EC chips, multi-chip package, system and electronic device
By integrating the bus interface, storage module, signature module, and control module into the EC chip, the problem of the lack of RPMC in laptops is solved, and replay protection with improved security is achieved without increasing costs, reducing hardware costs and increasing processing speed.
Patent Information
- Application Number
- PCT/CN2024/143584
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-04-16
- Filing Date
- 2024-12-30
- Publication Date
- 2025-10-23
AI Technical Summary
Some laptops lack a replay protection monotonic counter (RPMC) function because they do not have external flash memory, and existing technology has failed to effectively enhance security without increasing costs.
The EC chip integrates a bus interface, storage module, signature module, and control module. These modules enable replay protection, including generating signature information, parsing data packets, and executing replay protection commands, thereby reducing hardware costs and improving processing speed.
Replay protection has been implemented in devices such as laptops, reducing hardware costs and improving security by quickly processing replay protection commands through hardware circuitry.
Smart Images

Figure CN2024143584_23102025_PF_FP_ABST
Abstract
Description
EC chip, package chip, system and electronic device
[0001] Cross-reference to Related Applications
[0002] This application claims priority to the Chinese Patent Application No. 202410454356.6, filed on April 16, 2024, and entitled “EC chip, package chip, system and electronic device”, the content of which is incorporated herein by reference in its entirety. TECHNICAL FIELD
[0003] The present application relates to the technical field of replay protection, in particular to an embedded controller (EC) chip, a package chip, a system and an electronic device. BACKGROUND
[0004] Replay attacks refer to an attack mode in which an attacker records legitimate communication data packets and then sends the recorded communication data packets again to deceive the system, so that the system mistakenly believes that the data packets are legitimate, thereby achieving the attack purpose. Replay protection monotonic counter (RPMC) can be used to detect replay attacks. For example, communication parties with RPMC record the same count value by means of the monotonic counter. The data sender adds the recorded count value as a variable to the data packet, encrypts the data packet and transmits the data packet on the bus. The data receiver must know the same variable and include it in the data verification algorithm to pass the authentication, thereby preventing replay attacks.
[0005] RPMC is an important function for computing devices such as personal computers. In the related art, an external Flash integrates the RPMC scheme, which communicates with the platform controller hub (PCH) through the serial peripheral interface (SPI). However, the external Flash is not necessary for computing devices such as notebook computers, and some notebook computers do not have an external Flash to reduce costs, which results in that some notebook computers do not have the RPMC function. How to enhance the security of computing devices without increasing the cost of computing devices has not yet been effectively solved. SUMMARY
[0006] In view of the above problems, the embodiments of the present application provide an EC chip, a package chip, a system and an electronic device to solve the above technical problems.
[0007] In a first aspect, embodiments of the present application provide an EC chip, comprising: a bus interface configured to receive and send data packets; one or more storage modules configured to store at least part of replay protection related data; a signature module configured to generate signature information; and a control module configured to parse a received data packet to obtain a replay protection command, and control the signature module and access the one or more storage modules to verify and execute the replay protection command.
[0008] In a second aspect, embodiments of the present application provide an EC chip, comprising: a bus interface configured to receive and send data packets; one or more storage control modules configured to access one or more external storage modules, the one or more external storage modules configured to store at least part of replay protection related data; a signature module configured to generate signature information; and a control module configured to parse a received data packet to obtain a replay protection command, and control the signature module and the one or more storage control modules to verify and execute the replay protection command.
[0009] In a third aspect, embodiments of the present application provide a system-in-package, comprising: one or more storage chips configured to store at least part of replay protection related data; and an EC chip, the EC chip comprising: a bus interface configured to receive and send data packets; a signature module configured to generate signature information; a storage control module configured to access the one or more storage chips; and a control module configured to parse a received data packet to obtain a replay protection command, and control the signature module and the one or more storage control modules to verify and execute the replay protection command.
[0010] In a fourth aspect, embodiments of the present application provide a system, comprising: one or more storage modules configured to store at least part of replay protection related data; and an EC chip, the EC chip comprising: a bus interface configured to receive and send data packets; a signature module configured to generate signature information; a storage control module configured to access the one or more storage modules; and a control module configured to parse a received data packet to obtain a replay protection command, and control the signature module and the one or more storage control modules to verify and execute the replay protection command.
[0011] In a fifth aspect, embodiments of the present application provide an electronic device, comprising a device main body and an EC chip, or a system-in-package, or a system disposed on the device main body.
[0012] These and other aspects of the present application will become more apparent from the following description of embodiments. BRIEF DESCRIPTION OF DRAWINGS
[0013] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings needed to be used in the embodiments description will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without any creative effort based on these drawings.
[0014] Fig. 1 shows a structure schematic diagram of an EC chip provided by an embodiment of the present application.
[0015] Fig. 2 shows a structure schematic diagram of another EC chip provided by an embodiment of the present application.
[0016] Fig. 3 shows a structure schematic diagram of another EC chip provided by an embodiment of the present application.
[0017] Fig. 4a shows a structure schematic diagram of another EC chip provided by an embodiment of the present application.
[0018] Fig. 4b shows a structure schematic diagram of another EC chip provided by an embodiment of the present application.
[0019] Fig. 4c shows a structure schematic diagram of another EC chip provided by an embodiment of the present application.
[0020] Fig. 4d shows a structure schematic diagram of another EC chip provided by an embodiment of the present application.
[0021] Fig. 5 shows a structure schematic diagram of another EC chip provided by an embodiment of the present application.
[0022] Fig. 6 shows a structure schematic diagram of a sealing chip provided by an embodiment of the present application.
[0023] Fig. 7 shows a flow chart of an exemplary root key binding process provided by an embodiment of the present application.
[0024] Fig. 8 shows a flow chart of an exemplary signature key updating process provided by an embodiment of the present application.
[0025] Fig. 9 shows a flow chart of an exemplary reading replay protection monotonic counter value process provided by an embodiment of the present application.
[0026] Fig. 10 shows a flow chart of an exemplary replay protection monotonic counter value increasing by 1 process provided by an embodiment of the present application.
[0027] Fig. 11 shows a flow chart of an exemplary reading RPMC parameter process provided by an embodiment of the present application. DETAILED DESCRIPTION
[0028] The embodiments of the present application will be described in detail below with reference to the drawings, in which the same or similar components have the same or similar designations, and in which: The embodiments described below are exemplary only, and are not intended to be limiting of the present application.
[0029] In order to make persons skilled in the art better understand the schemes of the present application, the technical schemes in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only some of the embodiments of the present application, but not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by persons skilled in the art without creative labor fall within the scope of protection of the present application.
[0030] It should be noted that in the embodiments of the present application, in this document, the terms such as first and second, etc. are merely used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply that there is any such actual relationship or order between these entities or operations.
[0031] Moreover, the terms "comprising", "containing", or any other variant thereof are intended to cover non-exclusive inclusion, so that a process, method, article, or apparatus that includes a list of elements not only includes those elements, but also includes other elements not explicitly listed, or further includes elements inherent in such a process, method, article, or apparatus. Without more limitations, the element defined by the phrase "comprising a" does not exclude the presence of additional identical elements in the process, method, article, or apparatus that includes the element.
[0032] In the description of the embodiments of the present application, the words "example" or "for example" are used to mean exemplification, illustration, or description. Any embodiment or design scheme described as "example" or "for example" in the embodiments of the present application is not to be interpreted as being more preferred or having more advantages than another embodiment or design scheme. The words "example" or "for example" are intended to present a relative concept in a clear manner.
[0033] In addition, "a plurality of" in the embodiments of the present application means two or more, and in view of this, "a plurality of" in the embodiments of the present application can also be understood as "at least two". "At least one" can be understood as one or more, for example, as one, two or more. For example, including at least one means including one, two or more, and does not limit which ones are included, for example, including at least one of A, B and C means that A, B, C, A and B, A and C, B and C, or A and B and C can be included.
[0034] It should be noted that, in the embodiments of the present application, the association relationship of the associated objects described by "and / or" represents that there can be three kinds of relationships, for example, A and / or B can represent that there are three cases of A alone, A and B together, and B alone. In addition, the character " / ", if not specially stated, generally represents that the associated objects before and after it are in an "or" relationship.
[0035] It should be noted that, in the embodiments of the present application, "connection" can be understood as electrical connection, and the connection between two electrical elements can be direct or indirect connection between the two electrical elements. For example, A is connected to B, which can be direct connection between A and B, or indirect connection between A and B through one or more other electrical elements.
[0036] The EC chip can be in communication connection with a host processor, which can include a central processing unit (CPU). The communication interface between the EC chip and the host processor can include, but is not limited to, one or more of LPC (Low Pin Count), SPI (Serial Peripheral Interface), eSPI (Enhanced Serial Peripheral Interface), etc. The EC chip can help the host processor manage peripherals (also referred to as peripheral devices). For example, the peripherals can include, but are not limited to, one or more of a fan, a keyboard, a mouse, a video, an audio, a USB, a power supply, and others.
[0037] As an example, the EC chip can employ an MCU core, with built-in Flash storage, SRAM, instruction cache, support for one or more interfaces such as eSPI, LPC, I2C Host, etc., can have one or more interfaces such as high-speed UART, high-speed SPI, multi-mode I2C, USB, PD / TYPE-C, keyboard, fan, breathing light, atmosphere light, etc., can have built-in high-precision digital-to-analog conversion ADC / DAC, comparator, voltage monitoring, temperature monitoring, etc. digital-analog interface.
[0038] It should be understood that the foregoing EC chip is only an example and is not intended to limit the implementation of the present disclosure described and / or claimed herein.
[0039] The embodiments of the present application relate to implementing replay protection in an EC chip. Some embodiments of the present application implement replay protection in an EC chip through a signature module and a control module, which can implement replay protection in electronic devices such as notebook computers using an EC chip. Compared with the technical solution of externally hanging a Flash in an electronic device using an EC chip, the hardware cost can be reduced, and the replay protection command can be processed quickly by implementing replay protection through the control module and the signature module.
[0040] Figure 1 shows a structure diagram of an EC chip according to an embodiment of the present application. As shown in Figure 1, the EC chip 100 can include a bus interface 101, one or more storage modules 102, a signature module 103, and a control module 104. The bus interface 101 is configured to receive and send data packets. The one or more storage modules 102 are configured to store at least part of replay protection related data. The signature module 103 is configured to generate signature information. The control module 104 is configured to parse a received data packet to obtain a replay protection command, and control the signature module 103 and access the one or more storage modules 102 to verify and execute the replay protection command.
[0041] In some embodiments, as shown in Figure 2, the one or more storage modules 102 can include a first storage module 102-1 configured to store a root key.
[0042] In some embodiments, as shown in Figure 2, the one or more storage modules 102 can include a second storage module 102-2 configured to store a signature key generated based on the root key.
[0043] In some embodiments, as shown in Figure 2, the one or more storage modules 102 can include a third storage module 102-3 configured to store a replay protection monotonic counter value.
[0044] In some embodiments, as shown in Figure 2, the one or more storage modules 102 can include any two of the first storage module 102-1, the second storage module 102-2, and the third storage module 102-3. As an example, the one or more storage modules 102 can include the first storage module 102-1 and the second storage module 102-2. As another example, the one or more storage modules 102 can include the first storage module 102-1 and the third storage module 102-3. As yet another example, the one or more storage modules 102 can include the second storage module 102-2 and the third storage module 102-3.
[0045] In some embodiments, as shown in Figure 2, the one or more storage modules 102 can include a first storage module 102-1 configured to store a root key, a second storage module 102-2 configured to store a signature key generated based on the root key, and a third storage module 102-3 configured to store a replay protection monotonic counter value.
[0046] In some examples, the first storage module 102-1 can be a non-volatile memory (NVM), and the first storage module 102-1 can be configured to be read and written only by the control module 104 to ensure the security of the root key. In some examples, the first storage module 102-1 can be a non-volatile one-time memory, which can be written only once.
[0047] In some examples, the second storage module 102-2 can be a normal storage area, which can be lost when power is off. In some examples, the second storage module 102-2 can be configured to allow only the control module 104 to read and write, to ensure the security of the signature key.
[0048] In some examples, the third storage module 102-3 can be a non-volatile memory, and the third storage module 102-3 can be configured to be repeatedly written. In some examples, the third storage module 102-3 can be configured to allow only the control module 104 to read and write, to ensure the security of the replay protection monotonic counter value.
[0049] In some embodiments, one or more storage modules 102 can be external, that is, some replay protection related data can be stored in one or more external storage modules outside the EC chip 100. In the embodiments of the present application, the "external storage module" refers to a storage module located outside the EC chip.
[0050] FIG. 3 shows a structure diagram of another EC chip according to an embodiment of the present application. As shown in FIG. 3, the EC chip 300 can include a bus interface 301, a signature module 303, a control module 304, and one or more storage control modules 305. The bus interface 301 is configured to receive and send data packets. The signature module 303 is configured to generate signature information. The one or more storage control modules 305 are configured to access one or more external storage modules 201. The one or more external storage modules 201 are configured to store at least part of the replay protection related data. The control module 304 is configured to parse the received data packet to obtain a replay protection command, and control the signature module 303 and the one or more storage control modules 305 to verify and execute the replay protection command. By providing one or more storage control modules 305 in the EC chip 300, the data in the one or more external storage modules 201 can be prevented from being obtained by the outside world.
[0051] In some embodiments, one storage control module 305 is configured to access multiple external storage modules 201. In other embodiments, at least one storage control module 305 corresponds to one external storage module 201, that is, at least part of the external storage modules 201 are accessed by the corresponding storage control modules 305 respectively.
[0052] In some examples, as shown in FIG. 3, the one or more storage control modules 305 can include a first storage control module 305-1 for accessing a first external storage module 201-1 for storing a root key.
[0053] In some examples, as shown in FIG. 3, the one or more storage control modules 305 can include a second storage control module 305-2 for accessing a second external storage module 201-2 for storing a signature key generated based on the root key.
[0054] In some examples, as shown in FIG. 3, the one or more storage control modules 305 can include a third storage control module 305-3 for accessing a third external storage module 201-3 for storing a replay protection monotonic count value.
[0055] In some examples, as shown in FIG. 3, the one or more storage control modules 305 can include any two of the first storage control module 305-1, the second storage control module 305-2, and the third storage control module 305-3. As one example, the one or more storage control modules 305 can include the first storage control module 305-1 and the second storage control module 305-2. As another example, the one or more storage control modules 305 can include the first storage control module 305-1 and the third storage control module 305-3. As yet another example, the one or more storage control modules 305 can include the second storage control module 305-2 and the third storage control module 305-3.
[0056] In some examples, as shown in FIG. 3, the one or more storage control modules 305 can include a first storage control module 305-1 for accessing a first external storage module 201-1 for storing a root key; a second storage control module 305-2 for accessing a second external storage module 201-2 for storing a signature key generated based on the root key; and a third storage control module 305-3 for accessing a third external storage module 201-3 for storing a replay protection monotonic count value.
[0057] In some examples, the first external storage module 201-1 can be a non-volatile memory, which can be configured to be read and written only by the control module 304 through the storage control module 305 to ensure the security of the root key. In some examples, the first external storage module 201-1 can be a non-volatile one-time memory, which can be written only once.
[0058] In some examples, the second external storage module 201-2 can be a normal storage area, which can lose data when power is off. In some examples, the second external storage module 201-2 can be configured to allow only the control module 304 to read and write through the storage control module 305, so as to ensure the security of the signature key.
[0059] In some examples, the third storage control module 305-3 can be a non-volatile memory, and the third storage control module 305-3 can be configured to be repeatedly writable. In some examples, the third storage control module 305-3 can be configured to allow only the control module 304 to read and write through the storage control module 305, so as to ensure the security of the replay protection monotonic counter value.
[0060] In some embodiments, the EC chip can include one or more storage modules, and can include one or more storage control modules for accessing the one or more external storage modules.
[0061] FIGS. 4a-4d show structure diagrams of various EC chips according to embodiments of the present application. As shown in FIGS. 4a-4d, the EC chip 400 can include a bus interface 401, one or more storage modules 402, a signature module 403, a control module 404, and one or more storage control modules 405. The bus interface 401 is configured to receive and send data packets. The signature module 403 is configured to generate signature information. The one or more storage modules 402 are configured to store at least part of replay protection related data. The one or more storage control modules 405 are configured to access one or more external storage modules 201. The one or more external storage modules 201 are configured to store at least part of replay protection related data. The control module 404 is configured to parse a received data packet to obtain a replay protection command, and control the signature module 403 and the one or more storage modules 402 and the one or more storage control modules 405 to verify and execute the replay protection command.
[0062] In some examples, the one or more storage modules 402 are configured to store a first part of the replay protection related data, and the one or more external storage modules 201 are configured to store a second part of the replay protection related data. For example, the one or more storage modules 402 are configured to store one or any two of a root key, a signature key generated based on the root key, and a replay protection monotonic counter value, and the one or more external storage modules 201 are configured to store the remaining part of the root key, the signature key generated based on the root key, and the replay protection monotonic counter value.
[0063] In some embodiments, as shown in FIG. 4a, the one or more storage modules 402 can include a second storage module 402-2 for storing a signature key generated based on the root key, and a third storage module 402-3 for storing a replay protection monotonic counter value. The one or more external storage modules 201 can include a first external storage module 201-1 for storing the root key, and the storage control module 405 is configured to access the first external storage module 201-1. In this embodiment, the EC chip stores the root key and the replay protection monotonic counter value in the one or more storage modules 402, and the signature key generated based on the root key is stored in the one or more external storage modules 201, and the storage control module 405 is configured to access the signature key stored in the one or more external storage modules 201.
[0064] In some embodiments, as shown in FIG. 4b, the one or more storage modules 402 can include a first storage module 402-1 for storing the root key, and a third storage module 402-3 for storing a replay protection monotonic counter value. The one or more external storage modules 201 can include a second external storage module 201-2 for storing a signature key generated based on the root key, and the storage control module 405 is configured to access the second external storage module 201-2. In this embodiment, the EC chip stores the root key and the replay protection monotonic counter value in the one or more storage modules 402, and the signature key generated based on the root key is stored in the one or more external storage modules 201, and the storage control module 405 is configured to access the signature key stored in the one or more external storage modules 201.
[0065] In some embodiments, as shown in FIG. 4c, the one or more storage modules 402 can include a first storage module 402-1 for storing the root key, and a second storage module 402-2 for storing a signature key generated based on the root key. The one or more external storage modules 201 can include a third external storage module 201-3 for storing a replay protection monotonic counter value, and the storage control module 405 is configured to access the third external storage module 201-3. In this embodiment, the EC chip stores the root key and the signature key in the one or more storage modules 402, and the replay protection monotonic counter value is stored in the one or more external storage modules 201, and the storage control module 405 is configured to access the replay protection monotonic counter value stored in the one or more external storage modules 201.
[0066] In some embodiments, as shown in FIG. 4d, the one or more storage modules 402 can include a third storage module 402-3 for storing a replay protection monotonic counter value. The one or more external storage modules 201 can include a first external storage module 201-1 for storing a root key, a second external storage module 201-2 for storing a signature key, and a storage control module 405 for accessing the first external storage module 201-1 and the second external storage module 201-2. Although FIG. 4d shows the case that the first external storage module 201-1 and the second external storage module 201-2 are accessed through the storage control module 405, in an embodiment of the present application, a storage control module corresponding to each of the first external storage module 201-1 and the second external storage module 201-2 can be respectively arranged, which will not be described herein. It should be understood that FIG. 4d is only illustrative, and in an embodiment of the present application, any two storage modules 402 can be externalized, and a corresponding external storage module 201 can be arranged, which will not be limited in the embodiment of the present application.
[0067] In an embodiment of the present application, the one or more external storage modules described above can include one or more storage chips.
[0068] In some embodiments, the EC chip generates a response corresponding to the replay protection command, in order to improve the response speed, the EC chip can temporarily store predetermined data corresponding to the replay protection command in generating the replay protection related data, and after generating the response corresponding to the replay protection command, synchronizes the temporarily stored predetermined data to the storage module or the external storage module corresponding thereto.
[0069] FIG. 5 shows a structural schematic diagram of an EC chip according to an embodiment of the present application. As shown in FIG. 5, the EC chip 500 can include a bus interface 501, a signature module 503, a control module 504, and a temporary storage module 506.
[0070] In some embodiments, the EC chip 500 can further include one or more storage modules 502 for storing at least part of the replay protection related data. The bus interface 501 is configured to receive and send data packets. The signature module 503 is configured to generate signature information. The control module 504 is configured to parse the received data packet to obtain a replay protection command, and control the signature module 503 and the one or more storage modules 502 to verify and execute the replay protection command. The exemplary embodiments of the one or more storage modules 502 can refer to FIG. 2 and the description thereof, which will not be described herein.
[0071] In some examples, the control module 504 is further configured to, in the case that predetermined data corresponding to the replay protection command in the replay protection related data is generated, store the predetermined data to the temporary storage module 506, and after the response corresponding to the replay protection command is generated, synchronize the predetermined data stored in the temporary storage module 506 to the storage module 502 corresponding thereto.
[0072] In some embodiments, the EC chip 500 can further comprise one or more storage control modules 505 configured to access an external storage module storing at least part of the replay protection related data. The control module 504 is configured to parse the received data packet to obtain the replay protection command, and control the signature module 503 and the one or more storage control modules 505 to verify and execute the replay protection command. The exemplary embodiments of the one or more storage control modules 505 can be found in FIG. 3, which will not be repeated herein.
[0073] In some examples, the control module 504 is further configured to, in the case that predetermined data corresponding to the replay protection command in the replay protection related data is generated, store the predetermined data to the temporary storage module 506, and after the response corresponding to the replay protection command is generated, synchronize the predetermined data stored in the temporary storage module 506 to the external storage module corresponding thereto through the one or more storage control modules 505.
[0074] In some embodiments, the EC chip 500 can further comprise one or more storage modules 502 and one or more storage control modules 505. The exemplary embodiments of the one or more storage modules 502 and the one or more storage control modules 505 can be found in FIG. 4a to FIG. 4d, which will not be repeated herein.
[0075] In some examples, the control module 504 is further configured to, in the case that predetermined data corresponding to the replay protection command in the replay protection related data is generated, store the predetermined data to the temporary storage module 506, and after the response corresponding to the replay protection command is generated, synchronize the predetermined data stored in the temporary storage module 506 to the external storage module corresponding thereto through the one or more storage control modules 505.
[0076] In some embodiments, as shown in FIG. 5, the EC chip 500 can further comprise a synchronization module 507. The control module 504 is further configured to, in the case that predetermined data corresponding to the replay protection command in the replay protection related data is generated, store the predetermined data to the temporary storage module 506, and generate the response corresponding to the replay protection command. The synchronization module 507 is configured to synchronize the predetermined data stored in the temporary storage module 506 to the storage module 502 or the external storage module corresponding thereto.
[0077] As an implementation, the control module shown in FIGS. 1-5 of the foregoing description of the specification can include: a processing unit; a storage unit storing a program, wherein the program includes instructions that, when executed by the processing unit, cause the processing unit to: parse a received data packet to obtain a replay protection command, control a signature module, access one or more storage modules and or one or more external storage modules to verify and execute the replay protection command.
[0078] As an implementation, the control module shown in FIGS. 1-5 of the foregoing description of the specification can be configured to read a key for signing from at least one of the one or more storage modules, the one or more external storage modules, and send the key and a predetermined portion of the replay protection command to the signature module. The signature module can be configured to receive the key and the predetermined portion of the replay protection command, and sign the predetermined portion of the replay protection command based on the key to generate signature information, and return the generated signature information to the control module.
[0079] As an implementation, the EC chip shown in FIGS. 1-5 of the foregoing description of the specification, the control module can be configured to: in the case of parsing a binding root key command, control the signature module to sign a predetermined portion of the binding root key command based on a root key carried by the binding root key command to generate signature information; verify the binding root key command based on the generated signature information and signature information carried by the binding root key command; in the case of passing the verification of the binding root key command, write the root key to the corresponding storage module.
[0080] As an implementation, the EC chip shown in FIGS. 1-5 of the foregoing description of the specification, the control module can be configured to: in the case of parsing an update signature key command, control the signature module to sign a predetermined portion of the update signature key command based on a root key to generate signature information; verify the update signature key command based on the generated signature information and signature information carried by the update signature key command; in the case of passing the verification of the update signature key command, generate a signature key based on the root key and key data carried by the update signature key command, and write the signature key to the corresponding storage module.
[0081] As an implementation, the EC chip shown in FIGS. 1-5 of the foregoing description of the specification, the control module can be configured to: in the case of parsing an increase monotonic counter value command (also referred to as a replay protection monotonic counter value plus one command), control the signature module to sign a predetermined portion of the increase monotonic counter value command based on a signature key to generate signature information; verify the increase monotonic counter value command based on the generated signature information and signature information carried by the increase monotonic counter value command; in the case of passing the verification of the increase monotonic counter value command, increase the replay protection monotonic counter value by one, and write the increased replay protection monotonic counter value to the corresponding storage module.
[0082] As an implementation form, the EC chip shown in FIGS. 1-5 of the foregoing of the present specification, the control module can be configured to: in a case where the read monotonic counter value command is parsed, control the signature module to sign a predetermined part of the read monotonic counter value command based on a signature key to generate signature information; verify the read monotonic counter value command based on the generated signature information and signature information carried by the read monotonic counter value command; in a case where the read monotonic counter value command is verified, read the monotonic counter value from the corresponding storage module; and generate a response carrying the monotonic counter value.
[0083] As an implementation form, the EC chip shown in FIGS. 1-5 of the foregoing of the present specification, the control module can be configured to: generate a response corresponding to the replay protection command; and send the response through the bus interface.
[0084] As an implementation form, the EC chip shown in FIGS. 1-5 of the foregoing of the present specification, the control module can be configured to: control the signature module to sign a predetermined part of the response based on a signature key, and send the response carrying the signature through the bus interface.
[0085] As an implementation form, the signature module shown in FIGS. 1-5 of the foregoing of the present specification can include a hash message authentication code generation unit, and the signature information includes a hash message authentication code. The hash message authentication code is also referred to as hash-based message authentication code (HAMC). It should be understood that the present application does not limit the signature algorithm, and other algorithms capable of verifying the authenticity of data are also feasible, and the present application does not limit this.
[0086] As an implementation form, the bus interface shown in FIGS. 1-5 of the foregoing of the present specification can include an eSPI interface.
[0087] As an implementation form, the EC chip shown in FIGS. 1-5 of the foregoing of the present specification, the bus interface can include an eSPI interface, and the signature module can include an HMAC calculation module.
[0088] The present application also provides a sealing chip, which seals an external storage chip and an EC chip, that is, integrates the EC chip and the external storage chip in one package, so as to realize higher integration and smaller size, reduce the power consumption of the electronic device, improve the performance and simplify the design.
[0089] Figure 6 illustrates a schematic diagram of a bonded chip according to an embodiment of the present application. As shown in Figure 6, the bonded chip includes one or more memory chips 610 and an EC chip 620. The one or more memory chips 610 are configured to store at least part of replay protection related data. The EC chip 620 can include a bus interface 621 configured to receive and send data packets, a signature module 622 configured to generate signature information, a memory control module 623 configured to access the one or more memory chips 610, and a control module 624 configured to parse a received data packet to obtain a replay protection command, control the signature module 622 and control the one or more memory control modules 623 to verify and execute the replay protection command.
[0090] In some embodiments, the one or more memory chips 610 can include a first memory chip configured to store a root key.
[0091] In some embodiments, the one or more memory chips 610 can include a second memory chip configured to store a signature key generated based on the root key.
[0092] In some embodiments, the one or more memory chips 610 can include a third memory chip configured to store a replay protection monotonic counter value.
[0093] In some embodiments, the one or more memory chips 610 can include a first memory chip configured to store a root key, a second memory chip configured to store a signature key generated based on the root key, and a third memory chip configured to store a replay protection monotonic counter value.
[0094] In some embodiments, as shown in Figure 6, the EC chip 620 can further include one or more storage modules 625. The one or more storage modules 625 are configured to store a first part of the replay protection related data, and the one or more memory chips 610 are configured to store a second part of the replay protection related data.
[0095] As an example, as shown in Figure 6, the one or more storage modules 625 can include a third storage module 625-3 configured to store a replay protection monotonic counter value. The one or more memory chips 610 include a first memory chip 610-1 configured to store a root key and a second memory chip 610-2 configured to store a signature key generated based on the root key. It should be understood that Figure 6 is merely an exemplary combination of storage modules and memory chips, and other combinations of storage modules and memory chips can be found in Figures 4a to 4d, which will not be described herein again.
[0096] In some embodiments, the EC chip 620 can adopt the structure shown in Figure 5, which will not be described herein again.
[0097] As an implementation form, the control module 624 shown in FIG. 6 can include a processing unit, and a storage unit storing a program, wherein the program includes instructions which, when executed by the processing unit, cause the processing unit to: parse the received data packet to obtain a replay protection command, control the signature module 622, access the one or more storage modules 625, and control the one or more storage control modules 623 to verify and execute the replay protection command.
[0098] As an implementation form, the control module 624 shown in FIG. 6 is configured to read a key for signature from at least one of the one or more storage chips 610 and the one or more storage modules 625, and send the key and a predetermined part of the replay protection command to the signature module 622; the signature module 622 is configured to receive the key and the predetermined part of the replay protection command, and sign the predetermined part of the replay protection command based on the key to generate signature information, and return the generated signature information to the control module 624. The control module 624 verifies the replay protection command according to the signature information.
[0099] As an implementation form, the signature module 622 can include a hash message authentication code generation unit, and the signature information includes a hash message authentication code. The hash message authentication code is also referred to as hash-based message authentication. It should be understood that the embodiments of the present application do not limit the signature algorithm, and other algorithms capable of verifying data authenticity are also feasible, and the embodiments of the present application do not limit this.
[0100] As an implementation form, the bus interface 621 can include an eSPI interface.
[0101] The embodiments of the present application also provide a system, which can include the EC chip and the one or more storage modules of the embodiments of the present application. The structure and combination of the EC chip and the storage module are described above, and will not be described here. The system implements replay protection through the signature module and the control module in the EC chip, and can implement replay protection in electronic devices such as notebook computers using the EC chip. Compared with the technical solution of externally connecting a Flash chip in an electronic device using the EC chip, the system can reduce the hardware cost, and the replay protection implemented through the control module and the signature module can quickly process the replay protection.
[0102] The electronic device can be, but is not limited to, a body weight scale, a body fat scale, a nutrition scale, an infrared electronic thermometer, a pulse oximeter, a human body composition analyzer, a mobile power supply, a wireless charger, a fast charger, a vehicle-mounted charger, an adapter, a display, a USB (Universal Serial Bus) docking station, a touch pen, a true wireless earphone, a car central control screen, a car, a smart wearable device, a mobile terminal, and a smart home device. The smart wearable device includes, but is not limited to, a smart watch, a smart bracelet, and a cervical vertebra massage instrument. The mobile terminal includes, but is not limited to, a smart phone, a notebook computer, a tablet computer, and a POS (point of sales terminal) machine. The smart home device includes, but is not limited to, a smart socket, a smart rice cooker, a smart sweeper, and a smart lamp. The electronic device can realize replay protection through a signature module and a control module in an EC chip, and replay protection can be realized by means of the EC chip in an electronic device such as a notebook computer using the EC chip. Compared with a technical solution in which a Flash chip is externally connected to an electronic device using the EC chip, the hardware cost can be reduced, and replay protection can be quickly processed by means of the control module and the signature module.
[0103] The exemplary replay protection command verification and execution process realized by the EC chip, the sealed chip, the system, and the electronic device provided by the embodiments of the present application will be described below by taking the implementation of eRPMC (RPMC over eSPI OOB) through an eSPI OOB channel as an example. In the eRPMC solution, the bus interface of the embodiments of the present application is an eSPI interface, the signature module can be an HMAC calculation module for implementing a HAMC algorithm, the signature key generated according to a root key can be an HMAC key (HMAC-key), and the control module is also referred to as an eRPMC control module.
[0104] The exemplary root key (Root key) binding process is shown in FIG. 7. The bus interface (eSPI interface) of the EC chip receives a data packet (eSPI OOB packet) from the PCH, and the received data packet is handed over to the control module (eRPMC control module). The control module parses the data packet, and if a root key binding command (Root key binding command) is parsed, the signature module (HMAC calculation module) is called for calculation, and then the calculation result is verified. If the verification is correct, the root key carried in the root key binding command is written into the storage module (NVM 1) for storing the root key, and a response corresponding to the root key binding command is returned to the PCH. If the verification is incorrect, the response is directly returned to the PCH.
[0105] An exemplary update signature key (HMAC-key) flow is shown in FIG. 8. An update signature key command (update HMAC-key command) is sent each time the PCH is powered on. The bus interface of the EC chip receives the data packet and hands it over to the control module for parsing. The control module parses the data packet and, if the update signature key command is parsed, calls the signature module to generate a signature key (HMAC-key) and signature information according to the root key and parsed information. If the signature verification result is correct, the control module writes the signature key into the memory module (Momery 1) for storing the signature key and replies to the PCH response. If the signature verification is incorrect, the PCH-related response is directly replied.
[0106] An exemplary read replay protection monotonic counter value flow is shown in FIG. 9. The bus interface of the EC chip receives the data packet and hands it over to the control module for parsing. The control module parses the data packet and, if the read replay protection monotonic counter value command (read Monotonic Counter command) is parsed, calls the signature module to calculate and verify the signature. Whether the signature verification passes or not, the command execution condition information is replied.
[0107] An exemplary replay protection monotonic counter value increase by 1 flow is shown in FIG. 10. The bus interface of the EC chip receives the data packet and hands it over to the control module for parsing. The control module parses the data packet and, if the replay protection monotonic counter value increase by 1 command (Monotonic Counter increase by 1 command) is parsed, calls the signature module to calculate and verify the calculation result. If the signature verification result is correct, the replay protection monotonic counter value is increased by 1 and written into the memory module (NVM 2) for storing the replay protection monotonic counter value, and the command is replied. If the signature verification result is incorrect, the command execution condition can be directly replied.
[0108] An exemplary read RPMC parameter flow is shown in FIG. 11. The read RPMC parameter command is a non-standard RPMC command and is dedicated to eRPMC. The control module receives the eSPI command, parses the command information, and replies to the command.
[0109] The above is only a preferred embodiment of the present application and does not limit the present application in any form. Although the present application has been disclosed with the preferred embodiment above, it is not intended to limit the present application. Any person skilled in the art can make slight changes or modifications to the above disclosed technical content to obtain equivalent embodiments with equivalent changes without departing from the technical solution of the present application. Any simple modification, equivalent change, and modification of the above embodiments according to the technical essence of the present application are still within the scope of the technical solution of the present application.
Claims
1. An EC chip, comprising: a bus interface configured to receive and send data packets; one or more storage modules configured to store at least part of replay protection related data; a signature module configured to generate signature information; a control module configured to parse the received data packets to obtain a replay protection command, and control the signature module and access the one or more storage modules to verify and execute the replay protection command.
2. The EC chip of claim 1, wherein, The one or more storage modules comprise: a first storage module configured to store a root key.
3. The EC chip of claim 1, wherein, The one or more storage modules comprise: a second storage module configured to store a signature key generated based on the root key.
4. The EC chip of claim 1, wherein, The one or more storage modules comprise: a third storage module configured to store a replay protection monotonic counter value.
5. The EC chip according to any one of claims 1 to 4, wherein Further comprising: one or more storage control modules configured to access one or more external storage modules; wherein the one or more storage modules are configured to store a first part of the replay protection related data, and the one or more external storage modules are configured to store a second part of the replay protection related data.
6. The EC chip of claim 5, wherein, The one or more storage control modules comprise: a first storage control module configured to access a first external storage module configured to store a root key.
7. The EC chip of claim 5, wherein, The one or more storage control modules comprise: a second storage control module configured to access a second external storage module configured to store a signature key generated based on the root key.
8. The EC chip of claim 5, wherein, The one or more storage control modules comprise: a third storage control module configured to access a third external storage module configured to store a replay protection monotonic counter value.
9. The EC chip of claim 1, wherein, Further comprising: a temporary storage module; wherein the control module is further configured to, in a case where predetermined data corresponding to the replay protection command in the replay protection related data is generated, store the predetermined data to the temporary storage module, and after a response corresponding to the replay protection command is generated, synchronize the predetermined data stored in the temporary storage module to a storage module or an external storage module corresponding thereto.
10. The EC chip of claim 1, wherein, Further comprising: a temporary storage module and a synchronization module; the control module is further configured to, in a case where predetermined data corresponding to the replay protection command in the replay protection related data is generated, store the predetermined data to the temporary storage module, and generate a response corresponding to the replay protection command; the synchronization module is configured to synchronize the predetermined data stored in the temporary storage module to a storage module or an external storage module corresponding thereto.
11. The EC chip of claim 1, wherein, The signature module comprises: a hash message authentication code generation unit, and the signature information comprises a hash message authentication code.
12. The EC chip of claim 1, wherein, The bus interface comprises an eSPI interface. 13.An EC chip, comprising: a bus interface configured to receive and send data packets; one or more storage control modules configured to access one or more external storage modules configured to store at least part of replay protection related data; a signature module configured to generate signature information; a control module configured to parse the received data packets to obtain a replay protection command, and control the signature module and the one or more storage control modules to verify and execute the replay protection command.
14. The EC chip of claim 13, wherein, The one or more storage control modules comprise: The first storage control module is configured to access a first external storage module for storing a root key.
15. The EC chip of claim 13, wherein, The one or more storage control modules include: The second storage control module is configured to access a second external storage module for storing a signature key generated based on the root key.
16. The EC chip of claim 13, wherein, The one or more storage control modules include: The third storage control module is configured to access a third external storage module for storing a replay protection monotonic counter value.
17. A sealing chip, comprising: one or more storage chips configured to store at least part of replay protection related data; an EC chip, the EC chip comprising: a bus interface configured to receive and send data packets; a signature module configured to generate signature information; a storage control module configured to access the one or more storage chips; a control module configured to parse a received data packet to obtain a replay protection command, control the signature module, and control the one or more storage control modules to verify and execute the replay protection command.
18. The hermetically sealed chip of claim 17, wherein, The one or more storage chips include: a first storage chip configured to store a root key.
19. The hermetically sealed chip of claim 17, wherein, The one or more storage chips include: a second storage chip configured to store a signature key generated based on the root key.
20. The hermetically sealed chip of claim 17, wherein, The one or more storage chips include: a third storage chip configured to store a replay protection monotonic counter value.
21. The hermetically sealed chip of any one of claims 17 to 20, wherein, The EC chip further comprises: one or more storage modules; wherein the one or more storage modules are configured to store a first part of the replay protection related data, and the one or more storage chips are configured to store a second part of the replay protection related data.
22. The hermetically sealed chip of claim 17, wherein, The signature module includes: a hash message authentication code generation unit, and the signature information includes a hash message authentication code.
23. The hermetically sealed chip of claim 17, wherein, The bus interface includes an eSPI interface.
24. A system, comprising: one or more storage modules configured to store at least part of replay protection related data; an EC chip, the EC chip comprising: a bus interface configured to receive and send data packets; a signature module configured to generate signature information; a storage control module configured to access the one or more storage modules; a control module configured to parse a received data packet to obtain a replay protection command, control the signature module, and control the one or more storage control modules to verify and execute the replay protection command.
25. The system of claim 24, wherein, The one or more storage modules include: a first storage module configured to store a root key.
26. The system of claim 24, wherein, The one or more storage modules include: a second storage module configured to store a signature key generated based on the root key.
27. The system of claim 24, wherein, The one or more storage modules include: a third storage module configured to store a replay protection monotonic counter value.
28. The system of any of claims 24-27, wherein, The one or more storage modules include one or more storage chips.
29. The system of any one of claims 24-27, wherein, The EC chip further comprises: one or more internal storage modules; wherein the one or more internal storage modules are configured to store a first part of the replay protection related data, and the one or more storage modules are configured to store a second part of the replay protection related data; the control module is further configured to control the one or more internal storage modules.
30. An electronic device comprising a device body and the EC chip as claimed in any one of claims 1 to 16, or the hermetic chip as claimed in any one of claims 17 to 23, or the system as claimed in any one of claims 24 to 29, disposed in the device body.
Citation Information
Patent Citations
Chip-level transparent file encryption storage system, method and equipment
CN116886356A
EC chip, sealing chip, system and electronic equipment
CN118368098A
EC chip, sealing chip, system and electronic equipment
CN118368099A
EC chip, sealing chip, system and electronic equipment
CN118368100A
EC chip, sealing chip, system and electronic equipment
CN118368101A