Processor Security Checking via Peripheral Data Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing complexity of hardware design and manufacturing processes makes it difficult to detect and identify hardware Trojans or vulnerabilities in processors, compromising hardware security and controllability.

Innovation Solution

A checking method and device that acquire and analyze recording information of data read and write operations between a processor and peripherals to determine processor security, effectively detecting hardware vulnerabilities and improving security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If hardware design scale and complexity are increased to improve processing capability, then processor performance is improved, but hardware security and controllability deteriorate due to increased possibility of Trojans and difficulty in identification

Engineering Contradiction:
Improveprocessor performanceVSAvoidhardware security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies preliminary action by establishing a security checking mechanism that proactively monitors and verifies processor operations before potential security breaches can occur. The checking device records and analyzes data read/write operations in real-time, enabling early detection of Trojan activities or abnormal behaviors before they can compromise system security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback by creating a closed-loop security verification system. The checking device continuously monitors processor operations, compares actual behavior against expected security criteria, and provides feedback on security status. This feedback mechanism enables dynamic adjustment and continuous improvement of security measures while maintaining processor performance.

Inventive Principle:
Principle #23Feedback

2Ease of manufacture

If hardware design process is refined and divided into multiple stages, then manufacturing capability is improved, but security controllability deteriorates due to decreased ability to monitor and control Trojans

Engineering Contradiction:
Improvemanufacturing capabilityVSAvoidTrojan detection difficulty
Core Design Contradiction:
Ease of manufactureVSDifficulty of detecting and measuring

Solution Approach 1:

The patent applies segmentation by dividing the security checking function into independent, modular components. The checking device is separated from the processor, with distinct modules for recording operations, analyzing data, and determining security status. This modular approach enables independent verification at each stage of the hardware lifecycle without disrupting the refined manufacturing process.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary checking device that acts as a mediator between the processor and the external environment. This intermediary monitors all data read/write operations without interfering with the processor's normal operation or the manufacturing process, enabling continuous security verification throughout the refined manufacturing stages.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If processor and peripheral interactions are increased to improve functionality, then system capability is improved, but security risk increases due to more potential attack vectors

Engineering Contradiction:
Improvesystem capabilityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies universality by designing a checking device that can monitor multiple types of operations across different processors and peripherals through a unified interface. The security checking mechanism is not limited to specific processor-peripheral interactions but can universally apply to various data read/write operations, enabling comprehensive security coverage without restricting system functionality.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10572671B2Checking method, checking system and checking device for processor security
Publication Date: 2020.02.25 TSINGHUA UNIVERSITY
  • US10572671B2 patent drawing
  • US10572671B2 patent drawing

AI summary

The present disclosure discloses a processor security checking method, system and checking device. The processor security checking method includes: acquiring recording information of data read and write operations between a processor and a peripheral device, where the data read and write operation is a data read and write operation initiated by the processor or a data read and write operation initiated by the peripheral; and determining whether the processor is secure according to the recording information of the data read and write operation and an analysis result on the data read and write operation by the checking device. The embodiments of the present disclosure may detect hardware vulnerabilities and improve the security of hardware usage.