Microcontroller Security Domain Fault Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Microcontrollers lack effective security measures against fault attacks, such as clock manipulation and supply voltage fluctuations, which can lead to incorrect actions like opening debug interfaces or accepting wrong signatures, and current solutions are either too expensive or impractical.
Innovation Solution
The integration of a safety domain within the microcontroller that includes sensors to detect faults and alarm signals, which are then communicated to a security domain to initiate secure operations, such as locking cryptographic keys or resetting security settings.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If better or faster sensors are used to detect faults in real-time, then security against fault attacks is improved, but cost increases
Solution Approach 1:
The patent introduces a safety domain as an intermediary component that monitors faults and communicates with the security domain. This mediator handles the complex sensing and response tasks, allowing the security domain to remain simple and cost-effective while still achieving robust security through the collaborative safety-security domain architecture.
Solution Approach 2:
The microcontroller is segmented into distinct safety domain and security domain components. The safety domain handles fault detection and monitoring, while the security domain handles cryptographic operations and security responses. This segmentation allows each domain to be optimized independently, achieving high security without requiring expensive sensors throughout the entire system.
2Reliability
If redundant implementation of security logic is used to prevent fault attacks, then security is improved, but device complexity increases
Solution Approach 1:
Security logic is segmented between the safety domain (fault detection) and security domain (cryptographic operations). This segmentation avoids redundant implementation of the same security logic while achieving complementary security functions that together provide robust protection against fault attacks.
Solution Approach 2:
The safety domain acts as an intermediary that simplifies the security domain's task by handling fault detection and communication. This reduces the complexity of the security domain while maintaining comprehensive security through the coordinated interaction between domains.
3Reliability
If traditional sensors are used to monitor supply voltage, temperature and clock, then basic monitoring is provided, but response time is too slow to prevent incorrect actions
Solution Approach 1:
The safety domain continuously monitors fault conditions and maintains readiness to detect anomalies. By having the monitoring infrastructure pre-established and continuously active, the system can detect and respond to faults immediately when they occur, rather than relying on slower traditional sensor response mechanisms.
Solution Approach 2:
The safety domain implements continuous feedback monitoring of fault conditions and communicates with the security domain in real-time. This feedback mechanism enables immediate detection and response to faults, with the alarm signal transmission providing rapid feedback that triggers security responses before incorrect actions can occur.
Data Source
AI summary
A device includes a safety domain having a processing unit and a memory and is configured to provide at least one functionality and to implement one more safety measures for detecting faults. The safety domain is configured to transmit at least one alarm signal indicating one or more detected errors in response to detecting the faults. The device further includes a security domain having a processing unit and a memory and is configured to provide cryptographic services and to obtain alarm signals. The security domain is configured to perform security-related operations in a secure state in response to obtaining an alarm signal from the safety domain.


