SoC Boot Power Measurement for Device Key Reconstruction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for securing system on chip (SoC) devices, such as data encryption and intrinsic security based on manufacturing imperfections, are either resource-intensive or become obsolete if the encryption key leaks or the storage is read out.

Innovation Solution

A method that measures and verifies the unique power characteristic data of a processor during booting to derive a device key, allowing secure execution of software without on-chip stored secrets, and includes a bootloader that resets the processor if interference is detected, with optional measures like automatic restart and memory erasure to prevent unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data encryption is used to secure memory content, then confidentiality is improved, but the protection becomes obsolete if the encryption key leaks or storage is read out

Engineering Contradiction:
Improveconfidentiality protectionVSAvoidprotection obsolescence
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The invention extracts the secret key material from the chip storage and replaces it with publicly stored helper data. The actual device key is never stored on-chip but reconstructed dynamically using power measurement characteristics, eliminating the vulnerability of stored secrets while maintaining encryption capability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The invention introduces power measurement characteristics as an intermediary between the helper data and the device key. This mediator enables key reconstruction without directly storing the key, adding a layer of security that prevents both key leakage and storage readout attacks.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If intrinsic security based on manufacturing imperfections is used, then device-unique identification is improved, but extensive engineering and resources are required

Engineering Contradiction:
Improvedevice-unique identificationVSAvoidengineering resources
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The invention copies the idea of using physical characteristics for identification but simplifies it by using power consumption measurements during boot instead of complex manufacturing imperfections. This approach achieves device uniqueness with significantly reduced engineering complexity and resource requirements.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The invention replaces the mechanical/physical approach of exploiting manufacturing imperfections with an electrical measurement approach using power consumption analysis. This substitution maintains the ability to derive unique device characteristics while greatly simplifying the implementation requirements.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If the bootloader is reset upon detecting interference, then security is improved by stopping attacks, but normal operation may be interrupted by singular problems

Engineering Contradiction:
Improvesecurity protectionVSAvoidoperation continuity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The invention implements a dynamic response system that adapts to the situation: it allows multiple reset attempts for transient errors but blocks after a threshold of failures is reached. This dynamic behavior provides both security against persistent attacks and tolerance for singular operational problems.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The invention uses periodic reset attempts with a defined maximum number of repetitions. This periodic action allows the system to recover from transient interference while ultimately blocking persistent attacks, balancing security and operational continuity.

Inventive Principle:
Principle #19Periodic action

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This solution provides robust protection against attacks by using a unique power signature to secure software execution, preventing data readout and ensuring secure operation through automatic detection and response to potential threats.

Implementation Method 1

measuring electrical power consumed by the processor during booting in order to derive a unique power characteristic data

Methodology Applied
Scientific EffectPower consumption measurement:

Data Source

PatentUS10459732B2Method for operating a system on chip comprising a bootable processor to provide protection of confidential information on the system on chip
Publication Date: 2019.10.29 SIEMENS AG
  • US10459732B2 patent drawing
  • US10459732B2 patent drawing
  • US10459732B2 patent drawing

AI summary

A method for operating a system on chip (SoC) comprising a bootable processor, wherein the method includes executing a bootloader and measuring electrical power consumed by the processor during booting to derive a unique power characteristic data, verifying the unique power characteristic data, and reconstructing an device key from the unique power characteristic data and helper dater derived during an enrollment of the system on chip, where the measured power trace of the processor constitutes a unique signature of the SoC device executing specified software such that the solution secures the running software by itself.