Active Mesh Tamper Detection in Security ASICs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional tamper detection countermeasures in security ASICs are easily bypassed by sophisticated adversaries using focused ion beam machines, as they rely on static logic levels that can be traced and manipulated, rendering them ineffective against advanced hacking techniques.

Innovation Solution

Implementing an active mesh with time-varying codes generated by a random number generator to drive and configure the mesh, making it difficult for adversaries to predict and bypass, using either conductive metal wires or capacitors, and incorporating a tamper sensing unit to detect disparities and generate flag signals for anti-tampering actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a shielding layer with static logic level is used to cover sensitive areas, then the sensitive areas are protected from physical attacks, but the countermeasure can be easily bypassed using focused ion beam machines and invasive probing

Engineering Contradiction:
Improvetamper detection reliabilityVSAvoidmesh configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies dynamics by transforming the static shielding layer into a dynamic active mesh system. The mesh configuration changes over time based on random numbers generated by an RNG, with different subsets of mesh elements activated in different time periods. This temporal variation prevents adversaries from bypassing the countermeasure by making the protection pattern unpredictable and adaptive.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent implements parameter changes by varying the logic levels and configuration states of the mesh elements dynamically. Instead of fixed static levels, the system changes parameters such as which mesh elements are active, their logic states, and their spatial distribution over time based on random number generation, thereby enhancing security against sophisticated probing attacks.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If time-varying codes are used to drive the active mesh, then unpredictability is introduced to deter tampering attempts, but the system complexity and cost increase

Engineering Contradiction:
Improvesecurity against tamperingVSAvoidactive mesh system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies segmentation by dividing the mesh system into multiple independent elements or subsets that can be independently controlled. Each subset can be activated or deactivated based on the generated random numbers, allowing the system to achieve high security through coordinated control of simpler individual components rather than requiring a single complex mechanism.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements periodic action by continuously generating new random numbers at regular intervals to update the mesh configuration. This periodic refresh of the active mesh pattern based on time-varying codes ensures that the system maintains its security properties over time while using a systematic, manageable approach to complexity.

Inventive Principle:
Principle #19Periodic action

3Ease of manufacture

If conventional static logic level monitoring is used, then the implementation is simple and low cost, but sophisticated adversaries can trace and decipher the logic levels to bypass the countermeasure

Engineering Contradiction:
Improvecountermeasure implementation easeVSAvoidprotection against advanced hacking
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent applies preliminary action by pre-generating random numbers using an integrated RNG that are then used to configure the active mesh before tamper detection occurs. This preliminary generation of cryptographic-quality random values enables the mesh to adopt secure, unpredictable configurations in advance, preventing adversaries from tracing or deciphering the protection pattern.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary element in the form of a random number generator and control logic that mediates between the simple mesh structure and the security requirement. This intermediary layer translates simple random number generation into complex, unpredictable mesh configurations, maintaining ease of manufacture while achieving advanced security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10678951B2Tamper detection countermeasures to deter physical attack on a security ASIC
Publication Date: 2020.06.09 MAXIM INTEGRATED PROD INC
  • US10678951B2 patent drawing
  • US10678951B2 patent drawing
  • US10678951B2 patent drawing

AI summary

Various embodiments of the present invention relates generally to an integrated circuit, and more particularly, to systems, devices and methods of incorporating a tamper detection countermeasure into a security ASIC to deter physical attacks. The tamper detection countermeasure architects an active mesh to cover a sensitive area in the security ASIC. A plurality of time-varying random numbers is generated by a random number generator (RNG), and the active mesh is driven and configured according to these random numbers. During tamper detection cycles, the active mesh is monitored with respect to the plurality of random numbers that is directly provided by the RNG. Upon a tampering attempt, a flag signal is generated and used to initialize subsequent anti-tampering actions. The active mesh may be controlled and monitored based on time-varying codes, and therefore, an adversary may not easily bypass the active mesh and attack the sensitive area.