Clock Integrity Verification in Integrated Circuit Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Integrated circuits (ICs) face challenges in securing their clock configuration against external and internal attacks, which can lead to unauthorized access and improper operation.

Innovation Solution

The IC incorporates a reconfigurable clock management subsystem and a security subsystem that performs security operations while preventing alteration of the clock configuration. The clock management subsystem conducts a clock integrity check before security operations, ensuring that the clock configuration remains secure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the clock management subsystem is made reconfigurable to adjust clock characteristics and select clock sources, then the adaptability and functionality of the IC are improved, but the vulnerability to security attacks increases due to potential manipulation of clock configuration

Engineering Contradiction:
Improveclock configuration flexibilityVSAvoidsecurity vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

A dedicated security subsystem is introduced as an intermediary between the clock management subsystem and external/internal access points. This security subsystem monitors and controls access to clock configuration registers, preventing unauthorized or malicious modifications while allowing legitimate reconfiguration operations to proceed. The security subsystem acts as a gatekeeper that verifies the integrity of clock configuration changes before they are applied.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary validation checks on clock configuration requests before allowing reconfiguration to occur. The security subsystem pre-approves or blocks configuration changes based on predefined security policies, ensuring that only authorized modifications are permitted. This preliminary security check prevents malicious configurations from being applied in the first place.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If security operations are performed within the IC, then the security of assets is improved, but the risk of clock manipulation attacks increases that could bypass these security measures

Engineering Contradiction:
Improvesecurity operation integrityVSAvoidclock manipulation attack risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The security subsystem preemptively locks or protects clock configuration registers during security-critical operations. Before security operations begin, the system prevents any clock configuration changes from occurring, thereby counteracting potential clock manipulation attacks before they can affect the security operations. This preliminary protective measure ensures that clock signals remain stable and trustworthy throughout the security operation.

Inventive Principle:
Principle #9Preliminary anti-action

3Reliability

If the clock management subsystem is protected against alteration during security operations, then the security integrity is improved, but the device complexity increases due to additional protection mechanisms

Engineering Contradiction:
Improveclock configuration securityVSAvoidprotection mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security subsystem and clock management subsystem are integrated into a unified architecture where security policies for clock management are embedded within the same hardware structure. Rather than adding completely separate protection hardware, the system combines security control logic with the existing clock management infrastructure, reducing overall complexity while maintaining robust security protection.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS20250077646A1Clock integrity verification and protection in an integrated circuit (IC)
Publication Date: 2025.03.06 CIRRUS LOGIC INC
  • US20250077646A1 patent drawing
  • US20250077646A1 patent drawing
  • US20250077646A1 patent drawing

AI summary

An integrated circuit (IC), including multiple functional units for performing operations of the integrated circuit, provides security of a clock configuration at least during security operations. The IC includes a clock management subsystem for providing one or more clock signals to the functional units. The clock management subsystem is reconfigurable to adjust characteristics of the clock signal(s) or to select from among multiple clock sources from which the clock management subsystem generates the clock signal(s). The IC also includes a security subsystem for performing security operations within the IC and coupled to the clock management system to prevent alteration of a configuration of the clock management subsystem while the security operations are performed. The clock management subsystem performs a clock integrity check in response to the security operations before the security operations are performed. The security operations are not performed if the clock integrity check fails.