Intrusion Detection for Integrated Circuits via Bus Supervision

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Integrated circuits face vulnerabilities due to scan chain attacks, where attackers can access sensitive information by exploiting scan tests, making it difficult to distinguish between legitimate and illegitimate access attempts, especially in complex systems like automotive networks with insufficient test coverage.

Innovation Solution

A system and apparatus for intrusion detection in integrated circuits that monitor data traffic on a wired communications bus, differentiate between legitimate and illegitimate scan tests, and perform security actions to mitigate unauthorized access, utilizing a watchdog chipset to supervise data patterns and an action-responsive chipset to respond to suspicious activities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If scan tests are implemented to test integrated circuits, then test coverage and fault detection capability are improved, but security vulnerability increases due to potential illegitimate access

Engineering Contradiction:
Improvetest coverageVSAvoidsecurity vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a supervisory circuit as an intermediary component that monitors scan test operations. This circuit intercepts and analyzes scan test traffic between the test controller and the device under test, detecting illegitimate access attempts while allowing legitimate tests to proceed. The supervisory circuit acts as a mediator that adds security oversight without preventing authorized scan test functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms where the supervisory circuit continuously monitors scan test operations and provides real-time security status information. When illegitimate access is detected, the system responds by alerting authorized personnel or taking corrective actions. This feedback loop enables dynamic security adjustment while maintaining test functionality.

Inventive Principle:
Principle #23Feedback

2Reliability

If scan tests are performed in the field after manufacturing, then test coverage for field conditions is improved, but risk of illegitimate access during operational mode increases

Engineering Contradiction:
Improvefield test coverageVSAvoidillegitimate access risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements dynamic mode switching capability that allows the integrated circuit to transition between operational mode and scan test mode. The supervisory circuit dynamically monitors and controls these transitions, ensuring that scan tests can be performed in the field when needed while preventing illegitimate access attempts. The system adaptively adjusts its security posture based on the current operational context.

Inventive Principle:
Principle #15Dynamics

3Measurement precision

If intermediate results are stored in scan chains for testing, then test observability is improved, but attackers can retrieve cryptographic secrets through differential analysis

Engineering Contradiction:
Improvetest observabilityVSAvoidcryptographic secret exposure
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The supervisory circuit serves as an intermediary that monitors data flowing through scan chains. It can detect when intermediate results containing cryptographic information are being shifted out and prevent illegitimate retrieval. The supervisory circuit analyzes the data stream to identify patterns consistent with secret extraction attempts while allowing legitimate test observations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10853485B2Intrusion detection for integrated circuits
Publication Date: 2020.12.01 NXP BV
  • US10853485B2 patent drawing
  • US10853485B2 patent drawing
  • US10853485B2 patent drawing

AI summary

Certain aspects of the disclosure are directed to methods and apparatuses of intrusion detection for integrated circuits. An example apparatus can include a wired communications bus configured and arranged to carry data and a plurality of integrated circuits. The plurality of integrated circuits can include a first integrated circuit configured and arranged to operate in a scan mode during which the first integrated circuit performs a scan test to detect one or more faults in circuitry of the plurality of integrated circuits. The plurality of integrated circuits can further include a second integrated circuit configured and arranged to operate in a mission mode and supervise data traffic by monitoring communications including data patterns and accesses on the wired communications bus. In response to identifying a suspected illegitimate access, the second integrated circuit can perform a security action to mitigate a suspect illegitimate action in the plurality of integrated circuits.