Randomized Boot Clock Gating Against DPA Side-Channel Attacks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for securing the boot process of digital electronic devices are vulnerable to side-channel attacks, particularly power analysis techniques like Differential Power Analysis (DPA), as they fail to adequately obfuscate power signatures during the boot process.

Innovation Solution

A hardware boot circuit introduces clock randomness at the root node of the clock network using a random number generator and clock gate circuit, generating a randomized clock signal by intermittently gating clock pulses, which does not alter clock frequency or pulse width, thereby creating temporal noise to obscure power signatures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a fixed clock signal is used during the boot process, then the boot process executes efficiently and deterministically, but the power signature becomes predictable and vulnerable to differential power analysis attacks

Engineering Contradiction:
Improvesecurity against DPA attacksVSAvoidclock signal generation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies the Dynamics principle by transforming the static, fixed clock signal into a dynamic, randomized clock signal. A random number generator circuit generates random values that control clock gating, causing the clock signal to vary in duration and pattern while maintaining its fundamental frequency. This dynamic transformation obscures the power signature temporal characteristics, making differential power analysis attacks ineffective while preserving the deterministic execution of boot instructions through controlled randomization intervals.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent introduces an intermediary random number generator circuit and clock gating mechanism between the clock source and the boot core. This intermediary layer randomizes the clock signal delivery without altering the underlying boot process logic or instruction execution flow. The randomization acts as a mediator that decouples the relationship between power consumption patterns and operational timing, protecting against DPA attacks while maintaining system functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If clock pulses are randomized to obscure power signatures, then security against power analysis attacks is improved, but the boot process timing becomes unpredictable

Engineering Contradiction:
Improvesecurity against power analysis attacksVSAvoidboot process timing predictability
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies periodic action by organizing randomization into fixed intervals where a predetermined number of clock pulses are delivered within each interval. This periodic structure ensures that while individual pulse timing varies, the overall boot process progresses through predictable phases and completes within expected timeframes. The periodic intervals maintain deterministic performance characteristics while providing sufficient randomization to obscure power signatures for security purposes.

Inventive Principle:
Principle #19Periodic action

3Object-affected harmful factors

If a hardware random number generator is integrated into the boot circuit, then temporal obfuscation of power signatures is achieved, but the hardware circuit complexity increases

Engineering Contradiction:
Improvepower signature obfuscationVSAvoidboot circuit hardware complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent merges the random number generator circuit, clock gating logic, and boot core circuit into an integrated hardware boot circuit. By combining these functions into a unified circuit architecture, the patent reduces overall system complexity compared to having separate discrete components. The merged circuit shares resources and coordination mechanisms, achieving temporal obfuscation through integrated randomization while minimizing the increase in hardware complexity through efficient resource utilization and shared control logic.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP4654064A1Hardware randomized boot clock
Publication Date: 2025.11.26 STMICROELECTRONICS INT NV
  • EP4654064A1 patent drawingFigure 1~2
  • EP4654064A1 patent drawingFigure 3
  • EP4654064A1 patent drawingFigure 4

AI summary

A hardware boot circuit includes a random number generator circuit (103) configured to generate random values, a reference clock circuit (107) configured to generate a reference clock signal (127) that includes a series of intervals of fixed size, a clock gate circuit (102) configured to switch off at least one clock pulse in each interval to generate a randomized clock signal (122) at a root node of a clock network, and a boot core circuit (104) configured to use the randomized clock signal (122) to access an internal memory storing boot instructions. Clock pulses that are switched off are randomized by the random values from the random number generator (103). The randomized clock signal (122) or additional randomized clock signals (123, 124) generated by the clock gate circuit (102) may be used to clock peripherals (108) and/or processors (110) of a digital electronic device (100) that includes the hardware boot circuit. The random number generator (103) may include a physical entropy source.