Integrated circuit and method and device for testing fault injection attack countermeasure detector of integrated circuit
By introducing an attack simulator into an integrated circuit, simulating the fault injection attack stimulus, the complexity of evaluating the sensitivity and responsiveness of the hardware countermeasures detectors in the prior art is solved, efficient and automated testing and calibration are achieved, and the robustness of the integrated circuit is improved.
Patent Information
- Application Number
- CN202510040319.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2024-02-05
- Filing Date
- 2025-01-10
- Publication Date
- 2025-08-05
AI Technical Summary
The prior art is difficult to effectively evaluate the sensitivity and responsiveness of hardware countermeasure detectors in integrated circuits to fault injection attacks, and traditional testing methods are complex, expensive and time-consuming.
Introducing attack simulators in integrated circuits, simulating fault injection attack stimuli, evaluating the performance of countermeasure detectors and the toughness of integrated circuits, using attack simulators to simulate electrical conditional stimuli, and automatically testing the sensitivity and responsiveness of countermeasure detectors.
The efficient and automated testing of countermeasures detectors is realized, which reduces the demand for external testing, improves the performance of the detectors, and can be calibrated during integrated circuit production and operation, simplifying the testing process.
Smart Images

Figure CN120428070A_ABST
Abstract
Description
Technical Field
[0001] The present invention, in certain embodiments, relates to countermeasure detectors (CMs) against fault injection attacks on integrated circuits, and more particularly, but not limited to, testing and characterization of countermeasure detectors against fault injection attacks on integrated circuits. Background Art
[0002] A fault injection (FI) attack on an integrated circuit (IC) is an attack that injects or induces errors in the IC to disrupt its normal operation. There are many techniques that can be used to cause faults in ICs, such as laser irradiation, electromagnetic interference, and voltage interference.
[0003] When developing chips that need to protect against fault injection attacks, application-specific integrated circuit (ASIC) companies typically implement hardware countermeasures (CMs) to protect against various types of fault injection attacks. The purpose of hardware countermeasures is to detect when a fault injection attack occurs so that appropriate countermeasures can be implemented. Various countermeasure detectors are known in the art that can detect different types of fault injection attacks, such as clock / voltage interference and data perturbations.
[0004] A hardware countermeasure's ability to detect a specific attack and its sensitivity to that attack are crucial for ensuring a chip is protected from attack while minimizing unnecessary disruption to chip functionality. If a hardware countermeasure fails to detect an attack, it cannot trigger a response. However, if a hardware countermeasure is too sensitive, it may trigger excessive false alarms.
[0005] Accurately evaluating the effectiveness of hardware countermeasures in integrated circuits is complex. Current approaches use "brute force" tests, such as laser or electromagnetic (EM) radiation, to attempt to induce failures under controlled conditions and evaluate the hardware countermeasure's response. However, these methods are of limited use because replicating more sophisticated attacks is complex, expensive, and time-consuming. These hardware countermeasures may also be referred to herein as countermeasure circuits or countermeasure detectors.
[0006] Other technical background includes: 1) J. Breier and X. Hou, "How Practical Are Fault Injection Attacks, Really?", published in IEEE Access, Vol. 10, pp. 113122-113130, doi: 10.1109 / ACCESS.2022.3217212. The acknowledgment of the above references herein does not imply that these references have any relevance to the patentability of the present invention. Summary of the Invention
[0007] According to certain embodiments, an integrated circuit, an integrated circuit testing method, and an integrated circuit testing apparatus are provided, all of which are used to test the ability of a countermeasure detector to detect a fault injection attack.
[0008] The integrated circuit includes at least three components: a plurality of functional components, at least one countermeasure detector, and at least one attack simulator. The plurality of functional components are configured to execute operations of the integrated circuit; the at least one countermeasure detector is configured to detect a fault injection attack on the integrated circuit and output an alarm signal when a fault injection attack is detected; and the at least one attack simulator is configured to apply stimulation to the plurality of functional components to simulate a fault injection attack on the integrated circuit.
[0009] An attack simulator is used to simulate one or more fault injection attacks to test an integrated circuit by applying electrical condition stimulation that is similar to the stimulation generated when the integrated circuit is subjected to a real attack, and analyzing the countermeasure detector triggered by the simulated fault injection attack to evaluate the performance (such as sensitivity) of the countermeasure detector itself and / or the resilience of the entire integrated circuit.
[0010] In some cases, the operating parameters of the countermeasure detector can be configured to obtain different sensitivities to attacks. The same attack can be simulated using different operating parameters of the countermeasure detector to calibrate the countermeasure detector and maximize the effect of the parameter settings on detecting attacks.
[0011] In one example, the countermeasure circuitry of a power supply fault detector can be designed with a configurable fault detection level. It can be configured to detect a fault when the associated power supply line drops by 20%, 30%, or 40% below the nominal level of the corresponding power supply. An attack simulator can be used to verify whether the countermeasure detector can effectively detect realistic fault injection attacks at the expected level. For example, if the countermeasure detector is configured to detect an attack that causes the power supply line to drop by 30%, an attack simulator can be used to simulate attacks that are expected to cause the power supply line to drop by 30%, or within a range of 30% to 35%, to verify whether the countermeasure detector can detect the attack.
[0012] Effects of certain embodiments of the present invention may include but are not limited to:
[0013] 1) Remove or at least partially replace the need for external methods of performing fault injection attacks to test or characterize countermeasure detectors.
[0014] 2) The same circuit can be used to simulate attacks with different attack characteristics.
[0015] 3) Complex attack combinations and sequences with different attack characteristics can be automatically applied to thoroughly test and characterize the subsystems of the countermeasure detector.
[0016] 4) The performance of the countermeasure detector can be improved with only a slight increase in chip area.
[0017] 5) The susceptibility of functional components in an integrated circuit to fault injection attacks can be tested and characterized, regardless of whether countermeasure detectors are implemented in the integrated circuit.
[0018] 6) Comprehensive characterization of integrated circuits and automatic determination of configuration settings without human intervention.
[0019] 7) The countermeasure detector of each device can be calibrated during the production process of the integrated circuit and / or in the field.
[0020] According to a first aspect of certain embodiments of the present invention, an integrated circuit is provided, comprising interconnected electronic components. The electronic components include: a plurality of functional components, at least one countermeasure detector, and at least one attack simulator. The plurality of functional components are configured to perform operations of the integrated circuit; the at least one countermeasure detector is configured to detect a fault injection attack on the integrated circuit and output an alarm signal upon detection of the fault injection attack; and the at least one attack simulator is associated with the at least one countermeasure detector and is configured to apply a stimulus to the plurality of functional components based on at least one control signal to simulate a fault injection attack on the integrated circuit.
[0021] According to some embodiments of the invention, the stimulation comprises electrical stimulation.
[0022] According to some embodiments of the present invention, at least one parameter of the electrical stimulation is controllable by a control signal.
[0023] According to some embodiments of the present invention, the attack simulator is configured to interfere with a clock signal of an integrated circuit.
[0024] According to some embodiments of the present invention, the attack simulator is configured to cause abnormal behavior of the power line.
[0025] According to some embodiments of the present invention, the attack simulator is configured to cause the ground line to exhibit abnormal behavior.
[0026] According to some embodiments of the present invention, an attack simulator is configured to change a logic signal in an integrated circuit to an opposite logic level.
[0027] According to some embodiments of the present invention, the attack simulator is configured to shift the voltage level of a logic signal in the integrated circuit toward an opposite logic level.
[0028] According to some embodiments of the invention, the stimulation comprises electromagnetic stimulation.
[0029] According to some embodiments of the present invention, the responsiveness of at least one countermeasure detector to an attack may be adjusted based on the results of a simulated attack.
[0030] According to some embodiments of the present invention, the electronic component includes a plurality of attack simulators, and wherein at least two of the attack simulators simulate different types of attacks.
[0031] According to some embodiments of the present invention, at least one of the attack simulators is configured to simulate an attack when at least one of the countermeasure detectors is disabled.
[0032] According to some embodiments of the present invention, at least one attack simulator is configured to trigger a single countermeasure detector.
[0033] According to some embodiments of the present invention, at least one attack simulator is configured to trigger a plurality of countermeasure detectors.
[0034] According to some embodiments of the present invention, the integrated circuit further includes internal processing circuitry configured to analyze a response of the countermeasure detector to a simulated fault injection attack.
[0035] According to some embodiments of the present invention, the integrated circuit further includes an interface configured to provide an alarm signal to an external processor for analyzing performance of the at least one countermeasure detector during a simulated fault injection attack.
[0036] According to a second aspect of certain embodiments of the present invention, a method for testing a fault injection countermeasure detector in an integrated circuit is provided, comprising operating the integrated circuit, controlling at least one attack simulator to simulate a fault injection attack during the operation of the integrated circuit, and determining whether the at least one countermeasure detector detects the simulated fault injection attack. The integrated circuit includes a plurality of interconnected electronic components, the electronic components including: a plurality of functional components, at least one countermeasure detector, and at least one attack simulator. The plurality of functional components are configured to perform operations of the integrated circuit; the at least one countermeasure detector is configured to detect a fault injection attack on the integrated circuit; and the at least one attack simulator is associated with the at least one countermeasure detector and is configured to simulate a fault injection attack on the integrated circuit by applying stimulation to the plurality of functional components.
[0037] Some embodiments according to the present invention further include controlling at least one attack simulator to output different stimuli for a plurality of attack simulators, so as to evaluate the effectiveness of at least one countermeasure detector against different fault injection attacks.
[0038] According to certain embodiments of the present invention, evaluating the effectiveness of at least one countermeasure detector against different fault injection attacks is based on respective values of at least one characteristic of the fault injection attack, the characteristic comprising one of an electrical characteristic of the electronic component and an electrical distance, wherein the electrical distance is between an attack simulator that applies a stimulus and a countermeasure detector that detects the stimulus.
[0039] According to some embodiments of the present invention, an integrated circuit is installed in an operating device, and a method of testing a fault injection countermeasure detector of the integrated circuit is performed during operation of the operating device.
[0040] According to certain embodiments of the present invention, the operation of simulating a fault injection attack includes at least one of the following: applying electrical stimulation to a plurality of functional elements, changing a logic signal in an integrated circuit to an opposite logic level, interfering with a clock signal of the integrated circuit, abnormal behavior on a power line, abnormal behavior on a ground line, and applying electromagnetic stimulation to a plurality of functional elements.
[0041] According to some embodiments of the present invention, the method further comprises calibrating at least one countermeasure detector using the results of the simulated attack.
[0042] According to some embodiments of the present invention, the method further includes simulating an attack by activating at least one attack simulator while disabling all countermeasure detectors, and monitoring the functionality of the integrated circuit during the simulated attack, thereby evaluating the susceptibility of functional elements of the integrated circuit to the fault injection attack.
[0043] According to a third aspect of certain embodiments of the present invention, a test device for testing an integrated circuit is provided. The integrated circuit includes a plurality of interconnected electronic components, the electronic components including: a plurality of functional components, at least one countermeasure detector, and at least one attack simulator. The plurality of functional components are configured to perform operations of the integrated circuit; the at least one countermeasure detector is configured to detect fault injection attacks on the integrated circuit; the at least one attack simulator is associated with the at least one countermeasure detector and is configured to apply stimulation to the plurality of functional components according to at least one control signal to simulate a fault injection attack on the integrated circuit. The test device includes an interface and a processing circuit. The interface is configured to provide a control signal to the at least one attack simulator and to obtain an attack detection signal output by the at least one countermeasure detector; the processing circuit is associated with the interface and is configured to generate a control signal to simulate a fault injection attack, and to analyze the attack detection signal of the countermeasure detector to determine the response of the at least one countermeasure detector to the simulated fault injection attack.
[0044] According to certain embodiments of the present invention, a simulated fault injection attack includes at least one of the following: applying electrical stimulation to a plurality of functional elements, changing a logic signal in an integrated circuit to an opposite logic level, shifting a voltage level of a logic signal in an integrated circuit to an opposite logic level, interfering with a clock signal of an integrated circuit, causing abnormal behavior of a power line, causing abnormal behavior of a ground line, and applying electromagnetic stimulation to a plurality of functional elements.
[0045] According to some embodiments of the present invention, the processing circuit is configured to evaluate the responsiveness of at least one countermeasure detector to different simulated fault injection attacks.
[0046] According to some embodiments of the present invention, the processing circuit is configured to output the analysis result to an external component so as to redesign the integrated circuit according to the analysis result.
[0047] According to a fourth aspect of certain embodiments of the present invention, a method for testing the susceptibility of an integrated circuit to a fault injection attack is provided, comprising: operating the integrated circuit, controlling at least one attack simulator to simulate a fault injection attack during the operation of the integrated circuit, and evaluating, using a processor, the functionality of the integrated circuit during the simulated fault injection attack to determine whether the simulated fault injection attack disrupts the functionality of the integrated circuit. The integrated circuit includes a plurality of interconnected electronic components, the electronic components including a plurality of functional components and at least one attack simulator. The plurality of functional components are configured to perform operations of the integrated circuit; the at least one attack simulator is configured to simulate the fault injection functionality of the integrated circuit by applying stimulation to the plurality of functional components.
[0048] According to certain embodiments of the present invention, the operations of the simulated fault injection attack include at least one of the following: applying electrical stimulation to multiple functional elements, changing logic signals in an integrated circuit to opposite logic levels, interfering with the clock signal of the integrated circuit, abnormal behavior on the power line, abnormal behavior on the ground line, and applying electromagnetic stimulation to multiple functional elements.
[0049] According to some embodiments of the present invention, controlling the operation of the at least one attack simulator includes causing the attack simulator to simulate a fault injection attack detectable by the at least one countermeasure circuit.
[0050] According to some embodiments of the present invention, the method further includes calibrating a countermeasure circuit on the integrated circuit using evaluation results of the integrated circuit's functionality during the simulated fault injection attack.
[0051] According to some embodiments of the present invention, the method further includes redesigning the integrated circuit using evaluation results of the integrated circuit's functionality during the simulated fault injection attack.
[0052] According to a fifth aspect of certain embodiments of the present invention, there is provided a device for testing an integrated circuit, wherein the integrated circuit includes a plurality of interconnected electronic components, the electronic components including: a plurality of functional components and at least one attack simulator. The plurality of functional components are configured to perform operations of the integrated circuit; the at least one attack simulator is associated with the plurality of functional components and is configured to apply stimulation to the plurality of functional components according to at least one control signal to simulate a fault injection attack on the integrated circuit. The above-mentioned device includes: an interface and a processing circuit. The interface is configured to provide a control signal to the at least one attack simulator and output a signal from the integrated circuit; the processing circuit is associated with the interface and is configured to generate a control signal to simulate a fault injection attack, and analyze the signal output from the integrated circuit to identify the simulated fault injection attack used to interrupt the function of the integrated circuit.
[0053] According to some embodiments of the present invention, the signal is output by the integrated circuit during a simulated fault injection attack.
[0054] According to certain embodiments of the present invention, the operations of the simulated fault injection attack include at least one of the following: applying electrical stimulation to multiple functional elements, changing logic signals in an integrated circuit to opposite logic levels, interfering with the clock signal of the integrated circuit, abnormal behavior on the power line, abnormal behavior on the ground line, and applying electromagnetic stimulation to multiple functional elements.
[0055] According to some embodiments of the present invention, the apparatus further includes internal processing circuitry configured to analyze the functionality of the integrated circuit during a simulated fault injection attack.
[0056] Unless otherwise defined, all technical and / or scientific terms used herein have meanings understood by those skilled in the art as relevant to the present invention. Methods and / or materials similar or equivalent to the methods and / or materials described herein can be used in the practice and / or testing of embodiments of the present invention. Exemplary methods and / or materials are described below. With respect to the exemplary embodiments described below, materials, methods, and examples are illustrative and not necessarily limiting.
[0057] Certain embodiments of the present invention are embodied as systems, methods, or computer program products. For example, certain embodiments of the present invention may be implemented entirely in hardware, entirely in software (including firmware, resident software, microcode, etc.), or in the form of an embodiment combining software and hardware aspects, all of which may be generally referred to herein as "circuits," "modules," and / or "systems."
[0058] The execution of the method of some embodiments of the present invention and / or system may include manually, automatically or combine the two to execute and / or complete selected tasks. According to the actual instrument of some embodiments of the method of the present invention and / or system, selected tasks can be performed by hardware, software or firmware and / or any combination (e.g., using an operating system).
[0059] For example, hardware for performing selected tasks according to certain embodiments of the present invention may be implemented as a chip or circuit, while software for performing selected tasks according to certain embodiments of the present invention may be implemented as a plurality of software instructions executed by a computer device (e.g., using any suitable operating system).
[0060] In some embodiments, one or more tasks according to some exemplary embodiments of the methods and / or systems described herein are performed by a data processor, such as a computing platform for executing a plurality of instructions. Optionally, the data processor includes volatile memory and / or non-volatile memory for storing instructions and / or data. Optionally, a network connection is also provided. Optionally, a user interface, such as a display and / or a user input device, is provided.
[0061] Some embodiments of the present invention may be described below with reference to flowchart illustrations and / or block diagrams, for example, illustrating exemplary methods and / or apparatus (systems) and / or computer program products according to embodiments of the present invention. It will be appreciated that each step in the flowchart and / or block diagram and / or a combination of both steps may be implemented by computer program instructions. These computer program instructions may be provided to a processor of a general computer, a special-purpose computer, or other programmable data processing device to produce a machine, such that the instructions executed by the processor of the computer or other programmable data processing device produce a method for implementing the functions and / or actions specified in the flowchart steps and / or block diagram.
[0062] These computer program instructions may also be stored in a computer-readable medium that can direct a computer (e.g., in memory, locally and / or hosted in the cloud), other programmable data processing equipment, or other devices to operate in a specific manner, so that the instructions stored in the computer-readable medium can produce an article of manufacture, which includes instructions for implementing the functions / behaviors specified in the flowchart and / or block diagram.
[0063] Computer program instructions can also be executed by one or more computer devices to perform a series of operating steps on the computer device, other programmable devices, and / or other devices, thereby generating a computer-implemented process. Such instructions provide a procedure for implementing specified functions / actions in a flowchart and / or block diagram. BRIEF DESCRIPTION OF THE DRAWINGS
[0064] In order to understand the present invention, embodiments of the present invention will be described by way of non-limiting example only and with reference to the accompanying drawings. Unless otherwise specified, the features shown in the drawings are only used to illustrate certain embodiments of the present invention, and similar reference numerals are used to represent corresponding parts in the drawings.
[0065] In the block diagrams and flow charts, optional elements / components and optional stages may be enclosed within dashed boxes.
[0066] In the attached figure:
[0067] Figure 1 is a simplified schematic diagram of an integrated circuit according to an exemplary embodiment of the present invention.
[0068] Figures 2 to 4is a simplified diagram of an attack simulator for a digital signal network according to exemplary embodiments of the present invention.
[0069] Figures 5 and 6 is a simplified diagram of an attack simulator for a power supply network according to various exemplary embodiments of the present invention.
[0070] Figure 7 is a simplified block diagram of a voltage regulator for an attack simulator according to an exemplary embodiment of the present invention.
[0071] Figure 8 is a simplified diagram of an attack simulator for a power supply network according to an exemplary embodiment of the present invention.
[0072] Figure 9 is a simplified flow chart of testing an integrated circuit fault injection countermeasure detector according to an embodiment of the present invention.
[0073] Figure 10 is a simplified diagram of a test apparatus for an integrated circuit fault injection countermeasure detector according to an embodiment of the present invention.
[0074] Figure 11 is a simplified schematic diagram of an integrated circuit according to an exemplary embodiment of the present invention.
[0075] Figure 12 is a simplified flow chart of a method for testing the susceptibility of an integrated circuit to a fault injection attack according to an embodiment of the present invention.
[0076] Figure 13 is a simplified diagram of a test apparatus for an integrated circuit fault injection countermeasure detector according to an embodiment of the present invention.
[0077] Various embodiments of the present invention will be described below with reference to the accompanying drawings, which are to be considered in all respects only as illustrative and not restrictive.
[0078] The components shown in the figures are not necessarily drawn to scale, emphasis instead being placed on clearly illustrating the principles of the present invention. Furthermore, two different objects in the same figure may be drawn to different scales.
[0079] Explanation of symbols
[0080] 100: Integrated Circuits
[0081] 110.1~110.4:Functional components
[0082] 120.1~120.5: Hardware Countermeasures
[0083] 130.1-130.3: Attack Simulator
[0084] 140: I / O interface
[0085] 150: External processor
[0086] 160: Internal hardware countermeasure processing circuit
[0087] 200: Attack Simulator
[0088] 210: PMOS transistor
[0089] 220: NMOS transistor
[0090] 230: Built-in test (BIST) controller
[0091] 240: Countermeasures Detector
[0092] 300: Attack Simulator
[0093] 310: Inverter
[0094] 320: Controllable tri-state buffer
[0095] 330: Built-in test (BIST) controller
[0096] 340: Countermeasures Detector
[0097] 400: Attack Simulator
[0098] 410: PMOS transistor
[0099] 420: NMOS transistor
[0100] 430: Built-in Test (BIST) Controller
[0101] 440: Countermeasures Detector
[0102] 450: Analog voltage control circuit
[0103] 510: PMOS transistor
[0104] 520: NMOS transistor
[0105] 530: Built-in test (BIST) controller
[0106] 535: Analog Voltage Control Circuit
[0107] 540: Countermeasures Detector
[0108] 550: External / internal power supply
[0109] 560: Analog switch
[0110] 600: Voltage Regulator (VR)
[0111] 610: Built-in test (BIST) controller
[0112] 615: Analog voltage control circuit
[0113] 620: Voltage Reference
[0114] 630: Digital load
[0115] 640: Countermeasures Detector
[0116] 810: PMOS transistor
[0117] 820: NMOS transistor
[0118] 830: Built-in-Test (BIST) Controller
[0119] 835: Analog Voltage Control Circuit
[0120] 840: Countermeasures Detector
[0121] 910-950: Operation
[0122] 1000: Test equipment
[0123] 1010: Processing circuit
[0124] 1020: Interface
[0125] 1030: Processor
[0126] 1040: Memory
[0127] 1050: Integrated Circuit
[0128] 1100: Integrated Circuits
[0129] 1110.1~1110.4:Functional elements
[0130] 1130.1-1130.3: Attack Simulator
[0131] 1140: Input / output (I / O) interface
[0132] 1150: External processor
[0133] 1160: Internal processing circuit
[0134] 1210-1250: Operation
[0135] 1300: Test equipment
[0136] 1310: Processing circuit
[0137] 1320: Interface
[0138] 1330: Processor
[0139] 1340: Memory
[0140] 1350: Integrated Circuits
[0141] VHigh: voltage
[0142] VLow: voltage
[0143] VCC: voltage
[0144] GND: Ground
[0145] OUT: Output
[0146] VREF: voltage
[0147] REF: reference signal
[0148] I_LOAD: current load
[0149] REF_CONTROL: control signal
[0150] REG_CONTROL: control signal
[0151] LOAD_CONTROL: control signal
[0152] ERR AMP: Error Amplifier
[0153] VGATE: gate voltage
[0154] FB: Feedback
[0155] LOAD_CONTROL_N: control signal
[0156] LOAD_CONTROL_P: control signal
[0157] SWITCH_CONTROL: control signal DETAILED DESCRIPTION
[0158] The present invention, in certain embodiments, relates to countermeasure detectors for fault injection attacks on integrated circuits, and more particularly, but not limited to, testing countermeasure detectors for fault injection attacks on integrated circuits.
[0159] Certain embodiments described herein incorporate a controllable, selectively configurable attack simulator component into an integrated circuit (IC) that includes a countermeasure detector for detecting fault injection attacks. The attack simulator applies stimuli to the IC and tests the countermeasure detector to determine whether one or more specific stimuli cause the countermeasure detector to detect an attack. Analysis of such test results can assess the performance of the IC's hardware countermeasures (CM), and / or its resilience against attacks. Based on the test results, the IC or similar ICs can be redesigned to improve their overall robustness, and / or to calibrate one or more countermeasure detectors to better settings.
[0160] A similar test protocol can also be performed on a specific integrated circuit in an operational device. Thus, the countermeasure detector in a specific integrated circuit can be calibrated and verified according to the actual operating environment.
[0161] Using an on-chip attack simulator makes it easier and more economical to test integrated circuit designs.
[0162] The principles, uses and implementations of the present invention can be better understood with reference to the accompanying descriptions and drawings. After reading the descriptions and drawings, those skilled in the art can implement the present invention without expending excessive effort or conducting excessive experiments.
[0163] Before explaining at least one embodiment of the present invention in detail, it should be understood that the application of the present invention is not necessarily limited to the structural details and component and / or method arrangements described in the following description and / or drawings and / or examples. The present invention can also have other embodiments or be implemented or carried out in various ways.
[0164] 1) Functional elements: Functional elements perform operations that implement the functions of the integrated circuit. Functional elements can be any type of integrated circuit component, such as logic functions composed of logic gates, microprocessors, analog circuits, memory blocks, etc.
[0165] 2) at least one hardware countermeasure, wherein the hardware countermeasure detects attacks on the integrated circuit (particularly fault injection attacks) and outputs an alarm signal when a fault injection attack is detected; and
[0166] 3) At least one attack simulator (AE), which simulates a fault injection attack on the integrated circuit by applying one or more stimuli to the functional element and / or the related interconnect or power transmission network according to at least one control signal.
[0167] An integrated circuit may include other components necessary for its operation, such as electrical interconnects, power supply components, oscillators, interface components, etc.
[0168] As used herein, according to certain embodiments of the present invention, the term “fault injection attack” refers to an attack on an integrated circuit, the purpose of which is to cause changes in electrical signals (such as logic signals and / or voltage signals and / or clock signals) within the integrated circuit.
[0169] As described herein, according to some embodiments of the present invention, the term “countermeasure detector” refers to a circuit in an integrated circuit that outputs an alarm signal upon detecting a fault injection attack.
[0170] As used herein, according to certain embodiments of the present invention, the terms “triggering a countermeasure detector,” “the countermeasure detector is triggered,” and similar terms mean that a stimulus applied to the integrated circuit (by an actual attacker, a person testing or evaluating the integrated circuit, and / or an attack simulator) causes the countermeasure detector to output an alarm signal.
[0171] As used herein, according to some embodiments of the present invention, the term “calibrating a countermeasure detector” refers to adjusting one or more parameters of a countermeasure detector to cause it to behave differently in response to the same stimulus from an attack simulator or / and a fault injection attack.
[0172] As used herein, according to certain embodiments of the present invention, “effectively detecting an attack” refers to detecting an attack having a specific characteristic (eg, above a specific threshold) without an undesirable number of false positives (also referred to as false positive detections).
[0173] As used herein, according to some embodiments of the present invention, the term "simulated attack" refers to applying a stimulus within an integrated circuit whose effective result is similar to the result expected from a fault injection attack.
[0174] As used herein, the term "attack emulator" (abbreviated as AE) refers to a circuit in an integrated circuit that can generate a stimulus similar to the stimulus expected to be caused by a fault injection attack, according to some embodiments of the present invention.
[0175] As used herein, according to certain embodiments of the present invention, the term "stimulus" refers to a physical effect generated by an attack simulator that causes a change in the behavior of a signal or / and power supply within an integrated circuit (e.g., a change in voltage, current, state, timing, etc.).
[0176] As used herein, according to some embodiments of the present invention, the term “activating an attack simulator” refers to causing an attack simulator to generate stimulation.
[0177] As used herein, according to some embodiments of the present invention, the term “glitch” refers to a short-duration voltage pulse or current pulse.
[0178] Countermeasures Detector
[0179] According to certain embodiments of the present invention, the subject hardware countermeasure is to monitor the electrical behavior of signals, component behavior, and / or networks (e.g., digital signals, clock signals, power delivery networks, etc.) in a chip. When the hardware countermeasure detects a fault injection attack, it typically outputs an alarm signal.
[0180] Functions that can be performed by hardware countermeasures include high fanout network (HFN) monitoring, clock integrity monitoring, power supply fault detection, and electromagnetic fault injection detection. For example, U.S. Patent No. 9,523,736, the entire contents of which are incorporated herein by reference, describes a hardware countermeasure for detecting fault injection in and / or utilizing a high fanout network.
[0181] The alarm signal may be selectively just an indicator of a detected attack. Alternatively, the alarm signal may include more information, such as the type of attack, the detected signal level, the time, etc.
[0182] The alarm signal may be of any type known in the art, such as a digital signal, an analog signal and / or a combination of digital and analog signals.
[0183] The integrated circuit may optionally include a plurality of hardware countermeasures. In addition, the integrated circuit may further include at least two types of hardware countermeasures.
[0184] Additionally, hardware countermeasures may be optionally used to detect at least two types of fault injection attacks, or multiple hardware countermeasures may detect the same type of attack.
[0185] Optionally, at least one hardware countermeasure in an integrated circuit can detect more than one type of fault injection attack. Thus, a single hardware countermeasure can be used to evaluate the robustness of a chip against multiple types of fault injection attacks.
[0186] Optionally, after manufacturing (e.g., during testing and / or operation), when setting or calibrating hardware countermeasure operational parameters, the hardware countermeasures are experimentally configured to run at different parameter settings during different simulated attacks to determine preferred parameter settings for one, some, or all of the hardware countermeasures. Thus, the results of the attack simulations can be used to calibrate the hardware countermeasures to adjust their responsiveness to attacks.
[0187] Part or all of the alarm signal, derivatives of part or all of the alarm signal, and / or other representations of part or all of the alarm signal can optionally be output from the integrated circuit for external processing (e.g., to evaluate the hardware countermeasure performance and / or overall attack resistance of the integrated circuit). Alternatively, at least part of the processing and evaluation of the alarm signal can be performed by internal processing circuitry within the integrated circuit itself.
[0188] Attack Simulator
[0189] According to some embodiments of the present invention, an attack simulator applies a stimulus to an integrated circuit in order to create conditions similar to those encountered when the integrated circuit is subjected to an actual fault injection attack. An example of an attack simulator is described in detail below.
[0190] Attack simulators can be placed at locations of interest in an integrated circuit design to test the impact of stimuli on proximal and / or distal hardware countermeasures, and / or to test the impact on nearby sensitive circuit elements.
[0191] The stimulus applied by the attack simulator can be of any type that may interfere with the operation of the integrated circuit.
[0192] Note that a stimulus applied by an attack simulator does not necessarily trigger a hardware countermeasure. A hardware countermeasure that does not trigger in response to a stimulus applied by an attack simulator indicates that the hardware countermeasure did not detect the simulated attack, for example, due to the characteristics of the stimulus applied by the attack simulator, such as amplitude, duration, frequency, position within the clock cycle, stimulus characteristics relative to the hardware countermeasure setup under evaluation, physical distance between the attack simulator and the hardware countermeasure circuitry, etc. In some cases, this is a desirable result, indicating that the hardware countermeasure is not overly sensitive to a particular stimulus (e.g., a low-amplitude fault).
[0193] The attack simulator control signal can be any type of signal that causes the attack simulator to apply a stimulus to a component in the integrated circuit. Examples of control signals include, but are not limited to, digital signals, analog signals, and clock signals.
[0194] The control signal of the attack simulator may optionally be a digital signal.
[0195] The control signal of the attack simulator can optionally be a trigger signal, which can cause the attack simulator to output a known stimulus signal (such as a specific electrical signal).
[0196] Alternatively, the control signal of the attack simulator may affect parameters of the attack simulator output signal, such as the amplitude, duration, and / or timing of the stimulus. Thus, the hardware countermeasures can be tested under different attack conditions by the same attack simulator.
[0197] The integrated circuit optionally includes a single attack simulator.
[0198] In another embodiment of the present invention, a plurality of attack simulators are installed in the integrated circuit. In addition, at least two attack simulators can be selected to simulate different types of attacks.
[0199] The attack simulator can be positioned at different distances from the hardware countermeasures. This allows for checking whether the hardware countermeasures are affected by proximity to the attack simulator.
[0200] At least one attack simulator is optionally configured to trigger a single hardware countermeasure (eg, by being physically located in close proximity to the hardware countermeasure).
[0201] Additionally, at least one attack simulator is configured to trigger a plurality of hardware countermeasures. As described above, although the attack simulator may be configured to trigger a plurality of hardware countermeasures, one or more of the hardware countermeasures may fail to detect the simulated attack.
[0202] Determining that hardware countermeasures are not triggered by an attack simulator can be an important part of testing an integrated circuit's ability to withstand fault injection attacks. Analysis can be performed under conditions where the attack simulator triggers and does not trigger the hardware countermeasure to determine whether the hardware countermeasure is able to detect an attack with a specific signature, and / or to determine whether the hardware countermeasure detects an attack under conditions that are not intended to trigger an alarm signal (e.g., checking that a minor fault does not trigger the hardware countermeasure).
[0203] Optionally, multiple attack simulators (possibly in different groups) can be started simultaneously. This allows for simulating a multi-attack scenario and checking how hardware countermeasures react to stimuli from multiple sources.
[0204] In some embodiments of the present invention, the stimulus applied by the attack simulator is electrical (ie, can be expressed as a voltage level and / or a current level). In another or more embodiments of the present invention, the stimulus applied by the attack simulator is non-electrical.
[0205] The attack simulator may optionally apply an electrical stimulus to cause the power line to exhibit abnormal behavior.
[0206] The attack simulator optionally applies an electrical stimulus that causes the ground wire to behave abnormally.
[0207] The attack simulator can optionally apply an electrical stimulus to change the logic signal in the integrated circuit to an opposite logic level.
[0208] The attack simulator may selectively apply an electrical stimulus to change the voltage level of a logic signal in the integrated circuit to an opposite logic level.
[0209] The attack simulator may optionally apply an electrical stimulus that interferes with the integrated circuit's clock signal. Examples of interference with the integrated circuit's clock signal include, but are not limited to: i) distorting or glitching the clock signal, thereby selectively skipping clock signal pulses; and ii) introducing extraneous high and / or low clock pulses.
[0210] In some embodiments of the present invention, the stimulus applied by the attack simulator is electromagnetic. The attack simulator may optionally include a radiating element that emits an electromagnetic signal, using intentional crosstalk or other techniques to produce this effect.
[0211] The stimulus duration is very short, optionally causing a fault within the integrated circuit (e.g., a fraction of a clock cycle). In one example, the logic level at a specific location in the integrated circuit momentarily switches to the opposite logic level. In a second example, the stimulus is a brief power surge on a power line. In a third example, the stimulus is a brief short circuit to ground on a signal or power line.
[0212] At least one of the attack simulators can optionally be configured to simulate an attack while the hardware countermeasures are disabled. This allows the integrated circuit's susceptibility to a particular attack to be assessed without the hardware countermeasures providing an alert. Alternatively, some or all of the hardware countermeasures may be left disabled, but the alert signals provided (or not provided) by the hardware countermeasures may be ignored during the assessment.
[0213] Interface and processing
[0214] The integrated circuit may optionally include an interface for inputting an attack simulator control signal to the integrated circuit.
[0215] Additionally, the interface can be used to provide an alarm signal for hardware countermeasures to an external processor and / or controller.
[0216] In addition, the integrated circuit further includes an internal hardware countermeasure processing circuit 160. The internal hardware countermeasure processing circuit may perform tasks including, but not limited to, providing control signals, reading hardware countermeasure output signals, and calibrating hardware countermeasures.
[0217] The internal hardware countermeasure processing circuit 160 may optionally include a processor that executes software instructions. The software instructions may also optionally control at least a portion of the configuration and / or activation of the attack simulator.
[0218] The internal hardware countermeasure processing circuit 160 may optionally include volatile and / or non-volatile memory.
[0219] The internal memory optionally stores software instructions for execution by the processor.
[0220] In addition, the internal memory may also store data used in embodiments of the present invention. According to certain embodiments of the present invention, examples of additional data that may be stored in the memory include, but are not limited to, specifications for simulated attacks, characteristics and parameter settings of hardware countermeasures, test result data, and data collected during operation of the integrated circuit. In certain embodiments of the present invention, at least some of the data stored in the internal memory is used to analyze and evaluate the performance of the integrated circuit, particularly during simulated fault injection attacks.
[0221] In some embodiments of the present invention, hardware countermeasure output signals are analyzed to evaluate the performance of the hardware countermeasure during a simulated fault injection attack. This analysis can be performed by an external processor and / or an internal processor.
[0222] Optionally, a parameter of at least one hardware countermeasure is adjusted based on the evaluation result.
[0223] Optionally, parameters of the simulated attack can be adjusted based on the evaluation results to test the response of the hardware countermeasures to different attack scenarios.
[0224] Optionally, based on the analysis of the hardware countermeasure's response to the simulated attack, the integrated circuit may be redesigned, ie, a different integrated circuit incorporating the same or similar hardware countermeasure circuit may be redesigned.
[0225] Now refer to Figure 1 , is a simplified schematic diagram of an integrated circuit according to an exemplary embodiment of the present invention. Figure 1 It is for illustration purposes only and does not represent actual circuit elements or the interconnections between them.
[0226] For clarity, Figure 1 The functional components, countermeasure detectors, and attack simulators are illustrated as separate entities. However, application-specific integrated circuits (ASICs) may contain tens of millions of logic gates. In practice, it is expected that these components will be distributed across the integrated circuit chip. Figure 1 There is no limitation on the number and / or type and / or interconnection of functional elements, hardware countermeasures and attack simulators.
[0227] Integrated circuit 100 includes functional elements 110.1 to 110.4 (illustrated as triangles), hardware countermeasures 120.1 to 120.5 (illustrated as squares), and attack simulators 130.1 to 130.3 (illustrated as ovals).
[0228] Integrated circuit 100 optionally includes an I / O interface 140 for inputting and outputting signals to and from integrated circuit 100. In the attack simulation described herein, I / O interface 140 can be used to input control signals from the attack simulator, i.e., output alarms from hardware countermeasures, i.e., / or input calibration signals to calibrate the hardware countermeasures' responsiveness to stimuli. Furthermore, I / O interface 140 can also be used to communicate with external devices or systems, such as external processor 150.
[0229] Integrated circuits may be designed and / or manufactured using any technology known in the art to embed hardware countermeasures and attack simulators in the integrated circuit. Such technology may include, but is not limited to, any standard complementary metal oxide semiconductor (CMOS) wafer foundry process with geometries suitable for designing and manufacturing very large scale integrated circuit (VLSI) devices.
[0230] I. High Capacitance Cyber Attack Simulator
[0231] Certain nets in integrated circuits have relatively high capacitance and slowly changing signal levels are expected.
[0232] For example, high fan-out networks (HFNs) are large networks distributed across a large area of the chip and are typically expected to be static (i.e., rarely change state). Hardware countermeasures for high fan-out networks can verify the consistency of network logic values at different physical locations.
[0233] Power nets are also typically static. They may experience variations in supply levels due to normal chip activity, but the expected range of variation is limited. Power nets also have significant capacitance (typically much greater than high-fanout nets) and are driven to their levels by high-power devices (typically low-dropout regulators) on-chip and / or off-chip. Hardware countermeasures for power nets can include analog fault detectors.
[0234] Now refer to Figures 2 to 4 , is a simplified schematic diagram of a digital signal network attack simulator according to various exemplary embodiments of the present invention. For clarity, Figures 2 to 4 The description of the present invention is directed to an attack simulator for a high frequency network. For technicians, attack simulators with the same or similar structures can also be used for other types of networks (including relatively static digital signal networks).
[0235] Figure 2 A first exemplary embodiment of a high-frequency network attack simulator is shown. The attack simulator 200 is composed of a PMOS transistor 210 , an NMOS transistor 220 , and a built-in test (BIST) controller 230 . Figure 2 A simple circuit configuration using two transistors to generate a glitch on a high-frequency network line is shown. As will be appreciated by those skilled in the art, the same electrical behavior can be achieved using other circuit configurations (some of which are described below). Furthermore, other electrical components such as resistors and capacitors can be used to influence the electrical characteristics of the glitch, such as its shape.
[0236] One terminal of the PMOS transistor 210 is connected to a voltage VCC, and a second terminal is connected to a location in the high-frequency network. One terminal of the NMOS transistor 220 is connected to ground (GND), and a second terminal is connected to approximately the same location in the high-frequency network. A countermeasure detector 240 is also connected to the high-frequency network line to detect logic level faults on the high-frequency network.
[0237] The gates of PMOS transistor 210 and NMOS transistor 220 are each connected to a built-in test (BIST) controller 230. BIST controller 230 can activate one (or both) transistors at any given time by applying control signals to the transistor gates. For example, when NMOS transistor 220 is off, applying a brief pulse to the gate of PMOS transistor 210 will briefly connect the high-frequency network line to voltage VCC. Similarly, applying a brief pulse to the gate of NMOS transistor 220 will also briefly connect the high-frequency network line to ground (GND). If countermeasure detector 240 detects that the fault is an attack, it will output an alarm. Both PMOS transistor 210 and NMOS transistor 220 have the electrical capabilities to produce the desired effect and can be applied to the relevant high-frequency network.
[0238] BIST controller 230 can control transistor gates in any desired manner to simulate a specific attack. For example, BIST controller 230 can automatically enable transistors based on an externally provided signal (e.g., manual enable) or using internal control logic (e.g., using a sequencer).
[0239] Alternatively, the decision of whether to enable the PMOS transistor 210 and / or the NMOS transistor 220 depends on the current logic state of the high frequency network.
[0240] In another alternative embodiment, the attack simulator 200 interferes with an integrated circuit clock signal using appropriate control signals from a built-in-test (BIST) controller 230. In one example, the built-in-test (BIST) controller 230 can monitor the clock signal, detect the end of a clock pulse, and then apply an additional clock pulse between the previous clock pulse and the next clock pulse.
[0241] Figure 3 A second exemplary embodiment of a high-frequency network attack simulator is shown. The attack simulator 300 applies a stimulus based on the current logic state of the protected high-frequency network. The built-in test (BIST) controller 330 controls the controllable tri-state buffer 320. When the controllable tri-state buffer 320 is turned on, the output of the inverter 310 is connected to the high-frequency network line. In this way, a stimulus (such as interference) with a logic level opposite to the current level of the high-frequency network is applied. It should be noted that in this embodiment, the built-in test (BIST) controller 330 does not need to know the state of the monitored network in order to apply the opposite logic level. In addition, when the high-frequency network changes its state, the interference may stop or oscillate on the high-frequency network (producing a slightly different interference shape).
[0242] Figure 4A third exemplary embodiment of a high-frequency network attack simulator is shown. The attack simulator 400 has a similar structure to the attack simulator 200 (see FIG. Figure 2 ), but further includes an analog voltage control circuit 450, which can control the stimulation amplitude applied to the high-frequency network within a voltage range between a voltage VHigh and a voltage VLow.
[0243] Now refer to Figures 5 to 8 , which is a simplified schematic diagram of a power network attack simulator according to various exemplary embodiments of the present invention.
[0244] Figure 5 A first exemplary embodiment of a power network attack simulator is presented. Figure 5 Using similar PMOS and NMOS transistors, whose terminals are connected to power supplies with voltages VHIGH / VLOW, respectively, allows for highly controllable disturbance intensity and duration. A built-in test (BIST) controller 530 controls the gates of the PMOS transistor 510 and the NMOS transistor 520, as well as the state of the analog switch 560. During testing, the analog switch 560 can disconnect the external / internal power supply 550 of the countermeasure detector 540 without disturbing the power supply, resulting in an independent, low-capacitive monitored node that can be controlled with very high precision.
[0245] The attack simulator 500 may optionally further include an analog voltage control circuit 535 , which may control the stimulus amplitude applied to the high-frequency network within a voltage range between a voltage VHigh and a voltage VLow.
[0246] Figure 6 An exemplary embodiment of a power network attack simulator that reuses embedded chip components is presented.
[0247] Figure 6 The embedded voltage regulator (VR) 600 as a main power supply and digital circuit current loads (such as built-in digital modules, standard cell chains, memory, and other provided circuits) are included. The built-in test (BIST) controller 610 can reuse these loads for interference purposes. The monitored power supply voltage and digital circuit current load can be controlled by one or more of the following operations:
[0248] a) Temporarily shut down the voltage regulator (VR) 600 to avoid competition with interference;
[0249] b) controlling the voltage regulator (VR) 600 itself via a voltage reference;
[0250] c) by oscillating and / or directly to the gate of the transmission device ( Figure 7 to control the voltage regulator (VR) 600 itself by adjusting the gate voltage VGATE in the circuit to weaken / strengthen its function; and
[0251] d) By activating various digital modules in various ways, the digital load 630 is controlled to provide a current load (usually very large) to achieve power interference.
[0252] Optionally, stimulation (e.g., interference) may be performed using the above actions (a to d), alone or in combination. Non-limiting examples include:
[0253] a) Based on instructions from the countermeasure detector built-in test (CM-BIST), multiple inputs and outputs (IOs) are driven at a high rate to induce a disturbance internally (the number of IOs, drive strength, slew rate, output contention value, etc. are configurable to control the disturbance intensity for IO power failures).
[0254] b) Logic circuits, where certain logic is run in a dedicated built-in test (BIST) mode, which consumes significant power (eg, exceeds the normal operating power consumption allowed by the system specification).
[0255] Digital load startup can be performed by various methods.
[0256] Built-in-test (BIST) controller 610 outputs three control signals: REF_CONTROL, REG_CONTROL, and REG_CONTROL. REF_CONTROL is output to voltage reference 620, REG_CONTROL is output to voltage regulator 600, and LOAD_CONTROL is output to digital load 630. Each control signal can be a bus of any size. Together, these control signals provide the disturbance strength and duration required to evaluate countermeasure detectors (e.g., by countermeasure detector 640).
[0257] Optionally, the attack simulator further includes an analog voltage control circuit 615 , which can control the stimulation amplitude applied to the high-frequency network within a voltage range between a voltage VHigh and a voltage VLow.
[0258] Now refer to Figure 7 , the figure is applicable to Figure 6 A simplified block diagram of an exemplary voltage regulator of an embodiment. A regulator control signal (which can be a bus of any size) can be as described above with respect to Figure 6The voltage regulator (VR) 600 is turned on / off as described above. The regulator control signal can also be used to directly drive the gate voltage ("VGATE") node to any desired level. Direct control of the gate voltage (VGATE) enables a fast output (OUT) response, thereby acting as a glitcher. In addition, the voltage VHIGH can be adjusted to a higher or lower voltage level to achieve up / down glitches and a stronger / weaker state of the voltage regulator (VR) 600.
[0259] Figure 8 An exemplary embodiment of a power network attack simulator based on direct access to power supply nodes is shown. A PMOS transistor 810 and an NMOS transistor 820 are connected to power supply voltages VHIGH and VLOW, respectively. To apply a stimulus, the PMOS transistor 810 and the NMOS transistor 820 are turned on or off by a built-in test (BIST) controller 830, thereby charging or discharging the power supply node. The depth of the perturbation depends primarily on the size of the PMOS transistor 810 and the NMOS transistor 820 and the levels of the VHIGH and VLOW voltages, while the width of the perturbation depends on the width of the control (load control) pulse.
[0260] Optionally, the attack simulator further includes an analog voltage control circuit 835 , which can control the stimulation amplitude applied to the high-frequency network within a voltage range between a voltage VHigh and a voltage VLow.
[0261] Attack simulations can be initiated individually or in conjunction with the supply node by directly controlling the supply node. Figures 6 and 7 The reuse embodiments shown are combined.
[0262] II) Attack simulator to monitor clock integrity
[0263] The capacitance of the clock network is relatively small, so it can switch quickly and relatively continuously (until the logical gating). The countermeasure detector 840 can check the exact period and / or the exact number of pulses within a time window and / or the consistency between different branches of the clock tree. Therefore, the attack simulator of the clock network can choose to use Figure 2 、 Figure 3 or Figure 4 The circuit shown is used to apply an extraneous clock pulse to the clock network and / or shield an effective clock pulse therein.
[0264] Test Selection
[0265] Including an attack simulator in an integrated circuit allows testing of many aspects of the countermeasure detector performance and the integrated circuit itself.
[0266] 1) The embodiments of the present invention can be used for functional testing of integrated circuits by presenting small disturbances that the integrated circuit should be able to withstand (e.g., without causing malfunctions or alarms) and verifying whether the integrated circuit can withstand these disturbances and maintain correct operation. For example:
[0267] a. The attack simulator is coupled to the countermeasure detector so that an indication that the countermeasure detector responds to a known tolerable simulated attack is a good indicator of whether the countermeasure detector is overly sensitive to the tolerable attack.
[0268] b. A known tolerable attack on the chip power network (VCORE) can be simulated by briefly changing the regulator voltage VREF, which causes a momentary power disturbance and then checking whether the chip exhibits any malfunctions.
[0269] 2) The distance between the attack simulator and the countermeasure detector. The attack simulator can be placed at locations both close to and far from the countermeasure detector to evaluate the impact of the physical distance between the simulated attack locations on the response of a specific countermeasure detector to the simulated attack.
[0270] 3) Selective activation: Different groups of attack simulators can be activated separately to check the response of the integrated circuit, such as how the sensitivity of the countermeasure detector affects the detection of closer or farther interference.
[0271] 4) Perturbation depth / intensity. Attack simulators can be designed with controllable electrical intensity, allowing for the application of stimulus combinations (e.g., perturbations) of varying intensities and durations to observe how different countermeasure detectors perform under varying stimuli. For example, when a network is driven by competition, it must "compete" against the natural net driver. Even if the network is driven continuously, it may not reach the target voltage, especially if driven only for a short time. Ultimately, the network's drive strength, the voltage of the driving source, and the duration of the competition drive determine the shape of the perturbation / interference (including its width and peak value, which are often coupled). Using drive strength (resistance), drive voltage, and pulse width control for countermeasure detector built-in test (CM-BIST) allows for granular scanning of the glitch shape space. Note that controlling only a few parameters can be beneficial. For example, even sufficiently fine-grained control of pulse width can still scan the glitch space to a certain extent at a relatively low cost.
[0272] 5) Built-in-test (BIST) control can be designed to sweep a set of predefined pulse depth and duration combinations.
[0273] 6) Testing can be used to calibrate the process-dependent countermeasure detector for each specific IC by defining the countermeasure detector response criteria (e.g., at what disturbance setting the countermeasure detector should trigger) and then calibrating the countermeasure detector until it responds to the desired disturbance setting.
[0274] 7) The attack simulator can apply power and / or signal interference above or below the maximum or minimum voltage range allowed by the respective network. This can be achieved by using an available power supply (e.g., from an input / output (IO) power supply) with a voltage higher than the reference voltage or other circuit design methods. Alternatively, capacitor charging and discharging or other charge pumps can be used.
[0275] 8) The test can intentionally generate a power disturbance at the source of the power supply by leveraging a pre-designed mechanism within the chip's internal power supply (e.g., a low-dropout (LDO) regulator) or its bandgap reference circuit. Therefore, the stimulus is generated through the LDO regulator itself, rather than directly through a separate circuit on the power line. Therefore, there is no need to counter the LDO regulator's operation to generate the stimulus. For example, the voltage reference of a voltage regulator can be momentarily modified to cause it to output a higher or lower voltage, thereby generating a voltage disturbance on the power supply.
[0276] 9) Shared Circuit Logic: In some embodiments, the attack simulator output can be electrically connected to multiple physical locations on the integrated circuit via analog switches. By using control logic to control the analog switches, a single attack simulator can simulate attacks at multiple locations on the integrated circuit.
[0277] 10) The stimulus timing within a cycle can be controlled by built-in-test (BIST) controls, such as delays or random logic relative to the relevant clock edges.
[0278] Methods for testing fault injection countermeasure detectors
[0279] Now refer to Figure 9 , is a simplified flow chart of a method for testing a fault injection countermeasure detector in an integrated circuit according to an embodiment of the present invention. The integrated circuit includes interconnected functional elements, at least one countermeasure detector for detecting fault injection attacks on the integrated circuit, and at least one attack simulator for simulating the fault injection attacks to determine whether the attacks are detected by the countermeasure detector.
[0280] The integrated circuit and the electronic components it contains that are interconnected, such as functional elements, countermeasure detectors, and attack simulators, may conform to any of the embodiments described herein.
[0281] The integrated circuit begins operation in operation 910. Operations continue while the countermeasure detector is tested.
[0282] In operation 920 , at least one attack simulator is configured and controlled to simulate a fault injection attack.
[0283] In operation 930 , it is determined whether the countermeasure detector detects an attack simulating fault injection, for example, it is determined whether the countermeasure detector outputs an alarm signal.
[0284] Optionally, the method further includes an operation of evaluating the effectiveness of the countermeasure detector against different fault injection attacks 940. The attack simulator is controlled to output different stimuli or stimulus combinations to simulate attacks with different characteristics, and the output signals of the countermeasure detector generated by these attacks are analyzed.
[0285] Optionally, the evaluation is based on respective values of at least one characteristic of the attack, which may include but is not limited to at least one electrical characteristic of the electronic component (such as effective transistor saturation current) and an electrical distance between an attack simulator applying the stimulus and a countermeasure detector detecting the stimulus.
[0286] Optionally, the method further includes an operation of calibrating the countermeasure detector 950. Optionally, the countermeasure detector is calibrated using the results of one or more simulated attacks, such as analyzing whether the countermeasure detector outputs an alarm signal for a particular attack or a group of attacks.
[0287] The attack simulator may optionally simulate a fault injection attack by performing at least one of the following:
[0288] a) applying an electrical stimulus to the functional element;
[0289] b) changing the logic signal in the integrated circuit to the opposite logic level;
[0290] c) shifting the voltage level of a logic signal in the integrated circuit to an opposite logic level;
[0291] d) Interfering with integrated circuit clock signals;
[0292] e) Introducing abnormal behavior on the power line;
[0293] f) introducing unusual behavior in the ground conductor; and
[0294] g) applying an electromagnetic stimulus to the plurality of functional elements.
[0295] Optionally, the method further includes activating at least one attack simulator to simulate an attack while disabling all countermeasure detectors, and monitoring the integrated circuit functionality during the simulated attack. Alternatively, some or all of the countermeasure detectors are not disabled, but alarm signals provided (or not provided) by the countermeasure detectors are ignored during the evaluation.
[0296] Alternatively, the integrated circuit can be installed in an operating device and tested while the device is operating. This allows the countermeasure detector to be calibrated for each device and also for each target application system, rather than testing the integrated circuit individually for design and quality assurance purposes.
[0297] Test equipment
[0298] Now refer to Figure 10 , is a simplified schematic diagram of a device for testing a fault injection countermeasure detector in an integrated circuit according to an embodiment of the present invention. Figure 9 The method includes a processing circuit 1010 and an interface 1020 .
[0299] The processing circuit 1010 may include one or more hardware processors 1030. Optionally, the processing circuit 1010 also includes a memory 1040 for storing software instructions to be executed by the processor 1030 and / or other information, such as specifications of simulated attacks, countermeasure detector characteristics and parameter settings, test result data, etc.
[0300] The interface 1020 provides a control signal to the attack simulator and obtains an attack detection signal (ie, an alarm) output by the countermeasure detector.
[0301] Processing circuit 1010 generates control signals for the attack simulator on integrated circuit 1050 and analyzes countermeasure detector output signals to determine the responses of the countermeasure detectors on integrated circuit 1050 to the simulated attack. For example, during a particular simulated attack, some countermeasure detectors may output alarm signals, while others may not. Countermeasure detectors that output alarm signals may be considered to have responded to the attack, while other countermeasure detectors may be considered to have not responded. As described above, determining that a countermeasure detector did not respond to the attack may be an expected outcome of the test.
[0302] Alternatively, the processing circuit 1010 may evaluate the countermeasure detector's responsiveness to different fault injection attacks having different characteristics.
[0303] The processing circuit 1010 may optionally output the analysis results to an external device so as to redesign the integrated circuit 1050 and / or calibrate the countermeasure detector based on the results.
[0304] Optionally, the test apparatus 1000 further includes a base for supporting the integrated circuit under test.
[0305] Method for testing integrated circuit functionality during fault injection attacks
[0306] In certain embodiments of the present invention, an attack simulator may be used to determine how an integrated circuit operates during a simulated attack without using information obtained from a countermeasure detector.
[0307] In some embodiments, during a simulated fault injection attack, an integrated circuit performs one or more operations with observable results (e.g., data levels and / or signal levels). The observed results are compared with expected results. If the observed results match the expected results, the integrated circuit is deemed to be operating normally. If the observed results do not match the expected results, the integrated circuit is deemed to be operating abnormally.
[0308] Many such tests of integrated circuit functionality are known in the art. These tests only need to be performed while simulating a fault injection attack. It is expected that more tests will be developed in the future, such as those that test specific functions of integrated circuits and / or those based on new methodologies and / or new technologies for integrated circuits.
[0309] For example, a program can be run on the integrated circuit to perform computations and / or cryptographic operations. The results during the simulated attack are stored and checked to determine whether the target program executed correctly (e.g., in the expected order or other aspects of integrity) and / or whether the results of the target program are the same as the results of the same program executed without interference. Interference with the integrated circuit can be complex, for example, by running multi-stage attacks, combining multiple attack simulators, etc.
[0310] According to some embodiments of the present invention, an integrated circuit includes at least one of the following types of electronic components:
[0311] 1) Functional elements: Functional elements perform operations that realize the functions of integrated circuits.
[0312] 2) At least one attack simulator, which simulates a fault injection attack on the integrated circuit by applying one or more stimuli to the functional elements and / or related interconnections or power transmission networks according to at least one control signal.
[0313] Optionally, the integrated circuit comprises at least one countermeasure detector for detecting an attack on the integrated circuit (particularly a fault injection attack) and outputting an alarm signal when a fault injection attack is detected.
[0314] An integrated circuit may include other components necessary for its operation, such as electrical interconnects, power supply components, oscillators, interface components, etc.
[0315] Now refer to Figure 11 , is a simplified schematic diagram of an integrated circuit according to an exemplary embodiment of the present invention. Figure 11 It is for illustration purposes only and does not represent actual circuit elements or the interconnections between them. Figure 11 There is no limitation on the number and / or type and / or interconnection of functional elements, detection circuits and attack simulators.
[0316] Integrated circuit 1100 includes:
[0317] a) Functional elements 1110.1 to 1110.4 perform operations that implement integrated circuit functions and can be any type of integrated circuit elements, such as logic functions built from logic gates, microprocessors, analog circuits, memory blocks, etc.
[0318] b) Attack simulators 1130.1 to 1130.3 apply stimuli to simulate fault injection attacks. The attack simulators 1130.1 to 1130.3 may optionally conform to at least one of the above exemplary embodiments.
[0319] Optionally, integrated circuit 1110 includes internal processing circuitry 1160 for performing tasks required for integrated circuit functionality. Additionally, internal processing circuitry 1160 may optionally perform at least a portion of the task of analyzing whether the integrated circuit performs correctly during a simulated fault injection attack.
[0320] Optionally, the integrated circuit 1100 includes an input / output (I / O) interface 1140 for inputting signals to and outputting signals to the integrated circuit 1100. The I / O interface 1140 can be used to output information from the integrated circuit, i.e., / or analysis results from the internal processing circuit 1160, to an external processor 1150, i.e., / or input control signals to an attack simulator.
[0321] The attack simulator optionally simulates a fault injection attack by performing at least one of the following:
[0322] a) applying an electrical stimulus to the functional element;
[0323] b) changing the logic signal in the integrated circuit to the opposite logic level;
[0324] c) shifting the voltage level of a logic signal in the integrated circuit to an opposite logic level;
[0325] d) Interfering with integrated circuit clock signals;
[0326] e) introducing unusual behavior on the power lines; and
[0327] f) Introducing abnormal behavior on the ground wire.
[0328] Now refer to Figure 12 , is a simplified flow chart of a method for testing a fault injection countermeasure detector in an integrated circuit according to an embodiment of the present invention. The integrated circuit includes interconnected functional elements and at least one attack simulator for simulating a fault injection attack.
[0329] The integrated circuit and the interconnected electronic components it contains, such as functional components and attack simulators, may conform to any of the embodiments described herein.
[0330] In operation 1210, the integrated circuit begins operation. The integrated circuit continues to operate during the test process. During operation, the integrated circuit executes a known sequence of program instructions.
[0331] In operation 1220, at least one attack simulator is configured and controlled to simulate a fault injection attack. The attack simulator can be controlled to output different stimuli or stimulus combinations to simulate attacks with different characteristics.
[0332] In operation 1230 , functionality of the integrated circuit during the simulated attack is evaluated to determine whether functionality of the integrated circuit is disrupted by the simulated fault injection attack.
[0333] Examples of IC functional interruptions include but are not limited to
[0334] a) The execution of a sequence of instructions deviates from the orderly execution flow;
[0335] b) The execution time of the instruction sequence is different from the expected time;
[0336] c) Executing forced error instructions, resulting in failure to execute normally; and
[0337] d) produce unexpected results.
[0338] The attack simulator optionally simulates a fault injection attack by performing at least one of the following:
[0339] a) applying an electrical stimulus to the functional element;
[0340] b) changing the logic signal in the integrated circuit to the opposite logic level;
[0341] c) shifting the voltage level of a logic signal in the integrated circuit to an opposite logic level;
[0342] d) Interfering with integrated circuit clock signals;
[0343] e) Introducing abnormal behavior on the power line;
[0344] f) introducing unusual behavior in the ground conductor; and
[0345] g) applying an electromagnetic stimulus to the plurality of functional elements.
[0346] The IC can be optionally installed in an operating device and tested while the device is operating. This allows the IC to be calibrated for each device and for each target application system, rather than testing the IC individually for design and quality assurance purposes.
[0347] In operation 1240 , the evaluation results may be used to calibrate countermeasure circuitry on the integrated circuit.
[0348] The steps for calibrating the countermeasure detector can be based on testing the countermeasure detector itself (e.g. Figure 9 ) and functional testing of integrated circuits during simulated fault injection attacks (e.g. Figure 12 Understanding the countermeasure detector response and IC functionality during a simulated fault injection attack with known signatures (e.g., a known attack simulator setup) allows the countermeasure detector to be calibrated to its most effective setting, where it does not disturb the chip within its safe area but sounds an alarm when a fault injection attack takes the IC out of its safe area.
[0349] Consider the following numerical examples. Testing of the on-board glitch countermeasure detector revealed that it can identify faults that drop 100, 200, 300, or 400 mV below the 1.8V minimum supply voltage. The countermeasure detector can be configured to detect if the supply drops rapidly below 1.7V, 1.6V, 1.5V, or 1.4V. Furthermore, testing of the IC's functionality during a simulated fault injection attack revealed that the IC can withstand the glitch (i.e., maintain functionality) as long as it does not drop below 1.5V.
[0350] The countermeasure detector can be calibrated to detect disturbances of no less than 200 mV. This allows for robust disturbance detection with minimal disturbance to the integrated circuit (as might be the case if the countermeasure detector were calibrated to detect a 100 mV disturbance).
[0351] In operation 1250 , the evaluation results are optionally used to redesign the integrated circuit.
[0352] Test equipment for evaluating integrated circuit functionality during fault injection attacks
[0353] Now refer to Figure 13 , is a simplified schematic diagram of an integrated circuit functional test device according to an embodiment of the present invention. The test device 1300 performs Figure 12 The method includes a processing circuit 1310 and an interface 1320 .
[0354] The processing circuit 1310 may include one or more hardware processors 1330. Optionally, the processing circuit 1310 also includes a memory 1340 for storing software instructions to be executed by the processor 1330 and / or other information, such as specifications of simulated attacks, parameter settings, test result data, etc.
[0355] The interface 1320 provides control signals to the attack simulator and inputs signals from the integrated circuit 1350 .
[0356] Processing circuit 1310 generates control signals for the attack simulator on integrated circuit 1350 and analyzes the signals received from integrated circuit 1350. The analysis results can determine whether the simulated attack disrupts the functionality of the integrated circuit. The characteristics of the simulated attack are determined by the control signals of the attack simulator and can therefore be known or estimated.
[0357] Optionally, the signal is output from the integrated circuit during the simulated attack, or the signal is stored in an internal memory of the integrated circuit and later provided to the test equipment (eg, the equipment instrument extracts the signal from the internal memory before analysis).
[0358] Optionally, during the simulated fault injection attack, at least a portion of the analyzed integrated circuit functionality is performed by internal processing circuitry of the integrated circuit under test.
[0359] Optionally, the testing apparatus 1300 further includes a base for supporting the integrated circuit under test.
Claims
1. An integrated circuit, characterized in that: include: A plurality of interconnected electronic components, wherein the electronic components include: a plurality of functional elements configured to perform the operations of the integrated circuit; at least one countermeasure detector configured to detect a fault injection attack on the integrated circuit, and outputting an alarm signal when the above-mentioned fault injection attack is detected; and At least one attack simulator is associated with the at least one countermeasure detector and is configured to apply stimulation to the functional elements according to at least one control signal to simulate a fault injection attack on the integrated circuit.
2. The integrated circuit according to claim 1, wherein: The above stimulation includes electrical stimulation.
3. The integrated circuit according to claim 2, wherein: At least one parameter of the electrical stimulation is controlled by the control signal.
4. The integrated circuit according to claim 1, wherein: The attack simulator is configured to interfere with a clock signal of the integrated circuit.
5. The integrated circuit according to claim 1, wherein: The attack simulator is configured to cause abnormal behavior on a power line.
6. The integrated circuit according to claim 1, wherein: The attack simulator is configured to cause a ground line to exhibit abnormal behavior.
7. The integrated circuit according to claim 1, wherein: The attack simulator is configured to change a logic signal in the integrated circuit to an opposite logic level.
8. The integrated circuit according to claim 1, wherein: The attack simulator is configured to shift a voltage level of a logic signal in the integrated circuit toward an opposite logic level.
9. The integrated circuit according to claim 1, wherein: The above stimulation includes electromagnetic stimulation.
10. The integrated circuit according to claim 1, wherein: A responsiveness of the at least one countermeasure detector to an attack is adjusted according to a result of a simulated attack.
11. The integrated circuit according to claim 1, wherein: The electronic component includes a plurality of attack simulators, wherein at least two of the attack simulators simulate different types of attacks.
12. The integrated circuit according to claim 1, wherein: At least one of the attack simulators is configured to simulate an attack when the at least one countermeasure detector is disabled.
13. The integrated circuit according to claim 1, wherein: The at least one attack simulator is configured to trigger a single countermeasure detector.
14. The integrated circuit according to claim 1, wherein: The at least one attack simulator is configured to trigger a plurality of countermeasure detectors.
15. The integrated circuit according to claim 1, wherein: The method further includes internal processing circuitry configured to analyze a response of the countermeasure detector to a simulated fault injection attack.
16. The integrated circuit according to claim 1, wherein: The system further includes an interface configured to provide the alarm signal to an external processor for analyzing the performance of the at least one countermeasure detector during the simulation of the fault injection attack.
17. A method for testing a fault injection countermeasure detector of an integrated circuit, characterized in that: include: operating an integrated circuit, the integrated circuit comprising: A plurality of interconnected electronic components, wherein the electronic components include: a plurality of functional elements configured to perform the operations of the integrated circuit; at least one countermeasure detector configured to detect a fault injection attack on the integrated circuit; and at least one attack simulator, associated with the at least one countermeasure detector, configured to simulate a fault injection attack on the integrated circuit by applying stimulation to the plurality of functional elements; and During operation of the integrated circuit, controlling the at least one attack simulator to simulate the fault injection attack; and A determination is made as to whether the at least one countermeasure detector detects the simulated fault injection attack.
18. The method for testing a fault injection countermeasure detector of an integrated circuit according to claim 17, wherein: The method further includes controlling the at least one attack simulator to output different stimuli for a plurality of attack simulators, so as to evaluate the effectiveness of the at least one countermeasure detector against different fault injection attacks.
19. The method for testing a fault injection countermeasure detector of an integrated circuit according to claim 18, wherein: The evaluation is based on respective values of at least one characteristic of the fault injection attack, the characteristic comprising one of an electrical characteristic of the electronic component and an electrical distance between an attack simulator that applies the stimulus and a countermeasure detector that detects the stimulus.
20. The method of testing a fault injection countermeasure detector of an integrated circuit as claimed in claim 17, wherein: The integrated circuit is installed in an operating device, and the method of testing the fault injection countermeasure detector of the integrated circuit is performed during the operation of the operating device.
21. The method for testing a fault injection countermeasure detector of an integrated circuit as claimed in claim 17, wherein: The operations to simulate the above fault injection attack include at least one of the following: applying an electrical stimulus to the plurality of functional elements; changing a logic signal in the integrated circuit to an opposite logic level; Interfering with a clock signal of the integrated circuit; Abnormal behavior on the power line; Unusual behavior on a ground wire; and An electromagnetic stimulus is applied to the plurality of functional elements.
22. The method for testing a fault injection countermeasure detector of an integrated circuit as claimed in claim 17, wherein: The method further includes calibrating the at least one countermeasure detector using the results of a simulated attack.
23. The method for testing a fault injection countermeasure detector of an integrated circuit as claimed in claim 17, wherein: The method further includes simulating an attack by activating at least one attack simulator while disabling all of the countermeasure detectors, and monitoring the function of the integrated circuit during the simulation of the attack, thereby evaluating the susceptibility of the functional elements of the integrated circuit to the fault injection attack.
24. A testing device for testing an integrated circuit, characterized in that: The above-mentioned integrated circuit includes: A plurality of interconnected electronic components, wherein the electronic components include: a plurality of functional elements configured to perform the operations of the integrated circuit; at least one countermeasure detector configured to detect a fault injection attack on the integrated circuit; and at least one attack simulator, associated with the at least one countermeasure detector, configured to apply stimulation to the plurality of functional elements according to at least one control signal to simulate a fault injection attack on the integrated circuit; The above-mentioned test equipment includes: an interface configured to provide a control signal to the at least one attack simulator and obtain an attack detection signal output by the at least one countermeasure detector; and A processing circuit is associated with the interface and configured to generate the control signal to simulate a fault injection attack and analyze the attack detection signal of the countermeasure detector to determine a response of the at least one countermeasure detector to the simulated fault injection attack.
25. The testing device according to claim 24, wherein The simulated fault injection attack includes at least one of the following: applying an electrical stimulus to the plurality of functional elements; changing a logic signal in the integrated circuit to an opposite logic level; Shifting a voltage level of a logic signal in the integrated circuit to an opposite logic level; Interfering with a clock signal of the integrated circuit; This causes a power line to behave abnormally; This causes one ground wire to behave abnormally; as well as An electromagnetic stimulus is applied to the plurality of functional elements.
26. The testing device of claim 24, wherein: The processing circuit is configured to evaluate a responsiveness of the at least one countermeasure detector to different simulated fault injection attacks.
27. The testing device of claim 24, wherein: The processing circuit is configured to output the analysis result to an external component so as to redesign the integrated circuit according to the analysis result.
28. A method for testing the sensitivity of an integrated circuit to a fault injection attack, characterized in that: include: Operating an integrated circuit, the integrated circuit comprising: A plurality of interconnected electronic components, wherein the electronic components include: a plurality of functional elements configured to perform the operations of the integrated circuit; and at least one attack simulator configured to simulate a fault injection attack on the integrated circuit by applying stimulation to the plurality of functional elements; and During operation of the integrated circuit, controlling the at least one attack simulator to simulate the fault injection attack; and A processor is used to evaluate a function of the integrated circuit during the simulation of the fault injection attack to determine whether the simulated fault injection attack will disrupt the function of the integrated circuit.
29. The method for testing the sensitivity of an integrated circuit to a fault injection attack as claimed in claim 28, wherein: The above-mentioned fault injection attack simulated above includes at least one of the following: applying an electrical stimulus to the plurality of functional elements; changing a logic signal in the integrated circuit to an opposite logic level; Interfering with a clock signal of the integrated circuit; Abnormal behavior on the power line; Unusual behavior on a ground wire; and An electromagnetic stimulus is applied to the plurality of functional elements.
30. The method of testing the sensitivity of an integrated circuit to a fault injection attack as claimed in claim 28, wherein: The controlling of the at least one attack simulator includes causing the attack simulator to simulate a fault injection attack detected by at least one countermeasure circuit.
31. The method for testing the sensitivity of an integrated circuit to a fault injection attack as claimed in claim 30, wherein: The method further includes calibrating the countermeasure circuit on the integrated circuit using the evaluation results of the function of the integrated circuit during the simulation of the fault injection attack.
32. The method of testing the sensitivity of an integrated circuit to a fault injection attack as claimed in claim 28, wherein: The method further includes redesigning the integrated circuit using the evaluation results of the function of the integrated circuit during the simulation of the fault injection attack.
33. A device for testing an integrated circuit, characterized in that: The above-mentioned integrated circuit includes: A plurality of interconnected electronic components, wherein the electronic components include: a plurality of functional elements configured to perform the operations of the integrated circuit; and at least one attack simulator, associated with the plurality of functional elements, and configured to apply stimulation to the plurality of functional elements according to at least one control signal to simulate a fault injection attack on the integrated circuit; The above equipment includes: an interface configured to provide control signals to the at least one attack simulator and output signals from the integrated circuit; and A processing circuit is associated with the interface and configured to generate the control signal to simulate the fault injection attack and analyze the signal output from the integrated circuit to identify the simulated fault injection attack for disrupting the function of the integrated circuit.
34. The device for testing an integrated circuit as claimed in claim 33, wherein: The signal is output by the integrated circuit during the simulation of the fault injection attack.
35. The device for testing an integrated circuit as claimed in claim 33, wherein: The above-mentioned fault injection attack simulated above includes at least one of the following: applying an electrical stimulus to the plurality of functional elements; changing a logic signal in the integrated circuit to an opposite logic level; Interfering with a clock signal of the integrated circuit; Abnormal behavior on the power line; Unusual behavior on a ground wire; and An electromagnetic stimulus is applied to the plurality of functional elements.
36. The apparatus for testing an integrated circuit as claimed in claim 33, wherein: The invention further includes an internal processing circuit configured to analyze the function of the integrated circuit during the simulation of the fault injection attack.
Citation Information
Patent Citations
Detection of fault injection attacks using high-fanout networks
US9523736B2