Implementation method and device for preventing disassembly and electromagnetic side channel attack

CN122885986APending Publication Date: 2026-10-09BEIJING MICROCHIP SENSING TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610702650.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-05-21
Publication Date
2026-10-09

AI Technical Summary

Technical Problem

此外,当系统内部各检测模块与主控芯片之间的通信物理链路被恶意切断时,现有的响应机制往往陷入瘫痪,无法在脱离外部干预的情况下自主完成物理隔离与逻辑自毁

Benefits of technology

(1)本发明通过将核心电路包覆在采用一体化密封结构的封闭金属防护罩内,利用其内表面与核心电路之间形成寄生电容以及金属导体结构自身形成寄生电感,共同构成LC微波谐振腔体结构。电磁场域完整性检测模块向封闭金属防护罩发送探测信号并接收反馈信号,在发生机械刺探或化学腐蚀等物理破坏行为时,空间分布参数的改变会打破稳态分布,并同步引起反馈信号携带的频域特征与幅值特征产生偏移。该机制克服了传统机械卡扣或接触式开关容易被绕过的缺陷,能够精准识别微小的防护罩破坏行为,提升了物理防拆检测的可靠性。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122885986A_ABST
    Figure CN122885986A_ABST
Patent Text Reader

Abstract

The application relates to the technical field of electronic equipment hardware security protection, and discloses an implementation method and device for anti-disassembly and anti-electromagnetic side channel attack, which comprises a closed metal protective cover, an electromagnetic field domain integrity detection module, an active protection triggering module, an active electromagnetic shielding module and a core circuit. Heartbeat signals are continuously exchanged between the modules, the active protection triggering module sends a first message notification to the core circuit when receiving an attack signal or generating an internal triggering signal due to not receiving the heartbeat signal, the core circuit disconnects a power supply circuit, sets a hardware security pin state and executes a data area erasing operation, and high-sensitivity physical anti-disassembly detection, side channel active inhibition and hardware level self-destruction are realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of hardware security protection technology for electronic devices, specifically to a method and apparatus for preventing tampering and electromagnetic side-channel attacks. Background Technology

[0002] With the continuous development of information security technology, electronic devices carrying core confidential data face increasingly complex threats from physical intrusion and side-channel attacks. To protect the keys and sensitive data within the core circuitry, the industry typically sets up protective structures externally to the device, along with corresponding security detection mechanisms. However, existing hardware protection solutions have the following technical shortcomings in practical applications:

[0003] In terms of physical tamper detection, existing protective designs mostly employ mechanical microswitches, photoelectric sensors, or conductive meshes printed on the surface of circuit boards. These detection mechanisms, based on physical contact or simple DC electrical connectivity, inherently have assembly gaps and mechanical tolerances. Attackers can bypass detection nodes without triggering alarm circuits by using micro-hole probing, injecting conductive liquids, or applying chemical reagents for localized corrosion. Traditional physical switches and conductive meshes lack the sensitivity to detect minor deformations or non-penetrating damage to the protective casing, resulting in low reliability of the protective layer.

[0004] Regarding electromagnetic leakage protection, the core circuit generates electromagnetic radiation, including clock frequency and power supply ripple, during cryptographic operations and data interaction, accompanied by logic state transitions. Existing electromagnetic protection methods mainly rely on passive shielding using a single metal mesh. Passive shielding can only attenuate the overall field strength amplitude of the radiated signal; it cannot change the signal-to-noise ratio of the original electromagnetic leakage signal itself. External attackers, using high-gain antennas and high-sensitivity spectrum analysis equipment, can still capture residual electromagnetic signals from outside the shielding layer and then extract the working key inside the core circuit using side-channel techniques such as differential electromagnetic analysis.

[0005] In terms of protective responses to detected anomalous behavior, existing security devices generally rely on the software logic within the main control chip to execute power-off or data destruction procedures. Software-level responses are limited by the instruction execution cycle, resulting in millisecond-level delays. Attackers can exploit fault injection, clock glitches, or directly cut off physical power to freeze the chip's operating state before the software response routine completes, thereby preventing key erasure. Furthermore, when the physical communication links between the various detection modules and the main control chip are maliciously severed, existing response mechanisms often become paralyzed, unable to autonomously complete physical isolation and logical self-destruction without external intervention. Summary of the Invention

[0006] To achieve the above objectives, the present invention provides the following technical solution: a method for preventing tampering and electromagnetic side-channel attacks, applied to a device for preventing tampering and electromagnetic side-channel attacks, wherein the device includes a sealed metal protective cover, an electromagnetic field integrity detection module, an active protection triggering module, an active electromagnetic shielding module, and a core circuit; the method includes: During the initialization phase, the electromagnetic field integrity detection module sends a detection signal to the enclosed metal shield and receives a feedback signal returned by the enclosed metal shield. The electromagnetic field integrity detection module calculates an initial electromagnetic characteristic reference value based on the feedback signal and writes the initial electromagnetic characteristic reference value into the non-volatile storage unit built into the electromagnetic field integrity detection module. The device for preventing tampering and electromagnetic side-channel attacks enters the working phase; the electromagnetic field integrity detection module sends the detection signal to the closed metal protective cover at a preset time period and receives the feedback signal returned by the closed metal protective cover; the electromagnetic field integrity detection module calculates real-time electromagnetic characteristic parameters based on the feedback signal; During the operation phase, the active electromagnetic shielding module synchronously receives leakage frequency band reference information sent by the core circuit; the active electromagnetic shielding module generates and emits interfering electromagnetic waves based on the leakage frequency band reference information; the interfering electromagnetic waves contain noise waveforms with the same frequency band as the leakage frequency band reference information. The electromagnetic field integrity detection module compares the real-time electromagnetic feature parameters with the initial electromagnetic feature reference value, and calculates the feature difference between the real-time electromagnetic feature parameters and the initial electromagnetic feature reference value; the electromagnetic field integrity detection module compares the feature difference with a set threshold parameter, and when the feature difference is greater than or equal to the set threshold parameter, the electromagnetic field integrity detection module generates a status report and an attack signal, and sends the attack signal to the active protection triggering module; The electromagnetic field integrity detection module, the active protection triggering module, and the active electromagnetic shielding module continuously interact with a heartbeat signal containing count data and scrambling code data at fixed time intervals; the active protection triggering module parses the count data and scrambling code data contained in the heartbeat signal; when the active protection triggering module does not receive the heartbeat signal containing the corresponding count data and the corresponding scrambling code data within a preset time window, it generates an internal trigger signal. When the active protection triggering module receives the attack signal or generates the internal trigger signal, it sends a first message notification to the core circuit. The core circuit receives the first message notification and, according to the first message notification, disconnects the power supply line of the core circuit, sets the hardware security pin state of the core circuit, and performs a data area erasure operation to destroy the internal storage data of the core circuit.

[0007] Preferably, the enclosed metal protective cover is made of conductive metal material, the main body of the enclosed metal protective cover is formed by stamping process, and the structural joint parts are connected by welding sealing process to form a continuous metal conductive boundary; The enclosed metal protective cover forms a closed physical cavity, and the physical cavity and the core circuit together form a basic electromagnetic field. The enclosed metal protective cover has a physical anti-tamper state corresponding to the structural integrity. The physical anti-tamper state includes no mechanical probing damage, no chemical corrosion through the wall, no surface opening, and no prying of the joint. When mechanical probing, chemical corrosion, surface opening, or prying of joints occur, the continuous conductive metal boundary of the enclosed metal protective cover is disrupted, causing a change in the boundary conditions of the basic electromagnetic field domain and simultaneously triggering a shift in the electromagnetic parameters inside the basic electromagnetic field domain.

[0008] Preferably, a parasitic capacitance is formed between the inner surface of the enclosed metal shield and the core circuit, and the metal conductor structure of the enclosed metal shield itself forms a parasitic inductance; the parasitic capacitance and the parasitic inductance are distributed within the physical cavity and together with the enclosed metal shield constitute an LC microwave resonant cavity structure; the electromagnetic field integrity detection module employs a resonance detection method for the LC microwave resonant cavity structure, specifically including: The electromagnetic field integrity detection module pre-stores the size parameters and dielectric parameters of the LC microwave resonant cavity structure, and calculates the theoretical natural resonant frequency based on the size parameters and dielectric parameters. The electromagnetic field integrity detection module sends the detection signal with the theoretical natural resonant frequency as the center frequency during the initialization phase, and extracts the initial natural resonant frequency data and initial natural resonant amplitude data corresponding to the resonant peak from the feedback signal to form the initial electromagnetic characteristic reference value. The electromagnetic field integrity detection module starts its built-in hardware timer unit during the working phase and sends the detection signal according to the time period set by the hardware timer unit. The frequency sweep range of the detection signal is limited to a preset frequency offset interval centered on the initial inherent resonant frequency data. The electromagnetic field integrity detection module extracts real-time resonant frequency data and real-time resonant amplitude data from the feedback signal to form the real-time electromagnetic characteristic parameters. The electromagnetic field integrity detection module calculates the frequency offset difference between the real-time resonant frequency data and the initial inherent resonant frequency data as the feature difference; the set threshold parameter includes a frequency offset threshold and an amplitude ratio threshold; if the absolute value of the frequency offset difference is greater than or equal to the frequency offset threshold, or if the ratio of the real-time resonant amplitude data to the initial inherent resonant amplitude data is less than or equal to the amplitude ratio threshold, it is determined that the physical structure of the enclosed metal protective shield has been damaged, and the status report and the attack signal are output.

[0009] Preferably, the electromagnetic field integrity detection module employs a detection method based on multiple-input multiple-output channel characteristics, specifically including: The electromagnetic field integrity detection module transmits standard training signals as detection signals through M transmitting antennas arranged inside the closed metal protective cover during the initialization phase, and receives feedback training signals superimposed by the electromagnetic environment inside the closed metal protective cover through N receiving antennas as feedback signals, where M and N are positive integers greater than or equal to 1. The electromagnetic field integrity detection module constructs an initial channel estimation matrix of dimension M×N based on the standard training signal and the feedback training signal, and performs eigenvalue decomposition or singular value decomposition on the initial channel estimation matrix to extract the initial eigenvalue vector as the initial electromagnetic feature reference value. The electromagnetic field integrity detection module initiates a timed detection process during the working phase, transmitting the standard training signal through the M transmitting antennas at a preset time period, and receiving the real-time feedback training signal through the N receiving antennas; the electromagnetic field integrity detection module constructs a real-time channel estimation matrix with a dimension of M×N, and decomposes and calculates the real-time channel estimation matrix to extract real-time feature vectors as the real-time electromagnetic feature parameters. The electromagnetic field integrity detection module calculates the eigenvalue norm difference between the real-time eigenvalue vector and the initial eigenvalue vector as the eigenvalue difference; the set threshold parameter includes a norm threshold; when the eigenvalue norm difference is greater than or equal to the norm threshold, the status report and the attack signal are generated.

[0010] Preferably, the active electromagnetic shielding module is equipped with a noise suppression mechanism in the same frequency band, specifically including: The core circuit generates an accompanying electromagnetic leakage signal when performing logical operations and data interaction operations; the core circuit extracts the center frequency data and bandwidth data of the electromagnetic leakage signal, and packages the center frequency data and bandwidth data as the leakage frequency band reference information, and sends it to the active electromagnetic shielding module. The active electromagnetic shielding module generates a pseudo-random noise waveform based on the center frequency data and bandwidth data in the leakage frequency band reference information through a built-in signal generation unit; the spectral distribution range of the pseudo-random noise waveform covers the frequency band range of the electromagnetic leakage signal. The active electromagnetic shielding module adjusts the transmission power level of the pseudo-random noise waveform through a built-in radio frequency power control circuit, and sets the output power of the pseudo-random noise waveform to a preset power margin higher than the original radiated power of the electromagnetic leakage signal. The active electromagnetic shielding module transmits the pseudo-random noise waveform, which has been amplified by power, as the interfering electromagnetic wave into the internal cavity of the enclosed metal shield. The wave superimposes with the electromagnetic leakage signal along the spatial propagation path, thereby raising the electromagnetic noise floor of the internal cavity of the enclosed metal shield.

[0011] Preferably, the core circuit generates a raw periodic leakage signal, including power supply ripple signal and clock radiation signal, during the operation phase. The active electromagnetic shielding module acquires the original periodic leakage signal generated by the core circuit in real time through a built-in signal acquisition bypass. The acquired original periodic leakage signal is input to the built-in phase-shifting network circuit, and the phase-shifting network circuit is used to invert the original periodic leakage signal to generate an inverted cancellation signal corresponding to the original periodic leakage signal. The phase of the inverted cancellation signal is 180 degrees out of phase with the original periodic leakage signal. The active electromagnetic shielding module linearly superimposes the anti-phase cancellation signal and the pseudo-random noise waveform through a built-in signal superimposition device to generate a composite interference electromagnetic wave, and then emits the composite interference electromagnetic wave as the interference electromagnetic wave into the internal cavity of the closed metal protective cover.

[0012] Preferably, a hardwired link for transmitting the attack signal is established between the electromagnetic field integrity detection module and the active protection trigger module. During the protection triggering phase that generates the attack signal, the hard-wired link transmitting the attack signal jumps to a high-level state; the active protection triggering module receives the high-level state through the level enable terminal of the built-in high-speed analog switch circuit, and immediately shuts off the internal channel in the high-level state, thereby disconnecting the power transmission loop from the main power supply of the device to the power supply pin configured in the core circuit, as a specific implementation of disconnecting the power supply line of the core circuit; The trigger terminal of the active protection trigger module establishes a direct wire path with the hardware security lock pin configured in the core circuit; the active protection trigger module inputs the high-level state of the attack signal as the first message notification to the hardware security lock pin; the core circuit directly activates the chip hardware lock state machine according to the first message notification, as a specific implementation of setting the hardware security pin state of the core circuit.

[0013] Preferably, the core circuit includes a main control unit, an external storage unit, an internal random access memory, a network communication unit, and an energy storage capacitor; the main control unit has an external interrupt pin; the energy storage capacitor is connected to the power supply pin. The trigger terminal of the active protection trigger module establishes a hard-wired connection with the external interrupt pin, and uses the rising edge transition of the attack signal as the trigger condition to input a hardware interrupt signal to the external interrupt pin; the main control unit enters the non-maskable interrupt service routine according to the hardware interrupt signal; After the high-speed analog switch circuit disconnects the power transmission circuit from the main power supply of the device to the power pin, the energy storage capacitor connected to the power pin enters the discharge state to provide operating power for the main control unit, the external storage unit, the internal random access memory and the network communication unit. The main control unit uses the operating power to send multiple rounds of write-and-erase instructions to the key storage area in the external storage unit in the non-maskable interrupt service routine, so as to destroy the persistently stored working key and session key data; while executing the multiple rounds of write-and-erase instructions, the main control unit performs a memory zeroing operation on the cryptographic operation intermediate state data in the internal random access memory, as a specific implementation of the data area erasure operation; After executing the multi-round write-and-erase instructions and the memory clearing operation, the main control unit sets the tamper-proof flag in the built-in one-time programmable storage area. The main control unit uses the operating power to generate encrypted alarm data packets and sends the encrypted alarm data packets to the remote cloud server through the network communication unit.

[0014] Preferably, the electromagnetic field integrity detection module and the active electromagnetic shielding module respectively generate the count value data and extract the internally fixed device identification code data. The count value data is then scrambled according to the device identification code data to generate the scrambled data, which is packaged into a first heartbeat signal and a second heartbeat signal and sent to the active protection triggering module to form the heartbeat signal. The active protection trigger module has a built-in heartbeat verification unit, a communication timeout timer, and a logic OR gate circuit; the communication timeout timer is connected to the signal output terminal of the heartbeat verification unit. The heartbeat verification unit verifies the count data and scrambling code data carried by the first heartbeat signal and the second heartbeat signal; if the verification is successful, the heartbeat verification unit outputs a timeout reset signal to the communication timeout timer; if the verification fails, the heartbeat verification unit stops outputting the timeout reset signal. When the communication timeout timer does not receive the timer reset signal and the internal timer value accumulates to the preset timeout threshold, a timer overflow action is triggered, and the internal trigger signal is generated based on the timer overflow action. The active protection triggering module connects the internal trigger signal and the attack signal to the input terminal of the logic OR gate circuit respectively, and outputs a high-level state to the level enable terminal of the high-speed analog switch circuit and the hardware security lock pin through the output terminal of the logic OR gate circuit respectively.

[0015] Preferably, a device for preventing tampering and electromagnetic side-channel attacks includes: a closed metal protective cover, an electromagnetic field integrity detection module, an active protection triggering module, an active electromagnetic shielding module, and a core circuit. The enclosed metal protective cover is located outside the core circuit and covers the core circuit to form an electromagnetic shielding cavity; The electromagnetic field integrity detection module is used to perform the steps executed by the electromagnetic field integrity detection module in the above method; The active protection triggering module is used to execute the steps performed by the active protection triggering module in the above method; The active electromagnetic shielding module is used to perform the steps executed by the active electromagnetic shielding module in the above method; The core circuit is used to perform the steps in the above method executed by the core circuit.

[0016] This invention provides a method and apparatus for preventing tampering and electromagnetic side-channel attacks. It offers the following advantages: (1) This invention encloses the core circuit within a sealed metal shield with an integrated sealing structure. The parasitic capacitance formed between the inner surface of the shield and the core circuit, along with the parasitic inductance formed by the metal conductor structure itself, together constitute an LC microwave resonant cavity structure. The electromagnetic field integrity detection module sends a detection signal to the sealed metal shield and receives a feedback signal. When physical damage such as mechanical probing or chemical corrosion occurs, the change in spatial distribution parameters disrupts the steady-state distribution and simultaneously causes a shift in the frequency and amplitude characteristics carried by the feedback signal. This mechanism overcomes the shortcomings of traditional mechanical latches or contact switches, which are easily bypassed. It can accurately identify minute acts of damage to the shield, improving the reliability of physical anti-tamper detection.

[0017] (2) This invention receives the leakage frequency band reference information sent by the core circuit through an active electromagnetic shielding module, and uses a signal generation unit to generate a pseudo-random noise waveform based on the center frequency data and bandwidth data. The pseudo-random noise waveform, after power amplification, is emitted as an interfering electromagnetic wave into the internal cavity to raise the electromagnetic noise floor and reduce the signal-to-noise ratio of the electromagnetic leakage signal. At the same time, an anti-phase cancellation signal is generated using a phase-shifting network circuit, which cancels out the interference of the original periodic leakage signal wave in the spatial electromagnetic field. By combining the same-band noise suppression mechanism with phase cancellation technology, the transmission path for external spectrum analysis equipment to obtain data from the core circuit is effectively blocked.

[0018] (3) This invention immediately shuts off the internal channel by turning off the enable terminal of the high-speed analog switch circuit, thereby disconnecting the power supply circuit from the main power supply of the device to the power pin, and limiting the hardware response time for starting the physical isolation program to within 10 microseconds. In addition, the system uses a heartbeat verification unit to verify the count value data and scrambling code data contained in the heartbeat signal. When the timer overflows and generates an internal trigger signal, a high-level state is output through a logic OR gate circuit, directly activating the chip hardware lock-up state machine and entering the non-maskable interrupt service routine to perform multiple rounds of data area write-and-erase operations, effectively preventing external probe devices from reading internal confidential data through physical intrusion. Attached Figure Description

[0019] Figure 1 This is a schematic diagram of the device module of the present invention; Figure 2 This is a schematic diagram of the method flow of the present invention. Detailed Implementation

[0020] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0021] Please see Figure 1 - Figure 2 The present invention provides a device for preventing tampering and electromagnetic side-channel attacks, comprising: a closed metal protective cover, an electromagnetic field integrity detection module, an active protection triggering module, an active electromagnetic shielding module, and a core circuit.

[0022] An enclosed metal shield is placed outside the core circuit and covers the core circuit to form an electromagnetic shielding cavity; the enclosed metal shield serves as the electromagnetic field detection carrier for the electromagnetic field integrity detection module.

[0023] The electromagnetic field integrity detection module is connected to the enclosed metal shield and is used to send detection signals to the enclosed metal shield and receive feedback signals returned by the enclosed metal shield. The electromagnetic field integrity detection module calculates the change in electromagnetic field parameters based on the feedback signals and generates status reports and attack signals based on the change in electromagnetic field parameters.

[0024] The electromagnetic field integrity detection module is connected to the active protection trigger module and is used to send status reports and attack signals to the active protection trigger module.

[0025] The active protection trigger module is connected to the core circuit and is used to receive the attack signal sent by the electromagnetic field integrity detection module, and send a first message notification to the core circuit according to the attack signal; the first message notification instructs the core circuit to perform a key erasure operation, a chip lock-up operation, or a power-off operation.

[0026] The active electromagnetic shielding module is connected to the core circuit and is used to receive the leakage frequency band reference information sent by the core circuit and to emit interfering electromagnetic waves according to the leakage frequency band reference information; the active electromagnetic shielding module is also used to send a third message notification to the core circuit.

[0027] The active electromagnetic shielding module is connected to the active protection triggering module and is used to send a second message notification to the active protection triggering module.

[0028] The electromagnetic field integrity detection module, active protection trigger module, and active electromagnetic shielding module are connected by hardwire and exchange heartbeat signals with each other; the heartbeat signal contains count data and scrambling code data; when the active protection trigger module does not receive a heartbeat signal, it sends a first message notification to the core circuit.

[0029] Based on the above, the present invention also provides a method for preventing tampering and electromagnetic side-channel attacks, specifically: During the initialization phase, the electromagnetic field integrity detection module sends a detection signal to the enclosed metal shield and receives a feedback signal returned by the enclosed metal shield. The electromagnetic field integrity detection module calculates the initial electromagnetic characteristic reference value based on the feedback signal and writes the initial electromagnetic characteristic reference value into the non-volatile storage unit built into the electromagnetic field integrity detection module.

[0030] The anti-tampering and anti-electromagnetic side-channel attack devices enter the operational phase. The electromagnetic field integrity detection module sends detection signals to the enclosed metal protective cover at preset time intervals and receives feedback signals returned by the enclosed metal protective cover; the electromagnetic field integrity detection module calculates real-time electromagnetic characteristic parameters based on the feedback signals.

[0031] During operation, the active electromagnetic shielding module synchronously receives leakage frequency band reference information sent by the core circuit; the active electromagnetic shielding module generates and emits interfering electromagnetic waves based on the leakage frequency band reference information; the interfering electromagnetic waves contain noise waveforms in the same frequency band as the leakage frequency band reference information.

[0032] The electromagnetic field integrity detection module compares the real-time electromagnetic characteristic parameters with the initial electromagnetic characteristic reference value and calculates the characteristic difference between the real-time electromagnetic characteristic parameters and the initial electromagnetic characteristic reference value. The electromagnetic field integrity detection module compares the characteristic difference with a set threshold parameter. When the characteristic difference is greater than or equal to the set threshold parameter, the electromagnetic field integrity detection module generates a status report and an attack signal and sends the attack signal to the active protection triggering module.

[0033] The electromagnetic field integrity detection module, the active protection trigger module, and the active electromagnetic shielding module continuously exchange heartbeat signals at fixed time intervals; the active protection trigger module parses the count value data and scrambling code data contained in the heartbeat signal; when the active protection trigger module does not receive a heartbeat signal containing the corresponding count value data and the corresponding scrambling code data within a preset time window, it generates an internal trigger signal.

[0034] When the active protection trigger module receives an attack signal or generates an internal trigger signal, it sends a first message notification to the core circuit. The core circuit receives the first message notification and, according to the first message notification, disconnects the power supply line of the core circuit, sets the hardware security pin status of the core circuit, and performs a data area erasure operation to destroy the internal storage data of the core circuit.

[0035] Furthermore, the enclosed metal protective cover adopts an integrated sealing structure. The enclosed metal protective cover is made of conductive metal material. The main body of the enclosed metal protective cover is formed by stamping process, and the structural joints are connected by welding sealing process to form a continuous metal conductive boundary.

[0036] Continuous conductive metal boundaries are used to eliminate physical assembly gaps caused by mechanical snap-fit ​​connections, thereby cutting off the leakage and transmission paths of electromagnetic signals.

[0037] The enclosed metal shield forms a closed physical cavity, which together with the core circuit forms the basic electromagnetic field domain. The enclosed metal shield maintains the steady-state distribution of electromagnetic parameters inside the basic electromagnetic field domain through continuous conductive metal boundaries. The steady-state distribution serves as the physical environment basis for the electromagnetic field domain integrity detection module to perform benchmark calibration and difference comparison.

[0038] The enclosed metal protective cover has a physical anti-tampering state corresponding to the structural integrity; the physical anti-tampering state includes no mechanical piercing damage, no chemical corrosion through the wall, no surface opening, and no prying of the joints.

[0039] When mechanical probing, chemical corrosion, surface opening, or prying of joints occur, the continuous conductive metal boundary of the enclosed metal protective shield is disrupted, which in turn causes a change in the boundary conditions of the basic electromagnetic field domain and simultaneously triggers a shift in the electromagnetic parameters inside the basic electromagnetic field domain.

[0040] The enclosed metal shield prevents the leakage of electromagnetic waves radiated by the core circuit during operation and blocks the detection electromagnetic waves from the external environment from entering the physical cavity; the enclosed metal shield serves as the hardware carrier for the electromagnetic field integrity detection module to output detection signals inward and extract feedback signals outward.

[0041] Furthermore, the enclosed metal protective cover possesses electromagnetic field containment characteristics corresponding to the basic electromagnetic field domain.

[0042] Parasitic capacitance is formed between the inner surface of the enclosed metal shield and the core circuit, and the metal conductor structure of the enclosed metal shield itself forms parasitic inductance; the parasitic capacitance and parasitic inductance are distributed in the physical cavity and together with the enclosed metal shield constitute the LC microwave resonant cavity structure.

[0043] The enclosed metal shield utilizes the electromagnetic field enclosure characteristics to attenuate the internal electromagnetic leakage signals generated by the core circuit during operation, thereby blocking the propagation path of the internal electromagnetic leakage signals to the external space; at the same time, the enclosed metal shield isolates spatial electromagnetic interference in the external environment and maintains the stability of the electromagnetic environment inside the basic electromagnetic field domain.

[0044] The LC microwave resonant cavity structure constrains the propagation boundary of the detection signal, causing the detection signal to be reflected and resonated inside the physical cavity; the geometric dimensions of the enclosed metal protective cover, the permeability of the material, and the equivalent permittivity of the medium in which the core circuit is located jointly determine the inherent resonant state of the basic electromagnetic field.

[0045] The enclosed metal shield modulates the detection signal through its inherent resonant state to generate a feedback signal; the feedback signal carries frequency domain characteristics and amplitude characteristics that reflect the structural continuity of the enclosed metal shield.

[0046] When physical damage occurs, such as mechanical probing or chemical corrosion, against the enclosed metal protective cover, the physical structure of the LC microwave resonant cavity is damaged, which in turn leads to changes in the spatial distribution parameters of parasitic capacitance and parasitic inductance. The change in spatial distribution parameters disrupts the steady-state distribution of the basic electromagnetic field and simultaneously causes a shift in the frequency domain characteristics and amplitude characteristics carried by the feedback signal.

[0047] Furthermore, the electromagnetic field integrity detection module employs a resonance detection method for LC microwave resonant cavity structures to perform parameter calibration and state comparison.

[0048] The electromagnetic field integrity detection module pre-stores the dimensional and dielectric parameters of the LC microwave resonant cavity structure; based on these parameters, it calculates the theoretical natural resonant frequency. The formula for calculating the theoretical natural resonant frequency is:

[0049] In the formula, Represents the theoretically inherent resonant frequency. Represents the speed of light in a vacuum. The equivalent relative permittivity represents the dielectric constant of the medium in which the core circuit is located. The relative permeability representing the enclosed metal protective shield. This represents the internal length of the enclosed metal protective shield. This represents the internal width of the enclosed metal protective shield. This represents the internal height of the enclosed metal protective shield. , , These represent the resonant mode parameters. In the reference calibration calculation, the resonant mode parameters... , , The values ​​are 1, 0, and 0.

[0050] During the initialization phase, the electromagnetic field integrity detection module sends a probe signal with the theoretical natural resonant frequency as the center frequency, so that the probe signal constitutes a frequency sweep test signal. The electromagnetic field integrity detection module receives the feedback signal corresponding to the frequency sweep test signal and extracts the initial electromagnetic characteristic reference value of the corresponding resonant peak from the feedback signal. The initial electromagnetic characteristic reference value includes the initial natural resonant frequency data and the initial natural resonant amplitude data.

[0051] The electromagnetic field integrity detection module has a built-in hardware timer unit. During operation, the module activates the hardware timer unit and sends detection signals according to the time period set by the timer unit. During operation, the frequency sweep range of the detection signal is limited to a preset frequency offset interval centered on the initial inherent resonant frequency data to achieve precise directional detection. The module receives feedback signals and extracts real-time electromagnetic characteristic parameters from them; these parameters include real-time resonant frequency data and real-time resonant amplitude data.

[0052] The electromagnetic field integrity detection module calculates the frequency offset difference between the real-time resonant frequency data and the initial inherent resonant frequency data. Threshold parameters include a frequency offset threshold and an amplitude ratio threshold. In a specific embodiment of the invention, the frequency offset threshold is set to 500 kHz, and the amplitude ratio threshold is set to 0.5.

[0053] If the absolute value of the frequency offset difference is greater than or equal to the frequency offset threshold, or if the ratio of the real-time resonance amplitude data to the initial inherent resonance amplitude data is less than or equal to the amplitude ratio threshold, the electromagnetic field integrity detection module determines that the physical structure of the enclosed metal protective cover has been damaged and outputs a status report and attack signal.

[0054] Furthermore, the electromagnetic field integrity detection module employs a detection method based on multiple-input multiple-output channel characteristics.

[0055] The electromagnetic field integrity detection module is equipped with M transmitting antennas and N receiving antennas arranged inside a closed metal protective cover, where M and N are positive integers greater than or equal to 1.

[0056] During the initialization phase, the electromagnetic field integrity detection module transmits standard training signals through M transmitting antennas; these standard training signals serve as the specific form of the detection signals. N receiving antennas receive feedback training signals superimposed on the electromagnetic environment inside the enclosed metal shield; these feedback training signals serve as the specific form of the feedback signals.

[0057] The electromagnetic field integrity detection module constructs a dimension-10000-dimensional array based on the standard training signal and the feedback training signal. The initial channel estimation matrix; the initial channel estimation matrix characterizes the basic electromagnetic field characteristics of the enclosed metal shield under the condition of no physical damage.

[0058] The electromagnetic field integrity detection module performs eigenvalue decomposition or singular value decomposition on the initial channel estimation matrix to extract an initial eigenvalue vector; the initial eigenvalue vector contains multiple initial eigenvalues. ,in The range of values ​​is to The electromagnetic field integrity detection module writes the initial feature value vector into the non-volatile storage unit built into the electromagnetic field integrity detection module.

[0059] The electromagnetic field integrity detection module initiates a timed detection process during operation, sending standard training signals through M transmitting antennas at preset time intervals and receiving real-time feedback training signals through N receiving antennas.

[0060] The electromagnetic field integrity detection module constructs a real-time dimension of [dimensionality missing]. The real-time channel estimation matrix is ​​calculated, and then decomposed to extract the real-time eigenvalue vector; the real-time eigenvalue vector contains multiple real-time eigenvalues. .

[0061] The electromagnetic field integrity detection module calculates the eigenvalue norm difference between the real-time eigenvalue vector and the initial eigenvalue vector. The formula for calculating the eigenvalue norm difference is:

[0062] In the formula, Represents the norm difference of eigenvalues. Represented by real-time feature values The constructed real-time feature vector, Represents the initial eigenvalues The initial eigenvalue vector is formed. Represents the selected norm calculation standard. The value can be set to 0, 1 or 2.

[0063] The electromagnetic field integrity detection module stores a norm threshold. It compares the eigenvalue norm difference with the norm threshold; when the eigenvalue norm difference is greater than or equal to the norm threshold, the module generates a status report and an attack signal.

[0064] As a way to reduce computational power consumption, the electromagnetic field integrity detection module directly calculates the channel matrix difference value between the real-time channel estimation matrix and the initial channel estimation matrix, and compares the channel matrix difference value with the matrix difference threshold. When the channel matrix difference value is greater than or equal to the matrix difference threshold, the electromagnetic field integrity detection module generates a status report and an attack signal.

[0065] In a single-input single-output implementation where both M and N are equal to 1, the electromagnetic field integrity detection module compares the electromagnetic field strength data or signal amplitude data of the standard training signal and the feedback training signal to determine whether the physical structure of the enclosed metal protective cover has been damaged.

[0066] The active electromagnetic shielding module is equipped with a noise suppression mechanism in the same frequency band to resist side-channel attacks.

[0067] The core circuit generates accompanying electromagnetic leakage signals when performing logical operations and data interaction. The core circuit extracts the center frequency data and bandwidth data of the electromagnetic leakage signal, and packages the center frequency data and bandwidth data as leakage frequency band reference information, and sends them to the active electromagnetic shielding module.

[0068] The active electromagnetic shielding module receives reference information for the leakage frequency band; the active electromagnetic shielding module has a built-in signal generation unit; the active electromagnetic shielding module generates a pseudo-random noise waveform using the signal generation unit based on the center frequency data and bandwidth data in the leakage frequency band reference information; the spectral distribution range of the pseudo-random noise waveform covers the frequency band range of the electromagnetic leakage signal.

[0069] The active electromagnetic shielding module has a built-in radio frequency power control circuit. The active electromagnetic shielding module adjusts the transmission power level of the pseudo-random noise waveform through the radio frequency power control circuit, and sets the output power of the pseudo-random noise waveform to a preset power margin higher than the original radiated power of the electromagnetic leakage signal. In a specific embodiment of the invention, the preset power margin is set to 20dB to 30dB.

[0070] The active electromagnetic shielding module uses amplified pseudo-random noise waveforms as interference electromagnetic waves and emits them into the internal cavity of the enclosed metal shield. The interference electromagnetic waves superimpose with the electromagnetic leakage signal on the spatial propagation path to raise the electromagnetic noise floor of the internal cavity of the enclosed metal shield, thereby reducing the signal-to-noise ratio of the electromagnetic leakage signal.

[0071] The noise suppression effect of the interfering electromagnetic waves and the physical attenuation effect of the enclosed metal shield are superimposed simultaneously, so that the residual leakage electromagnetic field strength that penetrates the enclosed metal shield and radiates to the external environment is lower than the limited field strength threshold; in a specific embodiment of the present invention, the limited field strength threshold is set to -100dBm; the active electromagnetic shielding module blocks the transmission path of external spectrum analysis equipment to obtain data inside the core circuit by reducing the signal-to-noise ratio and field strength amplitude.

[0072] During operation, the core circuit generates raw periodic leakage signals, including power supply ripple signals and clock radiation signals. The active electromagnetic shielding module has a built-in signal acquisition bypass, which collects the raw periodic leakage signals generated by the core circuit in real time.

[0073] The active electromagnetic shielding module has a built-in phase-shifting network circuit. The active electromagnetic shielding module inputs the acquired original periodic leakage signal to the phase-shifting network circuit, and uses the phase-shifting network circuit to invert the original periodic leakage signal to generate an inverted cancellation signal corresponding to the original periodic leakage signal. The phase of the inverted cancellation signal is 180 degrees out of phase with the phase of the original periodic leakage signal.

[0074] The active electromagnetic shielding module has a built-in signal superimposed device. The active electromagnetic shielding module linearly superimposes the anti-phase cancellation signal and the pseudo-random noise waveform through the signal superimposed device to generate a composite interference electromagnetic wave, and then emits the composite interference electromagnetic wave as an interference electromagnetic wave into the internal cavity of the closed metal protective cover.

[0075] The anti-phase cancellation signal in the composite interference electromagnetic wave interferes with the original periodic leakage signal in the spatial electromagnetic field, thereby reducing the amplitude of the radiation waveform of the original periodic leakage signal. At the same time, the pseudo-random noise waveform in the composite interference electromagnetic wave masks the residual original periodic leakage signal in the frequency band, thereby achieving dual active suppression of channel leakage on the core circuit side.

[0076] Furthermore, the active protection trigger module is equipped with a hardware-level fast response circuit.

[0077] The active protection trigger module and the electromagnetic field integrity detection module are connected by hardwire; when the active protection trigger module receives an attack signal, it initiates a physical isolation program for the core circuit; the hardware response time for the active protection trigger module to initiate the physical isolation program is limited to within 10 microseconds.

[0078] The active protection trigger module has a built-in high-speed analog switch circuit, and the anti-tampering and anti-electromagnetic side-channel attack device is equipped with the device's main power supply; the input terminal of the high-speed analog switch circuit is connected to the device's main power supply, the output terminal of the high-speed analog switch circuit is connected to the power supply pin of the core circuit, and the level enable terminal of the high-speed analog switch circuit is connected to the hard-wired link for transmitting attack signals.

[0079] During normal operation when no attack signal is generated, the hardwired link transmitting the attack signal is in a low-level state; the enable terminal of the high-speed analog switch circuit receives the low-level state and keeps the internal channel open in the low-level state, so that the main power supply of the device outputs stable power to the core circuit through the high-speed analog switch circuit.

[0080] During the protection triggering phase when an attack signal is generated, the hard-wired link transmitting the attack signal jumps to a high-level state; the level enable terminal of the high-speed analog switch circuit receives the high-level state and immediately shuts off the internal channel in the high-level state, thereby disconnecting the power transmission circuit from the device's main power supply to the power pin.

[0081] The core circuit is equipped with a hardware security lockout pin; the trigger end of the active protection trigger module establishes a direct wire connection with the hardware security lockout pin; the active protection trigger module uses the high-level state of the attack signal as the first message notification input to the hardware security lockout pin.

[0082] The core circuit directly activates the chip hardware lockout state machine based on the first message notification received by the hardware security lockout pin. The core circuit blocks the communication link of the debugging interface through the chip hardware lockout state machine, freezes the read, write and erase permissions of the internal storage area, and executes the hardware zeroing action of the key register to prevent external probe devices from reading internal confidential data through physical intrusion.

[0083] Furthermore, the core circuit synchronously executes a software-level deep protection mechanism as an auxiliary protection mechanism against hardware-level power failure and lock-up.

[0084] The core circuit includes a main control unit with an external interrupt pin; the trigger terminal of the active protection trigger module is hardwired to the external interrupt pin. The active protection trigger module uses the rising edge of the attack signal as the trigger condition to input a hardware interrupt signal to the external interrupt pin; the main control unit suspends the normal business logic according to the hardware interrupt signal and enters the non-maskable interrupt service routine.

[0085] The core circuit also includes an external storage unit, an internal random access memory (RAM), a network communication unit, and an energy storage capacitor; the energy storage capacitor is connected to the power supply pin of the core circuit. After the high-speed analog switching circuit disconnects the power supply loop from the main power supply of the device to the power supply pin, the energy storage capacitor enters a discharge state, providing operating power to the main control unit, external storage unit, internal RAM, and network communication unit.

[0086] The main control unit uses operating power to send multiple rounds of write-and-erase instructions to the key storage area in the external storage unit in the non-maskable interrupt service routine, so as to destroy the persistently stored working key and session key data; in a specific embodiment of the present invention, the number of times the multiple rounds of write-and-erase instructions are executed is set to 3.

[0087] While executing multiple rounds of write-and-erase instructions, the main control unit performs a memory zeroing operation on the intermediate cryptographic operation data in the internal random access memory to prevent external probe devices from collecting residual cryptographic operation context through cold start methods; the intermediate cryptographic operation data includes private key parameters and round key data.

[0088] The main control unit has a built-in one-time programmable memory area. After the main control unit completes multiple rounds of write-and-erase instructions and memory clearing operations, it sets the anti-tamper flag in the one-time programmable memory area, making the anti-tamper flag set into an irreversible state.

[0089] In the subsequent reset process, the main control unit reads the tamper flag in the one-time programmable storage area, and when it detects that the tamper flag is set, it refuses to load the boot firmware, thereby cutting off the path for the system to resume operation at the firmware level.

[0090] The main control unit uses its operating power to generate encrypted alarm data packets and sends these packets to a remote cloud server via the network communication unit. The encrypted alarm data packets contain device serial number data, attack timestamp data, and device geographic location data. The network communication unit stops operating after sending the encrypted alarm data packets or after its operating power is exhausted.

[0091] Furthermore, the anti-tampering and anti-electromagnetic side-channel attack devices are equipped with a heartbeat verification circuit.

[0092] The electromagnetic field integrity detection module has a built-in first heartbeat generation unit, and the active electromagnetic shielding module has a built-in second heartbeat generation unit; the first heartbeat generation unit and the second heartbeat generation unit respectively generate count data corresponding to the current communication cycle, and the count data monotonically increases according to the communication cycle.

[0093] The first heartbeat generation unit and the second heartbeat generation unit respectively extract the internally fixed device identification code data, and perform scrambling operation on the count value data according to the device identification code data to generate scrambling code data; the scrambling operation includes XOR logic operation or hash encryption operation based on a preset hardware key.

[0094] The first heartbeat generation unit packages the count data and scrambling code data into a first heartbeat signal and sends the first heartbeat signal to the active protection trigger module via a hardwire link; the second heartbeat generation unit packages the count data and scrambling code data into a second heartbeat signal and sends the second heartbeat signal to the active protection trigger module via a hardwire link; the first heartbeat signal and the second heartbeat signal constitute a heartbeat signal.

[0095] The active protection trigger module has a built-in heartbeat verification unit, which receives the first heartbeat signal and the second heartbeat signal to extract the count value data and scrambling code data carried by the first heartbeat signal and the second heartbeat signal.

[0096] The heartbeat verification unit compares the received count data with the historical count data stored locally; if the received count data is less than or equal to the historical count data, the heartbeat verification unit determines that there is replaying signal data behavior in the communication link.

[0097] The heartbeat verification unit extracts the device identification code data of the corresponding module from the pre-stored verification algorithm configured locally, and recalculates the local reference scrambling code data; the heartbeat verification unit compares the local reference scrambling code data with the received scrambling code data; if the local reference scrambling code data is inconsistent with the received scrambling code data, the heartbeat verification unit determines that there is module replacement forgery in the system hardware.

[0098] Furthermore, based on the fact that the local reference scrambling code data is inconsistent with the received scrambling code data, the heartbeat verification unit determines that there is a module replacement forgery behavior in the system hardware. The active protection trigger module is configured with a self-destruct trigger loop for module abnormality and communication interruption.

[0099] The active protection trigger module has a built-in communication timeout timer, which is connected to the signal output terminal of the heartbeat verification unit. When the heartbeat verification unit successfully verifies the count value data and scrambling code data carried by the first heartbeat signal and the second heartbeat signal, the heartbeat verification unit outputs a timer reset signal to the communication timeout timer.

[0100] If the hardwire link between the electromagnetic field integrity detection module, the active protection trigger module, and the active electromagnetic shielding module is physically broken, causing the heartbeat verification unit to not receive a heartbeat signal, the heartbeat verification unit will stop outputting the timing reset signal.

[0101] If the heartbeat verification unit determines that there is replaying of signal data in the communication link, or determines that there is module replacement forgery in the system hardware, the heartbeat verification unit will synchronously stop outputting the timing reset signal.

[0102] When the communication timeout timer does not receive a timer reset signal and the internal timer value accumulates to the preset timeout threshold, a timer overflow action occurs, and an internal trigger signal is generated based on the timer overflow action.

[0103] The active protection trigger module has a built-in logic OR gate circuit; the active protection trigger module connects the internal trigger signal and the attack signal to the input terminal of the logic OR gate circuit respectively; the output terminal of the logic OR gate circuit is connected to the level enable terminal of the high-speed analog switch circuit and the hardware security lock pin of the core circuit respectively.

[0104] When the active protection trigger module generates an internal trigger signal, it outputs a high-level state through a logic OR gate circuit to control the high-speed analog switch circuit to disconnect the power transmission loop from the main power supply of the device to the power pin, and sends the first message notification to the core circuit.

[0105] The core circuit receives the first message notification and activates the chip hardware lock-in state machine, entering the non-maskable interrupt service routine to perform multiple rounds of data area write-and-erase operations, so as to achieve the self-destruction of the system when it is free from external intervention.

[0106] Although embodiments of the invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the appended claims and their equivalents.

Claims

1. A method for implementing anti-tampering and anti-electromagnetic side-channel attack, applied to a device for anti-tampering and anti-electromagnetic side-channel attack, the device comprising a sealed metal protective cover, an electromagnetic field integrity detection module, an active protection triggering module, an active electromagnetic shielding module, and a core circuit; characterized in that, The method includes: During the initialization phase, the electromagnetic field integrity detection module sends a detection signal to the closed metal protective cover and receives a feedback signal. Based on this, it calculates the initial electromagnetic characteristic reference value and stores the initial electromagnetic characteristic reference value into the non-volatile storage unit built into the electromagnetic field integrity detection module. During operation, the electromagnetic field integrity detection module sends the detection signal to the enclosed metal protective cover and receives the feedback signal at a preset time period, thereby calculating real-time electromagnetic characteristic parameters. The electromagnetic field integrity detection module calculates the characteristic difference between the real-time electromagnetic characteristic parameters and the initial electromagnetic characteristic reference value. When the characteristic difference is greater than or equal to a set threshold parameter, a status report and an attack signal are generated, and the attack signal is sent to the active protection triggering module. During the operation phase, the active electromagnetic shielding module synchronously receives the leakage frequency band reference information sent by the core circuit, and generates and transmits interference electromagnetic waves accordingly; the interference electromagnetic waves contain noise waveforms in the same frequency band as the leakage frequency band reference information. The electromagnetic field integrity detection module, the active protection triggering module, and the active electromagnetic shielding module continuously interact with a heartbeat signal containing count value data and scrambling code data at fixed time intervals; when the active protection triggering module does not receive the heartbeat signal containing the corresponding count value data and the corresponding scrambling code data within a preset time window, it generates an internal trigger signal. When the active protection triggering module receives the attack signal or generates the internal trigger signal, it disconnects the power supply line of the core circuit and sends a first message notification to the core circuit. The core circuit sets the hardware security lock pin state according to the first message notification and performs a data area erase operation to destroy the internal storage data of the core circuit.

2. The method for implementing anti-tampering and anti-electromagnetic side-channel attacks according to claim 1, characterized in that: The enclosed metal protective cover is formed by stamping and welding sealing processes from conductive metal material, constructing a continuous conductive metal boundary and a closed physical cavity, and together with the core circuit, forming a basic electromagnetic field. When a physical act occurs that disrupts the continuous conductive metallic boundary, it causes a change in the boundary conditions of the basic electromagnetic field domain and simultaneously triggers a shift in the electromagnetic parameters within the basic electromagnetic field domain.

3. The method for implementing anti-tampering and anti-electromagnetic side-channel attack according to claim 2, characterized in that: The inner surface of the enclosed metal shield forms a parasitic capacitance with the core circuit, and the metal conductor structure of the enclosed metal shield itself forms a parasitic inductance, together constituting an LC microwave resonant cavity structure; the electromagnetic field integrity detection module employs a resonance detection method for the LC microwave resonant cavity structure, specifically including: The theoretical natural resonant frequency is calculated based on the pre-stored size parameters and dielectric parameters of the LC microwave resonant cavity structure; during the initialization phase, the detection signal is sent with the theoretical natural resonant frequency as the center frequency, and the initial natural resonant frequency data and initial natural resonant amplitude data are extracted to form the initial electromagnetic characteristic reference value; During the working phase, the detection signal is sent within the preset frequency offset range according to the preset time period set by the hardware timer unit built into the electromagnetic field integrity detection module, and the real-time resonant frequency data and real-time resonant amplitude data are extracted to form the real-time electromagnetic characteristic parameters. The frequency offset difference between the real-time resonant frequency data and the initial inherent resonant frequency data is calculated as the feature difference; the set threshold parameter includes a frequency offset threshold and an amplitude ratio threshold; when the absolute value of the frequency offset difference is greater than or equal to the frequency offset threshold, or when the ratio of the real-time resonant amplitude data to the initial inherent resonant amplitude data is less than or equal to the amplitude ratio threshold, the status report and the attack signal are generated.

4. The method for implementing anti-tampering and anti-electromagnetic side-channel attacks according to claim 1, characterized in that: The electromagnetic field integrity detection module employs a detection method based on multi-input multi-output channel characteristics, specifically including: In the initialization phase, standard training signals are transmitted as the detection signals through M transmitting antennas arranged inside the enclosed metal protective cover, and feedback training signals are received as the feedback signals through N receiving antennas, where M and N are positive integers greater than or equal to 1; based on this, an initial channel estimation matrix is ​​constructed and an initial eigenvalue vector is extracted as the initial electromagnetic feature reference value; During the working phase, a timed detection process is initiated, the detection signal is sent and the feedback signal is received according to the preset time period, a real-time channel estimation matrix is ​​constructed, and the real-time feature value vector is extracted as the real-time electromagnetic feature parameter. The eigenvalue norm difference between the real-time feature value vector and the initial feature value vector is calculated as the feature difference; the set threshold parameter includes a norm threshold; when the eigenvalue norm difference is greater than or equal to the norm threshold, the status report and the attack signal are generated.

5. The method for implementing anti-tampering and anti-electromagnetic side-channel attacks according to claim 1, characterized in that: When performing operations, the core circuit extracts the center frequency data and bandwidth data of the accompanying electromagnetic leakage signal and sends them to the active electromagnetic shielding module as reference information for the leakage frequency band. The active electromagnetic shielding module generates a pseudo-random noise waveform whose spectrum covers the frequency band of the electromagnetic leakage signal. After setting its output power to a preset power margin higher than the original radiated power of the electromagnetic leakage signal, it emits the interference electromagnetic wave into the enclosed metal shield.

6. The method for implementing anti-tampering and anti-electromagnetic side-channel attacks according to claim 5, characterized in that: The active electromagnetic shielding module acquires the original periodic leakage signal, which includes power ripple signal and clock radiation signal, generated by the core circuit in real time. It uses its built-in phase-shifting network circuit to perform phase inversion processing to generate an inverse cancellation signal that is 180 degrees out of phase with the original periodic leakage signal. Then, it uses its built-in signal superposition device to linearly superimpose the inverse cancellation signal with the pseudo-random noise waveform to generate a composite interference electromagnetic wave, which is then emitted as the interference electromagnetic wave.

7. The method for implementing anti-tampering and anti-electromagnetic side-channel attacks according to claim 1, characterized in that: A hardwired link for transmitting the attack signal is established between the electromagnetic field integrity detection module and the active protection trigger module. When the attack signal is generated, the hard-wired link transmitting the attack signal jumps to a high level; the active protection trigger module receives the high level through its built-in high-speed analog switch circuit and immediately shuts off the internal channel as a step to disconnect the power supply line of the core circuit, specifically disconnecting the power transmission circuit from the main power supply of the device to the power supply pin configured in the core circuit. The active protection trigger module uses the high-level state as the first message notification and inputs it to the hardware security lock pin of the core circuit, directly activating the chip hardware lock-up state machine of the core circuit.

8. The method for implementing anti-tampering and anti-electromagnetic side-channel attack according to claim 7, characterized in that: The core circuit includes a main control unit, an external storage unit, an internal random access memory, a network communication unit, and an energy storage capacitor connected to the power supply pin. The main control unit has an external interrupt pin. The active protection triggering module uses the rising edge transition of the attack signal as a trigger condition to input a hardware interrupt signal to the external interrupt pin of the main control unit, causing the main control unit to enter the non-maskable interrupt service routine. After the main power supply of the device is disconnected, the energy storage capacitor enters the discharge state to provide operating power. The main control unit uses the operating power to send a write-erase command to the external storage unit to destroy the key data stored in the external storage unit, performs a memory clearing operation on the internal random access memory, then sets the anti-tamper flag built into the main control unit, and generates an encrypted alarm data packet which is sent to the remote cloud server via the network communication unit.

9. The method for implementing anti-tampering and anti-electromagnetic side-channel attack according to claim 7, characterized in that: The electromagnetic field integrity detection module and the active electromagnetic shielding module respectively perform scrambling code calculations based on their respective count value data and their respective built-in device identification codes to generate scrambling code data, which are then packaged into heartbeat signals and sent to the active protection triggering module. The heartbeat verification unit built into the active protection trigger module verifies the heartbeat signal. If the verification is successful, it outputs a timer reset signal to its built-in communication timeout timer. If the communication timeout timer does not receive the timeout reset signal and the accumulated timeout reaches the preset timeout threshold, the internal trigger signal is generated. The active protection trigger module connects the internal trigger signal and the attack signal to the input of its built-in logic OR gate circuit, and outputs a high-level state to the high-speed analog switch circuit and the hardware security lock pin through the output of the logic OR gate circuit.

10. A device for preventing tampering and electromagnetic side-channel attacks, characterized in that, include: Enclosed metal protective cover, electromagnetic field integrity detection module, active protection trigger module, active electromagnetic shielding module, and core circuitry; The enclosed metal protective cover encloses the core circuit to form an electromagnetic shielding cavity; The electromagnetic field integrity detection module is used to perform the steps executed by the electromagnetic field integrity detection module in the method as described in any one of claims 1 to 9; The active protection triggering module is used to perform the steps executed by the active protection triggering module in the method as described in any one of claims 1 to 9; The active electromagnetic shielding module is used to perform the steps executed by the active electromagnetic shielding module in the method as described in any one of claims 1 to 9; The core circuit is used to perform the steps executed by the core circuit in the method as described in any one of claims 1 to 9.