Electronic Device Security Assessment via Hardware Software Metrics

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods fail to provide a comprehensive and quantitative assessment of the security of electronic devices, particularly in mission-critical systems, as they primarily focus on software security, neglecting the importance of hardware security and the potential for faults and malicious attacks on both components.

Innovation Solution

A method and system for assessing the security of electronic devices by performing security tests on both software and hardware, generating metrics for correctness and fault injection tests, and combining these to provide a quantitative indication of the device's overall security, including correctness and security strength metrics for software and hardware.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If security tests are performed only on software, then software security can be assessed, but hardware security vulnerabilities remain undetected

Engineering Contradiction:
Improvesoftware security assessmentVSAvoidoverall device security
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The security assessment is divided into separate software and hardware components. Software security tests and hardware security tests are performed independently, with each component assessed separately before combining results into an overall device security metric.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The security testing system is designed to perform multiple functions: it can test software components, test hardware components (including integrated circuit designs), and generate comprehensive security metrics that combine both software and hardware assessments into a unified evaluation framework.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If comprehensive security tests are performed on both software and hardware, then overall device security can be assessed, but testing time and complexity increase

Engineering Contradiction:
Improveoverall device securityVSAvoidtesting time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Security tests are performed on the integrated circuit hardware design before the device is manufactured and deployed. This preliminary assessment allows security vulnerabilities to be identified and addressed in the design phase, preventing costly recalls or security patches later.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system generates quantitative security metrics that transform qualitative security assessments into measurable parameters. These metrics allow for efficient comparison and evaluation of different device configurations without requiring exhaustive re-testing.

Inventive Principle:
Principle #35Parameter changes

3Manufacturing precision

If formal verification is performed on integrated circuit hardware design, then hardware correctness can be ensured, but computational resources and time are consumed

Engineering Contradiction:
Improvehardware correctnessVSAvoidcomputational resources
Core Design Contradiction:
Manufacturing precisionVSUse of energy by moving object

Solution Approach 1:

Rather than performing exhaustive formal verification on the entire hardware design, the system applies formal verification to critical security-relevant portions of the integrated circuit design. This partial verification approach provides sufficient security assurance while consuming manageable computational resources.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20220405399A1Methods and Systems for Measuring the Security of an Electronic Device Comprising Hardware and Software
Publication Date: 2022.12.22 IMAGINATION TECH LTD
  • US20220405399A1 patent drawing
  • US20220405399A1 patent drawing
  • US20220405399A1 patent drawing

AI summary

A method of assessing the security of an electronic device comprising software and hardware. The method includes: performing one or more security tests on the software; generating one or more software security metrics based on results of the one or more security tests performed on the software; performing one or more security tests on an integrated circuit hardware design for the hardware; generating one or more hardware security metrics based on results of the one or more security tests performed on the integrated circuit hardware design; and generating one or more electronic device security metrics based on the one or more hardware security metrics and the one or more software security metrics, the one or more electronic device security metrics providing a quantitative indication of the security of the electronic device