Randomized Countermeasure Enforcement for Fault Attack Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Electronic devices are vulnerable to fault attacks, which involve unauthorized changes or access through induced errors, compromising security by facilitating unauthorized access to sensitive information, and existing security measures are not effectively randomized to prevent replication of attacks across devices.
Innovation Solution
The implementation of non-deterministic enforcement of fault attack countermeasures through randomized patterns in system circuitry, which includes processors and memories that dynamically adjust countermeasure enforcement based on random number generation and enforcement thresholds to protect against fault attacks, ensuring unique countermeasure enforcement patterns across devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If deterministic countermeasure enforcement is used, then security coverage is complete, but attackers can replicate attacks across devices
Solution Approach 1:
The patent applies dynamics by transitioning from static, deterministic countermeasure enforcement to dynamic, randomized enforcement. The system randomly selects which countermeasures to enforce at different times and across different devices, making the security behavior adaptive and unpredictable. This resolves the contradiction by maintaining complete security coverage through randomization while preventing attack replication, as attackers cannot determine which countermeasures will be active.
Solution Approach 2:
The patent changes the enforcement parameter from fixed/deterministic to variable/randomized. By introducing randomization in countermeasure enforcement patterns, the system maintains comprehensive security coverage while making it impossible for attackers to replicate attacks across devices. The parameter change transforms the security model from predictable to unpredictable, resolving the vulnerability to attack replication.
2Reliability
If countermeasures are always enforced, then security protection is maximized, but processing time and power consumption increase
Solution Approach 1:
The patent applies partial action by randomly selecting a subset of countermeasures to enforce rather than always enforcing all countermeasures. This approach maintains adequate security protection through randomization while reducing the processing overhead and power consumption associated with continuous full countermeasure enforcement. The system achieves security with less resource expenditure by being selective about which countermeasures to activate.
Solution Approach 2:
The patent implements periodic action through randomized countermeasure enforcement patterns that change over time. Instead of continuous, deterministic enforcement, the system periodically activates different countermeasures based on random selection. This maintains security protection while allowing processing time and power consumption to be reduced during periods when fewer countermeasures are active.
3Adaptability or versatility
If randomized countermeasure enforcement is implemented, then attack replication is prevented, but security predictability decreases
Solution Approach 1:
The patent embraces dynamics by intentionally introducing unpredictability into the security system through randomization. While this decreases security predictability in the traditional sense, it dramatically improves adaptability by preventing attack replication. The dynamic, randomized behavior ensures that security patterns cannot be anticipated or replicated by attackers, resolving the contradiction between predictability and prevention of replication.
Data Source
AI summary
A device may include countermeasure circuitry that provides a countermeasure check that protects device logic. The device may also include enforcement circuitry that non-deterministically enforces the countermeasure check on the device logic so that the device logic is not always protected by a countermeasure action within the countermeasure check. The device may non-deterministically enforce the countermeasure check according to an enforcement rate, and the device may adjust the enforcement rate depending on a priority of the device logic or device logic portion protected by a particular countermeasure check.


