Power Domain Voltage State Detection for Volt Boot Mitigation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Volt boot attacks pose a challenge in electronic circuits by retaining sensitive data in volatile storage during power down or low power mode transitions, making it difficult to distinguish from normal operations and risking data leakage.
Innovation Solution
Implementing a Secure Probe Management Controller (SPMC) with Secure Probe State Detector (SPSD) and Secure Power Cycle Controller (SPCC) to monitor voltage supply lines, detect volt boot attacks by comparing previous and requested supply line states, and initiate a repower cycle to erase sensitive data across all power domains.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If the system relies on voltage decay to erase stored data during power down, then the system simplicity is maintained, but the security against volt boot attacks deteriorates
Solution Approach 1:
The patent implements preliminary detection of volt boot attacks by monitoring voltage supply lines before data can be exfiltrated. The SPSD compares previous and requested supply line states to detect attack patterns, and the SPCC proactively initiates repower cycles to erase data before the attacker can access it, thus preventing the security vulnerability while maintaining system simplicity
Solution Approach 2:
The patent employs feedback mechanisms where the SPSD continuously monitors voltage supply lines and feeds back attack detection information to the SPCC. When a volt boot attack is detected through voltage state comparison, the system automatically triggers a repower cycle to erase sensitive data, creating a closed-loop security mechanism that responds dynamically to threats without adding significant system complexity
2Adaptability or versatility
If multiple power domains are used to optimize system level use cases, then the system adaptability is improved, but the difficulty of detecting volt boot attacks increases
Solution Approach 1:
The patent applies segmentation by implementing separate detection and control logic for each power domain. The SPSD monitors voltage supply lines in each power domain independently, and the SPCC can initiate repower cycles for specific domains or globally, allowing the system to maintain adaptability across multiple power domains while simplifying attack detection through domain-specific monitoring
Solution Approach 2:
The patent implements universal detection mechanisms that work across all power domains. The SPSD and SPCC are designed to handle multiple power domains through standardized voltage state comparison and repower cycle initiation, allowing the same detection logic to be applied universally across different power domains regardless of their specific configurations or use cases
3Ease of operation
If normal transitions to low power mode are allowed without verification, then the ease of operation is improved, but the risk of unauthorized data retention increases
Solution Approach 1:
The patent implements preliminary verification of power domain states before allowing transitions to low power modes. The SPSD checks voltage supply line states in advance to ensure normal operation, and the SPCC verifies that no volt boot attack is in progress before permitting the transition, thus preventing unauthorized data retention while maintaining ease of operation for legitimate transitions
Solution Approach 2:
The patent employs feedback verification where the SPSD continuously monitors voltage supply lines and provides real-time information about the power domain state. Before allowing a transition to low power mode, the system verifies that the current state is normal and not indicative of an attack, creating a safety check that prevents unauthorized data retention without significantly impacting operational ease
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A method for detection and mitigation of volt boot attacks includes applying a respective operating voltage to at least one power domain, wherein each respective operating voltage exceeds a low voltage detection level of the respective power domain. A flag is set for each of the at least one power domain, having the respective operating voltage applied, to define a previous state of supply for the corresponding pin (domain) for each flag. The at least one power domain is requested to transition to a respective lower voltage being less than the low voltage detection level for the respective power domain. The flag for each transitioned power domain is set to define a requested state. The previous state is compared to the requested state to determine a mismatch for each power domain. An occurrence of a volt boot attack is determined for each power domain comprising the respective mismatch.