Variable Delay Circuit for On-Chip Authentication Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems on a chip are vulnerable to fault injection attacks due to fixed delays in processing units, making it easy for attackers to determine the delay values by observing inputs and outputs.
Innovation Solution
Implementing a variable delay mechanism between processing units, where the first processed data line is delayed by a variable value, and the initial data line is also delayed by a variable value, making it difficult for attackers to identify the delay sequence, with control means to activate or deactivate delay cells to adjust the delay values randomly.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If fixed delay stages are used in processing units, then the system structure is simple and easy to implement, but the security against fault injection attacks is weakened because attackers can easily determine delay values by observing inputs and outputs
Solution Approach 1:
The patent applies the dynamics principle by transforming fixed delay stages into variable delay stages. The delay value is no longer static but can be dynamically adjusted through control signals that activate or deactivate delay cells. This allows the system to change delay characteristics in response to security requirements, making fault injection attacks significantly more difficult while maintaining reasonable structural complexity through modular delay cell design
Solution Approach 2:
The patent implements parameter changes by modifying the delay parameter from a fixed value to a variable value. The control means changes the delay parameter dynamically by activating or deactivating delay cells based on control signals. This parameter transformation enables the system to adapt delay characteristics for security purposes without fundamentally redesigning the entire processing unit structure
2Reliability
If variable delay values are applied to processed data lines and initial data lines, then security is enhanced by preventing attackers from identifying delay sequences, but the device complexity increases due to additional control means and delay cells
Solution Approach 1:
The patent applies segmentation by dividing the delay mechanism into multiple independent delay cells. Each delay cell can be independently controlled through control signals, allowing granular adjustment of the total delay value. This segmentation reduces overall complexity by breaking down a complex variable delay function into simpler, manageable units that can be activated or deactivated individually
Solution Approach 2:
The control means serves multiple functions: it activates or deactivates delay cells to adjust delay values, generates control signals for both processed data lines and initial data lines, and coordinates the variable delay application across different processing units. This multi-functionality reduces the need for separate control mechanisms, thereby limiting the increase in device complexity
3Reliability
If delay cells are activated to increase variable delay values, then security complexity for attackers increases, but the execution speed of application programs may be reduced due to additional processing time
Solution Approach 1:
The patent implements periodic action by alternately activating and deactivating delay cells in a controlled manner. The control means periodically adjusts delay values during program execution, creating variable delay patterns that prevent attackers from identifying consistent delay sequences. This periodic adjustment maintains security while allowing the system to optimize execution speed by reducing delays when security threats are not detected
Data Source
AI summary
An embodiment device comprises a first processing unit configured to process an initial data line and deliver a first processed data line, a first delay unit coupled to the output of the first processing unit and configured to deliver a delayed first processed data line delayed by a first delay, a second delay unit configured to deliver the delayed initial data line delayed by a second delay, a second processing unit coupled to the output of the second delay unit and configured to process the delayed initial data line and deliver a delayed second processed data line, and a comparison unit configured to compare the contents of the delayed first and second processed data lines and deliver a non-authentication signal if the contents are not identical, the first and second delays being equal to a variable value.


