Secure Boot Control Method, Device, Electronic Device and Storage Medium of Chip
The secure boot control method for intelligent drive chips addresses the risk of data damage during decryption by verifying the integrity of decrypted data, ensuring functional safety and enhancing secure boot performance.
Patent Information
- Application Number
- JP2023147420
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2022-11-08
- Filing Date
- 2023-09-12
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2043-09-12
AI Technical Summary
The secure boot process of intelligent drive chips, which involves encryption and decryption operations, poses a risk of functional safety failures due to potential damage to decrypted data, leading to degraded secure boot performance.
A secure boot control method that involves determining mirror data and verification codes from decryption results, comparing these codes to ensure integrity, and executing secure boot programs only if the integrity verification passes, thereby preventing data damage during decryption.
This method ensures the functional safety of the hardware security module and enhances the security of the chip boot process by verifying the integrity of decrypted data, thus preventing potential failures and improving overall secure boot performance.
Smart Images

Figure 0007684358000001 
Figure 0007684358000002 
Figure 0007684358000003
Abstract
Description
[Technical field]
[0001] The present disclosure relates to functional safety technology, and in particular to a secure boot control method, device, electronic device, and storage medium for a chip. [Background technology]
[0002] The secure boot of the intelligent drive chip is mainly implemented based on the conventional in-vehicle MCU (Microcontroller Unit), specifically, security boot (information secure boot) is implemented by HSM (Hardware Security Module). Conventional in-vehicle MCUs use built-in Flash (flash memory), so the boot procedure only requires performing signature verification operation of the stored data (e.g., signature based on private key is verified by public key) for data stored in the internal Flash, and does not involve encryption and decryption operations for the stored data, so there is no need to consider the issue of Safety Boot (functional secure boot) in conventional MCUs, and there are no additional functional safety requirements for HSM. However, with the development of intelligent drive technology, advanced manufacturing processes have begun to be widely used for intelligent drive chips, making it impossible to implement built-in Flash. Therefore, the current mainstream intelligent drive chips use external Flash to achieve non-volatile storage. According to security needs, the data stored in the external Flash needs to be encrypted before being stored. In the secure boot procedure of the intelligent drive chip, not only does the stored data need to be subjected to signature verification operations, but also encryption and decryption operations need to be performed on the stored data. In the operational procedure in which the HSM performs decryption, there is a possibility that the decrypted data may cause functional safety-related failures, which is likely to degrade the secure boot performance of the intelligent drive chip. Summary of the Invention [Problem to be solved by the invention]
[0003] In order to solve technical problems such as the degradation of performance related to the secure boot of an intelligent drive chip due to the above-mentioned secure boot flow, the present disclosure is proposed. The embodiments of the present disclosure provide a method, an apparatus, an electronic device, and a storage medium for controlling the secure boot of a chip. [Means for solving the problem]
[0004] According to an aspect of an embodiment of the present disclosure, a secure boot control method for a chip is provided, the method including the steps of: determining, at a preset stage of a chip boot procedure, first mirror data to be verified at the preset stage and a first verification code corresponding to the first mirror data from a decryption result acquired by a hardware security module; determining a second verification code based on the first mirror data; comparing the second verification code with the first verification code to obtain a comparison result; determining an integrity verification result of the first mirror data based on the comparison result; and executing a secure boot program corresponding to the first mirror data at the preset stage based on the integrity verification result.
[0005] According to another aspect of an embodiment of the present disclosure, a secure boot control device for a chip is provided, the device including: a hardware acceleration module connected to a hardware security module, which determines, at a predetermined stage of a chip boot procedure, first mirror data to be verified at the predetermined stage and a first verification code corresponding to the first mirror data from a decryption result acquired by the hardware security module, and determines a second verification code based on the first mirror data; a first processing module connected to the hardware acceleration module, which compares the second verification code with the first verification code and acquires a comparison result; a second processing module which determines an integrity verification result of the first mirror data based on the comparison result; and a third processing module which executes a secure boot program corresponding to the first mirror data at the predetermined stage based on the integrity verification result.
[0006] According to another aspect of the embodiment of the present disclosure, there is provided a computer-readable storage medium storing a computer program for executing the secure boot control method for a chip described in any one of the above embodiments.
[0007] According to a further aspect of an embodiment of the present disclosure, there is provided an electronic device including a processor and a memory storing instructions executable by the processor, the processor reading the executable instructions from the memory and executing the instructions to implement a secure boot control method for a chip described in any one of the embodiments above, or the electronic device including a secure boot control device for a chip described in any one of the embodiments above. Effect of the Invention
[0008] Based on the chip secure boot control method, device, electronic device, and storage medium provided in the above embodiments of the present disclosure, at a preset stage of the chip boot procedure, integrity verification is performed on the first mirror data in the decryption result obtained by the hardware security module, thereby ensuring that the decryption operation of the hardware security module does not damage the first mirror data, thereby ensuring the functional safety of the hardware security module and effectively improving the security of chip boot.
[0009] The technical solutions of the present disclosure are further described in detail below with reference to the drawings and examples. [Brief description of the drawings]
[0010] The above and other objects, features and advantages of the present disclosure will become apparent from the detailed description of the embodiments of the present disclosure with reference to the drawings. The drawings are used to provide a further understanding of the embodiments of the present disclosure, are a part of the specification, and are for explaining the present disclosure together with the embodiments of the present disclosure, but are not intended to limit the present disclosure. In the drawings, the same reference numerals generally represent the same components or steps. [Figure 1] 1 is an exemplary application scenario of the secure boot control method for a chip provided in the present disclosure. [Diagram 2] 1 is a schematic flowchart of a secure boot control method for a chip provided in an exemplary embodiment of the present disclosure. [Diagram 3] 11 is a schematic flowchart of a secure boot control method for a chip provided in another exemplary embodiment of the present disclosure. [Figure 4] FIG. 2 is a structural schematic diagram of a secure boot control device of a chip provided in an exemplary embodiment of the present disclosure. [Diagram 5] FIG. 2 is a structural schematic diagram of a secure boot control device of a chip provided in another exemplary embodiment of the present disclosure. [Figure 6]FIG. 2 is a structural schematic diagram of a hardware acceleration module 61 provided in an exemplary embodiment of the present disclosure. [Figure 7] FIG. 13 is a structural schematic diagram of a secure boot control device of a chip provided in a further exemplary embodiment of the present disclosure. [Figure 8] FIG. 13 is a structural schematic diagram of a secure boot control device of a chip provided in yet another exemplary embodiment of the present disclosure. [Figure 9] 1 is a structural schematic diagram of an application example of an electronic device according to the present disclosure. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0011] Hereinafter, exemplary embodiments of the present disclosure will be described in detail with reference to the drawings. It is clear that the described embodiments are only some of the embodiments of the present disclosure, and are not all of the embodiments of the present disclosure, and it should be understood that the present disclosure is not limited to the exemplary embodiments described in this specification.
[0012] It should be noted that unless specifically stated otherwise, the relative arrangement of the components and steps, the formulas and numerical values described in these examples do not limit the scope of the present disclosure.
[0013] Those skilled in the art will understand that the terms "first", "second", etc. in the embodiments of the present disclosure are merely used to distinguish different steps, devices, modules, etc., and do not represent any specific technical meaning, nor do they represent a necessary logical order between them.
[0014] Additionally, in the embodiments of the present disclosure, "plurality" can refer to two or more than two, and "at least one" can refer to one, two, or more than two.
[0015] The embodiments of the present disclosure may be applied to electronic devices such as terminal devices, computer systems, servers, etc., and may operate with many other general-purpose or specialized computing system environments or configurations. Examples of well-known terminal devices, computing systems, environments, and / or configurations suitable for use with electronic devices such as terminal devices, computer systems, servers, etc., include, but are not limited to, personal computer systems, server computer systems, thin clients, thick clients, handheld or laptop devices, microprocessor-based systems, set-top boxes, programmable appliances, networked personal computers, small computer systems, large computer systems, distributed cloud computing technology environments that include any of the above systems, and the like. Summary of the Disclosure
[0016] During the implementation of the present disclosure, the inventors have found that the secure boot of the intelligent drive chip is mainly implemented based on a conventional in-vehicle MCU (Microcontroller Unit), specifically, the security boot is implemented by an HSM (Hardware Security Module). The conventional in-vehicle MCU uses built-in Flash, so that the boot procedure only requires performing a signature verification operation (e.g., a signature based on a private key is verified by a public key) on the data stored in the internal Flash, and does not involve encryption and decryption operations on the stored data. Therefore, in the conventional MCU, there is no need to consider the issue of Safety Boot, and there is no additional functional safety requirement for the HSM. However, with the development of intelligent drive technology, advanced manufacturing processes have begun to be widely used for intelligent drive chips, making it impossible to implement built-in Flash. Therefore, current mainstream intelligent drive chips use external Flash to achieve non-volatile storage. According to security needs, data stored in external Flash must be encrypted before being stored. In the secure boot procedure of the intelligent drive chip, not only must the stored data be subjected to signature verification operations, but also encryption and decryption operations must be performed on the stored data. In the operational procedure in which the HSM performs decryption, there is a possibility that the decrypted data may cause functional safety-related failures, which may easily degrade the performance of the secure boot of the intelligent drive. Illustrative Overview
[0017] FIG. 1 is an exemplary application scenario of the secure boot control method for a chip provided in the present disclosure.
[0018] In the intelligent drive scenario, when booting the intelligent drive chip, first obtain the initial boot program pre-stored in the internal read-only memory, and execute the initial boot program to enter the subsequent boot stages, for example, the stage of executing the initial boot program may be called the BL0 stage, and the subsequent boot stages include the BL1 stage and the BL2 stage, which can be specifically set according to actual needs. Each stage that needs to load encrypted mirror data from an external device can be a pre-set stage, and the encrypted mirror data is an encryption result obtained by encrypting the mirror data (which can also be called the first mirror data) executed in the boot stage, and is used to ensure the security of the mirror data, and in order to perform the integrity verification on the mirror data later, in the present disclosure, the mirror data can be encrypted together with the first verification code of the mirror data to obtain the corresponding encrypted mirror data. The first mirror data is a file including the secure boot program of the corresponding stage. Using the chip secure boot control method disclosed herein (the method is executed by the chip secure boot control device), encrypted mirror data loaded from an external storage device is transmitted to a hardware security module (abbreviated as HSM) at any pre-set stage, and the HSM decrypts the encrypted mirror data to obtain a decryption result, which includes first mirror data to be verified at that stage and a corresponding first verification code, and in order to perform integrity verification on the first mirror data, a second verification code is determined based on the first mirror data, and the second verification code is compared with the first verification code to obtain a comparison result.The first verification code is the verification code of the first mirror data before decryption by the HSM, and the second verification code is the verification code of the first mirror data after decryption by the HSM. By comparing the two, it indicates that if the first mirror data is not damaged by the decryption operation of the HSM, the second verification code should match the first verification code; if the two do not match, it indicates that the first mirror data may be damaged by the decryption operation of the HSM. Based on this, the integrity verification of the first mirror data can be completed, and only for the first mirror data whose verification result is passed, the corresponding secure boot program is executed, which ensures the security of the decryption operation function of the HSM, realizes the secure boot of the chip, and further improves the security of the intelligent drive. Exemplary Methods
[0019] 2 is a schematic flowchart of a secure boot control method for a chip provided in an exemplary embodiment of the present disclosure. This embodiment can be applied to electronic devices, such as in-vehicle computing platforms, and chips such as intelligent drive chips on in-vehicle computing platforms. As shown in FIG. 2, the method includes steps 201 to 205.
[0020] In step 201, at a preset stage of a chip boot procedure, first mirror data to be verified at the preset stage and a first verification code corresponding to the first mirror data are determined from a decryption result obtained by a hardware security module.
[0021] Here, the chip boot procedure can be set into multiple stages according to actual needs, and corresponding boot functions can be completed in different stages, specifically, according to actual needs. For example, after power is applied to the chip, the chip boot flow can be divided into three stages. In the first stage, an initial boot program stored in an internal read-only memory is executed first, and the initial boot program may be called BL0. The functions performed in the first stage include, for example, initializing the system clock, initializing related boot peripherals (e.g., hardware acceleration module), determining the hardware boot method, etc., and further loading the encrypted mirror data of BL1 (a boot program used to initialize RAM (Random Access Memory) and serial ports, allocate stack space, clear BSS segments, load BL2 (BL2 is a boot program for initializing hardware, loadable kernel, etc. to be used in this stage), etc.) and transmitting it to a hardware security module (HSM), and the encrypted mirror data is decrypted by the hardware security module to obtain the decryption result. Here, the specific operation of decryption can be set according to actual needs, for example, encryption and decryption are performed based on a symmetric encryption algorithm or an asymmetric encryption algorithm, and a detailed description is omitted. After obtaining the decryption result, the first mirror data to be verified at the preset stage and the first verification code corresponding to the first mirror data are determined from the decryption result, and the first verification code is a verification code determined based on the first mirror data and the preset verification algorithm before encryption, and is used to perform integrity verification on the first mirror data in the subsequent process. Here, the preset verification algorithm includes information required for generating a verification code, such as an algorithm mode, an initial value, and a calculation length, and can be specifically set according to actual needs. BL0 to BL2 can be specifically set according to actual needs, and are not limited in the present disclosure.
[0022] Similarly, in the first stage, the boot program of BL1 is executed, and then the second stage is entered. The second stage is a preset stage. In the second stage, the encrypted mirror data of BL2 is loaded, and the decryption result is obtained by decrypting the HSM. From the decryption result, the first mirror data to be verified in the preset stage and the first verification code corresponding to the first mirror data are determined. By this analogy, the method disclosed herein can be executed at each preset stage. Detailed explanations are omitted here, and the subsequent processing flow will be described below using one preset stage as an example.
[0023] In practical applications, the specific division of the chip boot flow steps can be set according to actual needs, and is not limited in this disclosure.
[0024] In step 202, a second identification code is determined based on the first mirror data.
[0025] Here, the second verification code is a verification code generated based on a preset verification algorithm that coincides with the generation of the first mirror data and the first verification code after obtaining the first mirror data by decrypting the hardware security module, and is used to perform integrity verification on the first mirror data.
[0026] In step 203, the second verification code is compared with the first verification code to obtain a comparison result.
[0027] Here, the comparison result may include whether the second verification code and the first verification code are the same or different.
[0028] In step 204, the integrity verification result of the first mirror data is determined based on the comparison result.
[0029] Here, the integrity verification result may include two types of results: pass and fail. Since the first verification code is the verification code of the first mirror data before decryption by the HSM, and the second verification code is the verification code of the first mirror data after decryption by the HSM, by comparing the two, if the first mirror data is not damaged or no error is generated by the decryption operation of the HSM, the second verification code should be the same as the first verification code, and if the two are the same, it indicates that the integrity verification result is pass. If the two are different, the first mirror data may be damaged by the decryption operation of the HSM, and the integrity verification result is fail. Based on this, the integrity verification of the first mirror data can be completed.
[0030] In step 205, a secure boot program corresponding to the first mirror data is executed at a preset stage based on the integrity verification result.
[0031] Here, the corresponding secure boot program is executed only for the first mirror data whose integrity verification result is passed, so as to guarantee the security of the decryption operation function of the HSM, to realize the secure boot of the chip, and to improve the security of the intelligent drive. If the integrity verification result is failed, the boot flow is terminated.
[0032] In practical applications, steps 201-202 and steps 203-205 may be performed by the same processing module or by different processing modules, for example, steps 201-202 are performed by a hardware processing module, steps 203-205 are performed by a security core in the chip, and the hardware processing module is a hardware circuit independent of the safety core, which can be specifically configured according to actual needs.
[0033] The chip secure boot control method provided in this embodiment performs integrity verification on the first mirror data in the decryption result obtained by the hardware security module at a preset stage of the chip boot procedure, thereby ensuring that the decryption operation of the hardware security module does not damage the first mirror data, thereby ensuring the functional safety of the hardware security module and effectively improving the security of chip boot.
[0034] FIG. 3 is a schematic flowchart of a secure boot control method for a chip provided in another exemplary embodiment of the present disclosure.
[0035] In one optional example, before step 201, the method of the present disclosure may further include steps 301 to 303.
[0036] In step 301, a communication handshake signal between a hardware security module and a first memory is detected.
[0037] Here, the first memory may be a memory inside the chip, specifically a RAM or SRAM (Static Random-Access Memory), etc., and the decryption result obtained by the hardware security module needs to be stored in the first memory so that the corresponding processor (e.g., safety core) of the chip can read and execute it. The present disclosure determines when the hardware security module transmits the decryption result to the first memory by detecting a communication handshake signal between the hardware security module and the first memory. The communication handshake signal may be determined according to an actual handshake protocol, for example, the communication handshake signal may include a VALID signal and a READY signal, and is not specifically limited.
[0038] In step 302, a valid control signal is determined based on the communication handshake signal.
[0039] Here, by detecting the communication handshake signal, it is possible to determine when the hardware security module starts transmitting the decryption result, and based on this, a valid control signal can be determined, which indicates that it is possible to start collecting or obtaining the decryption result transmitted by the hardware security module. For example, after detecting VALID and READY, which indicates that the handshake between the hardware security module and the first memory is successful and data transmission is prepared, a valid control signal is determined.
[0040] In step 303, in response to the valid control signal, the decryption result transmitted by the hardware security module is obtained from the bus to which the hardware security module is connected.
[0041] Here, when the valid control signal is determined to indicate that acquisition of the decryption result can be started, the decryption result transmitted by the hardware security module can be acquired from the bus to which the hardware security module is connected.
[0042] In one optional example, the bypass of the bus can detect the communication handshake signal between the hardware security module and the first memory, the bypass of the bus can simultaneously transmit the communication contents between the hardware security module and the first memory through the bypass, the bypass is provided with a corresponding detection element, the detection element can receive the communication handshake signal between the hardware security module and the first memory and the data to be transmitted, the valid control signal is used to determine whether to receive and collect the data transmitted by the data bus, when there is no valid control signal, the data transmitted by the data bus is not received, and from the time when the valid control signal is determined to indicate that the data bus starts to transmit a valid decryption result, the data transmitted by the data bus can be received and the decryption result transmitted thereby can be obtained.
[0043] The present disclosure detects communication handshake information between a hardware security module and a first memory, determines a valid control signal, and then obtains the decryption result from a bus to which the hardware security module is connected, so that the integrity verification and storage of the decryption result can be processed in parallel without affecting the data transmission to the first memory of the hardware security module, thereby effectively improving the verification efficiency and shortening the time of the chip boot flow.
[0044] In one optional example, communication between the hardware security module and the first memory can be further bypassed to a hardware processing module (which may be called a hardware acceleration module) via a bus bypass, and integrity verification is performed by hardware or generation of a second verification code is performed, further improving verification efficiency and improving chip boot efficiency.
[0045] In one optional example, before step 201 of determining first mirror data to be verified at a preset stage and a first verification code corresponding to the first mirror data from the decryption result obtained by the hardware security module, steps 401 and 402 are further included.
[0046] In step 401, encrypted mirror data corresponding to a preset stage is loaded from an external storage device.
[0047] Here, the external storage device is a storage device for storing encrypted mirror data outside the chip. In the chip boot procedure, only the initial boot program is stored in the ROM (Read-Only Memory) inside the chip, and all boot programs required for subsequent boots need to be loaded from the outside into the internal RAM, and in order to ensure the security of the boot programs, they are generally stored in the external storage device as encrypted mirror data, so that in each step of the boot procedure, it is necessary to load the corresponding encrypted mirror data from the external storage device, and if you want to obtain the true mirror data, you need to perform a decryption process in the hardware security module.
[0048] In step 402, the encrypted mirror data is transmitted to a hardware security module so that the hardware security module decrypts the encrypted mirror data and obtains a decryption result.
[0049] Here, since the hardware security module needs to perform decryption processing on the encrypted mirror data, the encrypted mirror data needs to be transmitted to the hardware security module, and the hardware security module obtains the encrypted mirror data, and based on the associated hardware of the hardware security module, performs decryption of the encrypted mirror data to obtain the decryption result.
[0050] In one optional example, after obtaining the encrypted mirror data, the hardware security module can perform signature verification on the encrypted mirror data, where signature verification refers to verifying the legitimacy of data. For example, when loading and transmitting the encrypted mirror data, information for identifying the legitimacy, such as a certificate, digital signature, etc. of the encrypted mirror data can be carried, or after decrypting and obtaining the decryption result, signature verification can be performed on the first mirror data, where for example, the decryption result may further include information for identifying the legitimacy of the first mirror data, such as a certificate, digital signature, etc. of the first mirror data, and signature verification is performed on the first mirror data based on this information. A detailed description of the specific signature verification principle is omitted.
[0051] The present disclosure decrypts the encrypted mirror data loaded from an external storage device based on the hardware of a hardware security module, effectively ensuring the decryption speed and real-time performance, thereby ensuring the boot speed of the chip and shortening the time of the chip boot flow, and what is stored in the external storage device is the encrypted data of the mirror data, further ensuring the security of the chip boot.
[0052] In an alternative embodiment, the method of the present disclosure further comprises: A step 403 includes storing the decoded result in a first memory.
[0053] Here, the first memory may be a RAM or SRAM inside the chip, and after the hardware security module completes the decryption process of the encrypted mirror data, it can store the obtained decryption result in the first memory for use in the chip boot flow.
[0054] Step 203 of comparing the second verification code with the first verification code and obtaining a comparison result includes steps 2031 to 2033.
[0055] In step 2031, the interrupt completion signal is written to the first register.
[0056] Here, the interrupt completion signal is used to notify the associated processing module (or sub-module) that the generation of the second verification code has now been completed, and in step 202, after determining the second verification code of the first mirror data, the interrupt completion signal can also be written to the first register, and the device disclosed herein has an associated processing module or sub-module that responds to the interrupt and detects the status of the first register in real time or periodically.
[0057] In step 2032, in response to detecting the interrupt completion signal in the first register, a first verification code is obtained from the first memory.
[0058] Here, when an interrupt completion signal in the first register is detected, this indicates that the second verification code has been generated, and the first verification code can be obtained from the first memory and used for comparison with the second verification code.
[0059] In step 2033, the second verification code is compared with the first verification code to obtain a comparison result.
[0060] Exemplarily, the verification algorithm used for the integrity verification may be a CRC (Cyclic Redundancy Check) algorithm, a HASH (Hash) algorithm, etc. For example, for the HASH algorithm, the first verification code and the second verification code are the hash value of the first mirror data before encryption and the hash value of the first mirror data after decryption, respectively. The comparison of the second verification code and the first verification code refers to comparing whether the two values are the same, and a comparison result is obtained. A detailed description of the specific comparison principle is omitted.
[0061] In one alternative embodiment, step 2033 may be implemented with hardware comparison circuitry, further enhancing the real-time nature of the verification.
[0062] In one optional example, after determining the first verification code, the first verification code can be further written to a third register, and after obtaining the second verification code, the second verification code can be further written to a fourth register, and the third register and the fourth register are respectively connected to the input ends of a comparator to become two inputs of the comparator, and a comparison between the second verification code and the first verification code is performed based on the comparator.
[0063] In the present disclosure, after the second verification code of the first mirror data is generated, the second verification code can be compared with the first verification code by interrupting the response via an interrupt signal to complete the integrity verification, so that the generation of the second verification code can be performed by a module or submodule independent of the processor without taking up the time of the processor (e.g., safety core), further shortening the time delay of the chip boot and improving the real-time performance. Also, the comparison between the second verification code and the first verification code can be performed based on hardware, further improving the real-time performance.
[0064] In one optional example, the step 202 of determining the second verification code based on the first mirror data includes a step 2021 and a step 2022 .
[0065] In step 2021, pre-configured verification setting information is obtained, which includes verification algorithm information corresponding to a pre-configured stage.
[0066] Here, the verification setting information may be preset in a specific storage area, for example, preset in a register, and the verification algorithm information may include an algorithm mode for verification, a calculation length, and other related information, and the specific contents may be determined according to the actual verification algorithm, and are not limited in this disclosure. Here, the algorithm mode may be a specific verification algorithm, for example, a CRC algorithm, a hash algorithm, etc. Here, the CRC algorithm realizes an error detection function by utilizing the principle of division and remainder, and a detailed description of the specific principle is omitted. The hash algorithm maps a binary value of any length to a binary value of a short fixed length, and this short binary value is called a hash value and is used as a verification code. The calculation length may be the length of the verification code, for example, the length of the hash value calculated by the hash algorithm. The boot flow of different stages may correspond to the same or different verification setting information, and specifically, may be set according to actual needs.
[0067] In step 2022, a second verification code of the first mirror data is generated based on the verification setting information and the first mirror data.
[0068] Specifically, based on the verification algorithm information in the verification setting information, a calculation of the corresponding algorithm is performed on the first mirror data to obtain the second verification code.
[0069] For example, a hash calculation is performed on the first mirror data based on a preset hash algorithm. If the calculation length is 8 bits, an 8-bit binary hash value is obtained as the second verification code.
[0070] The present disclosure generates a second verification code for the first mirror data based on pre-set verification setting information, and can apply multiple types of verification algorithms according to actual needs, thereby improving versatility.
[0071] In one selectable example, steps 501 to 504 are further included before step 201 in which the first mirror data to be verified at a preset stage and the first verification code corresponding to the first mirror data are determined from the decryption result obtained by the hardware security module.
[0072] In step 501, an initial boot program is obtained from a read-only memory.
[0073] Here, the read-only memory is the chip's internal ROM, and the initial boot program is a boot program pre-stored in the read-only memory. After power is applied to the chip, the chip boots an associated processor or processor core (e.g., a safety core) and first executes the initial boot program in the ROM to begin the chip's boot flow.
[0074] In step 502, an initial boot program is executed to obtain initial verification configuration information.
[0075] Here, the initial boot program function is to perform some related initialization and settings, and the initial verification setting information may be information stored in ROM together with the initial boot program, and may include verification setting information corresponding to the encrypted mirror data that is loaded when the initial boot program is executed.
[0076] In step 503, an initial setting is made for secure boot of the chip based on the initial verification setting information.
[0077] Here, the initial setting may include setting the corresponding verification algorithm, calculation length, etc., for the module or sub-module for generating the second verification code based on the initial verification setting information. For example, if the module for generating the second verification code is a hardware module independent of the safety core, the hardware module is set based on the initial verification setting information so that the hardware module successfully completes the operation of generating the verification code. The specific settings can be set according to actual needs.
[0078] In one optional example, the initialization settings completed by executing the initial boot program may further include other related initialization and settings, such as the initialization of the aforementioned related boot peripherals, which can be specifically set according to actual needs.
[0079] In step 504, in response to completing the initialization, a pre-configured phase of the chip boot procedure is entered.
[0080] Here, completion of the initialization setting requires loading the encrypted mirror data of the boot program that needs to be executed subsequently. For example, BL0, which executes the above-mentioned initial boot program, completes the loading of the encrypted mirror data of BL1, and then completes integrity verification of BL1 at that stage using the method disclosed herein, passes the verification, and executes the secure boot program of BL1. In the procedure of executing BL1, the encrypted mirror data of BL2 is loaded, and then integrity verification of BL2 is completed using the method disclosed herein. By this analogy, this continues until all stages of the boot flow are completed, i.e., until the secure boot of the chip is completed.
[0081] In the present disclosure, by realizing the setting of initial verification setting information for the secure boot of the chip in the initial boot program, the chip can boot and perform integrity verification on the decryption result of the hardware security module, thereby ensuring the security of the decryption function of the hardware security module and improving the security of the chip boot.
[0082] The secure boot control method of any one of the chips provided in the embodiments of the present disclosure may be executed by any suitable device having data processing capability, including but not limited to a terminal device and a server. Or, the secure boot control method of any one of the chips provided in the embodiments of the present disclosure may be executed by a processor, for example, the processor calls a corresponding instruction stored in a memory to execute the secure boot control method of any one of the chips mentioned in the embodiments of the present disclosure. Hereinafter, detailed description is omitted. Exemplary Apparatus
[0083] 4 is a structural schematic diagram of a secure boot control device of a chip provided in an exemplary embodiment of the present disclosure, which is used to implement a corresponding method embodiment of the present disclosure, and the device shown in FIG. 4 includes a hardware acceleration module 61, a first processing module 62, a second processing module 63, and a third processing module 64.
[0084] The hardware acceleration module 61 is connected to the hardware security module, and at a preset stage of the chip boot procedure, determines first mirror data to be verified at the preset stage and a first verification code corresponding to the first mirror data from the decryption result acquired by the hardware security module, and determines a second verification code based on the first mirror data. The first processing module 62 is connected to the hardware acceleration module, and compares the second verification code with the first verification code to obtain a comparison result. The second processing module 63 determines an integrity verification result of the first mirror data based on the comparison result. The third processing module 64 executes a secure boot program corresponding to the first mirror data at a preset stage based on the integrity verification result.
[0085] In one optional example, the first processing module 62, the second processing module 63, and the third processing module 64 may be a processor core for booting in the chip, such as a safety core, and the performance of the safety core can be specifically set according to actual needs, for example, based on a low-latency processor core, a safety core with high security and reliability, low latency, and meeting a certain security level (e.g., ASILD (Automotive Safety Integrity Level D)) is constructed.
[0086] In one optional example, the hardware acceleration module 61 and / or the first processing module 62 may be a software module or a hardware circuit module, and can be specifically configured according to actual needs.
[0087] In one alternative example, the hardware acceleration module 61 may be connected to a first processing module 62, a second processing module 63, and a third processing module 64 via a bus.
[0088] The present disclosure can ensure that the decryption operation of the hardware security module does not damage the first mirror data by performing integrity verification on the first mirror data in the decryption result obtained by the hardware security module at a predetermined stage of the chip boot procedure, thereby ensuring the functional safety of the hardware security module and effectively improving the security of chip boot.
[0089] FIG. 5 is a structural schematic diagram of a secure boot control device of a chip provided in another exemplary embodiment of the present disclosure.
[0090] In one alternative example, the hardware acceleration module 61 includes a bus monitor 611 and a verification code generator 612, where the bus monitor 611 is connected to the hardware security module via a bus bypass, detects a communication handshake signal between the hardware security module and a first memory, and sends an enable control signal to the verification code generator based on the communication handshake signal to notify the verification code generator to start collecting the decryption result transmitted by the hardware security module. The verification code generator 612 is connected to the bus monitor 611 and further connected to the hardware security module via a bus bypass, and in response to the enable control signal of the bus monitor, collects the decryption result transmitted by the hardware security module from the bus to which the hardware security module is connected, and determines a second verification code based on the first mirror data in the decryption result.
[0091] Here, since the communication handshake signal is a control signal, the bus monitor 611 may be connected to the control bus of the bus bypass to monitor the communication handshake signal. Since the verification code generator 612 is used to collect the transmitted decryption result data, it may be connected to the data bus of the bus bypass, and specifically, it can be set according to actual needs, as long as it can implement the corresponding function. The function of the bus bypass is to transmit the communication content between the hardware security module and the first memory to the hardware acceleration module 61 in parallel through the bus bypass to achieve real-time detection of the communication handshake signal and real-time collection of the decryption result. For the meaning of the valid control signal, please refer to the above-mentioned method embodiment. Here, detailed description is omitted. For the specific operation of the verification code generator 612 after obtaining the decryption result, please refer to the above-mentioned method embodiment.
[0092] In one alternative embodiment, to further improve real-time performance, the bus monitor 611 and the verification code generator 612 can be implemented in hardware.
[0093] In the present disclosure, calculations such as a verification code for mirror data to be verified in the decryption result can be performed based on bus bypass, without affecting other circuits on the bus path, and the hardware can quickly calculate the verification code for mirror data to be verified in the decryption result of the hardware security module. Furthermore, the security processing module compares the verification code obtained by calculation with the verification code in the decryption result to determine the integrity of the mirror data, without the need for software calculation time or causing extra delays on the hardware path, thereby effectively shortening the overall boot flow time and improving the boot speed under circumstances that ensure the satisfaction of certain security level needs.
[0094] In one alternative embodiment, the device of the present disclosure further includes a load module 65 and a hardware security module 66 . The load module 65 loads encrypted mirror data corresponding to a preset stage from an external storage device. The hardware security module 66 is connected to the load module 65, and decrypts the encrypted mirror data to obtain the decryption result.
[0095] In one optional example, the load module 65 may be connected to the hardware security module 66 via a bus, or the load module 65 may be connected to the hardware security module 66 as a module in a processor or processor core via a connection between the processor or processor core and a bus, and the specific configuration can be based on actual needs.
[0096] In the present disclosure, encrypted mirror data of the secure boot program to be executed, which is stored in an external storage device at a pre-set stage, is loaded into the chip, and the chip decrypts the encrypted mirror data using a hardware security module to obtain the mirror data of the secure boot program to be executed, thereby providing an external storage function for the chip boot and reducing storage costs within the chip.
[0097] In one optional example, the device of the present disclosure further includes a first memory 67, and the hardware security module 66 further stores the decryption result in the first memory 67.
[0098] Here, the first memory 67 may be a RAM or SRAM inside the chip, and the hardware security module 66 can communicate with the first memory 67 via a bus.
[0099] In one optional example, the hardware acceleration module 61 further includes a first register 613 connected to the first processing module 62 for storing an interrupt completion signal, and the hardware acceleration module 61 further writes the interrupt completion signal to the first register 613 after determining the second verification code to notify the first processing module 62 that the second verification code has been generated. The first processing module 62 further obtains the first verification code from the first memory 67 in response to detecting the interrupt completion signal in the first register 613, and compares the second verification code with the first verification code to obtain a comparison result.
[0100] Here, the first register 613 may be any operable register, for example, using an existing register in the chip, or adding a register based on the needs of the present disclosure. Specifically, it can be set according to actual needs. After the second verification code is generated, the hardware acceleration module 61 or the aforementioned verification code generator 612 can write the second verification code to the first register 613 to notify the first processing module 62 that the second verification code has been generated. The first processing module 62 can detect the first register 613 periodically or in real time, and thus respond to the interrupt completion signal to complete the comparison of the subsequent second verification code with the first verification code to complete the integrity verification.
[0101] In one optional example, the hardware acceleration module 61 may include a comparator that performs a comparison between the second verification code and the first verification code, and may also store the comparison result in a corresponding comparison result register, which may be connected to the first processing module 62 so that the first processing module 62 can directly obtain the comparison result, further improving the real-time nature of the integrity verification.
[0102] In the present disclosure, by storing an interrupt completion signal in a first register, the generation of the verification code can be independent from the processor, and after the generation of the verification code is completed, an interrupt request is sent to the processor by the interrupt completion signal so that the processor responds to the interrupt request to confirm the integrity verification result, thereby further improving real-time performance.
[0103] In one optional example, the apparatus disclosed herein further includes a second register 68 connected to the hardware acceleration module 61 for storing verification setting information including verification algorithm information corresponding to the stage, and the hardware acceleration module 61 further obtains the verification setting information from the second register 68 and generates a second verification code for the first mirror data based on the verification setting information and the first mirror data.
[0104] Here, the second register 68 can be any operable register, specifically, can be set according to actual needs, and the contents stored in the second register 68 can be set according to any timing before the integrity verification of the boot flow, specifically, can be set according to actual needs. Optionally, the verification setting information of each stage may be pre-stored in the ROM in the chip together with the initial boot code, and is not specifically limited. Please refer to the above-mentioned embodiment for the specific contents and working principles of the verification setting information. Here, detailed description is omitted.
[0105] The present disclosure stores verification setting information of a preset stage in a second register, supports integrity verification of the first mirror data decrypted at the preset stage, ensures rapid generation of a verification code, and further improves real-time performance.
[0106] In an optional example, the device of the present disclosure further includes a second memory 69 and an initial processing module 70, where the second memory 69 stores an initial boot program and initial verification setting information of the hardware acceleration module 61. The initial processing module 70 executes the initial boot program stored in the second memory 69 to enter an initial boot stage, obtains initial verification setting information from the second memory 69 based on the initial boot program, and performs initialization setting for the hardware acceleration module 61 based on the initial verification setting information to enter a preset stage of the chip boot procedure.
[0107] Here, the second memory 69 may be a read only memory (ROM) in the chip, and an initial boot program is pre-stored in the ROM. After the chip is powered on, the initial processing module 70 starts to operate and executes the initial boot program in the ROM. The initial boot program performs initialization settings for the hardware acceleration module 61 so that the hardware acceleration module 61 can operate normally. Of course, the initial boot program may also include setting other related modules or functions of the chip to enter a preset stage of the boot procedure. Completing the boot operation corresponding to the preset stage includes loading encrypted mirror data from an external storage device, transmitting it to the hardware security module 66 for decryption, and the hardware security module 66 decrypting and acquiring the encrypted mirror data. The decryption result is transmitted to the first memory 67 and the hardware acceleration module 61 via the bus and the bus bypass, respectively, and the hardware acceleration module 61 obtains the decryption result, generates a second verification code of the first mirror data in the decryption result based on the verification setting information of the corresponding stage stored in the second register 68, writes an interrupt completion signal to the first register 613, and notifies the first processing module 62, and the first processing module 62 obtains the first verification code in the decryption result from the first memory 67 and obtains the second verification code from the hardware security module, compares the second verification code with the first verification code, obtains the comparison result, and further determines the integrity verification result based on the comparison result, and executes the secure boot program corresponding to the first mirror data in response to the integrity verification result being passed. For the specific principle, please refer to the above-mentioned embodiment. Here, detailed description is omitted.
[0108] The present disclosure provides a method for booting a chip by pre-storing an initial boot program in a read-only memory of the chip, so that after power is applied to the chip, the associated processor core (e.g., a safety core) for booting can first execute the initial boot program in the read-only memory, thereby entering the initial boot flow of the chip so that the chip enters the subsequent boot stage, and realizing secure boot of the chip.
[0109] In one alternative embodiment, the hardware acceleration module 61 further comprises: a fourth register 614 coupled to the verification code generator 612 for storing a second verification code; The verification code generator 612 further writes the second verification code to a fourth register 614 .
[0110] Here, the fourth register 614 can be any operable register, and can be specifically set according to actual needs.
[0111] In an optional example, FIG. 6 is a structural schematic diagram of a hardware acceleration module 61 provided in an exemplary embodiment of the present disclosure. In this example, the hardware acceleration module 61 may be fully or partially implemented by hardware, and the hardware acceleration module 61 may further include a third register 615 for storing a first verification code and a comparator 616. The third register 615 and the fourth register 614 may be respectively connected to the input terminal of the comparator 616, so that the comparison between the second verification code and the first verification code is performed by hardware, which further improves the real-time nature of the verification. If the comparator 616 is connected to the first register 613, the interrupt completion signal can carry the comparison result of the comparator 616, so that the interrupt completion signal can be transmitted to the first processing module 62 together with the comparison result, and the first processing module 62 can directly determine the integrity verification result based on the comparison result in response to the interrupt, which further improves the real-time nature of the verification.
[0112] In one optional example, the device of the present disclosure may further include an external storage device 71 for storing the encrypted mirror data.
[0113] 7 is a structural schematic diagram of a secure boot control device of a chip provided in a further exemplary embodiment of the present disclosure. In this embodiment, the above-mentioned first processing module 62, second processing module 63, third processing module 64, load module 65, and initial processing module 70 are modules in a safety core in the chip, and the hardware acceleration module 61 is a hardware module independent of the safety core, and the safety core, hardware security module 66, hardware acceleration module 61, first memory 67, second memory 69, and external memory 71 communicate with each other via a bus. When the chip is powered on, the safety core boots the initial boot program stored in the second memory 69 and performs initialization settings for the hardware acceleration module 61.Thus, after the hardware acceleration module 61 enters normal operation and the boot flow enters a preset stage, the safety core loads the encrypted mirror data corresponding to the preset stage from the external memory 71 and transmits it to the hardware security module 66 via the bus. The hardware security module 66 decrypts the encrypted mirror data (it can also perform signature verification before decryption), obtains the decryption result, and writes the decryption result to the first memory 67 via the bus. The hardware acceleration module 61 monitors the communication handshake signal between the hardware security module 66 and the first memory 67 via the bus bypass, and after determining the valid control signal, transmits it from the bus. the second verification code from the first memory 67 via the bus and the second verification code from the fourth register 614 in response to the interrupt completion signal, compares the second verification code with the first verification code to obtain a comparison result, and further determines an integrity verification result based on the comparison result, and executes a secure boot program corresponding to the first mirror data in response to the integrity verification result being pass.
[0114] In the present disclosure, the decryption result of the hardware security module is obtained via bus bypass, and the generation of a second verification code is performed by hardware, which can significantly reduce the processing time compared to calculating the second verification code by the safety core software, thereby effectively improving real-time performance and effectively improving the secure boot speed of the chip in a situation where the secure boot of the chip is guaranteed.
[0115] In one optional example, Figure 8 is a structural schematic diagram of a secure boot control device of a chip provided in yet another exemplary embodiment of the present disclosure. In this example, the hardware acceleration module 61 and the second register 68 can be provided in the hardware security module 66, and the decryption result of the hardware security module 66 is transmitted to the first memory 67 via the bus, while being transmitted to the hardware acceleration module 61, and the hardware acceleration module 61 generates a second verification code of the first mirror data and writes it into the fourth register 614, and writes an interrupt completion signal into the first register 613, notifying the safety core to perform subsequent comparison and other related processing, specifically, please refer to the above example. Here, detailed description is omitted.
[0116] In one optional example, if the integrity verification result of the first mirror data at a certain preset stage fails, the secure boot of the chip fails, and a recovery operation such as software recovery or recovery after external notification may be performed, and the execution of a new secure boot flow is resumed.
[0117] In the present disclosure, the integrity verification is realized through the bus bypass and the hardware acceleration module, and the calculation of the verification code can be quickly performed based on the hardware without causing extra delay in the chip hardware path and without affecting other circuits, and the boot time can be further shortened compared with the case where the integrity verification is completed using the processor software. In addition, compared with the case where the integrity verification of the decryption result is realized by the redundant setting of the hardware security module (i.e., by providing two hardware security modules, decrypting simultaneously, comparing the decryption results of both, if they match, the verification is considered to be passed, otherwise the verification is considered to be failed), the present disclosure can effectively reduce the hardware cost. Exemplary Electronic Devices
[0118] An embodiment of the present disclosure further provides an electronic device, the electronic device comprising: a memory for storing a computer program; and a processor that executes a computer program stored in the memory, and when the computer program is executed, the secure boot control method for a chip described in any one of the above embodiments of the present disclosure is implemented.
[0119] 9 is a structural schematic diagram of an application embodiment of an electronic device of the present disclosure. In this embodiment, the electronic device 10 includes one or more processors 11 and a memory 12.
[0120] The processor 11 may be a central processing unit (CPU) or other form of processing unit having data processing and / or instruction execution capabilities and may control other components in the electronic device 10 to perform desired functions.
[0121] The memory 12 may include one or more computer program products, which may include various forms of computer-readable storage media, such as volatile memory and / or non-volatile memory. The volatile memory may include, for example, random access memory (RAM) and / or cache. The non-volatile memory may include, for example, read-only memory (ROM), magnetic disk, flash memory, etc. One or more computer program instructions may be stored in the computer-readable storage medium, and the processor 11 may execute the program instructions to perform the methods of the above-mentioned embodiments of the present disclosure and / or other desired functions. The computer-readable storage medium may further store various contents, such as an input signal, a signal component, a noise component, etc.
[0122] In some examples, electronic device 10 may further include input devices 13 and output devices 14, with these components connected to each other via a bus system and / or other form of connection mechanism (not shown).
[0123] For example, the input device 13 may be a microphone or a microphone array as described above, and is used to capture an input signal of a sound source.
[0124] The input device 13 may further include a keyboard, a mouse, and the like.
[0125] The output device 14 can output various information including determined distance information, direction information, etc. to the outside. The output device 14 can include a display, a speaker, a printer, a communication network, and a remote output device connected thereto.
[0126] Of course, for the sake of simplicity, Fig. 9 shows only some of the components of the electronic device 10 related to the present disclosure, and omits components such as buses, input / output interfaces, etc. In addition, the electronic device 10 may further include any other suitable components according to specific application circumstances. Exemplary Computer Program Products and Computer-Readable Storage Media
[0127] In addition to the methods and apparatus described above, embodiments of the present disclosure may also be a computer program product that includes computer program instructions that, when executed by a processor, cause the processor to perform the steps of the methods of the various embodiments of the present disclosure described in the "Exemplary Methods" section above of this specification.
[0128] Although the basic principles of the present disclosure have been described above with reference to specific embodiments, it should be noted that the advantages, merits, effects, etc. mentioned in the present disclosure are merely illustrative and not limiting, and it should not be considered that each embodiment of the present disclosure necessarily has those advantages, merits, effects, etc. In addition, the specific details disclosed above are merely illustrative and for ease of understanding, and are not limiting, and the above details do not restrict the present disclosure to be realized by adopting the above specific details.
[0129] Each embodiment in this specification is described in a step-by-step manner, and the main points of each embodiment are the differences from other embodiments, and the same or similar parts between the embodiments can be referred to each other. Since the system embodiments basically correspond to the method embodiments, the description is relatively brief, and the relevant parts can be referred to the corresponding description of the method embodiments.
[0130] Block diagrams of devices, apparatus, instruments, and systems according to the present disclosure are merely illustrative examples and are not intended to require or imply that the devices, apparatus, instruments, and systems be necessarily connected, arranged, or configured in the manner shown in the block diagrams. Those skilled in the art will recognize that these devices, apparatus, instruments, and systems may be connected, arranged, or configured in any manner.
[0131] The method and apparatus of the present disclosure can be implemented in many ways. For example, the method and apparatus of the present disclosure can be implemented by software, hardware, firmware, or any combination of software, hardware, and firmware. The above-mentioned order of steps of the method is merely for illustration purposes, and the steps of the method of the present disclosure are not limited to the order specifically described above, unless otherwise specified. In some embodiments, the present disclosure is also implemented as a program recorded on a recording medium, and these programs include machine-readable instructions for implementing the method according to the present disclosure. Thus, the present disclosure also includes a recording medium storing a program for implementing the method according to the present disclosure.
[0132] In the apparatus, device, and method of the present disclosure, each component or each step can be disassembled and / or reassembled, and such disassembly and / or reassembly should be considered as an equivalent solution of the present disclosure.
Claims
1. A method for detecting a communication handshake signal between a hardware security module and a first memory; determining a valid control signal based on the communication handshake signal; In response to the enable control signal, obtaining a decryption result transmitted by the hardware security module from a bus to which the hardware security module is connected, and storing the decryption result in the first memory through the hardware security module; determining, from the decryption result acquired by the hardware security module at a preset stage of a chip boot procedure, first mirror data to be verified at the preset stage and a first verification code corresponding to the first mirror data, the preset stage being a stage of loading encrypted mirror data from an external storage device, the encrypted mirror data being an encryption result acquired by encrypting the first mirror data; determining a second verification code based on the first mirror data; comparing the second verification code with the first verification code to obtain a comparison result; determining an integrity verification result of the first mirror data based on a result of the comparison; and executing a secure boot program corresponding to the first mirror data at the preset stage based on the integrity verification result. A method for controlling secure boot of a chip.
2. prior to the step of determining, from the decryption result obtained by the hardware security module, first mirror data to be verified at the preset stage and a first verification code corresponding to the first mirror data, loading the encrypted mirror data corresponding to the preset stage from the external storage device; The secure boot control method for a chip of claim 1 , further comprising: transmitting the encrypted mirror data to the hardware security module, so that the hardware security module decrypts the encrypted mirror data and obtains the decryption result.
3. The step of comparing the second verification code with the first verification code to obtain a comparison result comprises: writing an interrupt completion signal to a first register; retrieving the first verification code from the first memory in response to detecting the interrupt completion signal in the first register; comparing the second verification code with the first verification code to obtain the comparison result. The secure boot control method for a chip according to claim 2.
4. The step of determining a second verification code based on the first mirror data includes: obtaining preset verification setting information including verification algorithm information corresponding to the preset stage; The method for controlling secure boot of a chip according to claim 1 , further comprising: generating the second verification code of the first mirror data based on the verification setting information and the first mirror data.
5. prior to the step of determining, from the decryption result obtained by the hardware security module, first mirror data to be verified at the preset stage and a first verification code corresponding to the first mirror data, obtaining an initial boot program from the read only memory; executing the initial boot program to obtain initial verification setting information; performing an initial setting for a secure boot of the chip based on the initial verification setting information; 2. The method of claim 1, further comprising the step of: entering the preset stage of the chip boot procedure in response to completion of the initialization.
6. a hardware acceleration module that, at a preset stage of a chip boot procedure, determines first mirror data to be verified at the preset stage and a first verification code corresponding to the first mirror data from a decryption result obtained by the hardware security module, and determines a second verification code based on the first mirror data; a first processing module connected to the hardware acceleration module, for comparing the second verification code with the first verification code to obtain a comparison result; a second processing module for determining an integrity verification result of the first mirror data based on a result of the comparison; a third processing module that executes a secure boot program corresponding to the first mirror data at the preset stage based on a result of the integrity verification, the hardware acceleration module includes a bus monitor and a verification code generator; the bus monitor is connected to the hardware security module via a bus bypass, detects a communication handshake signal between the hardware security module and a first memory, and sends a valid control signal to the verification code generator based on the communication handshake signal to notify the verification code generator to collect the decryption result transmitted by the hardware security module; the hardware security module is adapted to store the decryption result in the first memory; the verification code generator is connected to the bus monitor and further connected to the hardware security module via a bus bypass, and in response to the enable control signal of the bus monitor, collects the decryption result transmitted by the hardware security module from a bus to which the hardware security module is connected; The preset step is a step of loading encrypted mirror data from an external storage device, and the encrypted mirror data is an encryption result obtained by encrypting the first mirror data. The secure boot controller of the chip.
7. Further comprising a load module, The load module loads the encrypted mirror data corresponding to the preset stage from the external storage device; The secure boot control device for a chip according to claim 6 , wherein the hardware security module is connected to the load module, and decrypts the encrypted mirror data to obtain the decryption result.
8. The hardware acceleration module further comprises: a first register coupled to the first processing module for storing an interrupt completion signal; The hardware acceleration module further writes the interrupt completion signal to the first register after determining the second verification code, and notifies the first processing module that the second verification code has been generated; 8. The secure boot control device for a chip as described in claim 7, wherein the first processing module further retrieves the first verification code from the first memory in response to detecting the interrupt completion signal in the first register, compares the second verification code with the first verification code, and retrieves the comparison result.
9. A second register is connected to the hardware acceleration module and stores verification setting information including verification algorithm information corresponding to the preset step; The secure boot control device of a chip as described in claim 6, wherein the hardware acceleration module further obtains the verification setting information from the second register and generates the second verification code of the first mirror data based on the verification setting information and the first mirror data.
10. Further comprising a second memory and an initial processing module; The second memory stores an initial boot program and initial verification setting information of the hardware acceleration module; The secure boot control device for a chip as described in claim 6, wherein the initial processing module executes the initial boot program stored in the second memory to enter an initial boot stage, obtains the initial verification setting information from the second memory based on the initial boot program, performs initialization setting for the hardware acceleration module based on the initial verification setting information, and enters the preset stage of the chip boot procedure.
11. A computer-readable storage medium storing a computer program for executing the secure boot control method for a chip according to any one of claims 1 to 5.
12. An electronic device, A processor; a memory storing instructions executable by the processor; The processor reads the executable instructions from the memory and executes the instructions to perform the method for controlling secure boot of a chip according to any one of claims 1 to 5, or The electronic device includes: An electronic device comprising the secure boot control device of the chip according to any one of claims 6 to 10.
Citation Information
Patent Citations
Microcomputer and software tampering prevention method thereof
JP2007310688A
Computer system and abnormality detection circuit
JP2010140361A
Device, secure element and secure boot method for device
JP2021164009A
Electronic Control Units for Vehicles
US20190012483A1