SoC Security Firewalls Using Multi-Bit Validation Against Fault Attacks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Embedded devices in industrial and automotive applications are vulnerable to fault attacks, which can compromise their security and integrity by causing unintended errors, allowing access to critical information or disabling protection mechanisms.
Innovation Solution
A fault-tolerant security architecture is implemented using a system-on-chip (SoC) with hardware countermeasures, including a processor, firewalls, and a security manager that employs multi-bit values and validation bits to protect against fault attacks, and a reset circuitry that ensures reliable power-on reset signals to prevent vulnerabilities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If fault attacks are launched against embedded devices, then security vulnerabilities are exploited, but device integrity and trustworthiness are compromised
Solution Approach 1:
The security architecture is segmented into multiple independent firewalls (first firewall, second firewall) that operate separately to provide layered protection. Each firewall handles specific security checks, and the segmentation allows the system to maintain integrity even if one firewall is compromised by a fault attack.
Solution Approach 2:
The system performs preliminary security validation by checking relationships between adjacent bits in security values before allowing operations to proceed. The firewalls are configured in advance with security parameters, and bit relationship validations are performed proactively to prevent fault attacks rather than reacting to them after occurrence.
2Reliability
If multi-bit security values are used to protect against fault attacks, then security validation is improved, but device complexity increases
Solution Approach 1:
The security manager implements local quality by treating different bit positions within security values differently. Specific bits are designated for validation purposes while others carry security information. This localized differentiation allows efficient validation without requiring complete reconfiguration of the entire device architecture.
Solution Approach 2:
The security manager acts as an intermediary between the firewalls and the rest of the device. It manages the complex register configurations and bit relationship validations centrally, shielding other parts of the device from the complexity while maintaining robust security validation through multi-bit values.
3Adaptability or versatility
If firewalls are configured with bypass mode capability, then operational flexibility is improved, but security protection may be weakened
Solution Approach 1:
The firewalls are designed with dynamic operation modes that can switch between normal security enforcement and bypass modes based on validated security conditions. The bypass mode is not static but is dynamically enabled only when bit relationship validations confirm legitimate operations, providing flexibility without permanently weakening security.
Solution Approach 2:
The system uses feedback mechanisms where the security manager continuously monitors bit relationships in security values and provides feedback to the firewalls about whether to enforce security checks or allow bypass mode. This feedback loop ensures that bypass capability is exercised only when security validation confirms it is safe to do so.
Data Source
AI summary
A system, e.g., system-on-chip (SoC), is provided that includes security control registers that include security flags for security critical assets of the SoC, in which each security flag includes multiple bits. In an example, a system includes a processor; a set of devices including a first device that includes a set of registers; and a set of firewalls, each configured to couple the processor to a respective device of the set of devices. The set of registers stores a first value determined by a plurality of bits, and the first device determines whether to cause a first firewall of the set of firewalls to operate in a bypass mode based on a relationship between values of adjacent bits of the first value.


