System and method for detecting digital continuity tampering
The pseudo-random digital signal generator and comparator circuit in the integrated circuit monitor the conductivity changes of the electronic system and generate tamper detection signals, solving the problem that electronic systems are prone to tampering in the prior art, and achieving efficient tamper detection and correction measures.
Patent Information
- Application Number
- CN202111032765.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2020-11-20
- Filing Date
- 2021-09-03
- Publication Date
- 2025-08-12
- Estimated Expiration
- 2041-09-03
AI Technical Summary
The prior art is difficult to effectively prevent tampering with electronic systems or equipment that are only accessible to authorized personnel, and conventional protection methods are easily compromised.
The pseudo-random digital signal generator and comparator circuit in the integrated circuit are used to monitor the conductivity changes of the electronic system, a tamper detection signal is generated, and an interrupt signal is generated when tampering is detected to trigger the correction action.
It realizes efficient tampering detection of electronic systems, can respond in a timely manner and take corrective measures, and enhances the safety and protection capabilities of the system.
Smart Images

Figure CN114139145B_ABST
Abstract
Description
[0001] Cross-reference to related applications
[0002] This application claims the benefit of U.S. Provisional Application Serial No. 63 / 074,566, filed September 4, 2020, which is incorporated herein by reference in its entirety for all intents and purposes; this application is related to U.S. Non-Provisional Application Attorney Docket No. SLL.0141, entitled “SYSTEM AND METHOD OF LOW POWER SWITCH STATE DETECTION,” filed on the same date as this application. Technical Field
[0003] The present invention generally relates to tamper detection, and more particularly to a system and method for digital continuity tamper detection. Background Art
[0004] It may be necessary to detect tampering with electronic systems or devices that are accessible only to authorized personnel. Examples include metering systems, security systems, security panels, secure computer systems, and point-of-sale (POS) devices. These systems may include enclosures or barriers configured to prevent unauthorized access to sensitive electronic circuits, but such methods are not tamper-proof and can be compromised or otherwise compromised. Summary of the Invention
[0005] An integrated circuit according to a certain embodiment includes: an input terminal and an output terminal; a signal generator circuit that generates a pseudo-random digital signal provided at the output terminal; and a comparator circuit that compares an input signal received via the input terminal with the pseudo-random digital signal to provide a tamper detection signal indicative thereof.
[0006] The signal generator circuit may include a pseudo-random binary sequence generator, or may include a software triggered reloaded linear feedback shift register or other type of pseudo-random generator.The pseudo-random digital signal may include a digital signal having pseudo-random delays between pulses.
[0007] The comparator circuit may include a Boolean logic XOR gate having a first input terminal receiving the pseudo-random digital signal, having a second input terminal receiving the input signal, and having an output terminal providing the detection signal.
[0008] The integrated circuit may further include a buffer circuit and a filter circuit. The comparator circuit may include: a Boolean logic exclusive-OR gate having a first input terminal for receiving a pseudo-random digital signal, a second input terminal for receiving a filtered input signal, and an output terminal for providing a comparison signal; and a trigger having an input terminal for receiving the comparison signal and an output terminal for providing a tamper detection signal. The delay circuit may have an input terminal for receiving a pseudo-random digital signal provided by a signal generator circuit, and an output terminal for providing a delayed pseudo-random digital signal to the exclusive-OR gate, wherein the delay circuit inserts a delay representing a delay from the input terminal of the buffer circuit to the output terminal of the filter circuit, and the trigger is clocked by a delay clock. The integrated circuit may include a control circuit that measures the delay between the output terminal of the signal generator circuit and the output terminal of the filter circuit and programs the delay circuit accordingly. The integrated circuit may include a clock circuit that provides a delayed clock, the measured delay causing the delayed clock to be delayed.
[0009] The integrated circuit may further include: an interrupt circuit that provides an interrupt when the tamper detection signal is provided; and a processing circuit that performs a corrective action in response to the interrupt.
[0010] A method of detecting tampering according to an embodiment includes generating and providing a pseudo-random digital signal at an output terminal; and comparing an input signal received via an input terminal with the pseudo-random digital signal to provide a tampering detection signal indicative thereof.
[0011] The method may include providing a pseudo-random binary sequence. The method may include software triggered reloading of a linear feedback shift register. The method may include providing a digital signal with pseudo-random delays between pulses.
[0012] The method may include performing an exclusive-OR Boolean function between a pseudo-random digital signal and an input signal and providing a comparison signal. The method may include buffering a pseudo-random digital signal provided by a signal generator circuit and providing a corresponding buffered pseudo-random digital signal at an output terminal; filtering the input signal and providing a filtered input signal; performing an exclusive-OR Boolean function between the pseudo-random digital signal and the filtered input signal and providing a comparison signal; and latching the comparison signal to provide a tamper detection signal. The method may include delaying the pseudo-random digital signal and providing a delayed pseudo-random digital signal; and performing an exclusive-OR Boolean function between the delayed pseudo-random digital signal and the filtered input signal. The method may include measuring a delay between the pseudo-random digital signal and the filtered input signal and programming a delay circuit accordingly. The method may include delaying the latching of the comparison signal by the measured delay.
[0013] The method may include: interrupt circuitry that provides an interrupt when the tamper detection signal is provided; and performing a corrective action in response to the interrupt. BRIEF DESCRIPTION OF THE DRAWINGS
[0014] The present invention is illustrated and not limited by the accompanying drawings, in which like reference numerals represent like elements, and in which elements are drawn for simplicity and clarity and are not necessarily drawn to scale.
[0015] Figure 1 is a simplified block diagram of an electronic system including a semiconductor device or integrated circuit (IC) further integrating a continuity tamper detector implemented in accordance with an embodiment of the present disclosure.
[0016] Figure 2 This is a diagram showing an embodiment of the present disclosure. Figure 1 A simplified block diagram showing further details of the continuity tamper detector is shown.
[0017] Figure 3 This is a diagram showing a method implemented according to an embodiment of the present disclosure. Figure 1 A simplified schematic block diagram of at least a portion of an IC illustrating at least a portion of a continuity tamper detector is shown.
[0018] Figure 4 This is a diagram showing an embodiment of the present disclosure. Figure 3 A timing diagram illustrating the operation of the continuity tamper detector is shown.
[0019] Figure 5 This is a diagram showing an embodiment of the present disclosure. Figure 3 A flow chart illustrating the operation of a continuity tamper detector is shown. DETAILED DESCRIPTION
[0020] Figure 1 1 is a simplified block diagram of an electronic system 100 including a semiconductor device or integrated circuit (IC) 102, which further integrates a continuous tamper detector 104 implemented according to an embodiment of the present disclosure. IC 102 is shown as part of an electronic circuit 106 intended for limited access. Electronic circuit 106 may include or may be implemented in whole or in part on a printed circuit board (PCB) 107 or the like, to which IC 102 is mounted. As will be appreciated by those skilled in the art, additional semiconductor devices, ICs, and other electronic circuits and devices may be mounted on PCB 107 and coupled together via wires, conductors, traces, and the like. Electronic system 100 may be, for example, a metering system, a security system, a security panel, a secure computer system, a point-of-sale (POS) device, and the like.
[0021] In the illustrated embodiment, the electronic circuit 106 is contained within an enclosure 108, which can be configured to protect or isolate the electronic circuit 106 and prevent unauthorized access. The enclosure 108 can be tamper-resistant and implemented or configured as a barrier that prevents or at least inhibits access to the electronic circuit 106 contained therein. In alternative embodiments, the enclosure 108 can provide only minimal protection or no protection at all.
[0022] The enclosure 108 shown is depicted in a simplified format and may, for example, include a conductive chassis 110 electrically connected to a conductive cover 112, such as a door or lid. The chassis 110 and the cover 112 are configured to disconnect conductivity in the event of unauthorized access. Additionally or alternatively, a normally closed switch 114 may be provided and strategically positioned so that it disconnects in the event of unauthorized access. Additionally or alternatively, a pair of electrical contacts 116, individually shown as contact C1 and contact C2, may be electrically coupled together and strategically positioned so that contacts C1 and C2 are disconnected from each other in the event of unauthorized access. The switch 114 and / or contacts 116 may, for example, be provided on a lock, a handle latch, a hinge, etc., and positioned to open a circuit in the event of unauthorized access. Additionally or alternatively, at least one conductive trace 118 may be provided on the PCB 107 and configured or positioned to open or disconnect in the event of unauthorized access. Any of these connection methods may be included and / or replicated in different configurations, such as multiple switches, multiple contacts, multiple conductive traces, etc.
[0023] In the illustrated embodiment, IC 102 integrates a continuous tamper detector 104. IC 102 can be configured as a dedicated tamper device, or can incorporate other primary or secondary circuits and / or functions of electronic circuit 106. For example, although not explicitly shown, IC 102 can include the primary processing functions of electronic circuit 106, such as one or more microprocessors, microcontrollers, microcontroller units (MCUs), central processing units (CPUs), etc., or IC 102 can include the measurement functions of a metering device, or IC 102 can include communication circuitry, such as any type of wired or wireless communication. In other words, IC 102 can be a dedicated tamper device, or continuous tamper detector 104 can be provided on any of one or more semiconductor devices or ICs of electronic circuit 106.
[0024] As further described herein, the continuity tamper detector 104 monitors the electronic system 100 for tamper detection by monitoring the conductivity of selected portions of the electronic system 100. The conductive portions and / or traces are selected or otherwise configured to be disconnected, broken, or otherwise compromised during tampering activity detected by the continuity tamper detector 104. In the event of tamper detection, the continuity tamper detector 104 generates a tamper signal to a control circuit, etc., which in turn may generate a non-maskable interrupt signal, etc., to a processing circuit. The processing circuit may take remedial or corrective action, such as disabling critical functions, erasing the stored contents of a memory, sounding an alarm, sending a tamper message to an authorized entity, etc.
[0025] In the illustrated configuration, the continuity tamper detector 104 includes one or more ports for interfacing with corresponding components or portions of the electronic system 100 for tamper detection. As shown, the continuity tamper detector 104 includes four ports, A, B, C, and D, but it should be understood that any number of ports greater than zero may be included. Each of ports A through D of the continuity tamper detector 104 is coupled to a corresponding pair of pins or pads on the IC 102. As shown, for example, port A interfaces with pins 1 and 2 of the IC 102, port B interfaces with pins 3 and 4, port C interfaces with pins 5 and 6, and port D interfaces with pins 7 and 8. Pin 1 electrically interfaces with the chassis 110, while pin 2 electrically interfaces with the cover 112 to detect, for example, the opening of a door or the removal of a lid. Pin 3 couples to one terminal of a switch 114, and pin 4 couples to the other terminal of the switch 114 to detect when the switch 114 is open, such as by detecting manipulation of a hinge, latch, or door. Pin 5 is coupled to contact C1 and pin 6 is coupled to contact C2 to detect if and when contacts 116 are disconnected from each other, such as to detect manipulation of a hinge or latch or door, etc. Pin 7 is coupled to one end of conductive trace 117 and pin 8 is connected to the other end thereof to detect tampering with PCB 107, etc.
[0026] Figure 2 is a simplified block diagram illustrating further details of the continuity tamper detector 104 according to an embodiment of the present disclosure. Figure 2 The illustrated continuity tamper detector 104 includes a first tamper sensor 202 coupled to port A, a second tamper sensor 204 coupled to port B, a third tamper sensor 206 coupled to port C, and a fourth tamper sensor 208 coupled to port D. Although the continuity tamper detector 104 includes four ports, the continuity tamper detector 104 may include any other number of ports, less than or greater than four. Port A includes an output pad AO and an input pad AI, port B includes an output pad BO and an input pad BI, port C includes an output pad CO and an input pad CI, and port D includes an output pad DO and an input pad DI.
[0027] Conductive elements are coupled to each of ports A through D of the continuity tamper detector 104. As shown, for example, a first conductive element 212 is coupled between pads AO and AI of port A, a second conductive element 214 is coupled between pads BO and BI of port B, a third conductive element 216 is coupled between pads CO and CI of port C, and a fourth conductive element 218 is coupled between pads DO and DI of port D. The first conductive element 212 may represent a combination of the chassis 110 and the cover 112 coupled to pins 1 and 2 of the IC 102, the second conductive element 214 may represent a switch 114 coupled between pins 3 and 4 of the IC 102, the third conductive element 216 may represent a contact 116 coupled to pins 5 and 6 of the IC 102, and the fourth conductive element 218 may represent a conductive trace 117 coupled between pins 7 and 8 of the IC 102.
[0028] Each of the tamper sensors 202 , 204 , 206 and 208 includes a signal generator circuit and a corresponding comparator circuit for generating a corresponding one of four tamper detection signals TD_A, TD_B, TD_C and TD_D and providing it to the control circuit 210 . The tamper sensor 202 includes a signal generator circuit A that provides an output signal SAO to the conductive element 212 via the output pad AO, and the comparator circuit A receives the corresponding input signal SAI via the input pad AI. The tamper sensor 204 includes a signal generator circuit B that provides an output signal SBO to the conductive element 214 via the output pad BO, and the comparator circuit B receives the corresponding input signal SBI via the input pad BI. The tamper sensor 206 includes a signal generator circuit C that provides an output signal SCO to the conductive element 216 via the output pad CO, and the comparator circuit C receives the corresponding input signal SCI via the input pad CI. The tamper sensor 208 includes a signal generator circuit D that provides an output signal SDO to the conductive element 218 via the output pad DO, and the comparator circuit D receives the corresponding input signal SDI via the input pad DI.
[0029] The comparator circuit of each of the tamper sensors 202, 204, 206, and 208 compares its output signal with its corresponding input signal to determine and provide a corresponding tamper detection signal. Comparator circuit A compares SAO with SAI to provide TD_A, comparator circuit B compares SBO with SBI to provide TD_B, comparator circuit C compares SCO with SCI to provide TD_C, and comparator circuit D compares SDO with SCI to provide TD_D. In each case, when the input signal matches the output signal, the corresponding tamper detection signal remains de-asserted (e.g., de-asserted to low). In this way, as long as the conductive element 212 remains coupled and conductive, SAO and SAI remain substantially equal, causing comparator circuit A to keep TD_A de-asserted. When the input signal does not match the output signal, such as when the corresponding conductive element is no longer present, the corresponding comparator circuit asserts the corresponding tamper detection signal (e.g., asserts high). For example, if the conductive element 214 is disconnected or no longer conductive, SBO and SBI are no longer substantially equal, causing the comparator circuit B to assert TD_B. The operation of each of the tamper sensors 202, 204, 206, and 208 is substantially the same.
[0030] Each of the output signals SAO, SBO, SCO, and SDO may be a static or DC signal having a selected voltage level. Alternatively, each of the output signals SAO, SBO, SCO, and SDO may be a symmetrical periodic clock signal, etc. However, such a configuration may be easily monitored and circumvented. In one embodiment, each of the signal generator circuits A to D is a pseudo-random generator that generates and outputs a corresponding pseudo-random signal SAO, SBO, SCO, and SDO. Additionally, the pseudo-random signals SAO, SBO, SCO, and SDO are each different, further enhancing tamper resistance.
[0031] The control circuit 210 is coupled to each tamper sensor 202, 204, 206, and 208 via corresponding control signals 220. The control circuit 210 can enable and disable, or activate and deactivate, each tamper sensor 202, 204, 206, and 208 during operation. The control circuit 210 can generate corresponding seed values (SEED values), such as SEED_A, SEED_B, SEED_C, and SEED_D, for the signal generator circuits A through D, respectively. The control circuit 210 can alternatively perform a software-triggered reload. The control circuit 210 can also generate other control signals (not shown) and monitor each tamper sensor 202, 204, 206, and 208 via corresponding sense signals, etc. (not shown). During operation, when one or more of the tamper detection signals TD_A through TD_B are asserted one or more times, the control circuit 210 generates an interrupt signal IRQ to notify local or remote processing circuitry that tampering with the electronic system 100 has been detected.
[0032] Figure 3 is a simplified schematic block diagram of at least a portion of the IC 102 illustrating at least a portion of the continuity tamper detector 104 implemented according to an embodiment of the present disclosure. The continuity tamper detector 104 includes a tamper sensor 302 and a control circuit 304 for a selected port N. The continuity tamper detector 104 may also include a clock circuit 306 and a processing circuit 308, although the clock circuit 306 and / or the processing circuit 308 may be separately provided within the IC 102 or externally provided on a PCB 107, etc. The tamper sensor 302 may represent any one of the tamper sensors 202, 204, 206, or 208, and the port N may represent any one or more of the ports A through D of the continuity tamper detector 104 coupled to a pair of corresponding pins Y and Z of the IC 102. The control circuit 304 may represent the control circuit 210. Additional tamper sensors (not shown) may be included for interfacing with other ports of the continuity tamper detector 104, such as Figure 2 shown.
[0033] Tamper detector 302 includes a signal generator circuit 310, a driver or buffer circuit 312, a filter circuit 314, a two-input Boolean logic exclusive OR (XOR) gate 316, a D-type latch or flip-flop (DFF) 318, and a delay circuit 320. Signal generator circuit 310 generates a pseudorandom signal RDS and provides it to respective inputs of buffer circuit 312 and delay circuit 320. Buffer circuit 312 buffers or drives the RDS signal as an output signal RDS_O via the Y pin of port N. Filter circuit 314 has an input coupled to pin Z to receive input signal RDS_I and provide a corresponding filtered signal RDS_F. A pull-down resistor 315 having a resistance R is coupled between the output of filter circuit 314 and a reference node, such as ground (GND). Delay circuit 320 is programmed by a delay value DEL to delay the RDS signal and provide a corresponding delayed signal RDS_D. RDS_D and RDS_F are provided to respective inputs of an XOR gate 316, the output of which is coupled to the D input of a DFF 318. The non-inverting Q output of the DFF 318 generates a tamper detection signal TD, which is provided to an input of the control circuit 304. TD represents any tamper detection signal of the system, such as TD_A, TD_B, TD_C, and TD_D. Conductive element 322 is shown coupled between pins Y and Z and represents any external conductive tamper detection device, such as the enclosure 108, the switch 114, the contact 116, the conductive trace 118, etc.
[0034] The clock circuit 306 can be configured in any suitable manner to generate one or more clock signals for the IC 102 and / or the continuity tamper detector 104. As shown, the clock circuit 306 generates a clock signal CK that is provided to the signal generator circuit 310, the control circuit 304, and the processing circuit 308. The clock circuit 306 can also be configured to generate a real-time clock (RTC) signal that is shown as being provided to the control circuit 304. The RTC signal can include timestamp information, etc., for identifying the specific date and time each time the TD signal is asserted. As further described herein, the control circuit 304 determines a DEL value, which is then provided to the clock circuit 306 and programs the delay circuit 320. The clock circuit uses the DEL value to provide a delayed clock signal DELCK to the clock input of the DFF 318 to achieve synchronization as further described herein. The control circuit 304 provides a reset signal RST to the DFF 318 to reset the TD signal. The control circuit 304 detects one or more assertions of the TD signal to detect or determine tampering or a tampering event, and generates a corresponding interrupt signal IRQ to the processing circuit 308 .
[0035] Signal generator circuit 310 can be implemented in any suitable manner to provide the RDS signal, such as a pseudo-random binary sequence generator, a linear feedback shift register with software-triggered reload, or the like. Any type of generator that provides a pseudo-random digital signal is contemplated. Signal generator circuit 310 can generate a digital signal with pseudo-random pulses or pseudo-random delays between successive pulses. The SEED value provided by control circuit 304 can be randomly generated to enhance tamper protection.
[0036] The general operation of the continuity tamper detector 104 is described below. The control circuit 304 initially controls the operation of the tamper detector 302, as further described herein, to determine any delay between the RDS signal and the RDS_F signal and accordingly determines DEL to program the delay circuit 320. DEL is also provided to the clock circuit 306 to delay DELCK relative to CK. The control circuit 304 provides the SEED value to the signal generator circuit 310 and then starts the signal generator circuit 310 to output the pseudo-random signal RDS signal. The RDS signal is amplified or otherwise buffered by the buffer circuit 312 to provide the RDS_O output signal from pin Y (or output pin) to the conductive element 322. Assuming that the conductive element 322 is coupled to pins Y and Z and is conductive, the RDS_O output signal is fed back as the RDS_I input signal received via pin Z (or input pin). Filter circuit 314 can be configured as a Schmitt trigger device with hysteresis to filter out spurious fluctuations of RDS_I and provide a filtered input signal RDS_F. Filter circuit 314 drives RDS_F to follow RDS_I unless its input becomes undriven or open, in which case RDS_F is pulled low by resistor 315.
[0037] Delay circuit 320 delays RDS by the corresponding delay from the input of buffer circuit 312 to the output of filter circuit 314 and provides the RDS_D signal as a delayed version of the RDS signal to synchronize timing with the RDS_F signal. Delay circuit 320 is programmed to reduce or minimize any timing differences between RDS_D and RDS_F, despite the possibility of slight delay variations. XOR gate 316 compares RDS_D with RDS_F and provides a comparison signal, CS, to the D input of DFF 318. When there is a small timing difference between RDS_D and RDS_F, CS may exhibit temporary fluctuations during signal transitions. However, DFF 318 is clocked by an inverted version of DELCK, which is delayed relative to CK by approximately the same delay as delay circuit 320. In this way, as long as any timing difference between RDS_D and RDS_F is less than approximately one-half of the DELCK period, the CS signal should remain stable during negative transitions of DELCK to avoid or minimize false tamper detections.
[0038] Assuming the conductive element 322 is present and conductive, indicating the electronic system 100 has not been tampered with, TD remains deasserted low. However, if the electronic system 100 is tampered with, such that the conductive element 322 is removed, damaged, or otherwise open, RDS_F remains pulled low by resistor 315. When RDS_D is next asserted high within at least one DELCK cycle, CS is asserted high and remains high, causing DFF 318 to assert TD high. In one embodiment, the control circuit 304 can be configured to immediately assert the interrupt signal IRQ to the processing circuit 308 upon assertion of TD. In another embodiment, the control circuit 304 can be configured to statistically monitor multiple assertions of TD over time before asserting IRQ.
[0039] The processing circuit 308 can be configured for low-power operation, including a sleep mode, etc. During the sleep mode of the processing circuit 308, the tamper sensor 302 and the control circuit 304 can remain at least partially active to monitor for tamper events. Upon receiving an IRQ, the processing circuit 308 wakes up from its sleep mode (if in sleep mode) and performs remedial or corrective actions, such as disabling critical functions, erasing the stored contents of a memory, sounding an alarm, sending a tamper message to an authorized entity, etc.
[0040] In an alternative embodiment, the delay circuit 320 and DELCK can be omitted, in which case the DFF 318 is clocked by CK. In this case, the frequency of CK and the successive transitions of RDS are sufficiently separated in time relative to CK to ensure that RDS_F is stable in response to the transition of RDS by the next operational transition of CK (e.g., the falling edge of CK) that clocks the DFF 318.
[0041] Figure 4 This is a diagram showing an embodiment of the present disclosure. Figure 3A timing diagram illustrating the operation of the continuity tamper detector 104 in the illustrated configuration. Signals DELCK, RDS_D, RDS_F, and TD are plotted over time. As shown, DELCK switches at a selected frequency and may have a duty cycle of approximately 50%. Signals DELCK and RDS_D are delayed by the same amount relative to CK, so the transitions of RDS_D are essentially synchronized with each other. However, the RDS_D signal is triggered in a pseudo-random manner by signal generator circuit 310. The RDS_F signal follows the RDS_D signal with a slight timing difference. As shown at initial time t0, for example, when RDS_D goes high, RDS_F goes high with a slight delay. This slight delay is emphasized or slightly exaggerated for illustrative purposes. Timing circuit 320 and the DEL value can be configured to minimize the delay between RDS_D and RDS_F. Although not shown, the CS signal may fluctuate with the transitions of the RDS_D and RDS_F signals. However, this slight delay is not a concern as long as the RDS_D and RDS_F signals are stable on the falling edge of DELCK such that the TD signal remains de-asserted low (as shown) and the conductive element 322 remains unchanged.
[0042] At a subsequent time t1, a tamper event occurs, in which the conductive element 322 is removed, damaged, or otherwise disconnected. At this point, RDS_F is pulled low by resistor 315. At a subsequent time t2, when DELCK goes low the next time, RDS_D and RDS_F are sampled in different states, causing the TD signal to go high. When RDS_D and RDS_F are sampled again in different states, the TD signal remains high at time t3. When the RDS_D and RDS_F signals are sampled in the same logic state, the TD signal is low at subsequent times t4 and t5, but TD goes high again at subsequent time t6. Operation continues in this manner, with the TD signal toggling when the conductive element 322 is absent. As previously described, the control circuit 304 can be configured to assert IRQ once TD is sampled high. Alternatively, the control circuit 304 can assert IRQ when TD is sampled high a programmed number of times. The control circuit 304 can also sample the RTC signal each time TD is sampled high to record the timestamp value.
[0043] The pseudorandom signal RDS_D is displayed as a random transition with randomly distributed pulses and pulse widths. In an alternative embodiment, the pseudorandom signal can be a digital signal with random delays between pulses. Thus, the pulses can be randomly distributed over time. The pulses can have a consistent duration or a random duration.
[0044] Figure 5 This is a diagram showing an embodiment of the present disclosure. Figure 3Flowchart of the operation of the continuity tamper detector 104 in the configuration shown. At the first block 502, the IC 102 is powered on or reset (POR), and the IC 102 and the continuity tamper detector 104 are initialized. At the next block 504, the control circuit 304 performs a time measurement, wherein it controls the signal generator circuit 310 to output a timing signal to measure the delay between RDS and RDS_F. The timing signal is not a pseudo-random signal, but rather a periodic clock signal, etc., output as RDS_O, fed through the conductive element 322 and the filter circuit 314, and provided as the RDS_F signal. In this way, the control circuit 304 measures any delay from RDS to RDS_F. In addition, at block 504, the MAX COUNT value is set, as further described herein.
[0045] At the next block 506, a query is made as to whether the measured delay is greater than a pre-programmed or predetermined MAX DELAY value (e.g., >MAX DELAY). If not, the operation proceeds to block 508, where the control circuit 304 sets the DEL value to program the delay circuit 320 and delays the DELCK clock signal by the measured delay. The delay measurement can be performed in any suitable manner, such as using a timer (not shown). At the next block 510, the control circuit 304 provides the SEED value and prompts the signal generator circuit 310 to generate RDS as the corresponding pseudo-random signal. The control circuit 304 may also pulse the RST signal to reset the DFF 318, ensuring that TD is initialized low.
[0046] At the next block 512, a query is made as to whether another time measurement should be performed to update DEL. If not, the operation proceeds to block 514, where a query is made as to whether the TD signal has been asserted. If not, the operation loops between blocks 512 and 514 until another time measurement is to be performed, or until TD is asserted. The time measurement is used to synchronize the RDS_F and RDS_D signals by determining and / or updating DEL and programming the delay circuit 320 accordingly. Over time and any temperature variations, the delays may change, potentially necessitating another time measurement. When another time measurement is performed, as determined at block 512, the operation loops back to block 504. The time measurement may be performed over time to ensure that the delays remain reasonably accurate.
[0047] When it is detected at block 514 that TD has been asserted, operation proceeds to block 516 where the MAX COUNT value is decremented. The MAX COUNT value can be simply set to 1, thereby assuming a tamper event when the TD signal is first asserted. Alternatively, the MAX COUNT value can be set to a value greater than 1 and decremented each time TD is asserted. Operation then proceeds to block 518 where it is checked whether MAX COUNT has been decremented to zero (0). If not, operation loops back to block 512 to continue monitoring the TD signal. When it is determined at block 518 that MAX COUNT has been decremented to zero, operation proceeds to block 520 where the control circuit 304 asserts the IRQ circuit wake-up or otherwise notifies the processing circuit 308 that a tamper event has been detected. The processing circuit 308 can then take corrective or remedial action as previously described.
[0048] Referring back to block 506 , if the measured delay exceeds the MAX DELAY value, then it is determined that the conductive element 322 is not present or has been tampered with, and operation proceeds directly to block 520 , asserting the IRQ and interrupting the processing circuit 308 .
[0049] In an alternative embodiment where the delay circuit 320 is not provided and the DFF 318 is clocked by CK rather than DELCK, a simple continuity test may instead be performed at block 504 to determine the presence of the conductive element 322. If not present, then at block 506, the operation may proceed directly to block 520 to assert the IRQ signal to take any corrective action. Additionally, block 508 is omitted and the operation proceeds to block 510, and the query at block 512 is also omitted. Otherwise, the operation is substantially similar.
[0050] The description is presented to enable one of ordinary skill in the art to make and use the invention within the context of a specific application and corresponding requirements. However, the invention is not intended to be limited to the specific embodiments shown and described herein, but is intended to be consistent with the widest scope consistent with the principles and novel features of the present disclosure. Many other versions and variations are contemplated. It should be understood by those skilled in the art that the concepts and specific embodiments of this disclosure can be readily used as a basis for designing or modifying other structures to provide the same purposes as the present invention without departing from the spirit and scope of the invention.
Claims
1. An integrated circuit comprising: Input terminals and output terminals; a signal generator circuit that generates a pseudo-random digital signal provided at the output terminal; a delay circuit having an input for receiving the pseudo-random digital signal provided by the signal generator circuit and having an output for providing a delayed pseudo-random digital signal; a control circuit that measures a delay between an output of the signal generator circuit and an input signal received via an input terminal and programs the delay circuit accordingly; as well as A comparator circuit compares an input signal received via the input terminal with the delayed pseudo-random digital signal to provide a tamper detection signal indicative of the comparison.
2. The integrated circuit according to claim 1, wherein: The signal generator circuit includes a pseudo-random binary sequence generator.
3. The integrated circuit according to claim 1, wherein: The signal generator circuit includes a linear feedback shift register with software triggered reload.
4. The integrated circuit according to claim 1, wherein: The pseudo-random digital signal comprises a digital signal having pseudo-random delays between pulses.
5. The integrated circuit according to claim 1, wherein: The comparator circuit includes a Boolean logic XOR gate having a first input terminal receiving the pseudo-random digital signal, a second input terminal receiving the input signal, and an output terminal providing the detection signal.
6. The integrated circuit of claim 1 , further comprising: a buffer circuit having an input for receiving the pseudo-random digital signal provided by the signal generator circuit and having an output for providing a corresponding buffered pseudo-random digital signal at the output terminal; as well as a filter circuit having an input coupled to the input terminal and having an output providing an input signal comprising a filtered input signal; Wherein, the comparator circuit comprises: a Boolean logic XOR gate having a first input receiving the delayed pseudo-random digital signal, having a second input receiving the filtered input signal, and having an output providing a comparison signal; and A flip-flop has an input terminal for receiving the comparison signal and an output terminal for providing a tamper detection signal.
7. The integrated circuit according to claim 6, wherein: The delay circuit inserts a delay representing a delay from an input of the buffer circuit to an output of the filter circuit, and wherein the flip-flop is clocked by a delayed clock.
8. The integrated circuit according to claim 7, wherein: The control circuit measures a delay between an output of the signal generator circuit and an output of the filter circuit and programs the delay circuit accordingly.
9. The integrated circuit of claim 8, further comprising a clock circuit providing the delayed clock, the measured delay causing the delayed clock to be delayed.
10. The integrated circuit of claim 1 , further comprising: an interrupt circuit for providing an interrupt when providing the tamper detection signal; as well as Processing circuitry performs corrective action in response to the interrupt.
11. A tamper detection method, comprising: generating and providing a pseudo-random digital signal at an output terminal; measuring a delay between the generated pseudorandom digital signal and an input signal received via an input terminal and determining the measured delay; delaying the pseudo-random digital signal by the measured delay and providing a delayed pseudo-random digital signal; as well as The input signal received via the input terminal is compared with the delayed pseudo-random digital signal to provide a tamper detection signal indicative of the comparison.
12. The method according to claim 11, wherein The generating includes providing a pseudo-random binary sequence.
13. The method according to claim 11, wherein The generating includes software triggered reloading of a linear feedback shift register.
14. The method according to claim 11, wherein The generating comprises providing a digital signal having pseudo-random delays between pulses.
15. The method according to claim 11, wherein The comparing includes performing an exclusive-OR Boolean function between the pseudo-random digital signal and the input signal and providing a comparison signal.
16. The method according to claim 11, further comprising: buffering the pseudo-random digital signal and providing a corresponding buffered pseudo-random digital signal at the output terminal; as well as filtering a signal received by the input terminal and providing the input signal as a filtered input signal; Wherein, the comparison includes: performing an exclusive-OR Boolean function between the pseudo-random digital signal and the filtered input signal and providing a comparison signal; and The comparison signal is latched to provide the tamper detection signal.
17. The method according to claim 16, wherein The performing an exclusive-OR Boolean function includes performing an exclusive-OR Boolean function between the delayed pseudo-random digital signal and the filtered input signal.
18. The method according to claim 17, wherein Measuring the delay includes measuring a delay between the pseudorandom digital signal and the filtered input signal.
19. The method according to claim 18, further comprising: The latching of the comparison signal is delayed by the measured delay.
20. The method of claim 11, further comprising: providing an interrupt when said tamper detection signal is provided; as well as Corrective action is performed in response to the interrupt.
Citation Information
Patent Citations
Tamper detector for secure module
CN103425942A
Security RAM block with multiple partitions
CN106168931A