Instruction Stream Protection Circuitry Using Signature Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing instruction stream protection methods are inadequate as they can only detect irregularities and generate alarms, failing to prevent manipulation of critical system operations and provide continuous protection.
Innovation Solution
A circuitry with a signature memory, signature generator, subunits, protection unit, and decision controller that compares generated signatures with stored signatures to restrict access to subunits, ensuring only valid signatures unlock protected subunits, thereby preventing unauthorized access and ensuring continuous protection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a dedicated software or hardware test is executed to detect irregularities in the instruction stream, then the detection capability is improved, but the system can only generate alarms and cannot prevent manipulation of critical system operations
Solution Approach 1:
The patent applies preliminary action by executing signature tests continuously during instruction stream execution rather than after potential manipulation occurs. The protection unit preemptively verifies signature validity before allowing critical operations to proceed, preventing manipulation rather than merely detecting it after the fact.
Solution Approach 2:
The patent introduces a protection unit as an intermediary component that sits between the instruction stream execution and critical system operations. This mediator verifies signature validity and controls access to critical resources, enabling prevention capability while maintaining detection functionality.
2Ease of operation
If continuous protection is implemented through hardware-based signature verification, then the prevention capability is improved, but the device complexity increases
Solution Approach 1:
The patent merges the signature verification functionality with the existing instruction stream execution architecture. The protection unit is integrated into the hardware pipeline, combining detection and prevention functions within the existing structural framework rather than adding completely separate systems.
Solution Approach 2:
The protection unit serves multiple functions: it continuously monitors instruction stream signatures, detects irregularities, prevents manipulation of critical operations, and controls access to protected resources. This multi-functionality reduces the need for separate dedicated components for each function.
3Reliability
If signature tests are executed continuously during instruction stream execution, then the protection coverage is improved, but the performance overhead increases
Solution Approach 1:
The patent implements periodic action by executing signature verification at specific points during instruction stream execution rather than continuously at every cycle. The protection unit verifies signatures at critical boundaries and transition points, providing adequate protection coverage while minimizing performance overhead.
Data Source
AI summary
A circuitry is provided. The circuitry comprises a signature memory having stored thereon a plurality of stored signatures. Moreover, the circuitry comprises a signature generator configured to receive one or more monitored signals, and to generate a generated signature depending on at least one of the one or more monitored signals. Furthermore, the circuitry comprises one or more subunits configured to be accessed depending on at least one of the one or more monitored signals. Moreover, the circuitry comprises a protection unit configured to restrict access on the one or more subunits. Furthermore, the circuitry comprises a decision controller configured to compare the generated signature with a stored signature of the plurality of stored signatures to obtain a comparison result. The protection unit is configured to provide access to one of the one or more subunits depending on the comparison result.


