Smart Card Storage Element for Light Pulse Attack Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Control registers in integrated circuit cards are vulnerable to attacks using light pulses that can modify bit values, and existing solutions like doubling the registers to detect inconsistencies are costly in terms of silicon surface area.

Innovation Solution

A storage element that detects attacks on validation or internal signals by generating secure validation signals and switching signals, preventing data storage during attacks and triggering security actions, thereby optimizing the silicon surface area required for protection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If control registers are doubled to detect inconsistencies from light pulse attacks, then security against attacks is improved, but silicon surface area increases

Engineering Contradiction:
Improvesecurity against light pulse attacksVSAvoidsilicon surface area
Core Design Contradiction:
ReliabilityVSArea of stationary object

Solution Approach 1:

The invention segments the protection mechanism by dividing control registers into groups where each group shares a common validation signal. This allows multiple registers to be protected without duplicating protection logic for each register, thereby reducing the overall silicon surface area while maintaining security against light pulse attacks.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The invention introduces a validation signal as an intermediary between the control register and the data storage elements. This validation signal acts as a mediator that detects light pulse attacks and prevents unauthorized data modification, providing security without requiring doubled register structures.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Difficulty of detecting and measuring

If additional validation logic is added to detect attacks on validation signals, then detection capability is improved, but device complexity increases

Engineering Contradiction:
Improveattack detection capabilityVSAvoidlogic gate complexity
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The validation signal serves multiple functions: it enables normal data storage operations, detects light pulse attacks on the validation signal itself, and triggers security responses. This multi-functionality improves detection capability without proportionally increasing device complexity, as the same signal structure is reused for multiple purposes.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The invention implements feedback mechanisms where the validation signal monitors the state of control registers and triggers appropriate responses when attacks are detected. This feedback loop enables automatic detection and response to attacks without requiring complex external monitoring circuits.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP2424110B1Securisation of an element for storing binary data, check register and a smart card
Publication Date: 2013.04.24 OBERTHUR TECH SA
  • EP2424110B1 patent drawingFigure 1~3
  • EP2424110B1 patent drawingFigure 4~6
  • EP2424110B1 patent drawingFigure 7~9

AI summary

The element (60) has an input unit for inputting signal representing binary data, and a unit for providing output signal (Q) whose state represents data stored in the element. A detecting unit detects a service attack of validation signal (ENA) or signal internal to the element. A terminal receives the validation signal. A generating unit generates switching signal (S2) whose state represents switching of the output signal from a low state to an upper state.