Parallel Digital Sensor Vectors for IC Perturbation Attack Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing countermeasures against perturbation attacks in integrated circuits are inadequate as they rely on detecting abnormal parameter values using sensors, leading to Boolean alarms that lack interpretability and are incompatible with the fast reaction times required to prevent fault attacks, which can exploit the system within a limited time frame.
Innovation Solution
A device comprising a sensing unit with multiple digital sensors arranged in parallel, providing binary vectors that are analyzed to detect and classify perturbation attacks, using a combination of delay chains and combinatorial cells to determine bit outputs, and an analysis unit that employs machine learning algorithms to differentiate between false and true positives.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If conventional sensor-based detection is used to detect abnormal parameter values, then security monitoring is provided, but the system produces Boolean alarms that lack interpretability and cannot distinguish between false positives and true attacks
Solution Approach 1:
The patent segments the detection system into multiple independent digital sensors (at least two sensors in parallel), each monitoring different parameters or aspects of circuit behavior. This segmentation allows the system to collect multiple binary measurements that can be combined to form a more informative detection signal, enabling differentiation between false positives and true attacks through pattern recognition across multiple sensor outputs.
Solution Approach 2:
The patent transitions from single-dimensional Boolean alarm output to multi-dimensional binary vector output by combining outputs from multiple parallel sensors. This dimensional expansion transforms the detection result from a simple yes/no alarm into a rich binary vector that encodes information about which parameters deviated and by how much, providing interpretability while maintaining detection accuracy.
2Measurement precision
If statistical analysis is used to discriminate between false and true positives, then alarm accuracy is improved, but the reaction time is too slow for fast fault attacks that exploit the system within a limited time frame
Solution Approach 1:
The patent pre-computes and stores lookup tables containing pre-analyzed patterns of sensor outputs corresponding to different attack scenarios and false positive conditions. During operation, the system simply queries these pre-computed tables with the current binary vector, obtaining immediate classification results without performing time-consuming statistical analysis in real-time. This preliminary preparation enables fast reaction to attacks while maintaining high discrimination accuracy.
Solution Approach 2:
The patent replaces the mechanical/statistical analysis process with a digital lookup table query mechanism. Instead of performing iterative statistical computations to discriminate between false positives and true attacks, the system uses pre-computed digital tables that provide instant classification based on the binary sensor vector, achieving both speed and accuracy requirements.
3Device complexity
If a single fault detection approach is used, then the system is simple to implement, but it cannot reliably distinguish between normal variations and actual perturbation attacks
Solution Approach 1:
The patent merges the outputs of multiple parallel digital sensors into a combined binary vector that represents the collective state of all monitored parameters. This merging process integrates information from multiple independent detection channels, allowing the system to distinguish between normal variations (which would not consistently appear across multiple sensors) and actual perturbation attacks (which would manifest as coordinated deviations across multiple parameters), thereby improving reliability while maintaining manageable complexity.
Data Source
AI summary
There is provided a device of protecting an Integrated Circuit from perturbation attacks. The device includes a sensing unit configured to detect a perturbation attack, the sensing unit comprising a set of digital sensors comprising at least two sensors, the sensors being arranged in parallel. Each digital sensor provides a digitized bit output having a binary value, in response to input data, the sensing unit being configured to deliver at least one binary vector comprising a multi-bit value, the multi-bit value comprising at least two bit outputs provided by the set of digital sensors. The sensing device further comprising an analysis unit, the analysis unit being configured to receive at least one binary vector provided by the sensing unit, the analysis unit being configured to detect a perturbation attack from the at least one binary vector.


