Device for ensuring trusted loading of embedded software into a microcircuit
The integrated device within the SoC ensures secure firmware loading and data integrity by using domestic cryptographic algorithms and hardware isolation, addressing the limitations of existing solutions in protecting embedded software and data integrity.
Patent Information
- Authority / Receiving Office
- RU · RU
- Patent Type
- Utility models
- Current Assignee / Owner
- AKTSIONERNOE OBSHCHESTVO KRAFTVEJ KORPOREJSHN PLS
- Filing Date
- 2026-05-14
- Publication Date
- 2026-07-01
AI Technical Summary
Existing hardware-based security solutions for systems-on-a-chip (SoCs) lack integration with domestic cryptographic standards, fail to prevent firmware version rollbacks, and are not designed as standalone modules, making them unsuitable for protecting embedded software and data integrity.
A device integrated within the SoC that includes an AXI4 system bus, APB system bus, non-volatile memory, one-time programmable memory, watchdog timer, and cryptographic units to ensure secure firmware loading and data integrity, using domestic cryptographic algorithms and hardware isolation mechanisms.
Enhances security by preventing unauthorized access and modification of embedded software while allowing controlled updates, adhering to domestic cryptographic standards and preventing firmware rollback attacks.
Smart Images

Figure 00000001_ABST
Abstract
Description
[0001] Technical field
[0002] This utility model relates to hardware-based information security for integrated circuits, including systems-on-a-chip (SoCs). The term "microcircuit" is hereinafter also used to refer to a system-on-a-chip, specifically embedded hardware that ensures trusted firmware loading, protection against unauthorized access to data, integrity control of embedded firmware, and monitoring of the chip's state. This utility model can be used in the construction of network controllers, cryptographic modules, secure computers, and other microcircuits that require a trusted security loop and compliance with domestic cryptographic standards.
[0003] Technology Level
[0004] Technical solutions implementing trusted boot and hardware protection for software in computing devices are known. These solutions include hardware-software trusted boot modules (HSTBMs), trusted execution environment modules (TEEs), hardware root of trust modules (HRTs), and secure elements (SEEs) within systems-on-chip (SoCs).
[0005] A technical solution known as "Device for Creating a Trusted Environment for Computers in Information and Computing Systems" is available under patent RU 2538329 C1 (published January 10, 2015, IPC G06F 12 / 14). It implements a hardware and software trusted boot module based on a control microcontroller, a flash memory drive with an SPI interface containing the computer's BIOS, and a high-speed electronic key. This device is designed as a separate, standalone unit installed in the computer's bus and is intended to monitor the integrity of the external computer's BIOS.The disadvantages of this solution, when applied to the task of protecting the system-on-a-chip's own embedded software, are: its design is based on the principle of an external module protecting another microcircuit (the BIOS microcircuit of an external computer); the absence of the use of domestic cryptographic algorithms as a design feature of the device; and the absence of a hardware limitation on the number of firmware updates.
[0006] A technical solution is known under patent US 10083306 B2 "Establishing hardware roots of trust for internet-of-things devices" (published September 25, 2018), describing a hardware root of trust device containing a one-time programmable fuse, an asymmetric key, persistent memory of a secure boot loader, a cryptographic accelerator, an elliptic cryptography accelerator, a modular exponentiation accelerator, a random number generator, and a security processor. A disadvantage of this solution, as applied to the problems addressed by the claimed utility model, is the use of cryptographic algorithms and elliptic curve parameters that do not comply with domestic standards, which leads to the absence of hardware units with specific design features necessary for the implementation of these standards.
[0007] A technical solution is known under US Patent 11216597 B2 "Security system and method for preventing rollback attacks on silicon device firmware" (published 04.01.2022), which implements protection against firmware version rollback attacks by storing a 32-bit version counter in a one-time programmable memory array and comparing the current counter value with a reference value. A disadvantage of this solution, when applied to a complex task, is its narrow focus solely on the version rollback prevention function, without integration with other trusted circuit functions and without the use of domestic cryptographic standards. Furthermore, this solution uses a different memory cell design (a counter of a uniform size), rather than an array of identical addressable cells.
[0008] The closest to the claimed technical solution in terms of the set of essential features (prototype) is the device “Device for creating a trusted environment for special-purpose computers” according to patent RU 2569577 C1 (published on 27.11.2015, IPC G06F 21 / 00), which is a development of the solution according to patent RU 2538329 C1 and additionally contains a chipset signal level converter, a device for blocking and controlling the main power supply of the computer independent of the chipset, a universal PCI Express M.2 standard connector and an interface for identifying the motherboard model.
[0009] The significant shortcomings of the prototype with respect to the problem addressed by the utility model are: the device is implemented as a separate stand-alone module on a printed circuit board, which makes it impossible to use it as part of a single microcircuit (system on a chip); it is focused on protecting the BIOS of an external computer, rather than on protecting the microcircuit's own embedded software; the lack of implementation of domestic cryptographic algorithms for the formation and verification of an electronic digital signature and hashing in the form of built-in hardware units with design features that comply with the specified standards; the lack of hardware means for limiting the number of firmware updates with the prevention of version rollback, implemented as an array of identical addressable memory cells.
[0010] Disclosure of the essence of the utility model
[0011] The objective of this utility model is to create a device that ensures the formation of a closed trusted security loop and implements cryptographic transformations according to domestic standards.
[0012] The technical result of the utility model is to increase the security of the embedded software of the microcircuit and the data processed by it from unauthorized access and modification while maintaining the possibility of controlled updating of the embedded software.
[0013] The specified technical result is achieved in that the device for ensuring trusted loading of embedded software into a microcircuit, located on the chip crystal, contains an AXI4 system bus, an APB system bus, a control unit having an interface to the AXI4 system bus and an interface to the APB system bus, a non-volatile memory ROM unit storing a primary unchangeable image of the bootloader executed by the control unit during initialization and connected to the APB system bus, a one-time programmable memory OTP unit containing cells for storing at least one reference hash value of the embedded software and a reference public key for verifying an electronic digital signature and connected to the APB system bus, a watchdog timer unit connected to the APB system bus, a QSPI Flash memory controller unit connected to the AXI4 system bus and to external QSPI Flash memory, an inverse element,connected to the AXI4 system bus, a modulo multiplication unit connected to the AXI4 system bus, a hash function calculation acceleration unit connected to the AXI4 system bus, a shared key calculation unit connected to the AXI4 system bus, a public key generation unit connected to the AXI4 system bus, an electronic digital signature verification unit connected to the AXI4 system bus and configured to receive a hash value from the hash function calculation acceleration unit via the AXI4 system bus and a reference public key from the one-time programmable memory unit OTP via the control unit and the APB and AXI4 system buses, an elliptic curve point membership verification unit connected to the AXI4 system bus, an elliptic curve point coordinate conversion unit connected to the AXI4 system bus, an electronic digital signature calculation unit connected to the AXI4 system bus, and a unit physical isolation,connected to the AXI4 system bus and having an output interface configured to connect to a PCI Express host interface unit.
[0014] In one possible embodiment, the physical isolation unit contains a built-in active plug and is configured to switch, using a control signal, the modes of passing transactions received through the specified output interface from the PCI Express host interface unit, between the mode of transmitting the specified transactions to the remaining units of the device through the AXI4 system bus and the mode of redirecting the specified transactions to the built-in active plug, which generates response transactions of the AXI4 protocol without accessing the specified remaining units of the device, thereby blocking access from the host system to the internal units of the device.
[0015] In one of the possible embodiments, the OTP one-time programmable memory block is made using eFuse technology in the form of an array of one-time burned memory cells, wherein the OTP one-time programmable memory block contains N identical memory cells arranged sequentially in ascending order of addresses, each of which is configured to record the hash value of the reference image of the embedded software once, and the control unit is configured to select as the actual content the cell with the highest address, having a value different from zero.
[0016] In one possible implementation, the OTP memory block contains error correction code fields for the stored hash values and key data.
[0017] In one of the possible embodiments, it additionally contains a JTAG controller unit that provides exchange with an external JTAG debugger via the JTAG interface of the chip, and a JTAG controller isolation unit connected between the APB system bus and the said JTAG controller unit, implemented in the form of a multiplexer of the APB protocol signal lines and providing, upon a control signal, switching of the said lines on the side of the JTAG controller unit to constant values, which ensures the isolation of the internal units of the device from the external JTAG debugger.
[0018] In one possible embodiment, the elliptic curve point membership checking unit is configured to check the point's membership in projective coordinates on twisted Edwards curves.
[0019] In one possible embodiment, the modulo multiplication unit is configured to process 256-bit and 512-bit operands using the Barrett algorithm for modulo multiplication and the Karatsuba algorithm for regular multiplication.
[0020] In one possible embodiment, the hash function calculation acceleration unit is configured to calculate a hash value of 256 and 512 bits in length, as well as to calculate a CRC checksum.
[0021] In one of the possible embodiments, it further comprises a UART controller unit with support for the ISO / IEC 7816-3 standard, connected to the APB system bus and containing hardware for half-duplex exchange via a single data line and hardware for generating a time interval for protecting between bytes.
[0022] In one possible implementation option, the control unit is implemented on the basis of a processor core with the PJSC-V architecture, supporting the RV64IMCB instruction set, including the Zba, Zbb, Zbc and Zbs extensions for hardware acceleration of operations with bit fields.
[0023] In one possible embodiment, the physical isolation unit has two control inputs, wherein the first control input is connected to a dedicated cell of the one-time programmable memory block OTP, which stores the operation enable bit of the physical isolation unit, and the second control input is connected to a dedicated register within the control unit, accessible to the control processor for operational switching of the state of the physical isolation unit during the operation of the microcircuit.
[0024] In one possible embodiment, the JTAG controller isolation unit has two control inputs, wherein the first control input is connected to a dedicated cell of the one-time programmable memory block OTP, which stores the operation enable bit of the JTAG controller isolation unit, and the second control input is connected to a dedicated register within the control unit, accessible to the control processor for operational switching of the state of the JTAG controller isolation unit during the operation of the chip.
[0025] In one of the possible embodiments, the said microcircuit additionally contains an Ethernet network interface controller unit connected to the AXI4 system bus of the said device, and a network packet cryptographic processing unit connected to the AXI4 system bus of the said device and to the said Ethernet network interface controller unit, wherein the said Ethernet network interface controller unit and the network packet cryptographic processing unit are implemented in the form of hardware logic circuits in the hardware description language.
[0026] In special cases of the utility model implementation, an additional technical effect is achieved - eliminating the possibility of access from the host system to the internal data and network traffic of the microcircuit during the execution of critical operations.
[0027] The specified additional effect is achieved through two-channel control of the state of the physical isolation block based on the set of values of a single cell of the OTP block and a separate register in the address space of the control processor, which ensures both irreversible resolution of the isolation function at the stage of microcircuit manufacturing and operational switching of the block state during the operation of the device.
[0028] Additionally, in specific implementations of the utility model, another technical effect is achieved: eliminating the possibility of accessing the internal data of the chip from an external debugger connected to the chip's JTAG interface. This additional effect is achieved by incorporating a JTAG controller isolation unit into the device, designed to hardware-separate the JTAG controller unit from the system data bus in the chip's protected mode. The JTAG controller isolation unit is controlled using a dual-channel scheme, similar to the physical isolation unit of the PCI Express host interface.
[0029] Brief description of drawings
[0030] The drawing shows a structural diagram of the device, including the following blocks and elements:
[0031] 100 - microcircuit safety and status control device;
[0032] 101 - external QSPI Flash memory;
[0033] 102 - QSPI Flash memory controller block;
[0034] 103 - inverse element calculation block;
[0035] 104 - modulo multiplication block;
[0036] 105 - hash function calculation acceleration block;
[0037] 106 - shared key calculation block;
[0038] 107 - public key generation block;
[0039] 108 - electronic digital signature verification block;
[0040] 109 - block for checking whether a point belongs to an elliptic curve;
[0041] 110 - elliptic curve point coordinate transformation block;
[0042] 111 - electronic digital signature calculation block;
[0043] 112 - Ethernet network interface;
[0044] 113 - Ethernet network interface controller unit;
[0045] 114 - network packet cryptographic processing block;
[0046] 115 - physical isolation block;
[0047] 116 - PCI Express host interface block;
[0048] 117 - host system;
[0049] 118 - control unit;
[0050] 119 - non-volatile memory block ROM;
[0051] 120 - one-time programmable memory block OTP;
[0052] 121 - watchdog timer block;
[0053] 122 - internal sensor status control unit;
[0054] 123 - UART controller block with support for ISO / IEC 7816-3 standard;
[0055] 124 - external token (smart card);
[0056] 125 - UART controller block with RTS / CTS hardware flow control support;
[0057] 126 - External Hardware-Software Trusted Boot Module (EHSTBM);
[0058] 127 - JTAG controller isolation block;
[0059] 128 - JTAG controller block;
[0060] 129 - JTAG interface;
[0061] 150 - AXI4 (Advanced extensible Interface, version 4) system bus on a chip;
[0062] 151 - Advanced Peripheral Bus (APB) system bus on a crystal; 190 - a microcircuit on the crystal of which device 100 is located.
[0063] Implementation of a utility model
[0064] The device 100 for security and monitoring the state of the microcircuit is located on the crystal of the microcircuit 190 and contains blocks 102, 103, 104, 105, 106, 107, 108, 109, 110, 111, 115, 118, 119, 120, 121, 122, 123, 125, 127, 128, connected to each other via the system bus 150 AXI4 (Advanced extensible Interface, version 4) and the system bus 151 APB (Advanced Peripheral Bus). Bus 150 connects high-speed cryptographic processing units and a physical isolation unit, bus 151 connects a control unit, memory units, low-speed peripheral units, and JTAG units. Units 102, 103, 104, 105, 106, 107, 108, 109, 110, 111, 115, 119, 120, 121, 122, 123, 125, 127, 128 are implemented as hardware logic circuits (IP blocks) in a hardware description language (e.g., Verilog or System Verilog) and represent sets of hardware gates and registers. Control unit 118 is implemented on a processor core with RISC-V architecture.
[0065] Microcircuit 190, on the crystal of which device 100 is located, additionally comprises an Ethernet network interface controller unit 113, a network packet cryptographic processing unit 114, and a PCI Express host interface unit 116. Said units 113, 114, 116 are located on the same crystal as the units of device 100, but are not included in device 100 and ensure the regular interaction of microcircuit 190 with external network participants and the host system. Units 113 and 114 are connected to the AXI4 system bus 150 of device 100 and to each other. Block 116 is connected to block 115 of physical isolation of device 100 and, through said block, to system bus 150. Said blocks 113, 114, 116 are implemented in the form of hardware logical circuits in hardware description language. Blocks 113, 114, 116 are shown in the drawing to indicate the boundaries of device 100 as part of microcircuit 190 and information exchange across these boundaries.
[0066] External memory 101 QSPI Flash is located outside the chip crystal and is intended for storing the main firmware image loaded during device initialization.
[0067] QSPI Flash Memory Controller Block 102, implemented as a hardware logic circuit, is bidirectionally connected to AXI4 system bus 150 and external memory 101 and facilitates data exchange with said external memory via the QSPI interface. Block 102 is configured to read and write data blocks to said external memory in response to commands from control processor block 118.
[0068] Inverse element calculation unit 103, implemented as a hardware logic circuit, calculates the inverse element modulo a prime number of the order of a cyclic subgroup of elliptic curve points, used in the generation and verification of an electronic digital signature. Unit 103 implements an inverse element search algorithm, such as the binary Euclidean algorithm, and is connected to the AXI4 system bus 150. Using a specialized hardware unit instead of a software-based inverse element calculation reduces the execution time by tens of times and frees up the resources of the control processor of unit 118 for other tasks.
[0069] Modular multiplication unit 104, implemented as a hardware logic circuit, implements modulo multiplication and standard multiplication of two numbers with a bit width of 256 and 512 bits. These operations are basic for units 103, 106, 107, 108, 110, and 111 and ensure scalar multiplication of an elliptic curve point by a scalar, which underlies all cryptographic operations according to domestic electronic digital signature standards. Unit 104 implements a modulo reduction algorithm, such as the Barrett algorithm, and a multi-digit number multiplication algorithm, such as the Karatsuba algorithm. Unit 104 is connected to the AXI4 system bus 150.
[0070] Hash function acceleration unit 105, implemented as a hardware logic circuit, implements the operation of a hashing algorithm, for example, according to GOST R 34.11-2012 (the "Stribog" algorithm), with a hash value length of 256 and 512 bits, and contains hardware means for implementing the L and P transformations, a nonlinear S transformation based on the corresponding substitution table and an iterative structure with an internal state length of 512 bits. Unit 105 also implements the calculation of the CRC checksum. Unit 105 is connected to the AXI4 system bus 150 and is used by unit 108 to verify the electronic digital signature of the embedded software loaded by the microcircuit during initialization.
[0071] The shared key calculation unit 106, implemented as a hardware logic circuit, generates a shared key based on the counterparty's public key, its own private key, and a salt value in accordance with the elliptic curve key agreement algorithm. Unit 106, together with modulo multiplication unit 104, performs the scalar product and ensures the construction of secure interaction sessions with external token 124 and external trusted boot hardware and software module 126. Unit 106 is connected to the AXI4 system bus 150.
[0072] Public key generation unit 107, implemented as a hardware logic circuit, generates a public key by taking the scalar product of the private key and the generator of a cyclic subgroup of elliptic curve points. Unit 107, together with modulo multiplication unit 104 and the point coordinate conversion software unit, implements the key pair generation algorithm, for example, according to GOST R 34.10-2012. Unit 107 is connected to system bus 150 AXI4.
[0073] Electronic digital signature verification unit 108, implemented as a hardware logic circuit, verifies the electronic digital signature of the embedded software loaded by the chip during initialization. Unit 108 implements the electronic digital signature verification algorithm, for example, according to GOST R 34.10-2012, using a reference public key stored in unit 120 of the one-time programmable memory (OTP) and the hash value of the image being verified, calculated by unit 105. A positive verification result is a mandatory condition for transferring control to the loaded image. Unit 108 is connected to system bus 150 AXI4.
[0074] Elliptic Curve Point Membership Checker 109, implemented as a hardware logic circuit, verifies whether a point belongs to a given elliptic curve and provides protection against attacks on key agreement and digital signature generation algorithms, in which the adversary transmits points that do not belong to the specified curve. In one embodiment, Block 109 is configured to verify point membership in projective coordinates on twisted Edwards curves. Block 109 is connected to the AXI4 system bus 150.
[0075] Point coordinate conversion unit 110, implemented as a hardware logic circuit, implements the transformation of elliptic curve point coordinates between the Weierstrass form and the Edwards form. This transformation is used by units 107, 108, and 111 when performing operations on elliptic curve points, since various cryptographic transformation algorithms are implemented more efficiently in different forms of curve point representation. Unit 110 is connected to the AXI4 system bus 150.
[0076] Electronic digital signature calculation unit 111, implemented as a hardware logic circuit, generates an electronic digital signature for arbitrary data. Unit 111 implements the electronic digital signature generation algorithm, for example, according to GOST R 34.10-2012, and, together with hash function acceleration unit 105, modulo multiplication unit 104, and inverse element calculation unit 103, ensures the signing of messages and authentication data transmitted to external participants of secure protocols. Unit 111 is connected to system bus 150 AXI4.
[0077] The 112 Ethernet network interface is located off-chip and provides connection of the device to external network data lines.
[0078] Ethernet network interface controller unit 113, implemented as a hardware logic circuit, is located on the die of microcircuit 190 and is not part of device 100. Unit 113 provides connection of microcircuit 190 to network interface 112 and implements the functions of the physical and data link layers of the Ethernet protocol. Unit 113 is connected to system bus 150 AXI4.
[0079] The network packet cryptographic processing unit 114, implemented as a hardware logic circuit, is located on the crystal of the microcircuit 190 and is not included in the device 100. The unit 114 implements cryptographic transformations of the IPSec protocol network packets in accordance with block encryption algorithms, for example, according to GOST R 34.12-2015 in modes according to GOST R 34.13-2015. In one embodiment, the unit 114 is implemented according to the principle described in patent No. 12345. The unit 114 is connected to the AXI4 system bus 150 and to the unit 113.
[0080] Physical isolation unit 115, implemented in the form of a hardware logic circuit, is located in the AXI4 system bus 150 at the boundary of the device 100 and is connected to the PCI Express host interface unit 116, located on the die of the microcircuit 190 outside the device 100. Unit 115 contains a built-in active AXI4 bus stub, configured to generate correct response transactions of the AXI4 protocol with zero data. The isolation mode is enabled by the control unit 118 promptly during the operation of the microcircuit or once during the initialization of the device - based on the value of the isolation flag recorded in a separate cell of unit 120 of the one-time programmable memory OTP. In the inactive isolation mode, transactions coming from unit 116 are transmitted by unit 115 to the system bus 150 for further processing by the internal units of the device.In the active isolation mode, the specified transactions are redirected to the built-in active stub, which ensures that access from the host system 117 to the internal units of the device 100 is blocked.
[0081] The PCI Express host interface block 116, implemented in the form of a hardware logic circuit, is located on the crystal of the microcircuit 190 and is not part of the device 100. The block 116 provides the physical and channel layers of the PCI Express protocol for the interaction of the microcircuit 190 with the host system 117. The block 116 is connected to the physical isolation block 115 of the device 100, through which data is exchanged between the block 116 and the internal blocks of the device 100 located on the AXI4 system bus 150.
[0082] Host system 117 is an external computer to which the chip 190 is connected via the PCI Express interface.
[0083] Control unit 118 is implemented on a processor core with PJSC-V architecture and controls and coordinates the operation of all other units of device 100. The control processor of unit 118 executes the primary bootloader, reads from unit 120 OTP identification parameters of the microcircuit, locking features of debug interfaces, reference hash values and a reference public key for verifying the electronic digital signature, initiates reading the main image of the embedded software from external memory 101 QSPI Flash through unit 102 of the controller, initiates the calculation of the hash value of the specified image by unit 105, initiates verification of the electronic digital signature of the specified image by unit 108, and if the verification result is positive, transfers control to the specified image.In one embodiment, Block 118 is implemented on a processor core with the PJSC-V architecture, supporting the RV64IMCB instruction set, including the Zba, Zbb, Zbc, and Zbs extensions for hardware acceleration of bitfield operations. Block 118 is connected to the APB system bus 151.
[0084] Non-volatile ROM memory unit 119, implemented as a hardware logic circuit, stores the primary, immutable bootloader image, executed by control unit 118 immediately after power is applied to the chip. The bootloader image is written to unit 119 during chip manufacturing and cannot be changed during operation. Unit 119 is connected to system bus 151 (APB).
[0085] One-time programmable memory unit 120, implemented as a hardware logic circuit, is, in one embodiment, implemented using eFuse technology as an array of one-time-burned memory cells and contains N identical cells arranged sequentially in ascending address order, each of which is capable of once-only writing the hash value of a reference firmware image or other verification parameters. During device initialization, control unit 118 is configured to select the contents of the cell with the highest non-zero address as the actual value. This ensures a hardware limitation on the number of permissible firmware updates and prevents rollback to a previously used image. Unit 120 contains error correction code (ECC) fields for the stored hash values and key data, which ensures the reliability of data reading during memory cell degradation.Additionally, block 120 contains cells storing the physical isolation block 115 operation enable flag and the microcircuit debug interface lock flags. Block 120 is connected to system bus 151 (APB).
[0086] Watchdog timer unit 121, implemented as a hardware logic circuit, prevents control unit 118 and other system-on-chip units from freezing by forcibly resetting them if there is no activity confirmation within a predetermined time interval. Unit 121 is connected to system bus 151 (APB).
[0087] The 122 internal sensor status monitoring unit, implemented as a hardware logic circuit, is connected to temperature sensors, power supply voltage sensors, and transistor process parameters located directly on the chip, and continuously monitors these parameters. Unit 122 generates an alarm signal sent to control unit 118 when any of the monitored parameters exceeds preset value ranges. Unit 122 is connected to the APCS system bus 151.
[0088] UART controller block 123, which supports the ISO / IEC 7816-3 standard and is implemented as a hardware logic circuit, is designed to connect an external smart card-based token 124 to the device. Block 123 contains hardware for half-duplex communication via a single data line and hardware for generating a guard time interval between bytes in accordance with the specified standard. Block 123 is connected to the APB system bus 151.
[0089] The external token 124 is a smart card connected to the device 100 via the block 123, and is used to authenticate the user and store the user's private key.
[0090] UART controller block 125 with support for hardware RTS / CTS flow control, implemented in the form of a hardware logic circuit, provides connection to the device of an external hardware-software trusted boot module 126. Block 125 is connected to the system bus 151 APB.
[0091] The external hardware and software trusted boot module 126 (AHSM) is a stand-alone device that connects to the device 100 via the unit 125 and provides an additional authentication loop.
[0092] JTAG controller isolation unit 127, implemented as a hardware logic circuit, is connected between the APB system bus 151 and the JTAG controller unit 128 and is implemented as a multiplexer of the APB protocol signal lines. The isolation mode is activated by the control unit 118 either promptly during the chip's operation or once during the device's initialization, based on the isolation flag value stored in a separate cell of the one-time programmable memory unit 120. In the inactive isolation mode, the APB protocol signal lines are transmitted unchanged by unit 127 between the system bus 151 and the JTAG controller unit 128. In the active isolation mode, the multiplexer switches the specified signal lines on the side of block 128 to constant values, which ensures the isolation of block 128 from system bus 151 and the impossibility of access from the side of an external debugger connected to interface 129 to the internal data of the microcircuit.
[0093] JTAG controller block 128, implemented as a hardware logic circuit, implements the functions of the JTAG debug interface in accordance with the IEEE 1149.1 standard. Block 128 is connected to JTAG controller isolation block 127 on the APB system bus side and to JTAG interface 129 on the side of the external lines of the chip.
[0094] The 129 JTAG interface is located on the external pins of the chip and is designed to connect an external JTAG debugger during factory testing or authorized diagnostics of the chip.
[0095] The AXI4 system bus 150 is a high-speed on-chip bus of the AMBA family and is functionally included in the device 100. The said bus provides a connection between the blocks 102, 103, 104, 105, 106, 107, 108, 109, 110, 111 of the device 100; the physical isolation block 115 is located in the lines of the said bus on the boundary of the device 100 and provides a connection of the bus 150 with the PCI Express host interface block 116 located on the crystal of the chip 190 outside the device 100. The said bus 150 physically extends on the crystal of the chip 190 outside the device 100, which provides a connection of the blocks 113 and 114 to the said bus; blocks 113 and 114 are located on the crystal of the microcircuit 190 outside the device 100. The system bus 151 APB is a bus of the AMBA family for connecting low-speed peripheral blocks and provides a connection between blocks 118, 119, 120, 121, 122, 123, 125 and 127 of the device 100.The said buses 150 and 151 are connected to each other via a control unit 118 having interfaces to both buses.
[0096] Device 100 operates as follows. After power is applied, the control processor of block 118 begins executing the primary bootloader stored in block 119. The primary bootloader reads the chip identification parameters, debug interface locking indicators, the block 115 operation enable indicator, reference hash values, and the reference public key from block 120 via bus 151. When the block 115 operation enable indicator is set, the control processor of block 118 switches block 115 to the active (isolated) state by writing to a dedicated register in the address space of the control processor, which eliminates the possibility of access from host system 117 to the internal blocks of device 100 during the execution of critical operations.
[0097] Then the control processor of block 118 initiates reading the main image of the embedded software from the external memory 101 via bus 150 and block 102. The read data is sent to block 105, which calculates their hash value. After completing the calculation of the hash value, the control processor of block 118 initiates verification of the electronic digital signature of the said image by block 108 using the reference public key read from block 120 and the hash value calculated by block 105. When performing the verification, block 108 uses blocks 103, 104, 109, 110 to perform the corresponding cryptographic operations on elliptic curve points and modular arithmetic operations.
[0098] If the check is successful, the control processor of block 118 transfers control to the main firmware image. If the check is unsuccessful, the control processor of block 118 enters a lock state, in which the debug interfaces are disabled, while block 115 remains active.
[0099] During operation, unit 121 monitors the activity of unit 118 and other units, restarting them if there is no confirmation of activity within a preset time interval. Unit 122 continuously monitors the crystal's state parameters and, if any of the monitored parameters falls outside the preset value ranges, generates an alarm signal sent to unit 118. In response to the alarm signal, unit 118 can activate unit 115, initiate a device reset, or perform other protective actions.
[0100] The hardware limitation on the number of firmware updates is implemented by writing the hash values of the reference firmware images sequentially into array cells in block 120, starting with the lowest addresses. The cell with the highest address, whose contents are non-zero, is considered valid, preventing version rollbacks. Once all the array cells are exhausted, further firmware updates become impossible.
[0101] Hardware disabling of the JTAG debug interface during chip operation in protected mode is implemented by JTAG controller isolation block 127. When the block 127 operation enable bit is set in block 120, and when the control processor of block 118 writes to a dedicated register, the APB protocol signal line multiplexer within block 127 switches the specified lines on the side of JTAG controller block 128 to constant values. As a result, block 128, while remaining operational, does not receive data from APB system bus 151, and an external debugger connected to JTAG interface 129 cannot access the contents of device 100's internal blocks via block 128.
[0102] The information interaction of the microcircuit 190 with the network participants is carried out through the network interface 112 and the block 113. The network packets of the IPSec protocol, arriving through the block 113, are processed by the block 114, which implements cryptographic transformations on the packets in accordance with the block encryption algorithms and is used to build secure network connections using the cryptographic resources of the device 100, accessible through the system bus 150 AXI4.
[0103] All the specified blocks 102, 103, 104, 105, 106, 107, 108, 109, 110, 111, 115, 119, 120, 121, 122, 123, 125, 127, 128 of the device 100, as well as the blocks 113, 114, 116 of the microcircuit 190, are implemented by standard tools for designing digital integrated circuits and can be manufactured using serial technological processes for the production of integrated circuits (for example, CMOS processes with design standards of 28 nm or less).
[0104] Industrial applicability
[0105] The claimed utility model is industrially applicable, since it is implemented using existing design and production tools for integrated circuits and systems on a chip and can be used in the development of domestic network controller microcircuits, secure computers and cryptographic information protection tools.
Claims
1. A device for ensuring trusted loading of embedded software into a microcircuit, located on a chip crystal and containing an AXI4 system bus, an APB system bus, a control unit having an interface to the AXI4 system bus and an interface to the APB system bus, a non-volatile memory ROM unit storing a primary unchangeable image of the bootloader executed by the control unit during initialization and connected to the APB system bus, a one-time programmable memory OTP unit containing cells for storing at least one reference hash value of the embedded software and a reference public key for verifying an electronic digital signature and connected to the APB system bus, a watchdog timer unit connected to the APB system bus, a QSPI Flash memory controller unit connected to the AXI4 system bus and to external QSPI Flash memory, an inverse element calculator unit connected to the AXI4 system bus, a unit multiplication modulo two numbers,connected to the AXI4 system bus, a hash function calculation acceleration unit connected to the AXI4 system bus, a shared key calculation unit connected to the AXI4 system bus, a public key generation unit connected to the AXI4 system bus, an electronic digital signature verification unit connected to the AXI4 system bus and configured to receive a hash value from the hash function calculation acceleration unit via the AXI4 system bus and a reference public key from the one-time programmable memory unit OTP via the control unit and the APB and AXI4 system buses, an elliptic curve point membership verification unit connected to the AXI4 system bus, an elliptic curve point coordinate conversion unit connected to the AXI4 system bus, an electronic digital signature calculation unit connected to the AXI4 system bus, and a physical isolation unit connected to the AXI4 system bus and having an output interface,configured to be connected to a PCI Express host interface unit.
2. The device according to claim 1, characterized in that the physical isolation unit contains a built-in active plug and is configured to switch, by a control signal, the modes of passing transactions received through the said output interface from the PCI Express host interface unit, between the mode of transmitting said transactions to the remaining units of the device through the AXI4 system bus and the mode of redirecting said transactions to the built-in active plug, which generates response transactions of the AXI4 protocol without accessing the said remaining units of the device, thereby blocking access from the host system to the internal units of the device.
3. The device according to claim 1, characterized in that the one-time programmable memory block OTP is made using eFuse technology in the form of an array of one-time burned memory cells, wherein the one-time programmable memory block OTP contains N identical memory cells, arranged sequentially in ascending order of addresses, each of which is configured to record once the hash value of the reference image of the embedded software, and the control unit is configured to select as the actual content the cell with the highest address, having a value different from zero.
4. The device according to claim 1, characterized in that the one-time programmable memory block OTP contains error correction code fields for stored hash values and key data.
5. The device according to paragraph 1, characterized in that it further comprises a JTAG controller unit, providing for exchange with an external JTAG debugger via the JTAG interface of the microcircuit, and a JTAG controller isolation unit, connected between the APB system bus and the said JTAG controller unit, designed in the form of a multiplexer of the APB protocol signal lines and providing, upon a control signal, switching of the said lines on the side of the JTAG controller unit to constant values, which ensures the isolation of the internal units of the device from the external JTAG debugger.
6. The device according to claim 1, characterized in that the unit for checking the membership of a point on an elliptic curve is designed with the ability to check the membership of a point in projective coordinates on twisted Edwards curves.
7. The device according to claim 1, characterized in that the block for multiplying modulo two numbers is designed with the ability to process 256-bit and 512-bit operands using the Barrett algorithm for multiplication modulo and the Karatsuba algorithm for conventional multiplication.
8. The device according to claim 1, characterized in that the block for accelerating the calculation of the hash function is designed with the possibility of calculating a hash value of 256 and 512 bits in length, as well as calculating the CRC checksum.
9. The device according to claim 1, characterized in that it additionally contains a UART controller unit with support for the ISO / IEC 7816-3 standard, connected to the APB system bus and containing hardware for half-duplex exchange via a single data line and hardware for generating a time interval for protection between bytes.
10. The device according to claim 1, characterized in that the control unit is implemented on the basis of a processor core with the PJSC-V architecture, supporting the RV64IMCB instruction set, including the Zba, Zbb, Zbc and Zbs extensions for hardware acceleration of operations with bit fields.
11. The device according to claim 1, characterized in that the physical isolation unit has two control inputs, wherein the first control input is connected to a dedicated cell of the one-time programmable memory block OTP, which stores the bit for enabling the operation of the physical isolation unit, and the second control input is connected to a dedicated register within the control unit, accessible to the control processor for operational switching of the state of the physical isolation unit during the operation of the microcircuit.
12. The device according to claim 5, characterized in that the JTAG controller isolation unit has two control inputs, wherein the first control input is connected to a dedicated cell of the one-time programmable memory block OTP, which stores the bit for enabling the operation of the JTAG controller isolation unit, and the second control input is connected to a dedicated register within the control unit, accessible to the control processor for operational switching of the state of the JTAG controller isolation unit during the operation of the microcircuit.
13. The device according to claim 1, characterized in that said microcircuit additionally contains an Ethernet network interface controller unit connected to the AXI4 system bus of said device, and a cryptographic network packet processing unit connected to the AXI4 system bus of said device and to said Ethernet network interface controller unit, wherein said Ethernet network interface controller unit and cryptographic network packet processing unit are implemented in the form of hardware logic circuits in a hardware description language.