Secure Clock Switch Circuit for IC Boot Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional clock switches lack security features, making them vulnerable to hacker attacks that can manipulate the system clock and corrupt device configuration data, leading to unauthorized access to secure data stored on chip.

Innovation Solution

An integrated circuit (IC) with a clock switch that selectively chooses between an internal and external clock based on the completion of device configuration download and the IC's life-cycle state, incorporating security features to prevent unauthorized access by ensuring secure clock switching.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a conventional clock switch is used to switch between internal and external clocks, then clock switching functionality is provided, but security vulnerabilities arise that allow hackers to manipulate the system clock and corrupt device configuration data

Engineering Contradiction:
ImprovesecurityVSAvoidclock switch circuit
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by performing device configuration download and security state establishment before allowing external clock usage. The clock switch circuit is designed to prevent external clock selection during the configuration download phase, ensuring that security settings are established before the system becomes vulnerable to clock manipulation attacks.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary control mechanism that mediates between the clock switch functionality and security requirements. This intermediary layer monitors the device configuration state and selectively enables or disables external clock input based on whether configuration download is complete, thereby protecting against security threats while maintaining clock switching capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If the external clock is allowed to be used during device configuration download, then clock switching flexibility is improved, but the system becomes vulnerable to attacks that can corrupt configuration data and compromise security

Engineering Contradiction:
Improveclock switching flexibilityVSAvoidsecurity attacks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary anti-action by proactively preventing external clock input during the device configuration download phase. The clock switch circuit is designed to block external clock signals when the configuration is not complete, thereby preemptively countering potential security attacks before they can occur.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The patent implements dynamic clock switch behavior that adapts based on the device configuration state. The external clock enablement is not static but dynamically controlled according to whether configuration download is complete, allowing flexible clock switching when safe and preventing it when vulnerable.

Inventive Principle:
Principle #15Dynamics

3Reliability

If security features are added to the clock switch to prevent unauthorized access, then security is improved, but the circuit complexity and design difficulty increase

Engineering Contradiction:
ImprovesecurityVSAvoidclock switch circuit
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the security control logic with the existing clock switch circuit rather than adding completely separate security mechanisms. The configuration state monitoring and external clock enablement control are integrated into the clock switch architecture, achieving security enhancement while minimizing additional circuit complexity.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9891654B2Secure clock switch circuit
Publication Date: 2018.02.13 NXP USA INC
  • US9891654B2 patent drawing
  • US9891654B2 patent drawing
  • US9891654B2 patent drawing

AI summary

An integrated circuit (IC) having a clock switch that switches the system clock between an internal clock and an external clock based on whether or not the IC has finished downloading device configuration at boot and on whether or not the internal clock is functional. Further restrictions on the use of the external clock are imposed by the clock switch based on a life-cycle state of the IC. The use of the clock switch makes it significantly more difficult for the clock to be tampered with, thereby protecting the security settings of the IC and/or preventing unauthorized access to secure data stored on the IC using an external-clock-based security attack.