Instruction Stream Protection Circuitry Using Signature Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing instruction stream protection methods are inadequate as they can only detect irregularities and generate alarms, failing to prevent manipulation of critical system operations and provide continuous protection.

Innovation Solution

A circuitry with a signature memory, signature generator, subunits, protection unit, and decision controller that compares generated signatures with stored signatures to restrict access to subunits, ensuring only valid signatures unlock protected subunits, thereby preventing unauthorized access and ensuring continuous protection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a dedicated software or hardware test is executed to detect irregularities in the instruction stream, then the detection capability is improved, but the system can only generate alarms and cannot prevent manipulation of critical system operations

Engineering Contradiction:
Improvedetection capabilityVSAvoidprevention capability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies preliminary action by executing signature tests continuously during instruction stream execution rather than after potential manipulation occurs. The protection unit preemptively verifies signature validity before allowing critical operations to proceed, preventing manipulation rather than merely detecting it after the fact.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a protection unit as an intermediary component that sits between the instruction stream execution and critical system operations. This mediator verifies signature validity and controls access to critical resources, enabling prevention capability while maintaining detection functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If continuous protection is implemented through hardware-based signature verification, then the prevention capability is improved, but the device complexity increases

Engineering Contradiction:
Improveprevention capabilityVSAvoidhardware complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent merges the signature verification functionality with the existing instruction stream execution architecture. The protection unit is integrated into the hardware pipeline, combining detection and prevention functions within the existing structural framework rather than adding completely separate systems.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The protection unit serves multiple functions: it continuously monitors instruction stream signatures, detects irregularities, prevents manipulation of critical operations, and controls access to protected resources. This multi-functionality reduces the need for separate dedicated components for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If signature tests are executed continuously during instruction stream execution, then the protection coverage is improved, but the performance overhead increases

Engineering Contradiction:
Improveprotection coverageVSAvoidexecution performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements periodic action by executing signature verification at specific points during instruction stream execution rather than continuously at every cycle. The protection unit verifies signatures at critical boundaries and transition points, providing adequate protection coverage while minimizing performance overhead.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS10228945B2Circuitry and method for instruction stream protection
Publication Date: 2019.03.12 INFINEON TECHNOLOGIES AG
  • US10228945B2 patent drawing
  • US10228945B2 patent drawing
  • US10228945B2 patent drawing

AI summary

A circuitry is provided. The circuitry comprises a signature memory having stored thereon a plurality of stored signatures. Moreover, the circuitry comprises a signature generator configured to receive one or more monitored signals, and to generate a generated signature depending on at least one of the one or more monitored signals. Furthermore, the circuitry comprises one or more subunits configured to be accessed depending on at least one of the one or more monitored signals. Moreover, the circuitry comprises a protection unit configured to restrict access on the one or more subunits. Furthermore, the circuitry comprises a decision controller configured to compare the generated signature with a stored signature of the plurality of stored signatures to obtain a comparison result. The protection unit is configured to provide access to one of the one or more subunits depending on the comparison result.