Decryption FPGA encryption authentication circuit
By designing a decryption FPGA encryption authentication circuit, utilizing the data interaction between the microcontroller and memory module, and combining carefully designed circuit components, the problem of low reliability in existing FPGA encryption methods is solved, achieving efficient decryption and stable operation of FPGA devices, and improving system security and development efficiency.
Patent Information
- Application Number
- CN202520353781.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Utility models(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-03
- Publication Date
- 2026-02-13
- Estimated Expiration
- 2035-03-03
AI Technical Summary
Existing FPGA encryption methods mainly rely on the SHA-1 algorithm at the software level for decryption, which is technically difficult and has low reliability, making it difficult to effectively protect the data security of critical equipment.
Design an FPGA encryption authentication circuit for decryption, including a microcontroller module U1 and a memory module U2. Combined with components such as a crystal oscillator circuit, a filter circuit, a current-limiting resistor, and a capacitor, the circuit realizes the storage and retrieval of encrypted authentication data through data interaction between the microcontroller and the memory. LED indicators provide feedback on the working status, and a download power supply pin supports program download and debugging.
It enables efficient decryption of FPGA devices, ensures data security, improves system stability and maintainability, simplifies the development process, reduces faults caused by power fluctuations and signal interference, and provides intuitive circuit status indication.
Smart Images

Figure CN223911250U_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The utility model relates to FPGA logic design technical field, concretely relates to a decryption FPGA encryption authentication circuit. BACKGROUND
[0002] In the design of modern electronic system, the high speed FPGA needs to load its configuration data into internal SRAM when running, changes the data in SDRAM (synchronous dynamic memory), so that FPGA realizes different functions. But because it adopts the technology based on SRAM, it will reconfigure FPGA every time when power on, so it can realize the copy of design by monitoring the method of FPGA configuration pin bit stream, therefore, in the design of key equipment, the encryption technology will be adopted. At present, there are many encryption methods for FPGA, and the chip encryption using SHA-1 algorithm is one of them, and the decryption method of this encryption is mostly to crack SHA-1 algorithm in software level, which has high technical difficulty, difficult to realize and low reliability. Therefore, the utility model provides a decryption FPGA encryption authentication circuit to improve the above problems. UTILITY MODEL CONTENTS
[0003] Therefore, the technical problem to be solved by the utility model is to overcome the defects in the above, so as to provide a decryption FPGA encryption authentication circuit.
[0004] In order to solve the above problems, the utility model provides a decryption FPGA encryption authentication circuit, which comprises:
[0005] The microcontroller module U1 and the memory module U2 are connected, the microcontroller module U1 is connected with the first crystal oscillator circuit Y1 and the second crystal oscillator circuit Y2, and further comprises: a download power supply 4Pin pin S1, an LED indicator D1, an upper pull resistance AR1, an upper pull resistance BR20, an OUT3Pin pin S3, a first pull-down resistance R4, a second pull-down resistance R5, a first current limiting resistance R3, a first filter capacitor C13, a second filter capacitor C14, a third filter capacitor C3, a fourth filter capacitor C8, a fifth filter capacitor C9, a first electrolytic capacitor C11, a second electrolytic capacitor C12 and a third electrolytic capacitor C4.
[0006] Preferably, the PA1, PA2, PA3, PA4, PA5, PA6, PA7, PB10, PB11, PB9, PB8, PB15, PB14, PB13, PB13, PB12 pins of the microcontroller module U1 are connected with the LE, RE, CLE, WP, RB, CE, WE, DQ2, DQ3, DQ1, DQ0, DQ7, DQ6, DQ5, DQ4 pins of the memory module U2 respectively.
[0007] Preferably, the first filter capacitor C13 is connected in parallel with the second filter capacitor C14, the first electrolytic capacitor C11 is connected in parallel with the second electrolytic capacitor C12, the negative poles of the first electrolytic capacitor C11 and the second electrolytic capacitor C12 are grounded, and the positive poles of the first electrolytic capacitor C11 and the second electrolytic capacitor C12 are connected to the VDD_1, VDD_2, VDD_3 pins of the microcontroller module U1 and the VCC1, VCC2 pins of the memory module U2.
[0008] Preferably, the microcontroller module U1 is STM32f103c8t6, which adopts LQFP48 packaging, and the memory module U2 is H27U4G8F2DTR, which adopts SOP-48 packaging.
[0009] Preferably, one end of the first pull-down resistor R4 is grounded, the other end of the first pull-down resistor R4 is connected to the BOOT0 pin of the microcontroller module U1, one end of the second pull-down resistor R5 is grounded, and the other end of the second pull-down resistor R5 is connected to the BOOT1 pin of the memory module U2.
[0010] The negative pole of the LED indicator D1 is connected in series with the first current-limiting resistor R3 and the OUT3 pin S3, respectively, and the negative pole of the LED indicator D1 is grounded.
[0011] Preferably, the first crystal oscillator circuit Y1 is connected to the PC14 pin and the PC15 pin of the microcontroller module U1, respectively, and the second crystal oscillator circuit Y2 is connected to the OSCIN and OSCOUT of the microcontroller module U1.
[0012] Preferably, the third pin and the fourth pin of the download power supply 4-pin pin S1 are connected to the SWDCLK and SWDIO pins of the microcontroller module U1, respectively, the first pin and the second pin of the download power supply 4-pin pin S1 are connected in parallel with the third filter capacitor C3 and the third electrolytic capacitor C4, respectively, and the second pin of the download power supply 4-pin pin S1 is also grounded.
[0013] The fourth filter capacitor C8 is connected to the VDD_3 and VSS_3 pins of the microcontroller module U1, respectively, the fifth filter capacitor C9 is connected to the VDD_2 and VSS_2 pins of the microcontroller module U1, respectively, the pull-up resistor AR1 is connected in series with the RESET pin of the microcontroller module U1, and the pull-up resistor BR20 is connected in series with the PA5 pin of the microcontroller module U1.
[0014] Preferably, the first current-limiting resistor R3 and the pull-up resistor BR20 are each 1KΩ, and the pull-up resistor AR1, the first pull-down resistor R4, and the second pull-down resistor R5 are all 10KΩ.
[0015] Preferably, the first electrolytic capacitor C11, the second electrolytic capacitor C12, and the third electrolytic capacitor C4 are all 10uF / 16V; the first filter capacitor C13, the second filter capacitor C14, the third filter capacitor C3, the fourth filter capacitor C8, and the fifth filter capacitor C9 are all 100NF.
[0016] Preferably, the first crystal oscillator circuit Y1 consists of a passive crystal oscillator with a frequency of 32.76K and two 22pF capacitors connected in series; the second crystal oscillator circuit Y2 consists of a passive crystal oscillator with a frequency of 8M, two 22pF capacitors connected in series and a 1M resistor.
[0017] The decryption FPGA encryption authentication circuit provided by this utility model has the following beneficial effects:
[0018] This invention can decrypt the circuits of most FPGA encryption and authentication systems equipped with SHA-1 algorithm chips, and has universality. The circuit logic in this application is simple, without special topology, highly stable, and has a fast response speed. Through data interaction between the microcontroller and the memory, as well as the storage and retrieval of encrypted authentication data, it effectively ensures the security of data in the FPGA device and prevents data from being illegally stolen or tampered with. The carefully designed crystal oscillator circuit, power supply filter circuit, and reasonable resistor and capacitor configuration ensure that the circuit can operate stably in various environments, reducing failures caused by power fluctuations, signal interference, and other factors. The 4-pin power supply design facilitates developers to download and debug programs to the microcontroller, making it easier to upgrade and optimize functions, improving development efficiency and system maintainability. The LED indicator in this application can indicate whether the circuit is powered on. Attached Figure Description
[0019] Figure 1 This is a schematic diagram of the circuit principle of this utility model. Detailed Implementation
[0020] like Figure 1 As shown, this utility model provides a decryption FPGA encryption authentication circuit, which includes:
[0021] The microcontroller module U1 and the memory module U2 are connected, the microcontroller module U1 is connected with the first crystal oscillator circuit Y1 and the second crystal oscillator circuit Y2, and the circuit further comprises: a download power supply 4Pin pin S1, an LED indicator D1, a pull-up resistor AR1, a pull-up resistor BR20, an OUT3Pin pin S3, a first pull-down resistor R4, a second pull-down resistor R5, a first current limiting resistor R3, a first filter capacitor C13, a second filter capacitor C14, a third filter capacitor C3, a fourth filter capacitor C8, a fifth filter capacitor C9, a first electrolytic capacitor C11, a second electrolytic capacitor C12 and a third electrolytic capacitor C4.
[0022] Specifically, the decryption FPGA encryption authentication circuit is realized by using the microcontroller module U1 and the memory module U2 in combination to realize the decryption or replacement of any SHA-1 chip.
[0023] Specifically, in use, the microcontroller module U1 is used to send a random code to the encryption chip simulation FPGA, and then the MAC output by the encryption chip is obtained and burned into the memory; when the microcontroller module U1 sends a random code to the simulation encryption chip in the FPGA, the corresponding MAC in the memory is obtained and sent to the FPGA to complete decryption; after obtaining the encryption chip, the pins of the chip are connected to the OUT3Pin pin S3 through a flying wire, the MAC program obtained by the encryption chip is downloaded into the STM32f103c8t6 through the download power supply 4Pin pin S1, and the obtained MAC is stored in the computer through serial port software; after the MAC is checked for leakage and defects using the calibration program, it is stored in the form of Bit and burned into the H27U4G8F2DTR using the burner, and then it is welded into the circuit; the response sending program is downloaded into the STM32f103c8t6 through the download power supply 4Pin pin S1, and the OUT3Pin pin S3 is connected to the FPGA.
[0024] Specifically, when the circuit is powered on, the first crystal oscillator circuit Y1 and the second crystal oscillator circuit Y2 start working quickly, and provide different frequency clock signals for the microcontroller module U1; wherein the low frequency clock signal is used to meet the low clock frequency requirement of the RTC and other functional modules, and the high frequency clock signal provides the required clock reference for the microcontroller in high speed operation such as data processing and instruction execution; the microcontroller module U1 reads the stored encryption authentication data from the memory according to the preset program through the pins connected with the memory module U2; these data contain encryption keys, authentication information and other key contents; during the reading process, the microcontroller and the memory are connected through specific pins for data transmission and control signal interaction, to ensure accurate reading and processing of data.
[0025] Wherein, in the system running process, the download power supply 4Pin pin S1 can be used to update the program of microcontroller or debugging operation at any time; the developer can download the new program into the microcontroller through the interface, realize the upgrade or optimization of function; at the same time, when the circuit appears fault, the debugging can also be carried out through the interface, and the problem can be checked out; the LED indicating lamp D1 can carry out corresponding indication according to the working state of the circuit in real time; when the circuit runs normally, the indicating lamp is lighted; when the abnormal situation appears, the indicating lamp can flash or extinguish, which provides intuitive working state feedback for the user.
[0026] Wherein, the peripheral circuit composed of resistors and capacitors in the whole circuit plays an indispensable role; on the one hand, the peripheral circuit provides stable power supply for the whole circuit, removes the noise and ripple in the power supply through the filter capacitor, and ensures the purity of the power supply; on the other hand, the correct logic level is set through the pull-up resistor and the pull-down resistor, which ensures the accurate signal transmission and logic control between the modules; through the cooperative work of these components, it is ensured that the FPGA encryption authentication circuit can work normally and stably, and the encryption authentication function of the FPGA device is realized.
[0027] Specifically, a decryption FPGA encryption authentication circuit cooperates with obtaining an encryption chip MAC program, a calibration program and a response sending program, the encryption chip MAC program is obtained by simulating the FPGA to communicate with the encryption chip to obtain the mac information corresponding to each random code, a total of three times of communication with the encryption chip are needed, the first communication is mainly to collect the 64-bit ROM registration number of the encryption chip, after successfully communicating with the encryption chip through the 1-Wire protocol, the STM32f103c8t6 initiates a read ROM command signal (CCH), and then enters the input mode to receive the ROM registration number sent by the encryption chip to the STM32f103c8t6, the registration number is read out through the logic analyzer and noted down, the second communication is to send a 64-bit random code, the encryption chip will generate the corresponding MAC address by reading the corresponding random code, it is found through many experiments that the 32nd to 55th bits of the random code will change, so the corresponding MAC of the 24-bit random code which will change needs to be collected, the third communication needs to read the address information sent by the DS2432, and it is verified that the encryption chip will send the same address information each time; after the sending is completed, the encryption chip will send a segment of MAC and the end CRC data information, the second communication will send the random code many times, the corresponding MAC information needs to be printed out through the serial port and saved here;
[0028] Wherein, the calibration program is to integrate MAC information file and find the accuracy of MAC information, in the first program we will save the MAC information to the local, but because of the collection will lead to encryption chip work heat, resulting in unstable chip, may appear encryption chip does not work and other problems. After the experiment found that each collection 256*256*3 group of data most stable, so the first program will be collected MAC information for many times, will generate multiple MAC information file, first we need to integrate multiple files into one file, first traverse all the files in the folder, get the file name, then open the file according to the file name, integrate the information into a file, in the first program to collect data, due to the instability of the serial port, the data printed by the serial port will appear missing several bits of data, after integration, we also need to check the accuracy of the data, the data we collect is 176 bits, check the integrated file and judge whether the data is 176 bits, the data that appears error needs to repeat the first program to collect again, so as to obtain a complete MAC data information, finally burn into the H27U4G8F2DTR prepared in advance.
[0029] Wherein, the answer sending program is to simulate the encryption chip to communicate with FPGA to crack the encryption, which corresponds to the first program and also needs to communicate three times, the first communication we need to simulate the encryption chip to send the ROM registration number to FPGA, in the above we have read the ROM registration number of the encryption chip in advance, here we can directly send the known registration number, the second communication FPGA will send random code, after reading the random code, we need to find the correct MAC information in H27U4G8F2DTR through calculation and read out the MAC information, the third communication we need to send the address information read out above, after 830us delay, we need to send the correct MAC information found in the second communication, if the FPGA will not produce signal again if the sending is correct, at this time the communication encryption has been successfully decrypted.
[0030] In some embodiments, the PA1, PA2, PA3, PA4, PA5, PA6, PA7, PB10, PB11, PB9, PB8, PB15, PB14, PB13, PB13, PB12 pins of the microcontroller module U1 are connected to the LE, RE, CLE, WP, RB, CE, WE, DQ2, DQ3, DQ1, DQ0, DQ7, DQ6, DQ5, DQ4 pins of the memory module U2, respectively.
[0031] In some embodiments, the first filter capacitor C13 is connected in parallel with the second filter capacitor C14, the first electrolytic capacitor C11 is connected in parallel with the second electrolytic capacitor C12, the negative poles of the first electrolytic capacitor C11 and the second electrolytic capacitor C12 are grounded, and the positive poles of the first electrolytic capacitor C11 and the second electrolytic capacitor C12 are connected to the VDD_1, VDD_2, VDD_3 pins of the microcontroller module U1 and the VCC1, VCC2 pins of the memory module U2.
[0032] In some embodiments, the microcontroller module U1 is STM32f103c8t6 in LQFP48 package, and the memory module U2 is H27U4G8F2DTR in SOP-48 package.
[0033] In some embodiments, one end of the first pull-down resistor R4 is grounded, the other end of the first pull-down resistor R4 is connected to the BOOT0 pin of the microcontroller module U1, one end of the second pull-down resistor R5 is grounded, and the other end of the second pull-down resistor R5 is connected to the BOOT1 pin of the memory module U2.
[0034] The negative pole of the LED indicator D1 is connected in series with the first current-limiting resistor R3 and the OUT3 pin S3, respectively, and the negative pole of the LED indicator D1 is grounded.
[0035] In some embodiments, the first crystal oscillator circuit Y1 is connected to the PC14 pin and the PC15 pin of the microcontroller module U1, respectively, and the second crystal oscillator circuit Y2 is connected to the OSCIN and OSCOUT of the microcontroller module U1.
[0036] In some embodiments, the third pin and the fourth pin of the download power supply 4-pin pin S1 are connected to the SWDCLK and SWDIO pins of the microcontroller module U1, respectively, the first pin and the second pin of the download power supply 4-pin pin S1 are connected in parallel with the third filter capacitor C3 and the third electrolytic capacitor C4, respectively, and the second pin of the download power supply 4-pin pin S1 is also grounded.
[0037] The fourth filter capacitor C8 is connected to the VDD_3 and VSS_3 pins of the microcontroller module U1, respectively, the fifth filter capacitor C9 is connected to the VDD_2 and VSS_2 pins of the microcontroller module U1, respectively, the pull-up resistor AR1 is connected in series with the RESET pin of the microcontroller module U1, and the pull-up resistor BR20 is connected in series with the PA5 pin of the microcontroller module U1.
[0038] In some embodiments, the first current limiting resistor R3, the pull-up resistor BR20 is 1KΩ, the pull-up resistor AR1, the first pull-down resistor R4, the second pull-down resistor R5 are all 10KΩ.
[0039] In some embodiments, the first electrolytic capacitor C11, the second electrolytic capacitor C12, the third electrolytic capacitor C4 are all 10UF / 16V; the first filter capacitor C13, the second filter capacitor C14, the third filter capacitor C3, the fourth filter capacitor C8, the fifth filter capacitor C9 are all 100NF.
[0040] In some embodiments, the first crystal oscillator circuit Y1 is composed of a 32.76K frequency without rim crystal oscillator and two 22PF capacitors in series; the second crystal oscillator circuit Y2 is composed of a 8M frequency without rim crystal oscillator, two 22PF capacitors in series and a 1M resistor.
[0041] In the present application, the circuit of the FPGA encryption authentication system with most of the chips carrying the SHA-1 algorithm can be decrypted, which is universal; the circuit in the present application; the circuit in the present application is simple in logic, without special topology, high in stability, fast in response, and through the data interaction between the microcontroller and the memory and the storage and reading of the encryption authentication data, the safety of the data in the FPGA device is effectively guaranteed, and the data is prevented from being illegally stolen or tampered with; the carefully designed crystal oscillator circuit, power filter circuit and reasonable resistance and capacitance configuration ensure that the circuit can run stably in various environments, reduce the faults caused by power fluctuation, signal interference and other factors; the design of the 4Pin pin of the download power supply facilitates the developers to download and debug the program of the microcontroller, facilitates the upgrading and optimization of the function, improves the development efficiency and the maintainability of the system; the LED indicator light in the present application can indicate whether the circuit is in the power-on state.
[0042] The above only describes the preferred embodiments of the present application, and does not limit the present application, and any modification, equivalent replacement and improvement made within the spirit and principle of the present application shall be included in the protection scope of the present application. The above only describes the preferred embodiments of the present application, and it should be pointed out that for ordinary skilled in the art, without departing from the technical principles of the present application, a number of improvements and modifications can be made, which should be regarded as the protection scope of the present application.
Claims
1. A decryption FPGA encryption authentication circuit, characterized by, include: The system includes a microcontroller module U1 and a memory module U2, which are connected together. The microcontroller module U1 is connected to a first crystal oscillator circuit Y1 and a second crystal oscillator circuit Y2. It also includes: a 4-pin power supply connector S1, an LED indicator D1, a pull-up resistor AR1, a pull-up resistor BR20, a 3-pin OUT connector S3, a first pull-down resistor R4, a second pull-down resistor R5, a first current-limiting resistor R3, a first filter capacitor C13, a second filter capacitor C14, a third filter capacitor C3, a fourth filter capacitor C8, a fifth filter capacitor C9, a first electrolytic capacitor C11, a second electrolytic capacitor C12, and a third electrolytic capacitor C4.
2. The decryption FPGA encryption authentication circuit according to claim 1, characterized in that: The PA1, PA2, PA3, PA4, PA5, PA6, PA7, PB10, PB11, PB9, PB8, PB15, PB14, PB13, PB13, and PB12 pins of the microcontroller module U1 are respectively connected to the LE, RE, CLE, WP, RB, CE, WE, DQ2, DQ3, DQ1, DQ0, DQ7, DQ6, DQ5, and DQ4 pins of the memory module U2.
3. The decryption FPGA encryption authentication circuit according to claim 2, characterized in that: The first filter capacitor C13 is connected in parallel with the second filter capacitor C14, the first electrolytic capacitor C11 is connected in parallel with the second electrolytic capacitor, the negative terminals of the first electrolytic capacitor C11 and the second electrolytic capacitor are grounded, and the positive terminals of the first electrolytic capacitor C11 and the second electrolytic capacitor C12 are connected to the VDD_1, VDD_2, and VDD_3 pins of the microcontroller module U1 and the VCC1 and VCC2 pins of the memory module U2.
4. The decryption FPGA encryption authentication circuit according to claim 2, characterized in that: The microcontroller module U1 is an STM32f103c8t6, packaged in an LQFP48 package; the memory module U2 is an H27U4G8F2DTR, packaged in an SOP-48 package.
5. The decryption FPGA encryption authentication circuit according to claim 2, characterized in that: One end of the first pull-down resistor R4 is grounded, and the other end of the first pull-down resistor R4 is connected to the BOOT0 pin of the microcontroller module U1. One end of the second pull-down resistor R5 is grounded, and the other end of the second pull-down resistor R5 is connected to the BOOT1 pin of the memory module U2. The negative terminal of the LED indicator D1 is connected in series with the first current-limiting resistor R3 and the pin of the OUT3Pin connector S3, respectively, and the negative terminal of the LED indicator D1 is grounded.
6. The decryption FPGA encryption authentication circuit according to claim 2, characterized in that: The first crystal oscillator circuit Y1 is connected to the PC14 and PC15 pins of the microcontroller module U1, respectively, and the second crystal oscillator circuit Y2 is connected to the OSCIN and OSCOUT pins of the microcontroller module U1.
7. The decryption FPGA encryption authentication circuit according to claim 2, characterized in that: the third pin and the fourth pin of the download power supply 4-pin pin S1 are connected with the SWDCLK and SWDIO pins of the microcontroller module U1 respectively, the first pin and the second pin of the download power supply 4-pin pin S1 are connected with the third filter capacitor C3 and the third electrolytic capacitor C4 in parallel respectively, and the second pin of the download power supply 4-pin pin S1 is also grounded; the two ends of the fourth filter capacitor C8 are connected with the VDD_3 and VSS_3 pins of the microcontroller module U1 respectively, the two ends of the fifth filter capacitor C9 are connected with the VDD_2 and VSS_2 pins of the microcontroller module U1 respectively, the pull-up resistor AR1 is connected with the RESET pin of the microcontroller module U1 in series, and the pull-up resistor BR20 is connected with the PA5 pin of the microcontroller module U1 in series.
8. The decryption FPGA encryption authentication circuit according to claim 2, characterized in that: the values of the first current-limiting resistor R3 and the pull-up resistor BR20 are 1KΩ, and the values of the pull-up resistor AR1, the first pull-down resistor R4 and the second pull-down resistor R5 are all 10KΩ.
9. The decryption FPGA encryption authentication circuit according to claim 2, characterized in that: the values of the first electrolytic capacitor C11, the second electrolytic capacitor C12 and the third electrolytic capacitor C4 are all 10UF / 16V, and the values of the first filter capacitor C13, the second filter capacitor C14, the third filter capacitor C3, the fourth filter capacitor C8 and the fifth filter capacitor C9 are all 100NF.
10. The decryption FPGA encryption authentication circuit according to claim 6, characterized in that: the first crystal oscillator circuit Y1 is composed of a 32.76K frequency no-margin crystal oscillator and two 22PF capacitors connected in series, and the second crystal oscillator circuit Y2 is composed of an 8M frequency no-margin crystal oscillator, two 22PF capacitors connected in series and a 1M resistor.