Integrated circuit with tamper-proof protection and method thereof

By introducing tamper sensors and response circuits into the integrated circuits, detecting and preventing electromagnetic pulse fault injection, the tamper threat of the integrated circuit is solved and the data and passwords are ensured.

CN108986857BActive Publication Date: 2025-08-12SILICON LABORATORIES INC
View PDF 8 Cites 0 Cited by

Patent Information

Application Number
CN201810571846.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2017-06-02
Filing Date
2018-05-31
Publication Date
2025-08-12
Estimated Expiration
2038-05-31

AI Technical Summary

Technical Problem

The prior art is difficult to effectively defend against the attacks on integrated circuits by electromagnetic pulse failure injection, especially the tampering threat to password integrated circuits such as smart card controllers, resulting in the leakage of user data and passwords.

Method used

Using a combination of tamper sensors and tamper response circuits, prevent hackers by detecting fault injections in integrated circuits and performing protection operations.

Benefits of technology

Effectively prevent electromagnetic pulse failure injection from interrupting the integrated circuit, protect user data and passwords, and ensure the safety and integrity of the integrated circuit.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN108986857B_ABST
    Figure CN108986857B_ABST
Patent Text Reader

Abstract

An integrated circuit with tamper protection and a method thereof are disclosed. The integrated circuit includes a tamper sensor having multiple state circuits. Each of the multiple state circuits has a corresponding output that provides a corresponding logic state. When operating correctly, the corresponding logic state switches in response to a clock signal. The corresponding logic state fails to switch in response to a corresponding fault injection. The tamper sensor has an output that provides a fault signal in response to a difference in the corresponding logic states of the multiple state circuits. In addition, the integrated circuit includes a protected circuit and a tamper response circuit. The tamper response circuit is connected to the tamper sensor and the protected circuit. The tamper response circuit performs a protection operation to protect the protected circuit in response to the fault signal.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates generally to security circuits and, more particularly, to tamper protection circuits for secure integrated circuits. Background Art

[0002] Hackers attempt to gain access to cryptographic integrated circuits, such as smart card controllers, in an attempt to steal valuable user data, passwords, and the like. One technique hackers use is to inject electrical faults to cause the circuit to malfunction in a way that allows hackers to access the integrated circuit's memory and other resources. Fault injection is a serious threat to secure circuits. There are multiple methods for injecting faults into cryptographic circuits. Among these methods are laser, voltage, and electromagnetic (EM) fault injection. Laser fault injection has become a popular method due to its high spatial and temporal resolution. However, the use of lasers for fault injection has limitations. The increasing number of metal layers used to route signals in chips and evolving countermeasures have increased the inefficiency of laser attacks. Voltage spike injection is also exploited by injecting voltage spikes directly into the substrate of the target integrated circuit. The voltage spike injection produces ground bounces, or voltage drops, relative to the intensity of the spike. EM fault injection via targeted electromagnetic pulses is more commonly used in targeted attacks intended to disrupt the behavior of logic circuits within the integrated circuit.

[0003] Two types of EM injection platforms are known to be installed to introduce faults into circuits. Harmonic EM injection platforms generate sinusoidal EM waves that can be modulated to produce faults. Harmonic EM injection can interfere with the behavior of an integrated circuit's internal clock and bias true random number generators. Additionally, EM pulse (EMP) injection, generated using a high-voltage pulse generator and injector, has been shown to create faults exploitable from a cryptanalytic perspective. EMP injection generates a single but powerful EMP at a desired time and location on a target integrated circuit. This EMP induces a sudden current in the target integrated circuit's power ground network, resulting in a voltage drop, ground bounce, and timing faults. Each of these forms of fault injection is difficult to defend against. As devices become smaller and more ubiquitous in our environment, vulnerability to security vulnerabilities becomes increasingly important and more difficult to address. BRIEF DESCRIPTION OF THE DRAWINGS

[0004] Figure 1 A flow chart illustrating a method for cryptographically authenticating an integrated circuit during an electromagnetic pulse interruption, according to some embodiments.

[0005] Figure 2 Timing diagram showing internal voltage oscillations during electromagnetic fault injection for interrupting logic circuit behavior.

[0006] Figure 3 Diagram showing electromagnetic pulse induced magnetic field in an integrated circuit device.

[0007] Figure 4 A block diagram is shown for hackers to implement Figure 3 The electromagnetic pulse fault injection system of the fault injection.

[0008] Figure 5 Graphically illustrates electromagnetic fault injection glitch analysis.

[0009] Figure 6 An exemplary secure integrated circuit according to some embodiments is shown in block diagram form.

[0010] Figure 7 A hold and setup violation detection circuit is shown in block diagram form in accordance with some embodiments.

[0011] Figure 8 A hold and setup violation detection circuit is shown in block diagram form in accordance with some embodiments.

[0012] Figure 9 A tamper sensor circuit for detecting fault injection in accordance with some embodiments is shown in block diagram form.

[0013] Figure 10 Shown in graphical form Figure 5 and an overlay view of tamper sensor circuit distribution on an integrated circuit according to some embodiments.

[0014] Figure 11 The distribution of tamper sensor circuitry on an integrated circuit layout according to some embodiments is shown in block diagram form.

[0015] In the following description, the same reference numerals are used in different drawings to indicate similar or identical components. Unless otherwise specified, the word "couple" and its associated verb forms include direct and indirect electrical connections by means known in the art, and unless otherwise specified, any description of direct connection also implies an alternative embodiment using an appropriate form of indirect electrical connection. DETAILED DESCRIPTION

[0016] In one embodiment, an integrated circuit includes a tamper sensor having multiple state circuits. Each of the multiple state circuits has a corresponding output that provides a corresponding logic state. When operating correctly, the corresponding logic state switches in response to a clock signal. The corresponding logic state fails to switch in response to a corresponding fault injection. The tamper sensor has an output that provides a fault signal in response to a difference in the corresponding logic states of the multiple state circuits. In addition, the integrated circuit includes a protected circuit and a tamper response circuit. The tamper response circuit is connected to the tamper sensor and the protected circuit. The tamper response circuit performs a protection operation to protect the protected circuit in response to the fault signal.

[0017] In yet another embodiment, a tamper sensor detects fault injection. Each of a plurality of state circuits has a respective output that provides a respective logic state. When the tamper sensor is operating properly, the respective logic state switches in response to a clock signal. The respective logic state fails to switch in response to the respective fault injection. A comparator circuit compares the outputs of the plurality of state circuits. The comparator circuit provides a respective output. A tamper response circuit is connected to a register having an input connected to the output of the comparator circuit. The tamper response circuit is further connected to a clock input for receiving a clock signal and an output that provides a fault signal in response to a difference in the respective logic states of the plurality of state circuits.

[0018] Figure 1 A flow chart of a method 100 for cryptographically authenticating an integrated circuit during an electromagnetic pulse interruption, according to some embodiments, is shown. At block 102, primary firmware development and debug access is delegated to an authorized developer using cryptographic credentials. Cryptographic authentication is performed at block 104. At block 106, a fault injection, such as an electromagnetic (EM) pulse (EMP), is applied to the integrated circuit during cryptographic authentication. Fault injection can also be achieved through voltage and clock glitches. At block 108, a determination is made as to whether the EMP caused an interruption during signature verification. During the signature verification process at block 108, a subsequent EMP is applied at block 110. In response to detecting an EMP of sufficient strength to interrupt the integrated circuit at either block 106 or block 110, the signature is determined to be invalid, and the firmware integrity is protected. In response to the tamper sensor determining that the signature is valid, the firmware boot process continues.

[0019] Figure 2 A timing diagram illustrating internal / local voltage oscillations during EM fault injection for interrupting logic circuit behavior according to some embodiments. Graph 200 shows a waveform 220 of the deviation of the supply voltage (Vdd) from its nominal value (thresholds 210 and 212). The method for inducing a fault in an integrated circuit is to use EMP. Figure 2In the example shown, an EMP is injected at approximately 100 nanoseconds (ns) and causes Vdd to oscillate. When the deviation is outside predetermined limits, the Vdd oscillation results in a timing violation, where threshold 210 specifies an upper limit for a hold violation and threshold 212 specifies a lower limit for a setup violation. As a result of the voltage glitch, the EMP generates a timing failure. Threshold 210 depicts a high Vdd deviation of +50 mV and a low Vdd deviation of -50 mV. A targeted attack intended to use EMP to disrupt logic circuit behavior provides a pulse to an integrated circuit device having a tamper sensor. Thus, an EMP injection that generates a supply voltage deviation greater than threshold 210 (deviation > 50 mV) causes a hold timing failure in the tamper sensor. An EMP injection that generates a supply voltage deviation less than threshold 212 (deviation < -50 mV) causes a hold timing failure in the tamper sensor.

[0020] Figure 3 A diagram illustrating EMP-induced magnetic field distribution in an integrated circuit device according to some embodiments. Diagram 300 shows an EM probe 310 approaching the active surface of an integrated circuit. In one example, an EMP injection produces a strong and sudden magnetic field change in close proximity to a target device and / or a portion of a target device. EMP probe 310 has a single-turn loop with a diameter of 100 micrometers (μm) and induces a magnetic field in the target device that decreases with increasing distance from the injection. As shown in diagram 300, faults caused by EMP probe 310 can be highly localized.

[0021] Figure 4 A block diagram shows an EMP fault injection system 400 according to one embodiment, which can be used to inject Figure 3 EMP fault injection system 400 includes target device 410, power supply 415, host computer system 420, pulse generator 430, and EMP probe 440. Host computer 420 is connected to power supply 415, pulse generator 430, EMP probe 440, and target device 410.

[0022] In one example, a host computer 420 performs an EMP scan on a target device 410. The host computer system 420 is used to provide invalid boot firmware to the target device 410. A pulse generator 430 delivers an EMP to an EMP probe 440 to inject a fault into the target device 410. The EMP probe 440 is a miniaturized EMP injector positioned above the target device 410. Upon receiving a pulse from the pulse generator 430, the EMP probe 440 discharges a capacitor bank into a coil, thereby generating an EMP. The pulse generator 430 waits for a predetermined time (glitch offset) and issues a pulse when a trigger signal is asserted by the target device 410. The host computer system 402 communicates with the target device 410 and monitors its behavior. In one example, the power supply 415 is an interruptible power supply, enabling the host computer system 420 to interrupt power to the target device 420 to force a reboot. In another example, the power supply 415 is a control input that causes the target device 410 to repeat a critical sequence during a boot operation.

[0023] A stepper motor is used to manipulate the target device 410 and / or the EMP probe 440. A voltage pulse of a specific amplitude (e.g., 200V, 8A) is applied to a localized area on the surface of the target device 410 by the EMP probe 440 for a specified duration (e.g., 5 to 100ns). The host computer system 420 initiates an EMP glitch scan on the surface of the target device 410 to generate timing faults during the boot process of the target device 410. In one example, the scan is performed at a fixed glitch offset (time) with a predetermined glitch intensity and duration. Starting from a first position, the target device 410 is reset, the EMP probe 440 applies the EMP, and the host computer system 420 detects the results. The EMP probe 440 is stepped to the next position and the process is repeated. The host computer system 420 continues to monitor the target device 410 to determine when the target device 410 fails to operate correctly during the firmware boot authentication operation, thereby allowing the host computer system 420 to provide instructions that allow the memory on the target device 410 to be read and modified.

[0024] Figure 5 An electromagnetic fault injection glitch analysis according to some embodiments is shown in graphical form. Graph 500 includes glitch results 510, 515, and 520. In one example, similar to Figure 4 The system can be used to provide glitch analysis of the graph 500. The scan is performed on a target device, such as a microcomputer having a Cortex-A8 core processor licensed from Advanced RISC Machines of Cambridge, England, to run the test program. Figure 4) is to inject a fault at a time starting from reset and at a location on the integrated circuit to cause the integrated circuit to fail when performing authentication operations, thereby enabling the delivery of malicious firmware to the target device. The scan begins at the first XY location and continues across the entire surface of the device for a fixed amount of time after reset, which is known as a "glitch offset." The EMP is set to a fixed intensity and duration. These parameters are applied to the target device until the desired behavior is achieved. Region 510 represents an abnormal result, which identifies that the EMP injection produced a glitch that would allow a hacker to interrupt the authentication process. Region 515 represents a non-responding target, and region 520 indicates that the expected result was received.

[0025] Figure 6 An exemplary secure integrated circuit 600 according to some embodiments is shown in block diagram form. Integrated circuit 600 is a protected circuit that includes a microcontroller unit (MCU) 610, one or more tamper sensors 620, flash memory 631, read-only memory (ROM) 632, random access memory (RAM) 633, tamper response circuitry 635, debug interface circuitry 636, and a debug port 650.

[0026] MCU 610 is a processing device connected to ROM 632 and RAM 633. The MCU is also connected to flash memory 631, tamper response circuit 635, and debug interface circuit 636. ROM 632 is a nonvolatile memory used to store firmware associated with the integrated circuit. RAM 633 is used for program data storage. Flash memory 631 is a nonvolatile storage medium that retains data in the absence of power and can be electrically erased and reprogrammed. Blocks of flash memory 631 can be erased, and flash memory 631 can also be erased in its entirety.

[0027] Debug port 650 connects to debug interface circuit 636. Debug interface circuit 636 is an electronic interface that provides access to debug information stored on MCU 610. Debug port 650 simplifies development and debugging of MCU 610; however, debug port 650 can also be used by hackers to gain access to firmware, functionality, and secret data provided by MCU 610, another processor connected to MCU 610, peripheral devices, and / or memory components. A host can manage and query targets associated with debug interface circuit 636 via debug port 650. Debug interface circuit 636 only allows MCU debug access if the debug port provides appropriate cryptographic unlock credentials.

[0028] The tamper response circuit 635 is connected to the debug interface circuit 636, the MCU 610, and the memory blocks (flash memory 631, ROM 632, and RAM 633). The tamper response circuit 635 receives fault signals from the one or more tamper sensors 620 and, in response to the fault signals, performs protection operations to protect the components of the integrated circuit 600. When a fault signal is received from the one or more tamper sensors 620, the tamper response circuit 635 selectively issues a response to the debug interface circuit 636, the MCU 610, or the flash memory 631, thereby identifying a security interrupt to the integrated circuit 600.

[0029] The one or more tamper sensors 620 include a plurality of state circuits, each state circuit having a corresponding output that provides a corresponding logic state. When the logic state is operating correctly, the logic state is switched in response to a clock signal. In response to a fault injection, the logic state of the one or more tamper sensors fails to switch in response to the clock signal. The tamper sensor 620 has an output that provides a fault signal in response to a difference in the corresponding logic states of the plurality of state circuits.

[0030] In operation, integrated circuit 600 provides security functionality, storage of security keys, and / or storage of protected information. Information stored in flash memory 631 is protected by cryptographic authentication operations. During the booting period of integrated circuit 600, one or more tamper sensors 620 detect fault injection and output a fault signal to tamper response circuit 635. Tamper response circuit 635 dynamically provides a response to the fault signal. For example, tamper response circuit 635 can reset integrated circuit 600. In another example, tamper response circuit 635 selectively erases sensitive information from integrated circuit 600. In yet another example, tamper response circuit 635 enables debug interface circuit 636 to disable cryptographic authentication operations and lock access to debug interface circuit 636. In response to one or more tamper sensors 620 detecting a fault injection according to a tamper response policy defined during the manufacturing phase, tamper response circuit 635 erases secrets and / or functionality of integrated circuit 600.

[0031] The one or more tamper sensors 620 detect timing failures caused by fault injection attacks on the integrated circuit. More specifically, the one or more tamper sensors 620 detect hold time violations and setup time violations caused by fault injection attacks.

[0032] Figure 7A tamper sensor 700 according to some embodiments is shown in block diagram form. The tamper sensor 700 includes a hold time violation detection circuit 705 labeled "F" formed using a memory element, such as a clocked D flip-flop 710, a setup time violation detection circuit 715 labeled "S" formed using a memory element, such as a clocked D flip-flop 720, and a delay element 722, an elementwise compare circuit 730, and a clocked D flip-flop 740. The clocked D flip-flop 710 has a D input, a clock input for receiving a signal labeled "CORE CLK," a clear input for receiving a signal labeled "CORE RESET," and an inverting output connected to the D input and labeled " ," thereby forming the hold time violation detection circuit 705. Clocked D flip-flop 720 has a D input connected to delay element 722, a clock input for receiving the CORE CLK signal, a clear input for receiving the CORE RESET signal, and an inverting output connected to delay element 722, thereby forming setup time violation detection circuit 715. Element comparison circuit 730 has a first input connected to the Q (true) output of clocked D flip-flop 710, a second input connected to the Q (true) output of clocked D flip-flop 720, and an output. Clocked D flip-flop 740 has a D input connected to the output of element comparison circuit 730, a clock input for receiving the CORE CLK signal, a clear input for receiving the CORE RESET signal, and an output for providing a signal labeled "FAULT."

[0033] Component comparison circuit 730 detects differences in logic states at the outputs of clocked D flip-flops 710 and 720 that would be encountered after a fault injection, such as an EMP pulse of sufficient magnitude, is applied. Upon receiving the CORE RESET signal, D flip-flops 710 and 720 assume the same logic state, with their Q outputs set to "0." All circuits of tamper sensor 700 share a common clock. If a fault injection is encountered on tamper sensor 700 due to the application of an EMP, a voltage glitch above or below a predetermined limit causes a low hold time violation or a low setup time violation in one (but not the other) clocked D flip-flop. During each clock cycle, component comparison circuit 730 compares the output of clocked D flip-flop 710 with the output of clocked D flip-flop 720. In response to component comparison circuit 730 detecting that fewer than all of the Q outputs of D flip-flops 710 and 720 have the same logic state (in this case, only those two D flip-flops 710 and 720), component comparison circuit 730 outputs a logic high signal to the D input of D flip-flop 740. The D flip-flop 740 registers a logic high on the next rising edge of the CORE CLK signal to provide a FAULT signal to the tamper response circuit 635, thereby detecting a fault condition. The tamper response circuit 635 enables protection operations to be performed.

[0034] By detecting the difference in logic states between the two triggers, the tamper sensor 700 reliably detects the application of EMP in its vicinity and generates a FAULT signal to prevent the EMP from interrupting important operations such as password authentication operations, thereby preventing the integrated circuit from being hacked. Figure 1 In one embodiment not shown or described herein, another tamper sensor may include more than two triggers; tamper sensor 700 is shown as having exactly two.

[0035] Figure 8A tamper sensor 800 according to some embodiments is shown in block diagram form. The tamper sensor includes a hold time violation detection circuit 805 labeled "F" formed using a memory element, such as a clocked D flip-flop 810, a setup time violation detection circuit 815 labeled "S" formed using a memory element, such as a clocked D flip-flop 820, and a delay element 722, an element comparison circuit 830, and a clocked D flip-flop 840. The clocked D flip-flop 810 has a D input, a clock input for receiving a signal labeled "CORE CLK," a clear input for receiving a signal labeled "CORE RESET," and an inverting output " " connected to the D input, thereby forming the hold time violation circuit 805. Clocked D flip-flop 820 has a D input connected to delay element 822, a clock input for receiving the CORE CLK signal, a clear input for receiving the CORE RESET signal, and an inverting output connected to delay element 822 and labeled “ ”, thereby forming setup time violation detection circuit 815. Element comparison circuit 830 has a first input connected to the output of clocked D flip-flop 810, a second input connected to the output of clocked D flip-flop 820, and an output. Clocked D flip-flop 840 has a D input connected to the output of element comparison circuit 830, a clock input for receiving the CORE CLK signal, a clear input for receiving the CORE RESET signal, and an output for providing a signal labeled “FAULT”.

[0036] Similar to the tamper sensor 700 in operation, the element comparison circuit 830 detects the difference in logic states at the outputs of the clocked D flip-flops 810 and 820 that would be encountered after applying a fault injection, such as an EMP pulse of sufficient magnitude. Upon receiving the CORE RESET signal, the D flip-flops 810 and 820 assume the same logic state, with their outputs set to "1." All circuits of the tamper sensor 800 have a common clock. If a fault injection is encountered on the tamper sensor 800 due to the application of an EMP, a voltage glitch signal that is above or below a predetermined threshold causes a low hold time violation or a low setup time violation in one (but not the other) clocked D flip-flop. In each clock cycle, the element comparison circuit 830 compares the output of the clocked D flip-flop 810 with the output of the clocked D flip-flop 820. In response to the element comparison circuit 830 detecting a difference in the logic states of the clocked D flip-flops 810 and 820, the element comparison circuit 830 outputs a logic high signal to the D input of the D flip-flop 740, which registers a logic high to the next rising edge of the CORE CLK signal to provide a FAULT signal to the tamper response circuit 635. The tamper response circuit 635 enables the protection operation to be performed.

[0037] Figure 9 A tamper sensor circuit 900 for detecting fault injection according to some embodiments is shown in block diagram form. Tamper sensor circuit 900 includes a set of tamper sensor circuits, an element comparison circuit 910, a register 930, and a tamper response circuit 635. The set of tamper sensor circuits includes hold time violation detection circuits 705 and 805, and setup time violation detection circuits 715 and 815. Each of the plurality of tamper sensor circuits provides an output signal to element comparison circuit 910. Register 930 has a D input connected to the output of element comparison circuit 910, a clock input for receiving a CORE CLK signal, a clear input for receiving a CORE RESET signal, and an output for providing a signal labeled "FAULT" to tamper response circuit 635. In another example, register 930 is a distinct memory element or sequential storage device for storing binary information.

[0038] Hold time violation detection circuits 705 and 805 and setup time violation detection circuits 715 and 815 are located close to each other on the integrated circuit to detect faults caused by nearby EMPs. During operation, at each clock cycle, F, F', S, and S' are received at element comparison circuit 910. Element comparison circuit 910 compares the logic states from each clock transition. At each clock transition during normal operation, a 0-to-1 transition is expected on one pair of setup and hold time detection circuits, while a 1-to-0 transition is expected on the other pair. Element comparison circuit 910 outputs a 0 to register 930 unless it detects a difference in the expected output of logic states resulting from each clock transition, in which case element comparison circuit 910 outputs a 1. Register 930 captures a 1 on the next rising edge of CORE CLK and holds that 1 until the core is reset.

[0039] Figure 10 Shown in graphical form Figure 5 1032 and the distribution of tamper sensor circuits on an integrated circuit according to some embodiments. Diagram 1000 includes tamper sensor circuit 1010, integrated circuit 1032, and glitch results 1020, 1024, 1030, and 1034. In this embodiment, the tamper sensors (705, 805, 715, and 815) are distributed at a distance less than a predetermined distance relative to the expected fault injection area in the entire integrated circuit 1032. The formed tamper sensor network enables detection of tampering caused by Figure 5 The fault injection analysis shown in FIG. 1 produces glitch results 1020 , 1024 , 1030 , and 1034 .

[0040] Figure 11The distribution of tamper sensor circuitry on an integrated circuit layout according to some embodiments is shown in block diagram form. Layout 1100 includes an integrated circuit 1110, hold time violation detection circuits 705 and 805, and setup time violation detection circuits 715 and 815. The hold time violation detection circuits 705 and 805 and the setup time violation detection circuits 715 and 815 are positioned as a group of unit cells 1102.

[0041] The hold time violation detection circuits 705 and 805 and the setup time violation detection circuits 715 and 815 can be positioned in various configurations throughout the integrated circuit 1110. An advantage of distributing the groups of unit cells 1102 throughout the integrated circuit is the ability to locally detect the corresponding fault injections that trigger low hold time violations or low setup time violations. Alternatively, the hold time violation detection circuits 705 or 805 and the setup time violation detection circuits 715 or 815 can be positioned throughout the integrated circuit as a hold time / setup time violation detection pair (705 and 715, or 805 and 815) or as separate circuits (705, 715, 805, and 815). In another embodiment, the hold time violation detection circuits 705 and 805 and the setup time violation detection circuits 715 and 815 are positioned to protect specific components of the integrated circuit.

[0042] In one specific embodiment, an integrated circuit with tamper protection can be manufactured as follows. First, the integrated circuit is laid out to form a layout such as layout 1100. Typically, an integrated circuit designer provides the netlist of the integrated circuit to a commercially available place-and-route tool, which automatically places the electronic components in the integrated circuit to meet timing requirements. However, the designer indicates the desired location of unit cells 1102 to the place-and-route tool. The method includes defining a set of unit cells 1102, each having a set of state circuits. Each state circuit includes complementary outputs connected to its true input, and also has a clear input, a clock input, and an output. The method includes connecting a reset signal to the clear input of each unit cell 1102 and connecting a clock signal to the clock input of each unit cell 1102. The method includes distributing the unit cells 1102 on the layout, and specifically, separating each unit cell 1102 from adjacent unit cells by a distance corresponding to the gradient of an electromagnetic pulse of a predetermined magnitude. The method includes connecting the output of the set of state circuits to an element comparison circuit, connecting the output of the element comparison circuit to a register, and connecting the output of the register to a tamper response circuit.

[0043] Next, the integrated circuit is manufactured based on the layout. This manufacturing process can be performed using conventional integrated circuit manufacturing processes for complementary metal oxide semiconductor (CMOS) chips. The manufacturing process includes steps such as doping semiconductor wafers to form the active areas of transistors, patterning and etching gate electrodes and electrical interconnect structures, polishing the various layers for planarization, testing the completed integrated circuit die, and packaging the integrated circuit die in an integrated circuit for mounting on a printed circuit board.

[0044] The subject matter disclosed above is intended to be considered illustrative and not restrictive, and the appended claims are intended to cover all such modifications, enhancements and other embodiments that fall within the true scope of the claims. In one embodiment, a basic tamper sensor circuit includes a hold time violation detection circuit and a setup time violation detection circuit. Each circuit detects a corresponding fault injection that triggers a low hold time violation or a low setup time violation, respectively. In one example, the setup time violation circuit and the hold time violation circuit are randomly distributed on the integrated circuit. In another example, the setup time violation circuit and the hold time violation circuit are strategically placed to ensure the security of designated components on the integrated circuit. In an alternative embodiment, the tamper sensor circuit includes paired clusters of setup time violation circuits and hold time violation circuits. In yet another embodiment, the tamper sensor circuit utilizes four clusters. Therefore, to the maximum extent allowed by law, the scope of the present invention will be determined by the broadest interpretation permitted by the appended claims and their equivalents, and shall not be restricted or limited by the above detailed description.

Claims

1. An integrated circuit comprising: a tamper sensor having a plurality of state circuits, each state circuit configured to receive a common clock signal and having a respective output terminal providing a respective logic state, each state circuit switching the respective logic state in response to the clock signal during normal operation and failing to switch the respective logic state in response to a respective fault injection in response to the clock signal, wherein the tamper sensor has an output terminal providing a fault signal in response to a difference in the respective logic states of the plurality of state circuits; protected circuits; as well as A tamper response circuit is coupled to the tamper sensor and the protected circuit, and is configured to perform a protection operation in response to the fault signal to protect the protected circuit.

2. The integrated circuit according to claim 1, wherein: The protected circuitry includes a data processor, and the protection operation includes preventing debug operations.

3. The integrated circuit according to claim 1, wherein: The protection operation also includes providing a memory erase operation to the protected circuit.

4. The integrated circuit according to claim 1, wherein: The protection operation also includes providing an invalidation operation for invalidating a result of the cryptographic authentication operation.

5. The integrated circuit according to claim 1, wherein: The tamper sensor also detects hold time violations.

6. The integrated circuit according to claim 5, wherein: The tamper sensor detects the hold time violation using a first register having a data input and a complementary output coupled to the data input and a true output.

7. The integrated circuit according to claim 1, wherein: The tamper sensor also detects setup time violations.

8. The integrated circuit according to claim 7, wherein: The tamper sensor detects the setup time violation using a register circuit having a register and a delay element having an input coupled to a data input of the register and an output coupled to a complementary input of the register, the register having an output.

9. The integrated circuit according to claim 1, wherein: The tamper sensor comprises: a first register that is responsive to the clock signal to clock and detect hold time violations; a second register responsive to the clock signal to clock and detect setup time violations; a comparison circuit that compares an output of the first register with an output of the second register; and An output register is clocked in response to the clock signal and has a data input coupled to the output of the comparison circuit and an output for providing the fault signal.

10. The integrated circuit according to claim 9, wherein: The comparison circuit receives true outputs of the first register and the second register.

11. The integrated circuit according to claim 9, wherein: The comparison circuit receives complementary outputs of the first register and the second register.

12. The integrated circuit according to claim 9, wherein: The first register and the second register are separated on the integrated circuit by a distance that is less than a predetermined distance associated with an expected fault injection region.

13. The integrated circuit according to claim 9, wherein: The first register and the second register are collocated in four unit cell groups on the integrated circuit for local detection of the corresponding fault injection.

14. The integrated circuit according to claim 13, wherein: The four unit cell groups are distributed in an array across the integrated circuit.

15. The integrated circuit according to claim 1, wherein: The tamper sensor further detects the corresponding fault injection in response to an electromagnetic pulse injection having an absolute value exceeding a predetermined magnitude.

16. The integrated circuit according to claim 1, wherein: The tamper sensor also detects the corresponding fault injection when the corresponding fault injection is introduced through a voltage glitch.

17. The integrated circuit according to claim 1, wherein: The tamper sensor also detects the corresponding fault injection when the corresponding fault injection is introduced by a clock glitch.

18. A tamper sensor for detecting fault injection, comprising: a plurality of state circuits, each state circuit configured to receive a common clock signal and having a respective output terminal providing a respective logic state, each state circuit switching the respective logic state in response to the clock signal during normal operation and failing to switch the respective logic state in response to a respective fault injection; a comparison circuit, the comparison circuit being configured to compare outputs of the plurality of state circuits, wherein the comparison circuit provides a corresponding output; as well as a tamper response circuit coupled to a register having an input coupled to the output of the comparison circuit, a clock input for receiving a clock signal, and an output for providing a fault signal in response to a difference in the corresponding logic states of the plurality of state circuits.

19. The tamper sensor according to claim 18, wherein The plurality of state circuits detect setup time violations and hold time violations in response to the corresponding fault injections.

20. The tamper sensor according to claim 19, wherein The plurality of status circuits are unit cells having a pair of status circuits for detecting the setup time violation and the hold time violation.

21. The tamper sensor of claim 19, wherein The plurality of state circuits are unit cells having state circuit quadrants for detecting the setup time violation and the hold time violation at each clock transition.

22. The tamper sensor of claim 19, wherein: Each of the plurality of state circuits comprises: a first register having a data input and a complementary output coupled to the data input, and a true output for detecting the hold time violation; and A second register circuit having a second register and a first delay element having an input coupled to a data input of the second register, and having an output coupled to a complementary input of the second register, and the second register having an output for detecting the setup time violation.

Citation Information

Patent Citations

  • Tamper-resistant i.c. packaging and approach

    EP1576611B1

  • Temperature tamper detection circuit and method

    EP1788581B1

  • Test mode circuitry for a programmable tamper detection circuit

    US20110148620A1

  • Erase-on-demand memory cell

    US7675066B1

  • Tamper-resistant packaging and approach

    WO2004055918A2