Multi-Voltage Security Module for Fault Injection Resistance
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing integrated circuit devices, particularly application-specific integrated circuits (ASICs), are vulnerable to fault injection attacks such as electromagnetic pulses and voltage level manipulations, which can alter security mechanisms, allowing unauthorized access.
Innovation Solution
Implementing a security module with multiple voltage domains, each with its own supply voltage and register units, requiring simultaneous manipulation of register values across all domains for unauthorized access, combined with tampering detection and redundant register unit placement to enhance protection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If electromagnetic pulses or laser pulses are used to manipulate the register value, then unauthorized access is achieved, but security is compromised
Solution Approach 1:
The security module is divided into multiple voltage domains (at least two), each with separate register units storing portions of the release value. This segmentation ensures that manipulating one domain does not compromise the entire security mechanism, as each domain must be simultaneously manipulated to achieve unauthorized access.
Solution Approach 2:
Different voltage domains operate at different supply voltages, creating local quality differences. Each domain circuit is supplied by its respective supply voltage, making the system resistant to uniform voltage manipulation attacks while allowing controlled local operations.
2Reliability
If costly hardening processes are applied to block electromagnetic pulses, then security is improved, but manufacturing cost increases
Solution Approach 1:
The security module is divided into multiple voltage domains (at least two), each with separate register units storing portions of the release value. This segmentation ensures that manipulating one domain does not compromise the entire security mechanism, as each domain must be simultaneously manipulated to achieve unauthorized access.
Solution Approach 2:
Different voltage domains operate at different supply voltages, creating local quality differences. Each domain circuit is supplied by its respective supply voltage, making the system resistant to uniform voltage manipulation attacks while allowing controlled local operations.
3Reliability
If voltage level monitors are built into the ASIC to detect suspicious voltage variations, then protection against voltage manipulation is improved, but device complexity and cost increase
Solution Approach 1:
The security module is divided into multiple voltage domains (at least two), each with separate register units storing portions of the release value. This segmentation ensures that manipulating one domain does not compromise the entire security mechanism, as each domain must be simultaneously manipulated to achieve unauthorized access.
Solution Approach 2:
Different voltage domains operate at different supply voltages, creating local quality differences. Each domain circuit is supplied by its respective supply voltage, making the system resistant to uniform voltage manipulation attacks while allowing controlled local operations.
Data Source
Figure 1
Figure 2
AI summary
The invention relates to an integrated circuit device (10) comprising an operation module (12) and a security module (14). The security module (14) comprises a set of voltage domains (20) supplied by different respective supply voltages, each voltage domain (20) comprising a respective domain circuit (22), Each domain circuit (22) comprises a domain logic block (24), configured to provide a domain release signal (30) at a domain output connector (32) of the domain circuit (22), when the register value configuration satisfies a predefined domain release condition. The integrated circuit device (10) comprises a global logic block (42), configured to provide a predefined global release signal (16) at a security module output connector (44) of the security module (14) when the domain release signal (30) configuration satisfies a predefined global release condition.