Apparatus and method for blocking penetration
The intrusion prevention device secures digital devices by physically protecting processors and memory with a cover and controller, addressing vulnerabilities in HSMs and TPMs by deleting critical information during attacks.
Patent Information
- Application Number
- PCT/KR2025/099341
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-02-13
- Filing Date
- 2025-02-07
- Publication Date
- 2025-08-21
AI Technical Summary
Existing hardware security modules (HSMs) and Trusted Platform Modules (TPMs) are vulnerable to physical attacks, allowing attackers to access sensitive information when the digital device is turned off.
An intrusion prevention device with a protective cover that seals the processor and memory, using a controller to store and manage cryptographic keys, and includes a built-in battery to detect and respond to physical attacks by deleting critical information.
Protects digital devices from external attacks even when powered off by physically securing the processor and memory, ensuring the integrity of cryptographic keys and critical information.
Smart Images

Figure KR2025099341_21082025_PF_FP_ABST
Abstract
Description
Intrusion prevention device and method
[0001] The present invention relates to an intrusion prevention device and method capable of preventing an attack at the time of power-off, and more particularly, to an intrusion prevention device and method capable of protecting a digital device from external attacks even when the digital device to be protected is turned off.
[0002] In today's information technology environment, data security has become a critical issue. Protecting this data is essential for both businesses and individuals, who store and transmit sensitive data electronically. Encryption is widely used for data protection, protecting data from unauthorized access by encrypting it using encryption keys. The keys used in the data encryption process are broadly categorized as symmetric and asymmetric keys. Symmetric key encryption uses the same key for both encryption and decryption, while asymmetric key encryption uses two related keys: a public key and a private key. While the public key is accessible to anyone, the private key must be kept secret. Securely managing these keys is a crucial part of the encryption process. Unauthorized use or disclosure of these keys poses a serious security threat.
[0003] To prevent this, devices such as Hardware Security Modules (HSMs) and Trusted Platform Modules (TPMs) have been developed. Specifically, HSMs are modules equipped with processors and memory equipped with specific computational capabilities, capable of not only storing but also processing large amounts of information. HSMs are widely used due to their advantage of preventing the leakage of confidential information stored within them. Because HSMs can generate their own security keys and store them internally without external exposure, they can enhance security when used as electronic signature tools.
[0004] A Trusted Platform Module (TPM) is a hardware-based security device designed to enhance the security of computer systems. Similar to an HSM, a TPM provides functions such as generating, storing, and managing cryptographic keys, but its primary focus is platform protection, specifically enhancing the security of the entire computer system. Specifically, a TPM verifies the integrity of the system when the computer boots. During this process, the TPM ensures that software such as the BIOS, bootloader, and operating system have not been modified, thereby preventing malware from infiltrating the system during the boot process. The TPM continuously monitors system integrity during normal operation and, when necessary, enables appropriate security measures. The cryptographic keys generated and stored within the TPM are not exposed to external sources, providing a high level of security.
[0005] HSMs and TPMs typically have a small IC form factor, which means they may be vulnerable to physical attacks. For example, if an attacker obtains a digital device, it's possible to remove the HSM or TPM without physically damaging it. This leaves the digital device open to attack. Therefore, a new approach is needed to mitigate this vulnerability to physical attacks.
[0006] An object of the present invention is to provide an intrusion prevention device and method capable of protecting a digital device from external attacks even when the digital device to be protected is turned off.
[0007] However, the technical task that this embodiment seeks to achieve is not limited to the technical task described above, and other technical tasks may exist.
[0008] An intrusion prevention device according to one embodiment of the present invention includes an intrusion prevention cover including a controller having a storage space, which is manufactured in a shape that can cover a printed circuit board on which a processor to be protected is mounted and a shape that can cover the processor to be protected, and which is bonded to the printed circuit board to seal the processor to be protected from the outside so as to protect the processor to be protected from a physical attack, and the intrusion prevention cover can provide a service of encrypting and storing a signature / verification service and important information required by a digital device to be protected using a private key and a public key pair stored in the storage space of the controller, and destroying important information by deleting an encryption key used for encryption when an intrusion incident occurs.
[0009] In one embodiment, a reference value for determining whether important information has been changed is generated using a signature / verification service of an intrusion prevention cover, and before using the important information, the integrity of the reference value can be verified using a signature value created in advance by a digital device to determine whether the information has been tampered with.
[0010] In one embodiment, when the intrusion prevention cover detects an attack from outside, the controller can detect that the state has changed and delete critical information stored in the storage space so that an external attacker cannot read the critical information.
[0011] In one embodiment, the critical information may be at least one of settings required for the protected processor to operate and a cryptographic key used to encrypt these settings.
[0012] In one embodiment, the intrusion prevention cover or printed circuit board may further include a built-in battery. The built-in battery may be, but is not limited to, a coin cell battery, and may be composed of various types of batteries, taking into account size, flexibility, weight, and energy density. Preferably, the built-in battery may be composed of a lithium polymer battery.
[0013] In one embodiment, when an attack is detected in which the built-in battery is removed, the controller can delete critical information stored in the storage space to prevent an external attacker from reading the critical information.
[0014] A method for blocking intrusion according to another embodiment of the present invention is executed by a controller of an intrusion blocking device, and may include a step of recording important information in a storage space provided by the controller by a processor to be protected, a step of the controller receiving the important information from the processor to be protected, re-encrypting the important information and storing it in the storage space of the controller, and a step of the controller detecting that a state has changed and performing a response action to the detection when an attack that destroys the intrusion blocking cover occurs.
[0015] In one embodiment, after the step of storing in the storage space, when the protected processor searches for important information, the controller may include a step of decrypting the encrypted information and providing it to the protected processor.
[0016] In one embodiment, when the protected processor requests information previously stored by the controller, the controller may further include a step of providing the stored information to the protected processor.
[0017] In one embodiment, the step of performing a response action to detection may be a step of performing an action of deleting important information stored in a storage space of the controller.
[0018] According to the present invention, there is an effect of protecting a digital device from external attacks even when the digital device to be protected is turned off.
[0019] In addition, according to the present invention, a penetration prevention cover can provide a service in the form of an HSM or TPM to a digital device to be protected.
[0020] FIG. 1 is a side cross-sectional view showing a penetration blocking device according to one embodiment of the present invention.
[0021] Figure 2 is a plan view showing a penetration blocking device according to one embodiment of the present invention.
[0022] Figure 3 is a drawing for explaining the operation of the penetration blocking device.
[0023] Below, with reference to the attached drawings, embodiments of the present invention are described in detail so that those skilled in the art can easily implement them. The present invention is susceptible to various modifications and embodiments, and specific embodiments are illustrated in the drawings and specifically described in the detailed description. However, this is not intended to limit the present invention to specific embodiments, but rather to encompass all modifications, equivalents, and alternatives falling within the spirit and scope of the present invention.
[0024] To clearly explain the present invention, parts irrelevant to the description have been omitted from the drawings, and similar parts have been designated with similar drawing reference numerals throughout the specification. In addition, when describing with reference to the drawings, even if components are indicated by the same name, the drawing numbers may vary depending on the drawing. The drawing numbers are described merely for the convenience of explanation, and the concept, feature, function, or effect of each component is not limited by the drawing numbers.
[0025] In describing each drawing, similar reference numerals are used to refer to similar components. Terms such as first, second, etc. may be used to describe various components, but the components should not be limited by these terms. These terms are used only to distinguish one component from another. For example, a first component could be referred to as a second component, and similarly, a second component could also be referred to as a first component, without departing from the scope of the present invention. The term "and / or" includes any combination of multiple related listed items or any one of multiple related listed items.
[0026] Unless otherwise defined, all terms used herein, including technical or scientific terms, have the same meaning as commonly understood by one of ordinary skill in the art to which the present invention belongs.
[0027] Terms defined in commonly used dictionaries should be interpreted as having a meaning consistent with their meaning in the context of the relevant technology, and should not be interpreted in an idealized or overly formal sense unless expressly defined in this application.
[0028] Throughout the specification, when a part is said to be "connected" to another part, this includes not only the case where it is "directly connected" but also the case where it is "electrically connected" with another element in between. Furthermore, when a part is said to "include" a component, this should be understood to mean that it may include other components rather than excluding other components unless specifically stated to the contrary, and does not preclude the presence or possibility of one or more other features, numbers, steps, operations, components, parts, or combinations thereof.
[0029] In this specification, a 'part' or 'module' includes a unit realized by hardware or software, or a unit realized using both, and one unit may be realized using two or more pieces of hardware, or two or more units may be realized by one piece of hardware.
[0030] Hereinafter, the penetration blocking device and method according to the present invention will be described in detail with reference to the attached drawings.
[0031] FIG. 1 is a side cross-sectional view showing a penetration blocking device according to one embodiment of the present invention, and FIG. 2 is a drawing showing a penetration blocking device according to one embodiment of the present invention.
[0032] Referring to FIGS. 1 and 2, a penetration blocking device (100, 200) according to one embodiment of the present invention is for taking necessary measures against physical penetration into a digital device, and may include a printed circuit board (110, 210), a protected processor (120, 220) mounted on the printed circuit board (110, 210), a memory (130, 230), a penetration blocking cover (140, 240), a controller (150, 250), a storage space (151, 251) included in the controller, and a built-in battery (160, 260). Parts indicated by dotted lines in FIGS. 1 and 2 represent electronic components (171, 172, 271, 272) mounted on the printed circuit board.
[0033] The printed circuit board (110, 210) may be configured by stacking multiple layers, and the internal configuration of the printed circuit board (110, 210) may be configured with a variety of layers, such as a signal layer, a power layer, a ground layer, and an insulating layer. However, the present invention is not limited thereto, and the design of each layer may be changed according to various applications, and a combination of each layer is also possible.
[0034] The processor to be protected (120, 220) is mounted on a printed circuit board (110, 210) and may correspond to a processor provided in various types of computing devices such as a personal computer (PC), a server device, a mobile device, an embedded device, an Internet of Things (IoT) device, etc. For example, the processor may mean a central processing unit (CPU), a graphics processing unit (GPU), an application processor (AP), or a neural processing unit (NPU). In the embodiment of the present invention, the processor to be protected (120, 220) is located within a range covered by a penetration prevention cover (140, 240) and may control the operation of a digital device.
[0035] The memory (130, 230) is a hardware that stores various data processed by the processor (120, 220) to be protected, and can store various programs or applications to be driven by the processor (120, 220) to be protected. The memory (130, 230) may include at least one of volatile memory and nonvolatile memory. The nonvolatile memory may include ROM (Read Only Memory), PROM (Programmable ROM), EPROM (Electrically Programmable ROM), EEPROM (Electrically Erasable and Programmable ROM), flash memory, PRAM (Phase-change RAM), MRAM (Magnetic RAM), RRAM (Resistive RAM), FeRAM (Ferroelectric RAM), etc. Volatile memory can include DRAM (Dynamic RAM), SRAM (Static RAM), SDRAM (Synchronous DRAM), PRAM, MRAM (Magnetic RAM), RRAM (Resistive RAM), etc.
[0036] The penetration blocking cover (140, 240) is implemented in a three-dimensional shape to prevent the protected processor (120, 220) and memory (130, 230) from external intrusion, and can be formed to completely cover the protected processor (120, 220) and / or memory (130, 230). In addition, the penetration blocking cover (140, 240) can be formed to be sealed by being bonded to a printed circuit board (110, 210). The penetration blocking cover (140, 240) can be manufactured in various shapes and materials that can defend against physical attacks from the outside, and can preferably be manufactured as a flexible printed circuit board (FPCB). When using a flexible circuit board, it can be manufactured in a two-dimensional shape and then transformed into a three-dimensional shape that encloses the processor (120, 220) and / or memory (130, 230) to be protected using an origami technique. More preferably, the penetration barrier cover (140, 240) can be manufactured into a three-dimensional shape using, for example, a no-cut technique among origami techniques, and then installed by bonding it to a printed circuit board. The material and structure of the flexible circuit board can be selected in various ways depending on the heat transfer characteristics.
[0037] The penetration blocking cover (140, 240) may include a controller (150, 250). The controller (150, 250) may be implemented as, for example, an MCU (Micro Control Unit), may include a separate storage space (151, 251), and may have input / output ports and other peripheral devices integrated into one chip.
[0038] The penetration blocking cover (140, 240) may additionally include a built-in battery (160, 260), but is not limited thereto, and the built-in battery (160, 260) may be appropriately placed according to the internal needs of the digital device. The built-in battery (160, 260) may be configured as a coin cell type battery, but may be configured as various types of batteries considering size, flexibility, weight, and energy density, and may preferably be configured as a lithium polymer battery. FIG. 1 and FIG. 2 show that a separate storage space (151, 251) is included inside the controller (150, 250). Here, the storage space (151, 251) may be configured as a volatile memory. The volatile memory may include DRAM, SRAM, SDRAM, PRAM, MRAM, RRAM, etc.
[0039] The protected processor (120, 220) can record important information in a separate storage space (151, 251) provided within the controller (150, 250). Here, the important information may be settings required for the protected processor (120, 220) to operate and / or an encryption key used to encrypt these settings.
[0040] The penetration prevention cover (140, 240) provides a function in the form of an HSM or TPM to the digital device to be protected. If an external attacker obtains the digital device and attempts to attack the core hardware or steal important information, the external attacker must destroy the penetration prevention cover (140, 240) to access the internal core hardware (e.g., the protected processor (120, 220) and / or memory (130, 230)). In the present invention, if the penetration prevention cover (140, 240) is destroyed during the penetration process, the key protected by the HSM function provided by the penetration prevention cover (140, 240) is also destroyed, making it impossible for the attack to succeed.
[0041] Below, a method for protecting important information using a penetration blocking cover (140, 240) will be described in more detail.
[0042] The penetration blocking cover (140, 240) can store a private key / public key pair in a storage space (151, 251) included in the controller (150, 250) and provide a signature / verification service required by the digital device to be protected using these key pairs. The storage space (151, 251) included in the controller (150, 250) can be used to store a private key / public key pair and / or an encryption key, temporary calculation data, software code, etc.
[0043] The intrusion prevention cover (140, 240) can generate a signature for sensitive information using a signature service and use a verification service to determine whether the sensitive information has been compromised before use. Here, generating a signature for sensitive information means calculating a threshold value that serves as a basis for determining whether the information has not been altered.
[0044] For example, let's assume a situation where if a device detects that light sensor A has brightened, it deletes stored information such as setting values stored in the device. Here, if a device detects that light sensor A has brightened, this is an example of a situation where the illuminance increases due to a breakage of the intrusion prevention cover. The operation of the light sensor can be defined as follows. When it detects brightness, it outputs a value in the range of 0 to 100. A value closer to 0 means darker than a value closer to 100. If the operation of the device is to delete stored information when it detects that the illuminance has brightened, then the brightening means that the value output by the light sensor has changed from a situation where it can be judged as dark based on a specific value to a situation where it can be judged as bright. Here, the reference value that serves as the standard for judging 'dark / bright' is important. This can be referred to as 'important information'. If the device administrator sets the threshold to 10, causing the device to delete stored information at even the slightest increase in brightness, and an outsider were to change this threshold to 100 or 200, the device would not delete stored information no matter how bright the surroundings become. To prevent such malfunctions, the device could verify the integrity of the threshold using a pre-generated signature value before reading it and using it to determine brightness, and then respond by determining whether it has been tampered with.
[0045] The built-in battery (160, 260) may be included in the intrusion prevention cover (140, 240). However, the present invention is not limited thereto, and the built-in battery (160, 260) may be appropriately placed inside the digital device as needed. The built-in battery (160, 260) supplies power to the controller (150, 250) of the intrusion prevention cover (140, 240). The controller (150, 250) may enter a sleep mode to reduce power consumption of the built-in battery (160, 260). However, when a large-capacity battery is used, the controller (150, 250) does not necessarily have to enter the sleep mode.
[0046] If an “attack” occurs that destroys the intrusion prevention cover (140, 240), the controller (150, 250) can detect a change in state, wake up from sleep mode, and perform countermeasures against intrusion detection. That is, it can delete stored important information to prevent an attacker from reading it. If it does not enter sleep mode, the controller (150, 250) can detect a change in state and immediately perform countermeasures against intrusion detection.
[0047] In some embodiments, even if the connection between the built-in battery (160, 260) and the controller (150, 250) is broken or disconnected due to an external attack, important information may be deleted to prevent an attacker from reading the important information. That is, when the built-in battery (160, 260) is removed from the outside, important information stored in the storage space (151, 152) within the controller (150, 250), which is a volatile memory, may be deleted.
[0048] The protected processor (120, 220), memory (130, 230), controller (150, 250), and built-in battery (160, 260) may be directly or indirectly connected via a communication interface that transmits and receives data signals. The communication interface defines the format, transmission speed, connection method, etc. of the data, and may communicate via digital or analog signals. For example, UART (Universal Asynchronous Receiver / Transmitter), I2C (Inter-Integrated Circuit), and USB (Universal Serial Bus) may be used.
[0049] Figure 3 is a drawing for explaining the operation of the penetration blocking device.
[0050] Referring to Figure 3, an intruder (310) refers to an actor who unauthorizedly accesses a digital device, the target of protection. This may include an individual or group attempting to inappropriately physically manipulate the device, such as unauthorized disassembly, maintenance, or use.
[0051] The controller (320) refers to an active circuit that manages the status of the intrusion prevention cover. Here, the active circuit refers to a circuit with computational capabilities such as a processor, as opposed to a passive element. The controller (320) may be implemented, for example, as an MCU (Micro Control Unit), and may include a separate storage space (321), and input / output ports and other peripheral devices may be integrated into a single chip. The controller (320) monitors the integrity of the intrusion prevention cover and takes action on important information to be protected when an unauthorized intrusion attempt is made to destroy the intrusion prevention cover. Here, the action may include deleting the important information or transmitting a command to cause the deletion.
[0052] The protected processor (330) can be protected using a penetration barrier cover. The penetration barrier cover is configured to be bonded to a printed circuit board and sealed, thereby physically protecting the protected processor (330) from external penetration. The protected processor (330) controls the behavior of a protected device (e.g., a digital device, a computer device, an electronic device, etc.).
[0053] The 'Important Information Recording Tab (340)' describes a situation in which information that should not be exposed to the outside is recorded when an intrusion occurs. Specifically, in step S341, the protected processor (330) stores important information in the storage space (321) provided by the controller (320). Here, the important information may be settings required for the protected processor (330) to operate, such as reference values for a specific operation, or may be an encryption key used to encrypt these settings. In addition, the storage space (321) may be composed of volatile memory, and the volatile memory may include DRAM, SRAM, SDRAM, PRAM, MRAM, RRAM, etc.
[0054] When the protected processor (330) transmits important information to the controller (320), the controller (320) encrypts the important information again and stores it in the storage space (321). After storing the important information in the storage space (321), in step S343, the controller (320) may enter sleep mode until another request is made to conserve battery power. Alternatively, instead of using sleep mode, a large-capacity battery may be used to control the system from entering sleep mode.
[0055] As the amount of information stored in the controller (320) increases, the amount of information sent for storage also increases, and the deletion process may take a long time. Therefore, it is necessary to compensate for this shortcoming. To this end, the information is encrypted in the protected processor (330), and the protected processor (330) transmits the encryption key used to encrypt the information to the controller (320). At this time, a method is used in which the encryption key used is sent to the controller (320) and encrypted again in step S342.
[0056] The 'Important Information Inquiry Tab (350)' indicates a case where the protected processor (330) searches for information that is required for its operation. Specifically, in step S351, the protected processor (330) requests the controller (320) for previously stored information. Thereafter, in step S352, the controller (320) provides the information stored in the storage space (321) to the protected processor (330). At this time, the controller (330) decrypts the encrypted content and provides it to the protected processor (330). After providing the information, in step S353, the controller (330) may enter sleep mode until another request is made for battery efficiency. Alternatively, instead of using sleep mode, a large-capacity battery may be used to prevent the processor from entering sleep mode.
[0057] The 'Attack tab (360)' indicates the operation of the intrusion prevention cover when an external intruder (310) attempts to physically damage the digital device. Specifically, when an attack to destroy the intrusion prevention cover or an attack to damage the built-in battery by an external intruder (310) is detected, the controller (320) detects a change in status in step S361 and exits sleep mode. Thereafter, a response action to the detection is performed in step S362. The response action to the detection includes immediately deleting important information stored in the storage space (321) of the controller (320). This is a measure to prevent the intruder (310) from reading the important information.
[0058] This method can innovatively protect important information from physical intrusion.
[0059] The embodiments of the present invention described above may also be implemented in the form of a recording medium containing computer-executable instructions, such as program modules executed by a computer. Computer-readable recording media may include computer storage media, and computer storage media includes both volatile and nonvolatile, removable and non-removable media implemented in any method or technology for storing information, such as computer-readable instructions, data structures, program modules, or other data.
[0060] Although the devices and methods of the present invention have been described with respect to specific embodiments, some or all of their components or operations may be implemented using a computer system having a general-purpose hardware architecture.
[0061] The foregoing description of the present invention is for illustrative purposes only, and those skilled in the art will readily appreciate that the present invention can be readily modified into other specific forms without altering the technical spirit or essential characteristics of the present invention. Therefore, the embodiments described above should be understood as illustrative in all respects and not restrictive. For example, each component described as a single entity may be implemented in a distributed manner, and similarly, components described as distributed may be implemented in a combined manner.
[0062] The scope of the present invention is indicated by the claims described below rather than the detailed description, and all changes or modifications derived from the meaning and scope of the claims and their equivalent concepts should be interpreted as being included in the scope of the present invention.
Claims
1. In the intrusion prevention device, A printed circuit board on which a protected processor is mounted; and A protection device comprising a controller having a storage space, the controller being manufactured in a shape that can cover the protection target processor and is bonded to a printed circuit board to protect the protection target processor from physical attacks, and sealing the protection target processor from the outside, and an intrusion prevention cover, The above-mentioned intrusion prevention cover is an intrusion prevention device that provides a signature / verification service required by a protected digital device using a private key and public key pair stored in the storage space of the above-mentioned controller.
2. In paragraph 1, The above-mentioned intrusion prevention cover is an intrusion prevention device that additionally encrypts important information and stores it in the storage space of the controller, and deletes the encryption key used to encrypt the important information when an intrusion attack from outside occurs.
3. In paragraph 1, An intrusion prevention device that uses the signature / verification service of the above intrusion prevention cover to create a reference value for determining whether important information has been changed, and verifies the integrity of the reference value using a signature value created in advance by a digital device before using the important information to determine whether it has been altered.
4. In paragraph 1, An intrusion prevention device, wherein when the above intrusion prevention cover detects an attack from the outside, the controller detects that the state has changed and deletes the important information stored in the storage space so that an external attacker cannot read the important information.
5. In paragraph 1, A penetration barrier device, wherein the above penetration barrier cover or the printed circuit board further includes a built-in battery to enable the controller to enter a sleep mode.
6. In paragraph 5, An intrusion prevention device that, when detecting an attack in which the built-in battery is removed, deletes the important information stored in the storage space so that an external attacker cannot read the important information.
7. In any one of paragraphs 2 to 6, An intrusion prevention device, wherein the above-mentioned important information is at least one of the settings required for the protected processor to operate and the encryption key used to encrypt the settings.
8. In a method for blocking an intrusion attack by a controller of an intrusion prevention device, the power of the protected digital device is cut off at the time of blocking an external attack. A step of recording important information in a storage space provided by the controller by the protected processor; A step in which the controller, having received important information from the protected processor, re-encrypts the important information and stores it in the storage space of the controller; and A method for blocking intrusions, comprising the step of detecting that the controller has changed its state and performing a response action to the detection when at least one attack occurs among an attack that destroys the intrusion blocking device and an attack that removes the built-in battery.
9. In paragraph 8, A method for blocking intrusion, comprising, after the step of storing in the storage space, when the protected processor searches for the important information, the controller decrypts the encrypted information and provides it to the protected processor.
10. In paragraph 8, A method for blocking intrusion, further comprising the step of the controller providing the stored information to the protected processor when the protected processor requests the previously stored information from the controller.
11. In paragraph 8, A method for blocking intrusion, wherein the step of performing a response action to the above detection is a step of performing an action of deleting important information stored in the storage space of the controller.
12. In paragraph 8, A method for blocking intrusion, wherein the above-mentioned important information is at least one of the settings required for the operation of the protected processor and the encryption key used to encrypt these settings.
Citation Information
Patent Citations
Security computing system and working method thereof
CN111563280A
Apparatus Of Protecting Data Of Cryptographic DeviceFrom Opening For Personal Computer
KR1020010061371A
Data security apparatus
KR1020090025846A
Always-available embedded theft reaction subsystem
KR1020130118939A