SoC Security Flag Architecture for Fault Attack Resistance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Embedded devices in industrial and automotive applications are vulnerable to fault attacks that compromise their integrity and security, as existing technologies lack effective countermeasures against manipulation attempts that disrupt their operation and access security-critical information.

Innovation Solution

A system-on-chip (SoC) with a fault-tolerant security architecture is implemented, featuring security control registers with multi-bit security flags, an eFuse controller for configuration storage, and a device management security controller that manages security settings and protects against fault attacks by using validation bits and multi-bit values to prevent single-bit flipping vulnerabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If single-bit security flags are used in security control registers, then the device complexity is reduced and ease of manufacture is improved, but the device becomes vulnerable to fault attacks where single-bit flipping can compromise security-critical assets

Engineering Contradiction:
Improvesecurity integrityVSAvoidsecurity flag structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security flag is segmented into multiple bits (e.g., 4 bits) where each bit represents a different security attribute or permission level. This segmentation allows the system to detect faults by verifying the consistency of multiple bits rather than relying on a single bit, thereby improving security integrity while maintaining manageable complexity through structured organization.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the parameter of security flag representation from single-bit to multi-bit values. By using multi-bit security flags with defined valid states (e.g., specific binary combinations representing different security levels), the system increases reliability against fault attacks while the complexity remains controlled through well-defined state transitions and validation rules.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If multi-bit security flags are implemented to prevent fault attacks, then security integrity is improved, but the device complexity and manufacturing difficulty increase

Engineering Contradiction:
Improvefault toleranceVSAvoidsecurity architecture implementation
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The security flag values are pre-configured and validated during device initialization or manufacturing. The system establishes valid multi-bit states beforehand and uses these predefined states to protect against faults during operation. This preliminary action simplifies manufacturing by allowing validation logic to be built-in during production rather than requiring complex runtime verification mechanisms.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses redundant copying of security information across multiple bits where each bit or group of bits represents the same or related security attribute. This copying approach allows fault detection through comparison and validation of the copied values, improving fault tolerance while keeping the implementation straightforward through repeated patterns rather than complex unique logic.

Inventive Principle:
Principle #26Copying

3Reliability

If validation mechanisms for multi-bit security flags are added, then protection against fault attacks is enhanced, but the processing time and operational complexity increase

Engineering Contradiction:
Improvesecurity validationVSAvoidsecurity flag verification
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The validation of multi-bit security flags is performed periodically at key system events (e.g., power-on reset, mode transitions, or scheduled intervals) rather than continuously during every operation. This periodic validation approach maintains security integrity by checking security states at critical moments while minimizing time loss during normal operations where the security state is assumed to be valid.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The security validation mechanism is designed to be self-servicing through automatic detection of invalid multi-bit states and automatic triggering of security responses. The system monitors its own security flag states and autonomously validates them without requiring extensive external intervention or complex processing, thereby reducing the time overhead while maintaining reliable security validation.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11080432B2Hardware countermeasures in a fault tolerant security architecture
Publication Date: 2021.08.03 TEXAS INSTRUMENTS INC
  • US11080432B2 patent drawing
  • US11080432B2 patent drawing
  • US11080432B2 patent drawing

AI summary

A system-on-chip (SoC) is provided that includes security control registers, the security control registers including security flags for security critical assets of the SoC, wherein each security flag includes multiple bits. A set of security critical bits is signaled from a configuration storage of the SoC with a set of validation bits to be used to validate the set of security critical bits.