Defense Slave Device for Address Space Scan Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Integrated electronic circuits, such as ASICs and FPGAs, are vulnerable to unauthorized scanning of their address space, which can reveal configuration and function information, allowing for hacker attacks and reverse engineering.
Innovation Solution
A defense slave device is connected to the bus system to intercept and analyze accesses to unused addresses, initiating defensive measures such as resetting the circuit, simulating virtual interfaces, or deleting sensitive data to prevent information gathering during address-space scans.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If address space scanning is allowed for debugging and configuration purposes, then ease of operation is improved, but security against reverse engineering deteriorates
Solution Approach 1:
The patent implements preliminary protective measures by configuring the defense slave device with predetermined response behaviors before any scanning attack occurs. The device is pre-programmed to recognize scanning patterns and automatically execute countermeasures such as returning dummy data or triggering alarms, thereby preventing information leakage before it can be exploited for reverse engineering.
Solution Approach 2:
The defense slave device acts as an intermediary component between the master device and the address space. It intercepts access requests, analyzes them for scanning patterns, and mediates the response by either granting legitimate access or blocking malicious scanning attempts. This intermediary layer protects the system without completely preventing debugging and configuration operations.
2Difficulty of detecting and measuring
If comprehensive monitoring of all address accesses is implemented, then security detection capability is improved, but device complexity increases
Solution Approach 1:
The patent applies local quality by implementing monitoring only for specific address ranges that are likely to be scanned, rather than monitoring the entire address space uniformly. The defense slave device is configured to pay special attention to unused or sensitive address areas, reducing the overall monitoring burden and circuit complexity while maintaining effective detection capability where it is most needed.
Solution Approach 2:
The system implements partial monitoring by focusing on detecting specific scanning patterns rather than analyzing every single access request in detail. The defense slave device uses heuristic methods to identify suspicious access sequences, applying excessive scrutiny only to potentially malicious patterns while allowing legitimate accesses to pass through with minimal processing, thereby balancing detection capability with acceptable complexity.
Data Source
AI summary
A circuit arrangement and method for securing an integrated electronic circuit against scans of an address space, wherein the circuit arrangement has at least one master unit and at least one slave unit interconnected via a bus system for access of the master unit to the slave unit, and addresses are used from an address space that is allocated and used in accordance with functionalities of the integrated electronic circuit, where a defense slave unit is connected to the bus system, access to unused address regions of the address space are forwarded to the defense slave unit, the access is analyzed and evaluated by the defense slave unit and depending on an analysis result and the respective access type, defensive measures are triggered, such that address space scans are interrupted or a potential scan result is rendered useless in a simple manner.


