Energy-containing storage SoC chip integrated with cryptographic algorithm authentication and self-destruction control method thereof

CN122839451APending Publication Date: 2026-09-29BEIJING ZHONGKE SHIXINAN TECHNOLOGY CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202611279455.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2026-07-03
Filing Date
2026-08-21
Publication Date
2026-09-29

AI Technical Summary

Technical Problem

[0005]本申请的主要目的在于提供一种集成密码算法认证的含能存储SoC芯片及其自毁控制方法,旨在解决相关技术中存储芯片的安全防护力度不足的技术问题

Benefits of technology

本申请通过在存储SoC芯片内部独立设置国密认证模块,并采用SM3杂凑算法与SM2数字签名验证相结合的方式,对外部自毁指令进行身份真实性认证,仅当自毁指令通过授权身份验证后才允许输出自毁指令触发自毁,有效避免了传统方案中自毁信号输入端缺乏权威身份认证而导致的恶意伪造、非法触发等安全风险。同时,通过固定字段预杂凑、动态字段增量计算以及SM2验签流水线处理等机制,提高了认证效率,降低了认证延迟;进一步结合时间戳、序列号和随机数的联合校验机制,有效抵御重放攻击和重复触发攻击;此外,自毁控制与执行模块采用有效校验位、热码编码及时序校验的多重确认机制,对认证结果进行二次校验,进一步提高了自毁触发过程的可靠性和安全性,从而在保证自毁操作不可伪造、不可重放的同时,兼顾了芯片安全防护的实时性、可靠性和工程应用性能。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122839451A_ABST
    Figure CN122839451A_ABST
Patent Text Reader

Abstract

This application discloses a smart memory SoC chip with integrated cryptographic algorithm authentication and its self-destruct control method, applied to the national cryptographic authentication module of the memory SoC chip. The method includes: obtaining self-destruct instruction information through a self-destruct instruction interface, the self-destruct instruction information including the original self-destruct instruction and a digital signature; calculating the hash value of the original self-destruct instruction using the SM3 hash algorithm engine to obtain the instruction hash value; verifying the digital signature based on a pre-stored authorized public key using the SM2 asymmetric algorithm engine; if the verification passes, generating and verifying the self-destruct instruction based on the instruction hash value and the signature component of the digital signature; if the verification passes, generating the self-destruct instruction and outputting the self-destruct instruction to the self-destruct control and execution module, so that the self-destruct control and execution module triggers and executes the self-destruct action based on the self-destruct instruction. This application improves the security protection capability of the memory chip.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of information security technology, and in particular to an energy storage SoC chip with integrated cryptographic algorithm authentication and its self-destruct control method. Background Technology

[0002] The security protection technologies for memory chips are mainly divided into two categories: data-level encryption / destruction and hardware-level physical destruction.

[0003] In related technologies, most mainstream security chips currently employ data encryption schemes to protect stored information. For example, they integrate a coprocessor for Chinese national cryptographic algorithms (SM2 / SM3 / SM4) within the chip to encrypt and store data. Some security chips also have data destruction capabilities, allowing data to be overwritten or keys to be destroyed via software, making the data unreadable.

[0004] However, existing self-destruct chips typically rely solely on the logical judgment of the self-destruct decision chip for triggering, lacking deep integration with authoritative authentication mechanisms. While some chips employ password verification modules for access control, they directly trigger self-destruction after a certain number of failed password authentication attempts. This design simply links "protection" and "destruction"—any attacker who bypasses or breaks through the authentication process can easily gain control of the self-destruction and maliciously trigger it. In other words, the self-destruct signal input lacks identity verification based on national cryptographic algorithms, meaning anyone can send a self-destruct signal to the chip, posing a security risk of malicious remote triggering. Summary of the Invention

[0005] The main purpose of this application is to provide an integrated cryptographic algorithm authentication-enabled SoC chip with energy storage and its self-destruct control method, aiming to solve the technical problem of insufficient security protection of memory chips in related technologies.

[0006] To achieve the above objectives, in a first aspect, this application provides a self-destruct control method for an energy storage SoC with integrated cryptographic algorithm authentication, which is applied to the national cryptographic authentication module of the storage SoC chip. The national cryptographic authentication module is independently set in the storage SoC chip. The national cryptographic authentication module obtains external destruction instructions through a dedicated self-destruct instruction interface. The national cryptographic authentication module is also communicatively connected to the self-destruct control and execution module. The methods include: The self-destruct instruction information is obtained through the self-destruct instruction interface. The self-destruct instruction information includes the original text of the self-destruct instruction and its digital signature. The SM3 hash algorithm engine is used to calculate the hash value of the self-destruct instruction raw text to obtain the instruction hash value; The digital signature is verified using the SM2 asymmetric algorithm engine based on the pre-stored authorized public key. If the verification passes, a self-destruct instruction is generated and verified based on the instruction hash value and the signature component of the digital signature. If the verification passes, a self-destruct command is generated and output to the self-destruct control and execution module, so that the self-destruct control and execution module can trigger and execute the self-destruct action based on the self-destruct command.

[0007] In one embodiment, the step of calculating the hash value of the self-destruct instruction plaintext using the SM3 hash algorithm engine to obtain the first hash value includes: Identify the fixed and dynamic fields in the self-destruct command information; The fixed field is compared with the pre-stored fixed field. If the comparison passes, the hash value of the fixed field is determined based on the pre-stored hash value of the pre-stored fixed field. Calculate the hash value of the dynamic field and combine it with the hash value of the fixed field to determine the instruction hash value.

[0008] In one embodiment, the digital signature is verified using the SM2 asymmetric algorithm engine based on a pre-stored authorized public key. If the verification passes, the step of generating a self-destruct instruction based on the instruction hash value and the signature component of the digital signature includes: To obtain a digital signature, a pipelined approach is used, executing the following steps: After summing the signature component r and the signature component, the summation result is moduloed by the order n of the elliptic curve base point to determine the intermediate variable value t; where the elliptic curve base point is pre-stored in the chip; If the intermediate variable value t is not 0, the elliptic curve points are calculated based on the pre-stored authorized public key and the elliptic curve base points to determine the calculation result; wherein, the authorized public key is stored in the one-time programmable memory of the national cryptographic authentication module in affine coordinate format; If the calculation result is not the point of infinity, then the instruction hash value is summed with the x-coordinate of the elliptic curve point, and the order n of the elliptic curve base point is moduloed to determine the value to be verified. If the value to be verified is equal to the signature component r, then a self-destruct instruction is generated.

[0009] In one embodiment, the self-destruct instruction information further includes a timestamp, a random number, and, after the step of obtaining the self-destruct instruction information through the self-destruct instruction interface, the following step is also included: The timestamp is compared with the counter value of the chip's built-in counter. If the deviation of the timestamp exceeds the configurable window, the self-destruct instruction information is discarded; and / or, If the serial number does not fall within the serial number window register group or the serial number has already been used, the self-destruct instruction information is discarded; and / or, If the random number exists in the random number cache, the self-destruct instruction information is discarded. If the random number does not exist in the random number cache, the sequence number is added to the random number cache and the oldest sequence number in the random number cache is discarded.

[0010] In one embodiment, the method applied to the self-destruct control and execution module further includes the step of: Obtain the self-destruct instruction, which includes a 1-bit valid check bit, a 4-bit hot code, and a timestamp copy; If the valid check bit is valid, then read the hot code encoding and timestamp copy; If the hot code is equal to the preset code and the difference between the timestamp copy and the local timestamp of the self-destruct control and execution module is less than the preset value, then an ACK response is generated and the self-destruct action is executed.

[0011] Secondly, to achieve the above objectives, this application further provides an integrated cryptographic algorithm authentication-enabled SoC chip with energy storage. The storage SoC chip includes a main control and storage core area, which includes a processor core, a non-volatile memory array, and a storage read / write control circuit. The feature is that it also includes an independently set national cryptographic authentication module. The national cryptographic authentication module obtains external destruction instructions through a dedicated self-destruct instruction interface. The national cryptographic authentication module is also communicatively connected to the self-destruct control and execution module. The national cryptographic authentication module includes a hardware parser located at the front end of the self-destruct command interface, which is used to obtain self-destruct command information, including the original text of the self-destruct command and a digital signature; The SM3 hash algorithm engine is used to calculate the hash value of the self-destruct instruction plaintext to obtain the instruction hash value; The SM2 asymmetric algorithm engine is used to verify digital signatures based on pre-stored authorized public keys. If the verification passes, a self-destruct instruction is generated and verified based on the instruction hash value and the signature component of the digital signature. One-time programmable memory is used to store the authorization public key, authentication policy, and chip unique identifier; The self-destruct control and execution module includes a self-destruct control logic unit, which is used to generate a self-destruct trigger signal based on the self-destruct command output by the national cryptographic authentication module; An energetic self-destruct mechanism disposed on the chip substrate is used to perform a self-destruct action based on a self-destruct trigger signal.

[0012] In one embodiment, the authorized public key stored in the one-time programmable memory is encrypted using SM4 with a PUF key, and the hardware automatically decrypts and loads it into the SM2 asymmetric algorithm engine after the chip is powered on. The data and address lines of the one-time programmable memory are routed at the bottom layer of the metal layer, and the upper metal layer covers the dynamic pseudo signals; The read path of the one-time programmable memory integrates temperature and voltage sensors. When the chip operates outside the set temperature range and / or set voltage range, the read output of the one-time programmable memory is forced to zero.

[0013] In one embodiment, the SM3 hash algorithm engine, the SM2 asymmetric algorithm engine, and the one-time programmable memory are each powered by an independent low-dropout linear regulator; The self-destruct instruction interface uses an externally input clock, while the SM3 hash algorithm engine and the SM2 asymmetric algorithm engine use a fixed clock generated by an internal PLL. The two clock domains exchange data through an asynchronous FIFO buffer.

[0014] One or more technical solutions proposed in this application have at least the following technical effects: This application establishes a national cryptographic authentication module within the storage SoC chip and employs a combination of SM3 hash algorithm and SM2 digital signature verification to authenticate the identity of external self-destruct commands. Self-destruction is only allowed after the command has passed authorized authentication, effectively avoiding the security risks of malicious forgery and illegal triggering caused by the lack of authoritative authentication at the self-destruct signal input end in traditional solutions. Simultaneously, mechanisms such as fixed field pre-hash, dynamic field incremental calculation, and SM2 signature pipeline processing improve authentication efficiency and reduce authentication latency. Furthermore, a joint verification mechanism combining timestamps, serial numbers, and random numbers effectively resists replay attacks and repeated triggering attacks. In addition, the self-destruct control and execution module uses a multi-confirmation mechanism of valid check bits, hot code encoding, and time sequence verification to perform secondary verification of the authentication results, further improving the reliability and security of the self-destruct triggering process. Thus, while ensuring that the self-destruct operation is unforgeable and unreplayable, it also considers the real-time performance, reliability, and engineering application performance of chip security protection. Attached Figure Description

[0015] Figure 1 This is a schematic diagram of the chip architecture of the storage SoC chip in this application.

[0016] Figure 2 This is a flowchart illustrating an embodiment of the self-destruct control method for an energy storage SoC integrating cryptographic algorithm authentication as described in this application.

[0017] The realization of the purpose, functional features and advantages of this application will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation

[0018] It should be understood that the specific embodiments described herein are merely illustrative of this application and are not intended to limit this application.

[0019] In the field of information security, the security protection technologies for memory chips are mainly divided into two categories: data-level encryption / destruction and hardware-level physical destruction.

[0020] Most mainstream security chips currently use data encryption schemes to protect stored information. For example, they integrate a coprocessor for Chinese cryptographic algorithms (SM2 / SM3 / SM4) inside the chip to encrypt and store data.

[0021] Some security chips also have data destruction capabilities, which can overwrite data or destroy keys through software to make the data unreadable.

[0022] For example, an anti-attack IoT security chip that integrates national cryptographic algorithms can delete the power consumption and electromagnetic radiation information generated during chip use through software destruction when an attack is detected.

[0023] For high-security applications, physical destruction is considered the most thorough protection method. Existing physical destruction technologies mainly include: Electric fuse burning technology: By applying a fusing voltage to the metal fuse inside the chip, the electromigration effect is used to melt the fuse, thereby disconnecting the memory array from the read and write circuits and causing the chip to fail.

[0024] Energetic material detonation destruction technology: Energetic agents (such as copper azide, nano-aluminothermic agents, etc.) are placed inside or outside the chip package. A miniature ignition chip or semiconductor bridge detonates the energetic material, using a detonation wave or high temperature and pressure to cause irreparable physical damage to the memory chip. A research team at City University of Hong Kong has achieved instantaneous self-destruction of microchips using nano-energetic thin films. The latest research integrates fluorinated nano-aluminothermic agents into memory chips, enabling secure data destruction within 0.2 ms.

[0025] Safety control and isolation technology: To prevent energetic materials from being accidentally triggered, existing technology uses a miniature safety release unit to short-circuit the miniature transducer. The fuse is released and an ignition signal is issued only when the self-destruct decision chip determines that self-destruction is necessary.

[0026] With advancements in manufacturing processes, System-on-Chip (SoC) has become the mainstream design paradigm. Existing patents integrate processors, memory, and cryptographic security chips into SoC or SiP modules, but these primarily focus on data encryption and protection functions.

[0027] Existing self-destruct chips typically rely solely on the logical judgment of the self-destruct decision chip for triggering, lacking deep integration with authoritative authentication mechanisms. While some chips employ password verification modules for access control, they directly trigger self-destruction after a certain number of failed password authentication attempts. This design simply links "protection" and "destruction"—attackers can easily gain control of the self-destruction process and maliciously trigger it if they bypass or break through the authentication process. In other words, the self-destruct signal input lacks identity verification based on national cryptographic algorithms, meaning anyone can send a self-destruct signal to the chip, posing a security risk of malicious remote triggering.

[0028] Most existing security chips or self-destruct chips adopt an "all-or-nothing" permission mode—once an external signal passes a certain verification, it can simultaneously obtain data access permission and data destruction permission. The permission boundary between normal business operations and security responses is unclear, increasing the risk of accidental or malicious triggering.

[0029] Most existing solutions with energy-enabled self-destruct mechanisms employ a multi-chip discrete approach, resulting in large system size, high power consumption, and long response latency. Although SoC technology has been applied in the field of cryptographic security, there are still no products that truly integrate the national cryptographic authentication module (SM2 / SM3), the energy-enabled self-destruct mechanism, and the storage array on a single chip.

[0030] While physical destruction methods based on metal fuses can stop a chip from working, the chip itself remains intact after the fuse breaks, and the storage medium itself is not damaged, leaving a vulnerability for attackers to recover data through microscopic analysis.

[0031] Based on this, the embodiments of this application will below describe the integrated cryptographic algorithm authentication-enabled SoC chip and its self-destruct control method used in the technical implementation of this application: Reference Figure 1 , Figure 1 A schematic diagram of a SoC chip with integrated cryptographic algorithm authentication.

[0032] In this embodiment, the SoC chip with integrated cryptographic algorithm authentication includes a main control and storage core area, which includes a processor core, a non-volatile memory array, and a storage read / write control circuit. The feature is that it also includes an independently set national cryptographic authentication module. The national cryptographic authentication module obtains external destruction instructions through a dedicated self-destruct instruction interface. The national cryptographic authentication module is also communicatively connected to the self-destruct control and execution module. The national cryptographic authentication module includes a hardware parser located at the front end of the self-destruct command interface, which is used to obtain self-destruct command information, including the original text of the self-destruct command and a digital signature; The SM3 hash algorithm engine is used to calculate the hash value of the self-destruct instruction plaintext to obtain the instruction hash value; The SM2 asymmetric algorithm engine is used to verify digital signatures based on pre-stored authorized public keys. If the verification passes, a self-destruct instruction is generated and verified based on the instruction hash value and the signature component of the digital signature. One-time programmable memory is used to store the authorization public key, authentication policy, and chip unique identifier; The self-destruct control and execution module includes a self-destruct control logic unit, which is used to generate a self-destruct trigger signal based on the self-destruct command output by the national cryptographic authentication module; An energetic self-destruct mechanism disposed on the chip substrate is used to perform a self-destruct action based on a self-destruct trigger signal.

[0033] The authorized public key stored in the one-time programmable memory is encrypted using SM4 with a PUF key. After the chip is powered on, the hardware automatically decrypts and loads it into the SM2 asymmetric algorithm engine.

[0034] The data and address lines of the one-time programmable memory are routed at the bottom layer of the metal layer, and the upper metal layer covers the dynamic pseudo signals; The read path of the one-time programmable memory integrates temperature and voltage sensors. When the chip operates outside the set temperature range and / or set voltage range, the read output of the one-time programmable memory is forced to zero.

[0035] The SM3 hash algorithm engine, the SM2 asymmetric algorithm engine, and the one-time programmable memory are each powered by an independent low-dropout linear regulator. The self-destruct instruction interface uses an externally input clock, while the SM3 hash algorithm engine and the SM2 asymmetric algorithm engine use a fixed clock generated by an internal PLL. The two clock domains exchange data through an asynchronous FIFO buffer.

[0036] Specifically, the SoC chip with energy storage adopts a monolithic integrated architecture, integrating the following functional modules on a single silicon-based chip: The main control and storage core area, including the processor core RISC-V or ARM architecture 32-bit / 64-bit microprocessor, is responsible for overall operation coordination, data read and write control, and instruction parsing.

[0037] Non-volatile memory arrays, including Flash, RRAM, or MRAM media, are used to store user data.

[0038] The storage read / write control circuit, including the address decoder, read / write driver circuit, and data cache, is responsible for the read / write operations of the storage array in normal mode.

[0039] The national cryptographic authentication module includes the SM2 asymmetric algorithm engine for digital signature verification. External self-destruct commands must be signed using an authorized private key, and the chip verifies the authenticity of the signature using a pre-installed authorized public key in the OTP.

[0040] The SM3 hash algorithm engine is used for instruction integrity verification. It calculates a hash value on the received self-destruct instruction plaintext and compares it with the hash value in the signature to ensure that the instruction has not been tampered with during transmission.

[0041] One-time programmable memory (OTP) is used to store the authorized public key, authentication policies (such as signature validity period, anti-replay count, etc.) and the chip's unique identifier, which cannot be read or tampered with externally.

[0042] The self-destruct control and execution module includes a self-destruct control logic unit, which receives the output of the national cryptographic authentication module. After both SM2 signature verification and SM3 integrity verification pass, it executes the two-stage operation of "disarming the insurance - detonating" in a preset sequence.

[0043] The miniature energetic self-destruct mechanism is integrated on a specific area of ​​the chip substrate, including a semiconductor bridge / miniature transducer, an energetic material layer (copper azide, nano-aluminothermic porous silicon composite film, etc.), and a microchannel / sealed cavity structure.

[0044] It also includes a safety protection unit that uses a micro-MEMS switch to short-circuit or physically isolate the ignition electrode of the energetic material under normal conditions, preventing accidental triggering by static electricity or leakage current.

[0045] Input / output interfaces, including data communication interfaces such as SPI / I2C / UART, are used for data reading and writing in normal mode. This channel does not require authentication.

[0046] The self-destruct command interface uses a dedicated pin or a specific command word from the multiplexed communication interface to receive external self-destruct commands. The commands on this channel must be SM2 / SM3 certified.

[0047] The status indicator pin outputs a self-destruct status indication signal for the chip.

[0048] A hardware parser is located at the front end of the self-destruct command interface, independent of the processor. After receiving a complete data packet, it automatically performs the following: modulus matching (if it fails, it is discarded directly without waking up any modules), sequence number comparison (if it does not match, it is discarded and the error counter is incremented at the same time), length verification (if it does not match, it is discarded), and valid field extraction (sent to the SM3 engine and SM2 engine in parallel). The parser uses a finite state machine (FSM) design, and at a clock frequency of 100MHz, the complete parsing time is <1μs.

[0049] The authorized public key (SM2), chip unique serial number, authentication policy, and other data stored in the OTP memory are among the most sensitive data. This invention employs the following hardware-level protection: Physically Unclonable (PUF) assisted encryption: Upon chip power-up, a 128-bit PUF key is generated using SRAM power-on initial values ​​or a ring oscillator. The OTP actually stores the ciphertext of the public key (encrypted using the PUF key via SM4). After power-up, the hardware automatically decrypts and loads the data into the SM2 engine registers; the raw OTP data cannot be directly read externally.

[0050] The OTP data lines and address lines are routed on the bottom layer (M1) of the metal layer, and the upper metal layer covers the dynamic pseudo signal (randomly flipped dummy signal), making it difficult for the focused ion beam (FIB) probe to directly contact the sensitive signal.

[0051] The OTP read path integrates temperature and voltage sensors. When the chip operates outside the rated range (e.g., -40°C to 85°C, or voltage fluctuations > ±10%), the OTP read output is forced to zero to prevent bypassing verification through fault injection (e.g., voltage glitches).

[0052] To prevent power fluctuations or glitches from affecting the results during the certification process, critical modules use independent power domains: The SM2 / SM3 engine and OTP read circuit are powered by an independent low-dropout linear regulator (LDO). The input of the LDO is isolated by a Schottky diode connected in series with the main power supply and connected in parallel with a 1μF capacitor, which can withstand a power supply undershoot of 100ns and an amplitude of 50%.

[0053] The self-destruct command interface receives a clock from an external input (synchronized with the host), but the authentication engine uses a fixed 100MHz clock generated by an internal PLL. The two clock domains exchange data through an asynchronous FIFO to avoid authentication failure caused by clock jitter or the external clock stopping.

[0054] Based on the aforementioned chip architecture, referring to Figure 2 This embodiment further provides a self-destruct control method for an energy storage SoC with integrated cryptographic algorithm authentication, which is applied to the national cryptographic authentication module of the storage SoC chip. The national cryptographic authentication module is independently set in the storage SoC chip. The national cryptographic authentication module obtains external destruction instructions through a dedicated self-destruct instruction interface. The national cryptographic authentication module is also communicatively connected to the self-destruct control and execution module.

[0055] The method includes steps S10 to S40: Step S10: Obtain self-destruct instruction information through the self-destruct instruction interface. The self-destruct instruction information includes the original text of the self-destruct instruction and its digital signature.

[0056] Step S20: The hash value of the self-destruct instruction is calculated by using the SM3 hash algorithm engine.

[0057] Step S30: The digital signature is verified using the SM2 asymmetric algorithm engine based on the pre-stored authorized public key. If the verification passes, a self-destruct instruction is generated and verified based on the instruction hash value and the signature component of the digital signature.

[0058] Step S40: If the verification passes, a self-destruct command is generated and output to the self-destruct control and execution module so that the self-destruct control and execution module triggers and executes the self-destruct action based on the self-destruct command.

[0059] In one feasible implementation, step S20 includes steps A10 to A30: Step A10: Determine the fixed and dynamic fields in the self-destruct instruction information.

[0060] Step A20: Compare the fixed field with the pre-stored fixed field. If the comparison passes, determine the hash value of the fixed field based on the pre-stored hash value of the pre-stored fixed field.

[0061] Step A30: Calculate the hash value of the dynamic field and combine it with the hash value of the fixed field to determine the first hash value.

[0062] Step S30 includes steps AB0 to B40: Step B10, Obtain the digital signature. This is done using a pipelined approach, executing the following steps: Step B20: After summing the signature component r and the signature component of the digital signature, perform a modulo operation on the order n of the elliptic curve base point to determine the intermediate variable value t; wherein, the elliptic curve base point is pre-stored in the chip.

[0063] If the intermediate variable value t is not 0 in step B30, the elliptic curve points are calculated based on the pre-stored authorized public key and the elliptic curve base points, and the calculation result is determined; wherein, the authorized public key is stored in the one-time programmable memory of the national cryptographic authentication module in affine coordinate format.

[0064] In step B40, if the calculation result is not the point of infinity, the instruction hash value is summed with the x-coordinate of the elliptic curve point, and the order n of the elliptic curve base point is moduloed to determine the value to be verified.

[0065] Step B50: If the value to be verified is equal to the signature component r, then a self-destruct instruction is generated.

[0066] Following step S10, steps C10 to C30 are also included: Step C10 compares the timestamp with the counter value of the chip's built-in counter. If the timestamp deviation exceeds the configurable window, the self-destruct instruction information is discarded; and / or, Step C20: If the serial number does not fall within the serial number window register group or the serial number has already been used, discard the self-destruct instruction information; and / or, Step C30: If the random number exists in the random number cache, discard the self-destruct instruction information; if the random number does not exist in the random number cache, add the sequence number to the random number cache and discard the oldest sequence number in the random number cache.

[0067] Specifically, the SM3 algorithm employs a fully pipelined hardware architecture, supporting parallel computation in message blocks (512-bit blocks). Its coupling with the self-destruct instruction is as follows: Pre-computation acceleration allows the initial SM3 values ​​of fixed fields (such as magic number and type) in the instruction header to be pre-computed and stored in registers. During actual computation, only dynamic fields (timestamp and random number) need to be incrementally updated, compressing the typical hash computation time from 50 clock cycles to 15 cycles.

[0068] The SM3 engine receives instruction input from an external source, and the expected hash value is stored in the OTP. Based on the instruction, the engine outputs a real-time calculation result and compares it with a baseline value read from the OTP.

[0069] In addition, targeted anti-side-channel design is implemented. The SM3 engine employs random delay insertion and power balancing logic (all registers are flipped with pseudo-random data when idle) during the calculation process to prevent intermediate values ​​from being inferred through power consumption analysis or timing analysis.

[0070] SM2 signature verification involves elliptic curve dot product operations (scalar multiplication), which are computationally intensive. This invention provides specialized optimizations for self-destruct scenarios: The authorized public key stored in OTP uses an affine coordinate format (x, y), eliminating the need to parse the certificate every time verification is performed, saving hundreds of microseconds.

[0071] In the SM2 algorithm, the base point G of the elliptic curve is fixed. When the chip is fabricated, the pre-calculation table of G (e.g., 16 points are pre-stored using the window method) is fixed in the ROM, which improves the speed of dot multiplication by about 4 times.

[0072] The verification process consists of three steps: calculating t = (r + s) mod n; Calculate the elliptic curve point (x1, y1) = [s]G + [t]PA; Verify the value to be verified, R=r.

[0073] Specifically, during the signing phase, the signer uses their private key d_A to sign the hash value e of message M, generating (r, s). The verifier (SM2 asymmetric algorithm engine), upon receiving the signature, needs to verify its authenticity. First, it checks if r ∈ [1, n-1] and s ∈ [1, n-1]. If not, the verification fails. If successful, the signature component r and signature component s are summed and then moduloed on the order n of the elliptic curve base point to obtain the intermediate variable value t. If t=0, the verification fails; if t is not equal to 0, the elliptic curve point (x1, y1) is calculated.

[0074] The calculation method for points on an elliptic curve is expressed as follows: (x1,y1)=[s]G+[t]P_A Where (x1,y1) represents the elliptic curve point, [s]G represents incrementing the elliptic curve base point G by s times, and [t]P_A represents incrementing the public key P_A by t times. The public key p_A is stored in the one-time programmable memory of the national cryptographic authentication module in affine coordinate format.

[0075] If (x1, y1) is not at infinity, then calculate the value to be verified, R.

[0076] R = (e + x1) mod n Where e is the instruction hash value and x1 is the x-coordinate of the point on the elliptic curve.

[0077] Check if R = r is true. If true, the verification passes; otherwise, it fails.

[0078] This embodiment uses a three-stage pipeline, which can process one step per clock cycle, and the overall verification time is approximately 400 cycles (about 4μs at 100MHz).

[0079] When the result of the first step is t=0 or the result of the second step is at infinity, the hardware immediately sets a failure flag and interrupts subsequent calculations to avoid unnecessary power consumption and time waste.

[0080] To prevent attackers from intercepting legitimate self-destruct commands and retransmitting them (replay attacks), this invention integrates three hardware anti-replay mechanisms, which can be configured and used in combination: The chip incorporates a 32-bit low-power real-time counter (RTC, driven by an on-chip RC oscillator with an accuracy of ±5%). The timestamp in the instruction is compared to the RTC value; if the deviation exceeds a configurable window (e.g., ±5 seconds), the instruction is rejected. The RTC can maintain its count using a backup power source (such as an external battery or large capacitor) when the chip is powered off.

[0081] The chip maintains a 64-bit sequence number window register (implemented in SRAM). Each valid self-destruct instruction carries a 6-bit sequence number (0-63). The hardware records the most recently received sequence number; if the sequence number falls within the window and has not been used, it is accepted and the bit is marked; if the sequence number is less than the lower limit of the window or has already been used, it is rejected. The window slides automatically (when a received sequence number equals the lower limit of the window + 32, the window shifts 32 bits to the right).

[0082] The chip maintains a random number cache (FIFO structure) internally. During each authentication, it checks whether the random number carried in the instruction exists in the cache. If it exists, the authentication is rejected (replay attack); if it does not exist, it is added to the cache and pushed to the end of the FIFO, automatically evicting the oldest entry.

[0083] The above three mechanisms can be enabled independently or used in combination. The default configuration enables a time window + serial number sliding window, balancing security and implementation complexity.

[0084] Furthermore, when applied to the self-destruct control and execution module, the method also includes steps S50 to S70: Step S50: Obtain the self-destruct instruction, which includes a 1-bit valid check bit, a 4-bit hot code encoding, and a timestamp copy.

[0085] Step S60: If the valid check bit is valid, then read the hot code encoding and timestamp copy.

[0086] Step S70: If the hot code is equal to the preset code and the difference between the timestamp copy and the local timestamp of the self-destruct control and execution module is less than the preset value, then generate an ACK response and execute the self-destruct action.

[0087] Specifically, the authentication module and the self-destruct control logic communicate securely through a set of handshake signals (self-destruct instructions) to prevent single-bit signals from being tampered with by fault injection.

[0088] After the authentication module completes the SM2 / SM3 verification, it sets the hot code encoding auth_pass to 1010 (pass) or 0000 (failure), and simultaneously latches the current timestamp into auth_timestamp and sets the valid verification bit auth_valid=1.

[0089] After the self-destruct control logic (in polling state) detects that the valid verification bit auth_valid=1, it reads auth_pass and auth_timestamp.

[0090] If uth_pass==1010, and the difference between auth_timestamp and the local timestamp in the self-destruct logic is less than the preset value (e.g., 1 second), then the authentication is considered valid, and the process of de-escalation begins.

[0091] The self-destruct control logic is set to ack=1 for at least 2 clock cycles.

[0092] After the authentication module detects the ACK, it clears auth_valid and auth_pass and waits for the next instruction.

[0093] This handshake protocol prevents the following attacks: Replay authentication results: Because the timestamp changes with each authentication and the self-destruct logic only accepts one handshake, attackers cannot deceive with old successful authentication signals.

[0094] Single-bit flip attack: auth_pass uses a 4-bit hot code (1010). Any single-bit error will turn it into an illegal combination (such as 1011, 0010, etc.), and the self-destruct logic will refuse to execute.

Claims

1. A self-destruct control method for an energy storage SoC with integrated cryptographic algorithm authentication, characterized in that, A national cryptographic authentication module is applied to a storage SoC chip. The national cryptographic authentication module is independently set in the storage SoC chip. The national cryptographic authentication module obtains external destruction instructions through a dedicated self-destruct instruction interface. The national cryptographic authentication module is also communicatively connected to a self-destruct control and execution module. The methods include: The self-destruct instruction information is obtained through the self-destruct instruction interface. The self-destruct instruction information includes the original text of the self-destruct instruction and a digital signature. The SM3 hash algorithm engine is used to calculate the hash value of the self-destruct instruction plaintext to obtain the instruction hash value; The digital signature is verified using the SM2 asymmetric algorithm engine based on the pre-stored authorized public key. If the verification passes, a self-destruct instruction is generated and verified based on the instruction hash value and the signature component of the digital signature. If the verification passes, a self-destruct command is generated and output to the self-destruct control and execution module, so that the self-destruct control and execution module triggers and executes the self-destruct action based on the self-destruct command.

2. The self-destruct control method for an energy storage SoC with integrated cryptographic algorithm authentication according to claim 1, characterized in that, The step of calculating the hash value of the self-destruct instruction plaintext using the SM3 hash algorithm engine to obtain the first hash value includes: Identify the fixed and dynamic fields in the self-destruct command information; The fixed field is compared with a pre-stored fixed field. If the comparison passes, the hash value of the fixed field is determined based on the pre-stored hash value of the pre-stored fixed field. The hash value of the dynamic field is calculated, and the hash value of the fixed field is combined to determine the instruction hash value.

3. The self-destruct control method for an energy storage SoC with integrated cryptographic algorithm authentication according to claim 1, characterized in that, The step of verifying the digital signature using the SM2 asymmetric algorithm engine based on a pre-stored authorized public key, and generating a self-destruct instruction based on the instruction hash value and the signature component of the digital signature, if the verification passes, includes: To obtain a digital signature, a pipelined approach is used, executing the following steps: After summing the signature component r and the signature component of the digital signature, the summation result is moduloed with the order n of the elliptic curve base point to determine the intermediate variable value t; wherein, the elliptic curve base point is pre-stored in the chip; If the intermediate variable value t is not 0, the elliptic curve points are calculated based on the pre-stored authorized public key and the elliptic curve base points, and the calculation result is determined; wherein, the authorized public key is stored in the one-time programmable memory of the national cryptographic authentication module in affine coordinate format; If the calculation result is not the point of infinity, then the instruction hash value is summed with the x-coordinate of the elliptic curve point, and the order n of the elliptic curve base point is moduloed to determine the value to be verified. If the value to be verified is equal to the signature component r, then a self-destruct instruction is generated.

4. The self-destruct control method for an energy storage SoC with integrated cryptographic algorithm authentication according to claim 1, characterized in that, The self-destruct command information also includes a timestamp, a random number, and, after the step of obtaining the self-destruct command information through the self-destruct command interface, the following step is also included: The timestamp is compared with the counter value of the chip's built-in counter. If the deviation of the timestamp exceeds a configurable window, the self-destruct instruction information is discarded; and / or, If the serial number does not fall within the serial number window register group or the serial number has already been used, then the self-destruct instruction information is discarded; And / or, If the random number exists in the random number cache, the self-destruct instruction information is discarded; if the random number does not exist in the random number cache, the sequence number is added to the random number cache and the oldest sequence number in the random number cache is discarded.

5. The self-destruct control method for an energy storage SoC with integrated cryptographic algorithm authentication according to claim 1, characterized in that, The method, applied to the self-destruct control and execution module, further includes the following steps: Obtain a self-destruct instruction, which includes a 1-bit valid check bit, a 4-bit hot code encoding, and a timestamp copy; If the valid check bit is valid, then read the hot code and timestamp copy; If the hot code is equal to the preset code and the difference between the timestamp copy and the local timestamp of the self-destruct control and execution module is less than the preset value, then an ACK response is generated and the self-destruct action is executed.

6. A SoC chip with integrated cryptographic algorithm authentication and energy storage, the SoC chip comprising a main control and storage core region, the main control and storage core region comprising a processor core, a non-volatile memory array, and a storage read / write control circuit, characterized in that, It also includes an independently set national cryptographic authentication module, which obtains external destruction commands through a dedicated self-destruct command interface, and is also communicatively connected to the self-destruct control and execution module; The national cryptographic authentication module includes a hardware parser located at the front end of the self-destruct command interface, used to obtain self-destruct command information, which includes the original text of the self-destruct command and a digital signature; The SM3 hash algorithm engine is used to calculate the hash value of the self-destruct instruction plaintext to obtain the instruction hash value; The SM2 asymmetric algorithm engine is used to verify the digital signature based on the pre-stored authorized public key. If the verification passes, a self-destruct instruction is generated and verified based on the instruction hash value and the signature component of the digital signature. One-time programmable memory is used to store the authorization public key, authentication policy, and chip unique identifier; The self-destruct control and execution module includes a self-destruct control logic unit, which is used to generate a self-destruct trigger signal based on the self-destruct command output by the national cryptographic authentication module; An energetic self-destruct mechanism disposed on the chip substrate is used to perform a self-destruct action based on a self-destruct trigger signal.

7. The SoC chip with integrated cryptographic algorithm authentication according to claim 6, characterized in that, The authorized public key stored in the one-time programmable memory is encrypted using SM4 with a PUF key. After the chip is powered on, the hardware automatically decrypts it and loads it into the SM2 asymmetric algorithm engine. The data lines and address lines of the one-time programmable memory are routed at the bottom layer of the metal layer, and the upper metal layer covers the dynamic pseudo signal. The read path of the one-time programmable memory integrates a temperature sensor and a voltage sensor. When the chip operates outside the set temperature range and / or set voltage range, the read output of the one-time programmable memory is forced to zero.

8. The SoC chip with integrated cryptographic algorithm authentication according to claim 6, characterized in that, The SM3 hash algorithm engine, the SM2 asymmetric algorithm engine, and the one-time programmable memory are each powered by an independent low-dropout linear regulator. The self-destruct instruction interface uses an externally input clock, while the SM3 hash algorithm engine and the SM2 asymmetric algorithm engine use a fixed clock generated by an internal PLL. The two clock domains exchange data through an asynchronous FIFO buffer.