SoC Clock Source Switching With Glitch Detection and Hidden Crystal Backup

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing clock generation systems in SoCs are vulnerable to tampering and safety failures, which can disrupt the boot process and compromise security or safety.

Innovation Solution

Incorporating a hidden crystal within the SoC package substrate, in addition to an external crystal, and a clock generation circuit that dynamically selects between the two clock sources based on glitch detection and security events.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If an external crystal is used for clock generation, then the clock source is easily accessible and can be tampered with, but the system becomes vulnerable to security attacks and safety failures

Engineering Contradiction:
ImproveAccessibility of clock sourceVSAvoidSecurity and safety of clock signal
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent divides the clock source into two separate crystals: an external crystal accessible from outside the package and an internal crystal embedded within the package substrate. This segmentation allows the system to maintain ease of operation with the external crystal while having a protected internal crystal as a security backup, directly resolving the contradiction between accessibility and security

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a clock selection circuit as an intermediary component that dynamically selects between the external and internal crystal sources based on security conditions. This mediator enables the system to automatically switch from the vulnerable external crystal to the secure internal crystal when tampering is detected, maintaining both accessibility and reliability

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a hidden crystal is added within the package substrate, then a secure backup clock source is provided, but the device complexity increases

Engineering Contradiction:
ImproveBackup clock source availabilityVSAvoidNumber of clock sources and selection circuitry
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent designs the clock selection circuit to perform multiple functions: it monitors the external crystal for tampering, selects between the external and internal crystal sources, and manages the switching operation. This multi-functionality reduces the need for separate dedicated circuits for each task, thereby minimizing the increase in device complexity while providing reliable backup capability

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The internal crystal is pre-configured and ready within the package substrate before any tampering occurs. The clock selection circuit is pre-programmed with the logic to detect security events and automatically switch to the internal crystal. This preliminary preparation ensures that when tampering is detected, the switch to backup occurs immediately without requiring complex real-time decision-making circuitry

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250112627A1Clock generation with glitch detection and handling
Publication Date: 2025.04.03 NXP USA INC
  • US20250112627A1 patent drawing
  • US20250112627A1 patent drawing
  • US20250112627A1 patent drawing

AI summary

In a system on a chip (SoC), clock selection circuitry provides a selected one of a first or second clock signal as an output clock based on at least one of a first flag and a second flag. This output clock is provided as a reference clock to one or more phase locked loops (PLLs) of the SoC. The SoC includes a first clock path which receives a first oscillating signal from a first clock source external to the SoC to generate the first clock signal, and a second clock path which receives a second oscillating signal from a second clock source external to the SoC to generate the second clock signal. A first glitch monitor asserts the first flag when a glitch is detected in the first oscillating signal, and a second glitch monitor configured asserts the second flag when a glitch is detected in the second oscillating signal.