Hardware Attack Detection Unit for Single-Chip Intrusion Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing single-chip systems lack an effective intrusion detection system (IDS) that can provide extensive detection options while minimizing performance impact, and traditional software-based IDS solutions introduce additional attack paths and performance losses.

Innovation Solution

A hardware-based attack detection unit is integrated into the single-chip system, connected via hardware signal connections to the input/output control unit, which evaluates input signals against a set of attack detection rules, allowing for secure and performance-minimal intrusion detection and prevention without interacting with other computing units.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a software-based intrusion detection system (IDS) is added to the single-chip system, then intrusion detection capability is improved, but additional attack paths are introduced and system performance deteriorates

Engineering Contradiction:
Improveintrusion detection capabilityVSAvoidadditional attack paths
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent replaces the software-based IDS with a hardware-based attack detection unit that is integrated into the single-chip system. This hardware unit operates independently from the computing units and evaluates input signals directly at the hardware level, eliminating the need for additional software layers that would create attack paths. The hardware implementation provides intrusion detection capability while maintaining system security and performance.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If a software-based intrusion detection system (IDS) is added to the single-chip system, then intrusion detection capability is improved, but system performance deteriorates due to computing power consumption

Engineering Contradiction:
Improveintrusion detection capabilityVSAvoidsystem performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent replaces the computationally intensive software-based IDS with a dedicated hardware attack detection unit. This hardware unit processes input signals directly through hardware logic circuits, eliminating the need for software computation and associated performance overhead. The hardware implementation provides real-time intrusion detection without consuming computing power from the main processing units, thus preserving system performance.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If hardware-based security separation mechanisms are implemented, then security between subsystems is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity separationVSAvoidhardware mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a unified attack detection unit that serves multiple security functions simultaneously. This single hardware component evaluates input signals from multiple sources, detects various types of attacks, and provides security for the entire single-chip system. The attack detection unit is integrated with the existing input/output control unit and memory access control unit, sharing hardware resources and avoiding the need for separate security mechanisms for each subsystem, thus reducing overall complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20240028773A1Single-chip system, method for operating a single-chip system, and motor vehicle
Publication Date: 2024.01.25 AUDI AG
  • US20240028773A1 patent drawing
  • US20240028773A1 patent drawing

AI summary

Single-chip system, having multiple computing units, in particular computer cores and/or CPUs, at least one input/output unit, a memory unit, and an input/output control unit that coordinates the communication between the computing units and the at least one input/output unit, wherein the single-chip system further has an attack detection unit, produced as hardware, that is connected by means of a hardware signal connection to at least the input/output control unit as a component of the single-chip system and evaluates input signals received from the input/output control unit for a rule infringement in a set of attack detection rules, which rule infringement needs to be logged and/or responded to with at least one measure.