Electronic device with fault injection attack detection

By distributing detectors and evaluation devices in electronic devices, monitoring power supply and clock cycles, and detecting timing violations, the detection problem of fault injection attacks in electronic devices is solved, and low-cost and efficient security protection is achieved.

CN120296724APending Publication Date: 2025-07-11NXP BV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411782837.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2024-01-10
Filing Date
2024-12-05
Publication Date
2025-07-11

AI Technical Summary

Technical Problem

The prior art is difficult to effectively detect and mitigate fault injection attacks in electronic devices, especially due to their low cost and sophisticated characteristics, which make it difficult for traditional methods to identify and defend against these attacks.

Method used

By monitoring power supply and clock cycles, detecting timing violations are detected to identify fault injection attacks, especially setting and maintaining violations, digital, low-power detection methods are realized by monitoring power supply and clock cycles, using detectors such as trigger registers and evaluation devices such as comparators.

Benefits of technology

It realizes effective detection of local and global fault injection attacks, with low gate counting and low power consumption, can be easily integrated in existing electronic devices, providing fast response and high reliability security protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120296724A_ABST
    Figure CN120296724A_ABST
Patent Text Reader

Abstract

The invention describes an electronic device (100) comprising: i) a detector (110) configured to monitor a power supply and / or clock cycle; and ii) an evaluation device (120) coupled to the detector (110) and configured to evaluate a monitoring result with respect to a timing violation caused by a fault injection (FI) attack.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to an electronic device having a detector and an evaluation device. Specifically, the electronic device is configured to detect attacks such as, for example, a fault injection (FI) attack using the detector and the evaluation device. The present disclosure further relates to a method for detecting an FI attack in an electronic device.

[0002] Thus, the present disclosure may relate to the technical field of electronic devices such as, for example, integrated circuits, and specifically to aspects of detecting attacks on such electronic devices. Background Art

[0003] Detecting attacks on electronic devices (especially electronic components) such as, for example, processors or integrated circuits (or devices including these components) may still be considered a challenge. For example, a "fault injection (FI) attack" may be an attack that coerces an electronic device in an unusual manner. This may be achieved, for example, using physical or software-based means or using a hybrid method. For example, physical fault injection may include applying high voltage, extreme temperature, or electromagnetic pulses on electronic components such as, for example, computer memories and central processing units. In an illustrative example, an electromagnetic coil may be moved above an electronic device, thereby inducing a pulse in the current of the electronic device.

[0004] Due to the prevalence of FI attacks and the decreasing cost of attack equipment, electronic devices may constantly be challenged to find better and more effective ways to mitigate and detect cheaper and more sophisticated attacks. In this regard, two typical FI attacks may include power glitches and electromagnetic FI (see above). Even via a logic interface (i.e., software-based), power glitch attacks are possible, which means that no equipment is required to perform them, and little control of the power configuration of the electronic device is required to abuse the function. Summary of the Invention

[0005] There may be a need to detect fault injection attacks on an electronic device in an effective and reliable manner. An electronic device and a method are provided.

[0006] According to one aspect of the present disclosure, an electronic device (e.g., an integrated circuit) is described, which includes:

[0007] i) a detector (e.g., including a trigger register), which is configured to detect / monitor the power supply (supply voltage) and / or the clock period (of the electronic device; provided to the detector), and

[0008] ii) an evaluation device (e.g., including a comparator), which is coupled to the detector and is configured to evaluate the detection / monitoring result with respect to timing violations (e.g., setup violations and / or hold violations) caused by a (local or global) (fault injection) attack on the electronic device.

[0009] According to another aspect of the present disclosure, a method for detecting an attack (specifically, a fault injection attack), especially in a fully digital implementation, is described. The method includes:

[0010] i) Monitoring a power supply and / or clock cycles; and

[0011] ii) Evaluating the monitoring result with respect to a timing violation caused by the (fault injection) attack.

[0012] As used herein, the term "electronic device" may particularly refer to an electronic component or a device including such an electronic component. In one example, the electronic device may include an integrated circuit (IC) or a processor. In one example, the electronic device may include a memory, a central processing unit, a digital circuit, a cryptographic engine, or a circuit board.

[0013] As used herein, the term "timing violation" may particularly refer to a deviation from a specific / specified timing requirement in an electronic device. This timing violation may include a mismatch between the actual timing behavior and the (design) constraints of the electronic device. Examples of timing violations may include setup violations and hold violations.

[0014] According to an exemplary embodiment, the present disclosure may be based on the concept that when a detector (e.g., a D flip-flop) monitors a power supply and / or a clock within an electronic device and transmits the monitoring result (voltage signal) to an evaluation device (e.g., a comparator), and the evaluation device detects an attack based on a timing violation in the monitoring result, a fault injection attack on the electronic device can be detected in an effective and reliable manner. An FI attack may directly affect the power supply and / or the clock of the electronic device, and these effects can be directly detected based on a timing violation.

[0015] It has been shown that FI attacks typically only locally affect an electronic device, making these attacks difficult to detect. Therefore, in a preferred embodiment, a plurality of detectors may be distributed over the electronic device, enabling the detection of local FI attacks. In another preferred embodiment, the plurality of detectors are coupled to a common evaluation device such that the monitoring results of the plurality of detectors can be used as a reference for detecting (local) timing violations.

[0016] In one embodiment, the described detection method can allow for a cost-effective solution to find such attacks. Embodiments with a detector and an evaluation means (such as a trigger and a comparator) can have an extremely low gate count (around a few dozen gate equivalents). The detection method can be implemented (mainly) digitally (without the need for analog changes and customization according to the technology), and can have extremely low power consumption (no dynamic activity). Local FI (e.g., EMFI) or global FI (e.g., power glitches) of the power supply can be detected effectively and reliably. Additionally, due to its digital nature, the described detection method can be easily integrated into existing electronic devices.

[0017] Based on the examples of embodiments to be described below, the above-defined aspects and additional aspects of the present disclosure are obvious and are illustrated with reference to these examples of embodiments. The present disclosure will be described in more detail below with reference to the examples of embodiments, but the present disclosure is not limited to these examples of embodiments.

[0018] Exemplary embodiment

[0019] According to one embodiment, the detector is configured to detect a setup violation as a timing violation. The term "setup violation" can refer to a known timing violation, for example, when the input signal to a register (such as a flip-flop or a latch) is unstable for a sufficient duration before the arrival of the clock edge.

[0020] According to one embodiment, the setup violation includes at least one of the following (caused by at least one of the following): global undervoltage, local undervoltage, clock glitch. Thus, the negative impact of the FI attack can be measured via the setup violation.

[0021] According to one embodiment, the electronic device includes a long-delay function (specifically, a long-delay block / element / component) to introduce a long delay for detecting setup violations. Thereby, the detection of setup violations can be improved.

[0022] According to one embodiment, the detector is configured to detect a hold violation as a timing violation. The term "hold violation" can refer to a known timing violation, for example, when the input signal to a register (such as a flip-flop or a latch) does not remain stable for the required duration after the clock edge.

[0023] According to one embodiment, the hold violation includes at least one of global overvoltage and local overvoltage. Thus, the negative impact of the FI attack can be measured via the hold violation.

[0024] According to one embodiment, the electronic device includes a short-delay function (specifically, a short-delay block / element / component) to introduce a short delay for detecting hold violations. Thereby, the detection of hold violations can be improved.

[0025] According to one embodiment, the evaluation device is configured to compare a short-delay voltage signal (VDET3) with a static signal. In this way, another signal (such as VDET4) may not be required, thus saving effort.

[0026] According to one embodiment, the detector includes a register unit for monitoring. According to one embodiment, the register unit is coupled to a long-delay function and / or a short-delay function. The term "register" may particularly refer to a fast-accessible location available to an integrated circuit or a processor. A register may be implemented, for example, with flip-flops. A flip-flop may be a circuit (bistable multivibrator) that can have two stable states that can store state information. The circuit can change state by signals applied to one or more control inputs and can output its state. A flip-flop can be regarded as a basic building block of an electronic system.

[0027] According to one embodiment, the register unit includes D (data or delay) flip-flops. Thus, the register unit can be implemented in a straightforward manner using existing electronic components. A D flip-flop can capture the value of the D input at an explicit part of a clock cycle (such as the rising edge of the clock). The captured value becomes the Q output. At other times, the output Q may not change (compare Figure 2 and 3).

[0028] According to one embodiment, the detector is a first detector, and the electronic device further includes: a second detector, which is coupled to the evaluation device. According to one embodiment, the first detector is spatially separated from the second detector. According to one embodiment, the electronic device includes a plurality of detectors. According to one embodiment, the plurality of detectors are spatially separated from each other, for example, evenly or unevenly distributed above the electronic device. Since FI attacks are usually only local with respect to the electronic device, the detection performance can be significantly improved when a plurality of detectors are distributed (and electrically coupled) above the electronic device.

[0029] According to one embodiment, the electronic device includes five or more detectors, specifically ten or more detectors. Depending on the size (area) and density of the electronic device, a specific number of detectors may be particularly advantageous. Reliable attack detection can be achieved if most areas of the electronic device are monitored and covered. In an exemplary embodiment, in a 1 mm 2 area, four to eight detectors can be arranged.

[0030] According to one embodiment, the detectors are particularly arranged at / near important areas (such as the central processing unit) of the electronic device. In one example, security-related applications (such as a cryptographic engine, a security element) can be particularly protected against FI attacks (by a sufficient number of detectors). For example, one to four detectors can be arranged around this security-related component.

[0031] According to one embodiment, the evaluation device is configured to: compare the monitoring results of a first detector and a second detector such that the first detector serves as a reference for the second detector, or vice versa. According to one embodiment, a plurality of monitoring results (e.g., five or more) are compared with each other. Thereby, the monitoring results of the detectors can serve as references for each other and no additional reference will be needed. Thus, time and effort can be saved. In the case of a local attack, only one monitoring result will show an error while the other monitoring results appear normal.

[0032] According to one embodiment, the electronic device further includes: a clock device configured to provide a clock to the detector. In this way, the clock cycle can be effectively checked. According to one embodiment, the electronic device is configured as an integrated circuit (IC) to enable economically important applications.

[0033] According to one embodiment, the evaluation device includes a comparator. This can enable a direct and cost-effective implementation. Using the comparator, the monitoring results from different detectors can be easily compared.

[0034] According to one embodiment, the electronic device includes a determination unit configured to analyze the evaluation result of the evaluation unit and determine the location of a fault injection attack in the electronic device. For example, the determination unit can be configured to select the detector from which the error signal originates. If the detector is known, the corresponding area in the electronic device can be identified.

[0035] According to one embodiment, the FI attack can originate from a setup time or hold time violation. If the setup time is violated, data cannot be properly captured at the next clock edge. Similarly, if the hold time is violated, the data that is supposed to be captured at the next edge will be captured at the same edge. Either or a combination of both on a subset of the registers in the electronic device causes its malfunction, leading to an unspecified or unexpected state that may pose a security vulnerability. The electronic device described herein can be dedicated to detecting setup violations and / or hold violations. BRIEF DESCRIPTION OF THE DRAWINGS

[0036] Figure 1 An electronic device having a plurality of detectors coupled to a common evaluation device is shown according to an exemplary embodiment of the present disclosure.

[0037] Figure 2 A detector having a flip-flop register is shown according to an exemplary embodiment of the present disclosure.

[0038] Figure 3A The detection of a setup violation is schematically shown according to an exemplary embodiment of the present disclosure.

[0039] Figure 3BSchematically shows the detection of hold violations according to an exemplary embodiment of the present disclosure.

[0040] Figure 4 Shows an evaluation device with a comparator according to an exemplary embodiment of the present disclosure. Detailed Description

[0041] Before referring to the drawings, the embodiments will be described in more detail, and some basic considerations will be outlined, based on which the embodiments of the present disclosure have been developed.

[0042] According to an exemplary embodiment, the present disclosure may relate to a setup and hold violation detector that adds a layer of meaningful security protection against fault injection (FI) attacks, particularly glitches and electromagnetic FI (EMFI). FI detection can be achieved by an arrangement of distributed detectors / sensors dedicated to directly detecting timing violations. One of the main advantages of the present disclosure compared to well-known sensing concepts for, e.g., glitches, is that it can be physically placed within the boundaries of an architecture that cannot or should not be modified. Additionally, due to its very low gate count and power consumption, it can be instantiated several times, thus providing greater coverage for highly localized attacks.

[0043] According to an exemplary embodiment, most known detectors focus on detecting glitches by monitoring sudden power drops at the power supply or by checking high- or low-frequency edges observed in the clock. However, they rely on observations that require additional references and individual observation points at the power supply or the clock, respectively. Additionally, they require fine-tuning (not enabled from reset) and require a large gate count and power consumption (with multiple switching elements internally).

[0044] In contrast, the described detection method can address the source of fault injection due to setup or hold time violations. It may not include switching elements, and thus its power consumption can be minimal. It may additionally not require a large gate count, and thus it can be easily proliferated and distributed over all sensitive components of an electronic device (e.g., a system-on-chip). Its detection principle is straightforward and may not require a reference, and thus may not require any kind of fine-tuning and can be enabled immediately after the electronic device is powered on.

[0045] Figure 1An electronic device 100 is shown having a plurality of detectors 110, 111 coupled to a common evaluation device 120, according to an exemplary embodiment of the present disclosure. In this example, the electronic device 100 is configured as an integrated circuit (IC) and includes the plurality of detectors, including a first detector 110 and a second detector 111. Each detector 110 is configured to monitor power supplies and / or clock cycles within the electronic device 100. Each detector 110, 111 is connected to the evaluation device 120, which is configured to evaluate the monitoring results of the detectors 110, 111 with respect to timing violations caused by a fault injection attack. The detectors 110, 111 are spatially separated from each other and distributed over the entire electronic device 100 (as can be seen in this plan view). Thus, local FI attacks can be detected particularly effectively, especially without additional references.

[0046] In this example, the evaluation device 120 includes a comparator to compare the monitoring results from the detectors 110, 111. Additionally, the evaluation device 120 includes a capture unit 125 (see also Figure 4 ) to determine the localization of the FI attack within the electronic device 120 (record the detection source). The electronic device 100 also includes a reset unit 130, which is coupled to the evaluation device 120 and is configured to reset the electronic device 100 (initiate a restart of the IC) in the event of a determined FI attack (here indicated by the VDET ERROR signal).

[0047] Figure 2 An implementation of the detector 110 is shown, according to an exemplary embodiment of the present disclosure. The detector 110 includes a register unit 115 implemented as a D flip-flop. The register unit 115 receives the power supply VDD and the clock within the electronic device 100. The FI attack is schematically indicated by an arrow as possibly affecting the supply voltage and / or the clock cycle.

[0048] To effectively detect timing violations, the detector 110 includes a long delay function / block 116 coupled to the register unit 115, and a short delay function / block 118 also coupled to the register unit 115. Regarding the long delay, two voltage signals VDET 1 and VDET 2 are monitored and sent to the evaluation device 120. These voltage signals are particularly related to setting violations such as, for example, "voltage too low" or "clock cycle too short". Regarding the short delay, one voltage signal VDET 3 is sent to the evaluation device 120. This voltage signal is particularly related to a hold violation such as, for example, "voltage too high".

[0049] A long delay can be selected such that the setup time is minimized at the slowest corner. Short delays in the clock path force the BE tool to add just enough delay in the data path to avoid hold violations at all corners. An explicit short delay may not be necessary as there may be hold requirements of the flip-flop itself.

[0050] The setup violation detection logic can be configured to detect global / local undervoltage on the power supply and / or clock glitches. The status is signaled via VDET 1 and VDET 2. The hold violation detection logic can be configured to detect global / local overvoltage on the power supply. The status is signaled via VDET 3.

[0051] Figure 3A Schematically shows the detection of a setup violation according to an exemplary embodiment of the present disclosure. Signals VDET 1 and VDET 2 are output Q by the register unit 115 of the detector 110. The comparison with the input D to the register unit 115 results in the detection of a timing violation (indicated in Figure 3A ) that causes the VDET ERROR signal.

[0052] Figure 3B Schematically shows the detection of a hold violation according to an exemplary embodiment of the present disclosure. Signal VDET 3 is output Q by the register unit 115 of the detector 110. The comparison with the input D to the register unit 115 results in the detection of a timing violation (indicated in Figure 3B ) that causes the VDET ERROR signal.

[0053] Figure 4 Shows an evaluation device 120 with a comparator according to an exemplary embodiment of the present disclosure. The comparator includes a heartbeat checker function to check that no detector is stuck. This function can be implemented for each detector. The comparator further includes a setup violation comparator 122 (e.g., comparing VDET 1 and VDET 2 signals from all detectors) and a hold violation comparator 123 (e.g., comparing VDET 3 signals from all detectors). In the combined comparator 124, all signals from the detectors can be compared. Based on the evaluation result, an error signal VDET ERROR (at reference numeral 126) can be generated. As Figure 1 shown, the error signal can be sent to the reset unit 130 to restart / reset at least a part of the electronic device 100. Additionally, the capture unit 125 (or determination unit) can record the detection source to identify the specific location of the FI attack in the electronic device 100. In a particular example, the detectors themselves and with each other act as references for setup checks, while the expected values for hold checks are known a priori.

Claims

1. An electronic device (100), characterized in that, Comprising: a detector (110) configured to monitor at least one of a power supply, a clock cycle; and an evaluation device (120) coupled to the detector (110) and configured to evaluate the monitoring result based on a timing violation caused by an attack.

2. The electronic device (100) according to claim 1, It is characterized in that wherein the detector (110) is configured to detect a setting violation as the timing violation.

3. The electronic device (100) according to claim 2, characterized in that, The setting violation includes at least one of: a global undervoltage, a local undervoltage, a clock glitch.

4. The electronic device (100) according to any one of the preceding claims, It is characterized in that wherein the electronic device (100) includes a long delay function (116) to introduce a long delay for detecting the setting violation.

5. The electronic device (100) according to any one of the preceding claims, It is characterized in that wherein the detector (110) is configured to detect a hold violation as the timing violation.

6. The electronic device (100) according to claim 5, characterized in that, The hold violation includes at least one of: a global overvoltage, a local overvoltage.

7. The electronic device (100) according to any one of the preceding claims, It is characterized in that wherein the electronic device (100) includes a short delay function (118) to introduce a short delay for detecting the hold violation.

8. The electronic device (100) according to any one of the preceding claims, It is characterized in that wherein the detector (110) includes a register unit (115) for monitoring, wherein the register unit (115) is coupled to at least one of: the long delay function (116), the short delay function (118).

9. The electronic device (100) according to any one of the preceding claims, It is characterized in that wherein the detector (110) is a first detector (110), and wherein the electronic device (100) further includes: a second detector (iii) coupled to the evaluation device (120); wherein the first detector (110) is spatially separated from the second detector (120).

10. A method for detecting a fault injection FI attack, characterized in that, The method includes: monitoring at least one of: a power supply, a clock cycle, which are within the electronic device (100); and evaluating the monitoring result based on a timing violation caused by the attack.