SoC Security Firewalls Using Multi-Bit Validation Against Fault Attacks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Embedded devices in industrial and automotive applications are vulnerable to fault attacks, which can compromise their security and integrity by causing unintended errors, allowing access to critical information or disabling protection mechanisms.

Innovation Solution

A fault-tolerant security architecture is implemented using a system-on-chip (SoC) with hardware countermeasures, including a processor, firewalls, and a security manager that employs multi-bit values and validation bits to protect against fault attacks, and a reset circuitry that ensures reliable power-on reset signals to prevent vulnerabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If fault attacks are launched against embedded devices, then security vulnerabilities are exploited, but device integrity and trustworthiness are compromised

Engineering Contradiction:
Improvedevice integrityVSAvoidfault attack vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The security architecture is segmented into multiple independent firewalls (first firewall, second firewall) that operate separately to provide layered protection. Each firewall handles specific security checks, and the segmentation allows the system to maintain integrity even if one firewall is compromised by a fault attack.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary security validation by checking relationships between adjacent bits in security values before allowing operations to proceed. The firewalls are configured in advance with security parameters, and bit relationship validations are performed proactively to prevent fault attacks rather than reacting to them after occurrence.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If multi-bit security values are used to protect against fault attacks, then security validation is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity validationVSAvoidregister configuration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security manager implements local quality by treating different bit positions within security values differently. Specific bits are designated for validation purposes while others carry security information. This localized differentiation allows efficient validation without requiring complete reconfiguration of the entire device architecture.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The security manager acts as an intermediary between the firewalls and the rest of the device. It manages the complex register configurations and bit relationship validations centrally, shielding other parts of the device from the complexity while maintaining robust security validation through multi-bit values.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If firewalls are configured with bypass mode capability, then operational flexibility is improved, but security protection may be weakened

Engineering Contradiction:
Improvefirewall operation modeVSAvoidsecurity protection
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The firewalls are designed with dynamic operation modes that can switch between normal security enforcement and bypass modes based on validated security conditions. The bypass mode is not static but is dynamically enabled only when bit relationship validations confirm legitimate operations, providing flexibility without permanently weakening security.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system uses feedback mechanisms where the security manager continuously monitors bit relationships in security values and provides feedback to the firewalls about whether to enforce security checks or allow bypass mode. This feedback loop ensures that bypass capability is exercised only when security validation confirms it is safe to do so.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20240370591A1Hardware countermeasures in a fault tolerant security architecture
Publication Date: 2024.11.07 TEXAS INSTRUMENTS INC
  • US20240370591A1 patent drawing
  • US20240370591A1 patent drawing
  • US20240370591A1 patent drawing

AI summary

A system, e.g., system-on-chip (SoC), is provided that includes security control registers that include security flags for security critical assets of the SoC, in which each security flag includes multiple bits. In an example, a system includes a processor; a set of devices including a first device that includes a set of registers; and a set of firewalls, each configured to couple the processor to a respective device of the set of devices. The set of registers stores a first value determined by a plurality of bits, and the first device determines whether to cause a first firewall of the set of firewalls to operate in a bypass mode based on a relationship between values of adjacent bits of the first value.