Control flow consistency measurement for validating control flow in computing systems.
Control flow integrity measurements using a fault detection manager protect computing systems from fault injection attacks by validating control flow through cryptographic validation, enhancing security and integrity.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- GOOGLE LLC
- Filing Date
- 2022-03-25
- Publication Date
- 2026-05-15
AI Technical Summary
Computing systems are vulnerable to fault injection attacks that can bypass security features and alter control flow, compromising data integrity and security.
Implementing control flow integrity measurements through a fault detection manager that maintains and compares measurements during a scope, generating return values, and modifying them based on expression calculations to validate control flow, using cryptographic techniques to detect tampering.
Enhances security by preventing unauthorized control flow changes, ensuring the integrity of computations and protecting against fault injection attacks.
Smart Images

Figure 0007860234000001 
Figure 0007860234000002 
Figure 0007860234000003
Abstract
Description
Background Art
[0001] With the advancement of the computerization of society, the world is increasingly likely to be exposed to various cyberattacks that cause significant damage. The severity of these cyberattacks can vary, and they can not only affect the user's information security (e.g., digital currency transactions), but also pose a threat to the user's physical safety (e.g., autonomous driving). To prevent such cyberattacks, a number of security measures have been implemented in computing devices to prevent unauthorized access and manipulation of the device's data and communications. Although these security measures have already been proven to withstand thorough cyberattacks, these computing devices are continuously tested against state-of-the-art technologies that simulate potential cyberattacks for the purpose of identifying hardware or software vulnerabilities. The research field specialized in finding and breaking through the weaknesses of such security systems is called cryptanalysis.
[0002] In recent cryptanalysis evaluations, potentially security-threatening technologies including fault injection have been identified. In a fault injection attack, in contrast to software injection, the attacker may physically inject a fault into the computing system, which may involve intentionally changing the behavior of electronic components. As a result, a fault injection attack may bypass many system security features, change the behavior of the computing system to achieve malicious purposes, and / or extract confidential information. Physical fault injection attacks may include voltage glitches, clock glitches, laser injection, and electromagnetic injection, etc. In some cases, these cyberattacks may introduce as few as four fault injections at clearly defined locations, potentially breaking system security.
Summary of the Invention
[0003] This specification describes techniques and apparatus for performing control flow consistency measurements to validate control flow in a computing system. One embodiment discloses a method that includes maintaining a control flow measurement during a scope. The method further includes, during a scope, generating a return value for a calculation of an expression, the return value of which indicates whether the calculation of the expression was successful or unsuccessful. The method also includes, during a scope, modifying the measurement according to the calculated value in response to generating the return value of the expression, the calculated value being based on the measurement and the return value of the expression. The method further includes comparing the measurement to a predetermined value in order to validate the control flow during a scope.
[0004] In some embodiments, a system is also disclosed that includes an integrated circuit having at least one processor and at least one computer-readable storage medium coupled to the at least one processor. The computer-readable storage medium includes instructions that, when executed by the at least one processor, cause the processor to perform the method described above.
[0005] This outline is provided to introduce a simplified concept for performing control flow consistency measurements to validate control flows in computing systems, a concept that is further described in detail later and illustrated in the drawings. This outline is not intended to identify essential features of the claimed subject matter, nor is it intended to be used in determining the scope of the claimed subject matter.
[0006] This specification describes in detail one or more embodiments of control flow consistency measurements for validating control flows in computing systems with reference to the following drawings, where the same numbers are used in various examples, indicating similar features or components. [Brief explanation of the drawing]
[0007] [Figure 1]This figure shows an exemplary operating environment, including an exemplary computing device capable of performing control flow consistency measurements. [Figure 2] This figure shows integrated circuit components implemented as security-oriented integrated circuits. [Figure 3] This figure shows an exemplary embodiment of source code configured to perform control flow consistency measurements to validate control flow in a computing system. [Figure 4] This figure shows a fault detection manager configured to generate measurements for measuring control flow during scoping. [Figure 5] This figure shows a fault detection manager configured to generate the return value of an expression and modify the measured value. [Figure 6] This figure shows a fault detection manager configured to compare measured values to predetermined values in order to validate the control flow during the execution of instructions within the scope. [Figure 7] This figure shows an exemplary embodiment of a fault detection manager configured to maintain control flow integrity measurements to validate control flow in a computing system. [Figure 8] This figure shows an example of how to perform control flow consistency measurements to validate control flow in a computing system. [Modes for carrying out the invention]
[0008] overview Computing systems often include integrated circuits with security circuits and software that provide protection against defects, attacks, and other potentially dangerous events. Security circuits and software can implement numerous security paradigms. For example, during firmware updates, security circuits and software compliant with public-key cryptography standards (PKCS) may use digital signatures (e.g., cryptographic signatures) to verify the authenticity and integrity of data received and executed by the computing device. A digital signature scheme is a mathematical method used to validate a digital message or document. A valid digital signature allows the recipient to be confident that the message was produced by a known sender ("authenticity") and that it has not been tampered with anywhere during transmission ("integrity"). In doing so, security circuits and software reduce the chances of information being inadvertently disclosed or certain functions being used in a harmful or unauthorized manner.
[0009] In today's computing environment, malicious attackers can use numerous attack vectors to attack computing devices at countless levels. For example, fault injection attacks reduce the protection provided by many of these security paradigms. Fault injection attacks can bypass many system security features, alter system behavior to achieve malicious objectives, and / or expose sensitive information. Using fault injection attacks, attackers can use glitches (e.g., sudden, transient injected faults in a system) to indirectly or directly alter the programmed operation of electronic components (e.g., a central processing unit). While such attacks may sometimes "render computing devices inoperable," in other cases, precise and targeted attacks can expose them to security threats. For example, a targeted fault injection attack could cause a central processing unit to bypass digital signature authentication. As a result, the computing device could receive and execute unverified data or code.
[0010] Because branch instructions can be used to skip security level checks, malicious attackers using fault injection attacks frequently target branch instructions. Branch instructions used within unary error-handling programming structures are particularly vulnerable. For example, a processor executing a function with a branch instruction may return control outside the function if the enclosed function returns an error. Since this branch instruction has only one control dependency between the return value indicating successful execution and the error check (for example, there is no data dependency between the two), an attacker can make the function signal successful by skipping the early return.
[0011] To protect computing systems from such hazardous events, this specification describes techniques and apparatus for control flow integrity measurement to validate control flows in computing systems. The following discussion describes operating environments, techniques and method examples that may be used in those operating environments, and system-on-a-chip (SoCs) into which components of the operating environment may be incorporated.
[0012] Operating environment The following discussion describes the operating environment, the technologies that may be used in the operating environment, and the various devices or systems in which components of the operating environment may be incorporated. In the context of this disclosure, the operating environment is referred to only as an example.
[0013] Figure 1 shows an exemplary operating environment 100, including an exemplary computing device 102 capable of performing control flow consistency measurements. Examples of computing devices 102 include a smartphone 102-1, a tablet computer 102-2, a laptop computer 102-3, smart glasses 102-4, a computerized watch 102-5, and an automobile 102-6. Although not shown, computing devices 102 may be implemented as any of the following: a mobile station (e.g., fixed or mobile STA), a mobile communication device, a client device, a home automation and control system, an entertainment system, a game console, a personal media device, a health monitoring device, a drone, a camera, an internet-connected home appliance capable of wireless internet access and browsing, an IoT device, a security system, and a server or data center device. Note that computing devices 102 may be wearable, non-wearable but mobile, or relatively fixed (e.g., a desktop, an appliance). Furthermore, it should be noted that computing device 102 can be used with or integrated into many other computing devices 102 or peripherals, such as in automobiles or as an accessory to laptop computers. Computing device 102 may implement one or more macros configured to maintain control flow integrity measurements to validate control flow in a computing system. Computing device 102 may include components or interfaces that provide other functions or are omitted from Figure 1 for clarity or visual brevity.
[0014] The computing device 102 includes a printed circuit board assembly 104 (PCBA 104) on which the components and interconnections of the computing device are incorporated. Alternatively or additionally, the components of the computing device 102 may be incorporated on other substrates, such as flexible circuit material or other insulating material. Although not shown, the computing device 102 may also include a housing, various human input devices, a display, a battery pack, and an antenna, etc. Generally, the electrical and electromechanical components of the computing device 102 are assembled on a printed circuit board (PCB) to form the PCBA 104. The various components of the PCBA 104 (e.g., processor and memory) are then programmed and tested to verify the precise functionality of the PCBA 104. The PCBA 104 is connected to the other parts of the computing device 102 or assembled within the housing.
[0015] As shown, the PCBA 104 includes one or more processors 106 and a computer-readable medium 108. The processor(s) 106 may be any suitable single-core or multi-core processor (e.g., an application processor (AP), a digital signal processor (DSP), a central processing unit (CPU), or a graphics processing unit (GPU)). The processor(s) 106 may be configured to execute instructions or commands stored in the computer-readable medium 108 to implement the operating system 110 and fault detection manager 112 stored in the computer-readable storage medium. The computer-readable storage medium may include one or more non-temporary storage devices, each coupled to a computer system bus, such as random-access memory (RAM, dynamic RAM (DRAM), non-volatile RAM (NVRAM), or static RAM (SRAM)), read-only memory (ROM), or flash memory), a hard drive, an SSD, or any type of medium suitable for storing electronic instructions. The term "bonding" may refer to two or more elements that are in direct contact (physical, electrical, magnetic, optical, etc.), or two or more elements that are not in direct contact with each other but cooperate, communicate, and / or interact with each other.
[0016] PCBA104 may also include I / O ports 114 and one or more communication systems 116. The I / O ports 114 allow the computing device 102 to interact with other devices or users. The I / O ports 114 may include any combination of internal or external ports such as USB ports, audio ports, Serial ATA (SATA) ports, PCI-express based ports or card slots, Secure Digital Input / Output (SDIO) slots, and / or other legacy ports. Various peripherals, such as human input devices (HIDs), external computer-readable storage media, or other peripherals, may be operably coupled to the I / O ports 114.
[0017] The communication system 116 enables the communication of device data such as received data, transmitted data, or other information as described herein, and may provide connectivity to one or more networks and other devices connected thereto. Examples of communication systems include NFC transceivers, WPAN radios compliant with various IEEE 802.15 (Bluetooth®) standards, WLAN radios compliant with any of the various IEEE 802.11 (Wi-Fi®) standards, WWAN (3GPP® compliant) radios for mobile phones, Wireless Metropolitan Area Network (WMAN) radios compliant with various IEEE 802.16 (WiMAX®) standards, infrared (IR) transceivers compliant with the Infrared Communications Association (IrDA) protocol, and wired local area network (LAN) Ethernet® transceivers. Device data communicated via communication system 116 may be packetized or framed depending on the communication protocol or standard to which the computing device 102 is communicating. Communication system 116 may include wired interfaces such as Ethernet® interfaces or fiber optic interfaces for communication over a local network, intranet, or the Internet. Alternatively or additionally, communication system 116 may include wireless interfaces that facilitate communication over wireless networks such as wireless LANs, cellular networks, or WPANs.
[0018] Although not shown, computing device 102 may also include a system bus, interconnect, crossbar, or data transfer system that connects various components within the device. The system bus or interconnect may include one or a combination of various bus structures, such as a memory bus or memory controller, peripheral bus, universal serial bus, and / or a processor bus or local bus that utilizes any of the various bus architectures.
[0019] Furthermore, integrated circuit component 118 can be operably coupled to PCBA 104. In an embodiment, integrated circuit component 118 can be implemented as a general-purpose processor, a system-on-chip (SoC), or a security-oriented integrated circuit having enhanced firmware (e.g., a silicon root of trust (RoT) chip). In an embodiment, integrated circuit component 118 can include at least a portion of computer-readable medium 108 or may be coupled to a computer-readable storage medium. For example, integrated circuit component 118 can include a fault detection manager 112.
[0020] Computing device 102 can also include a power system that can be implemented as one or more power supplies and a power distribution network configured to provide power to integrated circuit component 118 and circuits of computing device 102.
[0021] Now, consider FIG. 2 showing an integrated circuit component (e.g., integrated circuit component 118) implemented as a security-oriented integrated circuit 202. However, this is just an example, and the integrated circuit component may be implemented as a microprocessor, a microcontroller, and an SoC, etc. In an embodiment, security-oriented integrated circuit 202 can include encryption software (e.g., a hash-based encryption function) and hardware modules (e.g., an enhanced memory protection unit). The techniques described herein, including maintaining measurements of control flow, can be integrated within any of a variety of computing systems that include one or more security-oriented components such as security-oriented integrated circuit 202.
[0022] As shown in Figure 2, the security-oriented integrated circuit 202 includes a processor 204 with an arithmetic logic unit 206 (ALU 206), a register file 208, a control unit 210, and an input / output (I / O) unit 212. The ALU 206 may be configured to perform arithmetic and logical operations on incoming data. The register file 208 may be an array of processor registers (e.g., control registers) that function as high-speed semi-temporary memory configured to allow rapid access to data during the processing of a program or function. The register file 208 may be tightly coupled to the ALU 206. To further facilitate access to data, the register file 208 may include multiple read ports or multiple write ports so that the ALU 206 and / or execution unit can retrieve multiple operands simultaneously in a single cycle. The register file 208 may be formed from flip-flops to accelerate the reading and writing of data bits. The control unit 210 may be configured to control the flow of data throughout the system(s). The I / O unit 212 may include ports that are operablely interfaced with other components of the device or security-oriented integrated circuit 202.
[0023] As further shown in FIG. 2, the security-oriented integrated circuit 202 may include a security-enhanced ROM 214. The security-enhanced ROM 214 may include at least a portion of the computer-readable medium 108 that includes the fault detection manager 112. In one example, the fault detection manager 112 can be implemented as executable code. The executable code can be generated by a compiler that converts macros (e.g., source code directives for inserting specific computational instructions) of source code (e.g., high-level language scripts) into executable code (e.g., low-level machine language). The fault detection manager 112 implemented as a set of macros in the source code (e.g., included as one or more header files) may include macros such as functions, chain macros, and / or macros such as objects. The source code may further include other programs, functions, and scripts, etc.
[0024] In an embodiment, the security-enhanced ROM 214 may be operably coupled to the processor 204. In such a configuration, the processor 204 can execute the executable code (e.g., read-only instructions) stored in the security-enhanced ROM 214. As a result, the processor 204 may execute the instructions of the fault detection manager 112.
[0025] In an aspect, the source code of the fault detection manager 112 may include variables, arrays, objects, subroutines, loops, and functions, etc. For example, a function is a set of instructions that execute a task and output a return value. The return values (the "return values") described herein refer to values of any data type such as strings, boolean values, and integers that are output by functions, subroutines, programs, etc. during or after the execution of a task (e.g., calculation, string manipulation). In one example, the return value can be an error code that includes a numerical value (e.g., hexadecimal) or an alphanumeric code. As further described herein, a scope refers to a code block that includes functions, subroutines, and programs, etc. and ends with a return value.
[0026] In some examples, during the execution of a scope, the fault detection manager 112 may instruct the processor 204 to stop further executions (e.g., within or outside the scope) due to errors occurring during the execution of the scope. Furthermore, the fault detection manager 112 may instruct the processor 204 to output a return value containing an error code ("failure error code") indicating that the task failed to complete. In other examples, during the execution of a scope, if no errors occurred during the execution of the scope, the fault detection manager 112 may instruct the processor 204 to output a return value containing an error code ("success error code") indicating that the task was successfully completed.
[0027] For example, a security-oriented integrated circuit 202 having a security-enhanced ROM 214 may include an executable instruction for a signature check function. The signature check function may cause the processor to perform a task that includes executing a digital signature acquisition subfunction and a digital signature verification subfunction. The signature check function may be designed to output a return value ("final return value") that has a success error code and, consequently, a validated digital signature.
[0028] While processor 204 is executing the signature check function, errors may occur during the execution of the digital signature verification subfunction. For example, an error may occur while comparing the message digest obtained from the digital signature with the digest of the corresponding message that has been validated against the digital signature. As a result, the digital signature verification subfunction may return a value with a failure error code. As an example, the signature check function may be designed with a unary error handling structure. In such an embodiment, the return value with a failure error code is compared with the expected return value with a success error code in the branch instruction. If the comparison fails, the signature check function returns early. Otherwise, if the comparison is successful, the program continues to operate. In this way, further operations and execution of the signature check function may be stopped, and the signature check function may terminate early ("early return"). The output of the signature check function is the return value with the failure error code of the digital signature verification subfunction.
[0029] An attacker might use a fault injection attack to target branch instructions in an attempt to alter the intended control flow of a computing system (for example, the order in which individual statements, instructions, or function calls in an imperative program are executed or evaluated). In some cases, a fault injection attack targeting a branch instruction could cause a signature check function to continue operating and executing by signaling success to the digital signature check subfunction by skipping an early return.
[0030] To prevent a scope (e.g., a signature check function) from outputting a final return value with a success error code when a fault injection attack ("tampering") occurs, the enhanced security ROM 214 may execute instructions from the fault detection manager 112.
[0031] Exemplary technology Figure 3 shows an exemplary embodiment of source code 300 configured to perform control flow integrity measurements to validate control flow in a computing system. In one embodiment, source code 300 includes a fault detection manager (e.g., fault detection manager 112) implemented as a set of macros 302. In one example shown in Figure 3, source code 300 includes macros 302 defined outside of a function (e.g., main function 304). In other examples, the fault detection manager technique can be applied (e.g., called and defined) within a function (e.g., main function 304).
[0032] As shown, macro 302 may be included in source code 300 as one or more header files. Source code 300 may include one or more expected values (e.g., hardcoded values) (e.g., within macro 302). Expected values may be pre-calculated using any of a variety of mathematical operations, including fingerprint functions and / or bitwise operations. In some examples, the mathematical operations are not encrypted. For example, the mathematical operations may include an unencrypted fingerprint function. In at least some examples, the mathematical operations may result in an encrypted message digest. For example, the mathematical operations may include an encrypted fingerprint function.
[0033] Source code 300 may further include a main function 304 (e.g., a signature check function). In this embodiment, a processor (e.g., processor 204) may execute executable code (e.g., compiled source code 300) to perform the operations of the main function 304. The main function 304 may include calls to other functions. For example, the main function 304 may perform fault detection by applying a defined macro 302 to the return value of a called subfunction. In this way, the processor may implement a fault detection manager as a result of executing the main function 304 and applying macro 302 to the return value of the called subfunction. Thus, the fault detection manager can measure the control flow during the execution of the main function 304. For example, the main function 304 may include a call to a function CFI_BEGIN306 defined in macro 302.
[0034] Referring to Figure 4, the fault detection manager creates a measurement to measure control flow during scope. In one example, when measurement 400 is created, the processor may allocate space in memory (e.g., RAM) to store the variable name, the variable data type, and / or the variable value. The creation of measurement 400 can be achieved in source code 300, for example, through variable initialization, variable assignment, and / or variable declaration. Measurements can contain numeric, alphanumeric, or alphabetic values. Furthermore, measurements can be implemented as local or global variables. In one embodiment, measurement in source code 300 may be declared as having a data type of long, assigned an initial value (e.g., secret value), and stored in memory (e.g., register file 208). Declaring a measurement is effective in 402 for initiating scope control flow measurement. For example, measurement may be created to maintain scope control flow measurement.
[0035] Returning temporarily to Figure 3, after the call to CFI_BEGIN306 within the main function 304, source code 300 includes a call to the function CFI_RETURN_IF_ERROR308 defined in macro 302. Referring to Figure 5, the fault detection manager generates a return value for the expression and modifies the measurement.
[0036] The function CFI_RETURN_IF_ERROR308 accepts one or more expressions (e.g., function calls) in 500. For example, the function CFI_RETURN_IF_ERROR308 may accept a function call to obtain a digital signature. The function CFI_RETURN_IF_ERROR308 may further compute an expression in 502. For example, computed arguments may involve the ALU206 accessing the register file 208 or another memory storage device in the computing device 102 operably coupled to the PCBA104. As a result of the computation of the expression, a return value of the expression is produced. The return value of the expression may include a failure error code or a success error code.
[0037] The function CFI_RETURN_IF_ERROR308 instructs the processor in 504 to store the return value of the expression in memory (e.g., register file 208). The function CFI_RETURN_IF_ERROR308 obtains the measurement in 506. For example, obtaining the measurement may involve ALU206 accessing register file 208. The function CFI_RETURN_IF_ERROR308 in 508 performs one or more mathematical operations on the return value and the measurement to produce a computed value. In some embodiments, performing mathematical operations may involve using any of the following: an unencrypted synthetic fingerprint algorithm, an unencrypted fingerprint algorithm (e.g., the Fowler-Noll-Vo hash function), or an encrypted fingerprint algorithm, which is referred to herein simply as a fingerprint algorithm.
[0038] In an exemplary embodiment, the unencrypted synthetic fingerprint algorithm combines the return value of an expression with a measured value, and then hashes the combined input. The return value of the expression and the measured value are then combined using a non-communication function that includes concatenation. In another embodiment, the return value of the expression and the measured value are combined using an injection function that includes serialization. In yet another embodiment, the unencrypted synthetic fingerprint algorithm maps the combined input to a fixed-size digest value (e.g., hash, digest output, fingerprint) to generate a computed value.
[0039] In other embodiments, or in addition thereto, the performance of mathematical operations may involve multiplication, shifting, addition, and / or bitwise operations on the return value of an expression and the measured value. In yet another embodiment, after performing one or more of the aforementioned mathematical operations, the Hamming weights of the resulting values obtained by the mathematical operations may be determined. Performing mathematical operations through such techniques can amplify small changes into large changes (e.g., avalanche effects).
[0040] The function CFI_RETURN_IF_ERROR308 modifies a measured value in 510. For example, a fault detection manager modifies a measured value based on a calculated value in response to generating a return value of an expression. In one example, the function CFI_RETURN_IF_ERROR308 redefines a variable that maintains a measured value (e.g., a previous measured value) to a calculated value. In this way, the fault detection manager can maintain (e.g., update, modify) the measured value during the execution of the scope.
[0041] The function CFI_RETURN_IF_ERROR308 compares the return value of an expression in a branch instruction in 512. For example, a branch instruction with an expected success error code may be compared to the return value of an expression using one of various conditional statements. If the comparison fails (e.g., the return value of the expression does not indicate the expected success error code), the function CFI_RETURN_IF_ERROR308 may skip further instructions in the main function and return early ("early return"). If the comparison is successful (e.g., the return value of the expression indicates the expected success error code), the processor may continue executing further instructions in the main function.
[0042] Returning temporarily to Figure 3, after the call to CFI_RETURN_IF_ERROR308 within the main function, source code 300 includes a call to the function CFI_CHECK_ALL_OK310. Referring to Figure 6, the fault detection manager compares measured values to predetermined values to validate the control flow during the execution of instructions within scope.
[0043] The function CFI_CHECK_ALL_OK310 accepts a number as a formal parameter in 600. The number may be statically known (e.g., known at compile time and hardcodeable in the main function 304). In some examples, CFI_CHECK_ALL_OK310 can accept any data type or variable related to the number. In yet another example, the number may be predetermined (e.g., for a fault detection manager) and correspond to a given number of calls to the function CFI_RETURN_IF_ERROR308 within the main function (e.g., Scope). In at least some examples, the number of calls to the function CFI_RETURN_IF_ERROR308 may be predetermined based on executing one or more conditional statements (e.g., if-else statements) or iterative statements (e.g., for loops, do-while loops) before CFI_CHECK_ALL_OK310 accepts the number.
[0044] In 602, the function CFI_CHECK_ALL_OK310 compares the measured value to a predetermined value. For example, in response to accepting the number 600, the function CFI_CHECK_ALL_OK310 obtains a predetermined value based on the accepted number corresponding to a predetermined number of calls to the function CFI_RETURN_IF_ERROR308 (e.g., calculate, access memory). In 602, the function CFI_CHECK_ALL_OK310 compares the measured value to a predetermined value using one or more conditional statements. In doing so, the fault detection manager verifies that no early returns from one or more branch instructions were skipped during one or more executions of the function CFI_RETURN_IF_ERROR308.
[0045] For example, if it is predetermined that the function CFI_RETURN_IF_ERROR308 will be called and executed three times within the main function, the number of acceptable values can be predetermined to correspond to the value 3. If a given value obtained by the function CFI_CHECK_ALL_OK310 based on the value 3 does not correspond to the measured value (e.g., not equal to, does not indicate), such an instance may indicate that one or more early returns were skipped during the execution of an instruction in the main function (e.g., Scope). If the comparison between the given value and the measured value fails, the fault detection manager can respond to tampering by generating an interrupt, passing control to an alert handler, preventing access to certain data, or shutting down at least part of the integrated circuit.
[0046] Returning to Figure 3, if the comparison between the given value and the measured value is successful, the main function may output a scope return value 312. In yet another example, if the comparison between the given value and the measured value fails, the fault detection manager may be configured to return a scope return value indicating a tampered failure rather than immediately shutting down. The fault detection manager may then use the scope return value indicating a tampered failure to respond to the attack. Furthermore, such embodiments may be branchless, making them difficult for an attacker to overcome. For example, the fault detection manager may respond to tampering by implementing protective features rather than shutting down the security-enhanced integrated circuit.
[0047] The techniques described herein create an explicit data dependency between early return decisions (e.g., early return 714) and scope return values by incorporating the return values of all expressions into the control flow measurements (e.g., hashing, combining). Furthermore, fault detection managers can be implemented within a computing system without compiler optimizations. In at least some examples, computing systems using the techniques described herein can implement optimized code (e.g., source code), but these optimizations may not interfere with certain ordering of calculations performed to compute the measurements, for example. Moreover, computing systems using the techniques described herein can implement fault detection managers without modifying the compiler.
[0048] Exemplary Embodiments This section describes exemplary embodiments of control flow consistency measurements for validating control flow in a computing system. Figure 7 shows an exemplary embodiment 700 of a fault detection manager configured to maintain control flow consistency measurements for validating control flow in a computing system.
[0049] In one embodiment, as shown in Figure 7, a fault detection manager (e.g., fault detection manager 112) may initialize the variable 702. Initializing the variable may involve assigning an initial measurement value to the variable. The initial value may be a secret value stored in enhanced security memory (e.g., ROM 214). Initializing the variable to be equal to the initial value can be achieved at any point before or during the execution of scope 704.
[0050] Next, the fault detection manager may compute an expression 706 that is valid for generating the return value of the expression. The fault detection manager may then hash the return value of the expression together with the measured value using an unencrypted fingerprinting algorithm (e.g., a synthetic fingerprinting algorithm) to generate a computed value 708. In response to the generation of the computed value, the fault detection manager may redefine the variable to the computed value.
[0051] Before, during, or after hashing 708 and / or redefining the variable 710, the fault detection manager may compare the return value of the expression 712. For example, the fault detection manager may determine whether the return value of the expression indicates that the calculation of the expression was successful or unsuccessful. If the comparison 712 fails, the fault detection manager may return prematurely 714. If the comparison 712 succeeds, the fault detection manager may compare the measurement to a predetermined value 716. In some examples, the fault detection manager may repeat the calculation of expression 706, hashing 708, redefining 710, and comparing 712 for multiple expressions.
[0052] If comparison 716 fails, the fault detection manager can detect a fault injection attack. If comparison 716 succeeds, the fault detection manager can return a scoped return value.
[0053] Exemplary Method This section describes exemplary methods for performing control flow consistency measurements to validate control flow in a computing system. These methods are presented as a set of blocks specifying the actions to be performed, but are not necessarily limited to the order or combination of actions shown by each block. Furthermore, one or more actions can be repeated, combined, rearranged, or linked to provide a wide range of additional and / or alternative methods. Some parts of the following discussion may refer to exemplary operating environments 100 and entities detailed in Figures 2–7, but these references are illustrative only. These techniques are not limited to being performed by one or more entities operating on a single device. Figure 8 shows an exemplary method 800 for performing control flow consistency measurements to validate control flow in a computing system.
[0054] In 802, a fault detection manager (e.g., fault detection manager 112) maintains control flow measurements during the scope. For example, a fault detection manager can store a variable with an assigned value in memory. In another example, a fault detection manager can create (e.g., declare) a variable and assign a value to it.
[0055] In 804, the fault detection manager generates a return value for the expression calculation during the scope. The return value of the expression may indicate that the expression calculation was successful or failed.
[0056] In the 806, the fault detection manager modifies the measured value according to a calculated value in response to generating a return value of an expression during the scope. The calculated value may be based on the measured value and the return value of the expression. For example, modifying (e.g., updating) the measured value may include setting the measured value equal to the calculated value.
[0057] In 808, the fault detection manager validates the control flow during the scope by comparing measured values to predetermined values. For example, the fault detection manager can determine whether a measured value is not equal to a predetermined value, and as a result, identify tampering in the computing system (e.g., a fault injection attack).
[0058] System-on-a-chip Figure 9 shows an integrated circuit component (e.g., integrated circuit component 118) implemented as an SoC900, which can implement various aspects of control flow integrity measurements to validate control flow in a computing system. The SoC900 may be a single chip containing components manufactured on the same semiconductor substrate. Alternatively, the SoC may be a number of such chips bonded together with epoxy resin. The SoC900 can be implemented in any suitable device, such as a smartphone, mobile phone, netbook, tablet computer, server, wireless router, network-attached storage, camera, smart appliance, printer, set-top box, or other suitable type of device. The entities in Figure 9 are described with reference to an SoC, but may be implemented as an ASIC or field-programmable gate array (FPGA), etc.
[0059] The SoC900 can be integrated with electronic circuits including components described in the operating systems listed herein. The SoC900 may also include an integrated data bus (not shown) that connects the various components of the SoC900 and enables data communication between them. The integrated data bus or other components of the SoC900 may be exposed or accessed through external ports, such as JTAG ports. For example, components of the SoC900 may be tested, configured, or programmed (e.g., flashed) through external ports at various stages of manufacturing.
[0060] In this example, the SoC900 includes a computer-readable medium 1102, one or more processors 904, a hash engine 906, and an I / O unit 908. The computer-readable medium may be stored in a computer-readable storage medium, each coupled to a computer system bus, including one or more non-temporary storage devices such as RAM (DRAM, NVRAM, or SRAM), ROM, or flash memory, a hard drive, an SSD, or any type of medium suitable for storing electronic instructions.
[0061] The computer-readable medium 902 of the SoC900 may contain executable code for a fault detection manager (e.g., fault detection manager 112). One or more processors 904 operably coupled to the computer-readable storage medium having the computer-readable medium 902 may execute instructions of the fault detection manager.
[0062] While the subject matter is described in language specific to structural features and / or methodological operations, it should be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or operations described herein, including the order in which they are performed.
[0063] Additional examples The following sections provide additional examples.
[0064] Example 1: A method performed on a computer, comprising: maintaining a measurement of a control flow during a scope; and generating a return value of a calculation of an expression during the scope, the return value of the expression indicating that the calculation of the expression was successful or failed; the method further comprises, in response to generating the return value of the expression during the scope, modifying the measurement according to a calculated value, the calculated value being based on the measurement and the return value of the expression; and the method further comprises, during the scope, comparing the measurement to a predetermined value to validate the control flow.
[0065] Example 2: A method performed on a computer as described in Example 1, further comprising creating a variable configured to store the measurement before maintaining the measurement.
[0066] Example 3: A method performed on a computer as described in Example 2, further comprising assigning the initial value to a variable configured to store the measurement, which is effective in setting the measurement to an initial value before maintaining the measurement.
[0067] Example 4: The method described in Example 3, executed on the computer, wherein the initial value is a secret value stored in secure, read-only memory.
[0068] Example 5: The method used on a computer as described in any of the preceding examples, which includes creating the aforementioned variable and declaring a local variable.
[0069] Example 6: A method performed on a computer as described in any of the prior examples, wherein updating the measured value includes setting the measured value to be equal to the calculated value.
[0070] Example 7: The scope includes multiple expressions, and the method is executed on a computer as described in any of the prior examples.
[0071] Example 8: The method described in Example 7, executed on a computer, wherein the scope includes a function and the multiple expressions include function calls.
[0072] Example 9: A method performed on a computer according to Example 7 or 8, further comprising repeating the generation and updating for each of the plurality of expressions within the scope.
[0073] Example 10: A method performed on a computer according to any of the prior examples, further comprising returning a scope return value indicating that the execution of the scope was successful or that the execution of the scope failed, in response to comparing the measured value with the predetermined value.
[0074] Example 11: The method executed on a computer as described in Example 10, wherein the scope return value and the return value of the expression include at least one error code.
[0075] Example 12: A method performed on a computer according to Example 10 or 11, further comprising determining, based on one or more conditional branch instructions, that the return value of the expression indicates that the calculation of the expression has failed.
[0076] Example 13: A method performed on a computer as described in Example 12, further comprising aborting further execution of the scope in response to determining that the return value of the expression indicates that the calculation of the expression has failed, and returning the scope return value indicating that the execution of the scope has failed.
[0077] Example 14: A method performed on a computer according to any of the prior embodiments, further comprising generating the calculated value using a hash function.
[0078] Example 15: The hash function comprises an unencrypted synthetic fingerprint algorithm, and the method for generating the computed value is the method described in Example 14, which is performed on a computer, comprising combining two inputs together using at least one noncommutative function including concatenation or an injection function including serialization, and mapping the combined inputs to a fixed-size digest value.
[0079] Example 16: Updating the measured value according to the calculated value is a method performed on a computer as described in any of the prior examples, which includes manipulating the measured value through one or more mathematical or bitwise operations.
[0080] Example 17: A method performed on a computer as described in any of the prior examples, wherein the predetermined value is calculated before the measurement is maintained and is based on several unary error return decisions within the scope.
[0081] Example 18: The method described in Example 17, which is executed on a computer, wherein the predetermined value is stored in enhanced security memory.
[0082] Example 19: A system comprising an integrated circuit, the integrated circuit comprising at least one processor and at least one computer-readable storage medium coupled to the at least one processor and containing instructions, wherein, when executed by the at least one processor, the instructions cause the processor to perform the method described in any of the prior embodiments.
[0083] Example 20: The system according to Example 19, wherein the integrated circuit is configured to perform the method described in any one of the prior examples without compiler optimization.
[0084] Example 21: A method performed on a computer, comprising: generating a measurement of the control flow of a signature check function configured to verify a digital signature; generating a return value of an expression indicating that the digital signature verification was successful within the scope of the signature check function; and updating the measurement according to a calculated value in response to generating the return value of the expression within the scope, the calculated value being based on the measurement and the return value of the expression, the method further comprising validating the control flow of the signature check function by comparing the measurement with a predetermined value.
[0085] Example 22: The method performed on the computer as in Example 21, wherein the return value of the above expression is the return value of a second expression, and the method performed on the computer further includes generating a return value of a first expression indicating that the acquisition of a digital signature was successful, before generating the return value of the second expression.
[0086] Example 23: A method performed on a computer as described in Example 22, wherein when the measured value is updated, the measured value is updated for the return value of the first equation and the return value of the second equation, respectively.
[0087] Example 24: A method performed on a computer as described in any of the prior examples, wherein updating the measured value includes setting the measured value to equal to the calculated value.
[0088] Example 25: A method performed on a computer as described in any of the prior examples, further comprising returning a scope return value in response to validating the control flow of the signature check function.
[0089] Example 26: The method executed on a computer as described in Example 25, wherein the scope return value includes at least one error code, the at least one error code indicating that the validation of the control flow of the signature check function was successful or that the validation of the control flow of the signature check function failed.
[0090] Example 27: The method performed on a computer as described in Example 25 or 26, wherein the return value of the expression includes at least one error code, the at least one error code indicating that the digital signature verification was successful or failed.
[0091] Example 28: A method executed on a computer as described in Example 27, further comprising: determining, based on one or more conditional branch instructions, that the return value of the expression indicates a failure of the digital signature verification; stopping further execution of the scope of the signature check function in response to determining that the return value of the expression indicates a failure of the digital signature verification; and returning the scope return value indicating a failure of the validation of the control flow of the signature check function.
[0092] Example 29: A method performed on a computer according to any of the prior examples, further comprising using a hash function to generate the calculated value.
[0093] Example 30: The hash function comprises an unencrypted synthetic fingerprint algorithm, and the method for generating the computed value is the method performed on a computer as described in Example 14, comprising combining two inputs together using at least one noncommutative function including concatenation or an injection function including serialization, and mapping the combined inputs to a fixed-size digest value.
[0094] Example 31: A method performed on a computer according to any of the prior examples, which involves manipulating the measurement value through one or more mathematical or bitwise operations, to update the measurement value according to the calculated value.
[0095] Example 32: A method performed on a computer as described in any of the prior examples, wherein the predetermined value is calculated before the measurement is maintained and is based on several unary error return decisions within the scope.
[0096] Example 33: The method described in Example 32, which is executed on a computer, wherein the predetermined value is stored in enhanced security memory.
[0097] Example 34: A system comprising an integrated circuit, the integrated circuit comprising at least one processor and at least one computer-readable storage medium coupled to the at least one processor and containing instructions, wherein, when executed by the at least one processor, the instructions cause the processor to perform the method described in any of the prior art.
[0098] Example 35: The system described in Example 34, wherein the integrated circuit is configured to execute the instructions without compiler optimization.
[0099] Example 36: The system described in Example 34 or 35, which includes instructions compiled with optimizations configured not to interfere with the maintenance of the measurement values.
[0100] Example 37: A method performed on a computer, the method performed on the computer comprising: initializing a local variable that is implemented within a scope and configured to maintain a local control flow measurement; and calculating an expression, the calculation of which is effective in producing a return value; the method further comprises hashing both the measurement and the return value, the hashing which is effective in producing a digest value; the method, following the hashing, comprises redefining the measurement of the local variable to the digest value; and comparing the measurement of the local variable to an expected value stored in a static variable, the comparison which is effective in validating control flow consistency.
[0101] Example 38: The method performed on a computer as in Example 37, further comprising repeating the hashing and redefinition for each calculation of an expression in scope before comparing the measured value of the local variable with the expected value stored in the static variable.
[0102] Example 39: The hashing is computed by an unencrypted synthetic fingerprint algorithm, the unencrypted synthetic fingerprint algorithm is the method of combining two inputs together, the combining is performed using a non-commutative function including concatenation or an injection function including serialization, the combining and the combined inputs are effective for mapping to a fixed-size digest value, as described in Example 37 or Example 38, performed on a computer.
[0103] Example 40: The expected value of the static variable is calculated in advance for several unary error return decisions within the scope, in a computer-based method as described in one of the prior examples.
[0104] Example 41: A method to be executed on a computer as described in any one of the prior examples, wherein the return value is an error code, the error code may indicate success or failure of execution.
[0105] Example 42: A method executed on a computer as described in any one of the prior examples, wherein the scope is a function having at least one check structure, the at least one check structure is configured to perform an early return if an error occurs.
[0106] Example 43: The method of initializing the local variable, as described in one of the prior examples, performed on a computer, which initializes the measured value to an initial secret value.
[0107] Example 44: A method performed on a computer as described in any of the prior examples, wherein updating the measured value according to the calculated value includes redefining the variable that maintains the measured value to the calculated variable.
[0108] conclusion While the techniques and / or methods for measuring control flow consistency for validating control flows in computing systems are described in a language specific to the features and / or methods, it should be understood that the subject matter of the appended claims is not necessarily limited to the specific features or methods described. Rather, the specific features and methods are disclosed as exemplary embodiments enabling control flow consistency measurement for validating control flows in computing systems.
Claims
1. A method that is performed on a computer, To generate measurements of the control flow of a signature check function configured to verify digital signatures, Within the scope of the signature check function, generate a return value of an expression indicating that the digital signature verification was successful, The method further includes updating the measured value according to a calculated value in response to generating a return value of the formula within the scope, wherein the calculated value is based on the measured value before the update and the return value of the formula, A method performed by a computer, comprising validating the control flow of the signature check function by comparing the updated measurement value with a predetermined value.
2. The method performed on a computer according to claim 1, wherein the return value of the above expression is the return value of a second expression, and the method performed on the computer further includes generating a return value of a first expression indicating that the acquisition of a digital signature was successful, prior to generating the return value of the second expression.
3. The method performed by a computer according to claim 2, wherein when the measured value is updated, the measured value is updated for the return value of the first equation and the return value of the second equation, respectively.
4. A method performed by a computer according to any one of claims 1 to 3, wherein updating the measured value includes setting the measured value before the update to be equal to the calculated value.
5. A method performed on a computer according to any one of claims 1 to 4, further comprising returning a scope return value in response to validating the control flow of the signature check function.
6. The method executed on a computer according to claim 5, wherein the scope return value includes at least one error code, the at least one error code indicating that the validation of the control flow of the signature check function was successful or that the validation of the control flow of the signature check function failed.
7. The aforementioned at least one error code includes at least one first error code, The method performed on a computer according to claim 6, wherein the return value of the expression includes at least one second error code, the at least one second error code included in the return value of the expression indicates that the digital signature verification was successful or that the digital signature verification failed.
8. Based on one or more conditional branch instructions, it is determined that the return value of the expression indicates a failure of the digital signature verification, In response to determining that the return value of the above expression indicates a failure in the digital signature verification, further execution of the signature check function within the scope is stopped. The method performed on a computer according to claim 7, further comprising returning the scope return value indicating that the validation of the control flow of the signature check function has failed.
9. A method performed on a computer according to any one of claims 1 to 8, further comprising generating the calculated value using a hash function.
10. The hash function includes an unencrypted synthetic fingerprint algorithm, The calculation of the aforementioned value is Combining two inputs together using at least one non-commutative function that includes concatenation, or an injection function that includes serialization, A method performed on a computer according to claim 9, comprising mapping the combined inputs to a fixed-size digest value.
11. A method performed on a computer according to any one of claims 1 to 10, wherein updating the measured value according to the calculated value includes manipulating the pre-update measured value through one or more mathematical or bitwise operations.
12. A computer-based method according to any one of claims 1 to 11, wherein the predetermined value is calculated before updating the measured value and is based on several unary error return decisions within the scope.
13. The method executed on a computer according to claim 12, wherein the predetermined value is stored in a secure memory.
14. The integrated circuit comprises, At least one processor, A system comprising at least one computer-readable storage medium coupled to the at least one processor and containing instructions, wherein, when the instructions are executed by the at least one processor, the at least one processor causes the at least one processor to perform the method according to any one of claims 1 to 13.
15. A computer program that causes a computer to perform the method described in any one of claims 1 to 13.