup or running phase), enabling the processing core to switch between active measurement and cryptographic service modes in a time-sharing manner. Simultaneously, an I / O router routes external bus signals to the communication interface corresponding to the current mode. The power management unit powers on before the host to ensure measurement priority execution and performs clock-gated or power-gated power consumption management on unused operational logic in a single mode. This solution eliminates the power waste caused by dual-module resident operation at the physical level, avoids bus access conflicts, simplifies board-level wiring, and improves system energy efficiency and integration.
[0028] like Figure 1 As shown, an embodiment of the present invention provides a dynamic switching circuit that supports active measurement and cryptographic services, including: a processing core 100, a control circuit 200, an I / O route selector 300, and a power management unit 400.
[0029] The processing core 100 integrates selectable measurement operation logic and cryptographic operation logic. The measurement operation logic is used to perform integrity measurement operations in active measurement mode, and the cryptographic operation logic is used to perform cryptographic operations in cryptographic service mode. The measurement operation logic 110 and the cryptographic operation logic 120 share the arithmetic logic unit (ALU) and register file, but have independent control paths and operation schedulers.
[0030] The control circuit 200 is connected to the processing core 100 and is used to acquire status information representing the system's working stage. It also generates a mode selection signal according to a preset switching strategy, controlling the processing core 100 to switch between active measurement mode and cryptographic service mode. The control circuit 200 is connected to the processing core 100, the I / O router 300, and the power management unit 400.
[0031] I / O router 300 is connected to processing core 100 and control circuit 200, and is used to dynamically route external bus signals to the communication interface corresponding to the current operating mode, controlled by a mode selection signal. I / O router 300 has an external bus input port (such as SPI, QSPI or LPC bus), and output ports (such as measurement-dedicated interface and cryptographic service interface) corresponding to active measurement mode and cryptographic service mode, respectively.
[0032] The power management unit 400 is connected to the processing core 100 and the control circuit 200. It powers on the processing core 100 and control circuit 200 before the host computing unit in the power-on sequence, and manages the power consumption of unused computational logic in the processing core 100 according to the current operating mode. The input of the power management unit 400 is connected to the system main power supply, and its output provides the processing core 100 and control circuit 200 with an early power rail independent of the host CPU.
[0033] In response to the status information indicating the system startup phase, the control circuit 200 controls the processing core 100 to enter the active measurement mode, and in response to the status information indicating the measurement is completed, the control processing core 100 switches to the password service mode.
[0034] For example, the dynamic switching circuit operates as follows after the system is powered on: When the main power supply is turned on, the power management unit 400, due to its early power rail design independent of the host CPU, establishes a stable power supply before the host computing components in terms of timing, and first provides operating voltage to the processing core 100 and the control circuit 200. At this time, after receiving power, the control circuit 200 enters the ready-to-work state, and its internal logic begins to collect state information representing the current system working stage from the system bus or dedicated signal lines—in the initial power-on stage, the system power-on timing signal is valid and the CPU is still in the reset state, and this combination of states is identified by the control circuit 200 as the "system startup stage". Accordingly, the control circuit 200 generates a corresponding mode selection signal according to the preset switching strategy, and outputs the signal simultaneously to the mode control terminal of the processing core 100 and the gating control terminal of the I / O router 300. Upon receiving a mode selection signal indicating active measurement mode, the processing core 100 activates its internal measurement operation logic (including a hash engine, measurement control state machine, and measurement result register). Simultaneously, it temporarily disables the cryptographic operation logic's operation path through internal clock gating or power gating, ensuring that the processing core 100's computing resources are entirely focused on the integrity measurement task during startup. Meanwhile, under the control of the same mode selection signal, the I / O router 300 dynamically routes its external bus input port (such as the QSPI bus) to the dedicated measurement output interface corresponding to the active measurement mode, thereby establishing a dedicated data path from the external firmware storage device to the processing core 100's measurement operation logic, ensuring that the firmware code segments required for measurement operations can be correctly read. After the measurement operation logic is activated, the processing core 100 sequentially reads the firmware code segments to be measured from the external bus, performs hash operations, and stores the measurement results in internal registers. After measurement completion, the processing core 100 feeds back a measurement completion status flag to the control circuit 200. After acquiring the measurement completion status information, the control circuit 200 determines that the active measurement task in the system startup phase has ended. Then, according to the preset switching strategy, it updates the mode selection signal, controls the processing core 100 to turn off the clock and power of the measurement operation logic, activates the cryptographic operation logic (including the encryption / decryption engine, key scheduler, and cryptographic operation control state machine), and controls the I / O router 300 to switch the external bus input port from the measurement-dedicated interface to the cryptographic service interface. This allows subsequent cryptographic operation requests (such as encryption, decryption, signing, and verification) issued by the host to be correctly routed to the cryptographic operation logic of the processing core 100 through this interface.Throughout the operation, the power management unit 400 continuously monitors the current operating mode. In active measurement mode, it maintains normal power supply and clock for the measurement operation logic in the processing core 100, while suppressing power consumption for the cryptographic operation logic (e.g., shutting down its power domain or stopping clock toggling). In cryptographic service mode, the opposite is true: it maintains power supply and clock for the cryptographic operation logic, while suppressing power consumption for the measurement operation logic.
[0035] By controlling the system startup phase and measurement completion status information in real time and making logical judgments through the control circuit 200, the timing of mode switching is not dependent on software polling or external intervention, but is completed autonomously by the hardware logic. This eliminates the switching lag that may be introduced by software response delays and ensures that the measurement operation is executed first before the host CPU is released and reset. The architecture of the measurement operation logic and the cryptographic operation logic sharing the ALU and register file but having independent control paths and operation schedulers in the processing core 100 allows the two operation logics to independently complete context initialization and resource release during mode switching, even though they are physically integrated in the same core. This avoids register state conflicts between different operation types and also allows the same set of arithmetic logic units to be time-division multiplexed in different modes, thereby reducing chip area. The I / O router 300 is controlled by the same mode selection signal and keeps synchronized with the mode switching of the processing core 100. This allows the external bus signal to be hard-switched at the physical layer to the communication interface that matches the current working mode. This eliminates the mixed transmission of measurement data and cryptographic data on the bus from the signal path and eliminates the data crosstalk and protocol conflicts that may occur when dual functions share the same interface. The power management unit 400 is powered on before the host in terms of timing, enabling the control circuit 200 to complete the initial mode determination and bus path security lock before the host CPU receives the clock and reset release. This physically ensures the basic principle of "measurement first, startup later" for reliable computing. Furthermore, it implements power management (including clock gating and power gating) on unused computational logic in the processing core 100 according to the current operating mode. This ensures that only the currently needed computational logic is effectively powered and clocked in any mode. Unused computational logic generates neither dynamic switching power nor static leakage power. Compared to a dual-module always-on resident solution, this circuit eliminates unnecessary energy consumption from idle computational resources throughout the entire operating cycle. Its power savings are directly equivalent to the sum of all static and dynamic power consumption of the shut-down portion under the same process and voltage conditions. The technical effects of each of these aspects are independent yet cumulative, collectively constituting the overall advantage of this dynamic switching circuit in improving energy efficiency and simplifying bus design while ensuring the priority execution of reliable measurements.
[0036] The aforementioned scheme, comprising a dynamic switching circuit, encryption device, and method supporting active measurement and cryptographic services, includes: a processing core integrating selectable measurement and cryptographic operation logic, wherein the measurement logic performs integrity measurement operations in active measurement mode and the cryptographic operation logic performs cryptographic operations in cryptographic service mode; a control circuit connected to the processing core, used to acquire status information representing the system's operating phase and generate a mode selection signal according to a preset switching strategy, controlling the processing core to switch between active measurement mode and cryptographic service mode; an I / O router connected to the processing core and the control circuit, controlled by the mode selection signal to dynamically route external bus signals to the communication interface corresponding to the current operating mode; and a power management unit connected to the processing core and the control circuit, used to supply power to the processing core and the control circuit before the host computing unit in the power-on sequence, and to implement power consumption management for unused operation logic in the processing core according to the current operating mode; wherein the control circuit, in response to status information indicating the system startup phase, controls the processing core to enter active measurement mode, and in response to status information indicating measurement completion, controls the processing core to switch to cryptographic service mode. In the aforementioned circuit, the computational logic required for active measurement and cryptographic services is integrated into a single processing core at the physical layer. A control circuit is introduced to collect system power-on timing, measurement completion flags, and other operational status information, dynamically generating a mode selection signal. This signal synchronously acts on the processing core and the I / O router, enabling the processing core to switch between active measurement mode and cryptographic service mode as needed, and dynamically routing bus signals to the communication interface corresponding to the current mode. Finally, the power management unit powers on before the host to ensure priority execution of measurement, and manages the power consumption of unused computational logic in a single mode. Thus, the same processing core can time-division multiplex measurement and cryptographic functions, and bus paths are dynamically allocated according to the operating mode. This ensures that trusted measurement is initiated before the host, thereby improving system energy efficiency and simplifying bus access control design.
[0037] In one embodiment, such as Figure 2As shown, the control circuit 200 includes a status signal acquisition subcircuit 210, a mode determination logic subcircuit 220, and a mode selection signal generation subcircuit 230. The status signal acquisition subcircuit 210 acquires status information representing the system's operating phase via a system bus (such as LPC or SMBus) or dedicated pins. This status information includes at least system power-on timing signals (e.g., PWR_GOOD), CPU startup phase identifiers (e.g., CPU_RESET#, active low indicating CPU is in reset state), and a confidence measurement completion status flag (e.g., MEASURE_DONE, output by the processing core after measurement completion). The mode determination logic subcircuit 220 receives the aforementioned status information and performs logical combinations and conditional judgments according to a preset switching strategy. Specifically, when the system power-on timing signal is valid and the CPU startup phase flag is valid (e.g., CPU_RESET# is low), the system is determined to be in the startup phase, and a switching indication signal to enter the active measurement mode is output. When the trusted measurement completion status flag is valid (e.g., MEASURE_DONE is high) and there is a cryptographic service request (e.g., the host issues a request via an interrupt or command register), the measurement is determined to be complete and cryptographic service is required, and a switching indication signal to enter the cryptographic service mode is output. The mode selection signal generation sub-circuit 230 generates a mode selection signal with sufficient driving capability based on this switching indication signal (e.g., high level corresponds to active measurement mode, low level corresponds to cryptographic service mode), and simultaneously outputs it to the mode control terminal of the processing core 100 and the gating control terminal of the I / O route selector 300. Through the above configuration, the circuit can automatically and smoothly switch to the cryptographic service mode after the trusted measurement is completed, according to the needs of the system startup and operation phases, without external intervention.
[0038] Furthermore, in the above embodiment, the control circuit 200 also includes a security state isolation sub-circuit 240. This security state isolation sub-circuit 240 is connected to the mode determination logic sub-circuit 220. When the mode determination logic sub-circuit 220 generates a mode switching indication signal (whether switching from metric mode to cryptographic mode or vice versa), the security state isolation sub-circuit 240 first suspends the pipeline of the processing core 100 and saves the data in the security-critical registers (such as the metric base value register and the key scheduling status register) and key caches (such as the SM2 private key temporary cache) within the processing core 100 to an isolated storage area independent of the host access domain (e.g., a secure partition in the on-chip SRAM, which is only accessible to the security state isolation sub-circuit 240). Only after the saving is complete does the security state isolation sub-circuit 240 allow mode switching to execute. After the mode switching is complete and the initial configuration of the new mode is ready, the security state isolation sub-circuit 240 restores the corresponding security context (e.g., restores the metric base or key state) from the isolated storage area. This isolation mechanism ensures that sensitive measurement parameters in the active measurement mode and key materials in the cryptographic service mode will not be leaked to each other due to mode switching, thus ensuring the secure isolation of the operating states between the two modes and effectively preventing cross-mode information leakage attacks.
[0039] In another embodiment, the control circuit 200 is also used to perform a handshake and coordination with the host CPU. Specifically, when the control circuit 200 responds to a status message indicating that the measurement is complete and is ready to switch to the cryptographic service mode, it does not immediately perform the switch. Instead, it first sends a measurement pass credential (containing a hash signature of the measurement result) to the host CPU through a secure channel (e.g., a dedicated GPIO interrupt line or a status word in shared memory). Simultaneously, the control circuit 200 waits for the host CPU to return a reset release signal (e.g., CPU_RELEASE#, indicating that the host CPU has completed internal initialization and is ready to receive the cryptographic service). Only after confirming that the reset release signal is valid does the control circuit 200 finally control the I / O router 300 to switch the external bus path from the active measurement communication interface (which is isolated from the host CPU's SPI Flash controller in measurement mode) to the cryptographic service communication interface (which interfaces with the host CPU's cryptographic coprocessor in cryptographic service mode). This handshake ensures that the host CPU cannot access any external storage or start malicious firmware before the measurement is completed, and the cryptographic service path can only be opened after the measurement is passed and the CPU is ready, thus strictly following the trust chain transmission principle of "measure first, then execute" in trusted computing.
[0040] In another embodiment, the control circuit 200 is also configured to support runtime Dynamic Trusted Measurement (DRTM). In cryptographic service mode, the control circuit 200 periodically receives a DRTM trigger command from the host (this command can be issued via the APB bus or a custom command register). In response to this trigger command, the control circuit 200 temporarily suspends the current cryptographic service task, saves the intermediate state of the cryptographic operation (again using the security state isolation sub-circuit 240), and then controls the processing core 100 to temporarily switch from cryptographic service mode to active measurement mode. In active measurement mode, the processing core 100 performs hash measurement operations on runtime components in system memory (such as dynamically loaded kernel modules and process code segments) and extends the measurement results to the Platform Configuration Register (PCR). After the measurement is completed, the control circuit 200 automatically controls the processing core 100 to switch back to cryptographic service mode and restore the previously saved cryptographic operation state to continue responding to subsequent cryptographic service requests. This dynamic switching process is transparent to the host, and the switching time is controlled within microseconds, without affecting the continuity of real-time cryptographic services. With this function, this circuit not only supports static startup metrics, but also dynamic trusted verification during runtime, meeting the needs of high-security systems for continuous security monitoring.
[0041] To further enhance resistance to physical attacks, the processing core 100 incorporates anti-attack redundancy verification logic. This logic is configured to perform two independent measurement operations on the same firmware code segment to be measured in active measurement mode, using two different hash algorithm rounds (e.g., the first round uses the SM3 algorithm, the second round uses the SHA-256 algorithm, or the same SM3 algorithm but with different initialization vectors and message padding methods). The two operations are executed independently in parallel or time-sharing, and the results are cross-checked. If they match, the measurement result is output; otherwise, the measurement fails and a security alarm is triggered. This redundancy verification mechanism effectively resists transient fault injection attacks targeting single measurement operations (such as clock glitches or power supply noise-induced errors). Attackers attempting to bypass the measurement must simultaneously interfere with both independent computation paths, significantly increasing the difficulty of the attack.
[0042] In a preferred embodiment, the aforementioned dynamic switching circuit supporting active measurement and cryptographic services is integrated into a single System-on-Chip (SoC) chip. The SoC chip's package integrates an active shielding layer, which uses a metal mesh trace to cover the physical layout area of the processing core 100, control circuitry 200, and I / O router 300. The active shielding layer is electrically connected to the control circuitry 200 and continuously monitors electrical parameters (such as impedance and voltage level) on the shielding layer. When physical probe intrusion is detected (e.g., the metal mesh is cut or short-circuited), the active shielding layer immediately sends an interrupt signal to the control circuitry 200. The control circuitry 200 then generates a forced reset signal, clearing all registers, SRAM, and key cache within the processing core 100, completely erasing all security states, and locking the chip's functionality until the next power-on reset. This active shielding layer effectively prevents attackers from directly stealing sensitive data inside the chip using focused ion beam (FIB) or microprobes.
[0043] Regarding the specific implementation of the power management unit, as follows: Figure 3 As shown, in one embodiment, the power management unit 400 includes a first supply voltage VCC and a control sub-circuit connected to the first supply voltage. The control sub-circuit specifically includes filter capacitors C1246 and C1247, resistors R1376, R1380, and R1378, and a first field-effect transistor Q5, a second field-effect transistor Q6, and a third field-effect transistor Q7 (all three are N-channel enhancement-type MOSFETs in this embodiment). Filter capacitors C1246 and C1247 are connected in parallel between the first supply voltage VCC and ground to effectively filter high-frequency noise on the power line, providing a stable and clean power supply for the processing core and control circuit, and preventing power ripple from affecting the timing stability of sensitive logic.
[0044] The gate of the first field-effect transistor Q5 is connected to the first supply voltage VCC through resistor R1376, the source is grounded, and the drain is connected to the TPCM_PRSNT_N signal terminal (this signal is active low and is used to indicate to the host or control circuit that the TPCM module is powered on and ready). When VCC is powered on, the gate of Q5 is pulled high by R1376, Q5 turns on, and its drain is pulled low, thereby pulling the TPCM_PRSNT_N signal low. This provides the control circuit with a power status indication during the system startup phase, indicating that the processing core has received power before the host CPU, satisfying the timing requirement of prioritizing the execution of reliability metrics.
[0045] The gate of the second MOSFET Q6 is connected to the TPCM_Measure_GPIO5_OK_N signal (this signal indicates measurement completion and is active low), and its drain is connected to the first supply voltage VCC through resistor R1380, while its source is grounded. When active measurement is complete, the processing core pulls the TPCM_Measure_GPIO5_OK_N signal low, turning on the gate of Q6 and pulling its drain low. This low-level signal at the drain node is fed back to the control circuit as a power-ready confirmation signal (e.g., PWR_READY) to confirm that the measurement has been completed and the state is stable. Based on this, the control circuit knows that it can safely perform subsequent mode switching operations.
[0046] The gate of the third field-effect transistor Q7 is connected to the first supply voltage VCC through resistor R1378, the drain is connected to the QSPI_SW_IN signal (used to control the switching of QSPI bus channels), and the source is grounded. When VCC is powered on, the gate of Q7 is pulled high by R1378, Q7 turns on, and its drain is pulled low, thus keeping the QSPI_SW_IN signal low during the initial power-on phase. This low level forces the I / O router to be locked in the default off safe state, that is, all external bus paths (especially the QSPI Flash access channel) are disconnected, effectively preventing the host from accessing external storage or executing untrusted code before the measurement is completed. After the control circuit confirms that the measurement has passed, the control circuit pulls the signal high through other outputs, releasing QSPI_SW_IN and allowing the I / O router to perform subsequent channel switching according to the mode selection signal.
[0047] In one specific embodiment, combined with Figure 1 and Figure 3For example, this dynamic switching circuit operates according to the timing logic of "priority measurement - conditional switching - time-sharing service - dynamic back-switch" throughout the complete working cycle after the system is powered on. Initially, when the main power supply of the system is turned on, the power management unit 400, due to its early power rail design independent of the host CPU, establishes the first power supply voltage VCC before the host computing components and provides stable power to the processing core 100 and the control circuit 200. At the same time, the first field-effect transistor Q5 inside the power management unit 400 turns on in response to the power-on of VCC, pulls the TPCM_PRSNT_N signal low, and sends a power status indication to the control circuit 200. The third field-effect transistor Q7 turns on synchronously, forcibly pulling the QSPI_SW_IN signal low, so that all external bus paths of the I / O router 300 are locked in the off safe state by default, preventing the host CPU from accessing any external storage or boot code before the measurement is completed. Upon receiving the power status indication, the control circuit 200's status signal acquisition sub-circuit 210 immediately acquires status information representing the system's operating stage from the system bus, including the system power-on timing signal PWR_GOOD being valid and CPU_RESET# being low (indicating the CPU is in a reset state). Based on this, the mode determination logic sub-circuit 220 determines that the system is currently in the startup stage and outputs a switching indication signal to enter the active measurement mode. The mode selection signal generation sub-circuit 230 converts this indication into a high-level mode selection signal and outputs it to the mode control terminal of the processing core 100 and the gating control terminal of the I / O router 300. After receiving this signal, the processing core 100 activates its internal measurement operation logic (including the SM3 hash engine, measurement reference value register group, and PCR extension logic) and disables the clock and power supply of the cryptographic operation logic, entering the active measurement mode. The I / O router 300 then routes the external bus input port (such as the QSPI bus) to the dedicated measurement interface according to the same mode selection signal, enabling the processing core 100 to read the firmware code segment in the SPI Flash and perform integrity measurement operations. During the measurement process, the anti-attack redundancy verification logic inside the processing core 100 performs two measurement operations on the same firmware code segment to be measured using two independent hash algorithms in two rounds, and cross-compares the two results. If the comparison is consistent, the measurement pass certificate (i.e., the hash value signature of the measurement result) is output. At the same time, the TPCM_Measure_GPIO5_OK_N signal is pulled low, and the second field-effect transistor Q6 is turned on to generate a power-ready confirmation signal, which is fed back to the control circuit 200.After receiving the confirmation signal, the control circuit 200 does not switch immediately. Instead, it first sends a measurement pass certificate to the host CPU through a handshake coordination mechanism and waits for the host CPU to return a reset release signal CPU_RELEASE#. After confirming that the signal is valid, the control circuit 200 starts the switching process: the security state isolation sub-circuit 240 first suspends the pipeline of the processing core 100 and mirrors and saves the security-critical registers (such as measurement baseline value and PCR value) used in the measurement mode to the isolation storage area. Then, the mode determination logic sub-circuit 220 outputs a switching indication signal to enter the password service mode based on the conditions that the trusted measurement completion status flag is valid and the password service request exists (such as the host issuing a request through the command register). The mode selection signal generation sub-circuit 230 flips the mode selection signal to a low level. Upon receiving a low-level signal, the processing core 100 shuts down the power supply and clock of the measurement operation logic, activates the cryptographic operation logic (including the SM2 / SM4 engine, key cache, and encryption / decryption scheduler), and restores the previously saved cryptographic context. The I / O router 300 synchronously switches the external bus path from the dedicated measurement interface to the cryptographic service interface, ensuring that subsequent cryptographic operation requests from the host CPU are correctly routed to the cryptographic operation logic of the processing core 100. At this point, the system completes a smooth switch from active measurement to cryptographic service, entering the service mode of the runtime phase. In cryptographic service mode, the control circuit 200 also periodically listens for dynamic trusted measurement trigger commands from the host. Upon receiving such a command, it suspends the current cryptographic task, saves the intermediate state of the cryptographic operation (such as the SM2 temporary key and the SM4 round key) to an isolated storage area, temporarily switches to active measurement mode to perform measurement operations on the runtime components in the system memory, and automatically switches back to cryptographic service mode after the measurement is completed, restoring the previously saved cryptographic state, thereby achieving dynamic trusted verification during runtime.
[0048] The aforementioned power management circuit not only strictly implements the timing control of powering on before the host, ensuring that active measurement is completed before the host starts, but also provides a channel default locking function in the initial stage of power-on through a simple combination of discrete components, avoiding bus signal competition and potential safety risks at the moment of power-on. At the same time, it provides reliable power status feedback for subsequent dynamic switching, enhancing the overall safety startup determinism of the system.
[0049] This invention also provides an encryption device that performs authentication encryption based on the dynamic switching circuit supporting active measurement and cryptographic services described in any of the above embodiments. For example, the encryption device can be a trusted computing cryptographic card, an embedded security module (ESM), or an IoT gateway with trusted boot functionality. In this device, the aforementioned dynamic switching circuit serves as the core security engine. Upon power-up, it first actively measures the integrity of the device firmware. After successful measurement, it switches to cryptographic service mode, providing accelerated computation of national cryptographic algorithms such as SM2 / SM3 / SM4 for the device host. Since this device requires only a single processing core to achieve both measurement and cryptographic functions, its power consumption is reduced by approximately 40% to 60% compared to a dual-chip solution while maintaining the same security capabilities. Furthermore, it saves more than half of the board space, making it particularly suitable for scenarios with limited size and power consumption, such as industrial control and edge computing.
[0050] It should be understood that the specific values, signal names, and circuit connection methods in the above embodiments are merely illustrative examples and do not constitute a limitation of the present invention. Those skilled in the art can adjust the capacitance value of the filter capacitor, the resistance value, or use other types of switching devices (such as PMOS or transistors) to achieve equivalent functions according to actual design requirements; all of these fall within the protection scope of the present invention.
[0051] This invention also provides a method for supporting dynamic switching between proactive measurement and cryptographic services, such as... Figure 4 As shown, the specific steps of this method for supporting active measurement and dynamic switching of cryptographic services include: S10-S30.
[0052] S10, Receive the mode selection signal generated by the control circuit.
[0053] For example, the processing core interacts with the control circuit via an internal interconnect bus, receiving a mode selection signal generated by the control circuit. This mode selection signal is a digital control signal generated by the control circuit based on the system power-on timing signal and the measurement completion status flag, after logical combination and conditional judgment. Its signal state can be directly mapped to an enable indication for either active measurement mode or cryptographic service mode. The processing core internally has a mode configuration register, which is mapped to the processing core's control path. The signal state is latched into the corresponding bit field of the register on the clock edge of receiving the mode selection signal. The mode selection signal can be represented by a single-bit signal, for example, a high level corresponding to active measurement mode and a low level corresponding to cryptographic service mode. Alternatively, it can use multi-bit encoding to carry additional control information for mode switching, such as switching priority and switching protection window duration.
[0054] Taking the TPCM metric priority scenario as an example, after the system is powered on, the control circuit detects that the power-on timing signal and the CPU startup stage identifier are both valid, and generates a mode selection signal indicating the active metric mode. The processing core receives this signal through the internal bus and latches it into the mode configuration register, providing a decision basis for the mode configuration of subsequent steps.
[0055] The processing core receives the mode selection signal directly through hardware registers, eliminating the need for software interrupts or instruction parsing to obtain the switching instruction. This limits the response latency of mode switching to the hardware signal setup time and register latch latency, typically keeping it within a few clock cycles. This ensures the real-time and deterministic nature of mode switching when the system's operating phase changes, avoiding uncontrollable delays and security risks that may be introduced by software involvement.
[0056] S20. When the mode selection signal indicates that the active measurement mode has been entered, a first routing control signal is generated to control the I / O router to route the external bus signal to the active measurement communication interface, and the measurement operation logic is activated to perform integrity measurement operation on the target firmware. At the same time, a first power management signal is output to the power management unit to suppress the power consumption of the cryptographic operation logic.
[0057] For example, when the mode selection signal of the processing core latch indicates the active measurement mode, the control state machine inside the processing core generates a series of internal control signals based on the status bits in the mode configuration register. The first routing control signal is generated by the input / output control submodule of the processing core and output to the selection control port of the I / O router to control the switch matrix or multiplexer network inside the I / O router to switch the external bus signal path from the default disconnected state to the active measurement communication interface. This active measurement communication interface is connected to the storage device of the target firmware being measured, such as an SPI flash memory chip storing BIOS firmware. At the same time, the measurement operation logic inside the processing core is activated by an enable signal. The hash operation unit in the measurement operation logic begins to read the target firmware code segment from the active measurement communication interface, calculates its hash value, compares the calculation result with the reference hash value pre-stored in the on-chip non-volatile memory, and outputs the measurement result. During this process, the processing core outputs a first power management signal to the power management unit, which indicates that it is currently in active measurement mode. The power management unit uses this signal to gate the clock input of the cryptographic operation logic or to switch the power supply voltage of the power domain where the cryptographic operation logic is located to a hold state.
[0058] Taking the initial measurement process after the system is powered on as an example, after the processing core receives the active measurement mode instruction, it generates the first routing control signal to control the I / O route selector to connect the SPI bus path to the flash memory chip storing the BIOS firmware. The measurement operation logic sequentially reads each data block of the BIOS firmware through the SPI bus and performs SM3 hash operation to generate a measurement digest and compare it with the pre-stored benchmark value. At the same time, the cryptographic operation logic is clock-gated, and its dynamic power consumption is reduced to a level close to zero.
[0059] Within the same control cycle after receiving the mode selection signal, the processing core generates routing control signals, metric operation activation signals, and power management signals in parallel, achieving timing synchronization of three operations: bus path allocation, computational resource scheduling, and power status management. This parallel control mechanism ensures that the startup delay from mode confirmation to the start of metric execution is limited only by the propagation delay of the combinational logic path, eliminating the need for multiple bus accesses or software configuration processes. Simultaneously, by implementing power suppression on the cryptographic operation logic instead of complete power shutdown, the wake-up delay of the cryptographic operation engine during mode switching is kept within nanoseconds, balancing power efficiency and switching response speed.
[0060] S30. When the mode selection signal indicates entry into the cryptographic service mode, a second routing control signal is generated to control the I / O router to route the external bus signal to the cryptographic service communication interface and activate the cryptographic operation logic to perform cryptographic operations. At the same time, a second power management signal is output to the power management unit to suppress power consumption of the measurement operation logic. The mode selection signal is generated by the control circuit based on the system power-on timing signal and the measurement completion status flag.
[0061] For example, after the active measurement phase is completed and the measurement result is passed, the measurement operation logic sets the measurement completion status flag. Upon detecting the validity of this flag, the control circuit, after a preset switching debouncing delay, switches the mode selection signal to indicate the cryptographic service mode. After receiving this mode selection signal, the processing core's internal state machine transitions from the measurement state to the cryptographic service state, generating a second routing control signal to control the I / O router to switch the external bus signal path to the cryptographic service communication interface. This interface is connected to the host CPU's bus interface, enabling the host to access the processing core's cryptographic service functions via standard bus protocols. Once activated, the cryptographic operation logic performs corresponding cryptographic operations based on the cryptographic service request issued by the host, including SM2 elliptic curve signature and verification operations, SM4 block encryption / decryption operations, and SM3 hash operations. The operation results are returned to the host through the cryptographic service communication interface. In this mode, the processing core outputs a second power management signal to the power management unit, implementing clock gating on the hash operation unit and comparison unit in the measurement operation logic, while maintaining power supply to the measurement control status register to preserve the storage of measurement results and configuration information.
[0062] Taking the cryptographic service operation phase as an example, the measurement switches to the cryptographic service mode through the post-processing core. The I / O router disconnects the SPI bus path from the flash chip side and connects it to the host CPU. The host sends an SM4 decryption request through the SPI bus. The SM4 hardware engine in the cryptographic operation logic reads the ciphertext and key, performs the decryption operation, and returns the plaintext to the host. During this period, the measurement operation logic is in the clock off state, and its static power consumption is only the leakage current power consumption.
[0063] The core processing unit performs mode switching based on the precondition of measurement completion, ensuring that the enabling of the cryptographic service mode strictly depends on the measurement pass signal. This guarantees the unidirectional transmission of the trust chain from the measurement phase to the operation phase at the hardware level, preventing the cryptographic service function from being enabled without measurement passing. Simultaneously, the power management unit suppresses power consumption while retaining state storage for the measurement operation logic. This allows the measurement operation logic to be quickly woken up and its context restored when dynamic measurement is needed, supporting efficient switching back from the cryptographic service mode to the active measurement mode.
[0064] In one embodiment, such as Figure 5 As shown, in step S20, when the mode selection signal indicates that the active measurement mode is entered, the measurement operation logic is activated to perform integrity measurement operation on the target firmware, specifically including the following steps: S21-S22.
[0065] S21: Divide the target firmware into multiple data blocks and read each data block sequentially. Calculate the block hash value for each data block using the SM3 hash algorithm.
[0066] For example, this step involves block reading and block-by-block hashing of the target firmware. The Direct Memory Access Controller (DMI) within the processing core sequentially reads the binary code of the target firmware from the firmware storage device via an active metric communication interface. During the reading process, the firmware data is divided into multiple data blocks of a preset fixed length. This fixed length can be set according to the input buffer capacity of the hardware hash accelerator in the metric operation logic; for example, the entire BIOS firmware image can be divided into several data blocks with a granularity of 1024 bytes or 4096 bytes. After each data block is read into the input buffer of the metric operation logic, the hardware hash accelerator initiates an SM3 hash operation. Using all bytes of the data block as input messages, after three stages of hardware pipelined processing—message filling, message expansion, and iterative compression—a 256-bit block hash value is output and stored in the block hash value temporary storage area within the metric operation logic. This temporary storage area can be implemented using a register file or static random access memory, storing the hash values of each block according to its data block number index.
[0067] Taking the BIOS firmware measurement scenario as an example, the target firmware is a UEFI BIOS image stored in SPI flash memory, with a size of 16MB. The processing core divides the 16MB firmware into 4096 data blocks of 4096 bytes each. Each data block is read sequentially through the SPI bus. The SM3 hardware engine in the measurement operation logic performs a complete SM3 hash operation on each 4096-byte data block, generating 4096 256-bit block hash values and temporarily storing them in the on-chip SRAM.
[0068] This step uses a block hash value calculation method, which allows the measurement operation logic to maintain a limited block hash value temporary storage area on-chip, without having to allocate a continuous complete hash operation buffer for the entire firmware, thus reducing the demand on on-chip storage resources. At the same time, block reading and hash operation are executed in a pipelined manner, that is, the reading operation of the Nth data block and the hash operation of the N-1th data block can be performed in parallel, so that the firmware reading latency is partially or completely masked by the hash operation time, thereby improving the overall throughput of the measurement operation.
[0069] S22: Using each hash value as a leaf node, calculate the parent node hash value layer by layer according to the preset binary Merkle tree structure until the root hash value is generated. Compare the root hash value with the pre-stored baseline root hash value. If they match, the measurement is considered successful; otherwise, the measurement is considered unsuccessful.
[0070] For example, this step utilizes a Merkle tree structure to aggregate the block hash values of each data block into a root hash value, which serves as the integrity metric digest for the entire target firmware. The metric operation logic reads the block hash values of each data block from the on-chip temporary storage area, uses each block hash value as the leaf node at the bottom of the Merkle tree, and calculates the hash value of the parent node layer by layer from the bottom up according to the preset binary tree topology. The hash value of each parent node is the result of concatenating the hash values of its left and right child nodes and performing an SM3 hash operation. When the number of nodes in a certain layer is odd, the last node is concatenated and hashed with the matching node generated by its own replication. This layer-by-layer aggregation process continues until a unique root hash value is finally generated. The comparison unit in the measurement operation logic reads the pre-stored reference root hash value from the on-chip non-volatile memory. The reference root hash value is the root hash value calculated and signed by the authorized party using the same block and Merkle tree structure in the trusted factory state of the target firmware. The comparison unit performs a bitwise XOR comparison between the calculated root hash value and the reference root hash value. If all 256 bits match, a measurement pass indication signal is output. If any bit does not match, a measurement failure indication signal is output.
[0071] Taking the BIOS firmware measurement scenario as an example, the 4096 block hash values generated in step S21 are used as the bottom leaf nodes of the Merkle tree. They are paired up and SM3 hash is performed to generate 2048 parent nodes. The nodes continue to aggregate upwards layer by layer. After 12 layers of calculation, a unique 256-bit root hash value is generated. The root hash value is compared bit by bit with the factory-preset reference root hash value. If they match, it is determined that the BIOS firmware has not been tampered with and the measurement passes.
[0072] This step aggregates numerous block hash values into a single root hash value using a Merkle tree structure. This allows the measurement comparison process to store and compare only one root hash value, instead of comparing all block hash values one by one. This reduces the storage overhead of the measurement result from O(n) to O(1), and also reduces the comparison time from linearly scanning multiple block hash values to a single 256-bit comparison operation. In addition, the Merkle tree structure supports the tampering location verification of a single data block. When the measurement fails, the tampered firmware data block can be quickly located by tracing the hash path layer by layer, providing fine-grained location information for subsequent measurement failure handling strategies.
[0073] In one embodiment, such as Figure 6 As shown, in step S22, each hash value is used as a leaf node, and the hash value of the parent node is calculated layer by layer according to the preset binary Merkle tree structure until the root hash value is generated. Specifically, it includes the following steps: S221-S223.
[0074] S221: When the number of nodes in the current layer to be calculated is even, the hash values of two adjacent nodes are concatenated and then the SM3 hash operation is performed to obtain the hash value of the parent node of the previous layer.
[0075] For example, this step handles the regular aggregation case when the number of nodes in the current layer is even during the Merkle tree construction process. The Merkle tree control state machine in the metric operation logic maintains a layer node counter to record the total number of nodes in the current layer to be processed. When the layer node counter value is even, the state machine sequentially takes the 256-bit hash values of two adjacent nodes each time, places the hash value of the previous node in the high bit and the hash value of the next node in the low bit, and concatenates them to generate a 512-bit concatenated message. This concatenated message is sent to the SM3 operation pipeline of the hardware hash accelerator. After message padding and expansion to the message block length and 64 rounds of iterative compression, a 256-bit parent node hash value is output and stored in the node temporary storage area of the previous layer.
[0076] Taking the calculation of the third level of the Merkle tree as an example, there are 8 nodes in the current level. The number of nodes is 8, which is an even number. The state machine sequentially takes node 0 and node 1, node 2 and node 3, node 4 and node 5, node 6 and node 7 and performs four pairwise concatenations and SM3 operations to generate 4 parent nodes and output them to the fourth level temporary storage area.
[0077] This step controls the node pairing and splicing order through a hardware state machine, so that all parent node hash calculations within each layer can be executed in a pipelined manner at a fixed rhythm. The pipeline of the hardware hash accelerator remains fully loaded when continuously processing paired nodes in the same layer, avoiding pipeline bubbling caused by data dependency waiting, and maximizing the throughput of the SM3 hardware engine.
[0078] S222: When the number of nodes in the current layer to be calculated is odd, copy the hash value of the last node to generate a matching node, concatenate the last node with the matching node and perform SM3 hash operation to obtain the hash value of the parent node of the previous layer.
[0079] For example, this step handles the boundary case when the number of nodes in the current layer is odd during the Merkle tree construction process. When the layer node counter value is odd, the first N-1 nodes are paired up according to the even-number rule of S221, and the last remaining Nth node participates in the calculation alone. When the Merkle tree control state machine detects that there is only one node left in the current layer and no paired node, it generates a node replication control signal. The 256-bit hash value of the Nth node is read from the node temporary storage area and simultaneously driven to the two input ports of the splicing logic. That is, the hash value of the Nth node is used as the high bit and its own replication value is used as the low bit to generate a 512-bit splicing message, which is sent to the hardware hash accelerator to perform SM3 hash operation, obtain the parent node hash value and output it to the upper layer.
[0080] Taking the second level of the Merkle tree as an example, the current level has 5 nodes. Since the number of nodes is 5, the state machine first processes node 0 and node 1, and node 2 and node 3 according to the even number rule. Finally, the remaining node 4 is a single node. The state machine copies the hash value of node 4, concatenates it with itself, and then performs the SM3 operation to generate the parent node of node 4 and outputs it to the third level.
[0081] This step employs a self-replication pairing mechanism for the last node in the odd-numbered node layer. This allows the Merkle tree construction process to complete aggregation operations in a uniform binary tree structure under any number of input nodes, without introducing additional empty node filling or preprocessing steps, thus simplifying the branching logic of the Merkle tree control state machine. At the same time, the self-replication operation is completed at the hardware level through bus multiplexing or register copying, adding only a one-clock-cycle node copying delay and not introducing additional hash operation overhead.
[0082] S223: Repeat the above layer-by-layer calculation process until only one target node remains, and use the target node as the root hash value. The SM3 hash operation at each layer is executed in a pipelined manner by the hardware hash accelerator in the metric operation logic.
[0083] For example, this step controls the iteration termination and root node output of the Merkle tree construction process. After the Merkle tree control state machine completes the calculation of all parent nodes of each layer, it switches the node temporary storage area of the previous layer to the current layer node temporary storage area of the next layer, updates the layer node counter to the number of nodes of the previous layer, and repeats the aggregation step S221 or S222. When the layer node counter value is 1 after the calculation of a certain layer is completed, the state machine determines that the Merkle tree construction has converged to the root node, stops the iteration, marks the unique node as the root hash value, and latches it into the root hash value output register. In the entire layer-by-layer aggregation process, the hardware hash accelerator continuously receives the splicing messages of each node in a pipeline manner. Each stage of the pipeline executes different stages of message filling, message expansion, and compression iteration in parallel, so that the SM3 hash operation of each layer can achieve a throughput of starting a new operation once per clock cycle under non-blocking pipeline conditions.
[0084] Taking a Merkle tree with 4096 leaf nodes as an example, the 4096 leaf nodes in the first layer are aggregated into 2048 parent nodes, the 2048 nodes in the second layer are aggregated into 1024 parent nodes, and so on. After 12 layers of iteration, it converges to a unique root node. The hardware hash accelerator keeps the pipeline running at full capacity in each layer until all nodes in that layer have been computed.
[0085] This step employs a hardware state machine-controlled, layer-by-layer iterative aggregation method, enabling the Merkle tree construction process to be entirely autonomously completed by hardware logic. No software intervention is required for scheduling and managing nodes at each layer, avoiding the instruction overhead and cache miss latency caused by software loop traversal. Simultaneously, the pipelined execution mode of the hardware hash accelerator allows for continuous parallel flow of SM3 hash operations on a large number of nodes within each layer. This reduces the total latency of Merkle tree construction from microseconds or milliseconds in software implementation to microseconds or even nanoseconds determined by the hardware pipeline, significantly shortening the hash value aggregation time in the active measurement phase. This, in turn, reduces the overall trusted startup establishment time from system power-on to measurement completion.
[0086] The above-described embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit it. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be included within the protection scope of the present invention.
[0087] It should be understood that the sequence number of each step in the above embodiments does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.
[0088] In the above embodiments, the descriptions of each embodiment have different focuses. For parts that are not described in detail or recorded in a certain embodiment, please refer to the relevant descriptions of other embodiments.
[0089] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0090] In the embodiments provided in this application, it should be understood that the disclosed apparatus / devices and methods can be implemented in other ways. For example, the apparatus / device embodiments described above are merely illustrative. For instance, the division of modules or units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.
[0091] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0092] The above-described embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application, and should all be included within the protection scope of this application.
Claims
1. A dynamic switching circuit supporting active measurement and cryptographic services, characterized in that, include: The processing core integrates selectable measurement operation logic and cryptographic operation logic. The measurement operation logic is used to perform integrity measurement operations in active measurement mode, and the cryptographic operation logic is used to perform cryptographic operations in cryptographic service mode. A control circuit, connected to the processing core, is used to acquire state information representing the working stage of the system, and generate a mode selection signal according to a preset switching strategy to control the processing core to switch between the active measurement mode and the cryptographic service mode. An I / O router, connected to the processing core and the control circuit, is controlled by the mode selection signal to dynamically route external bus signals to the communication interface corresponding to the current working mode. A power management unit, connected to the processing core and the control circuit, is used to supply power to the processing core and the control circuit before the host computing unit in the power-on sequence, and to implement power consumption management for unused arithmetic logic in the processing core according to the current working mode. The control circuit, in response to the status information indicating the system startup phase, controls the processing core to enter the active measurement mode, and in response to the status information indicating the measurement completion, controls the processing core to switch to the cryptographic service mode. The control circuit includes: A status signal acquisition sub-circuit is used to acquire the status information representing the working stage of the system from the system bus. The status information includes system power-on timing signals, CPU startup stage identifiers, and trust measurement completion status flags. The mode determination logic sub-circuit is connected to the state signal acquisition sub-circuit and is used to perform logical combination and condition judgment on the state information according to the preset switching strategy to generate a mode switching indication signal. A mode selection signal generation sub-circuit, connected to the mode determination logic sub-circuit, is used to generate the mode selection signal according to the mode switching indication signal and output it to the processing core and the I / O router. A security state isolation subcircuit, which is connected to the mode determination logic subcircuit, is used to first save the security key registers and key cache inside the processing core to an isolated storage area independent of the host access domain when the mode determination logic subcircuit generates a mode switching indication signal, and restore the corresponding security context from the isolated storage area after the mode switching is completed, so as to ensure the secure isolation of the operating states between the active measurement mode and the cryptographic service mode.
2. The dynamic switching circuit supporting active measurement and cryptographic services according to claim 1, characterized in that, The mode determination logic sub-circuit is configured as follows: When the status signal acquisition sub-circuit acquires a valid system power-on timing signal and a valid CPU startup phase identifier, it outputs a switching indication signal to enter the active measurement mode. When the trusted measurement completion status flag is valid and a password service request exists, a switching indication signal for entering password service mode is output.
3. The dynamic switching circuit supporting active measurement and cryptographic services according to claim 1, characterized in that, The control circuit is also used to perform handshake coordination with the host CPU. When the control circuit is ready to switch to the cryptographic service mode in response to the status information indicating that the measurement is completed, it first sends a measurement pass certificate to the host CPU and waits for the host CPU to return a reset release signal. After confirming that the host CPU has released the reset, it controls the I / O router to switch the external bus path from the active measurement communication interface to the cryptographic service communication interface.
4. The dynamic switching circuit supporting active measurement and cryptographic services according to claim 1, characterized in that, The control circuit is further configured to: In the cryptographic service mode, the system periodically receives dynamic trusted measurement trigger commands from the host. In response to the dynamic trusted measurement trigger commands, the processing core is controlled to temporarily switch from the cryptographic service mode to the active measurement mode to perform measurement operations on the runtime components in the system memory, and automatically switches back to the cryptographic service mode after the measurement is completed.
5. The dynamic switching circuit supporting active measurement and cryptographic services according to claim 1, characterized in that, The processing core also includes anti-attack redundancy verification logic, which is configured as follows: In active measurement mode, different hash algorithms are used to perform two measurement operations on the same firmware code segment to be measured, and the two measurement results are cross-compared to resist transient fault injection attacks targeting a single measurement operation.
6. The dynamic switching circuit supporting active measurement and cryptographic services according to claim 1, characterized in that, The dynamic switching circuit supporting active measurement and cryptographic services is a single system-on-a-chip (SoC). The SoC's package integrates an active shielding layer that covers the physical layout area of the processing core, the control circuit, and the I / O router, and is electrically connected to the control circuit. This active shielding layer is used to send a forced reset signal to the control circuit to clear all security states inside the processing core when a physical probe intrusion is detected.
7. The dynamic switching circuit supporting active measurement and cryptographic services according to claim 1, characterized in that, The power management unit includes: a first power rail and a control sub-circuit connected to the first power rail; the control sub-circuit includes a first filter capacitor, a second filter capacitor, a first resistor, a second resistor, a third resistor, and a first field-effect transistor, a second field-effect transistor, and a third field-effect transistor; The first filter capacitor and the second filter capacitor are connected in parallel between the first power rail and ground, configured to filter out power supply noise from the first power rail. The gate of the first field-effect transistor is connected to the first power rail through the first resistor, the source is grounded, and the drain is connected to the TPCM in-situ detection signal terminal. It is configured to pull down the TPCM in-situ detection signal when the first power rail is powered on, so as to provide the control circuit with a power status indication during the system startup phase. The gate of the second field-effect transistor is connected to the TPCM measurement completion indication signal terminal, the drain is connected to the first power rail through the second resistor, and the source is grounded. It is configured to respond to the TPCM measurement completion indication signal to turn on ground when the measurement is completed, thereby feeding back the power ready confirmation signal corresponding to the measurement completion state to the control circuit. The gate of the third field-effect transistor is connected to the first power rail through the third resistor, the drain is connected to the QSPI channel switching input signal terminal, and the source is grounded. It is configured to pull down the QSPI channel switching input signal when the first power rail is powered on, so as to force the I / O router to be locked in the default off safe state in the initial stage of power-on.
8. An encryption device, characterized in that, The encryption device performs authentication encryption based on a dynamic switching circuit that supports active measurement and cryptographic services as described in any one of claims 1-7.
9. A method for supporting dynamic switching between proactive measurement and cryptographic services, characterized in that, Executed by a processing core, wherein the processing core is a processing core that supports a dynamic switching circuit for active measurement and cryptographic services as described in any one of claims 1-7, and the processing core is configured to: Receive the mode selection signal generated by the control circuit; When the mode selection signal indicates entry into active measurement mode, a first routing control signal is generated to control the I / O router to route the external bus signal to the active measurement communication interface, and the measurement operation logic is activated to perform integrity measurement operation on the target firmware. At the same time, a first power management signal is output to the power management unit to suppress the power consumption of the cryptographic operation logic. When the mode selection signal indicates entry into the cryptographic service mode, a second routing control signal is generated to control the I / O router to route the external bus signal to the cryptographic service communication interface, and to activate the cryptographic operation logic to perform cryptographic operations. At the same time, a second power management signal is output to the power management unit to suppress the power consumption of the measurement operation logic. The mode selection signal is generated by the control circuit based on the system power-on timing signal and the measurement completion status flag. The control circuit includes: A status signal acquisition sub-circuit is used to acquire the status information representing the working stage of the system from the system bus. The status information includes system power-on timing signals, CPU startup stage identifiers, and trust measurement completion status flags. The mode determination logic sub-circuit is connected to the state signal acquisition sub-circuit and is used to perform logical combination and condition judgment on the state information according to the preset switching strategy to generate a mode switching indication signal. A mode selection signal generation sub-circuit, connected to the mode determination logic sub-circuit, is used to generate the mode selection signal according to the mode switching indication signal and output it to the processing core and the I / O router. A security state isolation subcircuit, which is connected to the mode determination logic subcircuit, is used to first save the security key registers and key cache inside the processing core to an isolated storage area independent of the host access domain when the mode determination logic subcircuit generates a mode switching indication signal, and restore the corresponding security context from the isolated storage area after the mode switching is completed, so as to ensure the secure isolation of the operating states between the active measurement mode and the cryptographic service mode.
10. The method according to claim 9, characterized in that, The activation of the measurement operation logic to perform integrity measurement operations on the target firmware includes: The target firmware is divided into multiple data blocks, and each data block is read sequentially. The SM3 hash algorithm is used to calculate the block hash value for each data block. Each block hash value is used as a leaf node, and the parent node hash value is calculated layer by layer according to the preset binary Merkle tree structure until the root hash value is generated. The root hash value is compared with the pre-stored reference root hash value. If they match, the measurement is considered successful; otherwise, the measurement is considered to have failed.
11. The method according to claim 10, characterized in that, The step of using each block hash value as a leaf node and calculating the parent node hash value layer by layer according to a preset binary Merkle tree structure until the root hash value is generated includes: When the number of nodes in the current layer to be calculated is even, the hash values of two adjacent nodes are concatenated and then the SM3 hash operation is performed to obtain the hash value of the parent node of the previous layer. When the number of nodes in the current layer to be calculated is odd, the hash value of the last node is copied to generate a matching node. The last node and the matching node are concatenated and then SM3 hash operation is performed to obtain the hash value of the parent node of the previous layer. Repeat the above layer-by-layer calculation process until only one target node remains, and use the target node as the root hash value; In this process, the SM3 hash operation at each layer is executed in a pipelined manner by the hardware hash accelerator in the metric operation logic.