Dynamic Fault Injection Detection Sensitivity Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security systems are inadequate in protecting against fault injection attacks, as they often result in high false positives and are not dynamically adjustable to changing security risk levels, leading to unnecessary sensitivity across all system operation times.
Innovation Solution
A security system that dynamically adjusts sensitivity levels based on real-time CPU execution flow, using a processor core to generate output indications of upcoming instructions and a sensitivity level control module to select appropriate sensitivity levels, thereby differentially sensitizing fault injection countermeasure circuitry to reduce false alarms and enhance security without affecting availability.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the system maintains high sensitivity levels 100% of the time to detect fault injection attacks, then security level is improved, but false alarm rate increases and system availability deteriorates
Solution Approach 1:
The patent implements dynamic sensitivity adjustment by monitoring CPU execution flow and opcode sequences in real-time. The system transitions from static high sensitivity to dynamic adaptive sensitivity, adjusting the detection threshold based on the current execution context. This resolves the contradiction by making sensitivity a variable parameter that adapts to actual security needs rather than remaining constantly high.
Solution Approach 2:
The system changes the sensitivity parameter dynamically based on execution flow analysis. By analyzing opcodes and execution patterns, the system adjusts the detection threshold parameter in real-time, lowering it during low-risk periods to reduce false alarms and maintaining high security during identified vulnerable execution sequences.
2Device complexity
If the system uses static sensitivity levels for fault injection detection, then device complexity is reduced, but adaptability to changing security risks deteriorates
Solution Approach 1:
The system implements feedback mechanisms by continuously monitoring CPU execution flow and using this information to adjust sensitivity levels. The execution flow monitor provides feedback about current operational context, and this feedback loops back to dynamically adjust detection parameters, enabling adaptability without requiring complex external control systems.
Solution Approach 2:
The detection system performs self-adjustment by analyzing its own operational context through CPU execution flow monitoring. The system serves itself by using its own execution state information to automatically tune its detection sensitivity, eliminating the need for external configuration or complex manual adjustment mechanisms.
3Measurement precision
If the system increases sensitivity during high-risk instructions, then detection precision is improved, but false positive rate worsens when applied uniformly across all instructions
Solution Approach 1:
The patent applies different sensitivity levels to different instruction types and execution contexts. Instead of uniform sensitivity application, the system implements local quality by tailoring detection sensitivity to specific opcodes and execution patterns. High sensitivity is applied locally to identified high-risk instructions while lower sensitivity is used for routine operations, resolving the false positive issue.
Data Source
AI summary
A security system dynamically, depending on processor core execution flow, controls fault injection countermeasure circuitry protect processor core from fault injection attacks. Includes a processor core which, when in use, executes instructions and concurrently, generates, in real time, output indications of instructions to be executed; a fault injection detector having selectable sensitivity levels; and a sensitivity level control module operative, in real time, to receive the output indications, select a next sensitivity level using sensitivity level selection logic which receives the output indications as inputs, and set the fault injection detector to the next sensitivity level, thereby to provide fault injection countermeasure circuitry which is differentially sensitive, when protecting the processor core from fault injection attacks, depending on the output indications of the instructions, and/or avoids false alarms which would result if processor core protection were provided at a sensitivity level unrelated to the output indications of the instructions.


