Processor Authentication via Signed Instruction Feedback

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current processor implementation methods and authentication techniques are vulnerable to cloning and emulation of opcodes, lacking effective measures to ensure authenticity.

Innovation Solution

A processor architecture that includes an arithmetic and logic unit with a result register bank capable of operating as a shift register, combining decoded opcodes with previous results to generate a signed instruction, which is processed to enhance authentication by differentiating from standard processor outputs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If standard processor authentication methods are used, then processor operation is maintained, but vulnerability to cloning and emulation remains

Engineering Contradiction:
Improveauthentication securityVSAvoidcloning and emulation vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements feedback by incorporating previous execution results into the current authentication process. The combination circuit uses feedback signals from the result register bank (containing previous opcode results) to generate authenticated output signals. This feedback mechanism ensures that each opcode execution is verified against historical data, making cloning and emulation detectable since counterfeit processors cannot replicate the feedback loop's complex verification logic.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent applies preliminary action by pre-configuring the result register bank to store previous execution results before the current authentication process begins. The combination circuit is pre-wired to automatically incorporate these pre-stored results into the authentication of each new opcode. This preliminary preparation of authentication data enables continuous verification without requiring external authentication systems, thereby securing the processor against cloning attempts.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If opcode authentication is implemented, then processor security is improved, but device complexity increases

Engineering Contradiction:
Improveprocessor authenticationVSAvoidprocessor architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the authentication function with the existing arithmetic and logic unit structure. The combination circuit integrates the authentication logic into the data path between the arithmetic and logic unit and the result register bank. By merging authentication operations into the existing pipeline rather than adding a separate authentication subsystem, the patent improves processor security while minimizing the increase in device complexity.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The result register bank serves multiple functions: it stores previous opcode execution results for authentication purposes, maintains processor state information, and provides feedback signals to the combination circuit. The combination circuit simultaneously performs data combination, authentication verification, and signal generation. This multi-functionality reduces the need for separate dedicated authentication components, thereby improving security without proportionally increasing device complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20240103873A1Processor authentication method
Publication Date: 2024.03.28 STMICROELECTRONICS BELGIUM
  • US20240103873A1 patent drawing
  • US20240103873A1 patent drawing
  • US20240103873A1 patent drawing

AI summary

The disclosure includes a method of authenticating a processor that includes an arithmetic and logic unit. At least one decoded operand of at least a portion of a to-be-executed opcode is received on a first terminal of the arithmetic and logic unit. A signed instruction is received on a second terminal of the arithmetic and logic unit. The signed instruction combines a decoded instruction of the to-be-executed opcode and a previous calculation result of the arithmetic and logic unit.