Security Processing Device Dynamic Instruction Timing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional methods for preventing side-channel attacks and fault injection in chips often disrupt system operation by resetting the system or clearing keys, which are not effective in preventing hacker access to confidential data without causing operational issues.
Innovation Solution
A security processing device with an attack detector, programming time controller, and non-volatile memory that adjusts the instruction cycle of a processing unit by updating flag values to prevent hackers from obtaining keys, allowing the system to operate securely without clearing the key.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the system is reset when an attack event is detected, then the security against fault injection is improved, but the system operation is disrupted and productivity deteriorates
Solution Approach 1:
The patent applies dynamics by making the instruction cycle time variable rather than fixed. The processing unit dynamically adjusts the instruction cycle time based on detected attack patterns, extending it when attacks are detected and restoring it when normal operation is confirmed. This dynamic adaptation allows the system to maintain security responses without continuous resets, preserving operational continuity while responding to threats.
Solution Approach 2:
The patent changes the parameter of instruction cycle time from a constant value to a variable parameter that can be adjusted based on security conditions. By modifying this temporal parameter in response to attack detection, the system achieves security enhancement without system-wide reset, thus maintaining productivity while improving reliability against fault injection attacks.
2Loss of information
If the key is cleared when an attack event is detected, then the confidentiality of confidential data is improved, but the system loses protection and reliability deteriorates
Solution Approach 1:
The patent extracts the security response mechanism from the key clearance approach. Instead of clearing the key entirely, the system isolates and responds to attack attempts by adjusting instruction cycle times for specific operations. This extraction allows the key to remain intact and functional while still providing security against fault injection, preventing both information leakage and loss of protection capability.
3Reliability
If the instruction cycle is extended to prevent key analysis, then the security against side-channel attack is improved, but the processing speed deteriorates
Solution Approach 1:
The patent applies dynamics by making the instruction cycle time variable rather than fixed. The processing unit dynamically adjusts the instruction cycle time based on detected attack patterns, extending it when attacks are detected and restoring it when normal operation is confirmed. This dynamic adaptation allows the system to maintain security responses without continuous resets, preserving operational continuity while responding to threats.
Solution Approach 2:
The patent implements periodic action by repeatedly adjusting the instruction cycle time in response to attack detection events. The system periodically monitors for attacks and applies timing extensions only when necessary, then restores normal timing. This periodic adjustment strategy maintains security against side-channel attacks while minimizing the impact on overall processing speed by not continuously extending cycles.
Data Source
AI summary
A security processing device for handling attacks including an attack detector, a programing time controller, a non-volatile memory device and a processing unit. The attack detector is used to detect whether an attack event occurs, and generate an attack trigger signal when the attack event occurs. The programing time controller is electrically connected to the attack detector, and used to update a first flag value when receiving the attack trigger signal. The non-volatile memory device is electrically connected to the program time controller, and used to store the first and the second flag values. The processing unit is electrically connected to the program time controller. When the security processing device is reset or boot-up, the programing time controller updates the second flag value and adjusts a time of a first instruction processed through the processing unit based on the first flag value and the second flag value.


