Hardware Malware Detection via Power Trace Template Correlation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Commercial off-the-shelf processing components may incorporate untrusted or vulnerable hardware, leading to potential hardware Trojans or malware that compromise the integrity of mission-critical systems by allowing unauthorized data extraction and observation.

Innovation Solution

A hardware malware detection apparatus using template processors and hardware sensors to collect and compare power trace data from primary and remote systems, generating system templates to identify anomalies and verify intended performance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If commercial off-the-shelf processing components are used to reduce cost and improve availability, then system cost and component availability are improved, but system security and integrity deteriorate due to potential hardware Trojans and malware

Engineering Contradiction:
Improvesystem costVSAvoidsystem integrity
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The system performs preliminary actions by creating a trusted reference model of normal system behavior through power trace analysis before deployment. This reference model is established in advance using a known-good system configuration, enabling subsequent detection of deviations that indicate hardware malware without requiring real-time intervention or changing the deployed system architecture.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary detection layer that monitors power consumption patterns between the untrusted hardware components and the system observer. This intermediary mechanism (power trace analysis) indirectly detects hardware malware by measuring electrical characteristics rather than directly inspecting the suspicious components, thus maintaining system operation while enabling security verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If hardware sensors and template processors are deployed to detect hardware malware through power trace analysis, then system security and detection capability are improved, but device complexity and computational requirements worsen

Engineering Contradiction:
Improvemalware detection capabilityVSAvoiddetection system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system creates a simplified copy or model of the expected system behavior through power trace templates rather than attempting to replicate or directly monitor all system components. These templates capture the essential electrical characteristics of normal operation, enabling malware detection through pattern matching without requiring complex real-time analysis of the entire system state.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent transforms the complex problem of hardware malware detection into a simpler parameter comparison task by measuring power consumption characteristics. Instead of analyzing complex hardware behaviors or software states, the system converts detection into a parameter-based approach where power trace patterns are compared against templates, reducing computational complexity while maintaining detection effectiveness.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If real-time power trace data is collected and correlated with system templates to detect malware, then detection accuracy is improved, but processing time and energy consumption worsen

Engineering Contradiction:
Improvemalware detection accuracyVSAvoiddetection processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary processing by pre-computing power trace templates from known-good system behavior before malware detection is needed. These templates are stored and reused for multiple detection operations, eliminating the need to re-analyze normal system behavior for each detection attempt. This shifts computational burden to an offline phase, enabling fast real-time detection.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system creates simplified copies of normal system behavior in the form of power trace templates that capture essential patterns without containing all the complexity of actual system operation. These template copies enable rapid comparison against real-time measurements through efficient pattern matching algorithms, reducing processing time while maintaining detection accuracy.

Inventive Principle:
Principle #26Copying

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

Effectively detects hardware malware in remote systems by correlating real-time power trace data with system templates, ensuring the integrity of sensitive information and preventing unauthorized access.

Implementation Method 1

The hardware sensors collect primary power trace data generated by processing components of the primary system in response to test commands, command sequences, and other input vectors

Methodology Applied
Scientific EffectPower trace analysis:

Implementation Method 2

The template processors correlate this remote power trace data with the system templates to determine the presence or absence of system anomalies within the remote systems

Methodology Applied
Scientific EffectData correlation:

Data Source

PatentUS11321463B2Hardware malware profiling and detection system
Publication Date: 2022.05.03 ROCKWELL COLLINS INC
  • US11321463B2 patent drawing
  • US11321463B2 patent drawing
  • US11321463B2 patent drawing

AI summary

A hardware malware profiling and detection system is disclosed. In embodiments, the system includes a primary (e.g., trusted) system including template processors and hardware sensors. The template processors submit input vectors to the primary system and characterize the system response via power trace data collected by the hardware sensors. Based on the input vectors and power trace data, the template processors generate system templates and derive system challenges therefrom. The template processors submit the system challenges to a remote system under test and characterize the remote system response in real time via identical remote hardware sensors. The template processors correlate the real-time remote system response data with the system templates corresponding to the issued challenges to detect system anomalies or malware within the remote system or its components.