Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

20 results about "Fault injection attack" patented technology

Fault-injection attacks have been around as long as the Web itself. They allow malicious access into a network or computer system through a Web application. With the explosive growth of applications, and as more applications are migrated to the Web, injection attacks have become a growing concern.

Security system

The present invention provides a security system configured on a chip to be protected, the system including fault injection detection subsystems configured on the chip, each fault injection detection subsystem having a plurality of real-time selectable sensitivity levels and including at least one hardware fault injection detector circuit disposed on the chip and / or sensitivity level control logic coupled with the hardware fault injection detector circuit, deployable on the chip and operable in real-time to transition the fault injection detection subsystem from a current sensitivity level of the plurality of selectable sensitivity levels to a next sensitivity level of the plurality of selectable sensitivity levels, for example by generating a sensitivity control signal (also referred to as a sensitivity level selection) and / or sending the sensitivity control signal to at least one hardware fault injection detector circuit in the fault injection detection subsystem. The fault injection countermeasure circuit is operated to protect the processor from fault injection attacks dynamically depending on the execution flow of the processor core.
Owner:NUVOTON

Circuit and method for detecting a fault injection attack in an integrated circuit

A fault detection circuit includes a plurality of conductors, a plurality of logic gates coupled to the conductors, a storage circuit, and a checker circuit. The conductors are arranged in parallel. Each logic gate is coupled to a first end of each conductor. The storage circuit is coupled to a second end of each conductor. The checker circuit is coupled to the storage circuit. A known initial bit pattern is provided to an input of the logic gates, and an output of the logic gates is provided to the storage circuit via the conductors. The checker circuit determines if the output of the logic gates stored in the storage circuit is an expected result. If the output is not the expected result, then the checker circuit provides an indication that a fault injection attack is occurring. In another embodiment, a method for detecting a fault injection attack is provided.
Owner:NXP BV

Anti-attack block cipher encryption method for multi-scene application

The application relates to an anti-attack block cipher encryption method for multi-scene application. A group of random numbers generated by a random number module is pre-stored in a register, two groups of round functions are designed to simultaneously encrypt plaintext, irrelevant data is encrypted by using an irrelevant key to interfere with the power consumption curve of the current chip when the plaintext is correctly encrypted, so that the power consumption curve obtained by an attacker contains irrelevant power consumption, the difficulty of power consumption curve analysis is increased, and a random pseudo round is inserted in the 10 rounds of normal operation to prevent a fault injection attack; when there is no attacker, the two groups of round functions are simultaneously used to simultaneously encrypt two groups of plaintext, and the encryption speed is improved.
Owner:NO 47 INST OF CHINA ELECTRONICS TECH GRP

System for detecting fault injection attacks

An integrated circuit (IC) that includes an always-on buffer and a power line is provided. The power line is routed on the IC such that a first end of the power line is at a first global supply voltage and a second end of the power line is at a second global supply voltage that is less than the first global supply voltage. The always-on buffer receives an input bit and the second global supply voltage and generates an output bit that has a same logic state as that of the input bit. During a fault injection attack, the second global supply voltage is altered such that the logic state of the output bit toggles while the logic state of the input bit remains same. Based on the toggling of the logic state of the output bit, the fault injection attack on the IC is detected.
Owner:NXP BV

Burr detector

The invention relates to voltage glitch detection in an integrated circuit for detecting fault injection attacks. Example embodiments include an integrated circuit (411), the integrated circuit (411) including: a hardware accelerator (412) including a computing module (4131, 4132) configured to perform a computing function; and a glitch detector (4161, 4162) comprising a delay function (4131, 4132) and a comparator (4191, 4192), the comparator (4191, 4192) being arranged to compare an output from the delay function (4131, 4132) to an expected result to provide an output for detecting glitch, wherein the delay function (4131, 4132) of the glitch detector (4161, 4162) is provided at least in part by the computing function of the computing module (4131, 4132) in the hardware accelerator (412).
Owner:NXP BV

Fault-resilient secure-by-design systems elements

This document describes apparatuses and techniques for fault-resilient secure-by-design systems elements. In aspects, a method is disclosed that includes operating a plurality of design elements in a computing system that are configured to operate with standard timing slack and at least one security-critical design element configured to operate with increased timing slack that is greater than the standard timing slack. The increased timing slack enables a security-guarantee operation to be successfully performed by the at least one security-critical design element before a fault injection attack directed at one or more of the plurality of design elements causes a fault in operation of one or more of the plurality of design elements that would have prevented the security-guarantee operation from being successfully completed if the at least one security-critical design element were configured to operate with standard timing slack.
Owner:GOOGLE LLC

An attack positioning method, device and system for a white-box block cipher algorithm and a storage medium

The application discloses an attack positioning method, device and system of a group white-box cryptographic algorithm and a storage medium, and relates to the technical field of information security. The method is used to at least solve the problem that in the process of a white-box cryptographic fault injection attack experiment, a key execution point of injected faults cannot be accurately identified and an accurate injection timing cannot be accurately determined, resulting in poor attack precision and low attack efficiency. The method comprises the following steps: collecting side channel waveforms generated in the execution process of the group white-box cryptographic algorithm in real time; analyzing the morphological characteristics of the side channel waveforms to determine a target round of attack; determining a target waveform region with a waveform difference degree less than a difference degree threshold from a preset reference waveform from the actual side channel waveforms generated in the target round; and determining an attack positioning point according to the target waveform region.
Owner:北京银联金卡科技有限公司

Protection of cryptographic substitution-permutation networks from fault injection attacks

Aspects of the present disclosure involve a method and a system to perform the method to obtain a cryptographic output of a plurality of rounds of a cipher, by performing a plurality of modified rounds of the cipher, each of the modified rounds computing an unmasking transform, an operation of a respective round of the cipher, and a masking transform, the unmasking transform being an inverse of the masking transform of a previous round of the cipher.
Owner:CRYPTOGRAPHY RESEARCH INC

Attack positioning method, device and system of grouping white-box cryptographic algorithm and storage medium

The invention discloses an attack positioning method, device and system for a grouped white-box cryptographic algorithm and a storage medium, relates to the technical field of information security, and aims to at least solve the problem that in a white-box cryptographic fault injection attack experiment process, key execution points and accurate injection opportunities of injection faults cannot be accurately recognized, and the fault injection efficiency is improved. And therefore, the problems of poor attack accuracy and low attack efficiency can be solved. The method comprises the following steps: acquiring a side channel waveform generated in an execution process of a grouping white-box cryptographic algorithm in real time; analyzing the morphological characteristics of the side channel waveform, and determining a target round of attack; determining a target waveform region in which the waveform difference between the target waveform region and a preset reference waveform is smaller than a difference threshold value from the actual side channel waveforms generated in the target round; and determining an attack positioning point according to the target waveform region.
Owner:北京银联金卡科技有限公司

Chip software code anti-attack protection method, chip and electronic equipment

The invention relates to the technical field of chip software security, and discloses a chip software code anti-attack protection method, a chip and electronic device.The method comprises the steps that in the running process of a chip software code, when the chip software code is executed to the position of a burying point, a random delay duration is generated, and the burying point is arranged at a to-be-protected node in the chip software code; pausing a main process of the chip software code and continuing the random delay duration; and after the random delay duration expires, recovering the main process of executing the chip software code. Based on the above method, for two or more fault injection attacks, random delay at the burying point enables the starting time of the key protection step to be uncertain, an attacker cannot repeatedly match the attack point, and key inspection is difficult to skip; for side channel attacks, random delay makes information such as execution time, chip power consumption and the like irregular, and attackers cannot extract rule features to reversely deduce sensitive data, so that attack logic is fundamentally cracked, and the security defect of an existing anti-attack protection scheme is made up.
Owner:BEIJING TSINGTENG MICROSYSTEM CO LTD

Fault-to-time converter sensor for low-overhead fault injection attack mitigation

ActiveUS12675610B2ConvertersLow voltage
Various embodiments of the present disclosure provide fault injection attack mitigation for an integrated circuit. In one example, an embodiment provides for providing a sampling clock signal to both high voltage threshold (HVT) cells and low voltage threshold (LVT) cells of a fault-to-time converter sensor of an integrated circuit, providing output of the HVT cells and the LVT cells to an encoder stage of the fault-to-time converter sensor, and detecting one or more fault injection attacks with respect to the integrated circuit based on output of the encoder stage.
Owner:UNIV OF FLORIDA RESEARCH FOUNDATION INC

Method for protecting against fault attacks an execution of a generation of a crystals-dilithium signature

The invention relates to methods, and associated devices, for protecting the execution of the generation of a Crystals-Dilithium digital signature σ of a message M with a secret key sk against attacks exploiting invalid signatures content by fault attacks. In order to prevent an attacker bypassing by fault injection attacks tests on a second test vector (I) from obtaining invalid signatures as outputs of the signature generation algorithm, the invention modifies the norm check performed on the second test vector (I) in such a way that if this check is skipped, the candidate signature is rejected by the subsequent test performed on a fourth vector of polynomials h.
Owner:THALES DIS FRANCE SA

An attribute-driven persistent fault analysis method

The application discloses a kind of attribute-driven persistent fault analysis methods, first establish basic logic unit formalization fault model library and the formalization fault model of cryptographic algorithm kernel;Then the random simulation of cryptographic algorithm kernel formalization fault model is carried out;Again the fault information that satisfies is automatically extracted fault attribute;Next, the persistent fault injection attack of cryptographic algorithm is carried out;Finally, the persistent fault analysis of cryptographic algorithm is realized using fault attribute as constraint.The present application establishes fault propagation model without complex mathematical operation, and has no strict requirement for the position and quantity of fault injection, reduces the number of fault ciphertext used and key search complexity, compared with the existing fault injection analysis technology, the application method is more widely used.
Owner:NORTHWESTERN POLYTECHNICAL UNIV

A data verification method, device, apparatus, and storage medium

This invention provides a data verification method, apparatus, device, and storage medium, relating to the field of cryptographic operations. The method includes: acquiring intermediate and final processing results obtained by performing cryptographic operations on the same data using multiple cryptographic operation cores; and verifying the intermediate and final processing results of the multiple cryptographic operation cores to obtain a verification result. By verifying the intermediate and final processing results of multiple cryptographic operation cores, this invention can promptly and effectively detect anomalies in the cryptographic operation cores, thereby improving the protection effect of the cryptographic operation cores and ensuring that they can effectively resist common-mode faults and malicious fault injection attacks.
Owner:HUNAN GOKE MICROELECTRONICS CO LTD

Method for protecting against fault attacks an execution of a generation of a crystals-dilithium signature

The invention relates to methods, and associated devices, for protecting the execution of the generation of a Crystals-Dilithium digital signature δ of a message M with a secret key sk against attacks exploiting invalid signatures content by fault attacks. In order to prevent an attacker bypassing by fault injection attacks any of first rejections tests on a second test vector r0 / ro~ or on a first test vector z or of second rejection tests on a fourth vector of polynomials h or on the value c*to from obtaining invalid signatures as outputs of the signature generation algorithm, the present invention, before outputting a candidate signature verifies that the value of the second vector of polynomials w1' computed when generating the candidate signature truly corresponds to the value w1' that will later be computed when verifying the candidate signature. To this end, an additional rejection test is added to the signature generation algorithm, after the second rejection tests.
Owner:THALES DIS FRANCE SA

Detection of a fault injection attack

The invention provides a method of detecting a fault injection attack during execution of a computer program comprising: - obtaining (201) a current value of an address register of a processor during a current clock cycle; - obtaining (202) a last executed instruction of the computer program, the last executed instruction being obtained during one of several clock cycles before the current clock cycle; - verifying (205) at least one predefined pair of conditions, each predefined pair of condition comprising a first condition related to the current value of the at least one address register and a second condition related to the last executed instruction of the computer program or to an external signal indicating an interrupt; - depending on the verification of the at least one predefined pair of conditions, detecting (210) a fault injection attack or validating (206) the last executed instruction.
Owner:THALES DIS FRANCE SA

Function call authentication for program flow control

This document discloses aspects of function call authorization for program flow control. In some aspects, a processor encounters a first instruction to initiate or call a function. The processor compares an immediate value of a second instruction at an entry point of the function to a function call authorization value stored in a register. In response to the immediate value of the second instruction matching the function call authorization value stored in the register the process transfers control flow to the function. Alternatively, if the values do not match, an exception or fault may be raised to halt execution of the function or other code. By so doing, these and other aspects of function call authorization may prevent fault injection attacks, execution of unauthorized instructions, or access to sensitive data.
Owner:GOOGLE LLC

Glitch detector

The disclosure relates to voltage glitch detection in an integrated circuit for detection of fault injection attacks. Example embodiments include an integrated circuit comprising: a hardware accelerator including a computing module configured to perform a computing function; and a glitch detector including a delay function and a comparator arranged to compare an output from the delay function with an expected result to provide an output for detecting a glitch, wherein the delay function of the glitch detector is provided at least in part by the computing function of the computing module in the hardware accelerator.
Owner:NXP BV