Hardware Design Side-Channel Vulnerability Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for detecting physical side-channel attack vulnerabilities in electronic devices are inefficient, as they require post-silicon changes, which are costly and often impossible to implement, and pre-silicon estimates of side-channel leakage are computationally expensive and slow.
Innovation Solution
The use of information flow analysis to filter out irrelevant signals and time windows, combined with simulated physical characteristics, reduces the complexity of side-channel leakage detection, allowing for precise identification of vulnerabilities before silicon fabrication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If pre-silicon estimation of side-channel leakage is performed using full physical simulation, then detection capability is improved, but computational cost and time increase significantly
Solution Approach 1:
The patent segments the hardware design into distinct modules or components, and performs information flow analysis at the module level rather than simulating the entire system. This divides the computational task into smaller, manageable segments that can be analyzed independently, reducing overall computational complexity while maintaining detection accuracy for side-channel vulnerabilities.
Solution Approach 2:
The patent extracts and analyzes only the specific signals and data flows that are relevant to side-channel leakage, rather than simulating all physical characteristics of the hardware. By taking out only the critical information flows that could lead to leakage, the system achieves accurate vulnerability detection without the prohibitive computational cost of full-system physical simulation.
2Measurement precision
If full hardware simulation is performed to detect PSCA vulnerabilities, then detection accuracy is improved, but computation time increases by orders of magnitude
Solution Approach 1:
The patent performs information flow analysis as a preliminary step before full physical simulation. This preliminary analysis identifies and filters out signals that cannot possibly lead to side-channel leakage, preparing a reduced dataset that can then be analyzed more quickly. This preliminary filtering action significantly reduces the time required for subsequent detailed analysis while maintaining detection accuracy.
Solution Approach 2:
The patent applies partial action by performing information flow analysis on only the critical paths and signals that are most likely to exhibit side-channel behavior, rather than analyzing all signals in the system. This selective partial analysis achieves sufficient detection accuracy for the most vulnerable components without the excessive computational time required for complete system simulation.
3Reliability
If design changes are made post-silicon to mitigate vulnerabilities, then security is improved, but manufacturing cost increases significantly
Solution Approach 1:
The patent enables side-channel vulnerability detection to be performed during the design phase, allowing security issues to be identified and mitigated before silicon fabrication. This preliminary detection and correction action prevents the need for costly post-silicon design changes, thereby improving security reliability while avoiding increased manufacturing costs associated with late-stage modifications.
Data Source
AI summary
Methods, systems, and apparatus, including computer programs encoded on computer storage media, for analyzing hardware designs for vulnerabilities to side-channel attacks. One of the methods includes receiving a request to analyze a device hardware design for side-channel vulnerabilities in the device after being manufactured. Physical characteristics data is obtained representing one or more physical characteristics of the device based on the device hardware design. Information flow analysis is performed to identify one or more signals of interest corresponding to digital assets. From the physical characteristics data and the one or more signals of interest, data representing potentially vulnerable signals in the device hardware design is generated. A leakage model is generated for the potentially vulnerable signals that quantifies one or more leakage criteria for one or more structures of the device hardware design.


