Ring Oscillator Cold-Boot Attack Detection Circuit

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Volatile memory in electronic circuits is vulnerable to attacks during reset operations, particularly 'Cold Boot' attacks where the circuit is switched on and off repeatedly, allowing unauthorized access to secret data due to the unreliable state of memory after power cycling.

Innovation Solution

A method and circuit that utilize a ring oscillator to detect cold-boot attacks by sampling and analyzing the proportion of states '1' and '0' in the output, determining a statistical range during a training phase, and comparing this to stored values in a non-volatile memory to determine if an attack has occurred, with periodic verification to protect against such attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If volatile memory is used for data processing, then data manipulation speed is improved, but data security deteriorates due to cold-boot attacks

Engineering Contradiction:
Improvedata manipulation speedVSAvoiddata security
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent applies preliminary action by performing verification of the volatile memory state before authorized access is granted. The system proactively checks whether the memory contains residual data from previous operations by analyzing the proportion of logical states, and prevents access if the verification fails, thus securing data before the attack can succeed.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback by continuously monitoring the volatile memory state through periodic verification of the proportion of logical states (0s and 1s). The system compares the actual proportion against expected ranges and uses this feedback to determine whether to allow or block access, creating a closed-loop security mechanism that responds to real-time memory conditions.

Inventive Principle:
Principle #23Feedback

2Reliability

If memory reset is performed to secure data, then data security is improved, but operation time deteriorates due to erasing time

Engineering Contradiction:
Improvedata securityVSAvoiderasing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent introduces an intermediary verification mechanism that acts as a mediator between the volatile memory and the access control logic. Instead of directly resetting the memory or blocking access unconditionally, the system uses the verification of logical state proportions as an intermediary check to intelligently decide whether security threats exist, enabling faster and more precise security responses.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent applies parameter changes by monitoring the proportion of logical states (0s and 1s) in the volatile memory as a key parameter. The system compares this parameter against predefined ranges to detect anomalies indicating cold-boot attacks, allowing dynamic security decisions based on real-time parameter analysis rather than static reset procedures.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If verification of memory state is performed, then data security is improved, but device complexity deteriorates

Engineering Contradiction:
Improvedata securityVSAvoidverification circuit complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the essential security verification function from complex memory analysis by focusing solely on measuring the proportion of logical states (0s and 1s) in the volatile memory. This extraction simplifies the verification circuit to perform only the critical measurement needed for cold-boot attack detection, eliminating the need for complex decryption or full memory scanning mechanisms.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11200322B2Protection of data stored in an integrated circuit
Publication Date: 2021.12.14 STMICROELECTRONICS INT NV
  • US11200322B2 patent drawing
  • US11200322B2 patent drawing
  • US11200322B2 patent drawing

AI summary

A method of detecting a cold-boot attack on an integrated circuit, including the steps of: periodically sampling a signal delivered by at least one ring oscillator; and verifying that the proportion of states “1” and of states “0” of the result of the sampling is within a range of values.