Dynamic safety protection in configurable analog signal chains

By introducing authentication blocks and signal chain integrity blocks into the analog signal chain, the connection between signal chain components is dynamically authenticated, thus solving the security problem of the analog signal chain of IoT nodes and achieving signal chain integrity and security at runtime.

CN113841337BActive Publication Date: 2025-11-21TEXAS INSTRUMENTS INC
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202080036612.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2019-04-05
Filing Date
2020-04-06
Publication Date
2025-11-21
Estimated Expiration
2040-04-06

AI Technical Summary

Technical Problem

In existing technologies, the analog signal chain of IoT nodes lacks dynamic runtime integrity checks, making it vulnerable to intrusion and failure, and lacking the ability to prevent unauthorized data access.

Method used

By introducing authentication blocks and signal chain integrity blocks into the analog signal chain, the connections between signal chain components are dynamically authenticated, forming source-destination pairs. Input authentication and configuration adjustments are performed at runtime to ensure the integrity of the signal chain.

Benefits of technology

It enables dynamic authentication and configuration of signal chains at runtime, preventing the formation of erroneous signal chains, improving the security and integrity of analog signal chains, and reducing security risks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113841337B_ABST
    Figure CN113841337B_ABST
Patent Text Reader

Abstract

A system and method for dynamically defending against security vulnerabilities in a reconfigurable signal chain. The system includes a signal chain formed by at least a first component (201) connected with a second component (202). The first component (201) has a set of source outputs and a first authentication block (221), and the second signal chain component (202) has a set of destination inputs and a second authentication block (222). The system also includes a signal chain configurator that populates the first authentication block (221) with at least one validated endpoint from the set of destination inputs. A signal chain integrity block (210) communicatively coupled with the first authentication block (221) and the second authentication block (222) identifies source-destination pairs from one or more endpoint pairs formed by the at least one validated endpoint and the set of source outputs. The signal chain integrity block (210) propagates the source-destination pairs to the first authentication block (221) and the second authentication block (222). The second authentication block authenticates any received inputs using the source-destination pairs.
Need to check novelty before this filing date? Find Prior Art

Description

BACKGROUND

[0001] The present disclosure relates to dynamically protecting configurable analog signal chains from security vulnerabilities.

[0002] The Internet of Things (IOT) is a network that allows attached devices to interact and exchange data. Security is of utmost importance given the increased sensing and processing load of IoT-enabled devices. Next generation IoT nodes with sensing nodes implement reconfigurable signal chain combinations with multiple analog components, such as analog-to-digital converters (ADCs), digital-to-analog converters (DACs), comparators (COMPs), reference voltages and / or currents (REFs), operational amplifiers (OPAMPS), etc., to ensure that sensing is enabled to the cloud. While there are methods available to protect data originating from analog signal chains using next generation advanced reduced instruction set computer machine (ARM)-based devices, end nodes still lack the ability to prevent faulty signal chain formation or prevent unauthorized access to sensing / actuator data via analog signal chains. Currently, there are no systems or methods available to interact with hardware to perform dynamic run-time integrity checks between signal chain inputs / outputs or across components / input-output pins in a given system on chip (SoC).

[0003] Figure 1 A conventional analog signal chain (100) is generally illustrated that includes an OPAMP (101), an ADC (102), a COMP (103), a DAC (104), and a VRef (105). The COMP (103) receives multiple inputs, namely an input (106) from the OPAMP (101), an input (107) from a source external to the SOC, another input (108) from the DAC (104), and an input (113) from the VRef (105). These connections between the various components of the signal chain (100) are typically wired.

[0004] If any of the components are compromised, the signal chain (100) is susceptible to intrusion and / or malfunction. For example, if the signal chain (100) is implemented in an IoT system where the outputs (109, 110) from the COMP (103) are used as control signals to open a door, the validity of the outputs (109, 110) depends on valid uncompromised inputs. If the DAC (104) output (108) is compromised, the COMP (103) can inadvertently activate the door, introducing a security risk not only in the analog signal chain but possibly in the entire system.

[0005] Because the signal chain (100) is pre-wired and fixed, there is a need to establish signal chain integrity at run-time and / or start-up time. Also, because software reconfigurable signal chains are a new emerging alienation in microcontroller space, there is also a need to reconfigure the analog signal chains locally and remotely. SUMMARY

[0006] A novel aspect of the present disclosure relates to a method for dynamically authenticating a signal chain formed by a set of components including a first component and a second component. In a signal chain formed by at least one first component connected to a second component, the first component includes a set of source outputs and a first authentication block, and the second component includes a set of destination inputs and a second authentication block, one or more validated endpoints are received into the first component. Each of the one or more validated endpoints is associated with a source output from the set of source outputs to form a set of endpoint pairs, and then, a source-destination pair is identified from the set of endpoint pairs. The source-destination pair is propagated to the first authentication block and the second authentication block. At least a portion of the signal chain is authenticated based on the source-destination pair, and a received input is authenticated based on the source-destination pair.

[0007] A novel aspect of the present disclosure also relates to a system for dynamically authenticating a signal chain. The system includes a signal chain formed by at least one first component connected to a second component. The first component has a set of source outputs and a first authentication block, and the second signal chain component has a set of destination inputs and a second authentication block. The system also includes a signal chain populator that populates the first authentication block with at least one validated endpoint from the set of destination inputs. A signal chain integrity block, communicatively coupled with the first authentication block and the second authentication block, identifies a source-destination pair from one or more endpoint pairs formed by the at least one validated endpoint and the set of source outputs. The signal chain integrity block propagates the source-destination pair to the first authentication block and the second authentication block. The second authentication block authenticates any received input using the source-destination pair. BRIEF DESCRIPTION OF DRAWINGS

[0008] Figure 1 A prior art analog signal chain formed by a set of interconnected analog components is explained.

[0009] Figure 2 An exemplary analog signal chain formed by a set of interconnected analog components is explained.

[0010] Figure 3 An exemplary system having an analog signal chain formed by a set of analog components is explained.

[0011] Figure 4 An exemplary comparator in an analog signal chain is depicted.

[0012] Figure 5 An exemplary authentication register for authenticated destination inputs (authenticated endpoints) in a comparator is illustrated.

[0013] Figure 6 An exemplary status register for valid destination inputs (authenticated endpoints) in a comparator is illustrated.

[0014] Figure 7 An exemplary flow diagram for dynamic authentication of an analog signal chain is depicted.

[0015] Figure 8 An exemplary flow diagram for dynamic reset of an analog signal chain is depicted. DETAILED DESCRIPTION

[0016] As used herein, the term "analog component" means an analog design block capable of performing an analog function. Examples of analog components can include the previously mentioned ADC, DAC, COMP, REF, and OPAMP. The term "analog signal chain" refers to a collection of interconnected analog components and, in some examples, to the input-output pins. For example, an analog signal chain can be formed by a COMP connected to a DAC. The term "endpoint" refers to an input to a destination component. In an exemplary analog signal chain formed by a connection between an output (i.e., source output) of a COMP to an input (i.e., destination input) of a DAC, the endpoint is the input to the DAC. An "authenticated endpoint" refers to an endpoint that has been preprogrammed to be valid. In a non-limiting embodiment, the endpoints programmed into an "endpoint table" are authenticated endpoints selected from a set of destination inputs. Examples of endpoint tables are described in more detail in the following paragraphs. An "endpoint pair" refers to a pairing of an authenticated endpoint with its corresponding source output. In an exemplary signal chain formed by a COMP and a DAC, the endpoint pair is the output of the COMP and the input of the DAC. The term "source-destination pair" refers to two signal chain components connected by an endpoint pair. The source-destination pair in the aforementioned example is COMP-DAC.

[0017] Various embodiments are described herein that implement novel aspects of reconfigurable signal chains. For example, one embodiment provides a hardware mechanism and related method to dynamically authenticate signal chain formation at runtime to ensure no snooping vulnerabilities or incorrect signal chain formation. Another embodiment provides a hardware mechanism to confirm at runtime that signal chain components are authorized to negotiate data exchange. In the event of a conflict or invalid authentication, hardware can be enabled to issue a security alert to the system to take necessary recovery actions. Yet another embodiment provides a hardware mechanism to confirm at runtime whether a necessary input / output configuration pair for a signal chain having a direct connection to a module external to the SoC is valid.

[0018] Figure 2Analog signal chain according to illustrative embodiments is generally described. The analog signal chain (200) includes a set of interconnected analog components, namely OPAMP (201), ADC (202), COMP (203), DAC (204), and VRef (205). Connections between components are shown by arrows pointing in the direction from source component to destination component. Note that while analog components are depicted, digital circuitry and digital components can be included in the signal chain (200). Additionally, VRef (205) can be replaced by a reference current IRef. Figure 2 Analog components are depicted, but digital circuitry and digital components can be included in the signal chain (200). Additionally, VRef (205) can be replaced by a reference current IRef.

[0019] Each signal chain component includes an authentication block that facilitates authenticating connections between signal chain components and reconfiguring one or more signal chains (or portions of signal chains) in response to detecting a security threat or error condition. In non-limiting embodiments, the authentication block includes a data register that associates each of the authenticated endpoints with a corresponding source output. An exemplary data register is depicted below in Figure 5 Figure 2 OPAMP (201) has an authentication block (221), ADC (202) has an authentication block (222), comparator (203) has an authentication block (223), DAC (204) has an authentication block (224), and VRef (205) has an authentication block (225). Each authentication block is communicatively coupled to the signal chain integrity block (210) to allow transmission of an output signal (211) and reception of an input signal (212). The output signal (211) provides data to the signal chain integrity block (210) identifying authenticated endpoints associated with a given source output of a signal chain component, and the input signal (212) provides information (e.g., source-destination pairs) that can be used later to authenticate signals and / or reconfigure the signal chain.

[0020] In one embodiment, the authenticated endpoints are programmed into the authentication block from an endpoint table that can be populated by a user. For example, a user can interact with a system configuration tool shown in Figure 3 to identify one or more authenticated endpoints from a set of destination inputs, as well as any corresponding source inputs. An example of an endpoint table is depicted in Table 1, populated with data derived from the system in Figure 3 .

[0021] Table 1. Exemplary endpoint table

[0022]

[0023] Referring to Figure 3 ​DAC (314) includes connectors Dl, D2, D3, and D4, which can be used as source outputs or destination inputs. Likewise, COMP 316 includes connectors Cl, C2, C3, and C4, which can also be used as source outputs or destination inputs. A user populates the first row of the endpoint table, as shown above, by deciding that source output Dl of DAC 314 should be connected to destination input C3 of COMP 316. By identifying C3 as the destination input for Dl, the endpoint is validated. Likewise, a user can specify that source output D3 of DAC 314 should be connected to destination input C4 of COMP 316 and modify the endpoint table as appropriate. The process is repeated for each signal chain component, as necessary. In Table 1, endpoint pairs are formed between source outputs originating from signal chain components and destination inputs; however, in alternative embodiments, the source outputs and / or destination inputs can be general purpose input output (GPIO) pins or fixed function peripheral pins. Additionally, while the endpoint table is described in table format, other data structures can also be implemented.

[0024] In the example of detecting a security vulnerability, a user can invalidate one or more endpoints by deleting from the endpoint table the destination inputs corresponding to the simulation blocks that have a security vulnerability. Modification of the endpoint table results in the ability to reconfigure and reset at least a portion of the signal chain during runtime, which ensures the integrity of the simulation chain.

[0025] The data stored in the endpoint table can be programmed into the individual authentication blocks (221-225) by the drivers assigned to their respective signal chain components. For example, referring again to Figure 3 , DAC driver (304) can program C3 as the validated endpoint (i.e., destination input) for source output Dl. In another embodiment, a single linked driver of the SoC can be responsible for programming the validated endpoints into the individual authentication blocks. Additional details regarding the programming of the authentication blocks are provided in the discussion of Figures 3 to 6 .

[0026] Referring back to Figure 2 , the signal chain integrity block (210) obtains the validated endpoints from each of the signal chain components through its respective output signal (211) and determines the source outputs of each, thereby identifying endpoint pairs. In a non-limiting embodiment, the signal chain integrity block (210) obtains the validated endpoint information from registers, an example of which is shown in Figure 5 . The signal chain integrity block (210) also identifies source-destination pairs from the endpoint pairs and maintains a data structure to store that information. An exemplary data structure maintained by the signal chain integrity block (210) is provided in Table 2 below.

[0027] Table 2. Exemplary Source-Destination Pair Table

[0028]

[0040] Source - Destination

[0041] Endpoint Pair

[0042] DAC - COMP

[0043] D1 - C3, D3 - C4

[0044] COMP - DAC

[0045] C2 - D2, C3 - D4

[0046] ADC - REF

[0047] A1 - R3

[0048] REF - COMP

[0049] R2 - C3, R2 - C4

[0050]

[0051]

[0029] Next, the signal chain integrity block (210) can propagate the source-destination pairs throughout the signal chain. In one embodiment, the source-destination pairs are selectively transmitted to only two components identified in the source-destination pairs; however, in another embodiment, each source-destination pair is transmitted to every signal chain component.

[0030] The authentication block in each of the components stores the source-destination pairs to identify the various source outputs from which its destination input can receive information. When a component receives an input during run-time, the component can determine whether the input is from a valid source and authenticate or reject the input based on the stored source-destination pairs. Thus, in at least one embodiment, the signal chain components authenticate and process inputs received with the authentication block. The signal chain components can notify an application level or software level whether an error was encountered during authentication.

[0031] Figure 3 An extended system (300) is described for dynamic security authentication of an analog signal chain of a signal chain (200) comprising Figure 2 A software layer having a signal chain configurator (301) that maintains an endpoint table (302) that can be populated by a user of a interfacing system configuration tool (303). In non-limiting embodiments, the system configuration tool (300) is maintained separate from the software layer, for example in the cloud.

[0032] The signal chain configurator (301) programs the registers in the authentication blocks of the signal chain components with the verified endpoint of each of its respective source outputs. In the example depicted in Figure 3 In the example depicted in FIG. 3, the signal chain configurator (301) programs each of the various authentication blocks through its respective drivers (304, 305, 306, 307). In at least one example, each of the drivers can be authenticated through a peripheral firewall. The peripheral firewall (310) between the drivers and the analog components can further filter and authenticate the programming of the analog components. Authentication at the peripheral firewall provides another level of security to the analog signal chain.

[0033] Each of the simulation components can authenticate input received on one of its destination inputs during runtime based on the source-destination pair formed by the validated end point received by the component with a corresponding source output. For example, if input (235) is presented to COMP (203) from DAC (204), the authentication block (223) checks if DAC (204) is a valid source component. If DAC (204) is a valid source component, the input is authenticated and processed. In some instances, a source can include multiple inputs and / or an input code. If the received input cannot be authenticated, an error is generated and reported to the application or software layer (not shown). In at least one embodiment, each of the signal chain components authenticates input signals and maintains signal chain integrity during runtime. In some examples, the signal chain components authenticate input signals and maintain signal chain integrity during startup time. In other examples, the signal chain components authenticate output signals rather than input signals during runtime or startup time. Hardware mechanisms operating in conjunction with the authentication blocks can check at runtime if input and output components are allowed to negotiate data exchange. If there is a conflict or invalid authentication, the hardware (simulation components) can issue a security alert to the system application and / or software to take recovery action. In other examples, the authentication blocks will check at runtime if input / output (IO) configuration pairs are valid for external IO pins in the system that are not directly transmitted or received from another component. In some embodiments, the security alert can be provided locally or on a network remotely located from other nodes in the IoT network.

[0034] In another example, the system application and / or software defines an end point table to identify real input signals that are allowed to be configured as inputs to components. In at least one embodiment, the system application and / or software identifies real output signals that are allowed to be used by remaining components in the system. The system application and / or software can configure for different end devices using silicon-based devices with reconfiguration capabilities.

[0035] Figure 4A comparator (400) is illustrated. The comparator (400) includes a pass through on the positive and negative terminals. The pass through is not selected solely based on select signals (402) (IPSEL) and (403) (IMSEL), but is further masked with a MUX signal (401) that authenticates the output (405) of the comparator. If the output (405) is authenticated, the output (405) is processed as needed. Alternatively, if the output (405) cannot be authenticated, an error interrupt condition (404) can be generated and the output (405) can be ignored or discarded. In at least one embodiment, a security error can be detected when a input is received on a destination input during run time that does not correspond to a valid source output. Upon detection of a security error, an interrupt can be generated. In another example, upon detection of a security error, the analog components can be reset and restored. The signal chain configurator can program the authentication block to reconfigure the analog chain during run time upon detection of an error condition. Additionally, the signal chain configurator can program the authentication block to reconfigure the analog chain during start up time.

[0036] The MUX signal (401) can be generated internally in the authentication block based on the destination input and the source output associated with the destination input. Any analog signal chain component can generate a MUX signal that multiplexes the received input with an authentication signal such as the MUX signal (401). Figure 4 A reference voltage generator (406) is also illustrated with inputs further multiplexed with the MUX signal (401) is also illustrated.

[0037] Figure 5 A register (500) of a COMP is generally illustrated with a number of bits programmed to indicate a verified endpoint. For example, bit 6 (513) is the destination input for a DAC. In one embodiment, if the bit reads logic 0, the destination input is a verified endpoint and the connection from the COMP to the DAC is allowed. If the bit reads logic 1, the connection to the DAC is not allowed. Similarly, bit 11 (501) and bit 10 (502) indicate the destination input from other signal chain components connected to the COMP. MUXs can be further generated based on the bits in the register (500). It should be noted that the authentication of the input received on an analog component can be implemented in several ways using digital logic with registers and logic gates.

[0038] Figure 6 A status register (600) in an authentication block in a comparator component is generally illustrated. Reference is made to Figure 4 and 6Both, when the comparator channel selection on the positive and negative terminals is authenticated by the MUX signal (401), the SELAUTH2 (602) and SELAUTH1 (601) bits in the status register (600) read logic 0. When the comparator channel selection on the positive and negative terminals is not authenticated by the MUX signal (401), the SELAUTH2 (602) and SELAUTH1 (601) bits in the status register read logic 1.

[0039] Figure 7 A method (700) of authenticating a signal chain formed of a plurality of analog components is described. In step (701), the method receives one or more authenticated endpoints output by each source into each of the analog components. For example, the signal chain configurator (301) can load destination inputs from the endpoint table (302) into the analog components, such as the DAC (314), the ADC (315), the COMP (316), and the VRef (317).

[0040] In step (702), the method proceeds to collect authenticated endpoints from one or more of the analog components. The signal chain integrity block (320) can collect destination inputs from all sources. In step (703), the method identifies one or more source-destination pairs based on the authenticated endpoints. In one embodiment, the signal chain integrity block (320) collects one or more authenticated endpoints, associates a source output with each of the one or more authenticated endpoints to form an endpoint pair, and identifies a source-destination pair based on the endpoint pair. The data can be stored in a table maintained by the signal chain integrity block (320), an example of which is shown in Table 2.

[0041] In step (704), the method propagates the one or more source-destination pairs to each of the analog signal chain components. The one or more source-destination pairs can be received into an authentication block and stored in a register, such as the register (500) shown in Figure 5 The information stored in the register (500) can be advantageously used to generate signals, such as the MUX signal (401) described in Figure 4

[0042] Next, in step (705), the method authenticates the signal chain based on the one or more source-destination pairs. In step (706), the method authenticates the input received in any analog component based on the one or more source-destination pairs. For example, the input (238) received in the COMP (203) from the OPAMP (201) can be authenticated based on the register bits in the register (500) and the state generated in the status register, such as the status register (600).

[0043] Figure 8 ​is a flowchart of a method (800) for dynamically resetting a signal chain. In step (801), the method polls a status register, such as bit in status register (600). Next, in step (802), the method detects an authentication error. An error is detected when a register bit indicates an error, for example, bit (602) reads 1. Next, in step (803), the method generates an interrupt of the application and / or software layer. Upon detecting an authentication error in step (802), the interrupt signal (404) can be asserted to alert the application and / or software layer. The method can also detect a security breach and automatically generate an interrupt condition of the CPU when not involved in software polling. Next, the method proceeds to step (804) to reset and restore the signal chain. For example, the application layer or software layer can reconfigure the endpoint table and program the authentication block based on the error type and received interrupt. It should be noted that the interrupt routine and reset mechanism can be implemented in one of several ways known in the art. The user can also program a default condition configured to automatically reset the endpoint table to an initialization condition of the overall system and generate an error notification that a security violation has occurred along with a timestamp of the security attack and associated information. The method can propagate the security error to a local application or over a network for recovery action.

Claims

1. A method for security protection, comprising: One or more verified endpoints are received in a signal chain formed by at least one first component connected to a second component, wherein the first component includes a set of source outputs and a first authentication block, wherein the second component includes a set of destination inputs and a second authentication block, and wherein the one or more verified endpoints are selected from the set of destination inputs. Associate each of the one or more verified endpoints with a source output from the group of source outputs to form a set of endpoint pairs; Identify source-destination pairs from the set of endpoint pairs; The source-destination pair is propagated to the first authentication block and the second authentication block; Authenticate at least a portion of the signal chain based on the source-destination pair; and The input received for authentication is based on the source-destination pair.

2. The method according to claim 1, further comprising: An interrupt is generated in response to determining that the received input has not been authenticated.

3. The method according to claim 1, further comprising: Reset one or more components of the signal chain in response to the detection of a security error.

4. The method of claim 1, wherein the group destination input comprises at least two verified endpoints for the first component, the method comprising: At least one second endpoint pair is formed by the group source output and the at least two verified endpoints.

5. The method of claim 1, wherein the signal chain further comprises a third component having at least one of a source output and a destination input, the method further comprising: The third source-destination pair containing the third component will be received in the third authentication block of the third component.

6. The method of claim 5, further comprising: Authentication of at least a second part of the signal chain is based on the third source-destination pair.

7. The method of claim 1, further comprising: In response to a failure to authenticate the signal chain, the signal chain is reconfigured during runtime.

8. The method of claim 1, further comprising: In response to a failure to authenticate the signal chain, the signal chain is reconfigured during startup.

9. A system for security protection, comprising: A signal chain formed by a set of components, wherein the set of components includes at least one first component connected to a second component, wherein the first component has a set of source outputs and a first authentication block, and wherein the second component has a set of destination inputs and a second authentication block; A signal chain configurator that communicates with the first authentication block, wherein the signal chain configurator populates the first authentication block with at least one verified endpoint selected from the group destination input; A signal chain integrity block, which communicates with at least the first authentication block and the second authentication block, wherein the signal chain integrity block is configured to identify source-destination pairs originating from one or more endpoint pairs formed by the at least one verified endpoint and the group source output, and wherein the signal chain integrity block is configured to propagate the source-destination pairs to the first authentication block and the second authentication block; and The second authentication block uses the source-destination pair to authenticate any received input.

10. The system of claim 9, wherein the first authentication block further includes a first programmable register, and wherein the first programmable register stores the at least one verified endpoint and its corresponding source output.

11. The system of claim 9, wherein the signal chain configurator further includes a data structure storing the at least one verified endpoint, and wherein the data structure associates the at least one verified endpoint with a corresponding source output from the group source output.

12. The system of claim 11, wherein the data structure is an endpoint table.

13. The system of claim 9, wherein the group destination input and the group source output are general purpose input / output pins.

14. The system of claim 9, wherein the first component further includes one or more destination inputs, and wherein the second component further includes one or more source outputs.

15. The system of claim 9, wherein the component comprises a third component, and wherein the third component has at least one of a source output and a destination input, and a third authentication block communicating with the signal chain configurator and the signal chain integrity block.

16. The system of claim 9, further comprising a set of drivers configured to program at least the first component using the at least one verified endpoint.

17. The system of claim 16, further comprising a perimeter firewall between the group driver and the group component.

18. The system of claim 9, further comprising a system configuration tool communicatively coupled to the signal chain configurator, wherein the system configuration tool receives user-generated data identifying the at least one verified endpoint.

19. The system of claim 9, wherein the group component includes a comparator configured to receive a set of selection signals and a multiplexer signal that masks the set of selection signals, wherein the multiplexer signal authenticates the output of the comparator.

20. The system of claim 19, wherein the first authentication block and the second authentication block are each configured to generate the multiplexer signal.

Citation Information

Patent Citations

  • Multiplexing of multiple data packets for multiple input / output operations between multiple input / output devices and a channel subsystem having multiple channels

    US6240446B1

  • Switching circuit for checking an analog input circuit of an a-d converter

    WO2019064059A1