Integrated Circuit Key Register Protection Against Unauthorized Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Integrated circuits such as ASICs and FPGAs are vulnerable to unauthorized access during their start-up phase, as security functions are not activated until after initialization, leaving them susceptible to hacker attacks and data manipulation.

Innovation Solution

A method that compares the data word used for writing access to key registers with predefined key data, marking unauthorized access and triggering defensive measures, including immediate activation of security functions and resetting the circuit to a defined initial state, to prevent unauthorized access and protect against hacker attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security functions are activated only after initialization, then the integrated circuit can complete startup and initialization processes, but the circuit is vulnerable to unauthorized access and hacker attacks during the start-up phase

Engineering Contradiction:
Improvesecurity protectionVSAvoidunauthorized access vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary security monitoring by comparing data words against predefined key data before security functions are fully activated. This preliminary action detects unauthorized access attempts during the vulnerable start-up phase before formal security measures are in place, allowing the system to switch on security functions immediately upon detecting an attack.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If data word comparison with predefined key data is performed during write access to key registers, then unauthorized access attempts can be detected, but additional processing time and complexity are introduced

Engineering Contradiction:
Improvedetection capabilityVSAvoidaccess control mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs self-service security monitoring by automatically comparing data words written to key registers against predefined key data stored in the system. This self-service mechanism detects unauthorized access attempts without requiring external monitoring infrastructure, and automatically triggers security function activation or circuit reset upon detecting attacks.

Inventive Principle:
Principle #25Self-service

3Reliability

If security functions are activated immediately upon detecting unauthorized access, then the circuit can be protected from further attacks, but normal startup processes may be interrupted

Engineering Contradiction:
Improvesecurity responseVSAvoidstartup efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements feedback-based security response where unauthorized access attempts are monitored and analyzed, and security functions are activated based on the analysis results. The system uses feedback from the comparison process to determine when to activate security measures, balancing security needs with normal operation by only activating security functions when actual attacks are detected rather than activating them preemptively.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3036676B1Method for protecting an integrated circuit against unauthorized access
Publication Date: 2021.07.14 SIEMENS AG OESTERR
  • EP3036676B1 patent drawingFigure 1

AI summary

The invention relates in general to the field of logic circuits, in particular integrated, electronic circuits such as application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or a one-chip system. Specifically, the invention relates to a method for protecting an integrated circuit against unauthorized access to key registers. Functions and/or applications of the integrated circuit are unlocked and/or activated by means of data stored in said key registers, for example during the start-up of the integrated circuit and/or during ongoing operation. If such a key register is accessed (2), a data word used is compared with specified key data (3). If access by means of a data word deviating from the specified key data is detected (4), said access is marked as unauthorized (6). Access marked as unauthorized is then recorded and evaluated (7). After an analysis, appropriate protective measures are triggered (8) in order to prevent further unauthorized access. By means of the method according to the invention, a key register method for protecting sensitive data is expanded in a simple manner and hacker attacks are quickly detected and thwarted.