Multi-Threshold Voltage Detection for IC Power-Up Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Integrated Circuits (ICs) with Non-Volatile Memory (NVM) are vulnerable to security attacks during power-up sequences, where attackers can manipulate the supply voltage to mis-read the operational state, leading to erroneous data interpretation and unauthorized access to sensitive resources.
Innovation Solution
The secure power-up circuitry performs a first readout of the operational state within a initial voltage range and, if it permits access to sensitive resources, verifies the supply voltage is within a more stringent range, followed by a second readout, initiating a responsive action if discrepancies are found, thereby enhancing security against voltage manipulation attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a single readout of operational state is performed during power-up, then the power-up sequence is fast and simple, but the system is vulnerable to voltage manipulation attacks that can mis-read the operational state
Solution Approach 1:
The patent performs a first readout of the operational state at an initial voltage threshold before finalizing the power-up sequence. This preliminary readout allows the system to detect potential voltage manipulation attacks early, and only if the readout is valid does the system proceed to a second confirmation readout at a higher voltage threshold. This preliminary action prevents unauthorized access without requiring complex continuous verification throughout the entire power-up sequence.
Solution Approach 2:
The patent changes the voltage threshold parameter during the power-up sequence to enhance security. The first readout is performed at an initial voltage threshold, and if that readout indicates a state permitting access to sensitive resources, the system then performs a second readout at a higher voltage threshold. This parameter change ensures that the operational state is read under different electrical conditions, making voltage manipulation attacks less effective while maintaining a relatively simple power-up sequence structure.
2Reliability
If voltage verification is performed at multiple thresholds, then security against manipulation attacks is enhanced, but the power-up sequence time increases
Solution Approach 1:
The first readout at the initial voltage threshold serves as a preliminary security check that filters out many potential attacks before requiring the time-consuming second readout. Only when the first readout indicates a potentially vulnerable state (one that would permit unauthorized access) does the system proceed to the second confirmation readout. This preliminary filtering minimizes the average time penalty while maintaining strong security.
Solution Approach 2:
The patent allows the power-up sequence to skip the second voltage verification step when the first readout indicates a safe state. If the first readout does not indicate a state permitting access to sensitive resources, the system rushes through the power-up sequence without performing the additional time-consuming second readout. This skipping mechanism ensures that normal, secure power-up operations complete quickly while still providing enhanced security when needed.
3Measurement precision
If a stringent voltage range is enforced for readout, then readout accuracy is improved, but the operational flexibility of the IC is reduced
Solution Approach 1:
The patent applies different voltage threshold requirements locally based on the operational state detected in the first readout. For states that do not permit access to sensitive resources, the system uses the more flexible initial voltage threshold for the readout. For states that would permit unauthorized access, the system locally enforces the more stringent higher voltage threshold for confirmation. This local quality approach maintains measurement precision where needed while preserving operational flexibility where risks are lower.
Solution Approach 2:
The system dynamically changes the voltage threshold parameter based on the operational state detected during the first readout. If the detected state is safe (does not permit access to sensitive resources), the system maintains the initial, more flexible voltage threshold. If the detected state is potentially vulnerable (permits access to sensitive resources), the system changes to a more stringent voltage threshold for the second readout. This conditional parameter change ensures high readout accuracy for security-critical operations while maintaining operational flexibility for routine operations.
Data Source
AI summary
An Integrated Circuit (IC) includes a non-volatile memory (NVM) and secure power-up circuitry. The NVM is configured to store an operational state of the IC. The secure power-up circuitry is configured to (i) during a power-up sequence of the IC, perform a first readout of the operational state from the NVM while a supply voltage of the IC is within a first voltage range, (ii) if the operational state read from the NVM in the first readout is a state that permits access to a sensitive resource of the IC, verify that the supply voltage is within a second voltage range, more stringent than the first voltage range, and then perform a second readout of the operational state from the NVM, and (iii) initiate a responsive action in response to a discrepancy between the operational states read from the NVM in the first readout and in the second readout.
