Microcontroller Security Domain Fault Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Microcontrollers lack effective security measures against fault attacks, such as clock manipulation and supply voltage fluctuations, which can lead to incorrect actions like opening debug interfaces or accepting wrong signatures, and current solutions are either too expensive or impractical.

Innovation Solution

The integration of a safety domain within the microcontroller that includes sensors to detect faults and alarm signals, which are then communicated to a security domain to initiate secure operations, such as locking cryptographic keys or resetting security settings.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If better or faster sensors are used to detect faults in real-time, then security against fault attacks is improved, but cost increases

Engineering Contradiction:
Improvesecurity against fault attacksVSAvoidcost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent introduces a safety domain as an intermediary component that monitors faults and communicates with the security domain. This mediator handles the complex sensing and response tasks, allowing the security domain to remain simple and cost-effective while still achieving robust security through the collaborative safety-security domain architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The microcontroller is segmented into distinct safety domain and security domain components. The safety domain handles fault detection and monitoring, while the security domain handles cryptographic operations and security responses. This segmentation allows each domain to be optimized independently, achieving high security without requiring expensive sensors throughout the entire system.

Inventive Principle:
Principle #1Segmentation

2Reliability

If redundant implementation of security logic is used to prevent fault attacks, then security is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity against fault attacksVSAvoidcomplexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Security logic is segmented between the safety domain (fault detection) and security domain (cryptographic operations). This segmentation avoids redundant implementation of the same security logic while achieving complementary security functions that together provide robust protection against fault attacks.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The safety domain acts as an intermediary that simplifies the security domain's task by handling fault detection and communication. This reduces the complexity of the security domain while maintaining comprehensive security through the coordinated interaction between domains.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If traditional sensors are used to monitor supply voltage, temperature and clock, then basic monitoring is provided, but response time is too slow to prevent incorrect actions

Engineering Contradiction:
Improvefault detection capabilityVSAvoidresponse time
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The safety domain continuously monitors fault conditions and maintains readiness to detect anomalies. By having the monitoring infrastructure pre-established and continuously active, the system can detect and respond to faults immediately when they occur, rather than relying on slower traditional sensor response mechanisms.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The safety domain implements continuous feedback monitoring of fault conditions and communicates with the security domain in real-time. This feedback mechanism enables immediate detection and response to faults, with the alarm signal transmission providing rapid feedback that triggers security responses before incorrect actions can occur.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12339975B2Security device and methods of operating a security device
Publication Date: 2025.06.24 INFINEON TECHNOLOGIES AG
  • US12339975B2 patent drawing
  • US12339975B2 patent drawing
  • US12339975B2 patent drawing

AI summary

A device includes a safety domain having a processing unit and a memory and is configured to provide at least one functionality and to implement one more safety measures for detecting faults. The safety domain is configured to transmit at least one alarm signal indicating one or more detected errors in response to detecting the faults. The device further includes a security domain having a processing unit and a memory and is configured to provide cryptographic services and to obtain alarm signals. The security domain is configured to perform security-related operations in a secure state in response to obtaining an alarm signal from the safety domain.