Hardware Security Module Selective Debugging Activation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Debugging computer programs in hardware security modules is challenging due to discrepancies between development and runtime environments, leading to imperfect emulation and increased debugging costs, as these modules have limited resources and security features that restrict information disclosure.

Innovation Solution

Incorporating debugging instructions into compiled programs that can be inhibited or activated within the hardware security module, allowing for precise debugging under production conditions without affecting performance, and enabling secure transmission of debugging information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If debugging instructions are incorporated into compiled programs for precise debugging under production conditions, then debugging accuracy is improved, but program execution time increases

Engineering Contradiction:
Improvedebugging accuracyVSAvoidprogram execution time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent applies dynamics by making the debugging instructions switchable between active and inactive states. A control mechanism allows the debugging mode to be dynamically changed based on operational requirements, enabling the system to transition between precise debugging mode and optimized execution mode seamlessly.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameter of instruction execution by introducing a control flag or configuration parameter that determines whether debugging instructions are executed. By modifying this parameter (activating or deactivating debugging mode), the system can adjust between high accuracy debugging and fast execution without changing the fundamental program structure.

Inventive Principle:
Principle #35Parameter changes

2Ease of operation

If debugging instructions are activated in hardware security modules with security features, then debugging capability is improved, but security protection is weakened

Engineering Contradiction:
Improvedebugging capabilityVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent segments the program execution into distinct debugging paths and normal operation paths. Debugging instructions are isolated in specific segments that can be selectively executed, allowing debugging capability to be activated without compromising the overall security architecture when debugging is not in use.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system dynamically switches between debugging mode and secure operation mode. When debugging is deactivated, the control mechanism ensures that debugging instructions are not executed, maintaining full security protection. This dynamic state change allows the same hardware to serve both debugging and secure operation requirements.

Inventive Principle:
Principle #15Dynamics

3Reliability

If hardware security modules use limited system resources for security functions, then security performance is improved, but debugging capability is reduced

Engineering Contradiction:
Improvesecurity performanceVSAvoiddebugging capability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements multi-functionality by designing the hardware security module to perform both secure operation and debugging functions using the same limited resources. The control mechanism enables the system to switch between these functions, allowing the limited resources to serve dual purposes without requiring separate dedicated hardware for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system changes operational parameters to enable debugging with limited resources. By adjusting execution parameters and controlling instruction selection, the module can perform debugging operations that leverage existing hardware resources efficiently, rather than requiring additional dedicated debugging hardware.

Inventive Principle:
Principle #35Parameter changes

4Measurement precision

If emulators are used to reproduce runtime environment for debugging, then debugging accuracy is improved, but emulation complexity increases

Engineering Contradiction:
Improvedebugging accuracyVSAvoidemulation complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent uses copying by incorporating debugging instructions directly into the compiled program that will be executed on the actual hardware. Instead of copying and creating complex emulators to simulate the runtime environment, the debugging capabilities are embedded in the program itself, simplifying the overall system architecture while maintaining debugging accuracy.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS9323646B2Hardware security module with means to selectively activate or inhibit debugging and corresponding debugging method
Publication Date: 2016.04.26 IDEMIA FRANCE SAS
  • US9323646B2 patent drawing
  • US9323646B2 patent drawing
  • US9323646B2 patent drawing

AI summary

The present invention relates to the field of debugging of compiled programs in a hardware security module such as a microprocessor card. A module according to the invention includes a microprocessor and a compiled program to be executed by the microprocessor in order to carry out an operation. The compiled program includes at least one debugging instruction which whether or not it is executed does not modify the execution of the operation. And, the hardware security module includes an element of inhibiting or activating the debugging instruction during the execution of the compiled program.