Fault Injection Trigger Timing via Crypto Signals

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing fault injection attack methods face practical difficulties in setting an artificial trigger at the precise point in time for a specific operation, especially when dealing with complete product encryption equipment, as code revision is not a feasible solution.

Innovation Solution

A fault injection attack method that determines a trigger start point based on an input signal and an end point based on an output signal for a crypto device, allowing for a fault injection attack without code modification, using input/output signals to set the trigger and specifying the target operation through electromagnetic trace analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If an artificial trigger is set at a specific operation point in time, then the precision of fault injection timing is improved, but the complexity of code modification increases

Engineering Contradiction:
Improvefault injection timing precisionVSAvoidcode modification complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent uses input and output signals as intermediary elements to establish trigger timing without direct code modification. The trigger start point is determined based on an input signal for the crypto device, and the trigger end point is determined based on an output signal of the crypto device. This mediator approach allows precise timing control while avoiding the complexity of modifying the target device's code.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If code revision is performed to set an artificial trigger, then the accuracy of trigger positioning is improved, but the ease of operation deteriorates

Engineering Contradiction:
Improvetrigger positioning accuracyVSAvoidtrigger setting ease
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The system uses the crypto device's own input and output signals to automatically determine trigger timing points. The processor determines the trigger start point based on the input signal and the trigger end point based on the output signal, allowing the target device to serve itself for timing reference without requiring external code modification or complex setup procedures.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If a relaxed trigger setting is applied, then the ease of operation is improved, but the precision of fault injection timing deteriorates

Engineering Contradiction:
Improvetrigger setting easeVSAvoidfault injection timing precision
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The patent replaces the mechanical/code-based trigger setting system with a signal-based electronic timing system. By using the crypto device's input and output signals to determine trigger points, the system achieves both ease of operation (no code modification needed) and precise timing (based on actual signal transitions), effectively substituting a more flexible electronic control mechanism for the rigid code-based approach.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS12019738B2Fault injection attack system
Publication Date: 2024.06.25 KOOKMIN UNIV IND ACAD COOP FOUND
  • US12019738B2 patent drawing
  • US12019738B2 patent drawing
  • US12019738B2 patent drawing

AI summary

Disclosed is a fault injection attack method including determining a trigger start point in time based on an input signal for a crypto device; determining a trigger end point in time based on an output signal of the crypto device; setting a trigger based on the trigger start point in time and the trigger end point in time; and performing a fault injection attack based on the set trigger.