Background technology
Along with intellective IC card is increasingly extensive in the use of financial field, hacker is also more and more to enrich to the attack means of financial IC card.It is exactly a kind of effective attack means that mistake is injected analysis.Assailant can utilize the attack patterns such as voltage, temperature, frequency, optical, electrical source burr to attack financial IC card, IC-card is operated under abnomal condition, thereby makes CPU produce wrong result.Then assailant analyzes wrong result again, thereby obtains data message or key in IC-card.
For fear of the invasion and attack of wrong injection attacks means, intellective IC card is generally provided with safety protection module, monitors the safety detector of these attacks.Safety detector comprises voltage-level detector, Temperature Detector, frequency detector, photodetector and power supply burr detecting device etc.When the working environment of IC-card occurs that when abnormal, corresponding detecting device will send alerting signal.These alerting signals can be interrupted or resetting system.As: working temperature exceeds the scope of regulation, and Temperature Detector will produce alerting signal.System, after obtaining alerting signal, will produce and interrupt or resetting system, so just guarantees the information security of IC-card.
Since detecting device is carried out the function of safety monitoring in IC-card, can detecting device self normally work so, whether function intact, just seems particularly important.In order to ensure safety detector circuit after experience is manufactured, can normally work according to expected design, confirm that safety detector is not by assault before intellective IC card work, these safety detectors need to add self-testing circuit.
And detector module as shown in Figure 1, is divided into following components: sensor circuit 101, decision circuit 102, logical circuit 103 at present.Sensor circuit 101 is mainly the variation of induction chip working environment, and is translated into electric signal, voltage or electric current.As voltage sensor will be experienced the operating voltage of chip, the variation that temperature sensor can induction chip environment temperature, and be voltage by temperature inversion, offer decision circuit below.Decision circuit 102 major functions are that the signal of sensor is processed, and judge whether this signal is signal to attack, and output logic level.Logical circuit 103 is results of processing decision circuit, and some circuit may need the result of decision circuit further to process, and then result is offered to digital circuit.For example, power supply burr testing circuit may design a signal latch module at output terminal.If jagged attack, signal latch module will lock alerting signal, until remove.The output 104 of detecting device can be connected to register, and testing result is deposited to register, for system, processes.
In order to ensure detecting device circuit after experience is manufactured, can normally work, and before chip operation, confirm that these detecting devices are not by assault, they need to add self-testing circuit.Now, a lot of IC-cards have been provided with the circuit that oneself detects in detector module, but these self test modes are very loaded down with trivial details, need to be on the original circuit topology of detecting device basis, increase complicated self-testing circuit, will expand chip area like this, increase the design cost of IC-card.In addition, complicated self-checking circuit also can increase the power consumption of IC-card, does not meet the design concept of low-power consumption.Because increase the self-detection of detecting device, the whole exchange hour of IC-card can extend to some extent.
Summary of the invention
Technical matters to be solved by this invention is to provide a kind of method and device that safety detector oneself detects of realizing, to simplify safety detector oneself testing process.
In order to solve the problems of the technologies described above, the invention discloses a kind of self-checking unit of safety detector, comprising:
Simulated strike signal output module, when safety detector is positioned at Auto-Sensing Mode, inputs the simulated strike signal of variation to the decision circuit of described safety detector;
Acquisition module, gathers the different value that described safety detector is exported along with the variation of described simulated strike signal;
Self check judge module, the different value of the safety detector gathering according to described acquisition module output judges that whether this safety detector is normal.
Alternatively, said apparatus also comprises:
Enable module, while effective self check enable signal being detected, determines that described safety detector enters Auto-Sensing Mode, and triggers described simulated strike signal output module to the simulated strike signal of the decision circuit input variation of described safety detector.
Alternatively, in said apparatus, described simulated strike signal output module adopts logical circuit to realize, described logical circuit consists of three switches in parallel, one end of three switches is all connected with an input end of decision circuit in described safety detector, wherein, the other end of the first switch is connected with sensor, the other end of second switch is connected with the high voltage signal of reference data voltage higher than described decision circuit, the other end of the 3rd switch is connected with the low voltage signal of reference data voltage lower than described decision circuit, when described the first switch opens, second, when the 3rd switch is alternately closed, the simulated strike signal changing to described decision circuit input.
Alternatively, in said apparatus, described acquisition module, gathering the different value that described safety detector exports along with the variation of described simulated strike signal at least comprises, while inputting described decision circuit higher than the high voltage signal of the reference data voltage of described decision circuit, the first output valve of described safety detector, and while inputting described decision circuit lower than the low voltage signal of the reference data voltage of described decision circuit, the second output valve of described safety detector;
Described self check judge module, when described the first output valve is identical with corresponding desired value respectively with the second output valve, judge that described safety detector is normal, or, the XOR value of described the first output valve and the second output valve is identical with desired value, judges that described safety detector is normal.
Alternatively, in said apparatus, described self check judge module adopts IC-card intelligent chip to realize.
Alternatively, in said apparatus, described safety detector is voltage-level detector, Temperature Detector, power supply burr detecting device or photodetector.
The invention also discloses a kind of method that safety detector oneself detects that realizes, comprising:
When safety detector is positioned at Auto-Sensing Mode, self-checking unit is to the simulated strike signal of the decision circuit input variation of described safety detector, and gathering described safety detector along with the different value of the variation output of described simulated strike signal, described self-checking unit judges that according to the different value of collected safety detector output whether described safety detector is normal.
Alternatively, in said method, described safety detector is positioned at Auto-Sensing Mode and refers to:
When described self-checking unit detects effective self check enable signal, determine that described safety detector enters Auto-Sensing Mode.
Alternatively, in said method, the simulated strike signal that described pick-up unit changes to the decision circuit input of described safety detector refers to,
Decision circuit input end three switches that are connected in parallel in described safety detector, wherein, the other end of the first switch is connected with sensor, the other end of second switch is connected with the high voltage signal of reference data voltage higher than described decision circuit, the other end of the 3rd switch is connected with the low voltage signal of reference data voltage lower than described decision circuit, when described the first switch opens, control second, third switch and be alternately closed, with the simulated strike signal changing to described decision circuit input.
Alternatively, in said method, described self-checking unit gathers described safety detector along with the different value of the variation output of described simulated strike signal, according to the different value of collected safety detector output, judges that the whether normal process of described safety detector comprises:
At least when the high voltage signal of the reference data voltage higher than described decision circuit is inputted described decision circuit, gather the first output valve of described safety detector, when the low voltage signal of the reference data voltage lower than described decision circuit is inputted described decision circuit, gather the second output valve of described safety detector;
When described the first output valve is identical with corresponding desired value respectively with the second output valve, judge that described safety detector is normal, or the XOR value of described the first output valve and the second output valve is identical with desired value, judges that described safety detector is normal.
Alternatively, in said method, described safety detector is voltage-level detector, Temperature Detector, power supply burr detecting device or photodetector.
Present techniques scheme provides a kind of novel safety detector oneself detection scheme, and the oneself of detecting device detects and completes under the cooperation of system, and implementation is simple, can reach the object that oneself detects.And the self-testing circuit of present techniques scheme is simple, can not produce extra power consumption.
Embodiment
For making the object, technical solutions and advantages of the present invention clearer, below in connection with accompanying drawing, technical solution of the present invention is described in further detail.It should be noted that, in the situation that not conflicting, the application's embodiment and the feature in embodiment can combine arbitrarily mutually.
Embodiment 1
The present embodiment provides a kind of self-checking unit of safety detector, mainly for existing safety detector, for example, voltage-level detector, Temperature Detector, power supply burr detecting device and photodetector etc. may have influence on all kinds of detecting devices of smart card security, enter self check operation.This device, at least comprises following each module:
Simulated strike signal output module, when safety detector is positioned at Auto-Sensing Mode, inputs the simulated strike signal of variation to the decision circuit of safety detector;
Acquisition module, gathers the different value that safety detector is exported along with the variation of described simulated strike signal;
Self check judge module, the different value of the safety detector gathering according to acquisition module output judges that whether this safety detector is normal.
In addition, can also comprise enable module, while effective self check enable signal being detected, determine that safety detector enters Auto-Sensing Mode, and trigger simulation signal to attack output module to the simulated strike signal of the decision circuit input variation of described safety detector.
And why above-mentioned self-checking unit can be realized self check by the simulated strike signal changing and operate.This is because decision circuit 201 generally has a reference data in existing safety detector (as shown in Figure 2), can be the threshold value of mos pipe, can be also the threshold value of phase inverter, may be also a constant input end in comparer.The positive input terminal 204 of comparer 203 connects a reference data.And the present embodiment is under Auto-Sensing Mode, to detecting device, provide the signal of a simulated strike, by another input end 205 inputs of comparer 203.Like this, along with the variation of simulated strike signal, decision circuit 201 input end 205 current potentials can produce the variation that is greater than reference data 204 or is less than reference data 204, thereby the height of the output generation level of decision circuit 201 is changed.Equally, the output 206 of detecting device also can produce corresponding variation.So just reached the object of safety detector being carried out to self check.If testing result conforms to expection, can prove following 2 points: the one, can illustrate that this safety detector is non-defective unit, can normally use, can carry out the task of chip monitoring safety.The 2nd, can illustrate that the output terminal of this safety detector is not attacked.If the output terminal of detecting device is clamped at a certain current potential (high level or low level) by hacker, even if IC-card is under attack so, safety detector can not produce alerting signal yet.
Temperature Detector take below as example, illustrate that above-mentioned self-checking unit realizes the detailed process of self check.
Figure 3 shows that Temperature Detector self check principle schematic.Wherein, 301 represent decision circuits, 302 presentation logic circuit diagrams, 303 outputs that be Temperature Detector, and an input of 304 expression decision circuits, meets reference data voltage Vref, 305 another inputs that are decision circuit.Under normal mode of operation, this input end can meet SenV; Under self-detecting pattern, this input end can be subject to the impact of simulated strike signal low and high level variation and meet noble potential VH or low-voltage VL.That is to say, in the present embodiment, simulated strike signal output module adopts logical circuit to realize, this logical circuit is by three switches 306 of parallel connection, 307,308 form, these three switches are controlled by unlike signal, are not guaranteeing in the same time to only have a switch to close, and all the other two switches are in open mode.The in the situation that of the normal work of Temperature Detector, switch 307 cuts out, and SenV accesses decision circuit, and Temperature Detector monitoring ambient temperature changes.Under Auto-Sensing Mode, VH and VL are controlled by gating switch 308,306, access decision circuit 301.VH is higher than Vref, and VL is lower than Vref.When simulated strike signal is while being high, switch 308 cuts out, and switch 306,307 is opened, and the input end 305 of VH access decision circuit 301, compares with another input end 304 of comparer, and Temperature Detector is output as low level.On the contrary, if when simulated strike signal is low, switch 306 cuts out, switch 307,308 is opened, and the input end 305 of VL access decision circuit 301 compares with another input end 304, and Temperature Detector can be exported high level.
And self-checking unit, at least once sampling output while being high of simulated strike signal, once sampling output at least again when low.Twice output is carried out to XOR (XOR) logical process.If the result of XOR is 1, illustrate that Temperature Detector function is normal, can carry out self check task, and Output rusults is credible.Otherwise, illustrate that Temperature Detector is undesired.Likely circuit is bad, or output terminal is locked by hacker, can not produce the output of reporting to the police.In this case, in use there is risk in illustrative system, do not advise using IC-card.This situation is to financial IC card danger close.
And the sequential of said temperature detecting device when self check as shown in Figure 4.After IC-card power supply, system is carried out reset processing.After reset, Temperature Detector carries out self check.During self check:
(1) open the EN that enables of Temperature Detector, Temperature Detector enters normal operating conditions, can carry out temperature-monitoring function.Output state now can not be believed.Because do not know that now whether IC-card or Temperature Detector self be under attack.So can ignore the now output signal of Temperature Detector.
(2) opening self check, to enable SC_EN(be self check enable signal), Temperature Detector enters Auto-Sensing Mode.After SC_EN was 1 a period of time, output simulated strike signal STIMU, in the present embodiment, STIMU signal is periodic signal.For example, during self check, in the output valve of STIMU once sampling temperature detection while being high (: sampling 1); At STIMU, the output valve of once sampling Temperature Detector is (for example: sampling 2) again while being low.
And for double sampling result, can judge that whether detecting device is normal according to following two kinds of modes:
The one, if Temperature Detector function is normal, when STIMU is high level, detecting device output should be low level so.If sampled result meets expection, can illustrate that the logic function of Temperature Detector is normal, like this, in the situation that having attack, can produce the low level alerting signal of expection.Two sampled values are consistent with desired value respectively, think that Temperature Detector is normal.
The 2nd, double sampling result is carried out to XOR processing, if result is " 1 ", illustrate that Temperature Detector has response to signal to attack.If there is attack, can produce alerting signal.Can also prove, the output terminal of Temperature Detector does not have under attack.If under attack, the output of Temperature Detector will be clamped at a set potential, and double sampling result will be consistent like this, after XOR is processed, can be " 0 ".Adopting two kinds of verification modes is that result is more credible in order to make the self check principle more can be rigorous.Be that sampled result XOR processing costs is consistent with desired value, think that Temperature Detector is normal.
(3) remove STIMU signal, close again after a while SC_EN.And then close IP_EN.Whole like this process of self-test finishes.If testing result is consistent with expection, Temperature Detector is by self check, and IC-card can be carried out subsequent operation (temporarily not considering the impact of other safe IP herein).After self check success, the enabling of Temperature Detector can be opened once again, Real-Time Monitoring chip environment temperature.
It should be noted that, during self check, the output valve of the Temperature Detector of also can sampling repeatedly while being high at STIMU; Similarly, also can sample repeatedly while being low at the STIMU output valve of Temperature Detector.Now, can judge that whether detecting device is normal according to first kind of way, all output valves of sampling when STIMU is high are all identical with corresponding desired value, can judge that Temperature Detector is normal.
In addition, above-mentioned self-checking unit can combined with intelligent card system be realized, and the self check judge module in above-mentioned self-checking unit can adopt IC-card intelligent chip.
Embodiment 2
The present embodiment provides a kind of method that realizes safety detector self check, as shown in Figure 5, comprises following operation:
Step 501, when safety detector is positioned at Auto-Sensing Mode, self-checking unit is to the simulated strike signal of the decision circuit input variation of safety detector;
Wherein, when self-checking unit detects effective self check enable signal, can determine that safety detector enters Auto-Sensing Mode.
Particularly, the simulated strike signal that self-checking unit changes to the decision circuit input of safety detector can adopt logical circuit to realize, now, and decision circuit input end three switches that are connected in parallel in safety detector, as shown in Figure 3.Wherein, the other end of the first switch (307) is connected with sensor, the other end of second switch (308) is connected with the high voltage signal of the reference data voltage higher than described decision circuit, the other end of the 3rd switch (306) is connected with the low voltage signal of the reference data voltage lower than described decision circuit, when the first switch opens, control second, third switch and be alternately closed, with the simulated strike signal changing to decision circuit input.
Step 502, the different value that safety detector is exported along with the variation of simulated strike signal is sampled;
Step 503, self-checking unit judges that according to the different value of sampled safety detector output whether safety detector is normal.
In addition, above-mentioned self-checking unit sampling safety detector is along with the different value of the variation output of simulated strike signal, can be when the high voltage signal input of the reference data voltage higher than decision circuit, at least gather one or several output valve of safety detector, when the low voltage signal input of the reference data voltage lower than decision circuit, at least gather one or several output valve of safety detector;
When the high voltage signal of the reference data voltage higher than decision circuit is inputted, all output valves of the safety detector gathering are all identical with corresponding desired value, and when the low voltage signal of the reference data voltage lower than decision circuit is inputted, all output valves of the safety detector gathering are all identical with corresponding desired value, judge that safety detector is normal.
Certainly determination methods is not limited to above-mentioned a kind of, an output valve (referred to as the first output valve) of the safety detector gathering in the time of also can inputting the high voltage signal of the reference data voltage higher than decision circuit, an output valve (referred to as the second output valve) of the safety detector gathering during with the low voltage signal input of reference data voltage lower than decision circuit, carry out XOR processing, when the end value of processing is identical with desired value, judge that safety detector is normal.
And related safety detector comprises the detecting devices such as voltage-level detector, Temperature Detector, power supply burr detecting device and photodetector in the present embodiment.
From above-described embodiment, can find out, present techniques scheme guarantees, under the normally functioning prerequisite of sensor circuit, to realize other parts of safety detector are carried out to self check by other means.The self check of safety detector is controlled by Auto-Sensing Mode.During self check, for safety detector provides a simulated strike signal, facilitate the cycle of control signal.Based on this thinking, the application makes self-checking circuit be easy to realize, and circuit structure is simple; Because self-checking circuit is simple, cause the self-checking circuit response time short, so process of self-test is consuming time short, for whole system, substantially do not increase the extra time.In addition, safety detector has Auto-Sensing Mode control signal, and when detecting device is normally worked, Auto-Sensing Mode is closed, and whole safety detector can not increase power consumption.
One of ordinary skill in the art will appreciate that all or part of step in said method can come instruction related hardware to complete by program, described program can be stored in computer-readable recording medium, as ROM (read-only memory), disk or CD etc.Alternatively, all or part of step of above-described embodiment also can realize with one or more integrated circuit.Correspondingly, each the module/unit in above-described embodiment can adopt the form of hardware to realize, and also can adopt the form of software function module to realize.The application is not restricted to the combination of the hardware and software of any particular form.
The above, be only preferred embodiments of the present invention, is not intended to limit protection scope of the present invention.Within the spirit and principles in the present invention all, any modification of making, be equal to replacement, improvement etc., within all should being included in protection scope of the present invention.