Glitch Resistant Integrated Circuit Security via Multi-Bit Key Activation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for protecting integrated circuits from unauthorized access and piracy lack robustness, as they can be vulnerable to glitches that allow attackers to load malicious code, compromising the security of the device.

Innovation Solution

A system utilizing a combination circuit activated by a hardware enabling key with a large number of bits, where each bit must be set correctly for the circuit to function correctly, and employing cryptographic functions like hash and decryption to ensure secure operations, with no intermediate or output bits determining the circuit's functionality, thereby preventing unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a hardware enabling key with a large number of bits is used to activate the combination circuit, then the security and reliability of the device is improved, but the device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security key is segmented into a large number of individual bits (at least 64 bits), where each bit independently controls a portion of the combination circuit's functionality. This segmentation ensures that the circuit only operates correctly when all bits are set to their correct values, providing robust security while distributing the complexity across multiple simple binary decisions rather than a single complex control mechanism.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The invention changes the parameter of key length to at least 64 bits, transforming the security mechanism from a simpler activation method to a highly secure multi-bit key system. This parameter change significantly increases the difficulty of unauthorized activation while maintaining a relatively simple circuit structure that just needs to check each bit's state.

Inventive Principle:
Principle #35Parameter changes

2Ease of operation

If intermediate or output bits derived from the key are used to determine circuit functionality, then the ease of operation is improved, but the security is worsened due to potential glitch vulnerabilities

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The invention extracts and eliminates intermediate or output bits that could be derived from the key bits, ensuring that no such bits exist that could determine the combination circuit's functionality. This removes potential vulnerability points where glitches could exploit intermediate signal states, while still allowing the circuit to be operated securely through the complete key bit verification process.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The invention converts the potential harm of having intermediate bits (which could be exploited by glitches) into a benefit by explicitly designing the system so that no such intermediate bits exist. The security mechanism benefits from this constraint, as it eliminates attack vectors while the circuit maintains its intended functionality through direct key bit verification.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

3Reliability

If cryptographic functions like hash and decryption are employed, then the security is improved, but the use of energy and computational resources increases

Engineering Contradiction:
ImprovesecurityVSAvoiduse of energy
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The cryptographic functions (hash and decryption) are performed in advance during the key generation and loading process, rather than during every operation of the combination circuit. The decrypted key is then stored in the key register for subsequent use, eliminating the need for repeated cryptographic computations during normal circuit operation and significantly reducing energy consumption during actual use.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9158901B2Glitch resistant device
Publication Date: 2015.10.13 CISCO TECHNOLOGY INC
  • US9158901B2 patent drawing
  • US9158901B2 patent drawing
  • US9158901B2 patent drawing

AI summary

A system and method for device security is described, the system and method including at least one integrated circuit including a CPU, a key register storing a hardware enabling key, the key including a large number of bits, such that each bit of the large number of bits has a correct value, and if any one bit of the large number of bits is set to an incorrect value the key will not function correctly a combination circuit for performing a function, ƒ, the function ƒ being essential for correct functionality of the CPU, such that the combination circuit is activated by the key, the combination circuit only performing function ƒ if each of the large number of bits of the key is set to the correct value, and there exists no set of intermediate or output bits derived from the large number of bits of the key, which determine if the combination circuit performs function ƒ, the set intermediate or output bits including fewer bits than are included in the key. Related apparatus, methods, and systems are also described.