Glitch Resistant Integrated Circuit Security via Multi-Bit Key Activation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for protecting integrated circuits from unauthorized access and piracy lack robustness, as they can be vulnerable to glitches that allow attackers to load malicious code, compromising the security of the device.
Innovation Solution
A system utilizing a combination circuit activated by a hardware enabling key with a large number of bits, where each bit must be set correctly for the circuit to function correctly, and employing cryptographic functions like hash and decryption to ensure secure operations, with no intermediate or output bits determining the circuit's functionality, thereby preventing unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a hardware enabling key with a large number of bits is used to activate the combination circuit, then the security and reliability of the device is improved, but the device complexity increases
Solution Approach 1:
The security key is segmented into a large number of individual bits (at least 64 bits), where each bit independently controls a portion of the combination circuit's functionality. This segmentation ensures that the circuit only operates correctly when all bits are set to their correct values, providing robust security while distributing the complexity across multiple simple binary decisions rather than a single complex control mechanism.
Solution Approach 2:
The invention changes the parameter of key length to at least 64 bits, transforming the security mechanism from a simpler activation method to a highly secure multi-bit key system. This parameter change significantly increases the difficulty of unauthorized activation while maintaining a relatively simple circuit structure that just needs to check each bit's state.
2Ease of operation
If intermediate or output bits derived from the key are used to determine circuit functionality, then the ease of operation is improved, but the security is worsened due to potential glitch vulnerabilities
Solution Approach 1:
The invention extracts and eliminates intermediate or output bits that could be derived from the key bits, ensuring that no such bits exist that could determine the combination circuit's functionality. This removes potential vulnerability points where glitches could exploit intermediate signal states, while still allowing the circuit to be operated securely through the complete key bit verification process.
Solution Approach 2:
The invention converts the potential harm of having intermediate bits (which could be exploited by glitches) into a benefit by explicitly designing the system so that no such intermediate bits exist. The security mechanism benefits from this constraint, as it eliminates attack vectors while the circuit maintains its intended functionality through direct key bit verification.
3Reliability
If cryptographic functions like hash and decryption are employed, then the security is improved, but the use of energy and computational resources increases
Solution Approach 1:
The cryptographic functions (hash and decryption) are performed in advance during the key generation and loading process, rather than during every operation of the combination circuit. The decrypted key is then stored in the key register for subsequent use, eliminating the need for repeated cryptographic computations during normal circuit operation and significantly reducing energy consumption during actual use.
Data Source
AI summary
A system and method for device security is described, the system and method including at least one integrated circuit including a CPU, a key register storing a hardware enabling key, the key including a large number of bits, such that each bit of the large number of bits has a correct value, and if any one bit of the large number of bits is set to an incorrect value the key will not function correctly a combination circuit for performing a function, ƒ, the function ƒ being essential for correct functionality of the CPU, such that the combination circuit is activated by the key, the combination circuit only performing function ƒ if each of the large number of bits of the key is set to the correct value, and there exists no set of intermediate or output bits derived from the large number of bits of the key, which determine if the combination circuit performs function ƒ, the set intermediate or output bits including fewer bits than are included in the key. Related apparatus, methods, and systems are also described.


