Semiconductor Boot Address Tampering Check

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Fault injection attacks can tamper with the secure boot address in semiconductor devices, preventing authentication and allowing unauthorized programs to execute.

Innovation Solution

A semiconductor device with a processor unit, memory, reset controller, and address check unit that verifies the secure boot address after reset, outputting an error signal if tampered with, ensuring only the correct secure boot program is executed.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If an address switching circuit is used to select boot addresses from external ROM or holding RAM, then the device can return from low power consumption mode to normal operation mode, but the secure boot address can be tampered with by fault injection attack

Engineering Contradiction:
Improveability to return from low power consumption modeVSAvoidsecurity of boot address
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies preliminary action by performing a tampering check on the boot address before the processor executes the boot program. The address check unit verifies the integrity of the boot address output from the reset controller, and only if the check passes does the processor proceed to execute the boot program from the selected address. This preliminary verification prevents fault injection attacks from successfully tampering with the boot address, while still allowing the device to return from low power consumption mode using the address switching circuit.

Inventive Principle:
Principle #10Preliminary action

2Object-affected harmful factors

If noise is intentionally injected into the semiconductor device, then the device may malfunction and avoid security mechanism, but the secure boot mechanism can detect and prevent unauthorized program execution

Engineering Contradiction:
Improvefault injection attackVSAvoidsecurity mechanism
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The patent implements feedback by introducing an address check unit that provides feedback on the integrity of the boot address. The address check unit continuously monitors the boot address output from the reset controller and compares it against expected values or integrity checks. If tampering is detected (indicating successful fault injection), the address check unit generates an error signal that prevents the processor from executing the boot program, thereby maintaining the security mechanism despite the fault injection attack.

Inventive Principle:
Principle #23Feedback

3Object-generated harmful factors

If the boot address is tampered with, then unauthorized programs can be executed, but the address check unit detects and prevents this

Engineering Contradiction:
Improveunauthorized program executionVSAvoidauthentication verification
Core Design Contradiction:
Object-generated harmful factorsVSReliability

Solution Approach 1:

The patent uses an intermediary approach by introducing the address check unit as a mediator between the reset controller and the processor. The address check unit sits in the signal path and verifies the boot address before it reaches the processor. This intermediary component detects tampering attempts and prevents unauthorized programs from being executed by blocking the corrupted boot address from reaching the processor, thereby maintaining authentication verification reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12050921B2Semiconductor device
Publication Date: 2024.07.30 RENESAS ELECTRONICS CORP
  • US12050921B2 patent drawing
  • US12050921B2 patent drawing
  • US12050921B2 patent drawing

AI summary

A semiconductor device includes a processor unit, a memory storing a boot program, a reset controller and an address check unit. The reset controller controls a reset for the processor unit based on a reset request and outputs a boot address for the boot program to be executed after reset release to the processor unit. The address check unit performs a tampering check for the boot address output from the reset controller and outputs a boot address error signal based on a tampering check result.