Hardware-Assisted Anti-Fault Injection Controller for Secure Boot

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Semiconductor chips are susceptible to attacks during boot operations, particularly fault injection attacks that can cause the chip to malfunction by switching to non-secure boot mode instead of secure mode, compromising the integrity of the system.

Innovation Solution

The implementation of hardware-assisted anti-fault injection systems using a dual behavior register and anti-fault injection controller circuitry that interrupts the processor when it attempts to execute non-secure boot instructions in secure mode, ensuring the processor resets and reverts to secure boot operations, thereby preventing malicious image loading.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If fault injection attacks are implemented to test system security, then security vulnerabilities can be detected, but the system may malfunction by switching to non-secure boot mode

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidsystem malfunction
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary anti-action by implementing a hardware-assisted detection mechanism that proactively identifies fault injection attempts before they can cause system malfunction. The anti-fault injection controller continuously monitors boot operations and detects abnormal conditions (such as unexpected mode switches to non-secure boot) before they result in harmful effects, thereby neutralizing the attack vector in advance.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The patent introduces an intermediary component - the anti-fault injection controller - that acts as a mediator between the processor and the bootrom. This controller intercepts and monitors boot operations, detecting fault injection attempts that try to force non-secure boot mode. The intermediary validates boot mode transitions and prevents malicious switches, thereby protecting the system while allowing legitimate boot operations to proceed.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If hardware-assisted anti-fault injection control is implemented, then fault injection attacks are prevented, but hardware and software complexity increases

Engineering Contradiction:
Improveprotection against fault injection attacksVSAvoidhardware and software changes
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies universality by designing the anti-fault injection controller to perform multiple functions within a single hardware module. The controller simultaneously monitors boot mode transitions, detects fault injection attempts, validates secure boot operations, and interfaces with the interrupt/reset circuitry. This multi-functionality reduces the need for separate dedicated components for each security function, thereby limiting the increase in overall system complexity while maintaining comprehensive protection.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements self-service by enabling the anti-fault injection controller to autonomously detect and respond to fault injection attempts without requiring extensive external intervention. The controller self-monitors boot operations, automatically identifies abnormal mode switches, and triggers appropriate reset or interrupt signals to prevent attacks. This self-service capability reduces the burden on external security management systems and minimizes the complexity of integrated security protocols.

Inventive Principle:
Principle #25Self-service

3Reliability

If secure boot operations are enforced, then system integrity is maintained, but boot process time increases due to additional verification steps

Engineering Contradiction:
Improvesystem integrityVSAvoidboot process time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by having the hardware-assisted controller pre-validate boot mode transitions during the boot process. Instead of performing extensive verification after a potential security breach occurs, the controller proactively checks mode switches in real-time and prevents unauthorized transitions to non-secure mode before they can compromise system integrity. This preliminary validation reduces the need for lengthy post-boot verification procedures.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces mechanical/software-based security verification with hardware-based detection. The anti-fault injection controller uses hardware circuits to monitor and validate boot mode transitions, substituting what would otherwise require software polling and verification routines. This hardware-level enforcement of secure boot operations provides real-time protection with minimal processing overhead, thereby reducing boot process time while maintaining system integrity.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS10878099B2Hardware assisted fault injection detection
Publication Date: 2020.12.29 MAXLINEAR INC
  • US10878099B2 patent drawing
  • US10878099B2 patent drawing
  • US10878099B2 patent drawing

AI summary

Anti-fault injection systems and methods are disclosed. An anti-fault injection system includes a processor; a boot ROM configured to store a series of boot instructions executable by the processor; and anti-fault injection controller circuitry. The anti-fault injection controller circuitry is accessible to the processor while the processor is executing the boot instructions. The anti-fault injection controller circuitry includes interrupt/reset circuitry configured to interrupt the processor in response to a trigger and secure boot circuitry. The secure boot circuitry is configured to, in response to being accessed by the processor: determine whether the processor is executing non-secure boot instructions in error; and in response to detecting that the processor is executing non-secure boot instructions in error, provide the trigger to the interrupt/reset circuitry.