Dynamic Fault Injection Detection Sensitivity Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security systems are inadequate in protecting against fault injection attacks, as they often result in high false positives and are not dynamically adjustable to changing security risk levels, leading to unnecessary sensitivity across all system operation times.

Innovation Solution

A security system that dynamically adjusts sensitivity levels based on real-time CPU execution flow, using a processor core to generate output indications of upcoming instructions and a sensitivity level control module to select appropriate sensitivity levels, thereby differentially sensitizing fault injection countermeasure circuitry to reduce false alarms and enhance security without affecting availability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the system maintains high sensitivity levels 100% of the time to detect fault injection attacks, then security level is improved, but false alarm rate increases and system availability deteriorates

Engineering Contradiction:
Improvesecurity levelVSAvoidsystem availability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements dynamic sensitivity adjustment by monitoring CPU execution flow and opcode sequences in real-time. The system transitions from static high sensitivity to dynamic adaptive sensitivity, adjusting the detection threshold based on the current execution context. This resolves the contradiction by making sensitivity a variable parameter that adapts to actual security needs rather than remaining constantly high.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the sensitivity parameter dynamically based on execution flow analysis. By analyzing opcodes and execution patterns, the system adjusts the detection threshold parameter in real-time, lowering it during low-risk periods to reduce false alarms and maintaining high security during identified vulnerable execution sequences.

Inventive Principle:
Principle #35Parameter changes

2Device complexity

If the system uses static sensitivity levels for fault injection detection, then device complexity is reduced, but adaptability to changing security risks deteriorates

Engineering Contradiction:
Improvedetection system complexityVSAvoidadaptability to security risks
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The system implements feedback mechanisms by continuously monitoring CPU execution flow and using this information to adjust sensitivity levels. The execution flow monitor provides feedback about current operational context, and this feedback loops back to dynamically adjust detection parameters, enabling adaptability without requiring complex external control systems.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The detection system performs self-adjustment by analyzing its own operational context through CPU execution flow monitoring. The system serves itself by using its own execution state information to automatically tune its detection sensitivity, eliminating the need for external configuration or complex manual adjustment mechanisms.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If the system increases sensitivity during high-risk instructions, then detection precision is improved, but false positive rate worsens when applied uniformly across all instructions

Engineering Contradiction:
Improveattack detection precisionVSAvoidfalse alarm rate
Core Design Contradiction:
Measurement precisionVSObject-generated harmful factors

Solution Approach 1:

The patent applies different sensitivity levels to different instruction types and execution contexts. Instead of uniform sensitivity application, the system implements local quality by tailoring detection sensitivity to specific opcodes and execution patterns. High sensitivity is applied locally to identified high-risk instructions while lower sensitivity is used for routine operations, resolving the false positive issue.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10990682B2System and method for coping with fault injection attacks
Publication Date: 2021.04.27 NUVOTON
  • US10990682B2 patent drawing
  • US10990682B2 patent drawing
  • US10990682B2 patent drawing

AI summary

A security system dynamically, depending on processor core execution flow, controls fault injection countermeasure circuitry protect processor core from fault injection attacks. Includes a processor core which, when in use, executes instructions and concurrently, generates, in real time, output indications of instructions to be executed; a fault injection detector having selectable sensitivity levels; and a sensitivity level control module operative, in real time, to receive the output indications, select a next sensitivity level using sensitivity level selection logic which receives the output indications as inputs, and set the fault injection detector to the next sensitivity level, thereby to provide fault injection countermeasure circuitry which is differentially sensitive, when protecting the processor core from fault injection attacks, depending on the output indications of the instructions, and/or avoids false alarms which would result if processor core protection were provided at a sensitivity level unrelated to the output indications of the instructions.