Using power fingerprinting (pfp) to monitor the integrity and enhance security of computer based systems
Abstract
Procedures are described for enhancing target system execution integrity determined by power fingerprinting (PFP): by integrating PFP into the detection phase of comprehensive defense-in-depth security; by deploying a network of PFP enabled nodes executing untrusted devices with predefined inputs forcing a specific state sequence and specific software execution; by embedding module identification information into synchronization signaling; by combining signals from different board elements; by using malware signatures to enhance PFP performance; by automatic characterization and signature extraction; by providing secure signature updates; by protecting against side-channel attacks; performing real-time integrity assessment in embedded platform by monitoring their dynamic power consumption and comparing it against signatures from trusted code, including pre-characterizing power consumption of the platform by concentrating on trace sections carrying the most information about the internal execution status; by using PFP from sequence of bit transitions to detect deviations from authorized execution of software in a digital processor.
Term
No projected expiry on record.
- Priority
- Filed
- Published
- Today
1 claim: 1 independent, 0 dependent
- 1Claims Zastrzeżenia patentowe 1. A method of performing a real-time coherence assessment of the execution of a procedure in a computing platform, including:1. Sposób wykonywania oceny spójności w czasie rzeczywistym wykonywania procedury w platformie przetwarzania komputerowego, obejmujący: (a) dla procedury zaufanego kodu: (a) for the trusted code procedure: (i) monitoring the performance of the procedure by tracking the processor's power consumption (205, 206, 2620) by sampling during the procedure;(i) monitorowanie wykonywania procedury poprzez śledzenie poboru energii procesora (205, 206, 2620) przez próbkowanie podczas wykonywania procedury;(ii) using a platform characterization technique that further includes discovery of track sections that exhibit the greatest dependence on state transitions in the processor (205, 206, 2620);and using the indicated section to select features that carry the most information;(ii) używanie techniki charakteryzowania platformy, która ponadto zawiera wykrywanie sekcji śladów, które wykazują największą zależność od przejść stanów w procesorze (205, 206, 2620);oraz używanie wskazanej sekcji, aby wybierać cechy przenoszące najwięcej informacji;(iii) obtaining from the characterization of selected features of the procedures contained in the indicated section of the set of trusted energy fingerprints procedure;(iii) uzyskiwanie z charakteryzowania wybranych cech procedury zawartych we wskazanej sekcji zestawu zaufanych energetycznych odcisków palców procedury;(iv) setting a threshold for a specific degree of false alarm based on the probability of distorting the distance from the signature consisting of the trusted fingerprints indicated;and (b) for the untrusted code procedure: (iv) ustanawianie progu dla określonego stopnia fałszywego alarmu w oparciu o prawdopodobieństwo zakłócenia odległości od sygnatury składającej się ze wskazanych zaufanych odcisków palców;oraz (b) dla procedury niezaufanego kodu: (i) comparing the library of trusted fingerprints to features obtained from traces from the execution of untrusted code;(i) porównywanie biblioteki wskazanych zaufanych odcisków palców do cech uzyskanych ze śladów z wykonywania niezaufanego kodu;(ii) determining the distance between the fingerprints and the features obtained;and (iii) exception reporting if the distance exceeds the threshold. (ii) określanie odległości pomiędzy wskazanymi odciskami palców oraz uzyskanymi cechami;oraz (iii) raportowania wyjątku jeśli odległość przekracza próg. 2. A method according to claim 1, further comprising synchronizing the indicated tracing with the execution of the procedure by embedding the identification module in the procedure. 2. Sposób według zastrz. 1, ponadto obejmujący synchronizowanie wskazanego śledzenia z wykonywaniem procedury przez osadzanie modułu identyfikacji informacji w procedurze. 3. A method according to claim 2, wherein the information identification module is a binary identification code stored in the IO register (3324) prior to the execution of the procedure. 3. Sposób według zastrz. 2, przy czym moduł identyfikacji informacji jest binarnym kodem identyfikacyjnym zapisanym w rejestrze IO (3324) przed wykonywaniem procedury. 4. Sposób według zastrz. 2, przy czym moduł identyfikacji informacji jest sekwencją instrukcji dających charakterystyczny wzór poboru energii. 4. The method according to claim 2, wherein the information identification module is a sequence of instructions giving a characteristic energy consumption pattern. 5. A method according to claim 1, wherein power consumption tracking combines signals from multiple processor circuits. 5. Sposób według zastrz. 1, przy czym śledzenie poboru energii łączy sygnały z wielu obwodów procesorowych. 6. Sposób według zastrz. 1, ponadto obejmujący zwiększanie jakości wskazanego raportowania wyjątków przez dodanie do wskazanej biblioteki sygnatur odcisków palców znanego szkodliwego oprogramowania (maleware). 6. The method according to claim 1, further comprising increasing the quality of the indicated exception reporting by adding to the indicated library fingerprint signatures of known malware (maleware). 7. System for performing real-time coherence evaluation of the execution of a procedure in a computer processing platform (205, 206, 2620), containing: 7. Układ wykonywania oceny spójności w czasie rzeczywistym wykonywania procedury w platformie przetwarzania komputerowego (205, 206, 2620), zawierający: means for monitoring the execution of the procedure by tracking the energy consumption of the processor (205, 206, 2620) by sampling during the procedure;means for using a platform characterization technique that further comprises means for detecting a track section that exhibits the greatest dependence on state transitions in the processor (205, 206, 2620);środki do monitorowania wykonywania procedury przez śledzenie poboru energii procesora (205, 206, 2620) przez próbkowanie podczas wykonywania procedury;środki do używania techniki charakteryzowania platformy, która ponadto zawiera środki do wykrywania sekcji śladów, które wykazują największą zależność od przejść stanów w procesorze (205, 206, 2620);means for using the indicated section to select the features carrying the most information;środki do używania wskazanej sekcji do wybierania cech przenoszących najwięcej informacji;means for deriving from the characterization of selected features contained in the indicated section of the set of trusted energy fingerprints procedure;środki do uzyskiwania z charakteryzowania wybranych cech zawartych we wskazanej sekcji zestawu zaufanych energetycznych odcisków palców procedury;means for setting a threshold for a specific degree of false alarm based on the probability of distorting the distance from the signature consisting of the trusted fingerprints indicated;środki do ustanawiania progu dla określonego stopnia fałszywego alarmu w oparciu o prawdopodobieństwo zakłócenia odległości od sygnatury składającej się ze wskazanych zaufanych odcisków palców;means for comparing the library of trusted fingerprints to features obtained from traces from the execution of untrusted code;środki do porównywania biblioteki wskazanych zaufanych odcisków palców do cech uzyskanych ze śladów z wykonywania niezaufanego kodu;means for determining the distance between the fingerprints and the features obtained;and means for reporting an exception if the distance exceeds the threshold;wherein the system is configured to automatically implement the method according to one of the preceding claims. środki do określania odległości pomiędzy wskazanymi odciskami palców a uzyskanymi cechami;oraz środki do raportowania wyjątku jeśli odległość przekracza próg;przy czym układ jest skonfigurowany aby automatycznie realizować sposób według jednego z poprzednich zastrz. 8. A system according to claim 7, further comprising an information identification module embedded in the procedure. 8. Układ według zastrz. 7, ponadto zawierający moduł identyfikacji informacji osadzony w procedurze. 9. A system according to claim 8, wherein the information identification module is a binary identification code stored in the IO register (3324) prior to the execution of the procedure. 9. Układ według zastrz. 8, przy czym moduł identyfikacji informacji jest binarnym kodem identyfikacyjnym zapisanym w rejestrze IO (3324) przed wykonywaniem procedury. 10. A system according to claim 8, wherein the information identification module is a sequence of instructions giving a characteristic energy consumption pattern. 10. Układ według zastrz. 8, przy czym moduł identyfikacji informacji jest sekwencją instrukcji dających charakterystyczny wzór poboru energii. 11. A system according to claim 7, wherein the means (110) for tracking the energy consumption combines signals from the plurality of processor circuits. 11. Układ według zastrz. 7, przy czym środki (110) do śledzenia poboru energii łączą sygnały z wielu obwodów procesorowych. 12. The system according to claim 7, further comprising means for improving the quality of the indicated exceptions reporting by adding to the indicated library fingerprint signatures of known malware (maleware). 12. Układ według zastrz. 7, ponadto zawierający środki do poprawy jakości wskazanego raportowania wyjątków przez dodanie do wskazanej biblioteki sygnatur odcisków palców znanego szkodliwego oprogramowania (maleware). Virginia Tech Intellectual Properties, Inc., Stany Zjednoczone Ameryki Pełnomocnik: Virginia Tech Intellectual Properties, Inc., United States of America Plenipotentiary: EP 2 635 992 B1 EP 2 635 992 B1 Z-15866/17 Z-15866/17 1/38 1/38 Fig. 1 Stan techniki Fig. 1 State of the art EP 2 635 992 B1 EP 2 635 992 B1 Z-15866/17 Z-15866/17 2/38 2/38 Fig. 2 Fig. 2 Fig. 3 Fig. 3 EP 2 635 992 B1 EP 2 635 992 B1 Z-15866/17 Z-15866/17 3 / 3S 3/3S Fig. 4 Fig. 4 EP 2 635 992 B1 EP 2 635 992 B1 Z-15866/17 Z-15866/17 4/38 4/38 Synchronizacja oraz wyzwalanie Synchronization and triggering About g .ę>, a ® £ o 2 n 44 ε O g .ę >, a ® £ o o 2 n 44 ε Fig. 5 Fig. 5 EP 2 635 992 B1 EP 2 635 992 B1 Z-15866/17 Z-15866/17 5/38 5/38 CO to What is it Fig. 6 Fig. 6 EP 2 635 992 B1 EP 2 635 992 B1 Z-15866/17 Z-15866/17 Fig. 7 Fig. 7 EP 2 635 992 B1 EP 2 635 992 B1 Z-15866/17 Z-15866/17 7/38 iO and O (N 7/38 iO iO (N LO LO O: oh Ó :o Fig. 8 iO Figs. 8 and 0 ROSS (HP) sad 9rap9JS ROSS (HP) sad 9rap9JS EP 2 635 992 B1 EP 2 635 992 B1 Z-15866/17 Z-15866/17 8/38 8/38 Medium mark mark (Basic and alternative executions) and L -1 "" "" "" "" Basic executions! Średni ślad znacznika (Wykonania podstawowe i alternatywne) i L -1 ““““““““Podstawowe wykonania! O + - ~ O +-~ O O O O O "i o o o >*"i npfeid joąod XMo;sniuupX;nj\[ OOOOO "iooo> *" and npfeid joaod XMo;sniuupX;nj \ [ -about -o X • r-H fi X • r—H fi N N About fi fi O fi fi N <U N <U X X -o fiC / 2 <U -o fiC/2 <U Ό fi Ό fi Fig. 9 Fig. 9 EP 2 635 992 B1 EP 2 635 992 B1 Z-15866/17 Z-15866/17 9/38 9/38 Różnica PDS pomiędzy znacznikiem a zmienionymi śladami (HP) SQd SMOorazęra x The PDS difference between the marker and the modified traces (HP) SQd SMOorazęra x Częstotliwość (Hz) Frequency (Hz) EP 2 635 992 B1 EP 2 635 992 B1 Z-15866/17 Z-15866/17 10/38 10/38 Fig. 11 Fig. 11 EP 2 635 992 B1 EP 2 635 992 B1 Z-15866/17 Z-15866/17 11/38 11/38 Distribution of sample samples for the detector project Rozkład próbek próbnych dla projektu detektora CD • I £ CD CD • I £ CD Ό Ό Ό Ό ABOUT O Fig. 12 Fig. 12 ABOUT O CO WHAT CM cd • w £ CM cd • w £ N N About the cd £ O cd £ N N Ό Ό ABOUT O EP 2 635 992 B1 EP 2 635 992 B1 Z-15866/17 Z-15866/17 12/38 wA <: SSSSSSSSSSSSSSSSSKtt «^^ SS ^ 12/38 wA<:SSSSSSSSSSSSSSSSSKtt«^^SS^ Authorized tags Autoryzowane znaczniki Run the target software under normal operating conditions or using a predefined input Uruchom docelowe oprogramowanie w normalnych warunkach działanie lub z użyciem wstępnie określonego wejścia Extraction of features and remoteness from stored tags Wydobywanie cech i oddalenia od przechowywanych znaczników Decision on consistency based on a pre-set threshold Decyzja co do spójności oparta o wstępnie ustalony próg Fig. 13 Fig. 13 EP 2 635 992 B1 EP 2 635 992 B1 Z-15866/17 Z-15866/17 13/38 13/38 ABOUT O CO ''T WHAT 'T N N About cd cd £ O cd cd £ N N Fig. 14 Fig. 14 EP 2 635 992 B1 EP 2 635 992 B1 Z-15866/17 Z-15866/17 14/38 14/38 UJ jj UJ jj Results of the example PFP consistency assessment (Number of traces: 588) Wyniki przykładowej oceny spójności PFP (Liczba śladów: 588) Ljljd Ljljd Ljvtvt Ljvtvt ŁTi l? " ŁTi l?" Ljt Ljt CM CM CM CM Lj" lj " ifi and ii • i- ( ifi ifi • i—( -about -o Oh and? " Oh i?" AND I Ljll Ljll Lj- | vtιη |? S Lj-| vtιη |?S Ifi Ifi CM CM CM CM Ifi s s ° sr Ifi ss ° sr Historia próbki The history of the sample Fig. 15 Fig. 15 EP 2 635 992 B1 EP 2 635 992 B1 Z-15866/17 Z-15866/17 15/38 15/38 Results of the exemplary PFP consistency assessment (Number of traces: 650) cont Wyniki przykładowej oceny spójności PFP (Liczba śladów: 650) cd P! P! • i- (£ • i—( £ N N About the cd £ O cd £ N N Ό Ό O • i- ( O • i—( -o td -o td Oh <d • i- (o Oh <d • i—( o ω ω Ό Ό Ό Ό Ο Ο - σ ' - σ' - I "- يο ο - I"-- ίο ο ΙΟ ο ΙΟ ο ΙΟ ΙΟ Historia próbki The history of the sample Fig. 16 Fig. 16 EP 2 635 992 B1 EP 2 635 992 B1 Z-15866/17 Z-15866/17 16/38 16/38 Detailed traces of PIC18 samples (average) Szczegółowe ślady próbek PIC18 (średnia) ABOUT O FROM OD UJ UJ UJ UJ UJ iN UJ iN O (DQ otóiunsn) yra O (DQ otóiunsn) yra Indeks próbki czasu (500 M próbek na sek.) Time sample index (500 M samples per sec) Fig. 17 Fig. 17 T ' " T‘" UJ UJ CN CN EP 2 635 992 B1 EP 2 635 992 B1 Z-15866/17 Z-15866/17 17/38 17/38 Traces in the original space Ślady w przestrzeni oryginalnej Przestrzeń transformowana (jedno wymiarowa) Transformed (one dimensional) space Fig. 18 Fig. 18 EP 2 635 992 B1 EP 2 635 992 B1 Z-15866/17 Z-15866/17 18/38 18/38 Fig. 19 Fig. 19 EP 2 635 992 B1 EP 2 635 992 B1 Z-15866/17 Z-15866/17 19/38 19/38 Detail of a single captured base trace of execution Szczegół pojedynczego wychwyconego bazowego śladu wykonania ABOUT O CM CM ABOUT O CM CM Q Q ABOUT O Q ΰΖ Q ΰΖ Q Q O and £> O i£> ie tj ABOUT O Q k " Q k" Indeks próbki (n) Fig. 20 Sample index (n) Fig. 20 Q Q Q Q S £> S£> CO WHAT Q Q Q S«« S Q S««S ABOUT ! and 8 »8- '? O ! i 8 » 8—‘ ? S 1 s nprpijdray S 1 s nprpijdray EP 2 635 992 B1 EP 2 635 992 B1 Z-15866/17 Z-15866/17 20/38 20/38 Traces of average markers (Basic and alternative implementations) iJ.Ct Ślady uśrednionych znaczników (Wykonania podstawowe oraz alternatywne) iJ.Ct AXIS OS Podstawowe wykonania “ASM bitWssSim The basic implementation of "ASM bitWssSim Immediate power consumption Immediate power consumption Natychmiastowy pobór prądu Natychmiastowy pobór prądu -Ό.δΐ -Ό.δΐ 606 5® 650 >. 606 5® 650>. \ · · Indeks próbek znaczników Index of tag samples Traces of average markers (Basic and alternative implementations) Ślady uśrednionych znaczników (Wykonania podstawowe oraz alternatywne) \ AXIS OS Ol "O.U i Ol "OU and δ.ώ δ.ώ 3S0 SOD 80Ω 18Ω8 iSSO 14Q0 3S0 SOD 80Ω 18Ω8 iSSO 14Q0 Indeks próbek znaczników Index of tag samples Fig. 21 Fig. 21 EP 2 635 992 B1 EP 2 635 992 B1 Z-15866/17 Z-15866/17 21/38 21/38 IN W In iosoumXsu9;ui 5 [iuzoiq W iosoumXsu9;ui 5[iuzoiq Euclidean distance from the primary marker Oddalenie euklidesowe od podstawowego znacznika Fig. 22 Fig. 22 EP 2 635 992 B1 EP 2 635 992 B1 Z-15866/17 Z-15866/17 22/38 22/38 CM CM Euclidean distance from the primary marker Oddalenie euklidesowe od podstawowego znacznika Fig. 23 Fig. 23 J_i _! _! _ 1_5 _! _! _ Q J_i_!_!_1_5_!_!_ Q iosoumXsu9;ui 5 (iuzoiq iosoumXsu9;ui 5(iuzoiq EP 2 635 992 B1 EP 2 635 992 B1 Z-15866/17 Z-15866/17 23/38 23/38 Instructions for profiling LDA funds Instrukcje profilowania środków LDA Indeks próbki Sample index Fig. 24 Fig. 24 i i npfeid ioqod XMOfsniuiqoXfnjq ii npfeid ioqod XMOfsniuiqoXfnjq EP 2 635 992 B1 EP 2 635 992 B1 Z-15866/17 Z-15866/17 24/38 • 5 CM 24/38 •5 CM Dismissal of Euclidean LDA Oddalenie LDA euklidesowe Ϊ j Ϊ j '.' and '(' and! '.'.i '( "i ! Euclidean distance from the primary marker Oddalenie euklidesowe od podstawowego znacznika Fig. 25 Fig. 25 iosoumXsu9;ui 5 [iuzoiq iosoumXsu9;ui 5[iuzoiq EP 2 635 992 B1 EP 2 635 992 B1 Z-15866/17 Z-15866/17 25/38 (D 25/38 (D. CM CM Fig. 26 Fig. 26 EP 2 635 992 B1 EP 2 635 992 B1 Z-15866/17 Z-15866/17 26/38 26/38 Circuit control Sterowanie obwodem Fig. 27 Fig. 27 EP 2 635 992 B1 EP 2 635 992 B1 Z-15866/17 Z-15866/17 27/38 27/38 Host / workstation / driver Peripheral defense Host/stacja robocza/sterownik Obrona peryferyjna Dam Zapora PFP monitoring range Zasięg monitorowania PFP Identification and \ authorization Identyfikacja oraz \ autoryzacja Features of the OS core Funkcje rdzenia OS Access for control \ Dostęp dla sterowania \ Access restrictions for updates Ograniczenia dostępu dla aktualizacji -Y.. S .. <·α::::: «Γ“ ''''Natychmiastowa'''''' odpowiedź <Α ·::::: «Γ" '' '' Immediate '' '' '' 'answer Odmowa ochrony usługi Refusal to protect the service Instant log creation Natychmiastowe utworzenie dziennika Trusted updates Zaufane aktualizacje User / IT security manager Użytkownik/ Kierownik bezpieczeństwa IT Fig. 28 Fig. 28 EP 2 635 992 B1 EP 2 635 992 B1 Z-15866/17 Z-15866/17 28/38 28/38 Fig. 29 Fig. 29 EP 2 635 992 B1 EP 2 635 992 B1 Z-15866/17 Z-15866/17 29/38 29/38 PFP nodes "Honey pots" Węzły PFP „Honey pots” Fig. 30 Fig. 30 EP 2 635 992 B1 EP 2 635 992 B1 Z-15866/17 Z-15866/17 30/38 30/38 Fig. 31 Fig. 31 EP 2 635 992 B1 EP 2 635 992 B1 Z-15866/17 Z-15866/17 31/38 31/38 Golden standard Złoty standard Niezaufany wytwórca Untrusted manufacturer .................................................. ............... Λ .................................................................Λ Monitorowanie monitoring PFP PFP Detect SW and HW burglaries Wykryj włamania SW oraz HW CAD model Model CAD Odnośnik 'U-A P Reference 'UA P Poprzednie próbki Previous samples Fig. 32 Fig. 32 Alternative implementation Alternatywne wykonania EP 2 635 992 B1 EP 2 635 992 B1 Z-15866/17 Z-15866/17 32/38 32/38 CN CN CO WHAT Fig. 33 Fig. 33 EP 2 635 992 B1 EP 2 635 992 B1 Z-15866/17 Z-15866/17 33/38 33/38 Fig. 34 Fig. 34 Traces of power with built-in Ślady mocy z wbudowaną EP 2 635 992 B1 EP 2 635 992 B1 Z-15866/17 Z-15866/17 34/38 34/38 Fig. 35 Fig. 35 EP 2 635 992 B1 EP 2 635 992 B1 Z-15866/17 Z-15866/17 35/38 35/38 Fig. 36 Fig. 36 EP 2 635 992 B1 EP 2 635 992 B1 Z-15866/17 Z-15866/17 36/38 36/38 Fig. 37 Fig. 37 EP 2 635 992 B1 EP 2 635 992 B1 Z-15866/17 Z-15866/17 Fig. 38 Fig. 38 EP 2 635 992 B1 EP 2 635 992 B1 Z-15866/17 Z-15866/17 38/38 38/38 Fig. 39 Fig. 39
321 paragraphs in 1 section, as filed
[0001] The present invention relates to performing a real-time coherence evaluation of the procedure. According to a second aspect, the invention relates to a corresponding arrangement.
[0002] In digital CMOS circuits, at each bit-transition, there is a transient current drain resulting from a short fault in the gates and charging and discharging the parasitic capacitance at the circuit outputs. In the processor, the intensity of these transient currents, and therefore the total energy consumed in a particular clock cycle, depends on the total number of bit transitions that take place in this cycle. The number of bit transitions is determined by the specific sequence of instructions executed, as well as their addresses and parameters. Power Fingerprinting is an integrity assessment and intrusion detection solution for critical cybernetic systems based on precise measurements of energy consumption by the processor and comparison with trusted signatures (patterns resulting from a specific sequence of bit transitions during execution) to detect anomalies . The basic approach to determining the energy of the fingerprint is known from Carlos R Aguayo Gonzales et al. Proceedings of "Power fingerprinting in SDR & CR integrity", Military Communications Conference, 2009, Milcom 2009. IEEE Piscataway, NJ, USA, pp. 1 to 7, ISBN 978 -1-4244-5238-5. This approach is to characterize the performance of trusted software and extract current signatures and use them as a reference to compare test marks to determine if the same code is being executed. The PFP monitor consists of three main elements common to all patterns of pattern recognition, as shown in Fig. 1:
detection 110, feature extraction 120 and detection / classification 130. The detection includes measuring the instantaneous current drain of the digital equipment, which can be achieved using a commercial current probe and a high performance oscilloscope. Extracting features is an important aspect of PFP and includes the determination of statistical and temporal current consumption properties that uniquely identify the execution of a given program procedure. It is a difficult task requiring a deep understanding of the processor architecture and software structure, but which can be facilitated by self-building software with certain characteristics that strengthen signatures and improve determinism. Ideally, the signature will be obtained from each execution path in the code. In cases where it is not feasible,
In a general approach to the fingerprinting technique, the detector 110 is placed on the processor board as close to the power connectors as possible. The detector intercepts the momentary current consumption of the processor. The detector can be a commercial current probe, shunt resistor or current mirror. The signal from the detector must be digitized at a higher rate than the main clock of the processor. If the processor has an internal phase synchronization loop to increase the operating frequency, then it becomes the effective clock frequency. The achieved satisfactory results were obtained using 3.5X effective clock frequency, but this is not a lower limit. Several mechanisms may be used to reduce the sampling requirements.
[0004] After synthesizing the instantaneous current drain to the power consumption trace, various signal processing techniques are used to extract discrimination features from the traces. After separating the features, they are transmitted by a supervised classifier or detector, 130 which has been previously trained using traces 140 from trusted software. The detector ultimately decides whether the software implementation corresponds to the authorized program or not. Pictographic description of the general approach to technology
Fingerprinting in the prior art is shown in Fig. 1.
[0005] The decision whether features from a particular power trace correspond to the authorized execution is performed by a carefully designed detector that compares incoming power consumption traces relative to all stored signatures 140 from the authorized code.
[0006] When the observed traces can not be matched with any of the stored signatures, with reasonable tolerance, it is concluded that there has been an intrusion. Although the difference in each of the features may be small, the confidence in the intrusion rating can be very high and arbitrarily determined due to the large number of features.
[0007] However, current techniques and procedures need to be enhanced and improved in order to keep up with technology and practice being developed and used by those who want to overcome or break security features that rely on fingerprints to ensure the integrity of computer systems.
SUMMARY OF THE INVENTION [0008] The object of the present invention is therefore to develop procedures for enhancing the integrity assessment of a target system as determined by means of a Fingerprint (Power Fingerprinting PFP). The invention mitigates the disadvantages of the prior art by the method according to claim 1 and the system according to claim 7.
The invention may be carried out: by incorporating PFP into the detection phase of a complex defense into depth; By implementing a network of nodes that support PFP; by executing untrusted devices with predefined input data forcing a particular state sequence and specific software execution; by embedding information identifying the module in signaling synchronization; by combining signals from different elements of the board; by using malware signatures to enhance PFP performance; through automatic characterization and extraction of the signature; by providing updates of secure signatures; by protection against attacks from side channels; by conducting a real-time integrity assessment on the embedded platform by monitoring their dynamic energy consumption and comparing it to the trusted code signatures; by pre-characterizing the energy consumption of the platform and focusing on the trace sections that contain the majority of information on the internal execution status; by improving PFP's ability to detect deviations from authorized execution on commercial embedded platforms. An aspect of the invention is a method for assessing the integrity of performing routine on a real-time computing platform. This is achieved by monitoring the performance of the routine, tracking the processor's energy consumption, sampling the processor during the routine. The technique of characterizing the platform is used, which detects the sections of traces, i.e. sections displaying the greatest dependence on state passages in the processor. These sections are used to select features that contain most information. This platform characterization applies to the platform and can be applied to all routines run on the platform. The next step is to obtain, from the characteristics of selected routine features, contained in the sections defined in the platform's characteristics, a set of trusted fingerprints for routine. Next, the threshold for a specific frequency of false alarms is set based on the probability distribution of the distance from the signature consisting of trusted fingerprints. The library of trusted fingerprints is then compared with the features distinguished from the traces from the execution of untrusted code, and then determines the distance between the fingerprints in the library, and the functions extracted from the execution of an untrusted code. An exception is reported if the distance exceeds the threshold.
[0009] Various procedures are described to improve operations, efficacy, usability and integrity assessment, and fingerprinting (PFP) based intrusion detection systems. Different procedures include:
• Embedding module identification information in synchronization signaling • Improved PFP monitoring by combining signals from different array elements • Using malware signatures to enhance PFP performance, generalize existing battery monitoring technology.
• Automatic characterization and extraction of signatures • Secure signature updates • Responding to integrity violations and layer protection • Protection against side-channel attacks [0010] Methods and apparatus for:
• Distributed PFP monitoring network to monitor the dynamics and behavior of malicious software • applying PFP to analysis of supply chain trust • managing licenses and executing a limited number of licenses • predicting failure based on PFP
BRIEF DESCRIPTION OF THE DRAWING [0012] The foregoing and other objects, aspects and advantages will be better understood from the following detailed description of preferred embodiments of the invention with reference to the drawing in which:
Fig. 1 is a general block diagram of a fingerprint.
Fig. 2 is a diagram showing the ideal detector location for a PFP monitor.
Fig. 3 is a diagram showing the ideal location of detectors for multiprocessor boards.
Fig. 4 is a diagram showing an example of a physical signal induction.
Fig. 5 is a schematic diagram illustrating the insertion of PFP strategic instructions for synchronization and invocation.
Fig. 6 is a schematic diagram showing indirect access to physical resources in the Linux driver paradigm.
Fig. 7 is a flow chart showing the characterization process of a trusted code.
Fig. 8 is a graph showing an example of preprocessing traces by calculating the spectral power density.
Fig. 9 is a graph showing exemplary traces processing in the time domain.
Fig. 10 is a graph showing the difference of PSD in the execution of test tracks, in relation to the traces stored
Fig. 11 is a diagram of a technological process showing the detector design process.
Fig. 12 is a graph showing probability distribution of a sample from the implementation of a trusted code used to design the detector and select a threshold.
Fig. 13 is a process flow diagram illustrating a PFP integrity assessment process.
Fig. 14 is a schematic diagram showing the configuration of an embodiment for the Android platform.
Fig. 15 is a graphical representation of the sample distributions resulting from the implementation of the original inseparable routine.
Fig. 16 is a graphical representation of the sample distributions resulting from the implementation of the fake routine.
Fig. 17 is a graph showing the detail of a sample trace showing different sections of traces containing different levels of discriminatory information.
Fig. 18 is a schematic representation of platform characteristics using a linear projection from the most informative point of view,
Fig. 19 is a schematic diagram showing the configuration of a reference measurement for characterization and monitoring of energy consumption in a platform using PFP.
Fig. 20 is a graph showing a sample trace of a base code execution to evaluate the ability to detect the minimum change in energy consumption.
Fig. 21 is a graphic representation of an average signature from a base code execution where each point represents a projection on the n-dimensional Euclidean space.
Fig. 22 is a graph showing the distribution of a sample of Euclidean distances from the average signature extracted from the execution of the base code.
Fig. 23 is a graph showing the distribution of a sample of Euclidean distances from the baseline signature in the transformed space of the obtained PCA.
Fig. 24 is a graph showing trace centroides from the LDA profiling instruction.
Fig. 25 is a graph showing the distribution of a sample of Euclidean distances from a baseline signature in a transformed space obtained using LDA.
Fig. 26 is a schematic block diagram of an exemplary target platform for detecting deviations from an authorized software implementation.
Fig. 27 is a schematic diagram showing the different layers in the "defense deep" approach to cyber security.
Fig. 28 is a schematic diagram showing the scope of PFP monitoring within a layered, "defense in depth" security system,
Fig. 29 is a schematic diagram showing a Honeypot PFP node for monitoring and collecting information.
Fig. 30 is a schematic diagram showing a diagram showing a Honeypot PFP network.
Fig. 31 is a schematic of a technological process of supply chain trust analysis using PFP.
Fig. 32 is a schematic diagram showing potential sources of reference signatures for supply chain trust analysis using PFP.
Fig. 33 is a diagram illustrating the use of an IO register to provide synchronization and identification signaling to a PFP monitor.
Fig. 34 is a diagram illustrating the incorporation of synchronization and identification of PFP signaling in power tracking.
Fig. 35 is a diagram illustrating an exemplary configuration of a sample for combining multiple signals to evaluate the integrity of PFP.
Fig. 36 is a schematic of a technological process to extract features that exclude failure of the PFP device.
Fig. 37 is a schematic diagram showing the relationship between various system elements influencing the automatic characteristics and extraction of features.
Fig. 38 is a diagram of a structure for preventing side channel attacks using an embedded PFP monitor.
Fig. 39 is a diagram of a structure for preventing side channel attacks using an external PFP monitor.
DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS [0013] Power fingerprinting (PFP) techniques are techniques that allow an external monitor to assess the integrity of a cyber machine. PFP is based on information on the execution status carried over by the dynamic power consumption of the processor. By using this information with predefined signatures from trusted credentials, PFP can determine the integrity of execution in target systems. For the practical application of PFP, it is necessary to implement specific equipment and perform specific procedures in order to provide an effective monitoring solution. In this work, we describe various procedures to improve the performance, effectiveness, usability and performance of the PFP monitoring solution.
The use of PFP to detect software modifications in smartphones and other embedded devices.
[0014] Cyber security has become a key element for national security. Microprocessors are ubiquitous in almost every aspect of modern life. The development of technologies in the area of information technologies is developing faster than the security solutions necessary to protect them. The threat of cyber attacks remains constant with potentially devastating consequences for critical infrastructure and national security. Cyber infrastructure has become so important that cyber space is now considered a new domain of warfare and a critical element for national security, which must be protected from all threats, including state-sponsored opponents.
[0015] We describe the integrity assessment technique, in real time, in smartphones and other embedded platforms, by monitoring their dynamic energy consumption and comparing them to the trusted code signatures. The described method and technology are based on the general concept of power fingerprinting techniques and provide reinforcement for general use on complex commercial devices. We present examples of preferred embodiments of general techniques that are to be used as references and examples. However, the techniques are general and can be adapted to any cybernetic platform.
[O16] As part of this approach, we also describe the methodology of the method, for initial characterization of power consumption for a particular platform and processor, to improve the performance of this approach by focusing classification activities on track sections that contain the most information about the internal state of the processor and ignore redundant or very noisy characteristics that may make it difficult to work.
[0017] The aim is to strengthen the general fingerprinting (PFP) approach to determine reliable techniques for detecting unauthorized software modifications in smartphones, embedded systems and general information systems. A general prior art approach is illustrated in Fig. 1.
[0018] The general PFP method begins by collecting small power consumption measurements while executing a trusted code. The detector 110 must collect direct or indirect data on dynamic power consumption or instant current drainage of the processor. The detector 110 can be implemented using a commercial current probe, a Hall effect sensor, a piezoelectric / magnetostrictive sensor, a composite magnetic field sensor, a Rogowski coil, a high current throughput mirror or a simple low resistive shunt resistor. Note that the detectors must meet the requirements specified for the selected feature extraction technique.
[0019] The physical location of the detector is a key element in the success of this approach. The ideal location 210 is shown in Fig. 2 on the VDD signal of the processor 205. If this place is impossible or introduces excessive noise in the power supply, the second best location 220 is also shown. If the detector 220 is in the second place, traces of copper with their parasitic capacity and the inductance together with the separating capacitors 215 form a low-flow RLC (LP) filter that acts on the current traces. For PFP, it is beneficial to pre-characterize this hardware effect by identifying the H transfer function, the LP filter using a commercial network analyzer or other system identification technique. The effect of the built-in LP filter can be minimized by transferring traces through another filter with the reverse transfer function, Hinv. It is recommended to enter a digital reverse filter. Since the direct inversion of H can lead to instability of the filter, it is necessary to select the closest stable Hinv approximation.
[0020] In Fig. 2, YDD_core 225 can be provided by various sources. Simple processors come directly from voltage regulators. For more advanced platforms, it can come from a power and circuit management system that is a comprehensive circuit that provides a wide range of services, including providing the required different voltage levels, handling resets and interrupts, and other perimeter management functions. Energy managers are complex systems that combine different signals and cause interference from a PFP perspective and have a tendency to hide power signatures. In the case of a system with an energy management circuit, it is recommended to design a system board together with the necessary regulations to place the current detector on the power management system to avoid additional interference and to facilitate the extraction of signatures.
[0021] In the case of multiple processors in the same board, the same principle can be repeated for each processor as shown in Fig. 3, where the n-processor 206 is preferably monitored at 211 or the second best location 221 after the separating condenser 216. In this case, the detector must be designed to combine and consider traces from both detectors. In the case of multi-core processors, in the same package, the same rules apply as in the multiprocessor example, but the location and feasibility will depend on the processor architecture, the number of cores driven by each bus and the requirements for separation.
[0022] With the detector in place, the next step is to characterize the trusted code. This process is accomplished by repeatedly executing the target trusted code in a controlled environment (including isolating the target software, fixed input data used during execution, and inserting specific tags that help synchronize traces). Markers can have different characters and help in triggering and synchronizing. Potential markers include physical signals (varying the voltage level of the plug) or a specific instruction sequence that gives a known sequence of power consumption. An example of a physical trigger signal 410 is shown in Fig. 4. The concept of entering a trigger instruction is illustrated in Fig. 5.
[0023] When the target application 610 operates in the user space of a platform that implements a Linux device driver scheme or any other operating system that has indirect access to physical signals as described in Fig. 6, it is necessary to consider the inherent uncertainties in implementation and timing caused by indirect access. In this case, the triggering instructions 515 will be performed in user space 610 that has no direct access to physical memory 640 and can access the registers 632 necessary to create physical signal 650 using device drivers 631 located in the kernel 620 space. Uncertainty in executing and timing exists because access to files requires that the process should wait (block execution) on the appropriate synchronization signaling,
[0024] Even if the tags 630 do not have to remain in the final code, the process of evaluating the working time is facilitated if they remain in place. In the event that the tags remain in the version used, it is necessary to ensure that the support programs or services used for marking remain in the installed platform (eg if the marker is to enable LED 640, LED 640 must exist on the used platform).
[0025] It is important to remember that during the characterization, use the exact code that will be implemented. This includes using exactly the same software development tools with the same level of optimization, etc.
[0026] For better performance, the characteristic should be an iterative and interdependent process, during which the structure of the source code is developed along with the appropriate markers to obtain the strongest signatures with the least variation in different execution instances.
[0027] The collection of several traces from the implementation of a trusted code may be necessary in order to average them and reduce the impact of random noise inherent in any physical system. The characterization process is shown in Fig. 7. After entering the 710 markers into the code, trusted software is executed and the acquired power traces are recorded 720. This applies to all important execution paths 730, using predefined input 735, if necessary. Deviations resulting from random parameters are removed using PCA (principal component analysis) 740. Discriminant features are extracted 750 and statistical analysis is performed, averaging and clustering 760 to generate a set of authorized signatures 770.
[0028] The signatures can be isolated from different signaling domains and be multivariate. In addition, many signatures can be used to identify a single code.
Trace processing and mining of objects [0029] The process of preparing test tracks to be compared with a known signature is known as pre-treatment and extraction of features. Pre-treatment of the trace requires general tasks to adapt the traces in order to identify selected discriminatory features, eg transforming traces into the appropriate domain or leveling traces with respect to a specific marker. An example of the pre-treatment of the trace is shown in Fig. 8, in which the time-domain traces of executing the BeagleBoard test software with the OMAP3 processor are first converted to a frequency domain by calculating the spectral power density.
[0030] Another example of the pre-treatment is the leveling of the tracks in the time domain, as shown by the alignment of the base and alternating traces (transitions)
-1 bit) in Fig. 9, before transferring them to the correlation detector. In this example, every trace of
N samples are considered a point in the multidimensional Euclidean space.
[0031] Extracting features is a process of calculating the final test statistic (from new traces) that is passed to the detectors and used to determine integrity. This process is unique for each selected feature. For example, in the basic time-domain correlation analysis, pre-treatment may include coarse synchronization and compensation for specific energy consumption patterns in the platform, while feature extraction occurs by comparing with the saved signature by calculating the correlation coefficient or Euclidean distance. An example of extracting a feature is shown in Fig. 10, which shows a PSD error in dB traces corresponding to the execution of trusted code and changed code in the BeagleBoard OMAP3 processor, according to the PSD example in Fig. 8. Using this difference vector,
Detector design [0032] After isolating the signatures and selecting discriminant characteristics, the next step in the PFP process is to design optimal detectors to perform the final integrity assessment. These detectors will make the final decision whether the test tracks should be considered as a break-in during the monitoring operation. The design process of detectors and normal monitoring operations are very similar. In the design of detectors, test tracks from the implementation of trusted software are intercepted and processed to extract selected discriminant features and compare them with saved signatures. Several traces are collected and processed, and their statistical distributions of samples are used to determine the threshold that provides the expected performance goals. The detector design process is shown in Fig. 11. Random or predefined input data 110 is provided to trusted software 120 and new test marks are captured from its performance. The results are aligned and synchronized 1130, and the traces are pre-processed and conditioned 1140. Using the authorized signatures 770 for comparison, the discriminant features selected were extracted, and a distance of 1,150 meters was generated. Then, statistical analysis and adjustment of the distribution was performed on 1160 on the required metrics. Finally, the Neyman-Pearson criterion is applied 1170 to determine the threshold that corresponds to the expected performance. Using the authorized signatures 770 for comparison purposes, selected discriminant features were extracted, and a distance of 1,150 meters is generated. Then, statistical analysis and adjustment of the distribution was performed on 1160 on the required metrics. Finally, the Neyman-Pearson criterion is applied 1170 to determine the threshold that corresponds to the expected performance. Using the authorized signatures 770 for comparison purposes, selected discriminant features were extracted, and a distance of 1,150 meters is generated. Then, statistical analysis and adjustment of the distribution was performed on 1160 on the required metrics. Finally, the Neyman-Pearson criterion is applied 1170 to determine the threshold that corresponds to the expected performance.
[0033] A common approach to creating optimal detectors requires the use of the Neyman-Pearson criterion to maximize the likelihood of detecting a false alarm for a given probability. As a brief reminder of this criterion, derived from the basic theory of hypothesis testing, the target probability of false alarm is determined on the basis of tolerance and the estimated cost of making a mistake in the final decision. Using the estimation of the probability distribution of discriminating features from the trusted code, the distance threshold is calculated, which gives the expected probability of a false alarm while increasing the probability of correctness of detection. An example of this process is shown in Fig. 12, in which sample 1220 of the distance for the probability distribution 1210 is calculated,
[0034] It is important to note that there are different techniques that can produce better results depending on the nature of the discriminant features selected. Other techniques for designing detectors and machine training include: neural networks, SVM support vector machines and HMM (Hidden Markov Model) models.
Operation monitoring [0035] When the signatures were extracted from the execution of trusted code, discriminant features were selected and optimal detectors were developed, the PFP monitor is ready to evaluate the integrity of the test software. As mentioned above, the normal integrity assessment process is very similar to the detector design process. During normal operation, the monitor takes selected discriminant features from the power traces after the necessary initial processing, and instead of collecting statistical data from several traces, as it was done with the detector, they are transferred by the appropriate detector to compare with appropriate thresholds and determine the integrity status of the implementation test code. The detector compares the test tracks with all known signatures, and if a single test statistic is not enough to determine, that an authorized code has been made, an infringement will be reported. This process is shown in Fig. 13. Target software is executed 13310 during normal operation or uses a predefined input signal to capture test tracks 1320, which are then aligned and synchronized 1330, then pre-processed and conditioned 1340. The detector then compares 1350 extracted features with known signatures 1370 to determine the distance, using a predetermined threshold of 1220 to make a coherence assessment decision 1360.
Test results [0036] To illustrate the PFP process on smartphones and other embedded platforms, we describe the reference implementation of this technique using the BeagleBoard revision C4 with an ARM processor (OMAP3 @ 720 MHz) operating on the Android platform. BeagleBoard 1410 is slightly modified by cutting the main power tracks 1420 to power the core rail to connect the 1430 current probe. The capture system is performed using a commercial 1440 and 1430 current probe. The oscilloscope is configured for a sampling rate of 2.5 GSps and accumulates a total of 30,000 samples in each trace initiated by the 1450 trigger. The configuration is described in Fig. 14.
[0037] A basic test application has been developed to demonstrate the process and demonstrate feasibility. This basic application consists of a simple counter that displays a growing integer on the device screen. The operation of the application is described in
LISTING 1 and consists of a typical Android Java application structure with an initialization procedure that prepares the screen to display the text field and sets the integer variable used as the counter. There is also a routine called DisplayCounter responsible for increasing the value of the counter and displaying it on the screen. This routine is configured as a repeating task that is called every second.
[0038] LISTING 1. Android application test pseudo-code _LISTING and .Pssudo-code of Android Test. App_ and Initialise
I DisplayCounter · ()!<sup>{</sup> '| counter = IncrementValue (counter);
and Display data.
!} and Sleep for one sec: DisplayCounter at wake up [0039] The critical incremental value of the routine was implemented in native C code and attached as an external library thanks to the Android NDK toolkit instead of the traditional Java implementation. Before the critical section, the physical trigger 1450 is set to a 1460 capture system signal to start collecting power traces.
[0040] We only describe and monitor the most important procedures shown in LISTING 2. [0041] 2. LISTING 2. Pseudo-code of the monitored native routine in C
I -1 ST IN i.e. 2. P o eud o-codo oh mon i tored nat i ve routine in C
7 * Criti cal native routine * 7 int incrementVal iie (int Vai)
With * uarl LED trigger * Z
Open device driver control file
Write 1 into file
Z * increment val * Z Val + -ł * ί / * General sxtra proceasing * / i = 1000, * while cl) i--;
Z * Reset LED usrl Trigger * /
Write 0 into file Close driver control file return Val;
[0042] The signature is extracted in the frequency domain simply by averaging
PSD a few traces from a trusted code execution. Track phase information is ignored. The PSD of two hundred tracks is averaged together to get the signature.
[0043] Discriminant characteristics are also extracted in the frequency domain also by means of the mean square error between the signature and the PSD of the test tracks (in dB). The PSD of the last three test marks are averaged together before calculating MSE. Only the first 200 MHz PSD is used for MSE calculations.
[0044] This signature extraction process provides a one-dimensional discriminant trait. The detector design was performed using the Neyman-Pearson criterion previously described using the false alarm target probability, PF4, of 1%. Statistical samples of the trace are taken from a sample of 200 traces from the implementation of a trusted code.
[0046] The sample distribution matched the Rayleigh distribution result with mean and variance equal to the mean and variance of the training sample distribution. Using this distribution, the inverse probability distribution is calculated to find the threshold that gives the target 1% PFA.
[0047] In order to test the possibility of detecting a deviation from a trusted code, we test the previously designed monitor using a slightly modified version of the application. The revised application, shown in the LISTING 3 list, aims to mimic the secret attack, in which the burglary remains inactive until the specified condition is met. The introduction consists in a very simple modification, in which the file is saved only when the counter value reaches a certain value (condition).
[0048] LISTING 3. Pseudo code of the changed critical native routine
L and ST 1NG cod ε _o tc nncal ^ riaii ye jo uti nc
Z * Critical oative routine * /
TNL; incrementyaluefint Val)
I / 'trigger LED wsrl * /
Open device drivec eontroi file Write and into file / * Tampęr * / if fVal == 1) {// open file / Write Val into file // Close file]
/ * Increment Val * /
Val ++;
/ * General extra Processing * / i «1000; while (i) i--;
/ * Keset LED uscl Trigger * /
Wrifce 0 into file ClOSe dnver COntrOl file return Vai;
[0049] It is worth noting that writing to files takes place only once during execution (i.e., when the counter is 1). The rest of the time when the routine is called, the condition is not met and the additional file is not saved. Therefore, most of the time when routine is called, the only modification from the point of view of logic is an additional evaluation of a given state.
Operational results [0050] The results of monitoring start-up while executing the original unchanged version of the procedure are shown in Fig. 15.
[0051] We see that for the duration of the test we had only a few cases that exceeded the threshold of 1510, which is consistent with the assumed probability of a false alarm.
[0052] The results of running monitoring using the modified version of the application are shown in Fig. 16. Note that no instance is erroneously classified as an authorized execution, and each execution of the changed application will be flagged as violating above the threshold of 1610. It is also important to remember that due to the conditional execution of the change, only once when executing the instances used in these results, the file was actually written. For the rest of the time, only the condition was checked, and when it was not met, normal exercise was resumed.
Evaluation of the platform and evaluation of the minimum sensitivity [0053] Measurements with exact sampling of power consumption can lead to unnecessary information that adds very few discriminatory information, but can cause significant disruption and uncertainty of the signatures. In the time domain, it looks like in Fig. 17. In this case, we would like to focus our attention on the trace sections (dimensions) that have the largest variance 1710 between the two embodiments, as opposed to the sections, e.g. 1720, which show a small difference between two versions. On the other hand, when evaluating a specific program procedure that adopts random parameters, the impact of these random parameters is intended to introduce noise into the signatures, which results in a reduction of effectiveness and increases the likelihood of a false alarm. In this case, we would like to pay attention to the dimensions (eg 1720), which remain unchanged during the execution of the target software and at the same time ignoring those that cause noise. In this case, we would like to ignore dimensions with high divergence (eg 1710). [0054] To improve the efficiency of PFP, it is necessary to reduce the number of characteristics analyzed by focusing only on those that carry the most information. This is done by first assessing the features that, as part of the pilot tests, carry the most information for a given platform, and then eliminating the excess information during pre-processing before passing the traces to the detectors. we would like to ignore dimensions with high divergence (e.g., 1710). [0054] To improve the efficiency of PFP, it is necessary to reduce the number of characteristics analyzed by focusing only on those that carry the most information. This is done by first assessing the features that, as part of the pilot tests, carry the most information for a given platform, and then eliminating the excess information during pre-processing before passing the traces to the detectors. we would like to ignore dimensions with high divergence (e.g., 1710). [0054] To improve the efficiency of PFP, it is necessary to reduce the number of characteristics analyzed by focusing only on those that carry the most information. This is done by first assessing the features that, as part of the pilot tests, carry the most information for a given platform, and then eliminating the excess information during pre-processing before passing the traces to the detectors.
Technical Background [0055] In traditional pattern recognition circuits, the process of selecting a subset of features that maximizes a specific criterion (in the case of PFP we want to maximize the PFP information discriminator) is referred to as the optimal selection of features. In cluster systems, this is usually done by projecting traces, x, onto the transformed space with fewer dimensions from the most useful (or from the information perspective) by means of linear transformation.
[0056] This transformation is described as
<img file="PL2635992T4_D0001.tif" />
, where W is a carefully designed linear transformation matrix that, when applied to test tracks, produces a transformed trace with fewer dimensions that maximizes a given criterion. There are various criteria for identifying the optimal transformation. Because we try to optimize the selection of features for discriminating information, it is natural to apply the theoretical information approach. This optimization has been carried out before and can be found in several sources in pattern recognition literature, for example, see JT Ton and RC Gonzalez. "Pattern Recognition Principles", Addison-Wesley Publishing Company, 1974.
Analysis of major components [0057] A well-known approach to determining the proper W that optimizes the entropy (or information) in the tracks is known as Principal Component Analysis (PCA). We assume that the covariance matrices for different classes, Ci, have a normal distribution and the same Ci = C. Therefore, the eigenvectors can be considered as information carriers for the considered traces. Some of these vectors have more discriminatory information in the classification sense than others that can be safely eliminated without a greater loss of performance. It should not come as a surprise that vectors with optimal features are associated with these eigenvectors and are used to create a W transformation matrix by aggregating eigenvectors in descending order according to their proper eigenvalues.
[0058] Linear transformation can be interpreted as a projection of a test trail in a transformed space with a lower number of dimensions from the perspective of the largest amount of information. PCA can be used in various ways, depending on the specific purpose. From the point of view of clustering, it is beneficial to construct W using the eigenvectors associated with the smallest eigenvalues, because this would create a denser cluster in the transformed space. On the other hand, it is also possible to use the eigenvectors associated with the largest eigenvalues, when traces from different versions are used. In this way, the PCA program will select the functions that have the largest differences between the classes. Assuming that covariance matrices are identical,
Linear discriminant analysis (LDA) [0059] PCA selects a subset of features in ascending or descending order, in order of variance, to optimize entropy tracking. However, it does not take into account the specific differences between classes in order to select the optimal set of features that will maximize the distance between them. Linear discriminant analysis (LDA) maximizes divergence between distributions, which is a measure of the distance between probability distributions. Divergence is closely related to the concept of relative entropy in information theory.
Using detailed information from different classes and divergences as the optimization criterion, the LDA identifies the optimal transformation matrix to project traces from a unique perspective that ensures maximum separation between them. This is because the transform vector is normal to the optimal discriminating hyper surface between the two distributions.
[0061] As per the assumption that the tracks have a normal distribution, it can be shown [TOU] that the transformation matrix that gives the extreme divergence is given by only one vector
<img file="PL2635992T4_D0002.tif" />
associated with a non-zero eigenvalue. This vector is given by your own
<img file="PL2635992T4_D0003.tif" />
, where W0 provides optimal projection to separate the two classes, while μ0 and μ1 are the appropriate centroids for the two pilot test classes. LDA can be extended to M discriminating classes. In this case, there will be M-1 associated vectors with non-zero eigenvalues.
Evaluation of power consumption in the platform [0062] As mentioned earlier, not all of the samples in the track test are equally important to determine whether or not there has been a deviation of performance. Due to the high proportion of oversampling and the nature of power traces, there are some sections of traces that carry more discriminatory information than others. In the case of PFP, the goal is to determine a linear transformation that reduces the number of track sizes by removing redundancy and at the same time emphasizing the dimensions that carry the most information.
[0063] The idea is to transform discriminant features to reduce the number of dimensions using a linear footprint using the optimal transformation matrix. In the time domain, the track sections corresponding to the full clock cycle 1810 are reduced to a single point 1820 in the transformed space as shown in Fig. 18. The classifiers must also be designed to operate in the transformed space, reducing the number of dimensions to be considered during normal monitoring work.
[0064] The assessment is done under controlled conditions in the laboratory and is only required once per platform. As described in the previous sections, there are two general approaches to identifying the optimal transformation matrix: PCA and LDA.
Evaluation of the platform using PCA [0065] To create a transformation matrix using PCA, the processor's power consumption should be observed in random clock cycles. Traces are aligned for each clock cycle to clearly show the sections of tracks most affected by the dynamic behavior of the processor. When the traces are aligned, the PCA is used to identify the transformation vector that is most variable in traces.
[0066] Evaluation of the execution platform using PCA is relatively easy to implement and is suitable for complex platforms in which the control of the content of the information stream is too difficult.
Evaluation of the Platform with the LDA [0067] Assessment of power consumption in the implementation platform using LDA requires the development of two carefully refined procedures. These procedures must perform specific instructions with specific addresses and parameters in the correct order to create two sets of footprints that have predetermined time differences over a specific clock cycle. Traces of pilot tests from the implementation of both procedures provide two classes for which LDA will find the optimal discriminating hyper surface e, which in turn will become the optimal transformation vector.
[0068] The purpose of the special evaluation procedure is to execute a carefully prepared instruction sequence to properly load the information flow so that a known change in time of each execution step (download, blocking, execution, etc.) takes place in a specific clock cycle. The changes should be relatively small, preferably due to changes in several bits in the relevant registers. The assessment procedure is not unique, but depends on the specificity of the platform, as it depends on the architecture, instruction set, etc. of the platform being evaluated. Different processors probably require a different sequence.
[0069] When the traces from the execution of both sequences are captured and synchronized, the LDA is used to find the optimal W transformation vector. It should be expected that platform evaluation using LDA will provide the best performance considering the availability of two known classes, but implementations are more complex than PCA.
Evaluation of the power consumption of the platform with respect to the results of implementation [0070] For this reference implementation we use a motherboard with an 8-bit PIC18LF4620 microcontroller from Microchip Technology Inc., similar to that used in the PICDEM Z Demonstration Kit, designed to evaluate and develop the IEEE 802.15 platform. 4. This is a popular built-in microcontroller, without a memory management unit, [0071] The CPU processor board is slightly modified to improve the power consumption characteristics. A total of six decopuling capacitors have been removed from the board, representing a total of 6 microFs. The function of these capacitors is to mitigate stress on power supplies due to the strong current peaks caused by digital processors. It is important to remember that removing decoupling capacitors would not be necessary,
[0072] Trace collection takes place using a real-time Tectronix TDS 649C 1910 oscilloscope and a 1920 current Tektronix TC-6 current probe. The probe is connected just behind the voltage regulators on the motherboard. The oscilloscope is suitable for 500 MS / s and 10 mV. Trigger (trigger) is driven by LED1 1930 and adapted to reduce the edge, the level of mV, and pre-trigger samples are not stored. After each triggering event, a total of L = 30,000 samples are collected. The measurement system is shown in Fig. 19. The traces are captured and transferred to the host computer using GPIB for their posteriori analysis.
[0073] In this experiment, an exemplary dual objective procedure was developed 1) to provide pilot test procedures for platform evaluation, and 2) to provide reference changes to measure the effectiveness of a given approach. We begin by describing the evaluation of the use of the procedure and providing a baseline performance for comparison. The test procedure is shown on
LISTING 4 and made in an infinite loop. In this procedure, the contents of register W from 00 to Of are included using various instructions. Note that the actual logic of the procedure does not affect the performance of the power marking. This procedure has been chosen because it is easy to control the number of bits that have passed. The results, however, do not depend on the specific software being made. For this reason, this procedure provides a representative example.
[0074]
LISTING 4.
BYTE and; // addr 00 BYTE j; // addr 01 BYTE k; // addr 10 BYTE 1; // addr 11 // Initialiee the system Boardlnit!);
// T.iiitialize data variable;
<td>asm</td><td></td><td></td><td></td>
<td>movlw</td><td>0x07</td><td></td><td></td>
<td>ttiovwf</td><td>i-, 0</td><td>// addr</td><td>0x00</td>
<td>roiovlw</td><td>OxOf</td><td></td><td></td>
<td>movwi</td><td>D 0</td><td>// addr</td><td>0x01</td>
<td>movlw</td><td>0x0f</td><td>/ / Set</td><td>for m;</td>
<td>movwf</td><td>k, 0</td><td>// addr</td><td>0x10</td>
<td>can<sup>1</sup>'Lw</td><td>Oxlf</td><td></td><td></td>
<td>IfllOwf</td><td>1, o</td><td>// addr</td><td>0x11</td>
<td>movlw</td><td>0x00</td><td></td><td></td>
// Target coda mfinite loop wh and 1. £ i 1; {
<td colspan="2">TMftOH ----- 0x00; //</td><td rowspan="2">Restart ΤΓΜ0 Trigger</td>
<td>TMROL - 0x LED 2 = 1; LED_2 = 0;</td><td>.00 and //</td>
<td>_asm</td><td></td><td></td>
<td>nop</td><td></td><td></td>
<td>iorwf</td><td>JI Ol</td><td>0 // w - Of</td>
<td>andiw</td><td>0x00</td><td>// w = 00</td>
<td>jnovf</td><td>j- 0,</td><td>0 // w - 0f</td>
<td>andiw</td><td>0x00</td><td>// w = 00</td>
<td>ttiOv £</td><td>k, 0,</td><td>0 // w - 0f</td>
<td>movlw</td><td>0x00</td><td>// w = 00</td>
<td>xorvf</td><td>j "Oz</td><td>0 // w - 0f</td>
<td>itovlw</td><td>0x00</td><td>// in - CO</td>
<td>iorwf</td><td>and*</td><td>0 // w = 0f</td>
<img file="PL2635992T4_D0004.tif" />
[0075] The procedure, as shown in LISTING 4, shows a reference embodiment. Preceding the target code, we create a trigger using the LED on the board. The trigger is used to synchronize trace capture using an oscilloscope. The "NOP" instruction between the trigger and the target code is included as a buffer to isolate target traces that create any residual effects from the trigger. Inside the main loop, the register W is switched from 00 to 0 f, creating four bit transitions in the registered each instruction. The alternate or modified code has one less bit transition. In line 15, we change the contents of the variable jz 0f to 07. In this way, when the target code is executed, in line 35 the parameter k is loaded into the register W, which passes from 00 to 07, there are only three bit transitions in the register for this instruction. Note that there is only one bit difference between this modified code and the reference execution which loads the W register from Of, and everything else in the execution is kept the same, including instructions, parameters and addresses. It should be noted that this one-bit change actually affects two clock cycles, because there is one less transition going into this instruction and one less comes out of it. Checking the target code exposes the "NOP" instruction string before repeating the loop. including instructions, parameters and addresses. It should be noted that this one-bit change actually affects two clock cycles, because there is one less transition going into this instruction and one less comes out of it. Checking the target code exposes the "NOP" instruction string before repeating the loop. including instructions, parameters and addresses. It should be noted that this one-bit change actually affects two clock cycles, because there is one less transition going into this instruction and one less comes out of it. Checking the target code exposes the "NOP" instruction string before repeating the loop.
[0076] Details of a typical trace are shown in Fig. 20. In this figure, we captured one complete cycle of execution of the target code. The effects of the trigger on power traces are clearly visible in the two stages of 2010 and 2020. The cycles of individual instructions are also noticeable. They can be identified as groups of four jumps that repeat every 125 samples. Using the timing information from the processor documentation, we can determine the section of the trace corresponding to the execution of the target code. In Fig. 20, this section is distinguished by a continuous line 2030 which includes ten instruction cycles. This is in line with the real code, which consists of ten assembly instructions, each of which takes one bus cycle to execute.
[0077] Several traces are captured for each reference and alternative execution, and traces from each implementation are averaged to provide a clear view of both embodiments showing the overall effect of a one-bit transition. The averaged traces are shown in Fig. 21. In this figure, ten clock cycles corresponding to the execution of the reference code are shown and the traces of each embodiment appear to be aligned. Around the 650 sample indicator, however, you can see a slight difference between the two marks. The difference (at 2110) is more noticeable in the upper part of Fig. 21, which provides a more accurate picture. With the proximity of centroids from both scenarios, it is also obvious that the traces are largely correlated due to over sampling, and also
[0078] For comparative purposes, we provide the results of a naive classification approach in the time domain without pre-assessment of the platform. We use the basic minimum distance classifier. In this approach, each captured trace with the length L = 1250 (length of the target code) represents the point in the L-dimensional Euclidean space. The Euclidean distance is taken from the performance centroid, which is a reference to every incoming test track. For the purpose of classification, the basic centroid and test marks constitute a single point or vector, in a multidimensional Euclidean space of 1,250 dimensions. Traces of tests differ from the pilot tests used to obtain the basic centroid. This is to avoid a systematic error when assessing the classifier with a minimum distance,
[0079] Traces of the tests of both procedures have the distributions of the Euclidean distances shown in Fig. 22. In this naive example, the efficiency of the power marks is not encouraging because there is very little difference between the distributions that are substantially overlapping. Given the low variation in power consumption between the basic and alternative scenarios, poor results are expected.
[0080] The first results of platform evaluation were obtained using PCA. In this process, we use all the clock cycles corresponding to the execution of our target code in the procedure shown in LISTING 4. The trace corresponding to the full trace execution is divided into different sections corresponding to the execution for one clock cycle. The subsections are then aligned, and the PCA is used to find the transform vector corresponding to the eigenvector that takes the most variances into account. In this case, as explained earlier, we take an over-sampled trace for one clock cycle and reduce it to one point.
[0081] After the platform assessment using PCA, the traces of the evaluation procedure tests are re-processed to demonstrate the performance improvements of the initial platform evaluation. The minimum distance distributions of the transformed test tracks for the signature in the new PCA transformed space are shown in Fig. 23.
[0082] A clear separation can be seen between a large part of the distributions, which is a marked improvement with respect to the naive classification efficiency shown in Fig. 22.
Results of platform evaluation using LDA [0083] In order to obtain traces of pilot tests necessary to use LDA, we perform basic procedures and a slightly modified version. We receive special traces of platform evaluation by comparing two sets of traces: from the basic version, which is again the code in LISTING 4 and its slightly modified version shown in LISTING 5. The changes in execution are carefully selected, which results in less than every step one bit transition, compared to the reference being made. In this modified version, the instruction in line 36 is changed from xorwf with operation code 0001 10da to iorwf with operation code 0001 00da (optional dia arguments, control bit, respectively, target and access to RAM, respectively, and are stored with the same values in both cases). During execution, the difference in operating codes will cause one bit less when blocking the instruction word. The parameter in the instruction has changed from j, located at address 0x01, to and, located at address 0x00 in RAM (access RAM). Once again, the change will create one bit transition without bit transition when it is executed. In addition, notice that the contents of j and i also differ in one bit. This will also translate into one less bit passage during the parsed parameter being analyzed, when executing the statement and when saving the results. The parameter in the instruction has changed from j, located at address 0x01, to and, located at address 0x00 in RAM (access RAM). Once again, the change will create one bit transition without bit transition when it is executed. In addition, notice that the contents of j and i also differ in one bit. This will also translate into one less bit passage during the parsed parameter being analyzed, when executing the statement and when saving the results. The parameter in the instruction has changed from j, located at address 0x01, to and, located at address 0x00 in RAM (access RAM). Once again, the change will create one bit transition without bit transition when it is executed. In addition, notice that the contents of j and i also differ in one bit. This will also translate into one less bit passage during the parsed parameter being analyzed, when executing the statement and when saving the results.
LISTING 5. Modified Platform Evaluation Procedure [0084]
<td>25</td><td>ϊτιϋνΐν</td><td>0x00</td><td>/ Λ-Ι</td><td>= 00</td>
<td>AE</td><td>iontf</td><td>ΐ, 0, 0</td><td>/ 7th</td><td>= 07</td>
<td>27</td><td>K / ł \. · 1 'ii</td><td>OitOO</td><td>// li</td><td>= 00</td>
[0085] For the platform evaluation, we use only traces corresponding to row 36 of LISTING 5. The average of these traces (for each embodiment, reference embodiment and one-bit transition) is shown in Fig. 24, [0086] Using these traces, we perform LDA to identify the optimal discriminating hyper surface and linear transformation that projects our traces from the most informative perspective. The test of traces from the assessment procedure is recycled to demonstrate an improvement in the performance of the initial evaluation of the platform. The minimum distance distributions from the transformed test tracks to the signature in the new LDA transformed space are shown in Fig. 25.
Detecting Deviations from Authorized Software Executions in Software Controlled Radio Platforms and Other Embedded Systems [0087] The dynamic power consumption of the processor can be monitored to determine whether it corresponds to the expected embodiment or whether there is a deviation.
Platform Description [0088] An example of a target platform to illustrate the application of this power marking (PFP) is a software-controlled radio in which a specific embodiment of the radio behavior is controlled by the software. The general block diagram of the planned platform is shown in Fig. 26.
[0089] On this platform, the behavior and design of transceiver 2610 RF is controlled by processor 2620. Application 2626 represents the top layer and realizes the intended functionality of the processor. In order to cooperate effectively with the transmitter 2610 RF, there is a set of application programming interfaces 2624 (APIs) that create a summary of the complexity of interaction with hardware for the main application. These APIsy together with the required drivers and implementation of the protocol stack 2622 provide a support package for a specific transceiver. A stack of 2622 protocols orders data to be transmitted in a pre-determined format, adding the required headers and preparing payload data so that the recipient can extract this information. He is also responsible for extracting information received from remote devices and presenting it in the application layer 2626. The cryptographic module 2612 may be implemented in the RF transceiver or in the software as part of the protocol stack. Fig. 26 shows it as part of a transceiver. The location of the cryptographic module 2612 does not represent a practical difference in approach. Layers MAC 2614 and PHY
2616 transceiver 2610 RF are responsible for medium access, physical transmission and reception of information.
[0090] The approach described is characterized by the execution of the application software 2626, in particular the execution of the 2624 API calls that affect the behavior of the cryptographic module 2612. In this approach, the specific code executed as the result of an API call is used to determine whether the encryption was used and what type of encryption was used. For example, if an application calls a special type of encrypted transfer, this approach confirms that execution of the code calls encryption. In the case of malicious or accidental changes, this approach is a reliable indicator of modification.
Acquiring the signature [0091] L-shaped traces recorded during the i-th of the authorized code execution a are represented by
<img file="PL2635992T4_D0005.tif" />
[0092] In order to avoid possible disturbances at low frequencies from other components of the board, the basic high-pass filter without multiplication is introduced by calculating the difference between the trace samples
<img file="PL2635992T4_D0006.tif" />
[0093] Several captured traces of the execution of the authorized code are used to create the signature, our target tag. N traces are averaged to create the target signature and reduce the impact of random noise in individual tracks.
<img file="PL2635992T4_D0007.tif" />
Acquisition of traits [0094] The process of extracting discriminative features consists of time-domain correlations with the target signature. Correlation, however, is performed at j> 0 partial sections of the signature and trace, each section has a length w = floor {L}. This partial correlation is performed to avoid the spread of potential differences in power traces by correlation for a full trace.
[0095] Cross-correlation for different samples, 0 <k <W, does not have sections with data traces by:
<img file="PL2635992T4_D0008.tif" />
, where and <sup>:</sup> is the average of the samples and the standard deviation of the relevant section w, and i i is the average of the samples and the standard deviation of the respective sections w.
[0096] In order to compensate for any clock drift, we maintain maximum correlation values for different delays. This makes it possible to reduce the number of dimensions of our traces to just the sequence j of the peak values of the correlation values for each trace:
<img file="PL2635992T4_D0009.tif" />
<img file="PL2635992T4_D0010.tif" />
<a name="caption1"></a>maxp k *
Under ideal conditions and for all sections j. Any deviations from the power consumption characteristics will be visualized by a reduced correlation coefficient.
[0097] The actual discriminant or statistical test used in the present work to assess traces is the minimum correlation peak for a given trace
<img file="PL2635992T4_D0011.tif" />
<img file="PL2635992T4_D0012.tif" />
<img file="PL2635992T4_D0013.tif" />
x, [0098] The random variable indicates the maximum deviation from the signature from the instance and the code
b. Using Xb, we can design appropriate detectors using different criteria depending on the statistical information that we can collect from the a priori system.
Response to integrity violation and layer security [0099] PFP is a very effective approach to detecting deviations in embodiments in cybernetic systems. In order to have a full solution, it is necessary to have a structured policy for handling integrity violations when PFP monitoring detects deviation from the expected performance.
[0100] There are three clearly defined phases of computer security:
• Prevention. It includes active mechanisms to stop, discourage and prevent attacks that interfere with the system by attackers, disclosure of information, etc.
• Detection. Because absolutely perfect prevention is impossible, it is necessary to constantly monitor the integrity of the system • Answer. A set of policies set to respond to successful attacks.
[0101] The architecture of PFP implementation will now be described in the comprehensive approach of in-depth security architecture (defense-in-depth). In this approach, PFP provides a robust solution for the "Detection" step to complement a range of different techniques to prevent and stop potential attacks. The right response to various successful attacks is determined in the "Response" phase and is described in accordance with the security policy described below.
[0102] While achieving the security of a system requires a process, not just isolation of mechanisms or technologies, isolation will focus on describing areas in which PFP can complement traditional security mechanisms to provide continuous or intermittent monitoring to assess integrity and intrusion detection. Before describing the role of PFP, it is worth mentioning that the security process involves several steps, including:
• Project. Applying to established design approaches and designing systems to help enforce security, reduce vulnerability, enforce access control, etc. A typical example is designing a system that secures security functions from the rest of the functionality, and access control functions are inherently enforced.
• Development. Follow the best developed practices to create products that can be maintained with a small number of gaps.
• Implementation. Make sure that only authorized modules are installed. This requires certain and non-refusing authentication approaches.
• Operation. Maintain a safe environment by enforcing secure access control and other security policies.
• Monitoring. Constantly evaluate the integrity of the system. PFP, anti-virus and network intrusion detection systems.
• Reply. Specify policies and procedures to follow when the attack completes successfully. Rules should be developed with regard to the criticality of systems and which should be strictly enforced.
[0103] This section describes an architecture that enables the integration of PFP monitoring into a comprehensive security solution that includes complementary security mechanisms in which gaps in one layer are covered by the next. Approaches and technologies included in different layers include: data encryption at rest, strong authentication, access control, resistance to changes, firewalls, sandboxes, virtualization and physical protection. The architecture also provides a mechanism for defining and enforcing a security policy to respond to integrity violations detected by PFP.
[0104] The architecture defines a layered security solution in which PFP monitoring provides the last line of defense by detecting when an intruder can go through all other defense mechanisms. Fig. 27 shows different layers 2700 in the approach of in-depth security architecture. Different layers have to slow down the opponent and make it harder and harder to break the protection of the layer without being noticed. External layers include external defense mechanisms, such as firewalls, physical protection of hardware and password, and security policies (ie to prevent organized group attacks). Inner layers correspond to the various protections that are inside the 2750 host. Starting from 2740 access control and data encryption at rest. They continue using various security mechanisms designed to protect application 2760 and operating system 2770. Core 2780 includes controls on the most basic kernel and security operations.
[0105] PFP can effectively control the integrity of the various layers. At core 2780, PFP can assess the integrity of kernel and security operations that other mechanisms depend on. It can also be extended to monitor the integrity of the core application in the 2770 operating system, as well as the integrity of critical applications 2760 at the user level. Note that PFP can monitor the integrity of all modules in the processor range, including anti-virus modules and encryption modules, as shown in Fig. 28, [0106] Integrating PFP into a deepened security architecture approach for cyber security, enabling faster handling of potential incidents before they can achieve their goals and cause damage.
[0107] Power signatures from the implementation of other security modules, such as encryption and anti-virus, are extracted and evaluated during the program execution time. From a PFP perspective, signatures from the kernel module and antivirus program are downloaded in the same way and using the same techniques.
[0108] It should be noted that PFP can be extended to another device to monitor its integrity at runtime. This includes devices that can be used to implement various security layers, such as firewalls, digital security locks, etc.
[0109] The final step of the cyber-defense using PFP is to determine the appropriate rules to handle the various abnormalities detected by the monitoring and evaluation operations. Because the appropriate response to a successful hacking depends on several factors specific to each platform and application, we can not generalize the response to the various invasions detected by PFP monitoring. Therefore, it is necessary to adhere to an architecture that accepts and enforces various definitions of security policies that can be adapted to different systems while maintaining and reusing the basic operating principles and structures.
Distributed PFP monitoring network for monitoring the dynamics and behavior of malicious software [0110] This section describes the operation of a wide network of nodes with PFP functions that are deployed in different geographic or logical regions to monitor the spread of malware, detect targeted attacks, and discover potential intentions of malicious opponents. This approach is used to detect hidden remote attacks on specific logical or geographical areas.
[0111] One of the main advantages of using PFP for this application is its concealment, which prevents opponents from detecting and monitoring monitoring activities, giving them a false sense of concealment (believing they have not been detected) and prompting them to conduct their actions, disclosing intentions and possibilities. This application of PFP is a powerful tool for gathering information.
Action.
[0112] Stealth monitoring is achieved due to the small footprint PFP and the slight memory load and delay in the target system. The distributed network of PFP nodes is implemented in the following way:
1. Enable representative nodes using PFP (match them to PFP monitoring and extract trusted signatures from their target components). The monitoring can be mounted in a stand and economical, because the target nodes only work as honeypot.
2. The deployment of a PFP network that allows nodes to target geographic or logical areas.
3. Monitor each node individually for violation of integrity and intrusion, as shown in Fig. 29.
4. Periodically send integrity results to a central place for logging and analysis.
5. In the event of a breach of integrity, the report should include:
(a) a copy of the traces of power that occurred in the breach, (b) a structured sequence of execution of the unchanged module that was made before the breach (c) an ordered sequence of modules made after the violation.
[0113] This application of PFP is shown in Fig. 30. The figure shows honeypot PFP in different geographic networks. It is worth noting, however, that network separation can be logical, as in various sections of the same network, or socio-political, as in networks for various government agencies or corporate departments.
[0114] The connections between honeypot and the centralized location of the analysis are shown in
Fig. 30 as dotted lines may be implemented as a separate network (e.g., dedicated wireless links) or implemented using available networks covering large surfaces, such as a public switched telephone network (PSTN) or the Internet. In any case, strong non-disconcerting mechanisms should be established to provide evidence (authenticity of high reliability) of the origin and integrity of traces, in order to maintain the credibility of the system as a whole.
Application of PFP to supply-chain trust analysis [0115] Outsourcing of manufacturing and production of equipment to foreign untrusted foundries and factories 3220 opens the door to potential breaches of security and change. Even with trusted suppliers, there is the possibility of foreign or dissatisfied staff who may try to disrupt the operation and functionality of critical systems.
[0116] PFP provides mechanism 3210 for unauthorized detection of modifications and other changes in software, firmware and hardware introduced by untrusted links in the supply chain throughout the entire life cycle of the system. Assessing the integrity of new deliveries and untrusted devices using PFP requires the steps shown in Fig. 31. The input vector generator 3110 is used to provide the necessary inputs to implement the target device in a controlled environment 3120, during which 3130 power traces are collected. Parameters of particular power consumption characteristics are compensated 3140 before extraction of 3150 features. The obtained characteristics are compared 3160 to stored reference signatures 3170, and this comparison gives the final result of the evaluation.
[0117] Detecting the integrity of digital devices using PFP is not a destructive process and requires only minimal cooperation with the device being evaluated. In addition, precise measurements of power consumption ensure significant visibility in the internal state of the device, which makes it extremely difficult to hide modifications. For example, PFP can detect changes that only activate under certain conditions (also known as time and logic bombs) due to partial activation of additional functionality or execution of flow during state control. The ability of PFP to detect additional or missing features does not depend on the purpose or intention of inserting them alone. [0118] Another advantage of PFP is that a specific execution path verified by PFP can be trusted, even if no harmful activity is triggered. In other words, if PFP does not detect a significant deviation from the signatures, this means that no changes or additional functions have occurred in this particular execution path.
[0119] A key element in implementing a PFP supply chain trust analysis is the execution of an untrusted device in a controlled environment 3120. This controlled environment includes predefined inputs 3110 that enforce a specific sequence of states and, for programmable devices, specific software to execute. For some systems, it may be necessary to develop supportive frames to control and isolate specific components. The individual input vectors depend on the functionality of the device or software module or software module and are expected to use critical execution paths for device operation. The same input vectors used to extract signatures must be used to assess the integrity of untrusted devices.
[0120] Due to the slight differences in the manufacturing process, different devices exhibit different power consumption characteristics. These differences in power consumption must be compensated for 3,140 before the separation of 3150 features to avoid erroneous assessments. Compensation is carried out using an adaptive filter whose taps are dynamically modified to match the specific characteristics of the power consumption traces. This adaptive filter allows PFP monitoring to focus on the power consumption resulting from the bit transition in the device register during execution and eliminates differences in traces caused by the varieties produced.
[0121] The most important aspect of an effective analysis of supply chain trust using PFP is the availability of reference signatures 3170. There are various potential sources for such signatures, as shown in Fig. 32. The best reference would be to provide an identical trusted implementation (gold standard) of 3230. In many cases, however, such trusted implementation is not available. In these cases, the reference signature can be extracted using alternative methods with varying degrees of error and reliability. For example, two relatively simple alternative reference sources include the prior implementation of a 3250 device (one that was tested over time) or an alternative implementation from another vendor 3260. In these cases, the signatures are extracted from performing alternative implementations, reducing the chances of two identical modifications by different suppliers. Signatures from the previous approach may not see any unidentified modifications present in earlier versions. In the latter approach, the attacker could create an identical modification in both versions from different providers to avoid detection.
[0122] Using the 3240 CAD model to obtain signatures requires more effort, but it can be done internally without the need to lean on other foundries. In order to extract the signatures using the CAD model, it is necessary to simulate the device implementation using deterministic input vectors. The simulator must be accurate in terms of power consumption for the level of register transfer.
Digital rights management and implementation of limited licenses [0123] Another new application for PFF is the enforcement of digital rights and the implementation of a limited license agreement to enable licensing based on the number of executions.
[0124] This approach is implemented by extracting signatures from the performance of protected software and monitoring runtime power markers to enforce only authorized modules. For example, a software layout may be licensed to cover only a set of functional modules with a subset of modules reserved for a higher license level. Tags from all modules are extracted before being released to the market. During execution, PFP monitors the performance of various modules with authorized licenses. When the unlicensed module works, as a result of a stolen password or a security breach, PFP monitoring may inform the agency issuing it of the violation. Additionally, it is possible to provide a trusted licensing approach limited to one instance for protected software. In this case, PFP monitoring stores the number of performances of the licensed software and informs the issuing agency about it after the license expires.
[0125] A similar approach can be obtained with licensed media content. By using PFP monitoring, you can detect the playback of specific files on known media players using PFP. In this case, protected media data replace the predefined input during the PFP assessment. If the same media is played on a specific player, the power signatures will match. For this reason, PFP can be used to detect unauthorized playback of licensed media.
PFP failure prediction [0126] Hardware components are subject to unavoidable aging processes, accelerated by operating in harsh environments or when systems are operating under a continuous environmental load. This aging is reflected in the power consumption characteristics of the platform. PFP can be used to monitor not only the correct implementation of the software, but also the integrity of the hardware platforms. PFP monitoring can continuously monitor the power consumption characteristics of the equipment and predict the failure before it occurs, indicating when to replace a specific system or element.
[0127] The tracking of the power consumption characteristics in the PFP is carried out using an adaptive filter. It is needed to compensate for differences in energy consumption from the moment the signature is extracted or due to environmental conditions. The same tracking mechanism can be used to monitor equipment status and compare power consumption characteristics with established patterns captured in equipment testing laboratories. The process of identifying failure characteristics is shown in Fig. 36. In this process, aging 3610 can be accelerated by exposing the target device to rapid temperature changes. The evaluation process takes place at intervals, during the test procedure an accelerated aging step of 3620 is applied, followed by grasping the 3620 track. Traces are collected for posteriori analysis, and the process is repeated until the device fails. After the failure of the device, the set of traces is examined to determine the specific features that appear before the failure 3630. These features are extracted from other similar devices to ensure statistical diversity and to isolate the general characteristics of 3640.
Embedding module identification information in the synchronization signaling [0128] PFP requires proper synchronization with the software to be performed to ensure correct evaluation. There are two cases of synchronization in
PFP: clock cycle level and routine level. The first can be easily achieved by tracking different cycles in the power consumption that occur at a given clock speed or, in the case of simple platforms, by sampling the clock signal itself. The latter synchronization is more difficult to achieve, and the process is facilitated by embedding the trigger or identifier itself, which will inform the PFP 3210 monitoring of the execution of a specific procedure.
[0129] In this section, we present a mechanism for identifying a node that is executed in triggering and signaling mechanisms. This mechanism not only helps in informing PFP monitoring which specific procedure is to be performed, but also provides a certain synchronization signaling for more accurate detection of anomalies and separation of the behavior signature.
[0130] The ultimate goal is to provide an identification code for the various modules that are evaluated and which is inserted for synchronization and triggering artifacts for PFP. There are two main approaches to providing signaling and identification synchronization for PFP: 1) creating an adjacent physical signal, as shown in Fig. 33, and 2) embedding a signal in the power consumption itself, as shown in Fig. 34. In this latter approach, binary the identification code is recorded in the physical register 3324 of the processor 3320 before performing the procedure 3322. The register is then sent 3335 for monitoring 3340 PFP, which captures traces of power 3315 from the sensor 3310 either in a parallel or serial manner. The length of the code and the registry depends on the number of procedures that need to be monitored. In the simplest sense, a one-bit register, for example LED, it can be used to signal the execution of the target procedure. In the case of separate physical signaling, the trigger is coded as a binary number in the register of signals, as shown in Fig. 33.
[0131] The second approach requires that the signaling be synchronized to be embedded in the power consumption itself by inserting a carefully prepared instruction sequence 3422 that gives a characteristic power consumption pattern. This approach is illustrated in Fig. 34. The instructions for the synchronization procedures are selected in such a way that the bit transition in their code words, addresses and parameters gives a specific number of bit transitions that ultimately drive power consumption and signal to the 3340 PFP monitoring that a specific the sequence is to be performed in order to capture the proper set of traces 3415 coming from the 3410 sensor. A higher number of bit transitions result in a higher power consumption. When developing the sequence, the length and characteristics of the information stream should be taken into account. As in the previous approach, the length of the instruction sequence (code) depends on the number of critical procedures that need to be identified. By creating different distinct power consumption patterns, the sequence is selected to give different pattern codes used to identify different modules.
[0132] It is important to note that signaling synchronization is a required element for an effective PFP because it allows the focus of the assessment effort to be on the code sections that are most important. Embedding the identification code in the signaling facilitates the evaluation process, but it is not a prerequisite. This is because using a single trigger allows PFP monitoring to capture the right set of traces, and signal classification techniques can be used to determine which particular procedure was performed and whether a reliable match (anomaly) can not be determined.
Improved PFP monitoring by combining signals from different panel elements [0133] Signals from various components of the system can be used by PFP monitoring and can be combined for better performance and reliability. Sources of multiple signals include multiple processors, co-processors, peripheral devices or other special-purpose elements, introduced only to increase PFP (e.g., IO registers used for triggering).
[0134] There are various ways to combine signals from different sources in PFP. One of the main approaches is to capture power traces from different processors or other digital circuits to perform integrity assessment on multi-processor and multi-core boards. Another approach is to monitor other elements of the system (power consumption or other side and direct channels) in order to collect special context information to be used during the integrity assessment. Special contextual information can be used to improve synchronization and facilitate behavioral assessment. Contextual information can be generated as a product of normal system operation or intentionally entered during design (eg IO registers used for triggering). Fig. 35 shows an exemplary configuration of PFP monitoring, which combines many signals. [0135] Additional signals may be captured from direct support of IO registers, from power consumption by various elements or from other side channels such as electromagnetic radiation. Combining signals from different sources requires a specially designed detector that can handle different functionalities. The specific connection mechanisms depend on the functionality of the system and the supported platform. For example, in a multi-core processor, you can scan power traces from each core to find traces that correspond to the target procedure. Another example on the radio specified by the software, activation of the power amplifier (PA) can be detected by monitoring power consumption and takes place when there is radio transmission.
Using Malware Signatures to Boost PFP Performance [0136] Although the main application of PFP is anomaly detection, the benefits of using available information for known malware to improve evaluation performance are important. After identifying the new malware trend, you can extract its PFP signature and add it to the library of known signatures. These malware signatures can be used to improve the effectiveness of PFP integrity assessments, providing traditional detection of signature-based malware as well as traditional antivirus software. Monitoring should be aware of the individual nature of each signature (white list and black list) in order to avoid incorrect assessments. Malware signatures can also be extracted from behavior patterns during execution. For example, some types of malware, such as exhaustion attacks, have very different patterns that can be easily identified using PFP.
[0137] The process of extracting signatures for malicious software is similar to the process of extracting signatures for trusted software, in which target modules are executed repeatedly in a controlled environment, and different signal processing techniques are applied to the resulting power traces to select features with the best discriminant properties. It is important to remember that the characterization of malware is made easier when malware has been identified, isolated and made in a controlled environment.
Automatic evaluation and isolation of the signature [0138] In order to effectively characterize the new software system or a new version of the existing system, it is necessary to have tools to automatically evaluate the trusted reference and extract PFP signatures that uniquely identify the execution of specific software. In a sense, this process is similar to automated testing because it requires specific modules to be run under controlled conditions. However, it differs from automatic tests, PFP assessment consists only in "observing" several instances of execution of various modules and does not attempt to assess any requirements or properties.
[0139] The purpose of this chapter is to describe the approach to facilitate the evaluation of complex layouts and software architectures, and to allow the signature to be extracted into real implementations of cybernetic systems with practical complexity. Without this automatic approach, it would take too long to characterize and extract unique signatures from complex systems (ie commercial systems) that are to be used for labeling.
[0140] The main purpose is to automate the evaluation process of the various modules using frames similar to what is typically used in software testing, as well as using various statistical analyzes and signal processing to determine the best discrimination features that markers create. The process begins when you need to evaluate a new software stack. The main tools necessary for this process include: critical module descriptors, signal processing tools for acquiring features, tools for detector design, frame for module execution (similar to test frames), input vector generators, report generation and signature packaging. To help us understand the approach, we provide a high level of discussion of the process that describes the details and interrelationships between different subsystems.
• Descriptors include required information about critical modules, including unique identifiers, dependencies, input analysis (division into different input classes), execution mode (dynamically linked, priorities, kernel module, etc.).
• The information from the descriptors is used to implement the framework for controlling the insulation of the implementation of the target modules. The frames allow the system to enter deterministic values as inputs to control the implementation of modules.
• A coverage analysis was conducted to identify the execution paths that were made and to determine the system's protection level.
• After loading the system, the operator (which can be an automatic system) performs various modules with frame support and provides the appropriate input vectors. When performing modules, PFP monitoring captures power consumption measurements.
• The power traces obtained by monitoring are then processed using various signal processing techniques to identify discriminatory characteristics. There is a predefined set of functions to be extracted for each component in different fields and using different techniques.
• After capturing several traces and analyzing the relevant features, a statistical analysis is performed to design optimal detectors to distinguish normal activity from anomalies based on specific application requirements.
• Signatures and detectors are then packaged together so that they can be implemented along with monitoring that will evaluate the integrity of the target systems.
[0141] The following sections include more detailed descriptions necessary for successful implementation of the approach described above.
Descriptors [0142] Descriptors contain a meta-information of specific modules to be evaluated. They are used to develop a framework for artifacts to extract individual modules and provide a controlled environment for performing different execution paths.
[0143] Descriptors should be made available in the markup language, easily readable by humans and machines, such as extendable markup language (XML), but the content, language and structure will depend on the specific tools used to automatically determine the process evaluation and it can be reserved.
[0144] The minimum information required, which must be included in the PFP assessment module descriptors, includes:
• Unique identifiers describing each module. Unique identifiers should be human-readable and provide the necessary information to uniquely find a given module. Elements in the human readable part include the company, product, class, module and version.
• Dependencies. Required software and hardware dependencies for the module.
• Status dependencies. Elements of the internal state affecting the behavior of the module and which must be controlled in order to ensure a consistent and deterministic performance.
• Interface analysis. Provides a breakthrough for different input classes and required input classes to implement different execution paths.
• Execution mode. It describes in which mode the module will be executed after implementation, i.e., static, for statically connected modules; dynamic, for dynamically connected modules; kernel or protected mode, for the operating mode that the processor will accept when executing the module; and priority level.
Input Vector Generators [0145] The function of the input vector generators is similar to their counterparts in software testing to provide adequate input data to force the component to a specific state sequence including different execution paths. Unlike tests, the goal for PFP input vectors is not to find implementation errors, but simply to perform different execution paths.
[0146] Depending on the nature of the target system, it is sometimes necessary to store the input vectors and distribute them with the signatures to be used during the evaluation (i.e., integrity check). The decision whether to keep the input vectors depends on the nature of the functions selected and whether traces caused by accidental input data can be removed.
[0147] Input vectors can be generated using a variety of techniques, including search-based ones (random search, maximum function finding, genetic algorithm, etc.), partial scanning, linear programming, and random and pseudorandom approach.
[0148] The actual identification of effective test vectors, however, remains to a large extent a heuristic approach, which depends on the specific functionality of the target module and its input domain, as well as information on the structure of the module. There will be several cases where a specific knowledge about the module's execution structure is needed (what are the execution paths and the sequences of states necessary to perform them) is needed to find meaningful input vectors within a reasonable time. In addition, a direct introduction of expert analysis may sometimes be required to provide guidance to automated tools to identify and generate meaningful, effective test vectors.
[0149] One of the key elements of generating test vectors for PFP is that the goal is to perform various paths that are to appear after implementation of the device, and not to find errors. This is a relatively risky approach, because it is possible to achieve an appropriate implementation that has not been characterized and is therefore marked as an anomaly. The advantage is that it reduces the search space to just a few states. In most critical systems, the execution space is relatively small, and the expected execution states are a subset.
Coverage Report [0150] Using information from the input vector generator, it is possible to generate a coverage report based on execution paths passed through specific input vectors. By using structural information from the target modules, you can calculate the PFP coverage rate as a percentage of existing paths in the module, and those that pass through the generated input vectors. This report is only an indication of the expected coverage for PFP. The report must still be completed, identifying the number of execution paths that actually yield acceptable PFP signatures.
[0151] The report is provided at the end to provide users with information on specific modules that can be monitored using PFP.
Scaffolding [0152] Together with the descriptors and software stack, a scaffold process is carried out to isolate the execution of critical modules and their various components. This is similar to the scaffolding process for automated testing. The purpose of the scaffolding is to implement the target modules in a controlled environment, similar to the one that will be found after the entire system has been started up to collect power traces during its execution. Because the modules are expected to have different execution paths that depend on the input data, the scaffolding must make it easier to use different input data. [0153] In the case where physical input is needed, scaffolds must provide appropriate physical interfaces to provide the necessary input data.
[0154] This is a partially manual process and depends on the characteristics of the target modules. Preferably, most scaffold components overlap with conventional automatic testing scaffolds (e.g., unit, system integration and testing), adding only a small amount of extra work.
[0155] It is important to remember that in the case of non-software implementations, scaffolding will have similar requirements, although the final implementation will be different. In these cases, the modules will be limited by sections that can be executed independently. In the case of very integrated systems, this can be a challenge.
Signal processing and extraction of features [0156] Thanks to power traces corresponding to the performance of different modules and their individual execution paths captured by the power / current sensor, discriminant features that uniquely identify the implementation of the target module should be extracted. The exact set of techniques and signal analysis necessary to identify the practical signatures depends on the specificity of the target modules.
[0157] We simply describe a frame for the simultaneous implementation of a number of different signal extraction and processing techniques to shorten the overall time required to characterize the target module.
[0158] An effective procedure is not known to determine the optimal discriminative features of a given problem. However, there are several techniques that can be assessed and which select the best, discriminatory features. A set of distinguished features is determined using a combination of heuristic approaches and experience. These features include: time domain correlation, Euclidean distance, cyclo-stationary analysis, frequency analysis, etc. The process of selecting the best discriminant features consists in calculating all the different features in the set in parallel and classifying them on the basis of intra-class variability. The Mahalanobis distance is an example indicator for such a feature assessment.
[0159] The feature selection process and detector design explained below are closely related to each other because statistically matched extraction results determine the necessary analysis to determine the optimal detection threshold.
Statistical analysis and detector design [0160] Statistical analysis is performed on various features obtained as a result of power traces obtained during independent instances of the target module. The aim of the statistical analysis is to select the features characterized by the best discriminatory properties and to determine the threshold levels or areas in which the observed set of functions will be considered generated by the target module (detector).
[0161] In PFP, an approach to detecting anomalies, the false alarm probability (PFA) is an important operational indicator that determines system performance. PFA is defined as the probability that the normal execution instance of the destination module is outside of the acceptance area and is classified as an anomaly. The PFP detector must be designed in such a way as to minimize PFA when maximizing the probability of correctly identifying the target module. This is a classic hypothesis testing problem and the Neyman-Pearson criterion can be used to detect the threshold. However, there are several other approaches that you can use.
[0162] Considering sufficient samples, arbitrary PFA can be achieved in PFP. In practice, however, systems are not feasible, and a certain practical PFA level must be specified. The PFA that can be tolerated depends on the specific module and nature of the application for which it is intended to work.
[0163] Ideally, signatures from different instances of the same embodiment must be located at a distance for the minimum sensitivity calculated during platform characteristics. In the event that the desired function can not be achieved, there are several ways PFP can provide accurate assessments. One simple approach is to average the tracks to get rid of the noise.
Package and signature encryption [0164] After characterization of the target modules, the obtained signatures, extraction techniques and thresholds are packaged for deployment with devices. The packaging and delivery mechanism depends on the characteristics of the device and the application. Complete signatures extracted using selected functions must be stored and transferred to monitors. For example, in the case of a simple time-domain correlation, a complete vector must be stored.
[0165] To protect signatures at rest or during transport, they must be encrypted to avoid giving potential attackers an accurate reference to the signatures that the monitor expects. This encryption can be performed using various private or public key encryption mechanisms. It is worth noting, however, that even if the potential attacker gains signatures, it would still be very difficult to match them perfectly to the signatures while maintaining malicious behavior.
Secure signature update [00166] When the monitored deployment system using PFP is updated, it is also necessary to update the PFP signatures in a reliable and secure manner in order to maintain an effective integrity assessment. This is a critical step, because the credibility of the assessment depends on the proper management of the signature. For this update process to be secure, it is necessary to check the integrity and authenticity of the signature. In this section, we describe the mechanism necessary to ensure secure update of PFP signatures.
[0167] For widespread PFP monitors, signatures should be distributed along with other software updates. For centralized PFP monitors, updates can be provided separately from software updates. The main challenge in updating PFP signatures is to authenticate (ie to make sure that the sender is an authorized entity, and the signature itself is correct and has not been tampered with or changed in any way). The challenge is not difficult with centralized PFP monitors where signatures can be distributed using physical media or trusted networks and where you can prepare to predict the transfer of sensitive signatures.
[0168] For widespread PFP monitors where the signature exchange can not be performed using physical means or alternative trusted networks, the signatures must be updated together with the actual software update. In this case, there are several weak points that can be used by the attacker with sufficient knowledge about the PFP system. For example, if it is not properly authenticated, the update process can be interrupted by a man-in-the-middle attack.
Secure signature update process and its operation.
[0169] Known approaches to secure content distribution commonly used in over-the-air programming and software update distribution may be adapted to update PFP signatures. Secure signature updates can be seen from two different perspectives: the original author of the signatures and the PFP monitor. From the generation of signatures, it is necessary to provide effective authentication information along with the signature and encryption of signature elements with a variable rotating key scheme.
[0170] Other techniques that can be used to allow secure signature updates include:
• encryption of both sample buffer and signature elements • Public or symmetric key encryption • Change of the encryption key to be used to decrypt the signature and traces according to the known sequence (PN Sequence), which updates the index after each signature update.
Protection against attacks by side channel.
[0171] PFP uses the same integrity assessment principles that are used for malicious side channel attacks. Therefore, to prevent potential opponents from using the PFP infrastructure to perform side attacks, it is necessary to protect the traces provided by the sensor, limiting access to them. This is especially important when power traces are transmitted using a wireless connection. This section describes a mechanism to protect unauthorized access to power traces that can be used in side channel attacks.
Action.
[0172] Track access protection is done by encrypting or encrypting traces using a shared key between the PFP sensor and the PFP monitor. In this perspective, there are two basic PFP operating modes: a built-in monitor (sensor and digitizer) and an external monitor.
[0173] In embedded operations, the traces are encrypted or encrypted with a strong private key (symmetric key encryption). The implementation of this encryption step is particularly important when power traces are transmitted wirelessly to external processing. The encryption process is described in Fig. 38. The analog output of the 3810 processor is monitored by the 3820 sensor and converted by the 3830 analog-digital converter and input into the 3850 cipher. The cipher 3850 can hide relevant information from the side channel attackers in several ways, including encryption block of bit samples or their coding (effectively a transpose cipher, where the key is a permutation).
[0174] For external monitors, the physical connection to access the tracks is enabled by a digital switch requiring a password. In this case, the external monitor contact points are provided by the power management system on the platform. An energy management system can be as simple as a voltage regulator, but in most commercial processors used in modern smartphones, energy management systems are much more complex. When connected to the appropriate monitor, the PFP PFP power manager reads the password from the external monitor when it is connected and then redirects the power supply to pass through an external sensor that allows the external monitor to capture instantaneous power consumption or energy consumption. Fig. 39 is a graphical representation of this process.
[0175] It is important to remember that the solutions described herein are not intended to prevent attackers from carrying out side channel attacks on target systems. Instead, they are designed to prevent the use of PFP monitoring devices for side channel attacks. If these measures were introduced, the potential attacker would have to introduce the same hardware modifications to the PFP monitoring board, as well as to the one without it.
[0176] Although the invention has been described in preferred embodiments, the scope of the invention is defined by the appended claims.
Virginia Tech Intellectual Properties, Inc., United States of America Plenipotentiary:
EP 2 635 992 B1-15866/17
30 members in 16 offices
Priority claims9
| Document | Office | Kind | Date |
|---|---|---|---|
| 40967010 | United States of America | P | |
| 40967010 | United States of America | P | |
| 201161475713 | United States of America | P | |
| 201161475713 | United States of America | P | |
| 118388453 | – | – | – |
| 201161475713P | – | – | – |
| 409670P | – | – | – |
| US20100409670P | – | – | – |
| US201161475713P | – | – | – |
Members30
| Document | Office | Kind | |
|---|---|---|---|
| CA2816970A1 | Canada | A1 | |
| WO2012061663A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO2012061663A3 | World Intellectual Property Organization (WIPO) | A3 | |
| AU2011323210A1 | Australia | A1 | |
| IL226078A0 | Israel | A0 | |
| SG190090A1 | Singapore | A1 | |
| MX2013005074A | Mexico | A | |
| EP2635992A2 | European Patent Office (EPO) | A2 | |
| CN103370716A | China | A | |
| KR20130118335A | Republic of Korea | A | |
| US2013318607A1 | United States of America | A1 | |
| JP2014501957A | Japan | A | |
| RU2013125468A | Russian Federation | A | |
| EP2635992A4 | European Patent Office (EPO) | A4 | |
| SG10201509052WA | Singapore | A | |
| US9262632B2 | United States of America | B2 | |
| US2016117502A1 | United States of America | A1 | |
| US2016117503A1 | United States of America | A1 | |
| BR112013011038A2 | Brazil | A2 | |
| CN103370716B | China | B | |
| US9558349B2 | United States of America | B2 | |
| US9558350B2 | United States of America | B2 | |
| EP2635992B1 | European Patent Office (EPO) | B1 | |
| ES2628820T3 | Spain | T3 | |
| PL2635992T3 | Poland | T3 | |
| PL2635992T4This record | Poland | T4 | |
| US2017310482A1 | United States of America | A1 | |
| TR201707304T4 | Türkiye | T4 | |
| US10423207B2 | United States of America | B2 | |
| US2020103949A1 | United States of America | A1 |
Numbers
- Publication
- 2635992
- Publication, DOCDB
- 2635992
- Publication, EPODOC
- PL2635992T
- Application
- 11838845
- Application, DOCDB
- 11838845
- Application, EPODOC
- PL20110838845T
Titles2
- English
- USING POWER FINGERPRINTING (PFP) TO MONITOR THE INTEGRITY AND ENHANCE SECURITY OF COMPUTER BASED SYSTEMS
- Polish
- UŻYWANIE WYZNACZANIA ENERGETYCZNEGO ODCISKU PALCA (PFP, POWER FINGERPRINTING) DO MONITOROWANIA INTEGRALNOŚCI I ZWIĘKSZANIA BEZPIECZEŃSTWA SYSTEMÓW KOMPUTEROWYCH
Classification
- CPC, 13
- G06F11/3062
- G06F1/28
- G06F21/00
- G06F11/3093
- G06F21/52
- G06F21/755
- G06F1/3206
- G06F11/30
- G06F11/22
- G06F21/56
- G06F2221/033
- G06F2221/034
- H04L9/3247
- IPC, 5
- G06F21 00
- G06F11 22
- G06F11 30
- G06F21 52
- G06F21 56