Integrated Circuit Bootstrap Security Against Electromagnetic Fault Injection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Integrated circuits lack effective protection against electromagnetic fault injection attacks, particularly in the buffers of electronic fuses, which can be exploited by attackers to bypass security measures.

Innovation Solution

Implementing a magnetic field detector and redundant hardware cache mechanisms, including jitter in querying electronic fuses, to enhance defense against electromagnetic fault injection attacks and ensure secure bootstrap processes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If electronic fuses are used to store security information for secure bootstrap, then security protection is improved, but the system becomes vulnerable to electromagnetic fault injection attacks

Engineering Contradiction:
Improvesecure bootstrapVSAvoidelectromagnetic fault injection
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by performing redundancy checks on fuse values before they are used in the secure bootstrap process. The system reads fuse values multiple times and verifies consistency beforehand, so that if an electromagnetic fault injection occurs during a read operation, the inconsistency is detected and the system can respond appropriately (e.g., abort the bootstrap or enter a secure state), thereby preventing the attack from succeeding.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies copying by creating redundant copies of critical fuse values in volatile memory during the bootstrap process. Instead of relying on a single read operation, the system copies the fuse values multiple times and compares them to detect electromagnetic fault injection attacks. This copying mechanism allows the system to identify and reject tampered values, thus protecting against the harmful factor while maintaining the security function.

Inventive Principle:
Principle #26Copying

2Reliability

If fuse values are read multiple times for redundancy checks, then protection against electromagnetic fault injection is improved, but the bootstrap process time increases

Engineering Contradiction:
Improveprotection against electromagnetic fault injectionVSAvoidbootstrap process time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies partial or excessive action by performing a limited number of redundancy checks (exactly two reads and comparisons) rather than continuous monitoring. This provides sufficient protection against electromagnetic fault injection attacks while keeping the time overhead acceptable. The system performs the minimum necessary redundancy operations to detect attacks without excessive delay to the bootstrap process.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If security information is stored in non-volatile memory like electronic fuses, then protection against manipulation is improved, but reading the information becomes complicated and slow

Engineering Contradiction:
Improveprotection against manipulationVSAvoidreading speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies preliminary action by reading and verifying fuse values early in the bootstrap process before any critical operations occur. The system performs the redundant reads and comparisons as the first step, establishing security before proceeding with firmware execution. This approach accepts the time cost of slow non-volatile memory reads but ensures that security verification is completed before any potentially vulnerable operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies intermediary by using volatile memory as a temporary buffer to store copied fuse values during the verification process. The volatile memory provides fast read access for the redundancy checks, mediating between the slow non-volatile fuse storage and the fast processing requirements of the bootstrap verification. This allows the system to maintain the security benefits of non-volatile storage while reducing the impact of read speed limitations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

The solution significantly improves defense against electromagnetic fault injection attacks by detecting and mitigating such threats, ensuring the secure execution of firmware and protection of security information during the bootstrap process.

Implementation Method 1

The implementation of a magnetic field detector is additionally appropriate: the magnetic field used for an attack is relatively strong and may be detected with high reliability.

Methodology Applied
Scientific EffectMagnetic field detection: Magnetic Field

Data Source

PatentUS11520892B2Integrated circuit and embedded system including such an integrated circuit with bootstrap configuration for attack prevention
Publication Date: 2022.12.06 ROBERT BOSCH GMBH
  • US11520892B2 patent drawing

AI summary

An integrated circuit including an electronic fuse for supporting a secure bootstrap process, in which the fuse is queried. The circuit includes a protection against electromagnetic fault injection. The circuit is configured in such a way that the protection extends to the bootstrap process.