Hardware Malware Detection via Power Trace Template Correlation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Commercial off-the-shelf processing components may incorporate untrusted or vulnerable hardware, leading to potential hardware Trojans or malware that compromise the integrity of mission-critical systems by allowing unauthorized data extraction and observation.
Innovation Solution
A hardware malware detection apparatus using template processors and hardware sensors to collect and compare power trace data from primary and remote systems, generating system templates to identify anomalies and verify intended performance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If commercial off-the-shelf processing components are used to reduce cost and improve availability, then system cost and component availability are improved, but system security and integrity deteriorate due to potential hardware Trojans and malware
Solution Approach 1:
The system performs preliminary actions by creating a trusted reference model of normal system behavior through power trace analysis before deployment. This reference model is established in advance using a known-good system configuration, enabling subsequent detection of deviations that indicate hardware malware without requiring real-time intervention or changing the deployed system architecture.
Solution Approach 2:
The patent introduces an intermediary detection layer that monitors power consumption patterns between the untrusted hardware components and the system observer. This intermediary mechanism (power trace analysis) indirectly detects hardware malware by measuring electrical characteristics rather than directly inspecting the suspicious components, thus maintaining system operation while enabling security verification.
2Reliability
If hardware sensors and template processors are deployed to detect hardware malware through power trace analysis, then system security and detection capability are improved, but device complexity and computational requirements worsen
Solution Approach 1:
The system creates a simplified copy or model of the expected system behavior through power trace templates rather than attempting to replicate or directly monitor all system components. These templates capture the essential electrical characteristics of normal operation, enabling malware detection through pattern matching without requiring complex real-time analysis of the entire system state.
Solution Approach 2:
The patent transforms the complex problem of hardware malware detection into a simpler parameter comparison task by measuring power consumption characteristics. Instead of analyzing complex hardware behaviors or software states, the system converts detection into a parameter-based approach where power trace patterns are compared against templates, reducing computational complexity while maintaining detection effectiveness.
3Measurement precision
If real-time power trace data is collected and correlated with system templates to detect malware, then detection accuracy is improved, but processing time and energy consumption worsen
Solution Approach 1:
The system performs preliminary processing by pre-computing power trace templates from known-good system behavior before malware detection is needed. These templates are stored and reused for multiple detection operations, eliminating the need to re-analyze normal system behavior for each detection attempt. This shifts computational burden to an offline phase, enabling fast real-time detection.
Solution Approach 2:
The system creates simplified copies of normal system behavior in the form of power trace templates that capture essential patterns without containing all the complexity of actual system operation. These template copies enable rapid comparison against real-time measurements through efficient pattern matching algorithms, reducing processing time while maintaining detection accuracy.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
Effectively detects hardware malware in remote systems by correlating real-time power trace data with system templates, ensuring the integrity of sensitive information and preventing unauthorized access.
Implementation Method 1
The hardware sensors collect primary power trace data generated by processing components of the primary system in response to test commands, command sequences, and other input vectors
Implementation Method 2
The template processors correlate this remote power trace data with the system templates to determine the presence or absence of system anomalies within the remote systems
Data Source
AI summary
A hardware malware profiling and detection system is disclosed. In embodiments, the system includes a primary (e.g., trusted) system including template processors and hardware sensors. The template processors submit input vectors to the primary system and characterize the system response via power trace data collected by the hardware sensors. Based on the input vectors and power trace data, the template processors generate system templates and derive system challenges therefrom. The template processors submit the system challenges to a remote system under test and characterize the remote system response in real time via identical remote hardware sensors. The template processors correlate the real-time remote system response data with the system templates corresponding to the issued challenges to detect system anomalies or malware within the remote system or its components.


