Beacon Circuit Hardware Trust Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Hardware vulnerabilities, particularly in the manufacturing process, pose significant security risks as malicious designs or backdoors can be introduced, compromising the integrity and security of hardware devices, with little oversight over the manufacturing process and potential for embedded backdoors in third-party components.

Innovation Solution

Incorporating a beacon circuit combined with a hardware-based protection module within a hardware device, which provides a beacon output when triggered, allowing for the determination of malicious implementations by matching a pre-determined output, thereby ensuring the device's trustworthiness even when manufactured by untrusted foundries.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If third-party components are integrated into hardware designs, then design flexibility and functionality are improved, but security risks increase due to potential embedded backdoors

Engineering Contradiction:
Improvedesign flexibilityVSAvoidsecurity trustworthiness
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies preliminary action by incorporating beacon circuits and protection modules into the hardware design before manufacturing. These security mechanisms are pre-configured with unique identifiers and cryptographic keys that enable post-manufacturing verification. The beacon circuit is integrated into the design flow such that it becomes part of the manufactured device, allowing security verification to occur after the device is built but before deployment.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses beacon circuits as intermediaries between the hardware device and the verification system. The beacon circuit contains unique identifiers and cryptographic keys that mediate the trust relationship between the device manufacturer and the end user. When triggered, the beacon circuit provides measurable outputs (power consumption, timing characteristics) that serve as cryptographic proof of the device's identity and integrity, enabling verification without exposing sensitive design information.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If manufacturing processes are outsourced to foundries, then production efficiency is improved, but control over security quality deteriorates due to lack of oversight

Engineering Contradiction:
Improveproduction efficiencyVSAvoidsecurity quality control
Core Design Contradiction:
ProductivityVSManufacturing precision

Solution Approach 1:

The patent implements feedback by creating a verification loop that occurs after manufacturing. The beacon circuit provides measurable outputs (power consumption profiles, timing characteristics, digital signatures) that can be verified against expected values. This feedback mechanism allows the design owner to verify that the manufactured device matches the intended design, even though the manufacturing process occurred at an untrusted foundry. The feedback closes the security verification loop without requiring control over the manufacturing process itself.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent applies preliminary action by embedding verification mechanisms (beacon circuits with unique identifiers and cryptographic keys) into the design before outsourcing manufacturing. These pre-configured security features ensure that even though the foundry controls the manufacturing process, the final device contains built-in evidence of its identity and integrity that can be verified later.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If protection modules are added to hardware devices, then security against malicious implementations is improved, but device complexity increases

Engineering Contradiction:
Improveprotection against malicious implementationsVSAvoidhardware structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the beacon circuit functionality with the existing hardware device architecture. The beacon circuit is integrated into the design such that it shares resources with the main device logic, including using the same power supply, clock signals, and physical substrate. The unique identifier and cryptographic keys are stored in the same security structures as the rest of the device, eliminating the need for separate dedicated security hardware and reducing overall complexity.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The beacon circuit is designed to be multi-functional, serving both as a security verification mechanism and as part of the normal device operation. The same circuit structures that provide device functionality also provide the beacon signals for verification. The unique identifier and cryptographic keys are used both for device operation and for security verification, eliminating the need for separate dedicated security hardware and reducing overall device complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Measurement precision

If beacon circuits are triggered for verification, then detection of malicious implementations is improved, but power consumption and timing overhead increase

Engineering Contradiction:
Improvedetection accuracyVSAvoidpower consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent applies periodic action by triggering the beacon circuit only at specific verification points rather than continuously. The beacon is activated periodically during manufacturing, testing, or deployment phases when verification is needed, and remains dormant during normal device operation. This periodic triggering minimizes the time the beacon circuit consumes power while still providing verification capability when required.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The beacon circuit performs verification functions with partial action, focusing only on the specific measurements needed for security verification (power consumption profiles, timing characteristics, digital signatures) rather than full device functionality. This partial verification approach reduces the computational and power overhead compared to running complete device tests, while still providing sufficient detection capability for malicious implementations.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10599847B2Implementations to facilitate hardware trust and security
Publication Date: 2020.03.24 THE TRUSTEES OF COLUMBIA UNIV IN THE CITY OF NEW YORK
  • US10599847B2 patent drawing
  • US10599847B2 patent drawing
  • US10599847B2 patent drawing

AI summary

Disclosed are devices, systems, apparatus, methods, products, media and other implementations, including a method that includes triggering a beacon circuit combined with a hardware-based protection module, included within a hardware device, the hardware-based protection module configured to provide protection against malicious implementations within the hardware device, with the beacon circuit being configured to provide a beacon output when triggered. The method further includes determining based on the beacon output provided by the triggered beacon circuit whether the hardware device includes at least one malicious implementation.