Protection method for heated tobacco product chip and hardware security module

By writing a user key into the chip of the heating appliance and encrypting it using a hardware security module, combined with the security authentication process of the chip control system, the problem of easy counterfeiting and imitation of heating appliance chips is solved, and data security and user information protection are achieved.

WO2026060989A1PCT designated stage Publication Date: 2026-03-26HUBEI CHINA TOBACCO INDUSTRY CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-05-27
Publication Date
2026-03-26

AI Technical Summary

Technical Problem

Existing heating smoke appliance chips are easily counterfeited and imitated, leading to safety risks and infringement of rights. In particular, the problem of preventing counterfeiting and imitation of chips in heating smoke appliances is difficult to solve.

Method used

By writing a user key into the chip of the heating smoke appliance and using a hardware security module to encrypt and decrypt the user key, combined with the security authentication process of the chip control system, data security is ensured and chip counterfeiting and imitation are prevented.

Benefits of technology

It effectively prevents chip counterfeiting and imitation, protects chip rights and user information security, and ensures the security of data encryption.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025097353_26032026_PF_FP_ABST
    Figure CN2025097353_26032026_PF_FP_ABST
Patent Text Reader

Abstract

Disclosed in the present application are a protection method for a heated tobacco product chip and a hardware security module. The method comprises the following steps: writing a user_key into a heated tobacco product chip; a hardware security module encrypting and decrypting the user_key by means of a root_key of the heated tobacco product chip, and storing the encrypted user_key in an eFlash; the hardware security module decrypting a Bootloader encrypted image on the basis of the decrypted user_key, and performing a security authentication operation; starting a chip control system that controls the heated tobacco product chip, so as to acquire an SDK encrypted image of the heated tobacco product chip; and, on the basis of the root_key and the encrypted user_key, the hardware security module decrypting the SDK encrypted image, and loading same into an SRAM. In the present method, encrypting data by means of the hardware security module ensures data security, so as to effectively avoid chip counterfeiting and forgery behaviors, protecting user information security while avoiding infringing the rights of chips.
Need to check novelty before this filing date? Find Prior Art

Description

A protection method and hardware security module for heating smoking set chip

[0001] This application claims priority to Chinese Patent Application No. CN202411300980.7, filed on September 18, 2024, the contents of which are incorporated herein in their entirety by reference. TECHNICAL FIELD

[0002] The present application relates to the field of chip security, in particular to a protection method and hardware security module for heating smoking set chip. BACKGROUND

[0003] With the development of technology, chips are widely used in various fields such as electronic payment and identity authentication. However, due to the low cost of chip manufacturing, a large number of counterfeit and fake behaviors have also occurred, which not only infringes the rights of the chip itself, but also brings great security risks to users.

[0004] Heating appliances are one of the core components of new tobacco, and chips are also provided in heating appliances. Therefore, preventing the chips in heating appliances from being counterfeited is also a big problem for tobacco industry supervision.

[0005] Therefore, it is an urgent technical problem for those skilled in the art to provide a protection method and hardware security module for effectively preventing the counterfeiting and faking of chips. SUMMARY

[0006] To solve the above technical problems, the purpose of the present application is to provide a protection method and hardware security module for heating smoking set chip, which encrypts data through a hardware security module to ensure data security, thereby effectively preventing counterfeiting and faking of chips, avoiding infringement of the rights of the chip itself, and protecting the information security of users.

[0007] The first purpose of the present application is to provide a protection method for heating smoking set chip.

[0008] The technical solutions provided by the present application are as follows:

[0009] A protection method for heating smoking set chip, comprising the following steps:

[0010] Writing a user key user_key into a heating smoking set chip;

[0011] Encrypting and decrypting the user key user_key through a root key root_key of the hardware security module, and storing the encrypted user key user_key in an eFlash flash memory;

[0012] The hardware security module decrypts the Bootloader encrypted image according to the decrypted user key user_key and performs a security authentication operation;

[0013] The chip control system for controlling the heating smoking set chip is started to obtain the SDK encrypted image of the heating smoking set chip.

[0014] The hardware security module decrypts the SDK encrypted image according to the root key root_key and the encrypted user key user_key and loads it into the SRAM static memory.

[0015] Preferably, before the hardware security module reads the root key root_key of the heating smoking set chip to encrypt and decrypt the user key user_key and stores the encrypted user key user_key in the eFlash flash memory, the method further comprises:

[0016] The chip control system for controlling the heating smoking set chip is started to obtain the Bootloader encrypted image of the heating smoking set chip.

[0017] Preferably, the chip control system for controlling the heating smoking set chip is started to obtain the Bootloader encrypted image of the heating smoking set chip, and specifically comprises:

[0018] The chip control system for controlling the heating smoking set chip is started to determine whether the security startup mode of the heating smoking set chip is software upgrading.

[0019] If yes, the Bootloader encrypted image is loaded using the UART data serial port.

[0020] If no, the Bootloader encrypted image is directly read in the eFlash flash memory.

[0021] Preferably, the hardware security module reads the root key root_key of the heating smoking set chip to encrypt and decrypt the user key user_key and stores the encrypted user key user_key in the eFlash flash memory, and specifically comprises:

[0022] The hardware security module reads the root key root_key of the heating smoking set chip to encrypt the user key user_key in the initialization stage and stores the encrypted user key user_key in the eFlash flash memory.

[0023] The hardware security module reads the root key root_key of the heating smoking set chip in the initialization stage to decrypt the user key user_key and performs a security authentication operation.

[0024] Preferably, the hardware security module reads the root key root_key of the heating smoking set chip in the initialization stage to decrypt the user key user_key and performs a security authentication operation, specifically including:

[0025] If the authentication fails, the heating smoking set chip executes an abnormal processing mechanism.

[0026] If the authentication passes, the hardware security module decrypts the Bootloader encrypted image according to the decrypted user key user_key and performs a security authentication operation.

[0027] Preferably, the chip control system of the heating smoking set chip is started to obtain the SDK encrypted image of the heating smoking set chip, specifically including:

[0028] The chip control system of the heating smoking set chip is started to determine whether the security start mode of the heating smoking set chip is software upgrade:

[0029] If yes, the SDK encrypted image to be upgraded is loaded through a UART data serial port;

[0030] If not, the SDK encrypted image is directly read in the eFlash flash memory.

[0031] Preferably, the hardware security module decrypts the Bootloader encrypted image according to the decrypted user key user_key and performs a security authentication operation, specifically including:

[0032] If the authentication fails, the heating smoking set chip executes the abnormal processing mechanism.

[0033] If the authentication passes, the decrypted Bootloader encrypted image is loaded into the ILM and run.

[0034] Preferably, the hardware security module decrypts the SDK encrypted image according to the root key root_key and the encrypted user key user_key and loads it into the SRAM static memory, specifically including:

[0035] The hardware security module decrypts the SDK encrypted image according to the root key root_key and the encrypted user key user_key and performs a security authentication operation:

[0036] If the authentication fails, the heating smoking set chip executes the abnormal processing mechanism;

[0037] If the authentication passes, the decrypted SDK encrypted image is loaded into the SRAM static memory and is run.

[0038] Preferably, the abnormal processing mechanism, in particular:

[0039] The hardware security module checks the control GPIO lighting function and fixes a GPIO interface output, and if the security startup check authentication fails, the GPIO is controlled to flash.

[0040] The second object of the application is to provide a hardware security module;

[0041] The technical solutions provided by the application are as follows:

[0042] A hardware security module based on a protection method of a heating smoking set chip, comprising a key management module, an encryption and decryption storage module, a BOOTROM module, an eFlash hardware address isolation module, an SM4-GCM module and a hardware security module controller.

[0043] The key management module is used for managing the initialization and read-write permissions of all keys.

[0044] The encryption and decryption storage module is used for encrypting and decrypting a user key user_key and storing a root key root_key.

[0045] The BOOTROM module is used for starting to control a chip control system of the heating smoking set chip to obtain a Bootloader encrypted image of the heating smoking set chip.

[0046] The eFlash hardware address isolation module is used for storing the encrypted user key user_key and is also used for isolating the software and hardware read-write permissions of a preset address in an eFlash flash memory.

[0047] The SM4-GCM module is used for decrypting the Bootloader encrypted image according to the decrypted user key user_key and performing a security authentication operation.

[0048] The hardware security module controller is used for decrypting an SDK encrypted image according to the root key root_key and the encrypted user key user_key and loading the SDK encrypted image into an SRAM static memory; and is also used for managing the overall operation of the hardware security module.

[0049] The application provides a protection method of a heating smoking set chip, which comprises the following steps: writing a user key user_key into the heating smoking set chip; a hardware security module encrypts and decrypts the user key user_key through a root key root_key of the heating smoking set chip, and stores the encrypted user key user_key in an eFlash flash memory; the hardware security module decrypts a Bootloader encrypted image according to the decrypted user key user_key, and performs a security authentication operation; a chip control system for controlling the heating smoking set chip is started to obtain an SDK encrypted image of the heating smoking set chip; the hardware security module decrypts the SDK encrypted image according to the root key root_key and the encrypted user key user_key, and loads the SDK encrypted image into an SRAM static memory; the method encrypts data through the hardware security module, guarantees the safety of the data, effectively prevents the chip from being counterfeited and imitated, avoids the rights and interests of the chip from being infringed, and protects the information safety of the user. BRIEF DESCRIPTION OF DRAWINGS

[0050] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings needed to be used in the embodiments or the prior art description. Obviously, the drawings in the following description are only some embodiments described in the present application, and for those skilled in the art, other drawings can also be obtained without creative labor on the basis of these drawings.

[0051] Fig. 1 is a flow chart of a protection method of a heating smoking set chip in an embodiment of the present application;

[0052] Fig. 2 is a structural schematic diagram of a hardware security module in an embodiment of the present application;

[0053] Fig. 3 is a structural schematic diagram of an electronic device in an embodiment of the present application. DETAILED DESCRIPTION

[0054] In order to make the skilled in the art better understand the technical solutions in the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below. Obviously, the described embodiments are only some of the embodiments of the present application, but not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor fall within the scope of protection of the present application.

[0055] It should be noted that when an element is referred to as being "fixed" or "set up" on another element, it can be directly on the other element or indirectly set on the other element; when an element is referred to as being "connected to" another element, it can be directly connected to the other element or indirectly connected to the other element.

[0056] It should be understood that the terms "length", "width", "upper", "lower", "front", "back", "left", "right", "vertical", "horizontal", "top", "bottom", "inner", "outer", and the like indicate the orientation or positional relationship shown in the drawings based on the orientation or positional relationship shown in the drawings, and are only for the convenience of describing the present application and simplifying the description, and therefore cannot be understood as indicating or implying that the devices or elements referred to must have a particular orientation, be constructed and operated in a particular orientation, and therefore cannot be understood as limiting the present application.

[0057] In addition, the terms "first", "second", "third", etc. are only used for descriptive purposes and cannot be understood as indicating or implying relative importance or implicitly indicating the number of technical features indicated. Therefore, the features defined with "first", "second" can explicitly or implicitly include one or more of the features. In the description of the present application, the meaning of "a plurality of" or "several" is two or more, unless otherwise explicitly specified.

[0058] It should be understood that the structure, proportion, size, etc. shown in the drawings of the present application are only used to cooperate with the content disclosed in the description, so that those skilled in the art can understand and read, and are not used to limit the implementation conditions of the present application, so they do not have technical significance. Any modification of structure, change of proportion relationship or adjustment of size, without affecting the effect and purpose that can be achieved by the present application, should still fall within the scope of the technical content disclosed by the present application.

[0059] As shown in FIG. 1, the present application provides a protection method for a heating smoking set chip, comprising the following steps:

[0060] S1. Write a user key user_key in the heating smoking set chip;

[0061] In step S1, during the initialization stage of the heating smoking set chip, write the user key user_key, the product serial number and the encrypted software related to the control of the heating smoking set.

[0062] S2. The hardware security module encrypts and decrypts the user key user_key through the root key root_key of the heating smoking set chip, and stores the encrypted user key user_key in the eFlash flash memory;

[0063] In step S2, the root key root_key of the heating appliance chip is securely stored in the encrypted storage area of the chip, and only the hardware security module can access it; therefore, the hardware security module reads the root key root_key of the heating appliance chip to encrypt and decrypt the user key user_key written in step S1, and then stores the encrypted user key user_key in the eFlash flash memory.

[0064] S3. The hardware security module decrypts the Bootloader encrypted image according to the decrypted user key user_key and performs a security authentication operation;

[0065] In step S3, the hardware security module decrypts the Bootloader encrypted image according to the decrypted user key user_key obtained in step S2, and performs a security authentication on the user key data to determine whether it is legitimate. The Bootloader encrypted image in this embodiment is the booting process of hardware startup, such as the first startup of the hardware system of the heating appliance, which has a booting process similar to the startup interface of a mobile phone. It can be understood as a process of reading software data, because the eFlash flash memory is fast and can be accurate to 0.1s.

[0066] S4. The chip control system for controlling the heating appliance chip is started to obtain the SDK encrypted image of the heating appliance chip.

[0067] In step S4, the chip control system for controlling the heating appliance chip is started to obtain the SDK encrypted image of the heating appliance chip. The chip control system in this embodiment includes software and hardware, and the SDK encrypted image stored in the chip can be obtained by starting the chip control system.

[0068] S5. The hardware security module decrypts the SDK encrypted image according to the root key root_key and the encrypted user key user_key and loads it into the SRAM static memory.

[0069] In step S5, the hardware security module decrypts the SDK encrypted image according to the root key root_key and the encrypted user key user_key in the encrypted storage area and loads it into the SRAM static memory. The main function of the SRAM static memory in this embodiment is different from the flash eFlash memory, and the data can remain constant when powered on, so it is faster and has lower power consumption. Unlike dynamic memory, only when powered on will there be data, and there will be no data record when powered off.

[0070] Compared with the prior art, the method encrypts data by a hardware security module, guarantees the security of data, effectively prevents the counterfeiting and counterfeiting behaviors of the chip, avoids the infringement of the rights and interests of the chip itself, and protects the information security of the user.

[0071] Preferably, the hardware security module encrypts and decrypts the user key user_key by reading a root key root_key of the heating smoking set chip, and stores the encrypted user key user_key in an eFlash flash memory, and the method further comprises the following steps of:

[0072] starting a chip control system for controlling the heating smoking set chip to obtain the Bootloader encrypted image of the heating smoking set chip.

[0073] In actual application, the chip control system for controlling the heating smoking set chip is started to obtain the Bootloader encrypted image of the heating smoking set chip; the chip control system in the embodiment includes two parts of software and hardware, and the Bootloader encrypted image stored in the chip can be obtained by starting the chip control system.

[0074] Preferably, the chip control system for controlling the heating smoking set chip is started to obtain the Bootloader encrypted image of the heating smoking set chip, and specifically comprises the following steps of:

[0075] The chip control system for controlling the heating smoking set chip is started to determine whether the security start mode of the heating smoking set chip is software upgrading.

[0076] If yes, the Bootloader encrypted image is loaded by using a UART data serial port.

[0077] If no, the Bootloader encrypted image is directly read in the eFlash flash memory.

[0078] In actual application process, the heating smoking set chip supports common starting mode and safe starting mode, and the safe starting mode is suitable for a scene requiring safe starting and software encryption. After power-on, a program in the BOOTROM write protection flash memory is first run, then the chip control system for controlling the heating smoking set chip judges whether to directly read the Bootloader encrypted image from the eFlash flash memory or load the Bootloader encrypted image through the UART data serial port, and then performs hardware security decryption and verification. After verification, the decrypted user program is run. Therefore, the chip control system for controlling the heating smoking set chip is used to judge whether the safe starting mode of the heating smoking set chip is software upgrading. If yes, the Bootloader encrypted image is loaded through the UART data serial port. If no, the Bootloader encrypted image is directly read from the eFlash flash memory.

[0079] Preferably, the hardware security module reads and decrypts the user key user_key by using the root key root_key of the heating smoking set chip, and stores the encrypted user key user_key in the eFlash flash memory, specifically including:

[0080] The hardware security module reads and encrypts the user key user_key by using the root key root_key of the heating smoking set chip in the initialization stage, and stores the encrypted user key user_key in the eFlash flash memory.

[0081] The hardware security module reads and decrypts the user key user_key by using the root key root_key of the heating smoking set chip in the initialization stage, and performs security authentication operation.

[0082] In actual application process, since the heating smoking set chip is provided with a life cycle, the hardware security module reads the root key root_key of the heating smoking set chip in the initialization stage of the heating smoking set chip, and is used to encrypt the user key user_key, and then stores the encrypted user key user_key in the eFlash flash memory. Then, the user key user_key is decrypted by using the root key root_key of the heating smoking set chip, and the user key data is subjected to security authentication to judge whether it is legal.

[0083] Preferably, the hardware security module reads and decrypts the user key user_key by using the root key root_key of the heating smoking set chip in the initialization stage, and performs security authentication operation, specifically including:

[0084] If the authentication fails, the heating smoking set chip executes an abnormal processing mechanism.

[0085] If the authentication passes, the hardware security module decrypts the Bootloader encrypted image according to the decrypted user key user_key and performs a security authentication operation.

[0086] In actual application, the security authentication operation means that if the authentication does not pass, the heating smoking tool chip executes an abnormal processing mechanism; if the authentication passes, step S3 is executed; the abnormal processing mechanism adopted in this embodiment is that the hardware security module checks the control GPIO lighting function and fixes a GPIO interface output, and if the security startup check authentication does not pass, the GPIO flashes.

[0087] Preferably, the chip control system for controlling the heating smoking tool chip is started to obtain the SDK encrypted image of the heating smoking tool chip, and specifically includes:

[0088] The chip control system for controlling the heating smoking tool chip is started to determine whether the security startup mode of the heating smoking tool chip is software upgrading.

[0089] If yes, the SDK encrypted image to be upgraded is loaded using a UART data serial port;

[0090] If no, the SDK encrypted image is directly read in the eFlash flash memory.

[0091] In actual application, the chip control system for controlling the heating smoking tool chip is started to determine whether the security startup mode of the heating smoking tool chip is software upgrading: if yes, the SDK encrypted image to be upgraded is loaded using a UART data serial port; if no, the SDK encrypted image is directly read in the eFlash flash memory; such determination mainly provides an interface mode for subsequent software upgrading.

[0092] Preferably, the hardware security module decrypts the Bootloader encrypted image according to the decrypted user key user_key and performs a security authentication operation, and specifically includes:

[0093] If the authentication does not pass, the heating smoking tool chip executes the abnormal processing mechanism;

[0094] If the authentication passes, the decrypted Bootloader encrypted image is loaded into the ILM and runs.

[0095] In actual application process, the security authentication operation is that if the authentication fails, the heating smoking set chip executes the abnormal processing mechanism; if the authentication passes, the decrypted Bootloader encrypted image is loaded into the ILM and is run; the abnormal processing mechanism used in the embodiment is specifically that the hardware security module checks and controls the GPIO light function and fixes a GPIO interface output, if the security startup check authentication fails, the GPIO is controlled to flash; the ILM in the embodiment is a local memory, which is a local memory with 32 KB storage space, and the code can be run on it; because the current bootloader code is about 10 KB, it is placed on the ILM local memory to run.

[0096] Preferably, the hardware security module decrypts the SDK encrypted image according to the root key root_key and the encrypted user key user_key and loads it into the SRAM static memory, specifically including:

[0097] The hardware security module decrypts the SDK encrypted image according to the root key root_key and the encrypted user key user_key and performs a security authentication operation:

[0098] If the authentication fails, the heating smoking set chip executes the abnormal processing mechanism;

[0099] If the authentication passes, the decrypted SDK encrypted image is loaded into the SRAM static memory and is run.

[0100] In actual application process, the security authentication operation is that if the authentication fails, the heating smoking set chip executes the abnormal processing mechanism; if the authentication passes, the decrypted SDK encrypted image is loaded into the SRAM static memory and is run; the abnormal processing mechanism used in the embodiment is specifically that the hardware security module checks and controls the GPIO light function and fixes a GPIO interface output, if the security startup check authentication fails, the GPIO is controlled to flash.

[0101] As shown in FIG. 2, the application further provides a hardware security module based on a protection method of a heating smoking set chip, including a key management module, an encryption and decryption storage module, a BOOTROM module, an eFlash hardware address isolation module, an SM4-GCM module and a hardware security module controller;

[0102] The key management module is used for managing initialization and read-write permissions of all keys;

[0103] The encryption and decryption storage module is used for encrypting and decrypting a user key user_key and storing a root key root_key;

[0104] The BOOTROM module is configured to start a chip control system for controlling a heating smoking tool chip to obtain a Bootloader encrypted image of the heating smoking tool chip.

[0105] The eFlash hardware address isolation module is configured to store the encrypted user key user_key, and isolate the read-write permission of a preset address in the eFlash flash memory.

[0106] The SM4-GCM module is configured to perform decryption and security authentication operation on the Bootloader encrypted image according to the decrypted user key user_key.

[0107] The hardware security module controller is configured to perform decryption on an SDK encrypted image according to the root key root_key and the encrypted user key user_key, and load the SDK encrypted image into an SRAM static memory, and manage the overall operation of the hardware security module.

[0108] In actual application, a hardware security module is provided, which is applied to a protection method of a heating smoking tool chip, and includes a key management module, an encryption and decryption storage module, a BOOTROM module, an eFlash hardware address isolation module, an SM4-GCM module and a hardware security module controller. The key management module is connected with the encryption and decryption storage module and the hardware security module controller. The SM4-GCM module and the hardware security module controller are connected. The hardware security module controller is connected with the BOOTROM module and the eFlash hardware address isolation module through a bus. The SM4-GCM module is a hardware accelerator containing a lightweight SM4-GCM algorithm, and is configured to realize encryption storage and security authentication of the user key user_key and software. The data is encrypted through the hardware security module, so that the security of the data is ensured, thereby effectively preventing the chip from being counterfeited and imitated, avoiding the rights and interests of the chip from being infringed, and protecting the information security of the user.

[0109] Further, the application further discloses an electronic device, and FIG. 3 is a structure diagram of the electronic device 20 according to an example embodiment. The content in the figure cannot be considered as any limitation on the use range of the application.

[0110] FIG. 3 is a structural schematic diagram of an electronic device 20 provided in an embodiment of the present application. The electronic device 20 can specifically include at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25, and a communication bus 26. The memory 22 is configured to store a computer program, and the processor 21 is configured to load and execute the computer program to implement the related steps in the protection method of the heating smoking set chip disclosed in any of the foregoing embodiments. In addition, the electronic device 20 in the embodiment can be specifically an electronic computer.

[0111] In the embodiment, the power supply 23 is configured to provide working voltage for each hardware device on the electronic device 20; the communication interface 24 is capable of creating a data transmission channel between the electronic device 20 and external devices, and a communication protocol followed by the communication interface 24 can be any communication protocol applicable to the technical solution of the present application, which is not specifically limited herein; the input / output interface 25 is configured to acquire external input data or output data to the outside, and a specific interface type thereof can be selected according to specific application requirements, which is not specifically limited herein.

[0112] In addition, the memory 22 as a carrier for resource storage can be a read-only memory, a random access memory, a magnetic disk, or an optical disk, and the resources stored thereon can include an operating system 221, a computer program 222, and data 223, etc., and a storage mode can be temporary storage or permanent storage.

[0113] The operating system 221 is configured to manage and control each hardware device on the electronic device 20 and the computer program 222, so as to implement the operation and processing of the processor 21 on the data 223 in the memory 22, and the operating system 221 can be Windows Server, Netware, Unix, Linux, etc. The computer program 222 can further include a computer program capable of completing other specific work in addition to the computer program capable of completing the protection method of the heating smoking set chip executed by the electronic device 20 disclosed in any of the foregoing embodiments. The data 223 can include data transmitted from an external device by a protection device of a heating smoking set chip in addition to data collected by the input / output interface 25 of the electronic device 20 itself.

[0114] The steps of the methods or algorithms described in conjunction with the embodiments disclosed herein can be implemented directly by hardware, a software module executed by a processor, or a combination thereof. The software module can be placed in a random access memory (RAM), a memory, a read-only memory (ROM), an electrically programmable ROM, an electrically erasable programmable ROM, a register, a hard disk, a removable disk, a CD-ROM, or any other form of storage medium known in the technical field.

[0115] Further, the application also discloses a computer readable storage medium for storing a computer program, wherein the computer program is executed by a processor to realize the protection method of the heating smoking set chip.

[0116] The various embodiments are described in a progressive manner in the specification, each of which focuses on the differences from other embodiments, and the same or similar parts between the various embodiments can be referred to each other. For the device disclosed in the embodiments, since it corresponds to the method disclosed in the embodiments, the description is relatively simple, and the relevant parts can be referred to the method part.

[0117] The skilled person can further realize that the units and algorithm steps of the examples described in combination with the embodiments disclosed herein can be realized by electronic hardware, computer software or a combination of both. In order to clearly illustrate the interchangeability of hardware and software, the components and steps of the examples have been described in a general manner in the above description. Whether the functions are realized in hardware or software depends on the specific application and design constraints of the technical solution. The skilled person can use different methods to realize the described functions for each specific application, but such implementation should not be considered beyond the scope of the application.

[0118] Finally, it should be noted that in this document, relationship terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between the entities or operations. Moreover, the terms "include", "contain" or any other variants thereof are intended to cover non-exclusive inclusion, so that the process, method, article or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed or inherent to such process, method, article or device. Without more limitations, the element defined by the statement "including a" does not exclude the presence of other identical elements in the process, method, article or device including the element.

[0119] If a flowchart is used in the application, the flowchart is used to illustrate the operations performed by the system according to the embodiments of the application. It should be understood that the preceding or subsequent operations are not necessarily performed in sequence. On the contrary, each step can be processed in reverse order or simultaneously. At the same time, other operations can be added to these processes, or one or more steps can be removed from these processes.

[0120] The foregoing description of the disclosed embodiments enables a person skilled in the art to make or use the application. Modifications of these embodiments will occur to persons of skill in the art, and that the appended claims are intended to cover all such modifications that do not depart from the true spirit and scope of the application. Therefore, the application is not limited to the embodiments shown but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A method of protecting a heating vaporizer chip, the method comprising: The method comprises the following steps: writing a user key user_key into a heating smoking set chip; encrypting and decrypting the user key user_key by a root key root_key of the hardware security module of the heating smoking set chip, and storing the encrypted user key user_key in an eFlash flash memory; decrypting a Bootloader encrypted image according to the decrypted user key user_key, and performing a security authentication operation by the hardware security module; starting a chip control system for controlling the heating smoking set chip to obtain an SDK encrypted image of the heating smoking set chip; decrypting the SDK encrypted image according to the root key root_key and the encrypted user key user_key, and loading the SDK encrypted image into an SRAM static memory by the hardware security module.

2. The method of claim 1, wherein, Before the hardware security module reads the root key root_key of the heating smoking set chip to encrypt and decrypt the user key user_key, and stores the encrypted user key user_key in the eFlash flash memory, the method further comprises the following steps: starting the chip control system for controlling the heating smoking set chip to obtain the Bootloader encrypted image of the heating smoking set chip.

3. The method of claim 2, wherein, The starting of the chip control system for controlling the heating smoking set chip to obtain the Bootloader encrypted image of the heating smoking set chip specifically comprises the following steps: starting the chip control system for controlling the heating smoking set chip to determine whether a security start mode of the heating smoking set chip is software upgrading: if yes, loading the Bootloader encrypted image by using a UART data serial port; if no, directly reading the Bootloader encrypted image in the eFlash flash memory.

4. The method of claim 1, wherein, The hardware security module reads the root key root_key of the heating smoking set chip to encrypt and decrypt the user key user_key, and stores the encrypted user key user_key in the eFlash flash memory, specifically comprising the following steps: the hardware security module reads the root key root_key of the heating smoking set chip to encrypt the user key user_key in an initialization stage, and stores the encrypted user key user_key in the eFlash flash memory; the hardware security module reads the root key root_key of the heating smoking set chip to decrypt the user key user_key in the initialization stage, and performs a security authentication operation.

5. The method of claim 1, wherein, The hardware security module reads the root key root_key of the heating smoking set chip to decrypt the user key user_key in the initialization stage, and performs a security authentication operation, specifically comprising the following steps: if the authentication fails, the heating smoking set chip executes an abnormal processing mechanism; if the authentication passes, the hardware security module decrypts the Bootloader encrypted image according to the decrypted user key user_key, and performs a security authentication operation.

6. The method of claim 1, wherein, The chip control system of the heating smoking set is started to obtain the SDK encrypted image of the heating smoking set chip, and specifically includes the following steps: The chip control system of the heating smoking set is started to determine whether the safe starting mode of the heating smoking set chip is software upgrading: If yes, the SDK encrypted image to be upgraded is loaded through the UART data serial port; If no, the SDK encrypted image is directly read from the eFlash flash memory.

7. The method of claim 5, wherein the heating of the smoking article chip is performed by a heating element. The hardware security module decrypts the Bootloader encrypted image according to the decrypted user key user_key and performs a security authentication operation, and specifically includes the following steps: If the authentication fails, the heating smoking set chip executes the abnormal processing mechanism; If the authentication passes, the decrypted Bootloader encrypted image is loaded into the ILM and run.

8. The method of claim 7, wherein, The hardware security module decrypts the SDK encrypted image according to the root key root_key and the encrypted user key user_key and loads it into the SRAM static memory, and specifically includes the following steps: The hardware security module decrypts the SDK encrypted image according to the root key root_key and the encrypted user key user_key and performs a security authentication operation: If the authentication fails, the heating smoking set chip executes the abnormal processing mechanism; If the authentication passes, the decrypted SDK encrypted image is loaded into the SRAM static memory and run.

9. The method of claim 8, wherein, The abnormal processing mechanism specifically includes the following steps: The hardware security module checks the control GPIO lighting function and fixes a GPIO interface output. If the security starting check authentication fails, the GPIO flash is controlled.

10. A hardware security module based on the protection method of a heating appliance chip according to claims 1 to 9, characterized in that, It includes: Key management module, encryption and decryption storage module, BOOTROM module, eFlash hardware address isolation module, SM4-GCM module and hardware security module controller; The key management module is used to manage the initialization and read-write permission of all keys; The encryption and decryption storage module is used to encrypt and decrypt the user key user_key and store the root key root_key; The BOOTROM module is used to start the chip control system of the heating smoking set to obtain the Bootloader encrypted image of the heating smoking set chip; The eFlash hardware address isolation module is used to store the encrypted user key user_key and isolate the software and hardware read-write permission of the preset address in the eFlash flash memory; The SM4-GCM module is used for the hardware security module to decrypt the Bootloader encrypted image according to the decrypted user key user_key and perform a security authentication operation; The hardware security module controller is used to decrypt the SDK encrypted image according to the root key root_key and the encrypted user key user_key and load it into the SRAM static memory; and is also used to manage the overall operation of the hardware security module.

Citation Information

Patent Citations

  • Method for defending fault injection during safe starting of Soc state secret security chip

    CN111814208A

  • Electronic atomizer communication device, electronic atomizer and application method

    CN115686580A

  • Chip security starting method and chip

    CN116775150A

  • Protection method for heating smoking set chip and hardware security module

    CN119167398A

  • A system and method for managing a smoking substitute device

    EP3750420A1