Method for detecting disturbances in a logic circuit and logic circuit for implementing the method
By designing programmable length data paths and test circuits in logic circuits, dynamic adjustment of propagation delay is achieved, the problem of side channel attacks in logic circuits is solved, detection capability and circuit stability are improved, and it is suitable for smart cards and other fields.
Patent Information
- Application Number
- CN202080089068.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2019-12-23
- Filing Date
- 2020-12-21
- Publication Date
- 2025-08-29
- Estimated Expiration
- 2040-12-21
AI Technical Summary
The prior art is difficult to effectively prevent side channel attacks in logic circuits, especially short-term pulse interference attacks, resulting in circuit failures and difficult to detect.
A logic circuit is designed, including a test circuit, capable of switching between calibration mode and detection mode, dynamically adjusting the propagation delay by adjusting the data path of the programmable length to detect disturbances in the logic circuit.
Effectively detect disturbances in logic circuits, reduce circuit failures, adapt to process, voltage and temperature changes, and reduce costs, especially suitable for constrained spaces such as smart cards.
Smart Images

Figure CN114846763B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of electronic circuits, in particular integrated circuits, where there is an interest in monitoring digital signals, such as digital power supplies, to detect perturbations that may be caused by side-channel attacks. Background Art
[0002] Side-channel attacks rely on signals derived from the actual execution of an algorithm, such as power consumption, timing data, or electromagnetic leakage, rather than relying on weaknesses in the algorithm itself. In computer security, they present a significant risk of fraudulent retrieval of secret information, particularly because they are typically non-invasive and undetectable. In this regard, even the strongest cryptographic algorithms are subject to careful external analysis and identification.
[0003] This type of side-channel attack explicitly relies on power analysis, which involves studying the power consumption of hardware devices. Its implementations include SPA for "Simple Power Analysis" (which intuitively explains power traces) and DPA for "Differential Power Analysis" (which utilizes statistical analysis of the collected data).
[0004] Numerous hardware and digital solutions have been developed over the years to prevent these attacks or render them unsuccessful. Some of these solutions are based on minimizing the strength of released signals associated with critical operations. While these solutions can significantly reduce the associated risks, appropriate devices require specialized, substantial implementation, can be expensive and complex, and cannot completely prevent signal leakage.
[0005] Other solutions are based on intentionally generating perceptible noise in the signal in order to obscure meaningful reverse analysis information from the hacker, which can be done, inter alia, by randomly introducing timing modifications (clock domains, jitter), amplitude modifications (filters, noise engines) or through dynamic reconfiguration.
[0006] However, these solutions can lead to substantial performance failures, in particular due to glitches, i.e. brief system failures, which are often more difficult to eliminate than, for example, software errors. These can include timing violations, among other things.
[0007] The non-patent literature document, "Power supply glitch attacks: Design and evaluation of detection circuits" (Gomina Kamil et al.), deals with the design and evaluation of detection circuits developed for power supply glitch attacks. This document provides background on the sensitivity of timing paths and logic gates in synchronous circuits to power glitch attacks. It defines the necessary limits for proper detection and proposes three detection methods and comparisons based on simulation results.
[0008] Another non-patent literature document entitled "A 45nm Resilient Microprocessor Core for Dynamic Variation Tolerance" (Keith A. Bowman et al.) discloses a microprocessor core that integrates resilient error detection and recovery circuitry to mitigate clock frequency guard bands for dynamic parameter variations to improve throughput and energy efficiency.
[0009] Document US 2015 / 137864 A1 discloses a circuit delay monitoring device comprising a ring oscillator having a plurality of delay elements and a series of sampling points, wherein one sampling point in the series of sampling points is provided in association with the output of each of the delay elements, wherein those sampling points provide inputs to associated flip-flops within a sampling circuit.
[0010] Document US 2017 / 030954 A1 relates to a device and a method for detecting a resonant frequency, thereby generating an impedance peak in a power transmission network.
[0011] Therefore, there is a need for improved methods and systems for preventing side-channel attacks in logic circuits in order to at least partially overcome the above-mentioned problems and disadvantages. Summary of the Invention
[0012] To address this issue, the present disclosure proposes, as a first aspect, a method for detecting disturbances in a logic circuit, wherein the logic circuit is configured to process data operations along multiple data paths coordinated by a clock signal, and wherein at least one of the data paths has an operation propagation delay. The logic circuit also includes at least one test circuit having a programmable-length data path for varying the test propagation delay. The test circuit also includes an input to be processed to instantaneously provide an output according to the programmable-length data path; and an error generator for providing an error if the output differs from the expected output of the input due to an inappropriate programmable-length data path setting or a disturbance in the logic circuit. In addition, the test circuit is configured to operate in two modes, namely a calibration mode and a detection mode, so as to repeatedly switch between the two modes.
[0013] Calibration modes include:
[0014] - Determines the critical propagation delay by varying the programmable length data path until the error generator outputs an error,
[0015] - Adjusting the programmable length datapath to include the allowed delay, and
[0016] -Switch to detection mode.
[0017] Detection modes include:
[0018] - Detecting disturbances in logic circuits along a programmable length data path in the event of an error generator output error.
[0019] Thanks to this solution, any disturbances intentionally introduced into the digital signals of the logic circuit, such as glitches, can be effectively detected. Furthermore, this detection remains effective regardless of process variations, voltage variations, and temperature variations of the logic circuit. As a further significant advantage, this circuit can be limited to include all-digital components, thus offering benefits at least in terms of size, power consumption, development, and cost price. In a more practical sense, this solution is of particular interest for smart cards, for example, where the space available for implementing anti-tampering solutions or improving such solutions is particularly limited.
[0020] According to a specific embodiment, the logic circuit further includes a second test circuit having at least the same capabilities as the first test circuit (i.e., the other test circuit). In addition, when one test circuit is in one mode (i.e., calibration or detection mode), the other test circuit is in another mode.
[0021] According to a preferred embodiment, changing the programmable length data path of the test circuit to determine the critical propagation delay is stopped until the critical propagation delay falls below a minimum delay required for processing data operations without disturbances or glitches.
[0022] According to another preferred embodiment, the method comprises iterations for iterating the calibration mode and the detection mode over time, ie for iterating the determining, adjusting, switching and detecting steps over time.
[0023] Preferably, the programmable length data path of the test circuit is formed by a number of elements to be included in one clock cycle. Also preferably, these elements are included according to a constant number during a first iteration and then the number of elements to be included is increased in the next iteration.
[0024] In one embodiment, the switch from calibration mode to detection mode is performed once the calibration mode is completed.
[0025] According to a preferred embodiment, the inputs of the test circuit are swapped or changed at each clock cycle in order to obtain different outputs between two consecutive clock cycles.
[0026] Preferably, the operational propagation delay within the data path is adjusted by applying a useful skew to the clock branches of the data path that coordinately generate the operational propagation delay.
[0027] According to a second aspect, the present disclosure also relates to a logic circuit for implementing a method according to any of the embodiments or variants disclosed therein while processing data operations along multiple data paths coordinated by a clock signal. The logic circuit includes at least one test circuit, and the test circuit includes means for switching from a calibration mode to a detection mode and from a detection mode to a calibration mode.
[0028] More specifically, the aforementioned test circuit is configured to operate according to a calibration mode designed to determine a critical propagation delay of a digital signal through at least one of the data paths and a detection mode designed to detect disturbances in the logic circuit. Furthermore, the test circuit includes:
[0029] - a first register configured to be loaded with an input,
[0030] - a logic unit storing a function configured to provide an output from an input,
[0031] - a second register for storing an expected output provided by the function of the above input,
[0032] - a comparator configured to verify that the output is equal to one of the expected outputs,
[0033] - an error generator for outputting an error in the event that the comparator provides a negative event,
[0034] - a programmable length data path for varying the propagation delay of a digital signal, thereby allowing an output to be obtained from an input, and
[0035] A switching unit for switching the calibration mode into the detection mode and for switching the detection mode into the calibration mode.
[0036] According to a preferred embodiment, the logic circuit further comprises a second test circuit, the two test circuits having at least similar capabilities to perform at least the same task. In addition, the test circuits are configured to operate simultaneously in one of a calibration mode and a detection mode, such that when one of the test circuits operates in one mode, the other test circuit operates in the other mode.
[0037] Also preferably, the programmable length data path includes a plurality of selectable delay units.
[0038] According to another preferred embodiment, the logic circuit is restricted to include fully digital components.
[0039] Further embodiments and advantages are disclosed in the detailed description below.
[0040] BRIEF DESCRIPTION OF THE DRAWINGS
[0041] The solutions and embodiments presented in this disclosure should be considered as non-limiting examples and will be better understood with reference to the accompanying drawings, in which:
[0042] Figure 1 Schematically depicted are different types of glitches that are commonly known in glitch attacks.
[0043] Figure 2 An example of the effect of a glitch on a synchronous logic circuit is shown.
[0044] Figure 3 is a diagram of a portion of a logic circuit,
[0045] Figure 4 is through Figure 3 Representation of the propagation of digital signals in logic circuits associated with clock signals,
[0046] Figure 5 It shows Figure 3 The diagram shows the changes in the timing margin of the logic circuit in different scenarios, especially the changes in the PVT model.
[0047] Figure 6 is similar to Figure 5 A diagram showing the timing margin of a logic circuit operating according to the method proposed in this solution,
[0048] Figure 7 is a schematic diagram showing calibration and detection mode switching, and
[0049] Figure 8 and Figure 9 It is shown how the solution can be implemented according to two different architectures.
[0050] Figure 1 Some examples of different kinds of glitches 1 are shown, which are presented in this specification as examples of disturbances or interferences that can be used by hackers in side channel attacks, in particular in so-called glitches. Glitches 1 can occur, for example, on the power supply (VDD) of an integrated circuit powered by a DC power supply, such as Figure 1 As shown in the upper figure of , or on ground (GND), as shown in the lower figure of this figure. A short-term pulse interference 1 can refer to a single spike 1a, or it can occur in a series of consecutive spikes 1b, which do not necessarily have the same amplitude. Figure 1 As shown, the short-time pulse interference 1 can be positive 1' or negative 1".
[0051] Glitches should not be confused with noise that can occur in electrical signals. Small variations in an electrical signal, such as ±10% of the nominal value or voltage, should be considered noise due to the insignificant effect such variations may have on logic circuits. Beyond the range recognized for noise, variations can be considered glitches or common glitches. Similarly, glitches can have a minimum width to have a sufficient impact on the electrical signal. This minimum width can be considered to be, for example, on the order of 2-3 ns.
[0052] The effects of short-duration pulse interference, such as on the power supply of a logic circuit, can vary depending on the type of components in the logic circuit. In this regard, a distinction should be made between sequential logic and combinational logic. In combinational logic, the state of the output at a given moment depends solely on the circuit and the values of its inputs at that moment. In contrast, in sequential logic, the state of a circuit's output at a given moment depends on both the values of its inputs at that moment and the output values at the previous moment. In other words, sequential logic uses the concept of a memory, while combinational logic does not. Sequential logic uses flip-flops to implement this concept, while the basic elements of combinational logic are logic gates, such as AND gates, OR gates, XOR gates, and NOT gates.
[0053] Additionally, there are two main categories of flip-flops: some are asynchronous with respect to the clock signal and are called latches, while the other main category is synchronous with respect to the clock signal and is simply called a flip-flop. Today, almost all sequential logic is clocked, or synchronous, logic. This is why this specification will specifically refer to synchronous circuits, i.e., circuits whose elements, under normal conditions, change their state in sync with a clock signal.
[0054] It has been estimated that glitches have a limited impact on sequential elements, especially synchronous ones, because flip-flops can only be affected near clock edge events. Since these sensitive transients correspond to rising or falling edges of the clock signal, they are very limited in time, as opposed to the clock signal's period.
[0055] In contrast, glitches have a greater impact on combinational components, such as logic gates, because they can alter the results of Boolean operations due to variations in delay cells. The effects of glitches on the power supply of combinational components are complex. However, they can be summarized as follows:
[0056] When a positive glitch 1' occurs on the power supply VDD or a negative glitch 1" occurs on the ground GND, the delay of the logic element provided in this manner is accelerated.
[0057] When a negative glitch 1" occurs on the power supply VDD or a positive glitch 1' occurs on the ground GND, the delay of the logic element provided in this manner slows down.
[0058] By way of example, Figure 2 The effect of a short-time pulse interference 1 on the synchronization design is shown. Figure 2 The upper part of FIG shows a single short-time pulse interference 1a and a series of short-time pulse interference 1b occurring on the power supply of a synchronous circuit including a flip-flop. In line with this upper part, Figure 2 The lower portion of the diagram shows the clock signal 4Clk and the data path Dta of the digital signal 2 along the time axis t in the upper portion. Boolean results N-1, N, and N1 are successively provided at the outputs of successive flip-flops. The operation of computing the Boolean result N generates the digital signal 2, which is represented by a zigzag line and generally begins with the first clock pulse P1 and ends at the end of the normal delay d.
[0059] As can be seen, when the second clock pulse P2 rises, the Boolean result N is complete and stable. This is illustrated by the safety margin Mg set between the Boolean result N and the second clock pulse P2. However, if glitches 1a and 1b occur, they slow down the combinational logic between two consecutive flip-flops, as indicated by the unusually long delay d+Δt required to provide the Boolean result N+1. Consequently, when the third clock pulse P3 rises to capture the Boolean result according to the synchronous design, the result is captured before its operation has properly concluded. This creates a timing violation, which can cause circuit failure or localized metastability within the circuit. For digital electronic circuits, metastability can be considered the ability to persist in an unstable equilibrium for an unknown duration due to the fact that the circuit remains unable to decide how to process its input signal.
[0060] refer to Figure 3 , which shows a plurality of data paths 5 within the logic circuit 10. The two upper data paths 5 are each represented by a continuous staircase-shaped line, and Figure 3 The data path 5 shown in the central part of the figure belongs to a more detailed part 11 of the logic circuit 10. Therefore, the logic circuit 10 is represented by a dotted line around the aforementioned part 11 and the data path 5. This part 11 can generally be used as an exemplary circuit in the method or logic circuit of the present solution. For this reason, this part is also called exemplary circuit 11. Although Figure 3 The logic circuit 10 depicted in FIG. 1 includes exemplary circuit 11, but it should be understood that any other logic circuit 10 may include different circuits, i.e., any other logic circuit 10 is not required to include Figure 3 An exemplary circuit 11 is shown.
[0061] Although it may be more complicated, Figure 3The exemplary circuit 11 suggested in the example of FIG is very simple, as it includes two registers 6 a, 6 b, each of which can include operands A or B. The exemplary circuit 11 also includes a function F configured to perform a calculation using operands A and B. This function involves a more or less complex calculation. Preferably, function F is configured such that the result provided by F(A, B) differs from the result provided by F(B, A). In other words, function F preferably provides two different results when the operands are swapped.
[0062] Preferably, the exemplary circuit also includes a final register 7 to which the Boolean result N from the function F is written. Considering that the exemplary circuit operates synchronously with the clock signal 4, the following time markings should be noted. At time t0, operands A and B are loaded into registers 6a, 6b. At time t1, these operands are released from registers 6a, 6b. Releasing the operands typically occurs at the beginning of a clock cycle T, typically at the rising edge of the clock, for example, at pulse P1 ( Figure 2 ). At time t2, function F has calculated the Boolean result N using the two operands A, B as inputs provided by registers 6a, 6b. The Boolean result N can be considered as the output provided by exemplary circuit 11. At time t3, this output is written to, or captured by, the last register 7. Thus, writing this result N is done at the end of clock cycle T, i.e., at the next rising edge of the clock in such a synchronous design, corresponding to pulse P2 ( Figure 2 ). The data path 5 traveled by the digital signal during the clock cycle T in the exemplary circuit 11 is Figure 3 The horizontal curling bracket 5 is shown in FIG.
[0063] Now refer to Figure 4 , the latter shows the propagation of a digital signal 2 through a logic circuit, more specifically through Figure 3 This digital signal propagation is shown in relation to the clock signal 4, consistent with a synchronous exemplary circuit where the flip-flops change their states in sync with the clock signal (under normal conditions). Figure 4 , it is shown that the digital signal 2 starts at the rising edge of the clock signal 4 (i.e., at time t1) and is stabilized before the end of the clock period T, more specifically before time t2. This means that at time t2, the Boolean result N is complete and is waiting to be written to the last register 7 at the next rising edge of the clock, i.e., time t3. The time interval between t2 and t1 corresponds to the propagation delay 2' of the digital signal 2 through the data path 5 of the exemplary circuit 11, and the time interval between time t3 and t2 can be regarded as the allowed delay 3', margin, or dead time margin.
[0064] If a disturbance 1 such as a short-time pulse interference 1" occurs before the digital signal 2 is stable, that is, before the Boolean result N is completed, the propagation delay 2' will increase by another time Δt, as shown in combination with Figure 2 However, if this additional time Δt is less than the allowed delay 3′, the exemplary circuit will not be affected by the disturbance 1 because the digital signal reaches a stable state before the end of the clock period T. Similarly, if the disturbance 1 occurs during the allowed delay 3′, the exemplary circuit 11 remains unaffected by this disturbance. Therefore, the exemplary circuit 11 may include a “shadow region” that makes such a circuit inefficient in detecting disturbances in a reliable manner.
[0065] Allowable delay 3'( Figure 4 ) or margin Mg( Figure 2 ) is usually defined based on the worst-case scenario (WCS) of a logic circuit and a given clock frequency. The WCS depends primarily on the so-called process-voltage-temperature (PVT) operating conditions, which have an impact on the timing of the data paths assigned to the logic circuit.
[0066] In the PVT acronym, process P models the timing effects of a small piece of semiconductor material (such as an integrated circuit, chip, or microchip) on which a given functional circuit is fabricated. This effect is related to the manufacturing process of the integrated circuit and can vary depending on the manufacturing process conditions. The voltage V in the PVT acronym refers to the small voltage change applied to the power supply of the semiconductor. In practice, higher voltages increase currents, reducing the delay of flip-flops and thus speeding up the calculation of logic operations. Ambient temperature T is also a parameter that has an impact on semiconductor timing.
[0067] To ensure that a logic circuit (e.g., the exemplary circuit) will be able to perform the computations of the relevant operations for which the logic circuit is designed, the designer must consider the WCS of the components of this circuit to ensure that the propagation delay of the operation required by the circuit is less than the clock period T, thereby avoiding any timing violations.
[0068] Figure 5 It is shown in different situations, especially under the change of PVT model Figure 3 Graph showing the variation of the timing margin Mg for the exemplary circuit shown. In this graph, time t is represented on the x-axis and the PVT values are represented on the y-axis between a minimum PVT value and a maximum PVT value. The time axis crosses the y-axis at the so-called typical PVT value, which can be considered as a median common value for the PVT parameter. The minimum PVT value can be mapped to a best case scenario (BCS) and the maximum PVT value can be mapped to a worst case scenario (WCS). With reference to the exemplary circuit 11, the curves of this graph can be considered as showing the variation of the propagation delay 2' along time. Therefore, the curve 2' between the maximum PVT limit Figure 5The timing margin Mg shown can be considered as the allowable delay 3'. Note that the timing margin Mg varies between a maximum margin MMg and a minimum margin MMg. To avoid any timing violations, the curve showing the propagation delay 2' of the digital signal 2 within the exemplary circuit does not exceed the maximum PVT limit (WCS).
[0069] Through curve 2', Figure 5 It shows that the timing margin Mg (i.e., the null time margin or the allowable delay 3') is not constant, but depends on the PVT parameters. This means that if a side channel attack occurs at time t M If the perturbation 1 is near Mg, there is a significant risk that the perturbation 1 will occur during a critical time interval for the timing margin Mg, resulting in the exemplary circuit 11 being unaffected by this type of attack. Given that the changes in curve 2' remain unpredictable over time, it is understandable that it is very difficult to effectively prevent side-channel attacks. Furthermore, since temperature is one of the parameters of PVT, malicious actors can intentionally manipulate the ambient temperature of logic circuits to place them under better conditions, allowing them to perform side-channel attacks at their advantage.
[0070] To solve this thorny problem, this solution is based on Figure 6 Instead of a constant or static margin level at the maximum PVT limit, this solution proposes to provide a margin that follows Figure 6 The dynamic margin of the curve 2' is shown. Due to this dynamic margin, the timing margin Mg or the permissible delay 3' remains constant or almost constant over time t and can be set to a value equal to or close to the minimum margin mMg. Under such conditions, the relevant parts of the logic circuit used to detect disturbances become more sensitive and are much more effective for detecting short-term pulse interference attacks, for example.
[0071] like Figure 6 As shown, one of the objectives of this solution is to provide an adaptive or dynamic detection device that can follow changes in PVT parameters and clock frequency. The propagation delay 2' of the digital signal within the circuit designed to detect disturbances is made variable so as to reach a critical limit corresponding to or close to the period T of the clock signal 4. In other words, one of the goals of this solution is to dynamically minimize the dead time margin or allowable delay 3' so as to maintain this allowable delay 3' at the minimum value of any current PVT parameter.
[0072] To this end, the exemplary circuit 11 is modified so as to have a data path 5 of programmable length. Thus, the propagation delay 2' of the digital signal 2 traveling through this data path is adjustable. In the further description, the exemplary circuit thus modified is referred to as a test circuit 21, 21' and is Figure 8 and Figure 9 Schematically depicted in .
[0073] In addition, this test circuit 21, 21' is intended to operate in two modes, namely a calibration mode Mc and a detection mode Md. Figure 7 The calibration mode Mc is an operating mode in which the test circuits 21, 21' are switched during the calibration phase in order to modify their variable allowable delay 3' according to the current PVT parameters. In the present disclosure, this is preferably achieved by adjusting the length of the data path so that the allowable delay 3' remains as close as possible to the constant minimum margin mMg. The detection mode Md is a second operating mode in which the test circuits 21, 21' are mainly used to detect any side channel attacks. The test circuits 21, 21' are switched during the calibration phase in order to modify their variable allowable delay 3' according to the current PVT parameters. In the present disclosure, this is preferably achieved by adjusting the length of the data path so that the allowable delay 3' remains as close as possible to the constant minimum margin mMg. Figure 7 This is schematically indicated in using dashed lines around the calibration and detection patterns, which are exchanged continuously along the time axis t.
[0074] Figure 8 and Figure 9 It is shown how the solution can be implemented according to two different architectures given here as examples.
[0075] With reference to the aforementioned figures, a first aspect of the present solution relates to a method for detecting a disturbance 1 in a logic circuit 10 for processing data operations along a plurality of data paths 5 coordinated by a clock signal 4. At least one data path 5 has an operation propagation delay. The logic circuit may include logic gates such as flip-flops or latches, and the data paths defined by digital elements may also include registers and buses. More specifically, the logic circuit 10 further includes at least one test circuit 21, 21 '( Figures 7 and 8 ), the at least one test circuit has a programmable length data path 22 for varying the propagation delay 2'. Since this propagation delay involves the test circuits 21, 21', it is also referred to as test propagation delay 2'. Figure 7 and Figure 8 As shown in FIG, a programmable length data path 22 may be obtained from a plurality of elements 23, such as delay cells, the number of which may be selected in order to vary the length of the data path, ie to extend or shorten the length of the data path belonging to the test circuit 21, 21'.
[0076] The test circuit 21, 21' also comprises at least two inputs X, Y to be processed to instantaneously provide an output N according to the programmable length data path 22, more specifically according to the length or duration represented by the data path. In this regard, it should be noted that Figures 8 and 9 The output N is Figure 3There is no specific relationship between the results N of , even though they may appear similar. The inputs X, Y can be regarded as operands loaded into at least two registers 12a, 12b. The output N corresponds to the result provided by this function F using the above-mentioned inputs X, Y as operands in the calculation of the function F. This function can be stored and run in a dedicated logic unit 24. The test circuits 21, 21' are configured to use at least two expected results R1, R2, which can be stored in appropriate registers 12c, 12d. Preferably, these expected results R1, R2 have been determined in advance based on the inputs X, Y and the function F. More specifically, the expected result R1 corresponds to the result provided by the function F(X, Y), which uses the inputs in a first order, while the expected result R2 corresponds to the result provided by the function F(Y, X), that is, the same function F but using the inputs in a second order. Therefore, the function preferably does not involve a commutative operation, so that if the operands X, Y are swapped, the result N provided by the function F also changes. Furthermore, the function F may be more or less complex, so that the expected results R1 , R2 may generally be difficult to predict.
[0077] like Figures 7 and 8 As shown in , the test circuit 21, 21' also includes a comparator 25 and an error generator 26, which provides an error E (i.e., an error signal or value) when the output N is different from the expected output R1, R2 of the input X, Y. The comparator 25 can generally determine that the output N is different from the expected output R1, R2 (i.e., determine N≠R1 or N≠R2) due to a disturbance in the logic circuit 10 or an inappropriate programmable length data path setting (i.e., due to a programmable length data path setting that causes a timing violation). This can occur, for example, when the length of the data path is too long or too short to provide the output N in a timely manner. Therefore, the comparator 25 includes a test function for verifying whether the result N (e.g., the result of F(X,Y)) is equal to the expected result R1. In the case of a positive event (illustrated by a binary output of 1), the method continues, while in the case of a negative event (binary output of 0), the process is configured to provide an error E at the output of the error generator 26.
[0078] As above combined Figure 7 As described above, the test circuits 21, 21' are configured to operate in two modes, namely, according to the calibration mode Mc and the detection mode Md, so as to repeatedly switch between these modes Mc, Md, thereby allowing the detection mode Md (i.e., the settings of this mode) to be frequently updated with the aid of or based on the calibration mode Mc. Thus, a dynamic margin that remains constant or substantially constant can be obtained, such as Figure 6 This dynamic margin corresponds to the time interval between the delivery of the output N and the next clock pulse of the clock signal 4, in particular the next rising edge of the clock signal 4. The calibration mode Mc comprises the following steps:
[0079] - determining the critical propagation delay by varying the programmable length data path 22 until the error generator 26 outputs the error E, and
[0080] - Adjusting the programmable length data path 22 to include the allowed delay 3' therein.
[0081] Therefore, it should be noted that the change in length data path is used to determine (i.e., find or discover through investigation) the critical propagation delay, and the programmable length data path continues to change as long as the error generator does not output an error. In addition, the aforementioned margin is not only dynamic, but also minimized, so that it can be called a constant minimum margin.
[0082] On the other hand, the detection mode Md comprises steps for detecting a disturbance 1 in the logic circuit 10 along the programmable-length data path 22 if the error generator 26 outputs an error E.
[0083] It should be noted that the two operating modes Mc, Md relate to normal operating modes (or working modes) of the test circuits 21, 21'. Therefore, none of these modes should be considered as special modes, eg performed for maintenance or repair purposes.
[0084] It is understood that the allowable delay 3′ (which is Figure 6 In the case of a constant minimum margin mMg as shown in FIG, the critical propagation delay can be regarded as the longest test propagation delay 2′ that can be included in the period T. The critical propagation delay is reached when the error generator 26 outputs an error E during the calibration mode. In practice, if the programmable length data path 22 is gradually lengthened during the calibration mode, there is a point at which the data path is too long for a given clock period T, resulting in a timing violation (e.g., Figure 2 If the critical point where the timing violation occurs is known, the programmable length data path 22 of the test circuit 21, 21' can be adjusted in a certain way so that the test propagation delay 2' plus the allowable delay 3' can correspond to the clock period T, or can be close to the clock period without exceeding it.
[0085] Once the programmable length data path 22 has been adjusted as described above, the calibration mode Mc ends and the test circuits 21, 21' can be switched to their detection mode Md. In the detection mode Md, the test circuits 21, 21' operate in the calibrated state at the end of the calibration mode Mc. As a result, the test circuits become particularly sensitive to any disturbances 1 (in addition to noise or jitter) that could be deliberately introduced, for example, by a hacker, into the power supply VDD of the logic circuit 10. After a certain time has elapsed, the test circuits 21, 21' can be switched back to their calibration mode Mc, and the switching between the two operating modes can be repeated as long as desired. Figure 7 The calibration and detection mode switching are shown in . The time lapse during which the test circuit operates in its detection mode Md may be predetermined or may depend on another parameter.
[0086] Preferably, once the calibration mode Mc is completed, switching (or swapping) from the calibration mode Mc to the detection mode Md is performed.
[0087] The above method is suitable for use with a single test circuit 21, 21'. However, when the test circuit listens for disturbances 1 during detection mode Md, there is a risk that the test circuit's calibration may become out of date, particularly if a malicious actor intentionally manipulates PVT parameters (e.g., temperature T) to extend the permissible delay 3', thereby rendering the test circuit uncalibrated again. There is also the risk of side-channel attacks occurring during the test circuit's calibration mode. In this mode, the test circuit is temporarily busy with the calibration phase and therefore cannot detect any disturbances.
[0088] In order to overcome this shortcoming, the present solution proposes an embodiment in which the logic circuit 10 further includes a second test circuit 21 ′, such as Figure 7 . Preferably, the second test circuit 21' is similar to or identical to the first test circuit 21, still preferably, the second test circuit 21' has at least the same capabilities and / or functions as the first test circuit 21. Typically, both the first test circuit 21 and the second test circuit 21' have at least similar capabilities to perform at least the same tasks, and are preferably configured to work simultaneously. More specifically, when one test circuit is in one mode, the other test circuit is in another mode. Therefore, the test circuit 21 and the test circuit 21' work simultaneously but with a time lag, i.e., with a time delay or time difference relative to each other when considering the calibration mode Mc or the detection mode Md. In fact, as Figure 7 As shown, when the first test circuit 21 is in the detection mode Md, the second test circuit 21' is in the calibration mode. In other words, the test circuits 21 and 21' preferably never operate in the same operating mode. Due to this embodiment, there is always one test circuit 21 and 21' operating in the detection mode. Therefore, the logic circuit 10 is permanently protected against side-channel attacks because at all times there is a test circuit operating in the detection mode to detect any perturbations or interferences.
[0089] It should be noted that the critical propagation delay can also be considered the minimum delay required to correctly execute a desired data operation in a data path, such as the data path of a test circuit. Therefore, in another embodiment, changes to programmable-length datapath 22 are stopped before this critical propagation delay falls below the minimum delay required to process the data operation without perturbations, to determine the critical propagation delay. In practice, if a critical propagation delay exists, beyond which digital signal 2 becomes too long and therefore unstable at the end of clock cycle T (thus causing a timing violation), the test circuit also requires a minimum delay to correctly calculate result N from inputs X and Y. This minimum delay is the shortened delay required by test circuits 21, 21' to process the operation under normal conditions. Therefore, if programmable-length datapath 22 must be gradually shortened during calibration mode, such shortening is stopped before the aforementioned minimum delay is reached. Due to this precaution, test circuits 21, 21' will always operate between two appropriate delays, i.e., between the aforementioned minimum delays, which can be, for example, half a clock cycle, and the critical propagation delay is typically close to clock cycle T. As can be seen from the foregoing, timing violations are primarily caused by inappropriate programmable-length datapath settings.
[0090] However, it should be noted that the last embodiment as disclosed above operates in the case where the programmable length data path 22 of the test circuit 21, 21' is at least as long as the longest data path 5 of the logic circuit 10 (assuming the clock signal has the same frequency for the entire logic circuit 10). The longest data path is the one included in the logic circuit 10 (such as Figure 3 The data path 5 schematically shown in the upper portion is the data path with the longest runtime among the data paths. If the shortest length of data path 22 (which depends on the minimum delay required for the test circuit to correctly calculate the result N) is shorter than the aforementioned longest data path, there is a risk that logic circuit 10 will not operate correctly. Therefore, to avoid such problems, it may be appropriate to first determine the longest data path 5 included in logic circuit 10 in order to obtain a lower limit below which the programmable-length data path 22 cannot operate. Such a lower limit can replace the aforementioned minimum delay required by the test circuit to properly calculate the result N, or, more simply, such a lower limit can be regarded as the minimum delay. Such limit values and / or minimum delays can, for example, be defined in advance as setup parameters.
[0091] It can be noted that determining the critical propagation delay can be considered as an operation intended to scan the entire range of the programmable length data path 22 from a nominal length, which programmable length data path can vary from a minimum length to a maximum length. The nominal length can be located anywhere between the minimum length and the maximum length of the data path 22. This nominal length can be defined, for example, from a predetermined value or from a previous value. Starting from this nominal length, if the error generator does not output an error, for example, no error is output despite reaching the minimum length, the process can be configured to automatically search for the critical propagation delay towards the reverse length, i.e., the maximum length in this example. The length of the data path 22 must at least cover the delay range of the data path 5 for the clock cycle, which under BCS conditions (fastest conditions) must cover all operating conditions that vary within the range.
[0092] According to a further preferred embodiment, the above method comprises an iteration i for iterating the calibration mode and the detection mode over time. In other words, these iterations allow the steps of determining, adjusting, switching and detecting these operating modes to be iterated over time. Figure 7 Some iterations i are schematically shown, in particular iterations i1, i2, ... i performed during the detection mode Md. n . In order to better distinguish between the two consecutive operating modes, the iterations present in the calibration mode Mc have been omitted in this figure. Due to these iterations, as long as the test circuits 21, 21' operate in the same operating mode, the process aimed at verifying (in each round) whether an error E is output from the error generator 26 is repeated. Such repetitions are performed not only for the detection mode Md, but also for the calibration mode Mc. In addition, it should be pointed out that the number of consecutive iterations i for one mode is not necessarily the same as for another mode. It also means that the speed for completing one iteration can vary between the modes. Preferably and in accordance with the method disclosed above, the calibration mode Mc can be regarded as a master mode, while the detection mode Md can be regarded as a slave mode that runs only after the calibration mode of one of the test circuits 21, 21' is completed. In the presence of a single test circuit 21, the detection mode can be executed during a predetermined or limited time interval that can be set as a setting parameter.
[0093] According to one embodiment, the programmable length data path 22 is formed by a plurality of elements 23 to be included in one clock cycle (ie, within one period T of the clock signal 4). Figure 8, these elements 23 may typically be delay cells. If the test performed by the comparator 25 is positive and shows that the programmable length data path 22 can be further extended, the value provided to the result register 27 will be positive. This positive result is transmitted to the controller 28 which is configured to manage the so-called trim register 29. The trim register is responsible for selecting the appropriate number of elements 23 to better adjust the programmable length data path 22 within the clock cycle. Such adjustment may include adding or removing delay cells according to the remaining dead time margin or the current size of the margin, such as Figure 4 As shown between time t3 and t2.
[0094] This adjustment is performed step-by-step during iteration i. For example, if programmable-length data path 22 at iteration i is still too short, comparator 25 of test circuit 21, 21' in its calibration mode Mc will provide a positive result "1" in result register 27. Consequently, controller 28, via trim register 29, will further extend programmable-length data path 22, for example by adding at least one element 23 to the data path of test circuit 21, 21'. At the next iteration i+1, comparator 25 will confirm whether the newly extended data path is long enough. If programmable-length data path 22 causes a timing violation, it means it is too long. Therefore, error generator 26 will provide error E. This information can be transmitted to controller 28, particularly when the test circuit is in its calibration mode Mc. Thus, controller 28 knows that the last adjustment step of the programmable-length data path (i.e., the last extension in this example) must be removed in order to retrieve the data path of the previous iteration (i), which will therefore correspond to the so-called critical propagation delay of the test circuit. Therefore, the controller will adjust programmable-length data path 22 accordingly, which will have the effect of including a tolerance delay 3' therein. It should be noted that retrieving the datapath of the previous iteration may be performed using a memory (eg, a temporary storage unit) for storing the previous configuration of the programmable-length datapath 22 (eg, the number of elements 23 ).
[0095] According to one embodiment, the elements 23 of the programmable length data path 22 are included according to a constant number during the first iteration, and then the number of elements to be included in the next iteration is increased. For example, in the first ten iterations i1, i2, ..., i 10 During this time, a single element 23 may be added to the programmable length data path 22 to try to reach a critical propagation delay. If this critical propagation delay is still not reached, the controller 28 may increase the number of elements added to the data path at each subsequent iteration. For example, the controller 28 may command that at iteration i 11 Add two elements at iteration i 12 Add three elements at iteration i 13Four elements are added at each iteration, and so on, until a critical propagation delay is reached. Thus, within a certain number of iterations, the increase in the number of elements changes and is preferably no longer linear, but can be exponential. Advantageously, this embodiment allows the calibration phase to be performed more quickly, especially if the space-time margin is significant in the first iteration.
[0096] according to Figure 9 In one embodiment shown, the test propagation delay is adjusted by applying a so-called useful skew to a clock branch 4' that is coordinated with the data path that generates the test propagation delay. Some parts of the logic circuit 10 can be synchronized by at least one clock signal derived from the master clock signal 4, rather than by a single clock signal 4. Thus, the clock tree can, for example, use several clock branches 4' to distribute the clock signal to parts of the logic circuit 10. Figure 9 In the embodiment of the present invention, the clock signal 4 is provided via a clock branch 4' in order to coordinate the test circuits 21, 21', in particular the programmable length data path 22 of the test circuits.
[0097] The purpose of the useful skew is to delay the instant t1 where the inputs or operands X, Y are released from registers 12a, 12b. Figure 4 The bottom of the figure shows such a situation, where the instant has been shifted from time t1 to time t 1' Therefore, due to the starting time t 1' The start of clock cycle T is delayed relative to the rising edge of clock signal 4, so the end of digital signal 2 will be moved towards the end of the clock cycle. Therefore, the dead time margin or allowed delay 3' between time t3 and t2 will be smaller. This time interval (t3-t2) can be adjusted until it is equal to or close to Figure 6 The minimum margin mMg has been depicted in . Figure 4 The time interval shown in 1' and t1, corresponding to the so-called useful skew.
[0098] Can be based on Figure 9 The architecture shown adjusts the useful skew, where a programmable length data path 22 is applied to the clock branch 4' in order to delay the rising edge of the clock signal 4 in this clock branch. As a result, the operands X, Y will be at a later time t 1' is released, while the test propagation delay for executing the operation by the function F in the dedicated logic unit 24 remains unchanged. Figure 8 The architecture is executed in the same way as in Figure 9 Adjustment of the programmable length data path 22 in the architecture.
[0099] according to Figure 8 and Figure 9In another embodiment shown in FIG, the inputs X and Y of the test circuits 21 and 21' are preferably swapped or changed so as to obtain a different output N between two consecutive outputs. This can be illustrated by multiplexers 12 and 12' belonging to the test circuits 21 and 21', respectively. Thus, the order of the operands X and Y can be swapped, as depicted by the intersecting arrows, so that the function F can be either F(X, Y) or F(Y, X). Due to this feature, the result N emitted by the function F calculated by the unit 24 will be different for each iteration i, thus ensuring that the digital signal 2 is present in the test circuits 21 and 21' at each iteration.
[0100] Although the reference Figure 8 and Figure 9 Two inputs X and Y have been disclosed, and therefore two expected results R1 and R2 have been disclosed, but it should be noted that this number is not limited to two. In addition, in addition to two inputs, it should be noted that the number of expected results is not necessarily the same as the number of inputs, but may be greater than this number due to different combinations to be made, even using a limited number of inputs.
[0101] According to a second aspect, the present solution also relates to a logic circuit 10 for implementing a method according to any one of its embodiments or any combination of these embodiments. To this end, the logic circuit 10 comprises at least one test circuit 21, 21'. This test circuit comprises means, such as a switching unit, for switching the calibration mode Mc to the detection mode Md and for switching the detection mode Md to the calibration mode Mc. The aforementioned switching unit may be a specific unit dedicated to the switching operation, or may be Figure 8 and Figure 9 The controller 28 is shown above.
[0102] More specifically, the logic circuit 10 includes at least one test circuit 21, 21', which is configured to operate according to a calibration mode Mc and a detection mode Md, the calibration mode Mc being designed to determine a critical propagation delay of the digital signal 2 through at least one of the data paths 5, and the detection mode Md being designed to detect a disturbance 1 in the logic circuit 10.
[0103] In addition, the aforementioned test circuits 21, 21' include:
[0104] - a first register 12a, 12b configured to be loaded with inputs X, Y,
[0105] a logic unit 24 storing a function F configured to provide an output N from inputs X, Y,
[0106] - a second register 12c, 12d for storing the expected outputs R1, R2 provided by the function F for the inputs X, Y,
[0107] a comparator 25 configured to verify whether the output N is equal to one of the expected outputs R1 , R2 ,
[0108] an error generator 26 for outputting an error E if the comparator 25 provides a negative event,
[0109] a programmable length data path 22 for varying the propagation delay 2' of the digital signal 2, thereby allowing obtaining an output N from inputs X, Y, and
[0110] A switching unit for switching the calibration mode Mc into the detection mode Md and for switching the detection mode Md into the calibration mode Mc.
[0111] As explained in conjunction with the related method, determining the critical propagation delay of the digital signal 2 through the data path 5 can generally be achieved by varying the programmable length data path 22 until the error generator 26 outputs an error E.
[0112] According to a preferred embodiment, the logic circuit 10 further comprises a second test circuit 21', which is configured to perform at least the same tasks as those of the first test circuit 21. In other words, the test circuit 21 and the test circuit 21' have at least similar capabilities so that both perform at least the same tasks. Preferably, the second test circuit 21' has at least the same capabilities and / or functions as the other test circuit 21' (i.e., the first test circuit 21). Furthermore, the test circuits 21, 21' are preferably configured to operate simultaneously in one of the calibration mode Mc and the detection mode Md, such as Figure 7 Schematically shown in FIG. The way in which the test circuit 21 and the test circuit 21 ′ operate relative to one another does not differ from that already explained in conjunction with the first aspect of the solution according to the invention. Furthermore, the characteristics and / or tasks described with respect to the first test circuit 21 also apply to the second test circuit 21 ′.
[0113] According to a preferred embodiment, programmable-length data path 22 includes multiple delay cells, specifically multiple selectable delay cells. These delay cells are part of elements 23 used to change the length of the test circuit data path. According to one embodiment, all elements 23 used for this purpose are identical. Alternatively, some elements 23 may differ from the others. For example, some elements 23 may be delay cells that provide a first delay, while other elements may be delay cells that have a second delay different from the first delay. It should be noted that delay cells are considered non-limiting examples, and other types of logic components with similar effects may also be considered elements 23. Furthermore, there is no limitation on selecting elements 23 individually. Thus, several elements 23 may be selected simultaneously to change the programmable-length data path 22. Furthermore, it should be understood that changing the programmable-length data path is not limited to extending the test circuit data path, but is also intended to shorten it. Therefore, the selection performed by controller 28 via trim register 29 may include removing at least one element 23 from programmable-length data path 22 to shorten the test propagation delay.
[0114] According to another embodiment, logic circuit 10 is limited to fully digital components. In other words, this means that logic circuit 10 includes only digital components. By eliminating any analog components, this solution has the advantage of providing a very compact design, which is particularly suitable for implementation in small spaces, such as smart cards. Furthermore, this fully digital solution is particularly economical in terms of both production costs and power consumption.
[0115] According to another embodiment, the aforementioned fully digital components are limited to the test circuits 21, 21'. Thus, a solution for preventing side channel attacks can be easily added to an existing analog or partially analog logic circuit 10.
[0116] It should also be noted that any embodiment or variant suggested in connection with the logic circuit may also be applied to the previously disclosed methods.
[0117] Final considerations
[0118] Although the overview of the subject matter of the present invention has been described with reference to specific exemplary embodiments, various modifications and changes may be made to these embodiments without departing from the broader spirit and scope of the embodiments of the present invention. For example, various embodiments of the features thereof may be mixed and matched or made optional by one of ordinary skill in the art. Therefore, the detailed description should not be construed as limiting, and the scope of the various embodiments is limited only by the appended claims and the full scope of equivalents to which such claims are entitled.
Claims
1. A method for detecting a disturbance (1) in a logic circuit (10) for processing data operations along a plurality of data paths (5) coordinated by a clock signal (4), at least one of the data paths (5) having an operation propagation delay, The logic circuit (10) further comprises at least one test circuit (21, 21') having a programmable length data path (22) for varying a test propagation delay (2'), The at least one test circuit (21, 21') comprises a first register (12a, 12b) to be loaded with an input (X, Y) to be processed by a function (F), the function being configured to calculate a Boolean result from a calculation using two operands to instantaneously provide an output (N) according to the programmable length data path (22); and an error generator (26) for providing an error (E) if the output (N) differs from an expected output (R1, R2) provided by the function (F) for the input (X, Y), wherein the expected output (R1, R2) is stored in a second register (12c, 12d), and one of the first registers (12a, 12b) is connected to the programmable length data path (22), The at least one test circuit (21, 21') is configured to operate in two modes, a calibration mode (Mc) and a detection mode (Md), so as to repeatedly switch between the calibration mode (Mc) and the detection mode (Md), wherein the calibration mode (Mc) comprises: - by changing the programmable length data path (22) up to the error generator (26) Output error (E) to determine the critical propagation delay, - adjusting the programmable length data path (22) to include an allowable delay (3') therein, - Switch to detection mode (Md), The detection mode (Md) includes: - detecting a disturbance (1) in the logic circuit (10) along the programmable-length data path (22) in the event that the error generator (26) outputs an error (E), The method comprises the steps of: entering a calibration mode (Mc) and executing the calibration mode; Entering a detection mode (Md) and executing the steps of said detection mode; and The disturbance (1) is detected by means of the detection mode.
2. The method according to claim 1 , wherein the at least one test circuit comprises a first test circuit ( 21 ) and a second test circuit ( 21 ′), the second test circuit ( 21 ′) having at least the same capabilities as the first test circuit ( 21 ) so that both perform at least the same task, and wherein When one test circuit (21, 21') is in calibration mode (Mc), the other test circuit is in detection mode (Md), and When one test circuit (21, 21') is in a detection mode (Md), the other test circuit is in a calibration mode (Mc).
3. The method of claim 1 or 2, wherein changing the programmable length data path (22) to determine the critical propagation delay is stopped before the critical propagation delay is lower than a minimum delay for processing the data operation without a disturbance (1).
4. The method according to claim 1 or 2, wherein the method comprises an iteration (i) for iterating the calibration and the detection mode over time.
5. The method according to claim 1 or 2, wherein the programmable length data path (22) is formed by a plurality of logic elements (23) to be included in one clock cycle (T). The method of claim 5 , wherein the elements are included according to a constant number during a first iteration and then the number of the elements to be included in a next iteration is increased.
7. Method according to claim 1 or 2, wherein the switching from the calibration mode (Mc) to the detection mode (Md) is performed once the calibration mode (Mc) is completed.
8. Method according to claim 1 or 2, wherein the inputs (X, Y) of the test circuit (21, 21') are swapped or changed in order to obtain a different output (N) between two consecutive outputs.
9. The method according to claim 1 or 2, wherein the test propagation delay (2') is generated by applying a useful skew (t 1' -t1) to adjust the test propagation delay (2').
10. A logic circuit (10) for implementing the method according to any one of claims 1 to 9 for processing data operations simultaneously along a plurality of data paths (5) coordinated by a clock signal (4), the logic circuit comprising at least one test circuit (21, 21') configured to operate according to a calibration mode (Mc) and a detection mode (Md), the calibration mode (Mc) being designed to determine a critical propagation delay of a digital signal (2) through at least one of the data paths (5), and the detection mode (Md) being designed to detect a disturbance (1) in the logic circuit (10), the at least one test circuit (21, 21') comprising: - a first register (12a, 12b) configured to be loaded with an input (X, Y), - a logic unit (24) storing a function (F) configured to calculate a Boolean result from a calculation using two operands to provide an output (N) from said input (X, Y), - a second register (12c, 12d) for storing an expected output (R1, R2) provided by said function (F) for said input (X, Y), a comparator (25) configured to verify whether the output (N) is equal to one of the expected outputs (R1, R2), an error generator (26) for outputting an error (E) if the comparator (25) provides a negative event, a programmable length data path (22) for varying the propagation delay (2') of the digital signal (2) so as to allow obtaining the output (N) from the input (X, Y), wherein one of the first registers (12a, 12b) is connected to the programmable length data path (22), and A switching unit for switching the calibration mode (Mc) into the detection mode (Md) and for switching the detection mode (Md) into the calibration mode (Mc).
11. The logic circuit (10) according to claim 10, wherein the at least one test circuit comprises a first test circuit (21) and a second test circuit (21'), the second test circuit (21') having at least the same capabilities as the first test circuit (21) so that both perform at least the same tasks and being configured to operate simultaneously in one of the calibration mode (Mc) and the detection mode (Md).
12. The logic circuit (10) of claim 10 or 11, wherein the programmable length data path (22) comprises a plurality of selectable delay cells (23).
13. The logic circuit (10) of claim 10 or 11, wherein the logic circuit is limited to fully digital components.
Citation Information
Patent Citations
Circuit delay monitoring apparatus and method
US20150137864A1
Apparatus and Method for Detecting a Resonant Frequency Giving Rise to an Impedance Peak in a Power Delivery Network
US20170030954A1
Digital programmable delay scheme to continuously calibrate and track delay over process, voltage and temperature
US20060033544A1