Secure data processor with cryptography and tamper detection
Abstract
The present invention is embodied in a Secured Processing Unit (SPU) chip, a microprocessor designed especially for secure data processing. By integrating keys, encryption/decryption engines and algorithms in the SPU, the entire security process is rendered portable and easily distributed across physical boundaries. The invention is based on the orchestration of three interrelated systems: (i) detectors, which alert the SPU to the existence, and help characterize the nature, of a security attack; (ii) filters, which correlate the data from the various detectors, weighing the severity of the attack against the risk to the SPU's integrity, both to its secret data and to the design itself; and (iii) responses, which are countermeasures, calculated by the filters to be most appropriate under the circumstances, to deal with the attack or attacks present. The present invention, with wide capability in all three of the detectors, filters and responses, allows a great degree of flexibility for programming an appropriate level of security/policy into an SPU-based application. <IMAGE>

Term
Term ended
Projected expiry passed 5 May 2015, 11.4 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
12 claims: 1 independent, 11 dependent
- 1A secure cryptographic chip for processing and storing sensitive information, including messages received and generated by the chip and keys used to encrypt and decrypt the messages, and for securing the information against potential attacks, the chip comprising:(a) a cryptographic engine for performing cryptographic operations on messages using a first key;(b) one or more detectors for detecting events characteristic of an attack;and(c) a plurality of potential responses to detected events, whereby sensitive information is unencrypted only on the chip, where it is secure from attack.
185 paragraphs, as filed
1. <u>BACKGROUND.</u>
This invention relates generally to integrated circuits for electronic data processing systems and more specifically to the architecture, implementation and use of a secure integrated circuit which is capable of effectively preventing inspection, extraction and/or modification of confidential information stored therein.
There are many applications in which information has to be processed and transmitted securely. For example, automated teller machines (ATMs) require the secure storage and transmission of an identifying key (in this context a password or PIN number) to prevent unauthorized intruders from accessing a bank customer's account. Similarly, pay-per-view (PPV) cable and satellite television systems must protect keys which both distinguish authorized from unauthorized subscribers and decrypt encrypted broadcast television signals.
Typically, one or more integrated circuits are used to process the information electronically. These integrated circuits may themselves store internal confidential information, such as keys and/or proprietary algorithms for encrypting and decrypting that information, as well as implement the encryption/decryption "engine." Clearly, there is a need for integrated circuits which are capable of preventing an unauthorized person from inspecting, extracting, and/or modifying the confidential information processed by such integrated circuits. Further, it is sometimes desirable to destroy certain confidential information (e.g., the keys) and preserve other confidential information (e.g., historical data, such as accounting information used in financial transactions) upon detection of intrusion.
One problem with existing security systems is that the confidential information (keys, encryption/decryption algorithms, etc.) is, at some point in the process, available to potential intruders in an unencrypted ("cleartext") form in a non-secure environment. What is needed is a single secure integrated circuit in which the keys and encryption/decryption engine and algorithms can be embodied and protected from intruders. Such an integrated circuit would effectively ensure that the information being processed (i.e., inputs to the chip) is not made available off-chip to unauthorized persons except in encrypted form, and would "encapsulate" the encryption/decryption process on the chip such that the keys and algorithms are protected, particularly while in cleartext form, from a variety of potential attacks.
Existing secure integrated circuits typically contain barriers, detectors, and means for destroying the confidential information stored therein when intrusion is detected. An example of a barrier is the deposition of one or more conductive layers overlying memory cells inside an integrated circuit. These layers prevent the inspection of the memory cells by diagnostic tools such as a scanning electron microscope. An example of a detector and destroying means is a photo detector connected to a switching circuit which turns off power to memory cells inside a secure integrated circuit upon detection of light. When power is turned off, the contents of the memory cells, which may contain confidential information, will be lost. The theory behind such a security mechanism is that the photo detector will be exposed to light only when the enclosure of the integrated circuit is broken, intentionally or by accident. In either event, it is often prudent to destroy the confidential information stored inside the integrated circuit.
One problem with existing security systems is the "hard-wired" nature of the process of responding to potential intrusions. Such systems are inherently inflexible because it is very difficult to change the behavior of the security features once the integrated circuit has been fabricated. The only way to alter the behavior of these security features is to undertake the expensive and time-consuming task of designing and fabricating a new integrated circuit.
Another consequence of a hard-wired architecture is that it is difficult to produce custom security features for low volume applications. This is because it takes a considerable amount of time and money to design, test, and fabricate an integrated circuit. Consequently, it is difficult economically to justify building small quantities of secure integrated circuits, each customized for a special environment.
There are many situations in which it is desirable to use the same secure integrated circuit, yet have the ability to modify the security features in accordance with the requirements of the application and environment. For example, if the secure integrated circuit is used to process extremely sensitive information, it will be prudent to implement a conservative security "policy" - e.g., destroying all the confidential data (e.g., keys) inside the integrated circuit upon detection of even a small deviation from a predetermined state. On the other hand, if the information is not very sensitive, and it is not convenient to replace the secure integrated circuit, the security policy could be more lenient - e.g., action could be taken only when there is a large deviation from the predetermined state.
Thus, it is desirable to have a secure integrated circuit architecture in which a broad range of flexible security policies can be implemented.
2. <u>SUMMARY OF THE INVENTION.</u>
The present invention is embodied in a Secured Processing Unit (SPU) chip, a microprocessor designed especially for secure data processing. By integrating the keys and the encryption/decryption engine and algorithms in the SPU, the entire security process is rendered portable and is easily distributed to its intended recipients, with complete privacy along the way. This is accomplished by the following SPU-based features: positive identification and reliable authentication of the card user, message privacy through a robust encryption capability supporting the major cryptographic standards, secure key exchange, secure storage of private and secret keys, algorithms, certificates or, for example, transaction records or biometric data, verifiability of data and messages as to their alteration, and secure authorization capabilities, including digital signatures.
The access card could be seen as a form of electronic wallet, holding personal records, such as one's driver's license, passport, birth certificate, vehicle registration, medical records, social security cards, credit cards, biometric information such as finger- and voiceprints, or even digital cash.
A personal access card contemplated for everyday use should be resilient to the stresses and strains of such use, i.e. going through X-ray machines at airports, the exposure to heat if left in a jacket placed on a radiator, a mistyped personal identification number (PIN) by a flustered owner, etc. Thus, in such an application, the SPU could be programmed with high tolerances to such abuses. A photo detector triggered by X-rays might be cued a few moments later to see if the exposure had stopped. Detection of high temperature might need to be coupled to other symptoms of attack before defensive action was taken. A PIN number entry could be forgiving for the first two incorrect entries before temporary disabling subsequent functions as is the case with many ATMs.
For an application like a Tessera Crypto-Card, a secure cryptographic token for the new Defense Messaging System for sensitive government information, the system might be programmed to be less forgiving. Handling procedures for Tessera Card users may prevent the types of common, everyday abuses present in a personal access card. Thus, erasure of sensitive information might be an early priority.
Various encryption schemes have been proposed, such as where a user creates and authenticates a secure digital signature, which is very difficult to forge and thus equally difficult to repudiate. Because of a lack of portable, personal security, however, electronic communications based on these schemes have not gained widespread acceptance as a means of conducting many standard business transactions. The present invention provides the level of security which makes such electronic commerce practical. Such a system could limit, both for new and existing applications, the number of fraudulent or otherwise uncollectible transactions.
Another possible application is desktop purchasing, a delivery system for any type of information product that can be contained in electronic memory, such as movies, software or databases. Thus, multimedia-based advertisements, tutorials, demos, documentation and actual products can be shipped to an end user on a single encrypted CD-ROM or broadcast though suitable RF or cable channels. Virtually any content represented as digital information could be sold off-line, i.e. at the desktop, with end users possibly permitted to browse and try such products before buying.
The encryption capabilities of the SPU could be employed to decrypt the information, measure and record usage time, and subsequently upload the usage transactions to a centralized billing service bureau in encrypted form, all with a high degree of security and dependability. The SPU would decrypt only the appropriate information and transfer it to a suitable storage medium, such as a hard disk, for immediate use.
Information metering, software rental and various other applications could also be implemented with an SPU-based system, which could authenticate users and monitor and account for their use and/or purchase of content, while securing confidential information from unauthorized access through a flexible security policy appropriate to the specific application.
This pay-as-you-go option is an incentive to information providers to produce products, as it minimizes piracy by authenticating the user's initial access to the system, securing the registration process and controlling subsequent use, thereby giving end users immediate access to the product without repeated authorization.
Other aspects and advantages of the present invention will become apparent from the following description of the preferred embodiment, taken in conjunction with the accompanying drawings and tables, which disclose, by way of example, the principles of the invention.
3. <u>BRIEF DESCRIPTION OF THE DRAWINGS.</u>
<ul id="ul0001" list-style="none"><li>FIG. <b>1</b> is a simplified block diagram of the apparatus in accordance with the present invention, showing the Secured Processing Unit (SPU) for performing PDPS.</li><li>FIG. <b>2</b> is a simplified block diagram of the Power Block shown in FIG. <b>1</b>.</li><li>FIG. <b>3</b> is a schematic representation of the Silicon Firewall.</li><li>FIG. <b>4</b> is a schematic representation of an embodiment of the Silicon Firewall shown in FIG. <b>3</b>.</li><li>FIG. <b>5</b> is a schematic representation of an alternative embodiment of the Silicon Firewall shown in FIG. <b>3</b>.</li><li>FIG. <b>6</b> is a block diagram of the System Clock shown in FIG. <b>1</b>.</li><li>FIG. <b>7</b> is a schematic representation of the Ring Oscillator shown in FIG. <b>6</b>.</li><li>FIG. <b>8</b> is a block diagram of the Real Time Clock shown in FIG. <b>1</b>.</li><li>FIG. <b>9</b> is a flowchart of the firmware process for performing the Inverting Key Storage.</li><li>FIG. <b>10</b> is a schematic representation of the Inverting Key Storage.</li><li>FIG. <b>11</b> is a block diagram of an embodiment of the Metallization Layer Detector shown in FIG. <b>1</b>.</li><li>FIG. <b>12</b> is a schematic representation of an alternative embodiment of the Metallization Layer Detector shown in FIG. <b>1</b>.</li><li>FIG. <b>13</b> is a schematic representation of a second alternative embodiment of the Metallization Layer Detector shown in FIG. <b>1</b>.</li><li>FIG. <b>14(a)</b> is a flowchart of the firmware process for performing the Clock Integrity Check.</li><li>FIG. <b>14(b)</b> is a flowchart of the firmware process for performing the Power Integrity Check.</li><li>FIG. <b>15</b> is a flowchart of the firmware process for performing the Bus Monitoring Prevention.</li><li>FIG. <b>16</b> is a flowchart of the firmware process for performing the Trip Wire Input.</li><li>FIG. <b>17</b> is a flowchart of the firmware process for performing the Software Attack Monitor.</li><li>FIG. <b>18</b> is a flowchart of the firmware process for performing the Detection Handler.</li><li>FIG. <b>19</b> is a simplified representation of the stages of the Filtering Process, including correlating the detectors and selecting the responses.</li><li>FIG. <b>20</b> is a flowchart of the firmware process for performing the filtering of detectors and selection of responses in the context of a simple SPU application; in this instance, using an SPU-equipped PCMCIA card as a digital cash or debit card.</li></ul>
4. <u>DETAILED DESCRIPTION.</u>
<u>a. General Architecture</u>.
A flexible architecture in accordance with the present invention permits extension and customization for specific applications without a compromise in security. One physical embodiment of this invention is a single-chip SPU that includes a 20-MHz 32-Bit CPU, based on the National Semiconductor NS32FV16 Advanced Imaging and Communications microprocessor, but lacking that chip's Digital Signal Processing (DSP) unit.
Referring to FIG. <b>1</b>, the gross features of the SPU architecture are described. This description is not meant to be a literal description of the SPU layout, as some features have been moved or regrouped in order to gain a better conceptual understanding of the principles underlying the present invention. The SPU's Micro Controller <b>3</b> is isolated from all off-chip input -- such input regulated by the External Bus Interface Block <b>9</b> and the general purpose I/O Port Block <b>1</b> --instead receiving programmed commands via an Internal Data Bus <b>10</b> from the on-board ROM Block <b>7</b>. In one embodiment, the ROM Block <b>7</b> is configured at 32 KBytes, and the battery-backed RAM Block <b>8</b> is configured at 4 KBytes. The Internal System Bus <b>10</b> carries all the major signals among the SPU peripherals, such as the address and data lines, read and write strobes, enable and reset signals, and the Micro Controller clock signal, CTTL <b>25</b>.
The System Clock Block has a programmable internal high-frequency oscillator, and is the source, through SYSCLK <b>35</b>, for the Micro Controller clock signal CTTL <b>25</b>, which governs all peripheral functions.
The Real Time Clock <b>5</b> for the SPU follows the IEEE 1212 standard, which specifies control and status register architecture, and which builds upon and significantly enhances the UNIX time format (UNIX time being the number of seconds elapsed since January 1, 1970). The Real Time Clock <b>5</b> is implemented through a binary ripple counter which is driven via RTCLK <b>29</b> by an off-chip external 32.768 KHz quartz crystal <b>14</b> in conjunction with RTC Oscillator <b>14</b> circuitry. Through an offset in battery-backed RAM <b>8</b>, for example, the Real Time Clock <b>5</b> provides UNIX time, and can implement a host of time-based functions and time limits under ROM Block <b>7</b> program control. One firmware routine stored in the ROM Block <b>9</b> cross-checks the System Clock <b>2</b> and Real Time Clock <b>5</b> so as to overcome tampering with the latter.
The I/O Port Block <b>1</b> is a general-purpose programmable input/output interface which can be used to access off-chip RAM, and meet general I/O requirements. Off-chip RAM (not shown) would be typically used for information that cannot be accommodated internally but, for security and performance reasons, still needs to be closer to the SPU than main system memory or disk storage. This information may be protected by modification detection codes, and may or may not be encrypted, depending on application requirements. In addition to serving as a memory interface, several signals on this port can be used to implement cryptographic alarms of trip wire inputs, or even to zero inputs or keys.
The External Bus Interface Block <b>9</b> is the communications port to the host system. In one embodiment, it is the means for getting the application commands as well as data to and from the SPU, and is designed to match the ISA bus standard requirements.
The Power Block <b>13</b> switches between system and battery power depending on system power availability. Power from an external battery (not shown) is supplied to the RTC Block <b>5</b>, the RAM Block <b>8</b> and a Status Register <b>11</b> through VPP <b>24</b>, as well as off-chip RAM (nor shown) through VOUT <b>23</b> when system power is not available. The Power Block <b>13</b> also provides signals PWRGD <b>27</b>, DLY_PWRGD <b>26</b> and CHIP_PWRGD <b>28</b>, which, respectively, start the System Clock <b>2</b>, reset the Bus Controller <b>4</b> and enable the isolation of the battery-backed parts of the circuit from the non-battery backed parts through the Power Isolation <b>12</b>.
A Silicon Firewall <b>20</b> protects the internal circuitry from any external asynchronous or otherwise anomalous signals, conditioning the inputs from the I/O Port Block <b>1</b> via PIN lines <b>32</b> or the External Bus Interface <b>9</b> via ADDR/DATA lines <b>33</b>, the RESET <b>30</b> to the Bus Controller <b>4</b>, as well as from a host of security detectors. Some internally generated signals, such as the output of the Real Time Clock <b>5</b>, are similarly conditioned.
The Status Register <b>11</b> is the repository of all hardware detector signals arrayed through the device to detect various attempted security breaches. Detectors may include a Photo Detector <b>16</b>, Temperature Detector <b>17</b>, Metallization Layer Detector <b>18</b> and any Additional Detectors <b>19</b> (represented in ghost), for example: high/low voltage detectors, vibration detectors, sand detectors. Each of these detectors may convey one or more bits of information which, in one embodiment, are stored in the Status Register <b>11</b>. The Status Register <b>11</b> may also store internally generated signals, such as the ROLLOVER <b>34</b> signal from the Real Time Clock <b>5</b> and the Valid RAM and Time (VRT) bit, used to verify the integrity of the information stored in the RAM Block <b>8</b> and the time counter in the Real Time Clock <b>5</b>.
In one embodiment, a DES Engine <b>6</b> is provided as a cryptographic engine to encrypt and decrypt data using its DES algorithm. Alternative embodiments of cryptographic engines may be implemented entirely in hardware or in a combination of hardware and software, and may use other cryptological algorithms, including RSA or secret algorithms such as RC2, RC4, or Skipjack or combinations thereof. The DES Engine <b>6</b> receives keys and data for the cryptographic process from the RAM Block <b>8</b> under the control of the Micro Controller <b>3</b>. The data used could be application data supplied from the External Bus Interface <b>9</b> or protected data from the RAM Block <b>8</b>. The DES Block <b>6</b>, in one embodiment, performs a decryption of a 64-bit block in 18 clock cycles. Thus, with an SPU rated at 20 MHz, a single decryption will take approximately 90 ns, which amounts to a decryption rate of 8.9 Mbytes per second.
Typically, the SPU receives "messages" in encrypted form. The cryptographic engine (e.g. DES Engine <b>6</b>) uses keys, for example, "session keys" specific to a particular application transaction or "session". The cryptographic engine is thus used to encrypt or decrypt the messages, or perform other cryptographic operations as is well-known in the art. In addition to providing secure message transfer, the SPU also provides secure key transfer. By having, or indeed even generating a "master key" internally (using any of the well-known key generation techniques for public or secret key algorithms), the SPU can receive session keys in encrypted form and, treating them like messages, decrypt them with the cryptographic engine using the master key. Conversely, the SPU can encrypt and send messages in a secure manner. The master key, the decrypted session keys and other sensitive information (e.g. the encryption/decryption algorithms) are stored in secure rewritable memory on the SPU, as described below.
i. <u>Power Block</u>.
The security requirements of the SPU impose special requirements on the power supply. As the Real Time Clock <b>5</b> is used to maintain accurate time and the RAM <b>8</b> is used to store and maintain information, both for the field life of the product, each must have a continuous source of power, VPP <b>24</b>, which here is supplied by the Power Block <b>13</b>.
Referring now to FIG. <b>2</b>, the battery VBAT <b>21</b> and system VDD <b>22</b> voltages are supplied to the Power Switching Circuit <b>101</b>. This circuit uses a conventional analog comparator to determine the higher of the two voltages, VDD <b>22</b> and VBAT <b>21</b>, and provide such voltage as VPP <b>24</b> to the internal circuitry and as VOUT <b>23</b>, which could be used as a voltage supply for off-chip RAM, for example. The Power Switching Circuit <b>101</b> also provides a PWRGD <b>27</b> signal, which is used to indicate whether the entire SPU chip is powered through VDD <b>22</b> (the high state), as opposed to only the battery-backed sections being powered via VBAT <b>21</b> (the low state). In one embodiment, the threshold for this switch is when VDD <b>22</b> exceeds 1.2 times VBAT <b>21</b>. If the external battery is dead, VBAT <b>21</b> is effectively zero, and PWRGD <b>27</b> goes high as soon as VDD <b>22</b> is turned on.
The PWRGD <b>27</b> signal, as not originating from the Internal Data Bus <b>10</b>, would represent a security risk within the circuitry inside the Silicon Firewall <b>20</b>, if left untreated. However, unlike other signals that are passed through the Silicon Firewall <b>20</b>, PWRGD <b>27</b> is used to start the System Clock <b>2</b>, as discussed below, and thus cannot be conditioned and synchronized by the Silicon Firewall <b>20</b> in the manner those other signals are treated. Thus, the Power Switching Circuit <b>101</b> conditions the PWRGD <b>27</b> signal by a low-pass filter, which acts as a "glitch eater" to prevent any rapid changes in the resultant PWRGD <b>27</b> signal and give it a sufficiently narrow bandwidth as to admit to the internal circuitry.
Two counters, PWRUP Counter <b>102</b> and PWRDN Counter <b>103</b> are provided to produce DLY_PWRGD <b>26</b>, a delayed version of PWRGD <b>27</b>, as clocked by the system clock CTTL <b>34</b> signal. These counters may be conventional devices as is well known in the art. In one embodiment, this DLY_PWRGD <b>26</b> signal is used as an input to the AND gate <b>31</b> incident to the Bus Controller <b>4</b>, as shown in FIG. <b>1</b>, thus assuring the SPU is always powered up in the reset state. The DLY_PWRGD <b>26</b> and PWRGD <b>27</b> signals are combined through an AND gate <b>114</b> to produce another signal, CHIP_PWRGD <b>28</b>.
The CHIP_PWRGD <b>28</b> signal is provided to prevent current flow from the battery-backed circuitry to the rest of the circuit that is not powered when the system power VDD <b>22</b> is removed, and thus allow for the orderly shutdown of the non-battery-backed sections. This signal acts as an early detection system for the system power going away. Referring to FIG. <b>1</b>, the CHIP_PWRGD <b>28</b> signal is used by the Power Isolation Circuit <b>12</b> which isolates the inputs and outputs of the Real Time Clock <b>5</b>, RAM <b>8</b> and Status Register <b>11</b> from non-battery-backed sections of the chip. CHIP_PWRGD <b>28</b> is conditioned in the manner of the Silicon Firewall <b>20</b> described below; this process has the added advantage of preventing any invalid writes to the RAM <b>8</b> or Real Time Clock <b>5</b> when the power source is being switched.
As described above, the DLY_PWRGD <b>26</b> signal may be used as a reset. However, if the PWRUP Counter <b>102</b> is powered up in the wrong state, it may affect the reset operation of the rest of the device. The state machine in PWRUP Counter <b>102</b> could power-up in a state of continual reset owing to the dual requirements of powering tip without reset, and delaying the stopping of CTTL <b>34</b> clocking upon power down. To overcome this problem, a separate analog circuit V<sub>cc</sub>PUD <b>104</b> is provided, with inputs SET_PWUP <b>110</b> and CLR_PWUP <b>111</b>, which respectively, set and clear the output VCCPWUP <b>107</b>. The V<sub>cc</sub>PUD <b>104</b> circuit also monitors VDD <b>22</b> such that VCCPWUP <b>107</b> will also clear if VDD <b>22</b> falls below approximately 2V. In this embodiment, VDD <b>22</b> is supplied by the Power Switching Circuit <b>101</b> via VREF <b>115</b>.
The operation of the PWRUP Counter <b>102</b> and PWRDN Counter <b>103</b> in conjunction with V<sub>cc</sub>PUD <b>104</b> is thus as follows. On power up, until the system power VDD <b>22</b> comes up above 1.2 times VBAT <b>21</b>, VCCPWUP <b>112</b> acts as a reset to PWRUP Counter <b>102</b> and PWRDN Counter <b>103</b>; afterwards PWRGD <b>27</b> and consequently VCCPWUP <b>112</b> will come up, triggering the start of the PWRUP Counter <b>102</b>. Seven clock cycles later, as clocked by CTTL <b>34</b>, the DLY_PWRGD <b>26</b> and CHIP_PWRGD <b>28</b> signals will go high. Conversely, when VDD <b>22</b> comes down, before it dips below 2V, it will drop below 1.2 times VBAT <b>21</b>, thus PWRGD <b>27</b> will go low, starting the PWRDN Counter <b>103</b> via inverter <b>108</b>. Eight clock cycles later, the PWRDN Counter <b>103</b> will trigger the SHUTDOWN <b>113</b> signal, which will activate CLR_PWUP <b>111</b>, causing VCCPWUP <b>112</b> to go low, resetting the PWRDN Counter <b>103</b> via AND gate <b>107</b> and the PWRUP Counter <b>102</b> via inverter <b>109</b>. Thus, if the PWRGD <b>27</b> signal is lower for longer than seven clock cycles the entire device is reset as if power has been completely removed. This delay takes into account transients in the power supply where VDD <b>22</b> goes high but dips below 2V briefly before returning to an acceptable level.
ii. <u>Alarm Wake Up</u>.
One embodiment of the present invention disables detection capability when the SPU is running on battery power VBAT <b>21</b> only. In an alternative embodiment, in the absence of system power, VDD <b>22</b>, non-battery backed parts of the SPU are temporarily powered through VBAT <b>21</b>. As represented in ghost in FIG. <b>1</b>, if any detector triggers a signal, the OR gate <b>39</b> would send an ALARM <b>38</b> signal to the Power Block <b>13</b>.
With further reference to FIG. <b>2</b>, if VBAT <b>21</b> alone was sufficiently high to power the whole SPU, a suitably modified Power Switching Circuit <b>101</b>, would upon triggering by the ALARM <b>38</b> signal: (i) generate a PWRGD <b>27</b> signal much as seen before; (ii) generate a new signal, APWRGD <b>40</b>, to indicate that the SPU was operating under alarm-triggered "emergency" power; and (iii) switch VREF <b>115</b> from VDD <b>22</b> to VBAT <b>21</b> so as not to interfere with the powering up process. In the continued absence of adequate VDD <b>22</b>, a SLEEP <b>41</b> signal received by the Power Switching Circuit <b>101</b> would make PWRGD <b>27</b> and APWRGD <b>40</b> go low, switch VREF <b>115</b> back to VDD <b>22</b>, and so trigger a power down much as seen before.
iii. <u>Silicon Firewall</u>.
A common assumption, when defining a security model, is that everything inside a system is protected while everything outside is not protected. In any effort to plan for security features, it is crucial to establish a clear understanding of the system boundary and to define the threats, originating outside the boundary, against which the system must defend itself. In the case of the SPU, the system boundary is the silicon boundary, or equivalently, the pins of the SPU package. The components inside the system boundary are of two types: those responsible for maintaining the security of the system; and, those responsible for performing other functions. Separating the two types of components is the boundary called the security perimeter, with the area between the security perimeter and the silicon boundary called the silicon firewall. The silicon firewall's role is thus to defend the security perimeter. One aspect of this role, for example, is to prevent asynchronous inputs from outside the security perimeter reaching inside untreated; such inputs may drive the system into unpredictable and uncontrollable states.
The Micro Controller <b>3</b> is one of the least trusted components in the SPU, precisely because it is difficult to verify all the multitudinous states of a micro controller. Consequently, the Micro Controller <b>3</b> in a SPU should be protected from asynchronous or otherwise abnormal inputs, i.e., signals which are outside the normal operating mode of the Micro Controller <b>3</b>. Examples of abnormal inputs are signals which have disallowed input levels (e.g., signals which have neither valid high nor valid low logic levels) and signals which have timing transitions which are out-of-specification. Not only do input signals external to the SPU need treatment, but all internal signals which are asynchronous to the Micro Controller must be treated by special protection circuitry.
A common technique to prevent asynchronous and abnormal inputs is to equip all inputs to a semiconductor chip with Schmitt trigger devices coupled with latch circuits, which thereby ensure that signals cannot change state while they are being sampled by the semiconductor chip. However, it is difficult to fabricate Schmitt triggers. Furthermore, Schmitt triggers are slow because of hysteresis effects. The SPU according to the present invention uses a "Silicon Firewall" design to protect all interfaces to the Micro Controller <b>3</b>. One of the designs of the Silicon Firewall involves a state machine. FIG. <b>3</b> shows one embodiment of a state machine <b>710</b> which could be used as a Silicon Firewall. State machine <b>710</b> comprises a data register <b>712</b>, the state of which is controlled by a clock <b>714</b>. In this embodiment, state machine <b>710</b> operates as a four t-state machine. During any time other than t1, data is locked out of data registers <b>712</b>. In t1, input data (if available) is latched into an input port <b>716</b> of data register <b>712</b>. However, data is not available to the output port <b>717</b> of data register <b>712</b> until t3. Consequently, any metastable states of the input data are nullified by the two t-cycle delay.
FIG. <b>4</b> shows an embodiment of a data register <b>720</b> which can be advantageously used in state machine <b>710</b>. Register <b>720</b> comprises two D flip-flops <b>722</b> and <b>724</b>. The output terminal <b>726</b> of flip-flop <b>722</b> is coupled to the input terminal <b>727</b> of flip-flop <b>724</b>. A clock signal is sent to the clock terminals <b>728</b> and <b>729</b> of flip-flops <b>722</b> and <b>724</b>, respectively, along line <b>730</b>.
When an external signal, which is generally asynchronous, is applied to the input terminal <b>732</b> of flip-flop <b>722</b>, its state (high or low) is latched into flip-flop <b>722</b> only at the rising edge of the first clock pulse. This state is kept the same until the rising edge of the second clock pulse. As a result, the output signal at terminal <b>726</b> of flip-flop <b>722</b> remains at the same state from the rising edge of the first clock pulse to the rising edge of the second clock pulse, regardless of the state of the input signal between the two rising edges.
The state of the output terminal <b>726</b> of flip-flop <b>722</b>, which corresponds to the external signal at the rising edge of the first clock pulse, is latched into flip-flop <b>724</b> at the rising edge of the second clock pulse. Consequently, the output terminal <b>734</b> of flip flop <b>724</b> will have a state equal to the state of the external signal at the rising edge of an earlier clock pulse.
It can be seen from data register <b>720</b> that the input is sampled at a time determined (i.e., synchronized) by the clock pulses. In addition, any abnormal signal is filtered by flip-flop <b>722</b>. Consequently, the signal connected to the embedded controller is a normal and synchronized signal.
FIG. <b>5</b> shows an alternative embodiment of a data register <b>740</b> which can be advantageously used in state machine <b>710</b>. Data register <b>740</b> consists of a multiplexer <b>742</b>, a D flip flop <b>744</b>, a buffer <b>746</b>, and a device <b>748</b> for generating a clock signal having four t-states in response to an input clock signal on line <b>750</b>. The output of multiplexer <b>742</b> is connected to the input of D flip flop <b>744</b>, and the output of D flip flop <b>744</b> is connected to the input of buffer <b>746</b> and one of the input terminals of multiplexer <b>742</b>. The other terminal of multiplexer <b>742</b> is connect to an external signal (typically asynchronous). Device <b>748</b> generates a clock signal on line <b>752</b> which controls multiplexer <b>742</b> such that the external asynchronous signal on line <b>758</b> is coupled to D flip flop <b>744</b> only at time t1. Device <b>748</b> also generates a clock signal on line <b>754</b> which controls buffer <b>754</b> such that the output signal of D flip flop <b>744</b> passes through buffer <b>746</b> only at time t3. As a result, the signal on line <b>756</b> is synchronized.
iv. <u>Internal System Clock</u>.
A system clock compatible with PDPS faces a series of design considerations: cost, governmental regulatory compliance, printed circuit board area, power consumption and last, but most important, security. The desire for high performance places a premium on clock speed, which is directly proportional thereto.
The cost of clocking circuits increases with frequency, and external clocks may represent a sizeable fraction of the entire manufacturing cost. The greater the physical extent of the high-frequency circuitry, the greater the high-frequency EM emissions, resulting in both a problem for security as well as meeting FIPS 140-1 requirements. EM emissions can give surprising amounts of information to sophisticated attackers -- by analyzing the power spectrum, one might even deduce which type of algorithm is being processed at any particular time. As compared with an internal clock sitting right on the microprocessor, an external clock coupled to a microprocessor cannot be made to comply as easily with the FIPS 140-1 EMI/EMC requirements which impose limits on EM emissions. External clocking arrangements can use significant real estate on printed circuit boards and hence restrict design applications. The desire to reduce power consumption favors internal clocks: they can operate at lower voltages than external ones, which have to deal with high outside EM interference; and, they have smaller power dissipation capacitances owing to their smaller physical dimensions. Moreover, the presence of an external clock allows a potential chip attacker to manipulate the clock speed, a factor which may allow it to foil other security devices.
Internal oscillators, of themselves, are not novel structures. One can find a programmable internal oscillator in Carver Mead and Lynn Conway, <u>Introduction to VLSI Systems</u>, Addison & Wesley (1980), pp. 233-236. Another example is a phase-locked loop circuit which locks upon an external low frequency reference, as described by Brian Case, "Sony & HDL Detail Embedded MIPS Cores", Microprocessor Report, vol. 7, no. 15, November 15, 1993. This outside link through an external reference is completely inappropriate in a security environment, however.
Referring now to FIG. <b>6</b>, the System Clock <b>2</b> is implemented using a standard 5-clock-cycle shutdown, 5-clock-cycle enable, state machine once a change request has been detected. The Bus Interface and Decoder <b>151</b> selects and decodes three types of signals off the Internal Bits <b>10</b>: the internal system clock signal CTTL <b>34</b> which is passed onto Power Block <b>13</b> as was illustrated in FIG. <b>1</b>; a STOP_CLK <b>166</b> signal to stop the System Clock <b>2</b>; and the 4 bit signal OSC_FREQ <b>172</b>, representing the programmed frequency for the Ring Oscillator <b>156</b> The OSC_FREQ <b>172</b> signal is stored in the Oscillator Control Register <b>152</b>, and is fed into the Change Pulse Generator <b>153</b>. The STOP_CLK <b>166</b> and PWRGD <b>27</b> signals are fed into AND gate <b>164</b>, the output of which is fed into the Change Pulse Generator <b>153</b>, AND gate <b>165</b>, the set of entry latches <b>154</b>, the Clock Edge Prohibit <b>155</b>, and the resets for the D flip-flops <b>159</b>,...,<b>163</b>. Thus, when the Change Pulse Generator <b>153</b> detects a change in any of its inputs, it generates a pulse CHANGE_DETECTED <b>167</b> which is latched onto the latch <b>158</b>. The D flip-flops <b>159</b>,...,<b>163</b> act as a shift register, propagating the latched signal from latch <b>158</b> down the line in five clock cycles, the clocking generated by RING_CLK_OUT <b>170</b>, the output of the Ring Oscillator <b>156</b>. When the signal has propagated through the last D flip-flop <b>163</b>, it generates: (i) an OPEN_LATCH <b>168</b> signal to the entry latches <b>154</b> and Clock Edge Prohibit <b>155</b>; and (ii) a CLOSE_LATCH <b>169</b> signal to the exit latch <b>157</b> and the AND gate <b>165</b>, thus resetting the latch <b>158</b>.
The OPEN_LATCH <b>168</b> signal, in conjunction with a high signal from the AND gate <b>164</b> will enable the Clock Edge Prohibit <b>155</b>, which is a one-shot trigger generating a SHUTDOWN_CLK <b>171</b> signal for approximately 120 ns, allowing a new frequency to be programmed into the Ring Oscillator <b>156</b> without introducing transient glitches. At the same time, the CLOSE_LATCH <b>169</b> signal will remain low for one clock cycle, resulting in the output SYSCLK <b>35</b> having a longer duty cycle for one clock cycle, and then the data in the Oscillator Control Register <b>225</b> will correspond to the output frequency of SYSCLK <b>35</b>.
The Ring Oscillator <b>156</b> itself will now be described. To compensate for the wide process variations introduced in manufacture, resulting in variances in individual clock rates over a wide range, the Ring Oscillator <b>156</b> is programmable to sixteen different frequencies of operation: 22 MHz, 23 MHz, 24.8 MHz, 26.2 MHz, 27.7 MHz, 29 MHz, 31.9 MHz, 34.3 MHz, 37.8 MHz, 40.2 MHz, 46 MHz, 51.2 MHz, 58.8 MHz, 64.9 MHz, 82.2 MHz and 102.2 MHz. The particular nature of the Micro Controller <b>3</b>, as well as concerns for the operational compatibility with the ROM <b>7</b>, dictated that these nominal frequencies be divided by two before the signal leaves the Ring Oscillator <b>156</b> and is provided to the Micro Controller <b>3</b> via SYSCLK <b>35</b>.
Referring now to FIG. <b>7(a)</b>, one can see that this aforementioned frequency division is accomplished by the D flip-flop <b>210</b> whose output is RING_CLK_OUT <b>170</b>. The OSC_FREQ <b>172</b> signals are supplied in pairs to one of two multiplexers MUX1 <b>204</b> and MUX2 <b>208</b>. The output of MUX2 <b>208</b> is fed to the D flip-flop <b>210</b> clock input and the NAND gate <b>209</b>. The SHUTDOWN_CLK <b>171</b> signal is fed to the D flip-flop <b>210</b> reset and the NAND gate <b>209</b>. Blocks <b>201</b>, <b>202</b>, <b>203</b>, <b>205</b>, <b>206</b>, <b>207</b> are chains of inverters, represented in FIGS. <b>4(b)</b>, <b>4(c)</b>, <b>4(c)</b>, <b>4(d)</b>, <b>4(e)</b> and <b>4(e)</b>, respectively. Depending on the state of the OSC_FREQ <b>171</b> signals, from (0,0,0,0) to (1,1,1,1), asserted on the multiplexers MUX1 <b>204</b> and MUX2 <b>208</b>, the results yield an effective circuit varying in the number of inverters. In FIG. <b>7(b)</b> a chain of 8 inverters <b>211</b>,...,<b>218</b> is shown, each connected to VPP <b>24</b> through capacitors <b>219</b>,...,<b>226</b>. These capacitors act to swamp all routing capacitance through the circuit. Similarly, FIG. <b>7(c)</b> shows the corresponding 4 inverter chain, with inverters <b>227</b>,..., and capacitors <b>231</b>,...,<b>234</b>. FIG. <b>7(d)</b> shows the 2 inverter chain with inverters <b>235</b> and <b>236</b>, capacitors <b>237</b> and <b>238</b>. Finally, FIG. <b>7(e)</b> also shows two inverters <b>239</b> and <b>240</b>, but with only a single capacitor <b>241</b> attached to the output of the second inverter <b>240</b>. Two inverters are required in this last case, because an even number of inverters, in conjunction with the NAND gate <b>209</b>, is required to give the ring a net overall inversion, sustaining the Ring Oscillator <b>156</b>. It is the combined propagation delays through all the inverters, the NAND gate <b>209</b> and the multiplexers MUX1 <b>204</b> and MUX2 <b>208</b> which generates the 16 different frequencies of the Ring Oscillator <b>156</b> listed above.
At manufacturing time, the frequency selected is based on calibration with an established time standard. This standard may be provided by the Real Time Clock <b>5</b>, or by "Start" and "Stop" time commands timed and sent from a trusted system. Using the Real Time Clock <b>5</b> provides the optimal calibration input. This calibration is accomplished at the same time secret keys are installed and can only be done in the manufacturing mode. The final set frequency, as read from the lowest four bits of the Oscillator Control Register <b>152</b>, is stored in the battery-backed RAM <b>8</b> or some other non-volatile memory. Each time the device is reset, or power is applied, the device assures itself that the final set frequency stored in non-volatile memory is correct by using modification detection codes, as described below. If the final set frequency is correct then it is loaded into the lowest four bits of the Oscillator Control Register <b>225</b> thus re-establishing the optimal operating frequency of the Ring Oscillator <b>156</b>. If the final set frequency is incorrect, as stored in the non-volatile memory, then no value is loaded into the Oscillator Control Register <b>225</b>, thus leaving it at its reset value. Leaving the Ring Oscillator <b>156</b> at its reset value, which is the lowest programmable frequency, ensures proper operation of the device even under conditions of non-volatile memory. For example, it assures that the internal Micro Controller clock input SYSCLK <b>216</b> is never driven at too high a frequency, which could lead to malfunction and possible security breach.
v. <u>Real-Time Clock</u>.
For the reasons disclosed above, as well as an innate temperature variability of about 30% over the SPU's operating range, the System Clock <b>2</b> represents a secure but somewhat inaccurate timing device, suitable for internal clocking of the Micro Controller <b>3</b>, but not for keeping UNIX time or to control timed and time-of-day events.
Referring to FIG. <b>1</b>, the RTC Oscillator <b>14</b> is designed to produce a 32.768 KHz signal, RTCLK <b>29</b>, through use of an external quartz crystal <b>15</b>. Alternatively, one could bypass the RTC Oscillator <b>14</b> and generate RTCLK <b>29</b> through an external clock. OSC_ON <b>42</b> allows the oscillator to be stopped even though battery power is applied to the device. This prevents drain on the battery, as for example, while the system is in inventory before it is sold. The output RTCLK <b>236</b> from the RTC Oscillator <b>241</b> is used to drive the Real Time Clock, as described below.
With reference to FIG. <b>8</b>, the Real Time Clock <b>5</b> consists of a binary Ripple Counter <b>302</b>, a Bus Interface and Decoder <b>301</b>, and a Synchronization Block <b>303</b>. The Ripple Counter <b>302</b> may be a conventional shift register array with 15 bits allocated to counting fractions of seconds, output via SFC <b>306</b>, and 32 bits allocated to a seconds counter, output via SC <b>307</b>. The value of SC <b>307</b>, when combined with an offset in the local battery-backed RAM Block <b>8</b>, produces the sought-after UNIX time. The final carry-over in the Ripple Counter <b>302</b> produces the ROLLOVER <b>34</b> signal.
The Bus Interface and Decoder <b>301</b> interfaces with the Internal Bus <b>10</b> and supplies the system clock CTTL <b>25</b>, the aforementioned OSC_ON <b>42</b> signal, and signals CLEAR_RTC <b>304</b> and CLOCK_RTC <b>305</b>. CLEAR_RTC <b>304</b> is used to reset the Ripple Counter <b>302</b>. CLOCK_RTC <b>305</b> allows the Micro Controller <b>3</b> to clock the Ripple Counter <b>302</b> without resorting to RTCLK <b>29</b>, and thus permits testing of the device.
As RTCLK <b>29</b> is an external asynchronous signal, the resulting signals SFC <b>306</b>, SC <b>307</b> and ROLLOVER <b>34</b> need to be treated by the Synchronization Block <b>303</b>, in the manner of the Silicon Firewall described earlier. Thereafter, the SFC <b>306</b> and SC <b>307</b> signals may be appropriately channeled through the Internal Bus <b>10</b> in response to polling by the Micro Controller <b>3</b>. The use of the ROLLOVER <b>34</b> signal will be discussed in the context of the Rollover Bit discussed below.
In accordance with the alarm wake-up feature of the alternative embodiment discussed above, a Countdown Counter <b>308</b> (represented in ghost) is set by the Micro Controller <b>3</b> via counter control signals sent on the Internal Bus <b>10</b>, decoded by the Bus Interface and Decoder <b>301</b> and transmitted via line(s) <b>310</b>. Thus, when the Countdown Counter <b>308</b> accomplishes a predetermined count, as clocked off the Ripple Counter <b>302</b> signals SC <b>307</b> or SFC <b>306</b>, it would issue an ALARM <b>38</b> signal in the same manner as described above. In addition, the ROLLOVER <b>309</b> signal, passed through OR gate <b>309</b>, may provide the basis of another wake up signal via ALARM <b>38</b>.
vi. <u>Inverting Key Storage</u>.
It is desirable to place secret information (e.g., the decryption key) in the volatile, or generally, re-writable memory of the SPU. The secret information will be destroyed if power to the SPU is turned off. On the other hand, if the secret information is placed in non-volatile memory, an attacker can remove the SPU and at his leisure and by conventional means examine the information in the non-volatile memory.
If secret information is not loaded into the volatile memory properly, an attacker may still be able to examine the SPU while system power is turned off and obtain the secret information. This is because the secret information stored in conventional volatile memory may leave a residue on the dielectric material of the SPU, which the attacker can read to obtain the secret information even after power is turned off. When the secret information is loaded into memory, the voltage level of the memory cells causes charge to build up in the dielectric material of the memory cells. If the same secret information is placed in the same memory location for an extended period of time, the dielectric material may be permanently affected by the charge of the memory cells. When this happens, it is possible to determine the secret information even after power is removed from the memory cells. Further, it is possible to artificially "age" the memory cells (so that the dielectric material can be permanently affected in less time) by elevating the voltage and changing the operating temperature of the SPU.
One aspect of the present invention is an inverting key storage arrangement wherein the secret keys are periodically inverted. As a result, the net average charge across all memory cells is the same, thus leaving no signature of a specially-selected key in the dielectric material of the memory cells which would be amenable to detection.
In one embodiment of the invention, the inverting key storage arrangement is implemented in firmware. The firmware includes a key inverting routine which is executed in a predetermined time, e.g., once every 100 ms. A flowchart <b>800</b> which includes a key inverting routine <b>802</b> is shown in FIG. <b>9</b>. Flowchart <b>800</b> contains a decision block <b>804</b> which determines if it is time to branch to inverting routine <b>802</b>. If the answer is negative, programs in the firmware are executed (block <b>806</b>). If it is time to execute the key inverting routine <b>802</b>, flowchart <b>800</b> branches to block <b>808</b> which causes all access to the keys to be disabled. The embedded controller then reads the key stored in volatile memory. The bits of the key are inverted and then stored back into memory (block <b>810</b>). In order to keep track of the current status of the inversion (i.e., whether the key is in a normal or inverted state), a key-inversion status bit is assigned to keep track of the status. After the key is inverted, the status of the key-inversion status bit is changed (block <b>812</b>). The access to the key is now enabled (block <b>814</b>). Flowchart <b>800</b> can now branch to block <b>806</b> to execute other firmware routines.
It is also possible to implement an inverting key storage arrangement using only hardware. FIG. <b>10</b> is a schematic diagram of such an arrangement <b>820</b>, which contains a JK flip flop <b>822</b> and a plurality of memory cells, such as cells <b>824</b> and <b>825</b>. The structure of these two cells are identical, and only one will be described in detail. Cell <b>824</b> contains two OR gates <b>827</b> and <b>828</b>, a JK flip flop <b>829</b>, a NOR gate <b>830</b>, an invertor <b>831</b>, and a buffer <b>832</b>. A clock signal on line <b>834</b> is connected to the clock input of the two flip flops <b>822</b> and <b>829</b>. A Toggle/Load signal (T/L*) on line <b>835</b> is used to put the cells <b>824</b> and <b>825</b> in a toggle state when the signal is at a high value and the cells in a load state when the signal is at a low value. Thus, when the T/L* signal is low, the data on line <b>839</b> is loaded into memory cell <b>824</b>. When the T/L* signal is high, the JK flip flop <b>829</b> will toggle according to the clock signal on line <b>834</b>. A read signal on line <b>836</b> is coupled to the enable terminal of buffer <b>832</b>. The read signal allows the data stored in the memory cells to be read. The signal on line <b>836</b> indicates whether the output on line <b>839</b> is the original or the inverted signal.
vii. <u>Additional Security Features</u>.
In addition to the features described above, the SPU can certainly be rendered more secure in any number of ways. For example, the physical coating disclosed in application Ser. No. 08/096,537, "Tamper Resistant Integrated Circuit Structure", filed July 22, 1993, in the name of inventor Robert C. Byrne, and incorporated herein by reference, has a tamper resistant structure laid down in a pattern which would cover portions of the SPU, but expose others so that etching away the tamper resistant structure destroys the exposed portions. Thus, the SPU would not be easily disassembled or reverse engineered, because the tamper resistant structure would hide the active circuitry and removal of the tamper resistant structure would destroy the active circuitry. This physical coating would act as a natural adjunct to the Metallization Layer Detector (FIGS. <b>11</b>-<b>13</b>).
Another security feature that could prove useful is disclosed in application Ser. No. <u>08/ </u>, "Secure Non-Volatile Memory Cell", filed <u> , 1994</u>, in the name of inventors Max Kuo and James Jaffee, also incorporated herein by reference, which has an EEPROM cell providing protection against external detection of the charge stored within the cell by causing any stored charge to dissipate upon the attempted processing of the cell. This type of EEPROM might fulfill the role of the ROM <b>7</b> block, or possibly even substitute for the Inverting Key Storage described earlier (FIGS. <b>9,10</b>).
<u>b. Implementation of the Detectors</u>.
i. <u>Photo Detector</u>.
If secure information resides in registers or memory of a VLSI device, often an attacker finds it fruitful to remove the packaging of such a device to impact such storage devices directly. This facilitates the investigation of the design architecture and makes it possible to probe internal nodes in an attempt to discover the secure information. Such package removal, or de-encapsulation, will thus likely expose the die to ambient light, even if inadvertently on the attacker's part. Detecting such light could act as input information for suitable responsive countermeasures to take place.
The construction of a light-sensitive device can be implemented in many standard CMOS processes without any extra masks or steps. For example, lightly doped N-type material exhibits a conductivity proportional to the amount of light to which the material is exposed.
Referring to FIG. <b>1</b>, the Photo Detector <b>16</b> signal passes through the Silicon Firewall <b>20</b> before setting a bit in the Status Register <b>11</b>. A plurality of such detectors may be placed at strategic places within the SPU, which may be used to localize and further characterize the nature of any intrusion.
ii. <u>High/Low Temperature Detector</u>.
The normal temperature operating range for the SPU is 0°C to 70°C. Any temperature above this range, in most applications, might well be considered to be the result of an intrusion attempt by an attacker, as for example, the heat generated by grinding away at the chip's outer layer. A substrate diode, well-known to the art, should be sufficient for detecting temperature changes, although any other comparable device known to those of ordinary skill in the art for performing temperature measurement should suffice.
With reference to FIG. <b>1</b>, the Temperature Detector <b>17</b> signal passes through the Silicon Firewall <b>20</b> before setting a bit in the Status Register <b>11</b>. Nothing in accordance with this invention precludes a multi-bit field characterizing a temperature scale, or a plurality of such detectors, to characterize any temperature differentials within the SPU.
iii. <u>Metallization Layer</u>.
Modern day integrated-circuit analysis equipment is able to probe the contents of an integrated circuit while power is applied to the circuit. As a result, it is possible to detect a key, or other secret data for that matter, which is stored in volatile memory. One way to protect the secret key is to cover the key with a metal layer which is able to deflect probing signals directed thereon. However, this metal layer could be removed or altered fairly easily by an attacker. Consequently, protecting the key through the use of a metal layer, as contemplated in the prior art, is rather ineffective.
One way to enhance the security of the metal layer is for the SPU to contain means for detecting any alteration of the metal layer which covers the key, or any particularly sensitive data for that matter. The SPU can then take actions to respond to the alteration. One embodiment of the invention is shown in FIG. <b>11</b>. The metal layer is divided into many metal traces, shown in FIG. <b>11</b> as parts <b>852-857</b>. Each trace is connected to an output pin of a latch <b>860</b> and an input pin of a latch <b>862</b>. These two latches are connected to the system bus <b>868</b>, which is in turn connected to the Micro Controller and the memory. They are also connected to the Status Register <b>11</b>. Traces <b>852</b> and <b>853</b> pass over a first area <b>864</b>, traces <b>854</b> and <b>855</b> pass over a second area <b>865</b>, and traces <b>856</b> and <b>857</b> pass over a third area <b>866</b>.
During a system bus cycle, the individual output pins of latch <b>860</b> are driven to either a logic high or a logic low, depending on the value of a random number generator (either implemented in hardware or software). As a result, the traces <b>852-857</b> should be set to a corresponding logic high or a logic low value. At a later bus cycle, latch <b>862</b> latches in the logic levels of traces <b>852-857</b>. If any of the latched logic levels are different from the logic level originally driven by latch <b>860</b>, it is assumed that an attack has been mounted on the SPU.
Another embodiment of the invention is shown in FIG. <b>12</b>. The metal layer is again divided into many metal traces, shown in FIG. <b>12</b> as numerals <b>902</b>-<b>904</b>. These metal traces are connected to a logic high potential. FIG. <b>12</b> also contains a plurality of AND gates, shown as numerals <b>906-908</b>, and a plurality of memory cells <b>913-916</b>. Each of the AND gates <b>906-908</b> has one input terminal connected to one of the traces <b>902-904</b> and one output terminal connected to one of the power lines <b>910-912</b> of memory cells <b>914</b>-<b>916</b>, respectively. The other terminals of each of AND gates <b>906-908</b> are connected to power lines <b>909-911</b>, respectively. These power lines <b>909-911</b> could feed off VPP <b>24</b>, for example.
When the metal traces are in their normal condition, i.e., connected to a logic high potential, the inputs of the AND gates are in a logic high potential. Thus, all the memory cells are powered by the outputs of the AND gates. However, if any one of the metal traces is removed, the output of the corresponding AND gate will be changed to a logic low, which turns off the associated memory cell. Since the output of an AND gate is connected to the input of an adjacent AND gate, the output of the adjacent AND gate becomes a logic low, which turns off the memory cell associated with the adjacent AND gate. This sequence of events propagates until all the outputs of the AND gates become a logic low. As a result, all the memory cells are turned off resulting in the destruction of the data stored therein. This embodiment does not require any action of the Micro Controller and could amount to a last-ditch defense.
A third embodiment of the invention is a LATN cell, shown in FIG. <b>13</b> as <b>920</b>. LATN cell <b>920</b> is essentially a latch with a weak feedback path so that any intrusion in the cell will cause the cell to toggle. A control signal on line <b>925</b> is applied to a transmission gates <b>924</b> and, through an inverter <b>926</b>, to another transmission gate <b>924</b>. As a result, only one of the transmission gates is turned on at a time. When transmission gate <b>922</b> is turned on, a data signal on line <b>927</b> passes through an inverter <b>928</b> to output inverters <b>929</b> and <b>930</b>. An inverter <b>931</b> is connected to inverter <b>929</b> in order to provide an inverted output. When transmission gate <b>922</b> is turned off, the data signal is no longer connected to the output inverters. However, the output signal retains its value because of the feedback provided by an inverter <b>932</b> and transmission gate <b>924</b>.
One of the important features of the LATN cell <b>920</b> of the present invention is that the feedback inverter <b>932</b> has weak output power. Thus, if the LATN cell <b>920</b> is exposed to radiation introduced by a probe, the feedback path is broken and the output value of LATN cell <b>920</b> would not be maintained.
In all of these embodiments, the outputs thereof could be used as detectors, as symbolically represented by Metallization Layer Detector <b>18</b>, feeding their signal through the Silicon Firewall <b>20</b> to the Status Register <b>11</b>. It should not be ignored that the Metallization Layer itself provides a passive defense to probing, as discussed below.
iv. <u>RTC Rollover Bit and the Clock Integrity Check</u>.
As discussed above, the Real Time Clock <b>5</b> uses a 32.768 KHz crystal to drive a Ripple Counter <b>248</b> which keeps UNIX time. Were one to replace this crystal with a frequency source several orders of magnitude higher, while the SPU is operating under battery power only, one could conceivably roll the counter over a predetermined number of pulses to the point where, when system power is reapplied, the Micro Controller <b>3</b> would not be able to detect that any discernable amount of time had passed since the previous time it was turned on. The implications for various applications is serious, as for example: metering information, where the time the information was actually used and the time subsequently charged for such use would have little bearing on each other.
Prior art solutions to detect clock tampering have the drawback that they require the entire system to be always tip and running; typically, however, in order to minimize power consumption in times of non-use, most of the system is powered down while the real-time clock continues to run from batteries. Thus, the problem is to create a mechanism that can detect tampering of a real time clock without the use of the external system, such mechanism to be contained wholly within the real time clock for security reasons, and be a minimal drain on the total power.
In the present invention, referring to FIG. <b>1</b>, this problem is solved by the provision of a rollover bit in the Status Register <b>11</b>, set by the ROLLOVER <b>34</b> signal. This rollover bit is configured to be read/write mask, i.e. it can only be cleared by writing a one to it when it already is set to one, and this write may only come from the Micro Controller <b>3</b>, a feature which enhances security. The Rollover <b>34</b> signal is generated by the Real Time Clock <b>5</b> described above. The 32 bits of the SC <b>305</b> output, as per FIG. <b>8</b>, represents a carry-over at 2<sup>32</sup> cycles, corresponding to about 136 years when operating in conjunction with a 32.768 KHz crystal. This is well within the contemplated lifetime of any SPU product. Even clocking the circuit at something like 32.768 MHz, three orders of magnitude higher, were this tolerated by the oscillator circuitry would result in a rollover after every 49.7 days, a long time for a would-be attacker to wait, and even then such attacker would be foiled by the rollover bit feature, as a rollover should never occur within the contemplated lifetime of the product, as just discussed. Resorting to a second rollover would not work, as the rollover bit cannot be cleared by a second carry-over, as just described.
This approach has the advantages of its low cost of implementation, the small amount of SPU real estate it requires, and its compatibility with a simple ripple counter architecture, yet not inviting additional security risks.
The security offered by the RTC Rollover Bit is supplemented by a general clock integrity check as shown in FIG. <b>14(a)</b>. The process begins at step <b>551</b> by reading back from RAM <b>8</b>, or some special register, a prior readout of the Real Time Clock <b>5</b> stored by this process <b>552</b>. A monotonicity test is performed by comparing the present time with the prior stored reading <b>553</b>. If the present time is less, a security problem has arisen and is signalled <b>560</b> and the process should then terminate <b>558</b>. If the present time is indeed greater, then it is stored for a future monotonicity test <b>554</b>. Next, a fixed benchmark performance test is conducted <b>555</b>; many of these types of tests are well-known in the art and need not be alluded to here. The important thing is that such test take a given number of system clock cycles, CTTL <b>25</b>, such length established during production time testing or alternatively, clocked at run time for the given number of cycles. At the completion of the benchmark test, the completion time, as measured by the Real Time Clock <b>5</b>, should be stored <b>556</b>. Thus, the benchmark test elapsed time, as measured by the Real Time Clock <b>5</b>, can be calculated and compared with the number of CTTL <b>25</b> clock cycles. The initial calibration of the System Clock <b>2</b>, that is, the setting of its operational frequency, should provide the necessary conversion factor between the Real Time Clock <b>5</b> and the System Clock <b>2</b>, allowing such a comparison. As described earlier, the System Clock <b>2</b> also exhibits a considerable degree of variability with temperature; thus, the time comparison should take into account some operational tolerance <b>557</b>. If the comparison falls outside this tolerance, the security problem should be signalled <b>559</b>, but in either case the process would then terminate <b>558</b>.
v. <u>VRT Security Bit and the Power Integrity Check</u>.
The VRT Security Bit is provided to inform the system that both the battery and system power have simultaneously dropped below an acceptable voltage, for example 2V. When that occurs, any volatile storage information, as well the time count in the Real Time Clock <b>5</b> may be lost. References to RAM <b>8</b> in this context will be deemed to include off-chip RAM powered by VOUT <b>23</b>. Referring to FIG. <b>1</b>, the VRT bit may be implemented as a special bit in the Status Register <b>11</b>, with voltage dejection circuitry tied to VPP <b>24</b>, such as pull-up or pull-down resistors, designed to make the bit go low in the absence of sufficient voltage. Thus, the VRT bit is cleared by the Power Block <b>13</b>, and is only set by the Micro Controller <b>3</b> via Status Read/Write lines <b>36</b>. The VRT bit is used in conjunction with rewritable-memory modification detection codes on the RAM <b>8</b>, to perform an overall integrity check on the battery-backed section of the SPU. The modification detection codes may be any one of an assortment of suitable codes, as is well-known in the art, from a simple checksum, to a cyclic redundancy check (CRC), to more elaborate algorithms such as MD5 owned by RSA Data Security, Inc., each affording different levels of security, compactness and error recoverability. For example, a simple checksum, while easy to implement, allows a large degree of freedom for an attacker to overwrite the contents of RAM <b>8</b> while preserving the same overall checksum. Whichever modification detection code is used, the code result is conventionally stored along with the RAM <b>8</b> it is measuring.
With reference now to FIG. <b>14(b)</b>, the general power integrity check process <b>251</b> will be described. As the SPU is powered up, the Micro Controller <b>3</b> performs the necessary initialization operations on the SPU <b>252</b>. Then, the Micro Controller <b>3</b> polls the Status Register <b>11</b> to ascertain the state of the VRT bit <b>253</b>. If the VRT bit is set to 1, a modification detection operation on the RAM <b>8</b> is performed <b>254</b>. Then, the SPU determines if any modification has been detected <b>255</b>. If not, the SPU is said to be in its normal operating state, and thus should only implement commands that give restricted access to its secret data <b>256</b>, and the process then exits <b>257</b>.
If a modification has been detected, the SPU is in an error state and so the security problem is signalled <b>258</b> and the process exits <b>257</b>.
If the VRT bit is set to 0, a modification detection operation is also performed <b>259</b>. If no modification is detected, the SPU is in a secure, albeit low power state; in other words, although the RAM <b>8</b> presently checks out, the power cannot be trusted and so this problem should be signalled <b>261</b> and the process exits <b>257</b>.
Finally, there is the scenario where modification was detected, yet VRT is 0 -- this modification detection is spurious as the RAM <b>8</b> is in a random configuration, i.e. it is said to be in the manufacturing state. The following is a description of a response taken in one embodiment of this invention, and should not be read to preclude any number of possible responses in this state. In this one embodiment, the SPU could zeroize all secret data areas and use the default operational configuration parameters, such as the lowest System Clock <b>2</b> oscillator frequency, stored preferably in the ROM <b>7</b>, to operate in the most trustworthy state <b>262</b>. The SPU then could enter a mode whereby manufacturing tests may be performed and the configuration parameters may be set <b>263</b>. Then, any manufacturing tests may be performed in order to guarantee the reliability of the SPU <b>264</b>. Once those tests have been made successfully, the secret data, such as the keys, may be loaded, and a modification detection code performed on the entire contents of RAM <b>8</b> and stored therein <b>265</b>. Finally, the SPU will set the VRT bit to 1, putting it into the normal operating state <b>266</b>, after which the process may exit <b>257</b>.
vi. <u>Bus Monitoring Prevention</u>.
With PDPS one is concerned with protecting secret information which, among other objectives, implies thwarting any attempt to monitor the internal data transactions that carry secret information. It is axiomatic that a device incorporating PDPS must have input and output ports, taking in data, performing operations on this data using the internal secret information and then outputting the resulting data. If an integrated circuit could be altered in such a way that the secret information contained in the device could be extracted through an input or output port, or if a random failure within the device caused this to happen, then the PDPS system would no longer be secure.
Prior solutions for keeping secret information have involved restricting such information to within the confines of a single integrated circuit chip, thus preventing an interloper with standard evaluation tools from monitoring inter-chip data traffic and thereby discerning the secret information. This confinement approach required a high degree of chip integration, in order that all functions needing the secret information are implemented on the same piece of silicon. Also, input and output ports of these integrated circuits would need to be disabled while secret information was being internally transferred.
The prior solutions relied on the difficulty in modifying already complete manufactured integrated circuits. This is no longer the case, as semiconductor evaluation tools have drastically improved in their sophistication and capabilities. It is now possible to modify parts of an integrated circuit without damaging the other parts or the chip's overall function. Thus, a device which would keep its secret information on internal buses only, could now be modified to transfer that information to its input or output ports. This is a lot easier to implement than creating specially-made probes to tap into the internal bus. It should be repeated that even random failures within an integrated circuit have been known to result in a similar scenario. In both cases, therefore, monitoring the input and output ports would allow the secret information to be determined.
The basis on which to combat this problem, in the present invention, is to create a mechanism internal to the chip that verifies that the original design of the input or output circuitry has not been modified by either an attack or random failure, before bringing out any secret information onto the internal bus. This is accomplished by interrogating critical circuit components to ensure that they are intact and functioning correctly. The detection of a security breach could thus be acted upon accordingly, but at the very least, the bus should be disabled from bringing out any secret information. Also, the secret information should be brought out in several pieces, which has the virtue that, were a random hardware fault to occur precisely when secret information was brought onto the internal bus, then only a small and probably useless portion would be compromised.
The SPU contains ports that allow data to be transferred from an internal secure bus to external buses. The implementation is brought about, in one embodiment, with special circuitry that is added to the input/output ports and special routines in firmware that are executed by the internal Micro Controller. The internal Micro Controller keeps an internal copy of the last data written to the output register of that port. The internal Micro Controller reads the contents of both the input and output registers; typically, only the input registers can be read by the internal Micro Controller. Before bringing secure information onto the bus, the Micro Controller interrogates the port to ensure that the last valid data written to the port is still in place; otherwise, the Micro Controller does not bring secret information onto the bus. If valid data is in place, then a portion of the secret data is brought onto the bus and transferred internally as necessary. The port is again checked to ensure that valid data is in place in the input/output port's output register. If the secret data, or any other data, is detected in the ports then the Micro Controller does not bring any other secret information onto the bus. This is continued until all secret information is transferred to its internal destination.
It should be noted that the use, or non-use, of the Bus Monitor is a process controlled from firmware. Referring to FIG. <b>15</b>, this process shall now be described in detail. Upon the Start <b>320</b>, the Micro Controller <b>3</b> determines whether secret data needs to be transferred onto the Internal Bus <b>10</b> in step <b>352</b>. If not, data may be transferred on the Internal Bus <b>10</b> in the conventional manner <b>353</b>. If secret data is to be transferred on the Internal Bus <b>10</b>, the Micro Controller <b>3</b> reads back the output port registers <b>354</b>, and stores them in temporary storage <b>355</b>. In one embodiment, before secret data is moved onto the Internal Bus <b>10</b>, non-secret data is sent over the Internal Bus <b>10</b> as a test <b>356</b>. The output port registers are again read back <b>357</b>, and compared with the previously stored read back <b>358</b>. Should they prove different, the process aborts and signals the security problem <b>325</b> and exits at step <b>362</b>, but if they are the same, the process may proceed, as part of a loop, to determine whether any and all parts of the secret data have already been transferred on the Internal Bus <b>10</b> in step <b>359</b>. If not, the next part of the secret data is moved on the Internal Bus <b>10</b> at step <b>360</b> and then the process loops back to step <b>357</b> to read back the output port registers again. If all parts of the secret data has been transferred, the process loops back to step <b>352</b> to control further data transfers on the Internal Bus <b>10</b>.
This approach has the virtue of relatively low cost implementation, without any special semiconductor processing. It also guards against combined physical and electrical attacks, as well as random failures. This system, by being implemented in multiple blocks within the integrated circuit, in conjunction with firmware operated by the Micro Controller, would be expensive and difficult to reverse engineer.
vii. <u>Trip Wire Input</u>.
Many of the concerns regarding attack on the input/output pins of the SPU, described above in the context of the Bus Monitor Prevention, may be addressed through monitoring of just these pins, providing cryptographic alarms or trip wires to just those kind of attacks. An attacker may be monitoring any given pin, to determine its functionality. The PINs <b>32</b> of the I/O Port <b>1</b>, being programmable, are ideally suited to detect any such unexpected read or writes. Furthermore, they may be used not only to detect an attacker usurping these PINs <b>32</b>, but may also be used as inputs from off-chip external detectors, such as a battery of photo detectors arrayed inside a PCMCIA card.
With reference to FIG. <b>16</b>, the process that begins at step <b>401</b> will now be described in detail. A given bit, the Xth bit, on the I/O Port <b>1</b> is set to a 1 <b>402</b>. The process waits until the operating system has determined it is time for the I/O Port <b>1</b> to be checked <b>403</b>. This should take into account, for instance, when such pin needs to be used for regular I/O operations. When such time arrives, the Xth bit is read <b>404</b> and checked if it is still a 1 <b>405</b>. If so, the process may return to its wait state at step <b>402</b>. Otherwise, the process aborts and signals the security problem <b>406</b>, and the process exits <b>407</b>.
viii. <u>Software Attack Monitor</u>.
One of the least expensive ways to defeat the security system in a hardware device (which may contain a plurality of components such as a microprocessor, PAL's, etc.) is to mount a random data electronic attack on the hardware device. Specifically, an attacker could send signals (which may be commands, data, or random signals) to the input pins of some of the components in the device and monitor the output pins of the same and/or different components. This kind of attack requires little or no special hardware, and the attacker may be able to learn confidential information contained in or protected by the hardware device.
A typical attack strategy is now described. An attacker would monitor the hardware and software operation of the components for some period of time during normal operation. As a result, the attacker could determine the normal command structure of the programmable components in the hardware device. The attacker would then create his/her own command sequences (e.g., by slightly modifying the commands or the command operators, or even creating entirely different commands) based on the information obtained. The reaction of the components to these command sequences is then recorded, as thus building up a "characterization database." As the operation of the components becomes understood, the signals sent to the components are no longer random but are designed to identify commands that could defeat the security of the system.
It can be seen from the above attack strategy that the components in the hardware device, including the microprocessor, will receive a large number of invalid commands, at least during the initial phase of the attack. Consequently, one aspect of the present invention is for the SPU to detect the occurrence of an excessive number of invalid commands and to take appropriate actions to defeat or hinder the attack. One should bear in mind that some perfectly innocent functions generate a series of invalid commands, as for example, when a computer upon boot-up interrogates all peripheral devices and ports to determine if they are present and active.
One means by which to measure an "excessive number" of invalid commands is to determine the number of invalid commands per unit time. The appropriate time unit can be determined by: (1) the rollover time of a counter driven by an oscillator, such as RTCLK <b>29</b>; (2) a predetermined number of ticks of the Real Time Clock <b>5</b>; or (3) a software timing loop. If the number of invalid commands per unit time exceeds a predetermined value ("limit parameter"), appropriate action will be taken by the SPU.
In some situations, it may be preferable for the SPU to set several limit parameters, each having an associated action. FIG. <b>17</b> contains a flowchart <b>940</b> which includes four limit parameters. Note that the number of limit parameters is illustrative only, and any number of limit parameters may be used. The flowchart begins at step <b>940</b> and then sets the values of each of the four limit parameters <b>942</b>. The flowchart then branches into a loop consisting of blocks <b>946-966</b>.
In block <b>946</b>, the SPU determines whether a command is valid. If the command is valid, it is processed in the regular manner (block <b>948</b>). The flowchart then branches back to block <b>946</b> to fetch and examine another command. If the command is not valid, flowchart <b>940</b> goes to block <b>950</b>, which calculates the number of invalid command per unit time. The result of the calculation is compared with the first limit parameter (block <b>952</b>). If the result is less than the first limit parameter, then no tamper-reactive action is taken, and the flowchart branches back to block <b>946</b> to process the next command. If the result is larger than the first limit parameter, the process generates a signal indicating a first level security problem (block <b>954</b>).
The flowchart then branches to block <b>956</b>, which compares the number of invalid commands per unit time with a second limit parameter. If the number is less than the second limit parameter, then no additional action is taken, and flowchart <b>940</b> branches back to block <b>946</b> to process the next command then. If the number is larger than the second limit parameter, the process generates a signal indicating a second level security problem (block <b>958</b>).
The flowchart <b>940</b> then branches to block <b>960</b>, which compares the number of invalid commands per unit time with a third limit parameter. If the number is less than the third limit parameter, no additional action is taken, and flowchart <b>940</b> branches back to block <b>946</b> to process the next command. If the number is larger than the third limit parameter, the process generates a signal indicating a third level security problem (block <b>958</b>).
The flowchart <b>940</b> then branches to block <b>964</b>, which compares the number of invalid commands per unit time with a fourth limit parameter. If the number is less than the fourth limit parameter, no additional action is taken, and flowchart <b>940</b> branches back to block <b>946</b> to process the next command. If the number is larger than the fourth limit parameter, the process generates a signal indicating a fourth level security problem (block <b>958</b>).
It is of course up to the supervisory program to decide what steps to take in response to signals of the various limit security problems. The SPU can be programmed to take any or all appropriate actions.
<u>c. Programmable Security</u>.
The Programmable Distributed Personal Security System is based on the orchestration of three conceptually distinct, but nonetheless, interrelated systems: (i) detectors, which alert the SPU to the existence, and help characterize the nature, of an attack; (ii) filters, which correlate the data from the various detectors, weighing the severity of the attack against the risk to the SPU's integrity, both to its secret data and to the design itself; and (iii) responses, which are countermeasures, calculated by the filters to be most appropriate under the circumstances, to deal with the attack or attacks present. The selection of responses by the filters would be said to constitute the "policy" of the SPU. The present invention permits a wide capability in all three of the detectors, filters and responses, allowing a great degree of flexibility for programming an appropriate level of security/policy into an SPU-based application.
The effectiveness of this PDPS trio is enhanced significantly by the other design features of the SPU architecture disclosed herein, for example: the Power Block <b>13</b>, Power Isolation <b>13</b>, Silicon Firewall <b>20</b>, System Clock <b>2</b> and Real Time Clock <b>5</b>, and the Inverting Key Storage. Although the implementation of some of these features creates security barriers, which do not strictly fit into the detector/filter/response paradigm, the presence of these barriers certainly slows or even thwarts an attacker's progress, allowing for more time to detect an attack, filter out the characteristics of such attack and thus make a more measured response thereto.
i. <u>Detection</u>.
A wide variety of detectors have already been disclosed -- some implemented in hardware, others in firmware. Some may bear witness unambiguously to an actual physical intrusion into the SPU, such as the Metallization Layer Detector <b>18</b>; others such as the Photo Detector <b>16</b> may be triggered by noninvasive means such an X-ray of the SPU, or by very invasive means, such as the actual de-encapsulation of the chip. Again, the purpose at this stage is not to decide on the course of action, nor even to coordinate all related information; it is simply to report the detection and move on.
Referring to FIG. <b>18</b>, the process of how detectors are generally handled will now be described. The process begins <b>451</b> by a decision of whether the detector signal is generated by hardware or firmware <b>452</b>. The exact nature of how this step is taken is unimportant. Here it is represented by an interrupt generated in the Micro Controller <b>3</b>, but it could just as easily be based on some periodic polling of registers or any other equivalent method well-known to practitioners in the art. Even the distinction between firmware and hardware detectors is at a certain level irrelevant, as the parallelism present in FIG. <b>18</b> shows. If the interrupt was generated by hardware, the Status Register <b>11</b> would then be polled <b>453</b>. In this implementation, the key to determining whether indeed any hardware detector was activated was that one or more bits of the Status Register <b>11</b> should have changed from the last time it was read <b>454</b>. If so, the SPU could then take actions as dictated by its programmed policy <b>455</b>. If not, either an error has occurred owing to a false detection or certain operational features are in play, such as the signal owing to a periodic wake-up of the SPU under battery power. In either case, action dictated by policy, given such an error or feature, should then be taken <b>460</b>. Alternatively, at step <b>452</b>, had the signal originated in firmware, the process would set about determining the routine generating it <b>461</b>. If such routine proved to be a valid one <b>462</b>, again action should be taken as dictated by policy <b>455</b>. Otherwise, action consistent with this error or possible feature should be taken, again as dictated by policy <b>463</b>. All the aforementioned scenarios thereafter converge. If, in accordance with one alternate embodiment disclosed herein, an alarm wake-up capability is provided, and the process was invoked owing to such an alarm <b>456</b>, the process would then generate the SLEEP <b>41</b> signal <b>459</b> and terminate <b>458</b>. Otherwise, the process would return from interrupt or whatever housekeeping required in accordance with the particular implementation used <b>457</b> and then terminate <b>458</b>.
ii. <u>Filtering</u>.
The programmable filtering process lies at the heart of PDPS; without it one merely has hardwired and indiscriminate responses to various attacks. With reference to FIG. <b>19</b>, this process itself consists of two stages: (i) correlating signals produced by the various detectors to ascertain the attacks involved (FIGS. <b>19(a)</b>, <b>19(b)</b>, <b>19(c)</b>); and (ii) based on the attacks involved, to select an appropriate response (FIGS. <b>19(d)</b>, <b>19(e)</b>, <b>19(f)</b>). There are, of course, operational factors involved at both stages of this process. These factors may be static and intrinsically related to the type of application, the architecture of the SPU, etc., or they may be dynamically varying and related to, for example: (i) the prior history or frequency of detected signals, responses, or all events; (ii) the present state of the SPU; (iii) the present stage or mode of the application; (iv) the potential harm a given attack may represent; or (v) combinations of factors or detectors, for example, coming from a given set, occurring in a particular order, or occurring within a fixed time frame.
The conditions whereby the detectors are correlated are as follows. In FIG. <b>19(a)</b>, a false alarm condition is shown. A signal is detected, D<sub>a</sub><b>501</b>, without corresponding to any real attack, A<sub>0</sub><b>502</b>. There are various means by which such a false alarm could be discerned. For example, the detector producing the D<sub>a</sub><b>501</b> signal could be polled once more to determine whether the first reading was spurious or not. Alternatively, it may be inferred from the state of other detectors. Such a scenario will be discussed in the context of FIG. <b>19(c)</b>. FIG. <b>19(b)</b> demonstrates an opposite extreme, where a signal D<sub>b</sub><b>503</b> corresponds unambiguously to one attack, A<sub>b</sub><b>504</b>. However, most attacks will be characterized as in FIG. <b>19(c)</b>, where each of one or more detectors, D<sub>c1</sub><b>505</b>, D<sub>c2</sub><b>506</b> and D<sub>c3</sub><b>507</b>, in conjunction with zero or more factors, F<sub>c1</sub><b>508</b>, F<sub>c2</sub><b>509</b> are required to fully characterize a given attack, A<sub>c</sub><b>510</b>.
The selection of responses to attacks fall into the following categories. There is, of course, the non-response R<sub>0</sub><b>512</b>, in FIG. <b>19(d)</b>, whereby no action is taken for a given attack, A<sub>d</sub><b>511</b>. This may owe to a lack of capability, a deliberate design choice, or an application decision. In FIG. <b>19(e)</b>, analogous to the unambiguous condition of FIG. <b>19(b)</b>, there is the unconditional response R<sub>e</sub><b>514</b> to an attack A<sub>e</sub><b>513</b>. This may represent a last-ditch scenario, where all outer defenses have been breached and some unequivocal and serious countermeasure needs to be taken. On the other hand, it may also be an application decision. Finally, in FIG. <b>19(f)</b>, there is the general scenario where one or more attacks, A<sub>f1</sub><b>515</b>, A<sub>f2</sub><b>516</b>, in conjunction with zero or more factors, F<sub>f1</sub><b>517</b>, F<sub>f2</sub><b>518</b>, F<sub>f3</sub><b>519</b>, must have been or are present, in order to select the response R<sub>f</sub><b>520</b>.
By custom tailoring the correlation of the detector signals, as well as the selection of the responses, a programmable security system can be application- as well as environment-specific.
iii. <u>Responses</u>.
The final system of PDPS involves the provision of a wide variety of responses, to allow for a rich and full set of countermeasures to any conceivable attack scenario. These responses can be categorized into five major groups: (i) passive; (ii) alarms; (iii) decoy activity; (iv) restriction of access; and (v) destructive. Examples of each are given in TABLE I, which is meant to be an illustrative, but by no means exhaustive, list. <tables id="tabl0001" num="0001"><table frame="all"><title>TABLE I</title><tgroup cols="5" colsep="1" rowsep="0"><colspec colnum="1" colname="col1" colwidth="31.50mm" /><colspec colnum="2" colname="col2" colwidth="31.50mm" /><colspec colnum="3" colname="col3" colwidth="31.50mm" /><colspec colnum="4" colname="col4" colwidth="31.50mm" /><colspec colnum="5" colname="col5" colwidth="31.50mm" /><thead valign="top"><row rowsep="1"><entry namest="col1" nameend="col5" align="center">Examples of Typical Responses</entry></row><row rowsep="1"><entry namest="col1" nameend="col1" align="left">Passive</entry><entry namest="col2" nameend="col2" align="left">Alarm</entry><entry namest="col3" nameend="col3" align="left">Decoy</entry><entry namest="col4" nameend="col4" align="left">Restricted Access</entry><entry namest="col5" nameend="col5" align="left">Destructive</entry></row></thead><tbody valign="top"><row><entry namest="col1" nameend="col1" align="left">• Non-response</entry><entry namest="col2" nameend="col2" morerows="1" align="left">• Signal local computer</entry><entry namest="col3" nameend="col3" morerows="2" align="left">• Random command response</entry><entry namest="col4" nameend="col4" morerows="1" align="left">• Disable SPU for period of time</entry><entry namest="col5" nameend="col5" align="left">• Destroy keys</entry></row><row><entry namest="col1" nameend="col1" morerows="1" align="left">• Log attack internally</entry><entry namest="col5" nameend="col5" morerows="1" align="left">• Destroy secret data</entry></row><row><entry namest="col2" nameend="col2" morerows="1" align="left">• Signal remote computer</entry><entry namest="col4" nameend="col4" morerows="1" align="left">• Require recertification</entry></row><row><entry namest="col1" nameend="col1" /><entry namest="col3" nameend="col3" morerows="1" rowsep="1" align="left">• Random external bus activity</entry><entry namest="col5" nameend="col5" morerows="1" rowsep="1" align="left">• Disable SPU permanently</entry></row><row rowsep="1"><entry namest="col1" nameend="col1" /><entry namest="col2" nameend="col2" align="left">• Set I/O Port pin high</entry><entry namest="col4" nameend="col4" align="left">• Disabling use of keys, passwords</entry></row></tbody></tgroup></table></tables>
A passive response would be one where the SPU conveys no external signal, nor functions in any observable manner differently from its normal mode of operation. This would of course include the classic "non-response" discussed earlier, but also an on-board logging of the attack with, its type, timestamp, context, etc.
An alarm response would indeed convey an externally detectable signal. The SPU may signal the calling application, for instance, to alert the user that the SPU is aware of the attack and may have to proceed to more drastic measures if such attack is not discontinued. In a situation where the SPU is connected via a network or modem to some monitoring computer, as for example, in an information metering context, the SPU may signal that remote computer to tell that the local user is attempting to attack it. On the hardware level, an alarm may be implemented simply by setting a particular pin on the I/O Port <b>1</b> high.
A decoy response is one that departs from the normal mode of SPU activity. It may indeed mimic valid SPU activity. Examples would be to execute SPU commands, or to generate signals on the External Bus Interface <b>9</b>, either selected at random or from some predetermined set.
A restricted access response would be to disable some functions from the normal mode of SPU operation. Examples include disabling the SPU totally for some period of rime or until recertified in some manner, or disabling operations involving specific keys or passwords.
Finally, there is the destructive response, which disables functionality of the SPU permanently. Examples include destruction in memory, by erasing keys or other secret data, or permanent physical disablement, such as the burning out of internal fuses.
<u>d. Attack Scenarios</u>.
Now that the overall structure of the invention has been laid out, it is fruitful to describe in detail the various attack scenarios, the manner in which they are conducted, the information or effect they wish to achieve or access, the design features of the SPU that would thwart such an attack, factors that are relevant in reacting to such attacks, and finally, responses appropriate to such an attack. A summary of the applicable disclosed SPU features, detectors and responses is to be found in TABLE II. These scenarios are by no means exhaustive, but merely illustrative. All further references, unless specified otherwise, are to elements of FIG. <b>1</b>. <tables id="tabl0002" num="0002"><table frame="all"><title>TABLE II</title><tgroup cols="4" colsep="1" rowsep="0"><colspec colnum="1" colname="col1" colwidth="39.37mm" /><colspec colnum="2" colname="col2" colwidth="39.37mm" /><colspec colnum="3" colname="col3" colwidth="39.37mm" /><colspec colnum="4" colname="col4" colwidth="39.37mm" /><thead valign="top"><row rowsep="1"><entry namest="col1" nameend="col4" align="center">Summary of Attack Scenarios</entry></row><row rowsep="1"><entry namest="col1" nameend="col1" align="left">Attack Type</entry><entry namest="col2" nameend="col2" align="left">SPU Protective Feature(s)</entry><entry namest="col3" nameend="col3" align="left">Triggered Detector(s)</entry><entry namest="col4" nameend="col4" align="left">Suggested Response(s)</entry></row></thead><tbody valign="top"><row><entry namest="col1" nameend="col1" morerows="5" rowsep="1" align="left">Electrical Attack on I/O Ports</entry><entry namest="col2" nameend="col2" align="left">• Silicon Firewall 20</entry><entry namest="col3" nameend="col3" align="left">• Bus Monitor</entry><entry namest="col4" nameend="col4" morerows="1" align="left">• Random command response</entry></row><row><entry namest="col2" nameend="col2" align="left">• Alarm wake up</entry><entry namest="col3" nameend="col3" align="left">• Trip Wire Input</entry></row><row><entry namest="col2" nameend="col2" /><entry namest="col3" nameend="col3" align="left">• Software Attack Monitor</entry><entry namest="col4" nameend="col4" morerows="1" align="left">• Random external bus activity</entry></row><row><entry namest="col2" nameend="col2" /><entry namest="col3" nameend="col3" morerows="1" align="left">• Metallization layer detector <b>18</b></entry></row><row><entry namest="col2" nameend="col2" /><entry namest="col4" nameend="col4" align="left">• Disable SPU temporarily</entry></row><row rowsep="1"><entry namest="col2" nameend="col2" /><entry namest="col3" nameend="col3" align="left">• Photo Detector <b>16</b></entry><entry namest="col4" nameend="col4" align="left">• Disable SPU permanently</entry></row><row><entry namest="col1" nameend="col1" morerows="3" rowsep="1" align="left">Clock Attack</entry><entry namest="col2" nameend="col2" align="left">• Silicon Firewall <b>20</b></entry><entry namest="col3" nameend="col3" align="left">• RTC Rollover Bit</entry><entry namest="col4" nameend="col4" align="left">• Use other clock</entry></row><row><entry namest="col2" nameend="col2" align="left">• System Clock 2</entry><entry namest="col3" nameend="col3" align="left">• Monotonicity test</entry><entry namest="col4" nameend="col4" morerows="1" align="left">• Disable metering functions</entry></row><row><entry namest="col2" nameend="col2" align="left">• Real Time Clock 5</entry><entry namest="col3" nameend="col3" align="left">• System/Real Time Clock cross-check</entry></row><row rowsep="1"><entry namest="col2" nameend="col2" /><entry namest="col3" nameend="col3" align="left">• Temperature Detector <b>17</b></entry><entry namest="col4" nameend="col4" /></row><row><entry namest="col1" nameend="col1" morerows="3" rowsep="1" align="left">Key Attack</entry><entry namest="col2" nameend="col2" align="left">• Battery-backed RAM <b>8</b></entry><entry namest="col3" nameend="col3" morerows="1" align="left">• Metallization layer detector <b>18</b></entry><entry namest="col4" nameend="col4" align="left">• Disable use of keys</entry></row><row><entry namest="col2" nameend="col2" align="left">• Metallization layer</entry><entry namest="col4" nameend="col4" align="left">• Destroy keys</entry></row><row><entry namest="col2" nameend="col2" align="left">• Inverting key storage</entry><entry namest="col3" nameend="col3" align="left">• Bus Monitor</entry><entry namest="col4" nameend="col4" /></row><row rowsep="1"><entry namest="col2" nameend="col2" /><entry namest="col3" nameend="col3" align="left">• VRT Security Bit</entry><entry namest="col4" nameend="col4" /></row><row><entry namest="col1" nameend="col1" morerows="1" rowsep="1" align="left">Physical Attack</entry><entry namest="col2" nameend="col2" align="left">• Physical coating</entry><entry namest="col3" nameend="col3" align="left">• Temperature Detector <b>17</b></entry><entry namest="col4" nameend="col4" align="left">• Disable keys, secret data</entry></row><row rowsep="1"><entry namest="col2" nameend="col2" align="left">• Metallization layer</entry><entry namest="col3" nameend="col3" align="left">• Photo Detector <b>16</b></entry><entry namest="col4" nameend="col4" align="left">• Destroy keys, secret data</entry></row><row rowsep="1"><entry namest="col1" nameend="col1" align="left">Combination Attack</entry><entry namest="col2" nameend="col2" align="left">• Any/all of the above</entry><entry namest="col3" nameend="col3" align="left">• Any/all of the above</entry><entry namest="col4" nameend="col4" align="left">• Any/all of the above</entry></row><row><entry namest="col1" nameend="col1" morerows="3" rowsep="1" align="left">User Fraud</entry><entry namest="col2" nameend="col2" align="left">• Silicon Firewall <b>20</b></entry><entry namest="col3" nameend="col3" align="left">• RTC Rollover Bit</entry><entry namest="col4" nameend="col4" align="left">• Signal Local Computer</entry></row><row><entry namest="col2" nameend="col2" align="left">• Power Block <b>13</b></entry><entry namest="col3" nameend="col3" align="left">• Monotonicity test</entry><entry namest="col4" nameend="col4" align="left">• Signal Remote Computer</entry></row><row><entry namest="col2" nameend="col2" /><entry namest="col3" nameend="col3" align="left">• System/Real Time Clock cross-check</entry><entry namest="col4" nameend="col4" align="left">• Disable metering functions</entry></row><row rowsep="1"><entry namest="col2" nameend="col2" /><entry namest="col3" nameend="col3" align="left">• VRT Security Bit</entry><entry namest="col4" nameend="col4" align="left">• Require recertification</entry></row></tbody></tgroup></table></tables>
i. <u>Electrical Attack on I/O Ports</u>.
Arguably, the simplest form of attack would be an electrical attack on the I/O Port <b>1</b>. This type of attack requires very little special hardware. The attacker simply uses the same system configuration that is used in the normal application, however instead of using the intended software, the attacker creates his own code to interrogate the device. The attacker could go one step further and place monitoring equipment on strategic points in the circuit, as for example, the SPU pins or PAL outputs. This would allow the attacker to more thoroughly characterize the chip in its normal operation, and when it is under attack.
The typical approach would be to monitor the hardware or software for some period of time during normal operation. From this the attacker could determine the normal command sequence. After this characterization, the attacker could then create his own command sequences based on the information he has obtained. He could try to slightly modify the commands or the command operators to get the device to perform different functions. He might also try to issue commands that he did not see before to see how the device would react. All during this process the attacker would be recording the responses to the different stimuli. As patterns are detected, the data that is issued to the device is no longer random but designed to further evaluate the particular operation. This continues until a particular operation is fully characterized. It would be the attacker's intention to identify commands or responses that could defeat the overall system. For example, the attacker might be looking for a reset operation command, and could then issue such command at inappropriate times.
The Silicon Firewall <b>20</b> would prevent asynchronous signals from the attacker overwhelming the system. The Software Attack Monitor (FIG. <b>17</b>) would be very sensitive to the overall characterization process. Possibly appropriate responses, in accordance with the measured stages of the Software Attack Monitor, would be to lead an attacker astray with random responses, or eventual disablement of the SPU.
ii. <u>Clock Attack</u>.
Many applications of the SPU could employ the Real Time Clock 5 advantageously, as for example in information metering. However, the Real Time Clock <b>5</b> could be attacked in a variety of ways. The external crystal <b>15</b> could be substituted to modify the frequency of the RTC Oscillator <b>15</b> and hence the internal Real Time Clock <b>5</b>. The SPU is designed to perform integrity tasks, one of which is to check the Real Time Clock <b>5</b> against the System Clock <b>2</b> to see if it is operating in the correct range (FIG. <b>14(a)</b>). However, in one embodiment, these integrity tasks would be performed only when the entire system is powered; when system power VDD <b>22</b> is removed, when only the battery-backed Real Time Clock <b>5</b> remains operational. It is at this opportunity that an attacker could attack the external crystal <b>15</b> without immediate detection. As the Real Time Clock <b>5</b> uses a simple binary ripple counter, an attacker could advance the counter until it rolled over. Subsequently, the attacker could continue to run the clock forward to whatever given time reading he wished. This is analogous to the resetting of the odometer of a used car by an unscrupulous dealer.
The inaccessibility of the Internal System Clock <b>2</b> to attack, and the Real Time Clock <b>5</b> buffering the time signal through an internal Silicon Firewall, certainly stand as barriers in the attacker's way. The System Clock/Real Time Clock cross-check of FIG. <b>14(a)</b> would detect any switch on power up. If an attacker tried to set the System Clock <b>2</b> off by cooling or heating the SPU, the Temperature Detector <b>17</b> would give such approach away, as well as a clock cross-check, hitherto successfully, eventually failing for falling outside the operational tolerance. Furthermore, an attacker attempting to rollover the Real Time Clock <b>5</b> would cause the ROLLOVER <b>34</b> signal to go off. A possible response would be to use the System Clock <b>2</b> to whatever extent possible in lieu of the Real Time Clock <b>5</b> should that clock prove untrustworthy. However, that option is highly application-dependent, in an information metering context. A more likely response would be to disable all metering functions.
iii. <u>Key Attack</u>.
Secret information is stored in volatile memory, such as RAM <b>8</b> within the SPU, rather than ROM <b>7</b>. This is done to prevent an attacker from gaining access to this information by simply de-encapsulating the SPU chip and "reading" the schematic. However, when keys or other such secret information are stored in volatile memory within a chip, one can deprocess the chip and detect residual charge in the volatile memory which may reveal the contents stored therein. The act of deprocessing would cause power to be removed from the volatile memory, thus causing the data within the memory to be lost, as the charge decays within the semiconductor. However, if the volatile memory contains the same data for a protracted period of time, charge may build up in the dielectric portion of the memory cell, charge which may be feasible to detect despite removal of power. Also, it may be possible to artificially age the memory device by elevating the voltage and changing the operational temperature of the silicon, thus making the SPU even more susceptible to this memory effect.
As described earlier, the Inverting Key Storage (FIGS. <b>9</b>, <b>10</b>) feature would thwart such key attack by averaging out any residual charge. The de-encapsulation process would be rendered more difficult by the presence of the Metallization layer, and the Metallization Layer detector <b>18</b> would be set off the moment such layer was cut. The protocol of the Bus Monitor Prevention (FIG. <b>15</b>), transferring only parts of keys from RAM <b>8</b> to the DES Block <b>6</b> via Internal Bus <b>10</b> would hinder tracing the keys, as well as giving away such attempts. Possible responses might be to disable the keys or other secret data from use, or where the security concerns are very high, or the assault unrelenting, to finally destroy them. Active zeroization could be used to assure such process of erasure is complete.
iv. <u>Physical Attack</u>.
An attacker might try to de-encapsulate a chip in order to reverse engineer it. Simple observation of the chip layout can lead one experienced in the art to determine where the Micro Controller <b>3</b>, I/O Port <b>1</b>, memory, etc., are located. Recognizing the pedigree of a chip. i.e. knowing the manufacturer and the series number and prior chips therefrom, can also aid in the resolution of functionality. Some structures are laid down randomly; others such as RAM and ROM are well-known and normally laid down in regular patterns via chip design macros, meaning that large areas of a chip need not be reverse engineered. Detailed resolution of the chip layout can result in reverse engineering of a chip, a process that might cost as much as $100,000 with today's technology.
Semiconductor industry evaluation tools now provide the capability of making edits to an integrated circuit after processing has been completed. For example, Focused Ion Beam Mill technology has advanced to the point where the equipment is capable of selectively removing or depositing material on the surface of an integrated circuit. These devices can remove layers of metal and oxide and also lay down layers of metal on the integrated circuit's surface. These devices are ostensibly used to debug integrated circuits by cutting metal traces that connect logic gates and by reconnecting the logical gates in a different manner. It is feasible to lay down internal probes; however, it is less costly and less difficult to modify an existing I/O port.
This kind of attack would first be thwarted by the physical coatings on the SPU, then the Metallization Layer; both acting to make difficult the process of ascertaining the chip layout and to actuate a connection of a test probe to nodes within the SPU. Such an attack would likely trigger the Metallization Layer Detector <b>18</b>, the Photo Detector <b>16</b>, and running the altered circuit live under system power VDD <b>22</b> would likely trigger the Bus Monitoring Prevention (FIG. <b>15</b>). The same responses as given above would likely be appropriate as well. The actual act of de-encapsulation through grinding can create enough heat to trigger the Temperature Detector <b>17</b> as well as set off a vibration detector, and again, unless done in total darkness, exposure of the die would set off the Photo Detector <b>16</b>. Disabling or even destroying the keys and secret data seem the most likely responses to such a scenario.
v. <u>Combination Attack</u>.
Deprocessing is a sophisticated process, requiring first de-encapsulation and then placing the chip, under power, on an ion probing station. Such a machine can actually detect voltage potentials at different pans of the chip, resolving the operational characteristics thereof. The probe cannot observe through a Metallization Layer; however, this would only serve to slow such a machine down. The machine can also be used to remove the Metallization Layer and thus uncover previously secure areas. The attacker might even try to reconnect any broken traces in the Metallization Layer before attempting to access secret information.
This attack would be slowed by practically every SPU protective feature, trigger practically all the aforementioned detectors, and could certainly be frustrated by any of the responses discussed and more. No guarantee of absolute security can ever be made, but as here the SPU, subject to the full range of defenses, would make an attack so costly in time and money, as to make the whole attempt pointless for the types of applications contemplated.
vi. <u>User Fraud</u>.
The thrust of user fraud is not to reverse engineer the SPU; that is chiefly the province of parties wishing to reproduce compatible or competing SPU products. The fraudulent user instead wishes to use products incorporating an existing SPU outside of its intended use, e.g., not paying, or being wholly undercharged, for information used through an information metering device, which is a likely fraud scenario. Thus, such a user may try simple operations such as trying to rollover the clock, or by resetting the device at various operational stages, a user might hope to interfere with usage reporting or metering. Furthermore, also in the information metering context, by trying to overwrite the RAM <b>8</b>, after a large purchase, with the contents of the same RAM <b>8</b>, from before the purchase, a user might hope to erase the traces of such transaction.
The Power Block <b>13</b>, with its powering up and down mechanisms, the Silicon Firewall <b>20</b>, and the Software Attack Monitor (FIG. <b>17</b>), give an attacker little opportunity for throwing the SPU into an unpredictable or unreliable state by inopportune resets, as discussed before. The protection of the ROLLOVER <b>34</b> signal and the clock cross-checks have also already been well described.
In the information metering context, usage might be based on pre-set credit limits, that should the SPU unit fail, it would be presumed that the credit limit had completely used, and thus the metering functions would be disabled. The user could only overcome this presumption by physically turning over the unit to whatever servicing agent to prove it had not been tampered with, or by remote interrogation via modem for instance, and thereafter have the servicing agent would recertify the SPU device.
<u>e. Sample SPU Application</u>.
Now that the architecture of the SPU, the nature of the detectors, the detection/filtering/response paradigm of PDPS, and the nature of expected attacks have been discussed, it would be useful to proceed through a sample application which illustrates the principles of the present invention. For this purpose, a modest application is postulated: the use of the SPU-equipped PCMCIA card, an "access card", whose sole function is to provide digital cash. It thus operates a simple debit-type card, programmed with a certain amount of money, and debited, through use of a PIN number in various transactions, until the entire programmed-in credit has been exhausted.
The detection/filtering/response process for this access card is as shown in FIG. <b>20</b>. It is by no means meant to be comprehensive, nor necessarily truly realistic, but simply illustrative of the application-specific demands placed upon programmable security. References herein may also be made to other figures or particular elements present in FIG. <b>1</b>. The process starts <b>1001</b> by determining whether any detector has been set off <b>1002</b>. If not, the process loops back to <b>1002</b>, preferably performing all the other tasks necessary to the application in the interim.
If the Photo Detector <b>16</b> is set off <b>1004</b>, the next inquiry is whether such detection is sustained over a period of time <b>1034</b>. For example, the access card may have been briefly passed through an X-ray machine at the airport. Such exposure should be very short term. Thus, if the exposure is not sustained, the event should just be logged <b>1042</b> and the process returns, through connectors <b>1043</b>, <b>1003</b> to step <b>1002</b> (all references to connectors will henceforth be dispensed with for the sake of clarity). If the exposure is sustained, the next inquiry is whether this detection is in conjunction with other detectors going off. This may be the hallmark of many of the attack scenarios discussed earlier. If there is sustained photo detection in isolation, it is suspicious enough on its own that a prudent step might be to disable the access card until it is recertified by an appropriate agent <b>1034</b>, and thereafter the process loops back to step <b>1002</b> until further action is taken. Combined with other detectors going off, however, it might be best to disable the access card permanently <b>1036</b>, and the process would thus end there <b>1037</b>.
If the Temperature Detector <b>17</b> is set off <b>1005</b>, it may then be only necessary to ask whether it occurred in conjunction with other detectors going off <b>1030</b>. This differs from the Photo Detector <b>17</b> scenario in that it is more likely that an access card would be subject to high heat for innocuous reasons, as for example, the user leaving the access card on the car dashboard all afternoon. Thus, the application would be more forgiving to mere sustained high temperature. In that case, the process may simply log the event <b>1042</b> and loop back to step <b>1002</b>. Combined with other detectors going off, it may indeed be wise to disable the access card permanently in step <b>1036</b>.
If the Metallization Layer Detector <b>18</b> is set off <b>1006</b>, it would be hard to justify anything but a harsh policy to such an event, such as to disable the access card permanently <b>1036</b>. An exception would be where the Metallization Layer Detector <b>18</b> were of the LATN cell type (FIG. <b>13</b>), which is so sensitive that other detectors should be correlated to make sure that a serious attack is indeed being made on the access card.
If either the ROLLOVER <b>34</b> signal or the Clock Integrity Check (FIG. <b>14(a)</b>) is triggered (steps <b>1008</b>,<b>1009</b> respectively), it may be safe simply to ignore them <b>1028</b> and loop back to step <b>1002</b>, as this simply is not a time-sensitive application.
If the Power Integrity Check (FIG. <b>14(b)</b>) is triggered <b>1010</b>, two situations are possible: (i) the error state; or (ii) the low-power state. In the error state, the contents of RAM <b>8</b> are no longer trustworthy, which merits that the access card be disabled permanently <b>1036</b>. In the low-power state, the RAM <b>8</b> contents are still trustworthy, but the battery power may soon fail, which therefore merits a message to the user to the effect that if the credit is not soon transferred to another access card, it may be irreparably lost <b>1026</b>. In the latter case, the process would again loop back to step <b>1002</b>.
If either the Bus Monitor (FIG. <b>15</b>) or Trip Wire Input (FIG. <b>16</b>) are triggered <b>1012</b>, there appears little justification to do otherwise than to disable the access card permanently <b>1036</b>.
If the Software Attack Monitor (FIG. <b>17</b>) is triggered <b>1014</b>, a logical first step would be to determine if the access card is still in the handshaking phase <b>1016</b>. This would correspond, for example, to the access card being inserted into a card reader and various protocols attempted until a proper link is established between the card and the card reader. In other words, this "handshaking" process should be excluded from serious security consideration. Thereafter, a particularly important command that the access card should be focused upon is the proper PIN number being issued by the user. Thus, the first time an improper command is given within the period of one transaction <b>1018</b>, the process may simply log the event <b>1042</b>. The second time an improper command is received within the period of one transaction <b>1020</b>, the access card may issue a message to the user warning them not to do it again <b>1024</b>, after which the process would again loop back to step <b>1002</b>. The third time an improper command is received within the period of one transaction <b>1021</b>, the access card may be disabled until recertification by an appropriate agent <b>1039</b>; otherwise, it should be disabled permanently <b>1036</b>.
If none of the above detectors is triggered, the process would loop back again to step <b>1002</b> to await further detected signals.
Although the invention has been described in detail with reference to its presently preferred embodiments, it will be understood by one of ordinary skill in the art that various modifications can be made, without departing from the spirit and the scope of the invention. Accordingly, it is not intended that the invention be limited except as by the appended claims.
20 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15 Sheet 16 Sheet 17 Sheet 18 Sheet 19 Sheet 20
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| WO2004063910A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| EP2131301A4 | Cited by | European Patent Office (EPO) | Search report |
| FR2866450A1 | Cited by | France | Search report |
| AT505459B1 | Cited by | Austria | Search report |
| FR2866450A1 | Cited by | France | Search report |
| US7836516B2 | Cited by | United States of America | Applicant |
| DE102004028338A1 | Cited by | Germany | Search report |
| WO2020002677A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| CN100449558C | Cited by | China | Search report |
| WO2004003711A3 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| KR100464598B1 | Cited by | Republic of Korea | Examiner |
| EP1662419A1 | Cited by | European Patent Office (EPO) | Search report |
| US6976162B1 | Cited by | United States of America | Applicant |
| US12058242B2 | Cited by | United States of America | Applicant |
| WO2004003711A2 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| US7124273B2 | Cited by | United States of America | Applicant |
| US10032211B2 | Cited by | United States of America | Applicant |
| WO0243342A2 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| US8417216B2 | Cited by | United States of America | Applicant |
| US9990208B2 | Cited by | United States of America | Applicant |
| WO2008117467A1 | Cited by | World Intellectual Property Organization (WIPO) | Applicant |
| US8286005B2 | Cited by | United States of America | Applicant |
| US9971615B2 | Cited by | United States of America | Applicant |
| FR3083412A1 | Cited by | France | Search report |
| US7308713B1 | Cited by | United States of America | Applicant |
| US10031759B2 | Cited by | United States of America | Applicant |
| WO2009101445A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| EP2978188A1 | Cited by | European Patent Office (EPO) | Search report |
| US9432362B2 | Cited by | United States of America | Applicant |
| WO0243342A3 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| EP2518974A1 | Cited by | European Patent Office (EPO) | Search report |
| US7242921B2 | Cited by | United States of America | Applicant |
| US12079377B2 | Cited by | United States of America | Applicant |
| EP1605410A3 | Cited by | European Patent Office (EPO) | Search report |
| US8458464B2 | Cited by | United States of America | Applicant |
| US10031759B2 | Cited by | United States of America | Applicant |
| WO2018046300A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| WO0212985A2 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| WO0212985A3 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| EP1400887A1 | Cited by | European Patent Office (EPO) | Search report |
| EP1605410A2 | Cited by | European Patent Office (EPO) | Search report |
| GB2353885B | Cited by | United Kingdom | Search report |
| US10175994B2 | Cited by | United States of America | Applicant |
| GB2381911A | Cited by | United Kingdom | Search report |
| US7702943B2 | Cited by | United States of America | Applicant |
| US8079034B2 | Cited by | United States of America | Applicant |
| CN100428750C | Cited by | China | Search report |
| US10042649B2 | Cited by | United States of America | Applicant |
| US9774457B2 | Cited by | United States of America | Applicant |
| EP2282279A1 | Cited by | European Patent Office (EPO) | Search report |
| US8756427B2 | Cited by | United States of America | Applicant |
| GB2381911B | Cited by | United Kingdom | Search report |
| WO2009101445A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| EP0635790A1 | Cites | European Patent Office (EPO) | Search report |
| US4807288A | Cites | United States of America | Search report |
| US5189700A | Cites | United States of America | Search report |
| WO9413080A1 | Cites | World Intellectual Property Organization (WIPO) | Search report |
11 members in 5 offices
Priority claims9
| Document | Office | Kind | Date |
|---|---|---|---|
| 267788 | United States of America | – | |
| 26778894 | United States of America | A | |
| 26778894 | United States of America | A | |
| 95918978 | European Patent Office (EPO) | A | |
| 95918978 | European Patent Office (EPO) | A | |
| 267788 | – | – | – |
| 95918978 | – | – | – |
| EP19950918978 | – | – | – |
| US19940267788 | – | – | – |
Members11
| Document | Office | Kind | |
|---|---|---|---|
| WO9600953A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO9600953A3 | World Intellectual Property Organization (WIPO) | A3 | |
| EP0715733A1 | European Patent Office (EPO) | A1 | |
| US5533123A | United States of America | A | |
| KR960705284A | Republic of Korea | A | |
| EP0965902A2This record | European Patent Office (EPO) | A2 | |
| EP0715733B1 | European Patent Office (EPO) | B1 | |
| DE69519662D1 | Germany | D1 | |
| DE69519662T2 | Germany | T2 | |
| KR100341665B1 | Republic of Korea | B1 | |
| EP0965902A3 | European Patent Office (EPO) | A3 |
10 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Application deemed to be withdrawnWithdrawn18D | 18D | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: THE APPLICATION IS DEEMED TO BE WITHDRAWNSTAA | STAA | |
| First examination report despatched17Q | 17Q | |
| Designation fees paidAKX | AKX | |
| Request for examination filed17P | 17P | |
| Designated contracting statesAK | AK | |
| Search report despatchedORIGINAL CODE: 0009013PUAL | PUAL | |
| Divisional application: reference to earlier applicationAC | AC | |
| Designated contracting statesAK | AK | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI |
Numbers
- Publication
- 0965902
- Publication, DOCDB
- 0965902
- Publication, EPODOC
- EP0965902
- Application
- 99115659
- Application, DOCDB
- 99115659
- Application, EPODOC
- EP19990115659
Titles3
- German
- Gesicherter Datenrechner mit Kryptographie und Aufdeckung unbefugter Manipulation
- English
- Secure data processor with cryptography and tamper detection
- French
- Processeur de données sécurisé à cryptographie et détection de manipulation non autorisée
Classification
- CPC, 15
- G06F21/81
- G06K19/07
- G06F21/572
- G06F21/71
- G06F21/725
- G06F21/77
- G06F21/86
- G06F2221/2101
- G06F2221/2135
- G06F2221/2153
- H04L9/002
- H04L9/0897
- H04L9/12
- H04L2209/56
- G06F21/109
- IPC, 2
- G06F1 00
- G06F21 00
Designated states17
- Contracting states, 17
- Austria
- Belgium
- Switzerland
- Germany
- Denmark
- Spain
- France
- United Kingdom
- Greece
- Ireland
- Italy
- Liechtenstein
- Luxembourg
- Monaco
- Netherlands (Kingdom of the)
- Portugal
- Sweden