Shadow Register Attack Detector Architecture for Laser Fault Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional attack detection circuits in circuit designs are area inefficient and performance deficient, leading to increased costs and inefficiencies in detecting malicious laser attacks, which can disable security mechanisms and induce faults in chip modules.
Innovation Solution
Implementing an attack detector architecture that uses shadow registers configured to detect fault-inducing attacks, such as optical attacks, by generating an alarm signal when a malicious attack is detected, with logic gates and shadow registers arranged to minimize impact on power, performance, and area (PPA) in physical circuit designs, and integrating this architecture with computing circuitry for various applications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional attack detection circuits are implemented, then malicious attacks can be detected, but area efficiency deteriorates and performance is deficient
Solution Approach 1:
The patent creates shadow copies of critical registers (shadow registers) that mirror the functionality of original registers. These shadow registers are used solely for attack detection purposes, allowing the system to compare expected vs. actual register states without modifying the original register functionality. This copying approach enables attack detection while minimizing area overhead by reusing the same physical register structures for dual purposes.
Solution Approach 2:
The attack detector circuit is designed to perform multiple functions: it detects laser attacks on registers, monitors for fault injection attempts, and provides alarm signaling. By making the detector circuit multi-functional, the patent reduces the need for separate dedicated circuits for each function, thereby improving area efficiency while maintaining comprehensive attack detection capabilities.
2Reliability
If conventional attack detection circuits are implemented, then attack detection is achieved, but performance is deficient
Solution Approach 1:
The shadow registers are pre-configured with expected values during normal operation, and the attack detector is continuously monitoring for discrepancies. This preliminary setup allows the detector to immediately identify attacks without requiring complex real-time analysis, thereby maintaining high performance while ensuring reliable detection.
Solution Approach 2:
The patent replaces complex mechanical or logic-intensive attack detection mechanisms with simpler comparison-based detection using shadow registers. By substituting elaborate detection logic with straightforward register value comparisons, the system achieves reliable attack detection with minimal performance impact on the main circuit operations.
3Object-affected harmful factors
If attack detector circuits are added to enhance security, then protection against laser attacks is improved, but area efficiency worsens
Solution Approach 1:
The patent uses shadow registers as simplified copies of critical registers specifically for attack detection. These shadow copies require minimal additional area compared to full redundant register sets, yet provide sufficient protection against laser attacks by enabling comparison of expected vs. actual register states.
Solution Approach 2:
The attack detection mechanism is applied selectively to only those registers that are critical for security operations, rather than duplicating all registers in the system. This localized approach to attack detection provides adequate protection against laser attacks while minimizing the overall area overhead of the detector circuit.
Data Source
AI summary
Various implementations described herein refer to a device having base registers that receive input signals, receive a reset signal and provide first output signals based on the input signals and the reset signal. The device may have shadow registers that correspond to the base registers, wherein the shadow registers receive inverted input signals, receive an inverted reset signal and provide second output signals based on the inverted input signals and the inverted reset signal. The device may have attack detector logic that receives the first output signals from the base registers, receives the second output signals from the shadow registers and generates an alarm signal based on the first output signals and the second output signals.


