Security Processing Device Dynamic Instruction Timing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for preventing side-channel attacks and fault injection in chips often disrupt system operation by resetting the system or clearing keys, which are not effective in preventing hacker access to confidential data without causing operational issues.

Innovation Solution

A security processing device with an attack detector, programming time controller, and non-volatile memory that adjusts the instruction cycle of a processing unit by updating flag values to prevent hackers from obtaining keys, allowing the system to operate securely without clearing the key.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the system is reset when an attack event is detected, then the security against fault injection is improved, but the system operation is disrupted and productivity deteriorates

Engineering Contradiction:
Improvesecurity against fault injectionVSAvoidsystem operation continuity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies dynamics by making the instruction cycle time variable rather than fixed. The processing unit dynamically adjusts the instruction cycle time based on detected attack patterns, extending it when attacks are detected and restoring it when normal operation is confirmed. This dynamic adaptation allows the system to maintain security responses without continuous resets, preserving operational continuity while responding to threats.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameter of instruction cycle time from a constant value to a variable parameter that can be adjusted based on security conditions. By modifying this temporal parameter in response to attack detection, the system achieves security enhancement without system-wide reset, thus maintaining productivity while improving reliability against fault injection attacks.

Inventive Principle:
Principle #35Parameter changes

2Loss of information

If the key is cleared when an attack event is detected, then the confidentiality of confidential data is improved, but the system loses protection and reliability deteriorates

Engineering Contradiction:
Improveconfidential data protectionVSAvoidsystem protection capability
Core Design Contradiction:
Loss of informationVSReliability

Solution Approach 1:

The patent extracts the security response mechanism from the key clearance approach. Instead of clearing the key entirely, the system isolates and responds to attack attempts by adjusting instruction cycle times for specific operations. This extraction allows the key to remain intact and functional while still providing security against fault injection, preventing both information leakage and loss of protection capability.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If the instruction cycle is extended to prevent key analysis, then the security against side-channel attack is improved, but the processing speed deteriorates

Engineering Contradiction:
Improvesecurity against side-channel attackVSAvoidinstruction processing speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent applies dynamics by making the instruction cycle time variable rather than fixed. The processing unit dynamically adjusts the instruction cycle time based on detected attack patterns, extending it when attacks are detected and restoring it when normal operation is confirmed. This dynamic adaptation allows the system to maintain security responses without continuous resets, preserving operational continuity while responding to threats.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent implements periodic action by repeatedly adjusting the instruction cycle time in response to attack detection events. The system periodically monitors for attacks and applies timing extensions only when necessary, then restores normal timing. This periodic adjustment strategy maintains security against side-channel attacks while minimizing the impact on overall processing speed by not continuously extending cycles.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS20240126874A1Security processing device, method and electronic device for handling attacks
Publication Date: 2024.04.18 NUVOTON
  • US20240126874A1 patent drawing
  • US20240126874A1 patent drawing
  • US20240126874A1 patent drawing

AI summary

A security processing device for handling attacks including an attack detector, a programing time controller, a non-volatile memory device and a processing unit. The attack detector is used to detect whether an attack event occurs, and generate an attack trigger signal when the attack event occurs. The programing time controller is electrically connected to the attack detector, and used to update a first flag value when receiving the attack trigger signal. The non-volatile memory device is electrically connected to the program time controller, and used to store the first and the second flag values. The processing unit is electrically connected to the program time controller. When the security processing device is reset or boot-up, the programing time controller updates the second flag value and adjusts a time of a first instruction processed through the processing unit based on the first flag value and the second flag value.