Tamper-Resistant IC Interconnect via Preliminary Attestation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current digital computer systems face challenges in maintaining the confidentiality and integrity of information, particularly in achieving human-scale latencies for digital signature operations, which are essential for secure communication between elements in integrated circuit (IC) devices, given the limited physical security and high interconnect latencies in distributed hardware systems.

Innovation Solution

The method involves configuring an interconnect system for IC devices with a communication plan that enables pairwise attestation data exchange between elements, ensuring data integrity and tamper resistance by combining attestation data from multiple elements, thereby creating a secure network that can detect and respond to security breaches within human-scale latency windows.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If digital signature operations are performed between distributed hardware elements, then security and integrity of information are improved, but interconnect latency increases significantly

Engineering Contradiction:
Improveinformation integrityVSAvoidinterconnect latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary attestation of hardware elements before cryptographic operations. Each element is attested by N-1 other elements in advance, creating a pre-established trust relationship. This preliminary attestation phase occurs separately from the critical cryptographic path, so it does not add latency to signature operations while still ensuring security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The security verification process is segmented into distinct phases: attestation data collection, attestation verification, and cryptographic operation execution. By separating the attestation phase from the cryptographic phase, the system ensures that security verification does not bottleneck the time-critical signature operations.

Inventive Principle:
Principle #1Segmentation

2Reliability

If pairwise attestation communication is implemented between all elements, then tamper resistance is improved, but communication overhead and complexity increase

Engineering Contradiction:
Improvetamper resistanceVSAvoidcommunication plan complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The interconnect system serves multiple functions: it carries both attestation data and normal operational traffic. The same communication infrastructure is used for both security verification and cryptographic operations, eliminating the need for separate dedicated attestation channels and reducing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

Attestation data is copied and distributed to multiple elements rather than requiring direct peer-to-peer verification channels between all pairs. Each element receives attestation data from N-1 other elements through the interconnect, simplifying the communication topology while maintaining comprehensive verification.

Inventive Principle:
Principle #26Copying

3Reliability

If N-1 elements attest each element, then security assurance is improved, but the time required for attestation increases

Engineering Contradiction:
Improvesecurity assuranceVSAvoidattestation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The attestation process is designed to occur continuously in the background during steady-state operation. Rather than performing attestation as a discrete pre-check that blocks operations, elements continuously exchange and verify attestation data, ensuring security verification is always current without adding latency to cryptographic operations.

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

Attestation data is prepared and verified in advance during idle periods or in parallel with other operations. The system ensures attestation is completed before critical operations begin, but the actual verification happens during non-critical time windows, keeping the cryptographic path fast.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10097355B2Tamper resistance of distributed hardware systems
Publication Date: 2018.10.09 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10097355B2 patent drawing
  • US10097355B2 patent drawing
  • US10097355B2 patent drawing

AI summary

Embodiments are directed to an IC device comprising a set of N elements, and an interconnect system for enabling communication between the set of elements. Each element of the set of elements is configured according to a first communication plan to receive attestation data of each other element of the set of elements. Upon receiving the attestation data the element may determine whether each of the received attestation data from the other elements match an attestation pattern as defined in the first communication plan. In case the received attestation data match the first communication plan, the element may determine whether the received attestation data is attested by N−1 elements of the set of elements. In case the attestation data is attested by N−1 elements of the set of elements, the element may indicate the presence of the set of elements before the time interval has lapsed.