DAC calibration control circuit with security check
Patent Information
- Application Number
- CN202522267788.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Utility models(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-27
- Publication Date
- 2026-09-15
- Estimated Expiration
- 2035-10-27
AI Technical Summary
然而,这种直接控制方式存在固有的安全隐患
[0020] This invention establishes a strict write operation authorization and interlocking mechanism at the hardware level by setting up a security gating module (3) independent of the conventional data path. Any write operation of the main control unit to the data latch (4) must be preceded by an access to a preset gate address to set the status register (U2A) in the security gating module (3), thereby generating a momentary "write enable" signal (GATE_EN). Any write attempt that does not conform to this operation sequence will be blocked by the hardware-level write control logic due to the lack of a valid "write enable" signal. This design fundamentally eliminates accidental or illegal data writing to the DAC caused by software program abnormalities, bus signal interference, etc., ensuring that the DAC value can only be updated when actively authorized by the software.
Smart Images

Figure CN224760238U_ABST
Abstract
Description
Technical Field
[0001] This utility model belongs to the field of electronic circuit technology, specifically relating to a DAC calibration control circuit with security verification. Background Technology
[0002] Digital-to-analog converters (DACs) are key components widely used in modern electronic systems. They are responsible for converting digital signals from digital processing units such as microcontrollers (MCUs) into analog signals such as voltage or current. In fields such as industrial automation, medical equipment, precision measuring instruments, and communication systems, the accuracy and stability of the analog signals output by DACs are crucial, directly affecting the performance and safety of the entire system.
[0003] In conventional DAC control circuit design, the MCU is typically connected directly to the data input of the DAC chip via its parallel or serial bus. The MCU's software program is responsible for calculating and sending digital codes to control the DAC to output corresponding analog signals. However, this direct control method inherently presents security risks. In complex systems, the MCU's software may malfunction due to program errors, memory overflows, or external interference, such as a program pointer malfunction, which could cause the MCU to write incorrect data to the DAC's bus address at an unexpected time. Furthermore, electromagnetic interference (EMI) or signal transients on the system bus can generate forged write signals, leading to accidental data tampering with the DAC. These erroneous write operations can cause the DAC to produce unexpected analog outputs, ranging from minor performance degradation or production interruptions to serious damage to downstream equipment or even safety incidents. Existing technologies typically rely on improving software reliability to avoid such problems, lacking an effective means of enforced constraints and protection at the hardware level. Therefore, how to prevent accidental or illegal writing to the DAC and ensure the integrity and controllability of the analog output signal under any circumstances is a pressing technical problem that needs to be solved in this field. Utility Model Content
[0004] The purpose of this invention is to address the deficiencies mentioned in the background art by proposing a DAC calibration control circuit with security verification.
[0005] The technical solution adopted in this utility model is as follows:
[0006] This utility model provides a DAC calibration control circuit with security verification, comprising:
[0007] One or more data latching and readback modules, wherein the parallel output of the data latching and readback module is connected to the data input of a digital-to-analog converter, and the data input of the data latching and readback module is connected to the data bus of a main control unit;
[0008] An address decoding module is connected to the address bus and control bus of the main control unit, and is used to generate at least one data strobe signal for selecting the data latch and readback module, and a gate reset signal Y2 according to a preset address;
[0009] A security gating module, the security gating module includes a status register, the output of the status register generates a security gating signal GATE_EN, the status register has a set input for setting it and a clear input for clearing it;
[0010] The set input of the status register is connected to the gate reset signal Y2 output by the address decoding module. It is used to set the status register when the main control unit accesses a preset gate address, so that the security gate signal GATE_EN enters the open state.
[0011] The circuit also includes write control logic. The input of the write control logic is connected to the security gating signal GATE_EN, the data strobe signal, and the write signal WR of the main control unit. The output of the write control logic is connected to the clock input CLK of the data latch and readback module. The write control logic generates a valid write pulse based on the data strobe signal and the write signal WR only when the security gating signal GATE_EN is in the enabled state, thereby triggering the data latch and readback module to latch the data.
[0012] As a preferred embodiment of this utility model, the clear input terminal of the status register is connected to the output terminal of the write control logic, and is used to clear the status register when the write control logic generates a valid write pulse, so that the security gate signal GATE_EN enters the closed state.
[0013] As a preferred embodiment of this utility model, the security gating module further includes a second logic gate, and the output of the write control logic is connected to the clear input of the status register through the second logic gate.
[0014] As a preferred embodiment of this utility model, the data latching and readback module has an output enable terminal; the circuit further includes read control logic, the input terminal of which is connected to the data strobe signal and the read signal RD of the main control unit, and its output terminal is connected to the output enable terminal of the data latching and readback module, which is used to enable the data latching and readback module to output the data latched inside to the data bus for readback verification when the main control unit performs a read operation.
[0015] As a preferred technical solution of this utility model, the data latching and readback module includes a low 8-bit data latching and readback module and a high 8-bit data latching and readback module, which together form a 16-bit data latching channel.
[0016] As a preferred technical solution of this utility model, the first strobe signal Y0 generated by the address decoding module is used to select the lower 8-bit data latch and readback module, and the second strobe signal Y1 generated is used to select the higher 8-bit data latch and readback module.
[0017] In a preferred embodiment of this invention, the status register is a D-type flip-flop.
[0018] As a preferred embodiment of this invention, the circuit further includes an analog output buffer stage composed of an operational amplifier, which is connected to the analog signal output terminal of the digital-to-analog converter.
[0019] The DAC calibration control circuit with security verification provided by this utility model has the following advantages compared with the prior art:
[0020] This invention establishes a strict write operation authorization and interlocking mechanism at the hardware level by setting up a security gating module (3) independent of the conventional data path. Any write operation of the main control unit to the data latch (4) must be preceded by an access to a preset gate address to set the status register (U2A) in the security gating module (3), thereby generating a momentary "write enable" signal (GATE_EN). Any write attempt that does not conform to this operation sequence will be blocked by the hardware-level write control logic due to the lack of a valid "write enable" signal. This design fundamentally eliminates accidental or illegal data writing to the DAC caused by software program abnormalities, bus signal interference, etc., ensuring that the DAC value can only be updated when actively authorized by the software.
[0021] Furthermore, the "automatic door-closing" feedback path designed in this invention ensures that the status register (U2A) is immediately cleared after any valid data write pulse is generated, thus instantly ending the "write enable" state and restoring the circuit to the default write-protected state. This mechanism minimizes the system's allowed write time window, greatly reducing the risk of interference during this window period, further enhancing the circuit's reliability and security, and ensuring a high degree of integrity and controllability of the DAC analog output signal. Attached Figure Description
[0022] Figure 1 This is a module connection diagram of a specific embodiment of the present invention.
[0023] Explanation of reference numerals in the attached diagram: 1. MCU bus interface module; 2. Address decoding module; 3. Security gating module; 4. Data latch and readback module; 5. DAC and analog output module. Detailed Implementation
[0024] It should be noted that, unless otherwise specified, the embodiments and features described in this embodiment can be combined with each other. The technical solutions of this utility model will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this utility model, and not all of them. All other embodiments obtained by those skilled in the art based on the embodiments of this utility model without creative effort are within the scope of protection of this utility model.
[0025] This utility model embodiment provides a DAC calibration control circuit with security verification. This circuit ensures that the control process of the DAC by the main control unit (MCU) is safe, orderly, and verifiable through hardware-level gating interlocking and readback verification mechanisms, thereby effectively preventing erroneous analog signal output caused by software anomalies or bus interference. (See attached diagram) Figure 1 This is a module connection diagram of a specific embodiment of the present invention.
[0026] like Figure 1 As shown, the system in this embodiment mainly includes: an MCU bus interface module 1, an address decoding module 2, a security gating module 3, a data latching and readback module 4, and a DAC and analog output module 5. The MCU bus interface module 1 is used to connect to an external master control unit (MCU), which provides the address bus signals (such as A0-A15), data bus signals (D0-D7), and control bus signals (such as chip select signal / CS, write signal / WR, and read signal / RD) required by the circuit.
[0027] The core component of address decoding module 2 is an address decoder U1, such as a 3-to-8 line decoder of model 74HCT138. This decoder U1 is connected to the address bus and control bus of the MCU. Specifically, its address inputs (A0, A1, A2) receive the low-order address bits of the MCU address bus, while its enable inputs (e.g., E3, / E2) are connected to the high-order address lines of the MCU (e.g., A15) and the master chip select signal / CS. In this way, this circuit module is mapped to a specific memory address space of the MCU. When the MCU accesses this preset address space, the address decoder U1 generates a unique, active-low strobe signal at its output based on the specific address. In this embodiment, these strobe signals include a first strobe signal / Y0 (SEL_LSB) for strobe the lower 8-bit data latch and readback module, a second strobe signal / Y1 (SEL_MSB) for strobe the higher 8-bit data latch and readback module, and a gate reset signal / Y2 (RST_GATE) for controlling the security gate module 3.
[0028] The data latch and readback module 4 is used to write a 16-bit target digital code in two steps via an 8-bit data bus, providing a stable 16-bit parallel digital input to the DAC core. In this embodiment, this module includes a low-8-bit data latch and readback module U3 and a high-8-bit data latch and readback module U4, both of which can use D-type flip-flop chips with tri-state output functionality, such as the 74HCT574. The data input terminals (D0-D7) of both latches are connected in parallel to the MCU's data bus. Their clock input terminals (CLK) receive the low-8-bit write pulse ( / WR_LSB) and high-8-bit write pulse ( / WR_MSB) generated by the write control logic, respectively. When a valid write pulse arrives, the latch captures and latches the 8 bits of data currently on the data bus. The parallel output terminals (Q0-Q7) of latches U3 and U4 together form a 16-bit data line, which is connected to the low-8-bit and high-8-bit input terminals of the DAC core U5, respectively. Furthermore, a key function of the data latch and readback module 4 is to support data readback verification. Both latches U3 and U4 have an active-low output enable pin ( / OE). This / OE pin is connected to the read control logic. When the MCU performs a read operation, the read signal / RD and the corresponding address strobe signal ( / Y0 or / Y1) work together to enable the / OE pin of the corresponding latch. At this time, the latch will re-drive its internally latched data onto the MCU's data bus. After the MCU reads this data, it can compare it with the previously sent value, thus verifying the correctness of the data write at the hardware level, which greatly enhances the system's reliability.
[0029] The security gating module 3 is the core of this invention. It constructs a hardware-level state interlocking mechanism to prevent any unauthorized or accidental write operations. This module includes a D-type flip-flop U2A (e.g., half of 74HCT74) as a status register, a first logic gate (NAND gate) for "opening the gate", and a second logic gate (OR gate) for "automatic closing the gate".
[0030] The workflow of security gating module 3 is as follows: First, in the default state of the circuit, the Q output of flip-flop U2A, i.e., the security gating signal (GATE_EN), is low, which is defined as the "gating off" state. At this time, any write operation to the data latch and readback module will be blocked by the hardware logic. When the MCU needs to update the DAC value, it must first perform a "gating on" operation. This operation is a write access to a preset special "gating address". After receiving the address, address decoder U1 will output the gating reset signal / Y2. This signal / Y2, together with the MCU's write signal / WR, serves as the input of the first logic gate GateNand. The output of GateNand is connected to the set terminal ( / PRE) of flip-flop U2A. Therefore, this special write access will cause flip-flop U2A to be set, making its Q output (GATE_EN) high, which is defined as the "gating on" or "write enable" state.
[0031] In the "gated" state, the circuit is authorized to perform one data write. One of the inputs of the write control logic of the data latch and readback module (composed of NAND gates WrLSB and WrMSB) is connected to the GATE_EN signal. Therefore, only when GATE_EN is high, combined with the corresponding address strobe signal ( / Y0 or / Y1) and the write signal / WR, can a valid write pulse ( / WR_LSB or / WR_MSB) be generated to drive the CLK terminal of the data latch and readback module, thereby successfully writing the data.
[0032] A key safety feature of this invention lies in its "automatic gate closing" mechanism. When any valid write pulse ( / WR_LSB or / WR_MSB) is generated, the pulse signal not only triggers the data latch but is also fed back to the input of the second logic gate, AutoCloseOr. The output of AutoCloseOr is connected to the clear terminal ( / CLR) of flip-flop U2A. This means that at the instant a data write operation is completed, flip-flop U2A is immediately cleared, causing the GATE_EN signal to return to a low level, and the "gate" automatically closes. This design ensures that the circuit's "write enable" state is instantaneous, returning to the default safe (write-disabled) state immediately after completing a single 8-bit data write. Therefore, to complete a full 16-bit data write, the MCU must strictly follow the operation sequence of "open gate -> write LSB -> (gate automatically closes) -> open gate again -> write MSB -> (gate automatically closes)". Any write operation that does not conform to this sequence will be rejected by the hardware.
[0033] Finally, the DAC and analog output module 5 is responsible for converting the successfully latched 16-bit digital code, which has undergone security verification, into the final analog signal. The core of this module is a 16-bit parallel-input digital-to-analog converter U5 (e.g., AD5761R). Its 16-bit data input is connected to the outputs of latches U3 and U4. Its load control terminal ( / LDAC) can be grounded, allowing the data to be converted by the DAC immediately after latching. To ensure the accuracy and drive capability of the output signal, a voltage follower consisting of a precision operational amplifier U6 (e.g., OPA2197) is connected after the DAC output (VOUT) as an output buffer stage. This buffer stage effectively isolates the DAC core from the external load, preventing load changes from affecting output accuracy and providing sufficient current drive capability. Furthermore, the circuit design should strictly distinguish between the digital power supply (+5V_D) and the analog power supply (+15V_A, -15V_A), and use independent digital and analog grounds connected at a single point to reduce the interference of digital noise on the analog signal.
[0034] In summary, this invention constructs a closed-loop, highly secure DAC control channel through the coordinated operation of address decoding, state gating, data latching, and hardware readback. It mandates that the main control unit adhere to a strict operating protocol, eliminating illegal DAC write operations caused by program crashes, bus conflicts, or transient interference at the hardware level, thus ensuring the stability and reliability of analog output in safety-critical fields such as industrial control, medical equipment, and precision instruments.
[0035] The above description is merely a preferred embodiment of the present utility model and is not intended to limit the scope of protection of the present utility model. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present utility model should be included within the scope of protection of the present utility model.
Claims
1. A DAC calibration control circuit with security verification, characterized in that, include: One or more data latch and readback modules (4), the parallel output of the data latch and readback module (4) is connected to the data input of a digital-to-analog converter (U5), and the data input of the data latch and readback module (4) is connected to the data bus of a main control unit; An address decoding module (2) is connected to the address bus and control bus of the main control unit, and is used to generate at least one data strobe signal for strobe the data latch and readback module (4) according to a preset address, and a gated reset signal Y2; A security gating module (3) includes a status register (U2A), the output of the status register (U2A) generates a security gating signal GATE_EN, and the status register (U2A) has a set input for setting it and a clear input for clearing it. The set input terminal of the status register (U2A) is connected to the gate reset signal Y2 output by the address decoding module (2), and is used to set the status register (U2A) when the main control unit accesses a preset gate address, so that the security gate signal GATE_EN enters the open state; The circuit also includes write control logic. The input of the write control logic is connected to the security gating signal GATE_EN, the data strobe signal and the write signal WR of the main control unit. The output of the write control logic is connected to the clock input CLK of the data latch and readback module (4). Only when the security gating signal GATE_EN is in the open state, the write control logic generates a valid write pulse according to the data strobe signal and the write signal WR to trigger the data latch and readback module (4) to latch the data.
2. The circuit according to claim 1, characterized in that, The clear input terminal of the status register (U2A) is connected to the output terminal of the write control logic. When the write control logic generates a valid write pulse, the status register (U2A) is cleared, so that the security gate signal GATE_EN enters the closed state.
3. The circuit according to claim 2, characterized in that, The security gating module (3) also includes a second logic gate, and the output of the write control logic is connected to the clear input of the status register (U2A) through the second logic gate.
4. The circuit according to claim 1, characterized in that, The data latch and readback module (4) has an output enable terminal; the circuit also includes read control logic, the input terminal of which is connected to the data strobe signal and the read signal RD of the main control unit, and its output terminal is connected to the output enable terminal of the data latch and readback module (4), which is used to enable the data latch and readback module (4) to output the data latched inside to the data bus for readback verification when the main control unit performs a read operation.
5. The circuit according to claim 1, characterized in that, The data latch and readback module (4) includes a low 8-bit data latch and readback module (U3) and a high 8-bit data latch and readback module (U4), which together form a 16-bit data latch channel.
6. The circuit according to claim 5, characterized in that, The address decoding module (2) generates a first strobe signal Y0 to select the lower 8-bit data latch and readback module (U3), and generates a second strobe signal Y1 to select the higher 8-bit data latch and readback module (U4).
7. The circuit according to claim 1, characterized in that, The status register (U2A) is a D-type flip-flop.
8. The circuit according to claim 1, characterized in that, The circuit also includes an analog output buffer stage consisting of an operational amplifier (U6), which is connected to the analog signal output terminal of the digital-to-analog converter (U5).