Computational System Integrity Protection via Polling Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current protection mechanisms against integrity violation in computational systems, such as security controllers and RFID devices, are susceptible to faults induced by physical attacks, which can compromise the secrecy of secret keys during encryption and decryption processes.

Innovation Solution

A computational system with a processing unit and critical resources that intermittently transmit polling values, apply transformations, and check response values for correctness, thereby controlling the controllability of critical resources based on the check results to prevent unauthorized access and ensure secure operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If protection mechanisms like access right flags and protection levels are used, then security against integrity violation is improved, but these mechanisms themselves can be subjected to integrity violation through physical attacks

Engineering Contradiction:
Improvesecurity protectionVSAvoidphysical attack susceptibility
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a critical resource as an intermediary component that mediates between the processing unit and protected data. This critical resource acts as a trusted mediator that verifies the integrity of protection mechanisms before allowing access, preventing direct attacks on access right flags and protection levels through physical attacks

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If critical resources are continuously locked to prevent unauthorized access, then security is improved, but system productivity and operational efficiency deteriorate

Engineering Contradiction:
Improveintegrity protectionVSAvoidsystem operational efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements periodic polling where the critical resource intermittently transmits polling values to the processing unit at predetermined intervals. This periodic interaction allows the system to maintain security while enabling efficient operation during authorized access periods, balancing protection with productivity

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The locking state of the critical resource is made dynamic rather than static. The resource transitions between locked and unlocked states based on verification results of response values, allowing the system to adapt its security posture to current operational needs and maintain both security and efficiency

Inventive Principle:
Principle #15Dynamics

3Measurement precision

If the critical resource continuously verifies polling values and response values, then detection precision for integrity violation is improved, but processing time and system performance worsen

Engineering Contradiction:
Improveintegrity violation detectionVSAvoidverification processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent applies partial verification by focusing checks only on critical response values that indicate potential integrity violations, rather than continuously verifying all data transmissions. This selective verification approach maintains high detection precision while minimizing processing time overhead

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS9195857B2Computational system
Publication Date: 2015.11.24 INFINEON TECHNOLOGIES AG
  • US9195857B2 patent drawing
  • US9195857B2 patent drawing
  • US9195857B2 patent drawing

AI summary

A computational system is configured to protect against integrity violation. The computational system includes a processing unit and a critical resource, the critical resource being controllable by the processing unit so as to be locked or unlocked. The critical resource is configured to intermittently transmit a polling value to the processing unit, and the processing unit is configured to apply a transformation onto the polling value so as to obtain a response value and send the response value back to the critical resource. The critical resource is configured to check the response value on correctness so as to obtain a check result, and subject the controllability to a dependency on the check result.