Secure Circuit Timing Delays Against Synchronized Fault Injection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cryptographic hardware is vulnerable to fault attacks where attackers can induce faults to obtain secret information, such as cryptographic keys, by correlating the effects of faults on electronic systems, and current countermeasures like Triple Modular Redundancy (TMR) come with high area and power dissipation penalties.

Innovation Solution

Implementing a secure circuit with redundant secure instances and additional delays, where the delay values N and M are randomly selected and periodically changed, ensuring that the total delay remains constant, making it difficult for attackers to synchronize faults across multiple instances.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If Triple Modular Redundancy (TMR) is used to protect against fault attacks, then security against fault attacks is improved, but area and power dissipation increase significantly

Engineering Contradiction:
Improvesecurity against fault attacksVSAvoidcircuit area
Core Design Contradiction:
ReliabilityVSArea of stationary object

Solution Approach 1:

The patent applies dynamics by making the delay values N and M variable rather than fixed. The delay circuits use different delay values in different time periods, and these values are randomly selected and periodically changed. This dynamic behavior prevents attackers from synchronizing faults across multiple instances because the timing relationships constantly change, while still maintaining the security benefits of redundancy without the full area overhead of static TMR

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameter of delay values from fixed to variable. By randomly selecting and periodically changing delay values N and M while maintaining a constant total delay (N+M=x), the system creates unpredictable timing variations that thwart fault synchronization attacks. This parameter change allows the circuit to maintain security with reduced area compared to traditional TMR

Inventive Principle:
Principle #35Parameter changes

2Reliability

If Triple Modular Redundancy (TMR) is used to protect against fault attacks, then security against fault attacks is improved, but power dissipation increases significantly

Engineering Contradiction:
Improvesecurity against fault attacksVSAvoidpower dissipation
Core Design Contradiction:
ReliabilityVSUse of energy by stationary object

Solution Approach 1:

The dynamic delay values cause the redundant circuits to operate at different times and with different timing characteristics. This reduces the simultaneous switching activity that causes power consumption in static TMR implementations, while still providing the fault detection and prevention capabilities needed for security

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

By varying the delay parameters N and M randomly and periodically, the system changes the operational timing of redundant circuits. This parameter variation reduces peak power consumption and average power dissipation compared to fixed TMR, while maintaining the security against fault attacks through the unpredictable timing that prevents fault synchronization

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If fixed delay values are used in redundant circuits, then circuit operation is simplified, but attackers can synchronize faults across multiple instances

Engineering Contradiction:
Improvecircuit operationVSAvoidprotection against synchronized fault attacks
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements dynamics by making delay values change over time rather than remain fixed. The delay circuits periodically change their delay values according to a random selection process, which maintains relatively simple circuit operation while effectively preventing fault synchronization attacks through the time-varying behavior

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent applies periodic action by having the delay values change periodically rather than remaining constant. The random delay values are updated at regular intervals, creating a periodic pattern that is simple to implement but effective at preventing attackers from establishing consistent timing relationships for fault synchronization across multiple circuit instances

Inventive Principle:
Principle #19Periodic action

Data Source

PatentEP3582434B1Fault attack protection against synchronized fault injections
Publication Date: 2022.01.12 NXP BV
  • EP3582434B1 patent drawingFigure 1~2
  • EP3582434B1 patent drawingFigure 3

AI summary

Various embodiments relate to a circuit, including: a first secure circuit configured to receive an input and to produce a first output; a first delay circuit configured to receive the first output and to produce a first delayed output delayed by a time N; a second delay circuit configured to receive the input and to produce a delayed input delayed by a time N; a second secure circuit configured to receive the delayed input and to produce a second delayed output; and a comparator configured to compare the first delayed output to the second delayed output and to produce a result, wherein the result is one of the first delayed output or second delayed output when the first delayed output matches the second delayed output and the result is an error value when the first delayed output does not match the second delayed output.