Configuration Register Tamper Detection Using Inverted Latch Pairs
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing processing systems face challenges in protecting configuration registers that store security information, such as configuration registers used to manage access to resources and reference passwords, from unauthorized modification by hackers.
Innovation Solution
A processing system is designed with storage elements like latches or flip-flops that store security-related configuration data, and a protection circuit that selectively executes control commands based on the logic levels stored in these elements, incorporating a tamper detection mechanism to prevent unauthorized changes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If configuration registers store security information to enable resource access control, then access control functionality is improved, but vulnerability to unauthorized modification by hackers increases
Solution Approach 1:
The patent applies preliminary action by pre-configuring protection mechanisms before security breaches can occur. Configuration registers are designed with inherent protection features such as write protection bits, password verification logic, and tamper detection circuits that are activated before any unauthorized access attempt. This ensures that security information is protected from modification before hackers can exploit vulnerabilities.
Solution Approach 2:
The patent introduces intermediary elements between the configuration registers and external access points. These intermediaries include protection circuits that mediate all write operations to configuration registers, requiring authentication through password verification or specific protection bit settings. This intermediary layer prevents direct unauthorized modification while maintaining legitimate access control functionality.
2Reliability
If protection mechanisms are added to configuration registers, then security against tampering is improved, but device complexity increases
Solution Approach 1:
The patent merges protection functions with the existing configuration register structure. Protection bits, password verification logic, and tamper detection capabilities are integrated directly into the configuration register blocks rather than being implemented as separate external circuits. This consolidation provides robust tamper protection while minimizing the increase in overall device complexity by reusing existing logic resources.
Solution Approach 2:
The patent implements universal protection mechanisms that serve multiple functions simultaneously. The same protection circuits and logic structures are used across different configuration registers to provide write protection, password verification, and tamper detection. This multi-functional approach reduces overall device complexity by avoiding redundant protection circuits for each individual register, achieving high reliability through standardized, reusable security IP blocks.
3Measurement precision
If tamper detection mechanisms are implemented, then detection precision for unauthorized changes is improved, but manufacturing complexity increases
Solution Approach 1:
The patent implements self-service tamper detection where the configuration registers automatically monitor and detect unauthorized changes without requiring external detection equipment. Tamper detection circuits are integrated into the register structure, continuously monitoring for unauthorized write attempts, physical tampering, or logic anomalies. This self-detecting capability provides high measurement precision for tamper events while simplifying manufacturing by eliminating the need for complex external testing and verification infrastructure.
Data Source
Figure 1~2
Figure 3
Figure 4~6
AI summary
A processing system (10a) is described. The processing system (10a) comprises a plurality of storage elements (113), wherein each storage element (113) is configured to receive a write request comprising a data bit (DATA) and store the received data bit (DATA) to a latch or flip-flop (1122). A hardware circuit (110, 150, 152, 1130, 1502) is configured to change operation as a function of the logic level stored to the latch or flip-flop (1122) of a first storage element (113) of the plurality of storage elements (113). A non-volatile memory (104; 126) is configured to store data bits (CD, LCD) for the plurality of storage elements (113) and a hardware configuration circuit (108) is configured to read the data bits from the non-volatile memory (104; 126) and generate write requests in order to store the data bits to the storage elements (113). Specifically, the hardware circuit (110, 150, 152, 1130, 1502) is configured to change operation also as a function of the first tamper signal (TAMP). For this purpose, the first storage element (113) comprises a further latch or flip-flop (1124) and is configured to store, in response to the write request, the inverted version (1126) of the received data bit to the further latch or flip-flop (1124). The first storage element (113) comprises also a combinational logic circuit (1128) configured to compare the logic level stored to the latch or flip-flop (1122) of the first storage element (113) with the logic level stored to the further latch or flip-flop (1122) of the first storage element (113). The combinational logic circuit (1128) is configured to de-assert a first tamper signal (TAMP) associated with the first storage element (113) when the logic levels are different, and assert the first tamper signal (TAMP) when the logic levels are the same.