Boot Clock Pulse Randomization for Power Analysis Resistance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for securing the boot process of digital electronic devices are vulnerable to power analysis attacks, as they do not effectively obfuscate power signatures, leading to potential manipulation and unauthorized access.

Innovation Solution

A hardware boot circuit introduces clock randomness at the root node of the clock network using a random number generator and clock gate circuit, generating a randomized clock signal by selectively gating clock pulses, which is used to access boot instructions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a fixed clock signal is used during boot process, then synchronous performance is maintained, but power signatures become predictable and vulnerable to power analysis attacks

Engineering Contradiction:
ImprovesecurityVSAvoidpower analysis attack vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies dynamics by transforming the static, fixed clock signal into a dynamic, randomized clock signal. The boot clock signal is modified by randomly inserting delays and varying pulse widths, making the timing characteristics changeable and unpredictable. This dynamic randomization prevents attackers from correlating power consumption patterns with specific boot operations, thereby securing the boot process against power analysis attacks while maintaining synchronous operation.

Inventive Principle:
Principle #15Dynamics

2Object-affected harmful factors

If clock pulses are randomized during boot, then power signature obfuscation is achieved, but clock signal predictability increases for attackers

Engineering Contradiction:
Improvepower signature obfuscationVSAvoidclock signal predictability
Core Design Contradiction:
Object-affected harmful factorsVSLoss of information

Solution Approach 1:

The patent applies parameter changes by modifying multiple parameters of the clock signal simultaneously - including pulse width, inter-pulse intervals, and timing offsets - rather than changing a single parameter. This multi-parameter randomization creates a more complex and unpredictable clock signal that effectively obfuscates power signatures. The randomized parameters ensure that attackers cannot predict when specific boot operations occur, preventing successful power analysis attacks.

Inventive Principle:
Principle #35Parameter changes

3Loss of time

If uniform clock intervals are used, then boot process timing is predictable, but power traces show consistent patterns enabling differential power analysis

Engineering Contradiction:
Improveboot process timingVSAvoidpower trace consistency
Core Design Contradiction:
Loss of timeVSReliability

Solution Approach 1:

The patent applies periodic action by introducing random periodic variations into the clock signal intervals. Instead of uniform, predictable intervals, the system implements periodically occurring random delays and interval variations during the boot process. This creates a pattern where timing inconsistencies occur at regular intervals, making it difficult for attackers to correlate power traces with specific operations. The periodic randomization effectively breaks the consistency that enables differential power analysis while maintaining overall boot process timing.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS20250355672A1Hardware randomized boot clock
Publication Date: 2025.11.20 STMICROELECTRONICS INT NV
  • US20250355672A1 patent drawing
  • US20250355672A1 patent drawing
  • US20250355672A1 patent drawing

AI summary

A hardware boot circuit includes a random number generator circuit configured to generate random values, a reference clock circuit configured to generate a reference clock signal that includes a series of intervals of fixed size, a clock gate circuit configured to switch off at least one clock pulse in each interval to generate a randomized clock signal at a root node of a clock network, and a boot core circuit configured to use the randomized clock signal to access an internal memory storing boot instructions. Clock pulses that are switched off are randomized by the random values from the random number generator. The randomized clock signal or additional randomized clock signals generated by the clock gate circuit may be used to clock peripherals and/or processors of a digital electronic device that includes the hardware boot circuit. The random number generator may include a physical entropy source.