Reset Tree Attack Detector Circuitry for Malicious Glitch Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional attack detection circuits in circuit designs are area inefficient and performance deficient, leading to increased costs and inefficiencies in malicious attack detection.
Innovation Solution
The implementation of a reset tree attack detector circuitry with a logic-based structure, including a reset synchronizer, sensors, and logic gates, which generates a reset alarm signal upon detecting malicious attacks by comparing the duration of timing glitches between reset-synchronizing and attack detection signals, minimizing impact on power, performance, and area.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional attack detection circuits are implemented, then malicious attacks can be detected, but area efficiency deteriorates and performance decreases
Solution Approach 1:
The reset tree structure is designed to serve multiple functions: it distributes reset signals to multiple flip-flops while simultaneously providing attack detection capabilities through sensor integration. This multi-functionality eliminates the need for separate dedicated attack detection circuits, thereby improving area efficiency while maintaining reliable attack detection.
Solution Approach 2:
The patent merges the reset signal distribution function with the attack detection function into a single integrated circuit. By combining these functions, the design reduces the total area required compared to having separate reset distribution logic and separate attack detection circuits, while maintaining both functionalities.
2Reliability
If conventional attack detection circuits are implemented, then malicious attacks can be detected, but performance efficiency deteriorates
Solution Approach 1:
The attack detection function is segmented and distributed across multiple sensors placed at different branches of the reset tree. Each sensor monitors a specific subset of reset signals, allowing parallel detection operations that improve overall performance efficiency while maintaining comprehensive attack detection coverage.
Solution Approach 2:
Sensors are integrated into the reset tree structure beforehand, so that attack detection is performed concurrently with normal reset signal distribution. This preliminary integration eliminates the need for separate detection phases, improving performance efficiency by detecting attacks in real-time during normal operation.
3Reliability
If reset signal monitoring is performed, then attacks can be detected, but power consumption increases
Solution Approach 1:
The sensors in the reset tree utilize the existing reset signal infrastructure to perform detection without requiring additional dedicated power-intensive monitoring circuits. The reset tree itself serves the dual purpose of signal distribution and attack detection, reducing overall power consumption while maintaining detection accuracy.
Data Source
AI summary
Various implementations described herein are directed to a device with a reset tree having leaf buffers that provide sensed output signals based on a reset-synchronizing input signal. The device may have a first sensor that receives the sensed output signals from the leaf buffers of the reset tree and provides an attack detection signal based on sensing a malicious attack. The device may have a second sensor that receives the reset-synchronizing input signal, receives the attack detection signal from the first sensor and provides a reset alarm signal based on duration of a timing glitch associated with comparing a difference between the reset-synchronizing input signal and the attack detection signal.


