Active Mesh Tamper Detection in Security ASICs
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional tamper detection countermeasures in security ASICs are easily bypassed by sophisticated adversaries using focused ion beam machines, as they rely on static logic levels that can be traced and manipulated, rendering them ineffective against advanced hacking techniques.
Innovation Solution
Implementing an active mesh with time-varying codes generated by a random number generator to drive and configure the mesh, making it difficult for adversaries to predict and bypass, using either conductive metal wires or capacitors, and incorporating a tamper sensing unit to detect disparities and generate flag signals for anti-tampering actions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a shielding layer with static logic level is used to cover sensitive areas, then the sensitive areas are protected from physical attacks, but the countermeasure can be easily bypassed using focused ion beam machines and invasive probing
Solution Approach 1:
The patent applies dynamics by transforming the static shielding layer into a dynamic active mesh system. The mesh configuration changes over time based on random numbers generated by an RNG, with different subsets of mesh elements activated in different time periods. This temporal variation prevents adversaries from bypassing the countermeasure by making the protection pattern unpredictable and adaptive.
Solution Approach 2:
The patent implements parameter changes by varying the logic levels and configuration states of the mesh elements dynamically. Instead of fixed static levels, the system changes parameters such as which mesh elements are active, their logic states, and their spatial distribution over time based on random number generation, thereby enhancing security against sophisticated probing attacks.
2Reliability
If time-varying codes are used to drive the active mesh, then unpredictability is introduced to deter tampering attempts, but the system complexity and cost increase
Solution Approach 1:
The patent applies segmentation by dividing the mesh system into multiple independent elements or subsets that can be independently controlled. Each subset can be activated or deactivated based on the generated random numbers, allowing the system to achieve high security through coordinated control of simpler individual components rather than requiring a single complex mechanism.
Solution Approach 2:
The patent implements periodic action by continuously generating new random numbers at regular intervals to update the mesh configuration. This periodic refresh of the active mesh pattern based on time-varying codes ensures that the system maintains its security properties over time while using a systematic, manageable approach to complexity.
3Ease of manufacture
If conventional static logic level monitoring is used, then the implementation is simple and low cost, but sophisticated adversaries can trace and decipher the logic levels to bypass the countermeasure
Solution Approach 1:
The patent applies preliminary action by pre-generating random numbers using an integrated RNG that are then used to configure the active mesh before tamper detection occurs. This preliminary generation of cryptographic-quality random values enables the mesh to adopt secure, unpredictable configurations in advance, preventing adversaries from tracing or deciphering the protection pattern.
Solution Approach 2:
The patent introduces an intermediary element in the form of a random number generator and control logic that mediates between the simple mesh structure and the security requirement. This intermediary layer translates simple random number generation into complex, unpredictable mesh configurations, maintaining ease of manufacture while achieving advanced security.
Data Source
AI summary
Various embodiments of the present invention relates generally to an integrated circuit, and more particularly, to systems, devices and methods of incorporating a tamper detection countermeasure into a security ASIC to deter physical attacks. The tamper detection countermeasure architects an active mesh to cover a sensitive area in the security ASIC. A plurality of time-varying random numbers is generated by a random number generator (RNG), and the active mesh is driven and configured according to these random numbers. During tamper detection cycles, the active mesh is monitored with respect to the plurality of random numbers that is directly provided by the RNG. Upon a tampering attempt, a flag signal is generated and used to initialize subsequent anti-tampering actions. The active mesh may be controlled and monitored based on time-varying codes, and therefore, an adversary may not easily bypass the active mesh and attack the sensitive area.


