Trusted starting circuit based on analog switch

By setting an analog switch between the Flash memory, trusted chip and CPU, and using the control signal of the trusted chip to change the conduction direction of the analog switch, the fast, secure verification and loading of the Flash memory program is achieved, and the problems of slow verification speed and low security in the prior art are solved, ensuring the stable operation of the system.

CN222914204UActive Publication Date: 2025-05-27JUNENG SPECIAL COMM EQUIP CO LTD TOEC GRP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202421681975.0
Authority / Receiving Office
CN · China
Patent Type
Utility models(China)
Current Assignee / Owner
Filing Date
2024-07-16
Publication Date
2025-05-27
Estimated Expiration
2034-07-16

AI Technical Summary

Technical Problem

The prior art has problems of slow speed and low security when verifying the correctness of programs in Flash memory chips, and it is difficult to quickly and securely verify the correctness of Flash storage content and realize program loading.

Method used

Using a trusted start circuit based on analog switches, by setting an analog switch between the Flash memory, trusted chip and CPU, the control signal provided by the trusted chip changes the conduction direction of the analog switch, thereby realizing the switching of the data transmission port, and quickly and safely verifying the correctness of the program in the Flash memory.

Benefits of technology

It realizes a fast, secure and trusted startup method, ensuring that the CPU is loaded with programs in the Flash memory that passes, improving the reliability of data loading, and ensuring the stable operation of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN222914204U_ABST
    Figure CN222914204U_ABST
Patent Text Reader

Abstract

The utility model discloses a trusted starting circuit based on an analog switch, which comprises a Flash memory, an SPI (Serial Peripheral Interface) of the Flash memory is connected to a public port of the analog switch, a first group of I / O (Input / Output) ports of the analog switch are connected to an SPI of a trusted chip, and a second group of I / O ports of the analog switch are connected to an SPI of a CPU (Central Processing Unit) for reading a program. A first path of GPIO control signal interface of the trusted chip is connected to a direction control signal pin of the analog switch, and a second path of GPIO control signal interface of the trusted chip is connected to a reset pin of the CPU. According to the utility model, the correctness of the Flash storage chip can be quickly and safely verified and the program loading can be realized through the technology of combining the analog switch and the trusted chip.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The utility model belongs to the technical field of computer security, and more specifically, it relates to a trusted startup circuit based on an analog switch. Background Art

[0002] With the rapid development of information technology, the security of computer systems has received increasing attention. As a secure startup process, trusted startup can ensure that a device only loads verified and correct software programs during startup, preventing the intrusion and operation of malicious software. Due to factors such as abnormal voltage, external interference, and human malicious tampering that the Flash chip storing the program may encounter, the security of the system is threatened, so the reliability problem of the data in the Flash chip has become increasingly prominent. To ensure the correctness of the program in the Flash storage chip, it needs to be verified and then loaded into the system. The existing verification methods mainly use software methods, which have certain limitations, such as slow verification speed and low security. Therefore, how to quickly and securely verify the correctness of the Flash storage content and implement program loading has become an urgent problem in this field. Summary of the Utility Model

[0003] The purpose of the utility model is to overcome the deficiencies in the prior art and provide a trusted startup circuit based on an analog switch. By combining the technologies of analog switches and trusted chips, it can quickly and securely verify the correctness of Flash storage chips and implement program loading.

[0004] The purpose of the utility model is achieved through the following technical solutions.

[0005] The trusted startup circuit based on an analog switch of the utility model includes a Flash memory. The SPI interface of the Flash memory is connected to the common port of the analog switch. The first group of I / O ports of the analog switch is connected to the SPI interface of the trusted chip. The second group of I / O ports of the analog switch is connected to the SPI interface for the CPU to read the program. The first GPIO control signal interface of the trusted chip is connected to the direction control signal pin of the analog switch. The second GPIO control signal interface of the trusted chip is connected to the reset pin of the CPU.

[0006] Further, the analog switch uses a 4-channel double-throw analog switch chip.

[0007] Further, the common port, the first group of I / O ports, and the second group of I / O ports of the analog switch are all four-wire interfaces, corresponding to the 4-wire SPI interface of the Flash memory, the 4-wire SPI interface of the trusted chip, and the 4-wire SPI interface for the CPU to read the program respectively.

[0008] Further, the trusted chip uses a dedicated security algorithm chip.

[0009] Further, the CPU refers to a computer or a central processing unit chip.

[0010] Compared with the prior art, the beneficial effects brought by the technical solution of the present utility model are as follows:

[0011] (1) By arranging an analog switch among the Flash memory, the trusted chip, and the CPU, the present utility model can control the path of the Flash data stream. The analog switch can change the conduction direction according to the control signal provided by the trusted chip, thereby realizing the switching of the data transmission port.

[0012] (2) Based on the control technology of the analog switch and the trusted chip, the present utility model provides a fast and secure trusted startup method, and ensures that the program loaded by the CPU is from the Flash memory that has passed verification. This method improves the reliability of data loading and ensures the stable operation of the system. BRIEF DESCRIPTION OF THE DRAWINGS

[0013] Figure 1 is a schematic diagram of the trusted startup circuit principle of the present utility model based on an analog switch.

[0014] Reference numerals: A - common port, B - first group of I / O ports, C - second group of I / O ports, IN - direction control signal pin, GPIO0 - first GPIO control signal interface, GPIO1 - second GPIO control signal interface. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0015] The present utility model will be further described below with reference to the drawings.

[0016] As Figure 1 shown, the trusted startup circuit of the present utility model based on an analog switch mainly includes a Flash memory, an analog switch, a trusted chip, and a CPU. Among them, the SPI interface of the Flash memory is connected to the common port "A" of the analog switch, the first group of I / O ports "B" of the analog switch is connected to the SPI interface of the trusted chip, the second group of I / O ports "C" of the analog switch is connected to the SPI interface of the CPU for reading programs, the first GPIO control signal interface "GPIO0" of the trusted chip is connected to the direction control signal pin "IN" of the analog switch, and the second GPIO control signal interface "GPIO1" of the trusted chip is connected to the reset pin of the CPU.

[0017] In the above-mentioned trusted startup circuit, preferably, the Flash memory is usually a storage chip with a 4-wire SPI interface, and can store the operating system, application programs, etc. of the CPU.

[0018] In the above-mentioned trusted boot circuit, preferably, the analog switch uses a 4-channel double-throw analog switch chip, such as CH445P of Nanjing Qinheng or RS2099 of Jiangsu Runshi, etc. The common port "A", the first group of I / O ports "B", and the second group of I / O ports "C" of the analog switch are all 4-wire interfaces. Each group of interfaces includes 4 signal lines, which respectively correspond to the 4-wire SPI interface of the Flash memory, the 4-wire SPI interface of the trusted chip, and the 4-wire SPI interface for the CPU to read the program. When a high level is provided to the direction control signal pin "IN", the common port "A" of the analog switch is internally connected to the first group of I / O ports "B", and the second group of I / O ports "C" is floating; when a low level is provided to the direction control signal pin "IN", the common port "A" of the analog switch is internally connected to the second group of I / O ports "C", and the first group of I / O ports "B" is floating.

[0019] In the above-mentioned trusted boot circuit, preferably, the trusted chip uses a dedicated security algorithm chip, such as CCP903T of Suzhou Guoxin or RNP-N10C of Wuxi Mochuang, etc., which has an SPI interface and a GPIO control signal interface, and supports national cryptographic standard algorithms including SM2, SM3, SM4, etc., as well as international general algorithms such as DES\AES\RSA. The trusted chip has the function of verifying the correctness of the Flash memory, such as CRC check, encryption algorithm verification, etc., and also has the function of outputting control signals to control the conduction direction of the analog switch.

[0020] In the above-mentioned trusted boot circuit, preferably, the CPU refers to the central processing unit chip of a computer or a common application system, and usually uses the SPI interface to load the initial program.

[0021] When the system is powered on and booted, the trusted chip starts up first. It outputs a high level to the analog switch through the first GPIO control signal interface "GPIO0", configures the analog switch to the connection mode of the common port "A" and the first group of I / O ports "B", and provides a low level to the CPU reset pin through the second GPIO control signal interface "GPIO1" to prevent the CPU from starting. At this time, the trusted chip can read the program content in the Flash memory through the SPI interface, calculate the result through the algorithm built in the chip, and compare it with the calculation result pre-stored inside the trusted chip to verify the correctness of the program in the Flash memory. If the calculation results are different, the verification fails, and no further action is taken. The CPU is controlled by the reset signal and does not continue to run, ensuring that the CPU will not load an incorrect program. If the calculation results are the same, the verification passes. The trusted chip outputs a low level to the analog switch through the first GPIO control signal interface "GPIO0", configures the analog switch to the connection mode of the common port "A" and the second group of I / O ports "C", and provides a high level to the CPU reset pin through the second GPIO control signal interface "GPIO1". At this time, the CPU continues to run, reads the program in the Flash memory through the SPI interface, and thus starts up normally.

[0022] The utility model sets an analog switch among the Flash memory, the trusted chip, and the CPU, which can control the path of the Flash data stream. The analog switch can change the conduction direction according to the control signal provided by the trusted chip, thereby realizing the switching of the data transmission port.

[0023] Through the above implementation scheme, the utility model provides a fast and secure trusted startup method based on the control technology of the analog switch and the trusted chip, and ensures that the program loaded by the CPU is the one in the Flash memory that has passed the verification. This method improves the reliability of data loading and ensures the stable operation of the system.

[0024] Although the functions and working processes of the utility model are described above in conjunction with the drawings, the utility model is not limited to the above specific functions and working processes. The above specific implementation manners are merely illustrative and not restrictive. Under the inspiration of the utility model, those of ordinary skill in the art can also make many forms without departing from the purpose of the utility model and the scope protected by the claims. All these fall within the protection scope of the utility model.

Claims

1. A trusted boot circuit based on an analog switch, comprising a Flash memory, characterized in that: The SPI interface of the Flash memory is connected to the common port (A) of the analog switch, the first group of I / O ports (B) of the analog switch is connected to the SPI interface of the trusted chip, the second group of I / O ports (C) of the analog switch is connected to the SPI interface of the CPU reading program, the first GPIO control signal interface (GPIO0) of the trusted chip is connected to the direction control signal pin (IN) of the analog switch, and the second GPIO control signal interface (GPIO1) of the trusted chip is connected to the reset pin of the CPU.

2. The analog switch-based trusted startup circuit according to claim 1, characterized in that: The analog switch adopts a 4-way double-throw analog switch chip.

3. The analog switch-based trusted startup circuit according to claim 1, characterized in that: The common port (A), the first group I / O port (B), and the second group I / O port (C) of the analog switch are all four-wire interfaces, corresponding to the 4-wire SPI interface of the Flash memory, the 4-wire SPI interface of the trusted chip, and the 4-wire SPI interface of the CPU reading program.

4. The analog switch-based trusted startup circuit according to claim 1, characterized in that: The trusted chip uses a dedicated security algorithm chip.

5. The analog switch-based trusted startup circuit according to claim 1, characterized in that: The CPU refers to a computer or central processing unit chip.