Shared Clock Counter Offset for Timing Attack Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing digital processing systems face challenges in protecting against timing attacks, where the execution times of secured tasks can be exploited by non-secured operating systems due to shared clock resources, especially when a hardware clock dedicated to each operating system is not feasible.

Innovation Solution

A method and system that share a single hardware clock signal between secured and non-secured operating systems by using a timer with an offset value for each counter, ensuring that the execution times of tasks are unexploitable, achieved by updating the second counter with a value different from the first counter, selected randomly, to prevent exposure of sensitive information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If a single hardware clock is shared between secured and non-secured operating systems, then device complexity is reduced, but security is compromised due to timing attacks

Engineering Contradiction:
Improveclock system complexityVSAvoidsecurity against timing attacks
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent introduces an intermediary mechanism (offset value) between the shared hardware clock and the counters used by different operating systems. This offset acts as a mediator that decouples the timing information visible to non-secured systems from the actual execution timing, thereby preventing timing attacks while maintaining a single shared clock hardware resource.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the parameter of counter values by introducing random offset values that are added to the actual clock cycles. This parameter transformation ensures that the counter values visible to non-secured operating systems do not reflect the true execution timing of secured tasks, thus maintaining security without requiring separate hardware clocks.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If separate hardware clocks are provided for secured and non-secured operating systems, then security against timing attacks is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity against timing attacksVSAvoidclock system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent makes a single hardware clock serve multiple functions by enabling it to securely support both secured and non-secured operating systems simultaneously. Through the offset mechanism, one clock resource achieves what would traditionally require separate clocks, demonstrating multi-functionality that reduces device complexity while maintaining security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If counter values are made accessible to non-secured operating systems, then ease of operation is improved, but security is compromised as timing information is exposed

Engineering Contradiction:
Improvecounter accessibilityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The offset value serves as an intermediary layer between the actual counter and the non-secured operating system. This intermediary transforms the counter value before presentation to the non-secured system, maintaining ease of operation (the system can still read counter values) while preventing security compromise (the timing information is obscured by the random offset).

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS7779289B2Methods and data processing systems for sharing a clock between non-secured and secured tasks
Publication Date: 2010.08.17 STMICROELECTRONICS FRANCE
  • US7779289B2 patent drawing
  • US7779289B2 patent drawing
  • US7779289B2 patent drawing

AI summary

A method and a system of sharing of a clock by an electronic circuit between at least one first task clocked by at least one first counter and at least one second task clocked by a second counter, the two counters varying at the rate of said clock, the content of the first counter plus or minus an offset value being, on each execution of the second task, assigned to the second counter.