Malicious Component Detection Circuit Using Event Counters

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The complexity of modern integrated circuit designs and the lack of control during contract manufacturing make it difficult to detect malicious components like Hardware Trojans, which can be activated later, posing a risk of data theft or system damage.

Innovation Solution

A data processing system incorporating a detection circuit with event counters and a machine learning analysis block that monitors internal states in real-time, using models like support vector machines or neural networks to identify abnormal behavior and flag potential malicious activity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If contract manufacturing is used to fabricate IC devices, then manufacturing efficiency and cost are improved, but the ability to detect malicious components during fabrication is lost

Engineering Contradiction:
Improvemanufacturing efficiencyVSAvoiddetection capability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies preliminary action by inserting a detection circuit into the IC design before the contract manufacturing process. This detection circuit is pre-configured to monitor for malicious components during operation, allowing the IC manufacturer to maintain control and detection capability even when using contract manufacturing without direct fabrication control.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If IC designs become more complex, then functionality and performance are improved, but the difficulty of detecting malicious components increases

Engineering Contradiction:
ImprovefunctionalityVSAvoiddetection difficulty
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent applies segmentation by dividing the detection function into a separate, dedicated detection circuit that operates independently from the main IC functionality. This detection circuit segments the monitoring task from the complex IC operations, making it easier to detect malicious components even as the overall IC design becomes more complex and versatile.

Inventive Principle:
Principle #1Segmentation

3Object-affected harmful factors

If malicious components are activated later, then stealth and avoidance of detection during manufacturing are improved, but the risk of data theft or system damage increases

Engineering Contradiction:
Improvestealth capabilityVSAvoiddata theft risk
Core Design Contradiction:
Object-affected harmful factorsVSObject-generated harmful factors

Solution Approach 1:

The patent applies feedback by implementing a continuous monitoring mechanism where the detection circuit receives feedback signals from various IC operations and compares them against expected behavior patterns. This feedback loop enables the system to detect activated malicious components in real-time, even when they activate after manufacturing, thereby reducing the risk of data theft or system damage.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11914703B2Method and data processing system for detecting a malicious component on an integrated circuit
Publication Date: 2024.02.27 NXP BV
  • US11914703B2 patent drawing
  • US11914703B2 patent drawing

AI summary

A method and data processing system are provided for detecting a malicious component in a data processing system. The malicious component may be of any type, such as a hardware trojan, malware, or ransomware. In the method, a plurality of counters is used to count events in the data processing system during operation, where each event has a counter associated therewith. A machine learning model is trained a normal pattern of behavior of the data processing system using the event counts. After training, an operation of the data processing system is monitored using the machine learning model. Current occurrences of events in the data processing system are compared to the normal pattern of behavior. If a different pattern of behavior is detected, an indication, such as a flag, of the different pattern of behavior is provided.