Power Management Security Interface for Side Channel Attack Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current system on chip (SoC) computing architectures are vulnerable to power management-related attacks, where attackers can determine active circuit blocks by accessing power management registers or monitoring power rails, compromising encryption processing security.
Innovation Solution
A security-enhanced power management integrated circuit (PMIC) is implemented, which uses a power management security interface to establish secure communication paths and prevent unauthorized access to power management registers, and employs side-channel noise analysis to detect and counter potential security threats by generating policy-based counter noise on power rails.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If power management registers are made accessible for circuit block control, then power management functionality is improved, but security vulnerability increases allowing attackers to determine active circuit blocks
Solution Approach 1:
A security enclave processor acts as an intermediary between attackers and power management registers. The SEP receives credential verification requests, validates them against stored credentials, and only grants access to power management registers if verification succeeds. This mediator architecture maintains power management functionality while blocking unauthorized access attempts.
2Use of energy by moving object
If power rails are monitored for power management, then power efficiency is improved, but side channel attack susceptibility increases allowing determination of active circuit blocks
Solution Approach 1:
The system performs preliminary credential verification through the security enclave processor before allowing any power rail monitoring or power management operations. By establishing authentication status in advance, the system prevents unauthorized side channel attacks while maintaining legitimate power management functions. The SEP's credential checking occurs before power rail access is granted.
3Ease of operation
If JTAG debug ports are enabled for system access, then debugging capability is improved, but physical attack access is facilitated enabling power rail monitoring
Solution Approach 1:
The security enclave processor serves as an intermediary that controls access through JTAG debug ports. Even when JTAG is physically accessible, the SEP intercepts and validates all access attempts through credential verification. This mediator ensures that debugging capability remains available to authorized users while blocking physical attackers from using JTAG to monitor power rails.
Data Source
Figure 1~2
Figure 3
Figure 4
AI summary
Systems, apparatuses and methods may provide for detecting a request to access a power management register and conducting, via a power management security interface, a runtime credential exchange with a source of the request. Additionally, the request may be denied if the runtime credential exchange is unsuccessful. In one example, a plug event is detected, via a dedicated side channel, with respect to a debug port. A noise analysis may be conducted of one or more power rails in response to the plug event, wherein policy based counter noise may be generated on at least one of the one or more power rails at runtime if the noise analysis identifies a potential security attack.