ASIC Root-Of-Trust Tamper Response for Secret-Key Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing ASICs are vulnerable to sophisticated attacks that compromise their security by unauthorized access to secret keys stored in non-volatile memory, which can degrade device performance and compromise network security.

Innovation Solution

Implement a Root-Of-Trust (ROT) module that continuously monitors the ASIC for potential attacks, using sensors to detect unauthorized access and executes tamper resistance processes such as overwriting or deleting secret keys to maintain security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If non-volatile memory is used to store secret keys for decryption, then the security of the ASIC is improved, but the vulnerability to sophisticated invasive attack mechanisms increases

Engineering Contradiction:
ImprovesecurityVSAvoidvulnerability to attack
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary anti-action by implementing continuous monitoring of chip operations and automatically overwriting secret keys before an attacker can successfully extract them. The system proactively detects tamper attempts and responds by destroying the cryptographic material, preventing the harmful effect of key extraction rather than reacting after compromise occurs.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The patent implements feedback mechanisms through continuous monitoring of chip operations and tamper detection. The system constantly monitors for signs of intrusion and adjusts its behavior by overwriting keys when tamper conditions are detected, creating a closed-loop security system that responds to attack conditions in real-time.

Inventive Principle:
Principle #23Feedback

2Reliability

If continuous monitoring of chip operations is implemented, then the tamper resistance is enhanced, but the device complexity increases

Engineering Contradiction:
Improvetamper resistanceVSAvoidmonitoring system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the monitoring function with the existing Root-Of-Trust hardware and cryptographic operations. Instead of adding a completely separate monitoring system, the monitoring capabilities are integrated into the existing security architecture, combining tamper detection with key management functions to reduce overall system complexity.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The monitoring system serves multiple functions: it monitors chip operations for security purposes, detects tamper attempts, and triggers key overwriting when needed. This multi-functionality reduces the need for separate dedicated components for each function, thereby reducing overall device complexity while maintaining enhanced tamper resistance.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If secret keys are stored in non-volatile memory, then the decryption capability is maintained, but the susceptibility to unauthorized access increases

Engineering Contradiction:
Improvedecryption capabilityVSAvoidunauthorized access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by continuously monitoring for tamper conditions and proactively overwriting secret keys before unauthorized access can succeed. The system prepares for potential attacks by maintaining awareness of the operational state and preemptively destroying cryptographic material when vulnerability conditions are detected.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary monitoring and response mechanism between the secret key storage and potential attackers. This intermediary system continuously assesses the security state and mediates by overwriting keys when tamper conditions are detected, preventing direct unauthorized access while maintaining normal decryption operations when secure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250258964A1Continuous impairment of a chip upon detecting a damaged package
Publication Date: 2025.08.14 CISCO TECHNOLOGY INC
  • US20250258964A1 patent drawing
  • US20250258964A1 patent drawing
  • US20250258964A1 patent drawing

AI summary

A method for monitoring an Integrated Circuit (IC). The method includes decrypting, by the Root-Of-Trust (ROT) module, an identity package that resides in a non-volatile memory of the IC using a secret accessible by the ROT module. The identity package is configured in a decrypted state at the non-volatile memory by use of the secret. The ROT module is configured to discover, based on monitoring data from a sensor that an attack is at least being attempted on a package of the IC. The ROT determines whether a debug package is present in response to the attack. If the debug package is not present, the ROT module is configured to execute a tamper resistance process to prevent the use of the secret by the ROT module and the identity package from being placed or remaining in a decrypted state in the non-volatile memory of the IC.