Trusted measurement control device
Through the new connection method of the security module and the main control module, combined with analog switch switching control and resistor design, the low measurement efficiency and signal integrity problems caused by multi-channel analog switch are solved, and efficient and stable reliable measurement control is achieved. It is suitable for a variety of storage media and communication protocols, improving the flexibility and stability of the system.
Patent Information
- Application Number
- CN202422508480.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Utility models(China)
- Current Assignee / Owner
- Filing Date
- 2024-10-16
- Publication Date
- 2025-08-01
- Estimated Expiration
- 2034-10-16
AI Technical Summary
The existing reliable metric control devices have low measurement efficiency and signal integrity problems due to the rate bandwidth limitation of the multi-channel analog switch module and the complex circuit design, which affect the stability and reliability of the system.
The new connection method of safety module, analog switch module and main control module is adopted to access the storage medium through analog switch switching control signals, avoid multi-channel analog switch transmission, and combine resistance design to improve signal integrity and stability.
It improves the measurement efficiency of the trusted metric control device, enhances signal quality and system stability, supports a variety of storage media and communication protocols, improves the flexibility and applicability of the system, extends the equipment life, and ensures high-performance operation in complex electromagnetic environments.
Smart Images

Figure CN223180594U_ABST
Abstract
Description
Technical Field
[0001] This application belongs to the field of computer technology, and particularly relates to a trusted measurement control device. Background Art
[0002] With the rapid development of intelligent Internet of Things technology, embedded hardware system devices are becoming more and more widespread in the fields of power and industrial control. Various communication data in the power and industrial fields are calculated, transmitted, and data-verified for other security through embedded devices. Therefore, a trusted control chip is used to perform trusted security measurement on the system to ensure the security and reliability of the system.
[0003] Existing trusted measurement control devices need to use a multi-channel analog switch module to switch the interface signals between the main control module and the storage medium. Due to the rate bandwidth limitation of the multi-channel analog switch module itself and the complex connection of the circuit design, the measurement efficiency is low, and certain signal integrity problems are generated, affecting the stability and reliability of the system. Summary of the Utility Model
[0004] The embodiments of this application provide a trusted measurement control device, which can improve the measurement efficiency of the trusted measurement control device, make the signal integrity and signal quality better, and improve the stability and reliability of the device.
[0005] The first aspect of the embodiments of this application provides a trusted measurement control device, including a security module, an analog switch module, a main control module, and a storage medium;
[0006] The reset signal output end of the security module is connected to the reset signal input end of the main control module. The analog switch switching control signal output end of the security module is connected to the controlled end of the analog switch module. The first input end of the analog switch module is connected to the security module. The second input end of the analog switch module is connected to the main control module. The output end of the analog switch module is connected to the storage medium. The data input end of the security module is connected to the first data interface of the storage medium. The data input end of the main control module is connected to the first data interface or the second data interface of the storage medium.
[0007] In one embodiment, the storage medium is a NOR flash or an embedded multimedia card.
[0008] In one embodiment, the storage medium is a NOR flash. The CS interface of the security module is connected to the first input end of the analog switch module. The CS interface of the main control module is connected to the second input end of the analog switch module. The output end of the main control module is connected to the CS interface of the storage medium.
[0009] In one embodiment, the storage medium is a NAND flash memory, and the SPI interface of the security module is connected to the SPI / QSPI interface of the storage medium.
[0010] In one embodiment, the storage medium is a NAND flash memory, and the SPI interface of the main control module is connected to the SPI / QSPI interface of the storage medium, or the QSPI interface of the main control module is connected to the SPI / QSPI interface of the storage medium.
[0011] In one embodiment, the storage medium is an embedded multimedia card. The IO_CMD interface of the security module is connected to the first input end of the analog switch module. The CMD interface of the main control module is connected to the second input end of the analog switch module. The output end of the main control module is connected to the CMD interface of the storage medium.
[0012] In one embodiment, the storage medium is an embedded multimedia card. The data input end of the security module is connected to the data interface of the storage medium through a single data line. The data input end of the main control module is connected to the data interface of the storage medium through multiple data lines.
[0013] In one embodiment, the analog switch module includes a single-pole double-throw switch. The first input end of the single-pole double-throw switch is the first input end of the analog switch module. The second input end of the single-pole double-throw switch is the second input end of the analog switch module. The common end of the single-pole double-throw switch is the output end of the analog switch module.
[0014] In one embodiment, a resistor is provided between the data input end of the security module and the first data interface of the storage medium, and between the data input end of the main control module and the first data interface or the second data interface of the storage medium.
[0015] In one embodiment, a resistor is provided between the first input end of the analog switch module and the security module, and between the second input end of the analog switch module and the main control module.
[0016] The trusted measurement control device provided in the first aspect of the embodiments of the present application includes a security module, an analog switch module, a main control module, and a storage medium; the reset signal output terminal of the security module is connected to the reset signal input terminal of the main control module, the analog switch switching control signal output terminal of the security module is connected to the controlled terminal of the analog switch module, the first input terminal of the analog switch module is connected to the security module, the second input terminal of the analog switch module is connected to the main control module, the output terminal of the analog switch module is connected to the storage medium, the data input terminal of the security module is connected to the first data interface of the storage medium, and the data input terminal of the main control module is connected to the first data interface or the second data interface of the storage medium. There is no need to transmit multiple signals through a multi-channel analog switch. Only the analog switch switching control signal is used to switch the access to the storage medium, which is no longer restricted by the analog switch module itself, improving the measurement efficiency of the trusted measurement control device, making the signal integrity and signal quality better, and improving the stability and reliability of the device. Description of the Drawings
[0017] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required for use in the embodiments or the description of the prior art. Obviously, the following drawings are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0018] Figure 1 It is a schematic structural diagram of a trusted measurement control device provided in an embodiment of the present application;
[0019] Figure 2 It is a schematic structural diagram of a trusted measurement control device provided in another embodiment of the present application;
[0020] Figure 3 It is a schematic structural diagram of a trusted measurement control device provided in another embodiment of the present application;
[0021] Figure 4 It is a schematic structural diagram of a trusted measurement control device provided in another embodiment of the present application;
[0022] Figure 5 It is a schematic structural diagram of a trusted measurement control device provided in another embodiment of the present application;
[0023] Figure 6 It is a flowchart of the control method of the trusted measurement control device provided in an embodiment of the present application. Detailed Embodiments
[0024] In the following description, specific details such as specific system architectures and technologies are presented for purposes of illustration and not limitation, so as to provide a thorough understanding of the embodiments of the present application. However, those skilled in the art should understand that the present application can also be implemented in other embodiments without these specific details. In other cases, detailed descriptions of well-known systems, devices, circuits, and methods are omitted to avoid unnecessary details from obscuring the description of the present application.
[0025] It should be understood that when used in the specification of the present application and the appended claims, the term "comprising" indicates the presence of the described features, wholes, steps, operations, elements, and / or components, but does not exclude the presence or addition of one or more other features, wholes, steps, operations, elements, components, and / or their combinations.
[0026] It should also be understood that the term "and / or" used in the specification of the present application and the appended claims refers to any combination and all possible combinations of one or more of the associated listed items, and includes these combinations.
[0027] As used in the specification of the present application and the appended claims, the term "if" can be interpreted as "when" or "once" or "in response to determining" or "in response to detecting" depending on the context. Similarly, the phrase "if determined" or "if [the described condition or event] is detected" can be interpreted as meaning "once determined" or "in response to determining" or "once [the described condition or event] is detected" or "in response to detecting [the described condition or event]" depending on the context.
[0028] In addition, in the description of the specification of the present application and the appended claims, the terms "first", "second", "third", etc. are only used for distinguishing descriptions and cannot be understood as indicating or implying relative importance.
[0029] Reference to "one embodiment" or "some embodiments" or the like described in the specification of the present application means that a specific feature, structure, or characteristic described in connection with that embodiment is included in one or more embodiments of the present application. Thus, statements such as "in one embodiment", "in some embodiments", "in other some embodiments", "in still other embodiments", etc. that appear in different places in this specification do not necessarily all refer to the same embodiment, but mean "one or more but not all embodiments", unless otherwise specifically emphasized in another way. The terms "comprising", "including", "having", and their variants all mean "including but not limited to", unless otherwise specifically emphasized in another way. "Plurality" means two or more.
[0030] As Figure 1As shown in the figure, an embodiment of the present application provides a trusted measurement control device, including a security module 1, an analog switch module 3, a main control module 2, and a storage medium 4;
[0031] The reset signal output terminal of the security module 1 is connected to the reset signal input terminal of the main control module 2. The analog switch switching control signal output terminal of the security module 1 is connected to the controlled terminal of the analog switch module 3. The first input terminal of the analog switch module 3 is connected to the security module 1. The second input terminal of the analog switch module 3 is connected to the main control module 2. The output terminal of the analog switch module 3 is connected to the storage medium 4. The data input terminal of the security module 1 is connected to the first data interface of the storage medium 4. The data input terminal of the main control module 2 is connected to the first data interface or the second data interface of the storage medium 4.
[0032] In applications, the security module can be a Trusted Platform Control Module (TPCM), or can also be an encryption microcontroller (encryption MCU). The storage medium can be a NOR Flash (Nor Flash) or an Embedded Multimedia Card (eMMC).
[0033] In applications, the analog switch switching control signal output terminal of the security module 1 outputs a control signal to the analog switch module 3 to control the analog switch module 3 to be connected to the first input terminal or the second input terminal, so as to connect the storage medium to the security module 1 or connect the storage medium to the main control module 2. The data input terminal of the security module 1 is used to read the startup firmware through the first data interface of the storage medium 4 for measurement and verification. The data input terminal of the main control module 2 is used to load the firmware program through the first data interface or the second data interface of the storage medium 4 after the measurement and verification is passed to complete the secure startup.
[0034] The embodiments of the present application are provided with a security module, a analog switch module, a main control module and a storage medium; the reset signal output terminal of the security module is connected to the reset signal input terminal of the main control module, the analog switch switching control signal output terminal of the security module is connected to the controlled terminal of the analog switch module, the first input terminal of the analog switch module is connected to the security module, the second input terminal of the analog switch module is connected to the main control module, the output terminal of the analog switch module is connected to the storage medium, the data input terminal of the security module is connected to the first data interface of the storage medium, and the data input terminal of the main control module is connected to the first data interface or the second data interface of the storage medium. There is no need to transmit multiple signals through a multi-channel analog switch. Only the analog switch switching control signal is used to switch the access to the storage medium, and it is no longer restricted by the analog switch module itself, improving the measurement efficiency of the trusted measurement control device, making the signal integrity and signal quality better, and improving the stability and reliability of the device. In addition, the embodiments of the present application support various types of storage media (such as Nor Flash and eMMC) and different communication protocols (such as SPI / QSPI), making the device have good compatibility and scalability, suitable for the requirements of different application scenarios, thereby improving the flexibility and applicability of the entire system.
[0035] In one embodiment, the storage medium 4 is a NOR flash memory 41 or an embedded multimedia card 42.
[0036] In one embodiment, as Figure 2 shown, when the storage medium 4 is a NOR flash memory 41, the CS interface of the security module 1 is connected to the first input terminal of the analog switch module 3, the CS interface of the main control module 2 is connected to the second input terminal of the analog switch module 3, and the output terminal of the main control module 2 is connected to the CS interface of the storage medium 4.
[0037] In application, the analog switch switching control signal output terminal of the security module 1 outputs a high level or a low level to implement the channel chip selection of the analog switch module 3. When the first input terminal of the analog switch module 3 is turned on, the CS interface of the security module 1 is connected to the CS interface of the storage medium 4, and the security module 1 reads the startup firmware for measurement verification; when the second input terminal of the analog switch module 3 is turned on, the CS interface of the main control module 2 is connected to the CS interface of the storage medium 4, and the main control module 2 loads the firmware program to complete the secure startup.
[0038] In one embodiment, a resistor is provided between the data input terminal of the security module 1 and the first data interface of the storage medium 4, and between the data input terminal of the main control module 2 and the first data interface or the second data interface of the storage medium 4.
[0039] In one embodiment, resistors are provided between the first input terminal of the analog switch module 3 and the security module 1, and between the second input terminal of the analog switch module 3 and the main control module 2.
[0040] In the embodiment of the present application, by providing resistors between the security module 1 and the storage medium 4, between the main control module 2 and the storage medium 4, and between the input terminals of the analog switch module 3 and the security module 1 and the main control module 2, the stability and signal quality of the system can be significantly improved. These resistors play a role in current limiting and protecting the circuit, preventing hardware damage caused by excessive current, and helping to reduce reflections and noise interference during signal transmission, thereby improving the reliability of data transmission. In addition, the presence of the resistors also provides additional electrical isolation for the system, enhancing the anti-interference ability, making the entire device applicable to complex electromagnetic environments. This design not only extends the service life of the device but also ensures high-performance operation under various working conditions, further enhancing the overall security and stability.
[0041] In one embodiment, the storage medium 4 is a NOR flash memory 41, and the SPI interface of the security module 1 is connected to the SPI / QSPI interface of the storage medium 4.
[0042] In applications, the data interface of the Nor Flash supports the standard SPI communication protocol and also the SPI / QSPI interface that supports the enhanced QSPI communication protocol. During the metric inspection phase, the security module uses the SPI interface to read data from the Nor Flash.
[0043] In one embodiment, the storage medium 4 is a NOR flash memory 41, and the SPI interface of the main control module 2 is connected to the SPI / QSPI interface of the storage medium 4, or the QSPI interface of the main control module 2 is connected to the SPI / QSPI interface of the storage medium 4.
[0044] In the embodiment of the present application, the SPI interface of the main control module 2 is connected to the SPI / QSPI interface of the storage medium 4, or the QSPI interface of the main control module 2 is connected to the SPI / QSPI interface of the storage medium 4. Compared with the prior art where only a common four-wire SPI interface is supported between the security module and the NorFlash, but the QSPI connection is used between the main control module and the Nor Flash, resulting in an incompatible unified interface and low metric efficiency, the embodiment of the present application can support both the four-wire SPI or QSPI interface or the eMMC interface, improving the metric efficiency.
[0045] In the embodiments of the present application, the SPI connection between the security module and the Nor Flash ensures that the startup firmware data can be read efficiently and reliably during the measurement verification phase. The main control module can choose to use the SPI or QSPI interface to load the firmware according to its own capabilities. This flexible interface configuration not only improves the data transmission rate but also enhances the compatibility and scalability of the system. Secondly, the unified design supporting multiple communication protocols avoids the low efficiency problem caused by inconsistent interfaces in traditional solutions, making the entire measurement and startup process smoother and reducing unnecessary waiting time. In addition, this design also simplifies the design complexity of the hardware interface, reduces costs, and provides convenience for future upgrades. For example, it can easily switch to a higher-performance storage medium or more advanced communication technology, thus ensuring the long-term technical competitiveness and reliability of the system.
[0046] In one embodiment, the analog switch module 3 includes a single-pole double-throw switch. The first input terminal of the single-pole double-throw switch is the first input terminal of the analog switch module 3, the second input terminal of the single-pole double-throw switch is the second input terminal of the analog switch module 3, and the common terminal of the single-pole double-throw switch is the output terminal of the analog switch module 3.
[0047] The embodiments of the present application only use a single-channel single-pole double-throw analog switch, which saves costs. It realizes the switching of the trusted measurement interface, reduces the complexity of the trusted measurement interface, simplifies the circuit design connection during circuit design, and there is no need to pass multiple signals through a multi-channel analog switch, improving the signal integrity and signal quality, and enhancing the stability and reliability of the system. Moreover, only one cs chip select signal or CMD command control signal is used to switch the access to the storage medium, so that the device is not limited by the bandwidth of the analog switch module itself, and the influence of the analog switch module on the SPI / QSPI or emmc signal is avoided.
[0048] In the application, the first input terminal of the single-pole double-throw switch is the B1 terminal, the second input terminal is the B0 terminal, and the common terminal of the single-pole double-throw switch is the output terminal of the analog switch module 3, that is, the A terminal.
[0049] In the application, during the stage of loading the firmware program, if the main control module supports the QSPI communication protocol, the QSPI interface is used to load the firmware program. If the main control module does not support the QSPI communication protocol, the SPI interface is used to load the firmware program.
[0050] In the application, such as Figure 3As shown in the figure, the SPI interface of the security module 1 is connected to the first data interface of the Nor Flash using four-wire SPI signals. Specifically, the MOSI pin of the security module 1 is connected to the MISO / QSPI_D1 pin of the Nor Flash, the MISO pin of the security module 1 is connected to the MOSI / QSPI_D0 pin of the Nor Flash, and the SCLK pin of the security module 1 is connected to the SCLK pin of the Nor Flash. Among them, a resistor R1 is connected between the MOSI pin of the security module 1 and the MISO / QSPI_D1 pin of the Nor Flash, a resistor R2 is connected between the MISO pin of the security module 1 and the MOSI / QSPI_D0 pin of the Nor Flash, and a resistor R3 is connected between the SCLK pin of the security module 1 and the SCLK pin of the Nor Flash. The CS pin of the security module 1 is connected to the first input terminal B1 of the analog switch module 3 through a resistor R4, and the CS pin of the main control module 2 is connected to the second input terminal B0 of the analog switch module 3 through a resistor R5. The output terminal of the analog switch module 3 is connected to the CS pin of the Nor Flash, the CS pin of the Nor Flash is connected to one end of a resistor R11, and the other end of the resistor R11 is connected to the power supply VDD. The SPI interface of the main control module is connected to the SPI / QSPI interface of the storage medium 4, or the QSPI interface of the main control module 2 is connected to the SPI / QSPI interface of the storage medium 4. Specifically, the MOSI / QSPI_D0 pin of the main control module 2 is connected to the MISO / QSPI_D1 pin of the Nor Flash through a resistor R6, the MISO / QSPI_D1 pin of the main control module 2 is connected to the MOSI / QSPI_D0 pin of the Nor Flash through a resistor R7, and the SCLK pin of the main control module 2 is connected to the SCLK pin of the Nor Flash through a resistor R8. The QSPI_D2 pin of the main control module 2 is connected to the QSPI_D2 pin of the Nor Flash, and the QSPI_D3 pin of the main control module 2 is connected to the QSPI_D3 pin of the Nor Flash. The GPIO2 pin of the security module 1 is connected to the Reset pin of the main control module 2, and the UART / SPI pin of the security module 1 is connected to the UART / SPI pin of the main control module 2.
[0051] In an application, after the system is powered on, the security module 1 (TPCM trusted control module or encrypted MCU) controls the reset pin of the main control module 2 (embedded main control SOC) to be at a low level through the GPIO2 pin, and the main control module 2 remains in the reset state. After the system device is powered on, the security module 1 controls the analog switch module SEL to be at a high level. The CS signal of the security module 1 is connected to the input pin of the analog switch module B1 through the resistor R4, and the output A of the analog switch module is connected to the CS signal pin of the Nor Flash. The security module 1 reads the BOOT startup firmware of the Nor Flash system through the SPI interface for measurement verification. When the measurement fails, it controls the Reset pin of the main control module 2 to remain at a low level to ensure that the device is not started when the system firmware stored in the Nor Flash fails to pass the verification, ensuring the trustworthiness of the system data. When the measurement passes, it controls the SEL pin of the analog switch module 3 to be at a low level. At this time, the CS signal of the main control module 2 is connected to the CS pin of the Nor Flash through the analog switch. The security module 1 controls the Reset pin of the main control module 2 to be at a high level, and the main control module 2 loads the firmware program from the Nor Flash to complete the startup. After the main control module 2 completes the startup, the security module 1 controls the SEL pin of the analog switch module 3 to be at a high level, and the security module 1 enters the normal operation state. At this time, the entire device completes the trust measurement of the system.
[0052] In one embodiment, as Figure 4 shown, when the storage medium 4 is an embedded multimedia card 42, the IO_CMD interface of the security module 1 is connected to the first input end of the analog switch module 3, the CMD interface of the main control module 2 is connected to the second input end of the analog switch module 3, and the output end of the main control module 2 is connected to the CMD interface of the storage medium 4.
[0053] In one embodiment, the storage medium 4 is an embedded multimedia card 42. The data input end of the security module 1 is connected to the data interface of the storage medium 4 through a single data line, and the data input end of the main control module 2 is connected to the data interface of the storage medium 4 through multiple data lines.
[0054] In the application, during the measurement and inspection stage, the security module 1 only reads data from the eMMC in the single data line mode. After the inspection is successful, during the firmware program loading stage, the main control module 2 loads the firmware from the Nor Flash through the DAT0 - DAT7 data lines (i.e., multiple data lines).
[0055] In the application, as Figure 5As shown in the figure, the data input terminal of the security module 1 is connected to the data interface of the storage medium 4 through a single data line. Specifically, the security module 1 is connected to the data interface (CLK, DAT0) of the eMMC through two-wire signals (CLK, IO_DAT), and a resistor R1 is connected between the CLK pin of the security module 1 and the CLK pin of the eMMC, and a resistor R2 is connected between the DAT0 pin of the security module 1 and the DAT0 pin of the eMMC. The IO_CMD pin of the security module 1 is connected to the first input terminal B1 of the analog switch module 3 through a resistor R3, and the CMD pin of the main control module 2 is connected to the second input terminal B0 of the analog switch module 3 through a resistor R4. The A terminal (common terminal) of the analog switch module 3 is connected to the CMD pin of the eMMC. The data input terminal of the main control module 2 is connected to the data interface of the storage medium 4 through multiple data lines. Specifically, the CLK pin of the main control module 2 is connected to the CLK pin of the eMMC through a resistor R5. The DAT0 - DAT7 pins of the main control module 2 are respectively connected to the DAT0 - DAT7 pins of the eMMC through resistors R6 - R13, and the DAT Strobe pin of the main control module 2 is connected to the DAT Strobe pin of the eMMC through a resistor R14.
[0056] In the application, after the system is powered on, the security module 1 controls the reset pin of the main control module 2 to be at a low level through GPIO2, so that the main control module 2 remains in the reset state. After the system device is powered on, the security module 1 controls the SEL pin of the analog switch module 3 to be at a high level. The IO_CMD signal of the security module 1 is connected to the input pin B1 of the analog switch module through the resistor R3, and the output terminal A of the analog switch module 3 is connected to the CMD signal pin of the eMMC. The security module 1 reads the system startup firmware in the eMMC through the eMMC interface using the single - line communication mode for measurement and verification. When the measurement fails, it controls the Reset pin of the main control module 2 to remain at a low level, ensuring that the device does not start when the system firmware stored in the eMMC fails to pass the verification, and ensuring the credibility of the system data. When the measurement passes, it controls the SEL pin of the analog switch module to be at a low level. At this time, the CMD signal of the main control module 2 is connected to the A port of U1 through the B0 port of the analog switch, realizing the connection to the CMD signal pin of the eMMC. Then, the security module 1 controls the Reset pin of the main control module 2 to be at a high level through GPIO2, and the main control module 2 loads the firmware from the eMMC through the data interface (DAT0 - DAT7) of the eMMC to start. After the embedded main control SOC starts successfully, at this time, the entire device completes the trusted measurement of the system.
[0057] In one embodiment, as Figure 6 shown, a control method for a trusted measurement control device includes the following steps S10 - S21:
[0058] Step S10: Start.
[0059] Step S11: Power on the device.
[0060] Step S12: The security module controls the Reset pin of the main control module to be at a low level.
[0061] Step S13: The security module controls the SEL pin of the analog switch module to be at a high level.
[0062] Step S14: The security module reads the startup firmware from the storage medium and performs measurement verification.
[0063] Step S15: Determine whether the measurement verification passes. If the measurement verification passes, execute Step S16; if the measurement verification fails, execute Step S17.
[0064] Step S16: The security module controls the SEL pin of the analog switch module to be at a low level.
[0065] Step S17: The security module controls the Reset pin of the main control module to be at a low level.
[0066] Step S18: The security module controls the Reset pin of the main control module to be at a high level.
[0067] Step S19: The security module loads the firmware program from the storage medium to complete startup.
[0068] Step S20: The security module controls the SEL pin of the analog switch module to be at a high level.
[0069] Step S21: The security module enters the normal operation state.
[0070] Through the above control method, the trusted measurement control device provided by the embodiments of the present application can achieve efficient and secure firmware verification and loading during the device startup process. Specifically, the method immediately controls the main control module to enter the reset state after power-on through the security module, ensuring the initial security of the system; then, the analog switch module is used to switch the connection between the security module and the storage medium to read and measure and verify the startup firmware. This process effectively isolates the main control module, preventing the loading of unverified firmware and enhancing the anti-attack ability of the system; if the measurement verification passes, the system will smoothly switch back to the main control module to complete the firmware loading and startup, and the whole process is smooth and reliable; on the contrary, if the measurement verification fails, the reset state of the main control module will continue to be maintained, preventing the operation of potential malware and ensuring the integrity of the system. This step-by-step control strategy not only improves the security of the system, but also simplifies the startup process, reduces unnecessary waiting time, improves the user experience, and at the same time ensures that the system can operate stably and reliably even in a complex security threat environment. In addition, since the analog switch module does not participate in signal transmission, it is not limited by the bandwidth of the analog switch module. This means that the speed and stability of data transmission depend entirely on the direct interface between the storage medium and the main control module or the security module, rather than the performance of the analog switch. This design avoids the signal delay and bandwidth bottleneck problems that may be brought by traditional multi-channel analog switches, ensuring that the requirements for high-speed data transmission are met. Especially in application scenarios that require fast startup and frequent access to the storage medium, this design can significantly improve the response speed and overall performance of the system, thus providing a smoother and more efficient user experience for users.
[0071] The above-described embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present application, and should all be included in the protection scope of the present application.
Claims
1. A trusted measurement control device, characterized in that, It includes a security module, an analog switch module, a main control module, and a storage medium; The reset signal output terminal of the security module is connected to the reset signal input terminal of the main control module. The analog switch switching control signal output terminal of the security module is connected to the controlled terminal of the analog switch module. The first input terminal of the analog switch module is connected to the security module. The second input terminal of the analog switch module is connected to the main control module. The output terminal of the analog switch module is connected to the storage medium. The data input terminal of the security module is connected to the first data interface of the storage medium. The data input terminal of the main control module is connected to the first data interface or the second data interface of the storage medium.
2. The trusted measurement control device according to claim 1, wherein The storage medium is a NOR flash memory or an embedded multimedia card.
3. The trusted measurement control device according to claim 2, wherein When the storage medium is a NOR flash memory, the CS interface of the security module is connected to the first input terminal of the analog switch module. The CS interface of the main control module is connected to the second input terminal of the analog switch module. The output terminal of the main control module is connected to the CS interface of the storage medium.
4. The trusted measurement control device according to claim 2, wherein When the storage medium is a NOR flash memory, the SPI interface of the security module is connected to the SPI / QSPI interface of the storage medium.
5. The trusted measurement control device according to any one of claims 2 to 4, characterized in that When the storage medium is a NOR flash memory, the SPI interface of the main control module is connected to the SPI / QSPI interface of the storage medium, or the QSPI interface of the main control module is connected to the SPI / QSPI interface of the storage medium.
6. The trusted measurement control device according to claim 2, wherein When the storage medium is an embedded multimedia card, the IO_CMD interface of the security module is connected to the first input terminal of the analog switch module. The CMD interface of the main control module is connected to the second input terminal of the analog switch module. The output terminal of the main control module is connected to the CMD interface of the storage medium.
7. The trusted measurement control device according to claim 2 or 6, characterized in that, When the storage medium is an embedded multimedia card, the data input terminal of the security module is connected to the data interface of the storage medium through a single data line. The data input terminal of the main control module is connected to the data interface of the storage medium through multiple data lines.
8. The trusted measurement control device according to any one of claims 1 to 4 and 6, characterized in that The analog switch module includes a single-pole double-throw switch. The first input terminal of the single-pole double-throw switch is the first input terminal of the analog switch module. The second input terminal of the single-pole double-throw switch is the second input terminal of the analog switch module. The common terminal of the single-pole double-throw switch is the output terminal of the analog switch module.
9. The trusted measurement control device according to any one of claims 1 to 4 and 6, characterized in that Resistors are provided between the data input terminal of the security module and the first data interface of the storage medium, and between the data input terminal of the main control module and the first data interface or the second data interface of the storage medium.
10. The trusted measurement control device according to any one of claims 1 to 4 and 6, characterized in that, Resistors are provided between the first input terminal of the analog switch module and the security module, and between the second input terminal of the analog switch module and the main control module.