Secure Chip-Wide Transmission Integrity Metadata
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security measures in computing systems are inadequate in preventing fault injection attacks, which can bypass system security features, alter system behavior, and expose sensitive information, with previous techniques like data parity being ineffective and vulnerable to attacks.
Innovation Solution
Implementing secure chip-wide communication by generating and validating integrity metadata for command and response payloads across the system, using error correction codes and scrambling data in memory to ensure end-to-end security and protect against fault injection attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If data parity is used for security, then implementation is simple, but it is vulnerable to fault injection attacks and ineffective
Solution Approach 1:
The data transmission is segmented into multiple components: command payload, data payload, and associated integrity metadata (CRC bits). Each segment is independently protected and validated, allowing the system to detect faults in specific segments without compromising the entire system. This segmentation makes the security mechanism more robust against targeted fault injection attacks compared to simple parity checking.
Solution Approach 2:
Integrity metadata (CRC bits) is generated and attached to command and data payloads before transmission. This preliminary action ensures that integrity verification is already in place before the data enters the system, allowing early detection of fault injection attacks and preventing compromised data from propagating through the system.
2Reliability
If integrity metadata is generated and validated for all data transmissions, then security against fault injection attacks is improved, but system complexity increases
Solution Approach 1:
The integrity metadata mechanism is designed as a universal solution that can be applied to multiple types of data transmissions throughout the system (commands, responses, data payloads). The same CRC generation and validation logic is reused across different communication paths, reducing the need for separate security mechanisms and thereby limiting the increase in overall system complexity.
Solution Approach 2:
Integrity metadata acts as an intermediary between the transmitted data and the validation logic. Instead of implementing complex validation directly on the data, the CRC bits serve as a mediator that encapsulates the integrity verification function, simplifying the overall system architecture while maintaining robust security.
3Object-affected harmful factors
If data is scrambled before storage in memory, then protection during storage is improved, but processing time increases
Solution Approach 1:
The data is transformed by changing its parameter representation through scrambling (XOR operation with a key). This parameter change protects the stored data from being directly readable or modified by fault injection attacks. The scrambling operation is computationally efficient, minimizing the time penalty while providing strong protection for stored data.
Data Source
AI summary
This document discloses aspects of secure chip-wide communication. In some aspects, a host of a system generates integrity metadata for a command payload issued to a destination over an interconnect of the system. The integrity metadata can be generated based on respective values of bits that form the command payload, such as plaintext data bits. The destination validates the integrity of the command payload based on the integrity metadata before consuming the command payload. In some cases, the destination stores the integrity metadata with data of the command payload, which may be returned to the host along the data when requested. By so doing, the host and destinations of the system can use the integrity metadata to implement secure-chip wide communication, which may prevent fault injection attacks on the command payloads or response data during transit or at temporal storage locations within the system.


