Dynamic Fault Injection Detection Sensitivity Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional security systems are inadequate in effectively managing fault injection attacks, as they often result in high false positives and inconsistent security levels, failing to dynamically adjust sensitivity based on real-time CPU execution flow.

Innovation Solution

A security system that dynamically adjusts fault injection countermeasure sensitivity levels in real-time based on CPU execution flow, using a processor core to generate output indications of upcoming instructions and a sensitivity level control module to select appropriate sensitivity levels, thereby reducing false alarms and enhancing security without affecting availability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional security systems use fixed sensitivity levels for fault injection detection, then security coverage is maintained, but false positive rates increase and security consistency deteriorates

Engineering Contradiction:
Improvesecurity consistencyVSAvoiddetection accuracy
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent implements dynamic sensitivity level adjustment by monitoring CPU execution flow and transitioning between security states (first, second, and third sensitivity levels) based on detected instruction patterns. The system switches from a first sensitivity level during normal execution to a second higher sensitivity level when specific instruction sequences are detected, and to a third level during cryptographic operations, thereby adapting security detection to real-time execution context and reducing false positives while maintaining consistent security coverage.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the sensitivity parameter of the fault injection detector based on the detected CPU execution state. By transitioning between multiple sensitivity levels (first, second, third levels) corresponding to different security states, the system optimizes detection accuracy for different operational contexts, resolving the contradiction between maintaining security consistency and avoiding false positives.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If sensitivity levels are increased to detect more fault injection attacks, then security improvement is achieved, but false alarm rates increase

Engineering Contradiction:
Improvesecurity levelVSAvoidfalse alarms
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The patent applies different sensitivity levels to different operational contexts by analyzing CPU execution flow. The system uses local quality by assigning higher sensitivity (second or third levels) only to specific critical instruction sequences and cryptographic operations, while maintaining lower sensitivity (first level) for normal execution, thereby improving security where needed without generating false alarms during routine operations.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically adjusts sensitivity levels based on real-time CPU state monitoring. By transitioning between sensitivity levels according to detected instruction patterns and security states, the system achieves high security levels during critical operations while minimizing false alarms during normal execution, effectively resolving the contradiction between security improvement and false alarm reduction.

Inventive Principle:
Principle #15Dynamics

3Reliability

If security monitoring is continuous at high sensitivity, then fault injection detection capability is improved, but system availability and usability decrease

Engineering Contradiction:
Improvefault detection capabilityVSAvoidsystem availability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system implements periodic transitions between different sensitivity levels based on CPU execution flow analysis. Rather than maintaining continuous high sensitivity, the system periodically switches to higher sensitivity levels (second or third states) only when specific instruction sequences or cryptographic operations are detected, and returns to lower sensitivity (first state) during normal execution, thereby maintaining fault detection capability while preserving system availability and usability.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The dynamic adjustment of sensitivity levels based on CPU execution state allows the system to maintain high fault detection capability during critical operations while reducing monitoring intensity during normal execution. This dynamic approach resolves the contradiction by adapting security monitoring to actual system needs, ensuring availability and usability are not compromised by continuous high-sensitivity monitoring.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12182260B2System and method for detecting fault injection attacks
Publication Date: 2024.12.31 NUVOTON
  • US12182260B2 patent drawing
  • US12182260B2 patent drawing
  • US12182260B2 patent drawing

AI summary

A security system configured for deployment on a chip which is to be protected, the system comprising fault injection detection subsystem/s configured for deployment on the chip, each fault injection detection subsystem having plural sensitivity levels which are selectable in real time and comprising at least one hardware fault injection detector circuit/s, configured for deployment on the chip, and/or, coupled thereto, sensitivity level control logic which may be configured for deployment on the chip and which may be operative, in real time, to transition the fault injection detection subsystem, from its current sensitivity level from among said plural selectable sensitivity levels, to a next sensitivity level from among said plural selectable sensitivity levels, e.g. by generating sensitivity control signals (aka sensitivity level selections) and/or feeding the sensitivity control signals to at least one hardware fault injection detector in the subsystem.