Computational System Integrity Protection via Polling Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current protection mechanisms against integrity violation in computational systems, such as security controllers and RFID devices, are susceptible to faults induced by physical attacks, which can compromise the secrecy of secret keys during encryption and decryption processes.
Innovation Solution
A computational system with a processing unit and critical resources that intermittently transmit polling values, apply transformations, and check response values for correctness, thereby controlling the controllability of critical resources based on the check results to prevent unauthorized access and ensure secure operations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If protection mechanisms like access right flags and protection levels are used, then security against integrity violation is improved, but these mechanisms themselves can be subjected to integrity violation through physical attacks
Solution Approach 1:
The patent introduces a critical resource as an intermediary component that mediates between the processing unit and protected data. This critical resource acts as a trusted mediator that verifies the integrity of protection mechanisms before allowing access, preventing direct attacks on access right flags and protection levels through physical attacks
2Reliability
If critical resources are continuously locked to prevent unauthorized access, then security is improved, but system productivity and operational efficiency deteriorate
Solution Approach 1:
The patent implements periodic polling where the critical resource intermittently transmits polling values to the processing unit at predetermined intervals. This periodic interaction allows the system to maintain security while enabling efficient operation during authorized access periods, balancing protection with productivity
Solution Approach 2:
The locking state of the critical resource is made dynamic rather than static. The resource transitions between locked and unlocked states based on verification results of response values, allowing the system to adapt its security posture to current operational needs and maintain both security and efficiency
3Measurement precision
If the critical resource continuously verifies polling values and response values, then detection precision for integrity violation is improved, but processing time and system performance worsen
Solution Approach 1:
The patent applies partial verification by focusing checks only on critical response values that indicate potential integrity violations, rather than continuously verifying all data transmissions. This selective verification approach maintains high detection precision while minimizing processing time overhead
Data Source
AI summary
A computational system is configured to protect against integrity violation. The computational system includes a processing unit and a critical resource, the critical resource being controllable by the processing unit so as to be locked or unlocked. The critical resource is configured to intermittently transmit a polling value to the processing unit, and the processing unit is configured to apply a transformation onto the polling value so as to obtain a response value and send the response value back to the critical resource. The critical resource is configured to check the response value on correctness so as to obtain a check result, and subject the controllability to a dependency on the check result.


