节点文献

基于RISC-V架构的可信芯片软核设计

Trusted Chip Soft Core Design Based on RISC-V Architecture

【作者】 张旭;

【导师】 韩跃平; 唐道光;

【作者基本信息】 中北大学 , 电子信息硕士(专业学位), 2023, 硕士

【摘要】 针对我国工控领域的信息安全需求,面对逻辑缺陷的攻击传统安全机制很难进行有效应对,安全防护手段在终端上缺乏主动控制。为防御外部威胁,可信计算3.0提出主动防御理念,可信芯片作为主动免疫防御体系的可信计算节点,是实现可信防护功能的关键部件,能依靠可信密码模块中的国密算法,对外部设备提供完整性度量、信息加解密等功能。为实现可信芯片的可信主动逻辑控制功能,采用微处理器作为运算控制单元,在现有处理器架构中,RISC-V架构生态配套丰富且开源,拥有模块化的指令集,用户可以根据需求选择不同的模块相组合。因此,利用FPGA开发一款基于RISC-V架构处理器的可信芯片具有重要价值和意义。自主设计32位RISC-V软核处理器作为可信芯片的可信控制单元,支持RV32I指令集,采用六级流水线的方式,解决流水线冒险问题。在可信密码模块中以硬件方式实现了SM-3、SM-4国密算法和真随机数发生器,提高了其加解密的安全性和运算速度,以软件的形式实现了SM-2非对称密码算法。对可信芯片板卡进行测试验证,处理器内核部分进行了功能仿真,结果表明各级流水线功能正常。在时钟为50MHz频率下,运行Coremark/MHz测试程序,性能优于同类设计。通过EDA工具将处理器软核烧录到Xilinx XC7A200T的FPGA上进行原型验证,通过PCIe接口将可信芯片板卡连接至国产飞腾D2000主板,在麒麟Linux的桌面操作系统环境下,编译并加载驱动文件,编写并编译Demo程序,对其中的SM-3、SM-4及SM-2加解密功能进行验证,实现了其对数据的加解密操作。综合结果表明,该可信芯片板卡能完成对宿主机的通信连接以及数据的加解密,可实现对宿主机的完整性度量。

【Abstract】 In response to the information security needs of China’s industrial control field,traditional security mechanisms are difficult to effectively respond to logical flaws attacks,and security protection measures lack proactive control on the terminal.To defend against external threats,the concept of active defense is proposed in Trusted Computing 3.0,and a trusted chip,as the trusted computing node of the active immune defense system,is a key component to achieve trusted protection functions.It can rely on national cryptographic algorithms in the trusted cryptographic module to provide functions such as integrity measurement and information encryption and decryption for external devices.In order to realize the trusted active logic control function of the trusted chip,a microprocessor is used as the computing control unit.Within the existing processor architecture,the RISC-V architecture has a rich and open-source ecosystem with modular instruction sets,allowing users to choose different modules according to their needs.Therefore,developing a trusted chip based on the RISC-V architecture processor using FPGA has significant value and meaning.A self-designed 32-bit RISC-V soft core processor is used as the trusted control unit of the trusted chip,supporting the RV32 I instruction set and using a six-stage pipeline to solve pipeline hazards.Using AXI as the bus system and IP cores to implement UART,SPI,GPIO,and other peripherals,SM-3,SM-4 national cryptographic algorithms,and a true random number generator are implemented in the trusted cryptographic module in hardware,improving the security and computing speed of encryption and decryption,while SM-2 asymmetric cryptographic algorithm is implemented in software.The trusted chip board is tested and validated,and the processor core is functionally simulated,showing normal operation at each pipeline stage.Running the Coremark/MHz test program at a clock frequency of 50 MHz,its performance is better than that of similar designs.The processor soft core is burned into Xilinx XC7A200 T FPGA through EDA tools for prototype verification.The trusted chip board is connected to the domestic Feiteng D2000 motherboard through PCIe interface,and the driver file is compiled and loaded in the desktop operating system environment of Kylin Linux.A demo program is compiled and written to verify the functions of SM-3,SM-4,and SM-2 encryption and decryption,achieving encryption and decryption operations on data.The overall results show that the trusted chip board can establish communication connection with the host and perform encryption and decryption of data,achieving integrity measurement of the host.

  • 【网络出版投稿人】 中北大学
  • 【网络出版年期】2024年 01期
  • 【分类号】TP309
节点文献中: 

本文链接的文献网络图示:

本文的引文网络