Intrusion Detection for Integrated Circuits via Bus Supervision
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Integrated circuits face vulnerabilities due to scan chain attacks, where attackers can access sensitive information by exploiting scan tests, making it difficult to distinguish between legitimate and illegitimate access attempts, especially in complex systems like automotive networks with insufficient test coverage.
Innovation Solution
A system and apparatus for intrusion detection in integrated circuits that monitor data traffic on a wired communications bus, differentiate between legitimate and illegitimate scan tests, and perform security actions to mitigate unauthorized access, utilizing a watchdog chipset to supervise data patterns and an action-responsive chipset to respond to suspicious activities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If scan tests are implemented to test integrated circuits, then test coverage and fault detection capability are improved, but security vulnerability increases due to potential illegitimate access
Solution Approach 1:
The patent introduces a supervisory circuit as an intermediary component that monitors scan test operations. This circuit intercepts and analyzes scan test traffic between the test controller and the device under test, detecting illegitimate access attempts while allowing legitimate tests to proceed. The supervisory circuit acts as a mediator that adds security oversight without preventing authorized scan test functionality.
Solution Approach 2:
The system implements feedback mechanisms where the supervisory circuit continuously monitors scan test operations and provides real-time security status information. When illegitimate access is detected, the system responds by alerting authorized personnel or taking corrective actions. This feedback loop enables dynamic security adjustment while maintaining test functionality.
2Reliability
If scan tests are performed in the field after manufacturing, then test coverage for field conditions is improved, but risk of illegitimate access during operational mode increases
Solution Approach 1:
The patent implements dynamic mode switching capability that allows the integrated circuit to transition between operational mode and scan test mode. The supervisory circuit dynamically monitors and controls these transitions, ensuring that scan tests can be performed in the field when needed while preventing illegitimate access attempts. The system adaptively adjusts its security posture based on the current operational context.
3Measurement precision
If intermediate results are stored in scan chains for testing, then test observability is improved, but attackers can retrieve cryptographic secrets through differential analysis
Solution Approach 1:
The supervisory circuit serves as an intermediary that monitors data flowing through scan chains. It can detect when intermediate results containing cryptographic information are being shifted out and prevent illegitimate retrieval. The supervisory circuit analyzes the data stream to identify patterns consistent with secret extraction attempts while allowing legitimate test observations.
Data Source
AI summary
Certain aspects of the disclosure are directed to methods and apparatuses of intrusion detection for integrated circuits. An example apparatus can include a wired communications bus configured and arranged to carry data and a plurality of integrated circuits. The plurality of integrated circuits can include a first integrated circuit configured and arranged to operate in a scan mode during which the first integrated circuit performs a scan test to detect one or more faults in circuitry of the plurality of integrated circuits. The plurality of integrated circuits can further include a second integrated circuit configured and arranged to operate in a mission mode and supervise data traffic by monitoring communications including data patterns and accesses on the wired communications bus. In response to identifying a suspected illegitimate access, the second integrated circuit can perform a security action to mitigate a suspect illegitimate action in the plurality of integrated circuits.


