Reconfigurable Signal-Processing Circuits Against Hardware Trojans

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current hardware architectures are vulnerable to hardware Trojans (HW Trojans), which are difficult to detect and can cause long-term, stealthy attacks, especially in automotive and industrial applications, necessitating a new approach to build a HW Trojan resilient architecture.

Innovation Solution

Implement a hardware circuit with a first sub-circuit that processes input signals differently to create multiple output signals, and a second sub-circuit that detects and processes these signals based on their origin, obfuscating the signal processing to confuse HW Trojans, using reconfigurable circuits like FPGAs for adaptability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If hardware Trojans are incorporated into the hardware design, then long-term stealth access is achieved, but security is compromised

Engineering Contradiction:
Improvestealth access capabilityVSAvoidsecurity vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements dynamic reconfiguration of hardware circuits using FPGAs, where the circuit topology and signal processing paths can change over time. This dynamic behavior prevents HW Trojans from maintaining consistent stealth access, as the circuit structure evolves and adapts to detect and counteract Trojan attempts.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes operational parameters such as signal processing modes, circuit configurations, and detection thresholds dynamically. By varying these parameters, the system creates an unpredictable environment that undermines the fixed trigger conditions of HW Trojans, thereby maintaining security while allowing legitimate operations.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If thorough analysis of every hardware component is performed to locate HW Trojans, then detection accuracy improves, but time consumption and complexity increase

Engineering Contradiction:
ImproveTrojan detection accuracyVSAvoidanalysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements preliminary detection mechanisms that continuously monitor hardware behavior for anomalous patterns indicative of Trojans. By performing detection proactively rather than through exhaustive post-manufacturing analysis, the system achieves high detection accuracy while minimizing the time and computational resources required.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system incorporates feedback loops where detection results from monitoring hardware signals are fed back to adjust detection parameters and trigger responses. This continuous feedback mechanism enables efficient, real-time Trojan detection without requiring complete disassembly or exhaustive analysis of every component.

Inventive Principle:
Principle #23Feedback

3Object-affected harmful factors

If signal processing is obfuscated to confuse HW Trojans, then security against Trojans improves, but system complexity increases

Engineering Contradiction:
ImproveTrojan effectivenessVSAvoidcircuit complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent uses dynamic reconfiguration to obfuscate signal processing paths, where the actual processing route changes based on operational context. This dynamic obfuscation confuses HW Trojans that rely on static analysis, while the underlying complexity is managed through systematic control and programming of the reconfigurable elements.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12488148B2Methods and apparatuses for cyber security enhancement
Publication Date: 2025.12.02 VOLKSWAGEN AG
  • US12488148B2 patent drawing
  • US12488148B2 patent drawing

AI summary

The disclosure describes a method of providing cyber security enhancement, comprising: receiving an input signal via a first hardware sub-circuit of a hardware circuit and processing the received input signal into at least one of a first processed signal according to a first type of processing and a second processed signal according to a second type of processing being different to the first type of processing; deriving from only from one of the first processed signal and/or second processed signal a first output signal; transmitting the first output signal to a second hardware sub-circuit of the hardware circuit; and detecting from which of the first processed signal and/or second processed signal the transmitted first output signal is derived from and processing the transmitted first output signal into a second output signal in dependency from result of the detection.