Reset Attack Detection in Data Processing Reset Trees
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Data processing systems with reset trees are vulnerable to reset tree attacks, where an attacker can force a partial reset of the tree, leading to security breaches by altering the privilege level or security state without affecting other parts, potentially allowing unprivileged code to execute with greater privileges.
Innovation Solution
Incorporating reset attack detection elements into the reset tree, which assert an error signal if the reset signal transitions at an intermediate node without a corresponding transition at the root node, and using reset error clearing circuitry to differentiate between real resets and attacks by clearing error signals when the root node resets.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If reset attack detection elements are added to the reset tree, then security against partial reset attacks is improved, but device complexity increases
Solution Approach 1:
The reset tree is segmented by inserting detection elements at strategic nodes, dividing the monolithic reset distribution network into monitored segments. Each detection element independently monitors its local segment for unauthorized reset transitions, enabling targeted security monitoring without requiring complete system redesign.
Solution Approach 2:
Reset attack detection elements are introduced as intermediary components between the reset signal source and the data holding elements. These intermediaries monitor reset signal transitions and prevent unauthorized partial resets by detecting mismatches between root node transitions and intermediate node transitions.
2Reliability
If reset attack detection elements are incorporated into the reset tree, then detection of unauthorized partial resets is improved, but manufacturing complexity increases
Solution Approach 1:
The reset attack detection elements are merged with the existing reset tree structure, sharing common signal paths and synchronization mechanisms. The detection elements utilize the same reset signal distribution infrastructure, combining security monitoring functions with the existing reset distribution architecture to reduce manufacturing overhead.
Solution Approach 2:
The reset attack detection elements serve multiple functions: they monitor for unauthorized resets, detect partial reset attacks, and provide security verification. This multi-functionality reduces the need for separate security subsystems, simplifying the overall manufacturing process while maintaining comprehensive security coverage.
Data Source
AI summary
An apparatus has a number of data holding elements for holding data values which are reset to a reset value in response to a transition of a signal at a reset signal input of the data holding element from a first value to a second value. A reset tree is provided to distribute a reset signal received at root node of the reset tree to the reset signal inputs of the data holding elements. At least one reset attack detection element is provided, with its reset signal input coupled to a given node of the reset tree, to assert an error signal when its reset signal input transitions from the first value to a second value. Reset error clearing circuitry triggers clearing of the error signal, when the reset signal at the root node of the reset tree transitions from the second value to the first value.


