A method, apparatus, and system-on-a-chip for defending against voltage error injection attacks.

By detecting voltage changes in the on-chip system to identify voltage error injection attacks and activating a defense protection mechanism in severe cases, the problem of secure boot caused by voltage error injection attacks is solved, thus protecting the boot process and preventing information theft and code tampering.

CN114282213BActive Publication Date: 2026-04-03HYGON INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-12-14
Publication Date
2026-04-03

AI Technical Summary

Technical Problem

Existing technologies are insufficient to effectively defend against voltage error injection attacks, especially during the startup process. Attackers can steal keys or bypass defenses by introducing erroneous results, leading to the tampering of the secure startup code.

Method used

During the CPU startup process of the system-on-a-chip, attacks are identified by detecting voltage changes, and defense protection mechanisms are activated when the severity reaches a certain level, including measures such as powering off or erasing firmware. Voltage detection modules and security processors are used to identify and respond to voltage error injection attacks.

Benefits of technology

It effectively prevents voltage error injection attacks, protects the security of internal CPU information, prevents the theft of confidential information and code tampering, and improves the system's secure boot capability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114282213B_ABST
    Figure CN114282213B_ABST
Patent Text Reader

Abstract

This invention discloses a method, apparatus, and system-on-a-chip (SoC) for defending against voltage error injection attacks. The method includes: detecting changes in the voltage of a set component of the SoC during CPU startup, wherein the set component includes internal CPU modules; identifying the attack situation of the set component based on the detection results; and activating a defense protection mechanism after determining that the set component has been attacked to a preset severity level. This invention can achieve defense against voltage error injection attacks on the SoC.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of information security technology, and in particular to a method, apparatus, and system-on-a-chip for defending against voltage error injection attacks. Background Technology

[0002] Error injection attacks refer to the introduction of errors into cryptographic algorithms or critical steps in cryptographic chips or general-purpose CPUs (central processing units), causing cryptographic devices or general-purpose CPUs to produce incorrect results. The errors can then be analyzed to obtain keys or bypass defenses on the general-purpose CPU.

[0003] The main methods of error injection attacks include:

[0004] a) Glitch Attack

[0005] Attacking a device by disrupting its external voltage or clock is easy to implement, but it cannot target a specific part of the device. Currently, most chips are protected against such attacks by using glitch detectors or DC filters.

[0006] b) Temperature Attack

[0007] By altering the external temperature, the normal operation of the equipment is disrupted, resulting in erroneous results;

[0008] c) Laser attack

[0009] Laser attacks disrupt the normal operation of cryptographic devices by using photons through laser irradiation; they can target specific locations and are the most powerful attack method; since chips are primarily protected on the front and rarely on the back, laser attacks can target the back by irradiating it.

[0010] d) Electromagnetic attack

[0011] Electromagnetic attacks use powerful magnetic fields to interfere with devices; their advantage is that they are inexpensive, but they are not as powerful as laser attacks.

[0012] Types of errors: including permanent errors and temporary errors.

[0013] a) Permanent error

[0014] It is powerful and can be used to attack data (EEPROM, RAM) or code (EEPROM), but it is difficult to implement.

[0015] b) Temporary error

[0016] Interfering with specific operations of the code includes: skipping subroutines, avoiding test, executing code differently, fetching wrong values, and modifying the program counter.

[0017] The main purpose of Secure Boot is to protect the startup code, ensuring its legitimacy and security, and preventing image tampering. To protect the image, the startup code needs to be encrypted / signed. If the code is modified or corrupted by a third party, the image cannot start; only images that have passed authentication can be executed, thus achieving the purpose of Secure Boot.

[0018] Voltage error injection attacks targeting secure boot typically involve injecting errors during the boot process, causing errors in critical steps of the boot program. For example, the final step of signature verification, which should fail, might return as successful due to a voltage error. This allows hackers to forge firmware to boot the system and execute tampered code. Summary of the Invention

[0019] In view of this, embodiments of the present invention provide a method, apparatus and system-on-a-chip for defending against voltage error injection attacks, so as to achieve defense and protection against voltage error injection attacks on the system-on-a-chip.

[0020] In a first aspect, embodiments of the present invention provide a method for defending against voltage error injection attacks, comprising:

[0021] During the CPU startup process of the system-on-a-chip, the change in the voltage of the system-on-a-chip setting components is detected, including the internal modules of the CPU.

[0022] Identify the types of attacks that the specified components have been subjected to based on the detection results;

[0023] The defense protection mechanism is activated after determining that a designated component has been attacked to a preset severity level.

[0024] Optionally, based on the detection results, identify the attack situation of the specified component, including:

[0025] Determine whether the set component has voltage pulse signals that exceed the preset normal conditions or whether the voltage is fluctuating;

[0026] If so, it is determined that the configured component has been attacked.

[0027] Optionally, the method further includes: determining the severity of the attack on the specified component based on the number of attacks and / or the time period of the attacks.

[0028] Optionally, the setting component may also include a security processor.

[0029] Optionally, during the CPU startup process of the on-chip system, changes in the voltage of the on-chip system's setting components are detected, and the attack situation on the setting components is identified based on the detection results, including:

[0030] During the CPU startup process of the system-on-a-chip, the voltage detection module detects changes in the voltage of the system-on-a-chip set components, identifies the attack situation of the set components based on the detection results, and sends the identification results to the security processor.

[0031] After determining that a designated component has been attacked to a preset severity level, a defense protection mechanism is activated, including: the security processor activates the defense protection mechanism after determining that a designated component has been attacked to a preset severity level based on the identification results of the voltage detection module.

[0032] Optionally, activate the defense protection mechanism, including:

[0033] The security processor instructs the CPU to shut down and erase the firmware;

[0034] The security processor is off.

[0035] Secondly, embodiments of the present invention provide an apparatus for defending against voltage error injection attacks, comprising:

[0036] The voltage detection unit is used to detect changes in the voltage of the on-chip system setting components during the CPU startup process of the on-chip system, wherein the setting components include internal modules of the CPU.

[0037] An attack identification unit is used to identify the attack situation of a designated component based on the detection results.

[0038] The defense protection unit is used to activate the defense protection mechanism after determining that a set component has been attacked by a preset severity level.

[0039] Optionally, the attack identification unit is used to identify the attack situation suffered by the designated component based on the detection results, including:

[0040] Determine whether the set component has voltage pulse signals that exceed the preset normal conditions or whether the voltage is fluctuating;

[0041] If so, it is determined that the configured component has been attacked.

[0042] Optionally, the device further includes an attack severity determination unit, used to determine the severity of the attack on the set component based on the number of attacks and / or the time period of the attack.

[0043] Optionally, the setting component may also include a security processor.

[0044] Thirdly, embodiments of the present invention provide a system-on-a-chip, the system including a voltage detection module, wherein:

[0045] During the CPU startup process of the system-on-a-chip, the voltage detection module detects changes in the voltage of the internal modules of the CPU and identifies the attack situation of the internal modules of the CPU based on the detection results.

[0046] After determining that the CPU's internal modules have been attacked to a preset severity level based on the voltage detection module's identification results, the voltage detection module activates a defense protection mechanism.

[0047] Fourthly, embodiments of the present invention provide another system-on-a-chip, the system comprising a central processing unit (CPU), a security processor, and a voltage detection module, wherein:

[0048] During the CPU startup process of the system-on-a-chip, the voltage detection module detects the voltage changes of the internal modules and security processor of the CPU, identifies the attack situation of the internal modules and security processor of the CPU based on the detection results, and sends the identification results to the security processor.

[0049] After determining that the CPU's internal modules and / or the security processor have been attacked to a preset severity level based on the identification results of the voltage detection module, the security processor activates a defense protection mechanism.

[0050] In the technical solution provided by the embodiments of the present invention, voltage error injection attacks on the CPU are identified by detecting changes in the voltage of the internal modules of the CPU. When the attack reaches a certain level, the defense protection mechanism is activated in a timely manner, thereby effectively preventing the risk of stealing internal confidential information by using voltage error injection attacks on the CPU and improving the security of the CPU. Attached Figure Description

[0051] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0052] Figure 1 A flowchart illustrating a method for defending against voltage error injection attacks provided in an embodiment of the present invention;

[0053] Figure 2 A flowchart illustrating a method for defending against voltage error injection attacks, provided as a specific example of the present invention;

[0054] Figure 3 A schematic diagram of a device for defending against voltage error injection attacks provided in an embodiment of the present invention;

[0055] Figure 4 This is a schematic diagram of a system-on-a-chip provided in an embodiment of the present invention. Detailed Implementation

[0056] The embodiments of the present invention will now be described in detail with reference to the accompanying drawings.

[0057] It should be understood that the described embodiments are merely some, not all, of the embodiments of the present invention. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without inventive effort are within the scope of protection of the present invention.

[0058] First, a brief explanation of some of the terms used in the embodiments of this invention will be given.

[0059] SoC: System-on-a-Chip, also known as a system-on-a-chip, is a product, an integrated circuit with a specific purpose, which contains a complete system and all the embedded software.

[0060] PSP: Platform Secure Processor, a dedicated processor in addition to general-purpose processors for managing security policies, with independent RAM (Random Access Memory);

[0061] CCP: Crypto Co-processor, a hardware device specifically designed to process various encryption and decryption algorithms;

[0062] VFI: Voltage Fault Injection

[0063] FIA: Fault Injection Attack

[0064] SecureBoot: Secure Boot refers to the process of verifying the code during startup to prevent the loading of tampered code and protect device security. It typically uses signature verification or hash verification methods.

[0065] Physical attacks: Attacks that require actual contact with the device cannot be launched remotely or solely through software.

[0066] The technical solution of the present invention will be described in detail below.

[0067] See Figure 1 This invention provides a method for defending against voltage error injection attacks, which specifically includes the following steps 101-103.

[0068] Step 101: During the CPU startup process on the SoC, detect changes in the set component voltage of the SoC.

[0069] The setting component, as the detection object, may include internal CPU modules. If the SoC also includes a security processor, the setting component may include both internal CPU modules and the security processor. Typically, the internal CPU modules in the setting component may refer only to the CPU's internal core modules (such as cache, core, etc.), which can be pre-defined by those skilled in the art based on various parameters such as area and power consumption.

[0070] Step 102: Identify the attack situation of the set component based on the detection results.

[0071] In step 102, the specific identification process may involve determining whether the voltage change of the SoC's specified component exceeds a preset normal condition; if so, it is determined that the SoC's specified component has been attacked. For example, it may involve determining whether the SoC's specified component exhibits a voltage pulse signal exceeding a preset normal condition or whether voltage jitter occurs; if so, it is determined that the SoC's specified component has been attacked. When the SoC's specified component includes multiple components, such as multiple modules within the CPU, or at least one module within the CPU and a security processor, the specific determination involves determining whether any of the SoC's multiple components exhibits a voltage pulse signal exceeding a preset normal condition or whether voltage jitter occurs; if so, it is determined that the SoC's specified component has been attacked. Optionally, the attack duration, voltage, CPU clock count, and other attack conditions of the attacked component can be further monitored and recorded for subsequent analysis. The attack duration refers to the duration of the voltage pulse signal exceeding the preset normal condition or the duration of voltage jitter.

[0072] Step 103: After determining that the set component has been attacked by a preset severity level, activate the defense protection mechanism.

[0073] In practice, the severity of the attack on the SoC's designated components can be determined based on the number of attacks and / or whether the attack time falls within the time range during which the CPU processes preset critical instructions. The preset severity level can be set by those skilled in the art based on experience. For example, the defense protection mechanism can be activated only when the attack severity reaches a certain level or higher. The attack severity level is divided according to the number of attacks and / or the time range during which the attacks occur; the more attacks and the longer the attack time falls within the time range during which the CPU processes preset critical instructions, the higher the attack severity level. Alternatively, it can be simply set so that the defense protection mechanism is activated as soon as it is determined that the SoC's designated components have been attacked.

[0074] Furthermore, as a specific implementation, the configuration component of the SoC only includes the internal modules of the CPU, and accordingly, the defense protection mechanism is activated, including:

[0075] Turn off the CPU;

[0076] Alternatively, an MCA (machine check error) interrupt and exception can be generated, and the CPU can respond to this interrupt and exception. In this way, the attack will be recorded in the CPU log, which will facilitate subsequent inspection and auditing.

[0077] In another specific implementation, the configuration component of the SoC includes an internal CPU module and a security processor, and accordingly, a defense protection mechanism is activated, including:

[0078] The security processor instructs the CPU to shut down and erase the firmware; the security processor then shuts down.

[0079] It should be noted that the specific defense protection mechanism adopted can be set according to different usage scenarios, the sensitivity of the data processed by the SoC, and the level of confidentiality.

[0080] Of course, you can also choose not to implement strong defenses against attacks and simply record the attack details.

[0081] Regarding the above solutions, it should be noted that when the SoC's configuration components only include the internal modules of the CPU, steps 101-103 are all executed by the CPU; or, a separate module is deployed independently of the CPU to execute steps 101-103; or, steps 101-102 are executed by a module deployed independently of the CPU while step 103 is executed by the CPU, and so on.

[0082] Similarly, when the configuration components of the SoC include both the CPU internal module and the security processor, steps 101-103 can still be executed by the CPU, or by the security processor, or by a separate module deployed independently of the CPU and the security processor to execute steps 101-103, or by a module deployed independently of the CPU and the security processor to execute steps 101-102 while step 103 is executed by the security processor, and so on.

[0083] In this embodiment of the invention, the entity that executes which step in steps 101-103 above, among the CPU, the security processor, and modules deployed independently of the CPU and the security processor, can be determined based on the structure of the SoC and the usage scenario.

[0084] Typically, when the configuration components of a SoC include internal CPU modules and a security processor, during the CPU startup process of the SoC, changes in the voltage of the configuration components are detected, and the attack status of the configuration components of the SoC is identified based on the detection results. Specifically, this includes:

[0085] During the CPU startup process of the SoC, the voltage detection module detects the voltage changes of the set components of the SoC, identifies the attack situation of the set components of the SoC based on the detection results, and sends the identification results to the security processor.

[0086] The defense protection mechanism is activated after determining that the set component of the SoC has been attacked to a preset severity level, including: the security processor activates the defense protection mechanism after determining that the set component of the SoC has been attacked to a preset severity level based on the identification result of the voltage detection module.

[0087] Based on the above embodiments, a preferred example is provided below. In this example, the SoC includes a CPU and a security processor, as well as a voltage detection module deployed independently of the CPU and security processor. See also Figure 2 This example specifically includes the following steps:

[0088] Step 201: During the CPU startup process, the voltage detection module detects changes in the voltage of the CPU's internal modules and the security processor.

[0089] Step 202: The voltage detection module detects a voltage pulse signal or voltage jitter in any component of the CPU's internal core module or security processor that exceeds the preset normal condition, and determines that it has been attacked.

[0090] Step 203: The voltage detection module sends an interrupt signal to the security processor, wherein the interrupt signal includes: the component under attack, the component voltage, the attack duration, and the CPU clock count;

[0091] Step 204: After receiving the interrupt signal, the security processor executes its internal interrupt handler.

[0092] Step 205: The interrupt handler determines the severity of the attack on the component based on the received interrupt signal and activates the defense protection mechanism corresponding to the severity of the attack.

[0093] Typically, step 205 includes:

[0094] Sub-step 2051: Based on the component voltage and attack duration in the received interrupt signal, determine whether the component is under a real attack or experiencing voltage instability; if so, proceed to sub-step 2052; otherwise, do not enable the defense protection mechanism.

[0095] Sub-step 2052: Based on the attacked component and CPU clock count in the received interrupt signal, determine:

[0096] When a component is severely attacked, it exits the interrupt handler and enters destruction mode: the security processor notifies the CPU to shut down and erases all firmware; the security processor then shuts down.

[0097] When a component is subjected to a non-serious attack, the attack is recorded internally, and the CPU's management program is notified of the attack.

[0098] The determination of a serious attack can be made using any of the following methods:

[0099] The first type is when the component is subjected to continuous attacks, which can specifically be two or more attacks after power-on.

[0100] The second type of attack occurs during the time period when the CPU is processing preset critical instructions. The attack time period is determined by the CPU clock count in the interrupt signal. The specific determination process is existing technology and will not be elaborated here.

[0101] The third type is when the component is subjected to continuous attacks, and the time intervals of N attacks are within the time range when the CPU is processing preset critical instructions. N can be any integer greater than or equal to 1 and less than or equal to the total number of continuous attacks.

[0102] Currently, voltage error injection attacks targeting x86 CPUs primarily aim to bypass Secure Boot, steal firmware encryption keys, and then attack core confidential information stored in the firmware, such as certificate private keys and encryption keys, by tampering with firmware code. Although voltage error injection attacks require physical access to the device, once successful, subsequent attacks can be carried out remotely or via software. For example, if a hacker obtains the certificate private key, they can use it to simulate a confidential computing environment with a company signature and pass remote authentication, thus compromising the entire defense for confidential computing. Similarly, if a hacker obtains the encryption key through a voltage error injection attack, they can use it to decrypt confidential data on other machines, with equally serious consequences. This invention specifically addresses this by embedding a voltage pulse jitter detection module in the SoC and adding interrupt and special processing modules to the secure processor to detect voltage error injection attacks. The firmware code in the secure processor is then analyzed and processed accordingly, effectively preventing the theft of internal confidential information using voltage error injection attacks on the CPU.

[0103] This invention provides an apparatus for defending against voltage fault injection attacks. This apparatus can be used to execute methods for defending against voltage fault injection attacks. The apparatus can be integrated into a smart device with a System-on-a-Chip (SoC), which embeds a CPU. See also... Figure 3 The device specifically includes the following units:

[0104] The voltage detection unit 301 is used to detect changes in the voltage of the SoC setting components during the CPU startup process of the SoC, wherein the setting components include internal modules of the CPU;

[0105] The attack identification unit 302 is used to identify the attack situation of the set component based on the detection results;

[0106] The defense protection unit 303 is used to activate the defense protection mechanism after determining that the set component has been attacked by a preset severity level.

[0107] Furthermore, the attack identification unit 302 is used to identify the attack situation suffered by the set component based on the detection results, including:

[0108] Determine whether the set component has voltage pulse signals that exceed the preset normal conditions or whether the voltage is fluctuating;

[0109] If so, it is determined that the configured component has been attacked.

[0110] Furthermore, the device also includes an attack level determination unit 304, used for:

[0111] The severity of the attack on the specified component is determined based on the number of attacks and / or the time period of the attacks.

[0112] Furthermore, the setting component also includes a security processor.

[0113] The device for defending against voltage error injection attacks provided in this embodiment belongs to the same inventive concept as the aforementioned method embodiment. Technical details not described in this embodiment can be found in the relevant descriptions in the aforementioned method embodiment, and will not be repeated here.

[0114] Furthermore, embodiments of the present invention also provide a system-on-a-chip (SoC), which includes a voltage detection module, wherein:

[0115] During the CPU startup process of the SoC, the voltage detection module detects changes in the voltage of the internal modules of the on-chip system CPU and identifies the attack situation of the internal modules of the CPU based on the detection results.

[0116] After determining that the CPU's internal modules have been attacked to a preset severity level based on the voltage detection module's identification results, the voltage detection module activates a defense protection mechanism.

[0117] It should be noted that the voltage detection module can be located inside the CPU or outside the CPU on the SoC.

[0118] This invention also provides another system-on-a-chip (SoC), see [link to SoC]. Figure 4 The system includes a central processing unit (CPU), a security processor, and a voltage detection module, wherein:

[0119] During the CPU startup process of the SoC, the voltage detection module detects the voltage changes of the internal modules and security processor of the SoC's CPU, identifies the attack situation of the internal modules and security processor based on the detection results, and sends the identification results to the security processor.

[0120] After determining that the CPU's internal modules and / or the security processor have been attacked to a preset severity level based on the identification results of the voltage detection module, the security processor activates a defense protection mechanism.

[0121] Typically, the voltage detection module sends the identification result to the safety processor via a control signal (such as an interrupt signal).

[0122] Furthermore, the SoC also includes SRAM (Static Random-Access Memory) TPM (Trusted Platform Module) firmware, on-chip memory, and a cryptographic coprocessor. These components are all connected to the security processor via an on-chip bus. The CPU calls the security processor to calculate hash commands and query hash values. The security processor loads code from the SRAM TPM firmware, performs hash command calculations by running the code, and can call the cryptographic coprocessor to complete cryptographic calculations during processing. The on-chip memory stores the processing results of the security processor.

[0123] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0124] In this embodiment of the invention, the term "and / or" describes the relationship between associated objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone. The character " / " generally indicates that the preceding and following associated objects have an "or" relationship.

[0125] The various embodiments in this specification are described in a related manner. The same or similar parts between the various embodiments can be referred to each other. Each embodiment focuses on describing the differences from other embodiments.

[0126] In particular, the device embodiment is basically similar to the method embodiment, so the description is relatively simple. For relevant details, please refer to the description of the method embodiment.

[0127] For ease of description, the above apparatus is described by dividing it into various functional units / modules. Of course, in implementing this invention, the functions of each unit / module can be implemented in one or more software and / or hardware.

[0128] Those skilled in the art will understand that all or part of the processes in the above embodiments can be implemented by a computer program instructing related hardware. The program can be stored in a computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. The storage medium can be a magnetic disk, optical disk, read-only memory (ROM), or random access memory (RAM), etc.

[0129] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in the present invention should be included within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be determined by the scope of the claims.

Claims

1. A method for defending against voltage error injection attacks, characterized in that, The method includes: During the CPU startup process of the system-on-a-chip, the voltage detection module detects changes in the voltage of the system-on-a-chip setting components, which include internal CPU modules and a security processor. Based on the detection results, the voltage detection module identifies the attack situation of the set component and sends an interrupt signal to the security processor; the interrupt signal includes: the component under attack, the component voltage, the attack duration, and the CPU clock count; After receiving an interrupt signal, the security processor executes its internal interrupt handler. The interrupt handler determines the severity of the attack on the selected component based on the interrupt signal sent by the voltage detection module and then activates the defense protection mechanism. The severity of the attack is determined as follows: the component is subjected to continuous attacks, and the time interval of N attacks falls within the time range when the CPU processes a preset critical instruction. N can be any integer greater than or equal to 1 and less than or equal to the total number of continuous attacks. The time interval of the attack is determined based on the CPU clock count in the interrupt signal.

2. The method according to claim 1, characterized in that, The detection results identify the types of attacks that the components have been subjected to, including: Determine whether the set component has voltage pulse signals that exceed the preset normal conditions or whether the voltage is fluctuating; If so, it is determined that the configured component has been attacked.

3. The method according to claim 1, characterized in that, Activate the defense protection mechanism, including: The security processor instructs the CPU to shut down and erase the firmware; The security processor is off.

4. A device for defending against voltage error injection attacks, characterized in that, The device includes: The voltage detection unit is used to detect changes in the voltage of the on-chip system setting components during the CPU startup process of the on-chip system, wherein the setting components include the CPU internal modules and the security processor. An attack identification unit is used to identify the attack situation of a set component based on the detection results. The voltage detection module sends an interrupt signal to the security processor. The interrupt signal includes: the component that was attacked, the component voltage, the attack duration, and the CPU clock count. The execution unit is used to execute the internal interrupt handler after the security processor receives an interrupt signal; The defense protection unit is used by the interrupt handler to determine, based on the interrupt signal sent by the voltage detection module, that a set component has been attacked by an attack of a preset severity level and then activate the defense protection mechanism. The severity of the attack is determined as follows: the component is attacked continuously, and the time interval of N attacks falls within the time range when the CPU is processing a preset critical instruction. N can be any integer greater than or equal to 1 and less than or equal to the total number of continuous attacks. The time interval of the attack is determined based on the CPU clock count in the interrupt signal.

5. The apparatus according to claim 4, characterized in that, The attack identification unit is used to identify the attack situation suffered by the designated component based on the detection results, including: Determine whether the set component has voltage pulse signals that exceed the preset normal conditions or whether the voltage is fluctuating; If so, it is determined that the configured component has been attacked.

6. A system-on-a-chip, characterized in that, The system includes a central processing unit (CPU), a security processor, and a voltage detection module, wherein: During the CPU startup process of the system-on-a-chip (SoC), the voltage detection module detects changes in the voltage of the internal modules and security processor of the SoC CPU. Based on the detection results, it identifies the attack situation of the internal modules and security processor of the CPU and sends an interrupt signal to the security processor. The interrupt signal includes: the identified attacked component, the component voltage, the attack duration, and the CPU clock count. After receiving an interrupt signal, the security processor executes its internal interrupt handler. The interrupt handler, based on the interrupt signal received from the voltage detection module, determines that the internal modules of the CPU and / or the security processor have been attacked to a preset severity level and then activates the defense protection mechanism. The severity of the attack is determined as follows: the component is subjected to continuous attacks, and the time intervals of N attacks fall within the time range when the CPU is processing preset critical instructions. N can be any integer greater than or equal to 1 and less than or equal to the total number of continuous attacks. The time interval of the attack is determined based on the CPU clock count in the interrupt signal.

Citation Information

Patent Citations

  • Voltage detection and frequency detection-based chip anti-attack method

    CN101968840A

  • Attack detection device and attack detection method

    JP2020187443A