Frequency manipulation detection for secure time base

By designing a monitoring system in an electronic system to detect the voltage supply of protected circuit blocks, the problem of unauthorized users accessing sensitive information through manipulating time bases is solved, and effective defense against clock manipulation attacks is achieved, ensuring the security of the system.

CN113260995BActive Publication Date: 2025-05-23ARM LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202080007973.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2019-01-10
Filing Date
2020-01-07
Publication Date
2025-05-23
Estimated Expiration
2040-01-07

AI Technical Summary

Technical Problem

When electronic systems are faced with tampering or hacking, unauthorized users may access sensitive information by manipulating the time base, resulting in compromised system security.

Method used

A monitoring system is designed to detect frequency manipulation of the clock signal by voltage supply coupled to the protected circuit block using a voltage detector and a comparator, determine whether the frequency of the safe time base has been tampered with, and output a warning signal.

Benefits of technology

Effectively detect and prevent clock manipulation attacks, ensure that the security of electronic systems is not tampered with, thereby protecting the security of sensitive information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113260995B_ABST
    Figure CN113260995B_ABST
Patent Text Reader

Abstract

The present invention provides an electronic system, which may include: a charge storage device controllably connected to a voltage source; a protected circuit block controllably connected to the charge storage device for receiving a voltage supply from the charge storage device, the protected circuit block operating via an operating clock signal; a voltage detector coupled to the voltage supply of the protected circuit block; a comparator coupled to an output of the voltage detector; and a countermeasure processor coupled to receive an alert signal from the output of the comparator. The voltage at the voltage supply is related to the frequency of the operating clock, and a frequency manipulation attack is detected by monitoring the difference between the voltage supply and the comparison voltage.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to a method of operating an electronic system with frequency manipulation detection, and an electronic system with frequency manipulation detection. Background Art

[0002] Tampering or hacking of electronic systems may enable unauthorized users to access sensitive information. Examples of such sensitive information may be secret key information used in cryptographic engine implementations such as AES (Advanced Encryption Standard). Examples of tampering may include accessing sensitive information by unintended methods (e.g., causing unintended behavior of the system). One technique that an unauthorized user or adversary may use to obtain such sensitive information is to exploit vulnerabilities that exist due to the implementation of the design in an integrated circuit (IC). For example, there may be vulnerabilities that enable an adversary to perform a side channel analysis attack or a fault injection attack.

[0003] This sensitive data needs to be protected from access by an adversary, either encrypted or otherwise. Sometimes an adversary can manipulate or attempt to manipulate the timing of an electronic system to determine sensitive operations such as the function of AES, the sequence of security protocols, or the reading / writing of control bits / status bits. Attempts to manipulate the timing are often referred to as clock manipulation attacks. In this type of attack, an adversary can manipulate the timing with the goal of causing unintended behavior of the system that can be used to compromise the security of the system. Summary of the invention

[0004] The present invention provides frequency manipulation detection of a secure time base. A monitoring system and method for using the monitoring system are described herein, which can be used in an electronic system to monitor a secure time base and determine whether the frequency of the time base relative to the time base has been tampered with. The monitored secure time base may include, but is not limited to, an operating clock of a protected circuit block.

[0005] The monitoring system described herein can detect frequency manipulation of an operating clock. The monitoring system can be part of an electronic system. The electronic system may include a charge storage device controllably connected to a voltage source according to a charging clock signal, a protected circuit block controllably connected to the charge storage device according to the charging clock signal, and a monitoring system. The protected circuit block receives a voltage supply from the charge storage device and operates via an operating clock signal. The monitoring system includes a voltage detector coupled to the voltage supply of the protected circuit block and a comparator coupled to the output of the voltage detector. The monitoring system can determine whether the frequency of the secure time base has been tampered with by determining whether the voltage read from the voltage supply of the protected block satisfies a condition about a threshold amount. For example, the condition can be whether the voltage measured at the voltage supply of the protected circuit block is lower than the comparison voltage by more than a threshold amount, wherein the threshold amount is a preset amount that does not change, a preset amount that can be modified at a later time, or an amount that is dynamically modified based on the context of the operation.

[0006] A method of operating an electronic system with frequency manipulation detection may include: charging a charge storage device (CSD) of a protected circuit block of the electronic system, the CSD providing a voltage supply to the protected circuit block; operating the protected circuit block via an operating clock signal while the CSD provides the voltage supply to the protected circuit block; detecting frequency manipulation of the operating clock signal by: measuring a voltage at the voltage supply provided to the protected circuit block via a voltage detector; and determining whether a difference between the measured voltage and a comparison voltage is greater than a threshold amount; wherein when the difference is greater than the threshold amount, frequency manipulation of the operating clock signal is detected; and when frequency manipulation of the operating clock signal is detected, outputting a warning signal to a countermeasure processor.

[0007] This summary is provided to introduce a series of concepts in a simplified form, which are further described in the detailed description below. This summary is not intended to identify key features or essential features of the claimed subject matter, nor is it intended to be used to limit the scope of the claimed subject matter. BRIEF DESCRIPTION OF THE DRAWINGS

[0008] Figure 1 An exemplary electronic system that may incorporate frequency manipulation detection is shown.

[0009] Figure 2 An exemplary implementation of a secure power domain circuit is shown.

[0010] Figure 3 shows the voltage supply V used to monitor the protected circuit blocks to the safety power domain circuit SPD An exemplary embodiment of a system.

[0011] Figure 4A and Figure 4B shows an exemplary waveform of the safety time base and its dependence on the voltage supply value V SPD impact.

[0012] Figure 5 A method of operating an electronic system with frequency manipulation detection is shown. DETAILED DESCRIPTION

[0013] The present invention provides frequency modulation detection of a secure time base. A monitoring system and method of using the monitoring system are described herein, which can be used in an electronic system to monitor a secure time base and determine whether the frequency modulation of the time base relative to the secure time base has been tampered with.

[0014] The monitoring system and method of using the monitoring system as described herein may be implemented in any electronic system such as an integrated circuit (IC), a system on a chip (SOC), or a board-level system that includes at least one secure timebase.

[0015] Figure 1 An exemplary electronic system that may incorporate frequency manipulation detection is shown. The exemplary electronic system 100 may have a non-secure power domain 102 and a secure power domain 104, where a power domain represents a power supply mechanism for circuits within its domain. That is, the electronic system 100 may include multiple time bases that may or may not be related to each other. For example, the time bases on which the non-secure power domain 102 operates may include, but are not limited to, system clocks such as Sys Clk 1 106 and Sys Clk 2 108. The time bases on which the secure power domain 104 operates may include, but are not limited to, a secure power time base (SPTB) 110 and a cryptographic (Crypto) clock 112, which may be used to control a charge distribution system to provide an isolated power supply for powering sensitive circuits (e.g., a protected circuit block 114).

[0016] An example of a protected circuit block 114 may be a standard cryptographic unit that implements cryptographic operations such as AES. The secure power domain 104 may be derived from the non-secure power domain 102, independent of the non-secure power domain 102, or isolated from the non-secure power domain 102. The protected circuit block 114 may be partially or fully powered on for a period of time or the entire time as part of the secure power domain 104. For example, the secure power domain 104 may include a power supply formed by a protective charge storage device and a control switch that controls the power supply to the protected circuit block 114. In some cases, multiple power supplies (e.g., multiple capacitors forming a capacitor system) may be used to power the secure power domain 104. The output of the capacitor system may become the input of the protected circuit block 114.

[0017] The adversary may attempt to manipulate the operational clock signal during a clock manipulation attack. For example, the adversary may attempt to manipulate the encryption clock 112 during a clock manipulation attack. In this way, the adversary may gain insight into the operational characteristics of the protected circuit block and obtain sensitive information.

[0018] Figure 2 An exemplary implementation of a secure power domain circuit is shown. An electronic system having a secure power domain circuit 200 may include a secure power domain implemented using a charge storage device 202 controllably connected to a voltage source 204 under control of a charging clock signal 206. Although the charge storage device 202 is shown as a capacitor, other devices capable of holding a charge may also be used for the charge storage device 202, depending on the implementation. The voltage source 204 may be internal to the electronic system (e.g., internal to the secure power domain circuit 200 or external to the secure power domain circuit) or external to the electronic system. A protected circuit block 208 may be controllably connected to the charge storage device 202 for receiving a voltage supply V from the charge storage device 202. SPDThe protected circuit block 208 operates via an operating clock signal 210. The operating clock may be a secure time base, for example, an encrypted clock such as a reference clock. Figure 1 Similarly, the charging clock 206 may be a safe power time base, such as a reference Figure 1 The time base 110 is described.

[0019] The charge storage device 202 is controllably connected to the voltage source 204 through a first switch S1 212 (and in some cases a switch (not shown) between the charge storage device 202 and the first voltage line 216). When S1 212 is closed by the charging clock signal 206, the charge storage device is charged. The protected circuit block 208 is controllably connected to the charge storage device 202 through a second switch S2 214 (and in some cases a switch (not shown) on the first voltage line 216 between the charge storage device 202 and at the charge storage device 202). When S2 214 is closed by an inverted signal 206B of the charging clock signal 206 (which may be provided, for example, by an inverter 218), the protected circuit block 208 receives a voltage supply from the charge storage device 202. S1 212 may be controlled by the charging clock signal 206 such that S1 212 opens on one edge (e.g., a positive edge or a negative edge) of the charging clock signal 206 and closes on the opposite edge of the charging clock signal 206. S2 214 receives the inverted signal 206B of the charging clock signal, so that S2 214 is open when S1 212 is closed, and S2 214 is closed when S1 212 is open. The operation of the protected circuit block 208 can cause the charge on the charge storage device to be depleted. In some cases, a switch (not shown) can be provided to partially or completely discharge the charge storage device 202 between charging operations of the charge storage device 202. For example, such a discharge switch can be provided in parallel with the charge storage device 202.

[0020] During the design of an electronic system having the secure power domain circuit 200, a relationship may be established between the charging clock signal 206 and the operating clock signal 210. That is, the frequencies of these two time bases may be designed to have a particular relationship relative to one another such that the charging clock signal provides sufficient coupling of the charge storage device to the power source so that the charge storage device adequately powers the protected blocks during operation controlled by the operating clock signal 210. Thus, if the operating clock 210 is manipulated, for example by speeding up the frequency of the operating clock 210, the effect may be felt relative to the charging clock signal 206 (and more specifically, the sufficiency of the power provided by the charge storage device in the secure power domain).

[0021] As an illustrative example, the voltage supply value V from the charge storage device SPDV is related to the time that the charge storage device 202 has been charged and the time that the charge storage device 202 is coupled to the protected circuit block 208 when the protected circuit block 208 is in operation. The longer the charge storage device 202 is charged before being used by the protected circuit block 208, the greater the V SPD The larger the value of , the greater the charge storage device 202 reaches a saturation limit determined by the physical limitations of the device. The length of time that the charge storage device 202 is charged depends on the frequency of the charging clock signal 206. If the frequency of the charging clock is faster than expected, causing S1212 to switch too quickly, the charge storage device 202 cannot be charged to a level sufficient to power the protected circuit block 208. Therefore, there is an expected voltage value that the voltage supply should be able to supply after charging; and this expected voltage value is based on the above-mentioned relationship between the charging clock signal 206 and the operating clock signal 210.

[0022] In some cases, the relationship between the charging clock signal 206 and the operating clock signal 210 is defined as a preset condition that cannot be modified. This enables the expected voltage value (e.g., a reference value) and / or tolerance (e.g., a threshold amount to still indicate that the expected voltage value is obtained) to be preset. In some cases, the relationship between the charging clock signal 206 and the operating clock signal 210 is defined as a preset condition that can be modified at a later point in time. This results in an adjustable preset for the reference value and / or threshold amount. In some cases, the relationship between the charging clock signal 206 and the operating clock signal 210 is dynamically determined or automatically modified based on the context of the circuit operation. This results in a reference value and / or threshold amount that is automatically adjusted based on the operating context.

[0023] When a relationship is defined as a modifiable or non-modifiable preset condition, the relationship can be established by the circuit designer at the design stage, for example, through the designer's selection of the capacitance of the charge storage device 202, the operating clock frequency 210, the charging clock frequency 206, the power requirements of the protected circuit block 208, or a combination of these design elements. The corresponding preset value of the reference value can be established, for example, using a voltage divider with a set resistor or a programmable resistor (to potentially adjust the reference value). For another example, a register can be written to store the value of the reference value and / or the threshold amount.

[0024] When the relationship is dynamically defined / determined, the control processor may determine or modify the relationship based on the operating context. Examples of operating contexts for automatically determining the relationship may include, but are not limited to: operating mode or functional context; inputs from one or more external or internal sensors such as voltage sensors, temperature sensors, optical sensors, etc.; and time series data such as power changes, command streams, or a series of operations. The reference value and / or the corresponding dynamic value of the threshold amount may be provided by the control processor and stored in a register (or other mechanism for adjusting a voltage divider or for providing a comparison / reference value).

[0025] Clock manipulation attacks can be performed by increasing the voltage supply V SPD and a comparison voltage such as a reference voltage V REF When the frequency of the charging clock signal 206 increases above the threshold, the charging period of the charge storage device 202 will be insufficient to support the power requirements of the protected circuit block 208. Therefore, illegal acceleration may cause a power shortage condition to occur at the input of the protected circuit block 208, and detection of the power shortage condition may result in implementation of countermeasures to protect sensitive information in the protected block.

[0026] Figure 3 shows the voltage supply V used to monitor the protected circuit blocks to the safety power domain circuit SPD An exemplary embodiment of a system. Figure 3 The monitoring system 300 can be used to mitigate potential clock manipulation attacks. The monitoring system 300 can be coupled to a reference Figure 2 The secure power domain circuit 200 described above. The monitoring system 300 can measure a characteristic of the protected circuit block 208 and compare the measured characteristic to a known reference characteristic. The difference between the measured characteristic and the reference characteristic can be used to identify an indication of a frequency manipulation attack. One type of characteristic that the monitoring system can monitor is the voltage supply V to the protected circuit block 208. SPD .

[0027] The monitoring system 300 may include a voltage supply V coupled to the protected circuit block 208. SPD The voltage detector circuit 302, and the output of the voltage detector 302 is coupled to receive V SPD and a comparison voltage such as a reference voltage V REF The comparator 304 of FIG. 304. In some cases, a countermeasure processor 306 may be coupled to receive an alert signal from the output of the comparator 304. The countermeasure processor 306 may be part of the monitoring system or separate from the monitoring system (such that multiple monitoring systems may be coupled to the countermeasure processor). The countermeasure processor 306 may initiate appropriate countermeasures upon receiving the alert signal. Examples of such countermeasures may include, but are not limited to, shutting down operation of a protected circuit block, triggering a response such as a reset condition (e.g., a local reset or a global reset), and / or suspending operation, operation, or function of the target circuit. The countermeasures may be permanent or temporary.

[0028] In some cases, one monitoring system 300 may be used for multiple power domain circuits 200; one or more comparators will be used to compare the voltage value with a reference voltage or even with other voltage supply values.

[0029] A method of detecting frequency manipulation of a secure time base may include measuring a voltage supply of a protected circuit block and comparing the measured voltage supply to a comparison voltage.

[0030] Figure 4A and Figure 4B shows an exemplary waveform of the safety time base and its dependence on the voltage supply value V SPD impact. Figure 4A An exemplary waveform 400 of a secure time base in which no tampering has occurred and V SPD The corresponding voltage curve 402. Figure 4A In the example, V SPD The voltage curve of 402 reaches (and may exceed) the reference value V during the charging cycle (starting from the rising edge and ending at the falling edge). REF . Figure 4B An exemplary waveform 404 of a secure time base in which tampering has occurred and V SPD The corresponding voltage curve 406. Figure 4B In the example, V SPD The voltage curve of 406 is lower than the reference value V REF level, resulting in insufficient power to operate the protected circuit blocks.

[0031] Figure 5 A method of operating an electronic system having frequency manipulation detection is shown. Figure 3 When the electronic system of the monitoring system is described, process 500 may be performed. Process 500 may include charging (502) a charge storage device (e.g., CSD 202) and coupling (504) the CSD (e.g., CSD 202) to a protected circuit block (e.g., protected circuit block 208). For example, when the safety time domain circuit 200 receives an edge (positive edge or negative edge, as determined by the system designer) of the charging clock signal 206, the circuit 200 may charge the charge storage device 202, causing S1 212 to close, coupling the CSD 202 to the voltage source 204 and triggering the CSD 202 to begin charging. The CSD completes charging at the end of the pulse and is coupled to the protected circuit block 208 instead. At Figure 3 In the example shown, switch S2 214 receives the inverted charging clock signal 206B and may therefore close after a slight delay to allow CSD 202 to provide a voltage supply to protected circuit block 208 (as provided by operation 504). CSD 202 may continue to provide a voltage supply to protected circuit block 208 as long as it has charge remaining and switch S2 214 remains closed.

[0032] The protected circuit block 208 may begin operating according to the operating clock signal while the CSD 202 is providing power (506). Although not shown in process 500, the CSD may be decoupled from the protected circuit block and recharged (and even discharged) in operation according to the charging clock signal 206 (and the inverted signal 206B). The operation of monitoring (508) the system for frequency manipulation of the operating clock may be performed during the time when the CSD 202 is providing power to the protected circuit block 208 and the protected circuit block is in operation. The monitoring operation may be performed by using the voltage detector circuit 302 to read the voltage value V of the voltage supply provided to the protected circuit block. SPD The measured voltage can be supplied to V SPD With reference value V REF is compared to determine V SPD With V REF Is the difference between the threshold value within the threshold value? SPD Characteristics such as V SPD The frequency manipulation is detected (510) by determining whether the characteristic of the measured voltage satisfies a frequency modification (FM) condition. The FM condition may be whether the difference between the measured voltage and the comparison voltage is greater than a threshold amount, or whether the measured voltage is lower than the comparison voltage (e.g., V REF or another circuit's V SPD ). If V SPD If the frequency modification (FM) condition is met, an alert signal may be output 512. For example, if the difference is greater than a threshold amount, an alert signal may be transmitted to a countermeasure processor to initiate appropriate countermeasures as described above.

[0033] Thus, the system can detect frequency manipulation of the operating clock signal by measuring the voltage at the voltage supply provided to the protected circuit block via a voltage detector, and determining whether the difference between the measured voltage and the comparison voltage is greater than a threshold amount. Thus, when the difference is greater than the threshold amount, frequency manipulation of the operating clock signal is detected.

[0034] Although the subject matter is described in language specific to structural features and / or actions, it should be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or actions described above. Instead, the specific features and actions described above are disclosed as examples of implementing the claims, and other equivalent features and actions are intended to fall within the scope of the claims.

Claims

1. A method of operating an electronic system having frequency manipulation detection, the method include: charging a charge storage device CSD of a protected circuit block of the electronic system, the CSD providing a voltage supply to the protected circuit block; operating the protected circuit block via an operating clock signal while the CSD provides the voltage supply to the protected circuit block; The frequency manipulation of the operating clock signal is detected by: measuring, via a voltage detector, a voltage at the voltage supply provided to the protected circuit block; as well as determining whether a difference between the measured voltage and a comparison voltage is greater than a threshold amount, wherein the comparison voltage is a measured voltage supplied from another voltage to another protected circuit block operated by a corresponding operation clock signal; wherein said frequency manipulation of said operational clock signal is detected when said difference is greater than said threshold amount; as well as When the frequency manipulation of the operation clock signal is detected, an alert signal is output to a countermeasure processor. The method according to claim 1 , wherein the threshold amount is a preset threshold. The method of claim 1 , wherein the threshold amount is an adjustable preset threshold. The method of claim 1 , wherein the threshold amount is a dynamic threshold that is automatically adjusted based on an operational context. The method of claim 4 , wherein the operating context is an operating mode. The method of claim 4 , wherein the operational context is input from one or more external or internal sensors. 7 . The method according to claim 4 , wherein the operation context is time series data from the group consisting of power variation, command flow, and a series of operations.

8. The method of claim 1, further comprising issuing a temporary or permanent response when the countermeasure processor receives the alert signal.

9. The method of claim 8, wherein the response comprises shutting down operation of the protected circuit block.

10. The method of claim 8, wherein the response comprises triggering a reset condition.

11. The method of claim 8, wherein the responding comprises suspending operation or functionality of the protected circuit block.

12. An electronic system having frequency manipulation detection, include: a charge storage device controllably connected to a voltage source; a protected circuit block controllably connected to the charge storage device for receiving a voltage supply from the charge storage device, and wherein the protected circuit block is operated via an operating clock signal; a voltage detector coupled to the voltage supply of the protected circuit block; a comparator coupled to the output of the voltage detector, wherein the comparator receives a comparison voltage for comparison with a measurement voltage at the output of the voltage detector, the comparator outputs an alert signal when a difference between the measurement voltage and the comparison voltage is greater than a threshold amount, and the comparison voltage is a measurement voltage supplied from another voltage to another protected circuit block operated by a corresponding operation clock signal; and A countermeasure processor is coupled to receive the alert signal from the output of the comparator.

13. The electronic system according to claim 12, further comprising: include: a first switch controllably connecting the charge storage device to the voltage source according to a charging clock signal; and A second switch controllably connects the protected circuit block to the charge storage device according to an inverted signal of the charging clock signal.

14. The electronic system of claim 12, wherein the countermeasure processor issues a temporary or permanent response upon receiving the alert signal, wherein the response comprises at least one of: shutting down operation of the protected circuit block, triggering a reset condition, or suspending operation or function of the protected circuit block.

Citation Information

Patent Citations

  • Method and apparatus for limiting access to an integrated circuit (IC)

    US20140035560A1