Storage Device Preloading Stage for Fault Injection Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Special function registers in storage devices are vulnerable to fault injection attacks, and traditional security measures like end-to-end integrity concepts are resource-intensive and costly for most peripherals.
Innovation Solution
A storage device with a preloading stage that verifies the integrity of data by calculating and comparing checksums in multiple preload registers before loading data into special function registers, enhancing resilience against fault injection attacks with a virtual end-to-end integrity concept.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional end-to-end integrity concepts are applied to protect special function registers, then security against fault injection attacks is improved, but resource consumption and cost increase significantly
Solution Approach 1:
The patent applies preliminary action by performing integrity verification in advance through a preloading stage. Data is loaded into preload registers and verified using checksums before being transferred to special function registers. This proactive verification prevents faulty data from reaching the vulnerable registers, providing security without requiring full end-to-end integrity mechanisms throughout the entire system.
2Measurement precision
If checksum verification is performed on preloaded data, then detection of faulty data is improved, but device complexity increases due to additional preload registers and verification logic
Solution Approach 1:
The patent applies segmentation by dividing the data path into distinct stages: a preloading stage with preload registers for verification, and the execution stage with special function registers. This segmentation isolates the verification logic to a specific segment (the preloading stage), allowing checksum verification to be performed on subsets of data without complicating the entire system architecture.
Solution Approach 2:
The patent uses preload registers as intermediary structures between the data source and the special function registers. These intermediary registers serve as a buffer where data can be verified using checksums before being committed to the final destination. This intermediary layer enables detection of faulty data without requiring direct modification of the special function registers themselves.
3Reliability
If data is verified before loading into special function registers, then likelihood of successful fault injection attacks is reduced, but loading time increases due to verification steps
Solution Approach 1:
The verification process is performed in advance during the preloading stage, before data is committed to the special function registers. By calculating and verifying checksums on preload registers beforehand, the system ensures that only verified data is transferred to the final destination, reducing the risk of fault injection attacks while maintaining efficient data flow.
Data Source
AI summary
In accordance with a first aspect of the present disclosure, a storage device is provided, comprising: one or more special function registers; a preloading stage comprising a first preload register, wherein the preloading stage is configured to preload data in the first preload register before loading the preloaded data into the special function registers; wherein the preloading stage is further configured to perform a verification of the integrity of the preloaded data before loading said preloaded data into the special function registers. In accordance with a second aspect of the present disclosure, a corresponding method of operating a storage device is conceived.


