Electronic device and method for detecting security attack

By introducing voltage sensing circuits into integrated circuits to detect voltage waveform differences and identify voltage bypass attacks, the problem of sensitive data leakage caused by voltage glitches in existing technologies is solved, and effective protection of integrated circuits is achieved.

CN121786894APending Publication Date: 2026-04-03NUVOTON
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-03
Publication Date
2026-04-03

AI Technical Summary

Technical Problem

Existing technologies are insufficient to effectively detect and defend against voltage bypass attacks, especially voltage glitches, which can lead to the leakage of sensitive data in integrated circuits.

Method used

By introducing a voltage sensing circuit into an integrated circuit, a sensing voltage waveform is received from the power input using an electrical connection different from the operating voltage. The voltage waveform difference is detected to identify security attacks, and protective measures are taken when an attack is detected.

Benefits of technology

It achieves effective detection and defense against voltage bypass attacks, protecting sensitive data in integrated circuits and preventing unauthorized data access.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121786894A_ABST
    Figure CN121786894A_ABST
Patent Text Reader

Abstract

An electronic device and a method for detecting security attacks are provided, where the electronic device includes a power input, a protected circuit, and a voltage sensing circuit. A protected circuit is configured to draw current from the power supply input to obtain an operating voltage waveform from the power supply input. The voltage sensing circuit is configured to receive a sensing voltage waveform different from the operating voltage waveform from the power supply input through a second electrical connection different from the first electrical connection, and detect a security attack on the protected circuit in response to the sensing voltage waveform.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the security of electronic devices, and in particular to methods and apparatus that allow the detection of voltage power supply bypass attacks. Background Technology

[0002] Attackers attempting to extract confidential data from an integrated circuit sometimes employ voltage side-channel error-injection attacks. Some background information on glitch-detection side-channel attacks can be found in U.S. Patent Application Publication No. 2023 / 0102249, which discloses a method comprising: selecting an impedance threshold for a battery in electronic communication with an integrated circuit; acquiring an impedance of the battery; calculating an average impedance of the battery over a period of time; determining whether the integrated circuit is a victim of a power side-channel attack if the average impedance of the battery over that period exceeds the impedance threshold; and responding to the power side-channel attack.

[0003] U.S. Patent Application Publication No. 2024 / 0005045 discloses a system-on-a-chip (SoC) including a memory controller. The memory controller has a clock synchronization circuitry based on a phase-locked loop (PLL). The SoC further includes a voltage glitch attack detector. The voltage glitch attack detector is configured to monitor a clock synchronization signal generated by the clock synchronization circuitry and check whether the monitored clock synchronization signal is a nominal signal or a signal characteristic of a voltage glitch attack. The voltage glitch attack detector can be a software detector executed by a processing unit.

[0004] U.S. Patent 9,523,722 discloses a monolithic integrated circuit device including a power supply voltage glitch detector for detecting improper power supply voltage conditions. The detection threshold of the power supply voltage glitch detector is adaptively set based on the device's operating mode or a specific part of the device, which is determined internally by the device based on specific inputs received by the device (e.g., instructions, interrupts, control signals, etc.). Summary of the Invention

[0005] An embodiment of the present invention provides an electronic device comprising a power input, a protected circuit, and a voltage sensing circuit. The protected circuit is configured to draw current from the power input to obtain an operating voltage waveform from the power input. The voltage sensing circuit is configured to receive a sensed voltage waveform, different from the operating voltage waveform, from the power input via a second electrical connection different from a first electrical connection, and to detect a security attack on the protected circuit in response to the sensed voltage waveform.

[0006] In some embodiments, the first electrical connection includes a first number of bonding wires, and the second electrical connection includes a second number of bonding wires.

[0007] In one embodiment, the voltage sensing circuit is configured to detect a security attack in response to a sensed voltage waveform and a comparison between the sensed voltage waveform and an operating voltage waveform. In another embodiment, the voltage sensing circuit is configured to detect a security attack based on the sensed voltage waveform, independent of the operating voltage waveform.

[0008] In some embodiments, the voltage sensing circuit is configured to activate a security protection measure in response to the detection of a security attack.

[0009] According to one embodiment described herein, an additional method is provided, comprising, in a protected circuit of an electronic device, drawing current from a power input to obtain an operating voltage waveform from the power input. In a voltage sensing circuit of the electronic device, a sensed voltage waveform, different from the operating voltage waveform, is received from the power input via a second electrical connection different from a first electrical connection, and in response to the sensed voltage waveform, a security attack on the protected circuit is detected.

[0010] The invention will be more fully understood from the following detailed description of various embodiments of the invention, taken in conjunction with the accompanying drawings. Attached Figure Description

[0011] Figure 1 A block diagram illustrating an anti-attack electronic device according to an embodiment of the present invention.

[0012] Figure 2A block diagram illustrating a differential detection anti-attack electronic device according to an embodiment of the present invention is provided.

[0013] Figure 3 The flowchart illustrates a security attack detection method according to an embodiment of the present invention.

[0014] Symbol Explanation

[0015] 100: Anti-attack electronic devices

[0016] 102, 202: Integrated Circuits

[0017] 104, 204: Protected circuits

[0018] 106, 206: Power input

[0019] 107, 207: Capacitors

[0020] 108, 208: Power supply voltage traces

[0021] 110, 120, 210: Bond wire

[0022] 112, 122, 212, 220: solder pads

[0023] 114, 214: Voltage sensing circuit

[0024] 116, 216: Voltage sensing input

[0025] 200: Differential Detection Anti-Attack Electronic Device

[0026] 230: Voltage comparator

[0027] Ipc: Current

[0028] 300: Flowchart

[0029] 302, 304, 306, 308: Operations Detailed Implementation

[0030] Overview

[0031] Electronic devices often contain sensitive data (e.g., passwords, authentication keys, encryption keys, etc.).

[0032] Hackers often use side-channel attacks to access sensitive data without authorization. Examples include monitoring the power consumption of integrated circuits (ICs), timing measurement attacks, and electromagnetic and acoustic radiation signature attacks.

[0033] Error injection is a type of attack in which hackers inject errors (called "glitches") into integrated circuits in an attempt to bypass security measures that the integrated circuit may contain, or otherwise transform the integrated circuit into an abnormal state, thereby leaking sensitive information. The following describes a security attack involving injecting noise into the power input of an integrated circuit (power supply noise injection).

[0034] When an integrated circuit is packaged, a hacker may not be able to directly access the IC's power input. Instead, they can inject errors through the IC package's power input, which is connected to the IC via one or more bonding wires. It should be noted that the power input pin may contain the actual power supply pin, or sometimes it may contain the pin for a filter capacitor used in an on-chip low-dropout (LDO) regulator. Error injection can be performed through both types of power input pins. These two types of power input pins will be referred to below as the "supply voltage (Vdd)".

[0035] Embodiments of the present invention provide circuits and methods for detecting and taking protective measures in response to security attacks. In one embodiment, the integrated circuit includes a protected circuit (capable of processing confidential data) and a sensing circuit. The power supply of the protected circuit is connected to a power supply voltage (Vdd) trace in a printed circuit board (PCB) via one or more bonding wires. The voltage at the power supply input of the protected circuit is referred to as the operating voltage. In some embodiments, the PCB refers to a PCB of a ball grid array (BGA) package substrate, rather than a circuit board with chips mounted on it.

[0036] In order to inject a large number of glitches (the glitch intensity may be sufficient to disrupt the operation of the protected circuit) into the power input terminal of the protected circuit, the hacker must inject larger glitches into the power voltage traces on the printed circuit board due to the inductance of the bond wire.

[0037] In some embodiments, power supply voltage traces on a printed circuit board are connected via individual bond wires (or a set of bond wires) to a sensing circuit that detects security attacks (e.g., glitch on the power supply voltage trace) and takes protective measures when an attack is detected. In some embodiments, the detection circuit may selectively or additionally compare the input voltage of the protected circuit with the voltage on the power supply voltage trace in the PCB.

[0038] System Description

[0039] The following disclosure refers to an electronic device comprising an integrated circuit. The integrated circuit further comprises one or more sensitive circuits. These one or more sensitive circuits are protected against unauthorized access (protected circuitry). In some embodiments, the electronic device includes circuitry for detecting side-channel attacks. Side-channel attacks comprise electrical noise injection through the power input of the electronic device. In some embodiments, the integrated circuit is connected to the power input of the electronic device via one or more bonding wires.

[0040] Individuals or entities that attempt to access data in electronic devices without authorization are called hackers.

[0041] Figure 1 This is a block diagram illustrating an attack-resistant electronic device 100 according to an embodiment of the present invention. The attack-resistant electronic device 100 includes an integrated circuit 102. The integrated circuit 102 further includes a protected circuit 104. The protected circuit 104 can store confidential data (e.g., encryption keys, passwords, signatures, etc.). It should be clarified that, in the current context, the term "protected circuit" refers to any circuit that contains or processes confidential data, containing a complex processor core performing complex computing or communication tasks, but which may occasionally process confidential data.

[0042] The protected circuit 104 includes a power input 106. The power input 106 is coupled to ground via an integrated noise-decoupling capacitor 107 (note that the noise-decoupling capacitor 107 includes on-IC decoupling capacitance and does not include any off-IC decoupling capacitance that a hacker could disconnect). In some embodiments, a voltage regulator (e.g., a low-dropout regulator) is used in place of or to supplement the noise-decoupling capacitor 107. In one embodiment, when using a low-dropout regulator, the attack-resistant electronics 100 may include an external filter capacitor. The external filter capacitor is connected to a dedicated pin in the package.

[0043] The current supplied to the protected circuit 104 through the power input 106 is called the supply current Ipc. The voltage across the power input 106 is called the operating voltage.

[0044] A hacker might attempt to introduce glitches or abnormal voltage levels on power input 106 in an attempt to bypass data protection mechanisms that the protected circuit 104 may have. For example, a glitch might alter the program counter of the processor in the protected circuit, potentially bypassing any protective software code (in the following description, the term "security attack" in this invention refers to such noise injection attempts, although the term "security attack" generally encompasses many other types of attacks).

[0045] However, hackers typically only have access to the package pins of the integrated circuit, and not directly to the power input 106 in integrated circuit 102. The power supply voltage trace 108 on the printed circuit board is electrically connected to integrated circuit 102. According to... Figure 1 In the illustrated embodiment, the electrical connection includes a bonding wire 110. The bonding wire 110 is connected to the pad 112 of the integrated circuit 102. Alternatively, any other suitable type of electrical connection may be used (when using an external low-dropout filter capacitor for the integrated circuit, a hacker may typically use a decoupling capacitor pin or a Vdd input pin to perform a pulse insertion after removing the filter capacitor).

[0046] The bonding pad 112 is connected within the integrated circuit to the power input 106 of the protected circuit 104. In some embodiments, the impedance in each bonding wire 110 includes resistance and inductance, respectively in the range of tens of milliohms and a few nanohenries. To reduce resistance and inductance, the three bonding wires 110 are connected in parallel (in some alternative embodiments, any other suitable number of bonding wires may be used).

[0047] The waveform of the operating voltage (on power input 106) changing over time is referred to as the operating voltage waveform. In some embodiments, the supply current Ipc of the protected circuit 104 is relatively large, and although it is distributed among the three bond wires, the current in each bond wire is still quite large (in other embodiments, the supply current may be low when no fault injection occurs, and only one bond wire 110 is needed; in one embodiment, the current may be significantly larger during fault injection). The currents are designated as current Ipc-a, current Ipc-b, and current Ipc-c via the three bond wires 110.

[0048] To induce a voltage spike sufficient to disrupt the normal operation of the protected circuit 104, the noise decoupling capacitor 107 must be rapidly charged or discharged. This means a significant voltage drop across the bond line 110 (forcing a large di / dt through the inductor). Consequently, the spikes applied by a hacker to the power supply voltage trace 108 on the printed circuit board will be much stronger than those observed on the operating voltage waveform. For example, in some embodiments, to induce a 0.5V spike at the power input 106 of the protected circuit 104, a hacker might apply a spike of several positive or several negative volts to the power supply voltage trace 108 on the printed circuit board.

[0049] To detect security attacks, integrated circuit 102 further includes a voltage sensing circuit 114. The voltage sensing input 116 of the voltage sensing circuit 114 is coupled via an electrical connection, which is separate from the electrical connection used to connect the protected circuit 104. In this example, the electrical connection of the voltage sensing circuit 114 includes a bonding wire 120 (bonding wire 120 is different from bonding wire 110).

[0050] The voltage sensing input 116 of the voltage sensing circuit 114 is coupled to the power supply voltage trace 108 of the printed circuit board via a bonding wire 120 and a solder pad 122 (the current through the voltage sensing input 116 is negligible; therefore, the voltage at the voltage sensing input 116 of the voltage sensing circuit 114 closely matches the voltage level on the power supply voltage trace 108 of the printed circuit board). The voltage level of the voltage sensing input 116 is referred to as the sensing voltage, and the waveform of the sensing voltage changing over time is referred to as the sensing voltage waveform. Because the sensing voltage closely matches the voltage level on the power supply voltage trace 108 of the printed circuit board, the voltage sensing circuit can easily detect drastic voltage fluctuations on the power supply voltage trace of the printed circuit board. In one embodiment, the voltage sensing circuit 114 compares the sensing voltage with predefined thresholds (e.g., twice the power supply voltage and 0.2 times the power supply voltage) to detect spikes in the power supply input 106 indirectly applied to the protected circuit and generate a security attack warning accordingly.

[0051] In some embodiments, the circuitry in integrated circuit 102 may activate security protection measures (e.g., resetting or permanently erasing sensitive data) in response to such a security attack warning. In one embodiment, the voltage sensing circuitry is configured to take security protection measures, in addition to sending a warning to the integrated circuit, or alternatively, to send a warning to the integrated circuit using security protection measures.

[0052] Figure 1The configuration of the anti-attack electronic device 100 shown is referenced by way of example. Other configurations may be used in alternative embodiments. For example, in some embodiments, the anti-attack electronic device 100 (e.g., in the form of a chip) is packaged in a leadframe, and bonding wires 110 connect pads in the leadframe to pads in the integrated circuit. In some embodiments, the number of bonding wires connecting the power input of the protected circuit to the power supply voltage trace may be less than (including 1) or greater than 3.

[0053] Differential detection

[0054] like Figure 1 As shown, the anti-attack electronic device 100 detects security attacks on the electronic device based on the sensed voltage at the input of the voltage sensing circuit 114, which closely corresponds to the voltage on the power supply voltage trace 108 of the printed circuit board. As previously mentioned, an attacker could inject a large number of voltage spikes into the power supply voltage trace 108 of the printed circuit board to achieve operating voltage spikes, which could potentially cause the protected circuit 104 to malfunction.

[0055] However, in some embodiments, attack detection can be achieved if the sensing circuit also (or additionally) checks the difference between the operating voltage waveform and the sensing voltage waveform. Ignoring any voltage drop across the bond wire 120 and the pad 122 (because the current consumption of the sensing circuit is negligible), this difference is proportional to the rate of change of the operating waveform. In other words, this difference represents the sum of the first derivative of the supply current Ipc multiplied by the inductance of the bond wire, plus the product of the current and the resistance.

[0056] Figure 2 This is a block diagram illustrating a differential detection anti-attack electronic device 200 according to an embodiment of the present invention.

[0057] Similar to the anti-attack electronic device 100, the differential detection anti-attack electronic device 200 includes a protected circuit 204. The protected circuit 204 receives a supply current Ipc from the power supply voltage trace 208 of the printed circuit board via one or more bonding wires 210 and a plurality of pads 212 at a power input 206 of the protected circuit that is coupled to ground through a capacitor 207.

[0058] The voltage sensing circuit 214 receives the sensing voltage from the power supply voltage trace 208 on the printed circuit board at the voltage sensing input 216 via the bonding wire 210 and the pad 220.

[0059] With voltage sensing circuit 114 ( Figure 1Unlike other voltage sensing circuits, voltage sensing circuit 214 includes a voltage comparator 230. The voltage comparator compares the voltage sensing waveform (at voltage sensing input 216) with the operating voltage waveform of the protected circuit (at power input 206). In some embodiments, the sensing circuit detects a security attack in response to the comparison between the voltage sensing waveform and the voltage waveform of the protected circuit.

[0060] In some embodiments, the sensing circuit warns of a security attack when the absolute value of the difference between the voltage sensing waveform and the voltage waveform of the protected circuit exceeds a preset threshold. In other embodiments, different thresholds may be set for positive and negative glitches. In other embodiments, the sensing circuit may include a multi-source attack detection circuit. The multi-source attack detection circuit includes a first threshold for positive-edges, a second threshold for negative-edges, a third threshold for the maximum value of the sensing voltage waveform, and a fourth threshold for the minimum value of the sensing voltage waveform. In one embodiment, the thresholds are programmable.

[0061] Power supply to the sensing circuit

[0062] The configuration of the anti-attack electronics 100 and the differential detection anti-attack electronics 200 does not involve the power supply of the sensing circuit. It should be noted that if the power input to the sensing circuit is the operating voltage, glitches generated at the operating voltage may impair the operation of the sensing circuit. Therefore, in some embodiments, the sensing circuit is configured to operate at a voltage far below the minimum voltage of the protected circuit.

[0063] In another embodiment, the power input of the sensing circuit is the sensing input. The power consumption of the sensing circuit is much lower than that of the protected circuit. Therefore, the supply voltage of the sensing circuit will closely correspond to the Vdd power supply trace on the printed circuit board.

[0064] method

[0065] Figure 3 Flowchart 300 schematically illustrates a security attack detection method according to an embodiment of the present invention. The security attack detection method comprises a differential detection anti-attack electronic device 200 (…). Figure 2 The differential detection anti-attack electronic device 200 includes a voltage sensing circuit 214.

[0066] Flowchart 300 begins with operation 302, which provides the operating voltage, wherein the electronic device transmits the operating voltage from the power supply voltage traces on the printed circuit board to the power input of the protected circuit 204 via one or more bond wires.

[0067] Next, in operation 304 of providing the sensing voltage, the electronic device transmits the sensing voltage from the power supply voltage traces on the printed circuit board to the voltage sensing input of the voltage sensing circuit 214 via one or more bonding wires.

[0068] according to Figure 3 As shown in flowchart 300, a hacker cannot directly access the core of the protected circuit 204. Therefore, in order to apply glitches to the operating voltage, a hacker would apply glitches to the power supply voltage traces on the printed circuit board. However, due to the inductance of the bond wires (typically on the order of a few millihenries), the glitches applied by a hacker to the power supply voltage traces on the printed circuit board would have to be much larger. In some embodiments, this can reach several volts (positive and negative voltage).

[0069] The sensing circuit can detect Vdd glitches by monitoring the sensing voltage (which is closely matched to the voltage of the power supply traces on the printed circuit board). Furthermore, by comparing the operating voltage and the sensing voltage, the sensing circuit can directly measure the rate of change of the supply current to the protected circuit, which may indicate the presence of a Vdd glitch attack.

[0070] In operation 306 of detecting a security attack, the sensing circuit detects the security attack according to a preset standard, which may include comparing the sensing voltage with a preset threshold (e.g., the threshold voltage of a transistor) and comparing the difference between the operating voltage and the sensing voltage with a preset threshold (e.g., the threshold voltage of a transistor, etc.).

[0071] Finally, in operation 308, where security measures are taken, the electronic device can again protect against security attacks. In one embodiment, the electronic device is reset. In another embodiment, the electronic device can erase sensitive information, or in yet another embodiment, a fuse is blown to disable access to the core of the protected circuit. After operation 308, flowchart 300 ends.

[0072] Figure 3 The configuration of flowchart 300 shown and the content described above are for illustrative purposes only. Other configurations may be used in alternative embodiments. For example, in one embodiment, the sensing circuit is not connected to the operating voltage and detects security attacks solely based on the sensing voltage.

[0073] The above, Figures 1 to 3The illustrated anti-attack electronics 100 and differential detection anti-attack electronics 200 configurations, including voltage sensing circuits 114 and 214, and the method of flowchart 300, are illustrative configurations and methods shown purely for conceptual clarity. Any other suitable configurations and methods may be used in alternative embodiments. Different elements of integrated circuits 102 and 202 may be implemented in an integrated circuit (e.g., an application-specific integrated circuit (ASIC) or a field-programmable gate array (FPGA)).

[0074] Therefore, it is understood that the above embodiments are merely illustrative references, and the present invention is not limited to the content specifically presented and described herein. Rather, the scope of the present invention includes combinations and sub-combinations of the various features described above, as well as variations and modifications that will be obvious to those skilled in the art after reading the above description but not disclosed in the prior art. References incorporated herein by reference should be considered an integral part of the application; however, if any definition of terms in these references conflicts with the express or implied definitions in this specification, the definitions in this specification shall prevail.

Claims

1. An electronic device, characterized in that, include: One power input; A protected circuit is configured to draw current from the power input to obtain an operating voltage waveform from the power input. as well as A voltage sensing circuit is configured to receive a sensed voltage waveform, different from the operating voltage waveform, from the power input via a second electrical connection different from a first electrical connection, and to detect a security attack on the protected circuit in response to the sensed voltage waveform.

2. The electronic device as claimed in claim 1, characterized in that, The first electrical connection includes a first number of bonding wires, and the second electrical connection includes a second number of bonding wires.

3. The electronic device as claimed in claim 1, characterized in that, The voltage sensing circuit is configured to detect the security attack in response to the sensed voltage waveform and a comparison between the sensed voltage waveform and the operating voltage waveform.

4. The electronic device as claimed in claim 1, characterized in that, The voltage sensing circuit is configured to detect the security attack based on the sensing voltage waveform, independent of the operating voltage waveform.

5. The electronic device as claimed in claim 1, characterized in that, The voltage sensing circuit is configured to activate a security protection measure in response to the detection of the security attack.

6. A method for detecting security attacks, characterized in that, include: In a protected circuit of an electronic device, current is drawn from a power input to obtain an operating voltage waveform from the power input. as well as In a voltage sensing circuit of the electronic device, a sensing voltage waveform different from the operating voltage waveform is received from the power input through a second electrical connection different from a first electrical connection, and a security attack on the protected circuit is detected in response to the sensing voltage waveform.

7. The method as described in claim 6, characterized in that, The first electrical connection includes a first number of bonding wires, and the second electrical connection includes a second number of bonding wires.

8. The method as described in claim 6, characterized in that, The operation to detect the security attack is performed in response to the sensing voltage waveform and a comparison between the sensing voltage waveform and the operating voltage waveform.

9. The method as described in claim 6, characterized in that, The detection of this security attack is independent of the operating voltage waveform and is based on the sensing voltage waveform.

10. The method as described in claim 6, characterized in that, This also includes responding to the detection of the security attack by initiating a security protection measure.

Citation Information

Patent Citations

  • Power side-channel attack detection through battery impedance monitoring

    US20230102249A1

  • System on chip with voltage glitch detection based on clock synchronization monitoring

    US20240005045A1

  • Method and apparatus for supply voltage glitch detection in a monolithic integrated circuit device

    US9523722B2