ECU Authentication Timing Randomization for Glitch Attack Prevention
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods to counter glitch attacks, such as using voltage or clock sensors, require hardware changes and do not prevent attacks, while duplicating authentication processes increase communication time, necessitating a solution that prevents glitch attacks without altering hardware or communication time.
Innovation Solution
An electronic control unit that acquires an authentication request and randomly determines the timing for executing the authentication process, ensuring the authentication process is not skipped even under glitch attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If voltage sensor or clock sensor is mounted to detect glitch attacks, then detection capability is improved, but hardware complexity and cost increase
Solution Approach 1:
The patent extracts the detection function from hardware sensors and relocates it to software-based timing randomization. Instead of adding physical sensors to detect glitches, the system uses software logic to randomize authentication timing, making glitch attacks ineffective without requiring additional hardware components.
Solution Approach 2:
The patent replaces the mechanical/hardware approach (voltage sensors, clock sensors) with a software-based approach (timing randomization algorithm). This substitution eliminates the need for additional hardware while achieving the same security objective of preventing glitch attacks.
2Reliability
If authentication process is duplicated to prevent glitch attacks, then security is improved, but communication time increases
Solution Approach 1:
The patent applies dynamics by making the authentication timing random and unpredictable rather than fixed or duplicated. The authentication process executes once but at a randomly determined time, creating dynamic timing variation that prevents glitch attacks without requiring multiple authentication cycles.
Solution Approach 2:
The patent changes the timing parameter of authentication execution from predictable to random. Instead of duplicating the authentication process multiple times, the system varies the timing parameter randomly, which effectively prevents timing-based attacks while maintaining single-pass authentication efficiency.
3Productivity
If fixed timing authentication is used, then communication efficiency is improved, but vulnerability to glitch attacks increases
Solution Approach 1:
The patent introduces asymmetry in timing by using random timing rather than symmetric or fixed timing patterns. This asymmetric timing approach breaks the predictability that glitch attacks rely upon, while maintaining the efficiency of single-pass authentication.
Data Source
AI summary
By an electronic control unit, an electronic control system, an authentication method, a non-transitory computer-readable storage medium storing an authentication program, an authentication request is acquired from a different device, a timing of execution of an authentication process according to the authentication request is randomly determined, the authentication process is executed at the determined timing determined.


