Simulation Code for Fault Injection Attack Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods are inadequate in countering fault injection attacks that modify executable or interpretable code, particularly in smart cards, as they fail to effectively predict and mitigate the effects of such attacks on sensitive instructions and memory registers.
Innovation Solution
A method and system that simulate the effects of fault injection attacks by generating and executing 'simulation' code, which represents the result of attacks on sensitive instructions, allowing analysis of register values to identify and assess potential security breaches, and enabling countermeasures to be applied.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Object-affected harmful factors
If fault injection attacks are performed on embedded circuits to modify code or variable values, then access to sensitive memory registers or execution of restricted instructions may be obtained, but the ability to predict and detect security breaches becomes difficult
Solution Approach 1:
The patent applies preliminary action by generating simulation code that represents potential attack scenarios before actual attacks occur. The system pre-identifies sensitive instructions and creates corresponding simulation code that models various fault injection effects, allowing security analysis to be performed in advance on simulated attack outcomes rather than waiting for actual attacks to detect vulnerabilities.
Solution Approach 2:
The patent uses copying by creating simulation code that replicates the behavior and structure of the original target code but incorporates simulated attack effects. This copy allows security analysts to study attack scenarios without executing them on the actual system, preserving the original code while enabling comprehensive security testing through the simulated version.
2Reliability
If methods are used to detect vulnerabilities in software and correct them, then secure code can be generated, but the methods are not suitable for countering attacks with difficult to predict effects
Solution Approach 1:
The patent applies dynamics by making the simulation code generation process adaptive and flexible. The system dynamically creates different simulation code variants based on various attack scenarios, allowing it to adapt to diverse and unpredictable attack patterns. The simulation framework can be configured to model different types of faults and attack vectors, providing versatile security testing capability.
Solution Approach 2:
The patent uses parameter changes by modifying code parameters and execution conditions in the simulation code to represent various attack effects. By changing parameters such as variable values, instruction outcomes, and execution flow in the simulated environment, the system can model different attack scenarios and analyze their potential impacts on security-sensitive operations.
3Measurement precision
If simulation code representing attack effects is generated and executed, then the effects of attacks on memory registers can be analyzed, but the system complexity increases
Solution Approach 1:
The patent applies segmentation by dividing the security analysis process into distinct phases: identifying sensitive instructions, generating simulation code for each attack scenario, executing simulations, and analyzing results. This segmentation allows the complex task of security testing to be broken down into manageable, modular steps that can be performed systematically.
Solution Approach 2:
The patent uses an intermediary approach by introducing simulation code as a mediator between the original target code and the security analysis process. The simulation code acts as an intermediate representation that captures attack effects without requiring direct modification or execution on the actual system, enabling safe and precise analysis of potential security breaches.
Data Source
AI summary
Methods and systems of simulating the effects of an attack seeking fraudulently to modify target code that is interpretable by a processor are disclosed. Various implementations may include means and operations for searching for a set of sensitive instructions in the target code; generating an interpretable “simulation” code having instructions representing the result of said attack on the set of instructions; selecting memory registers that might be accessed during the interpretation of the simulation code; interpreting at least a portion of the simulation code; and storing at least one value of the registers during the interpretation in order to enable the effects of the attack to be analyzed.


