WO2012061663A2

Using power fingerprinting (pfp) to monitor the integrity and enhance security of computer based systems

Abstract

Procedures are described for enhancing target system execution integrity determined by power fingerprinting (PFP): by integrating PFP into the detection phase of comprehensive defense-in-depth security; by deploying a network of PFP enabled nodes executing untrusted devices with predefined inputs forcing a specific state sequence and specific software execution; by embedding module identification information into synchronization signaling; by combining signals from different board elements; by using malware signatures to enhance PFP performance; by automatic characterization and signature extraction; by providing secure signature updates; by protecting against side- channel attacks; performing real-time integrity assessment in embedded platform by monitoring their dynamic power consumption and comparing it against signatures from trusted code, including pre-characterizing power consumption of the platform by concentrating on trace sections carrying the most information about the internal execution status; by using PFP from sequence of bit transitions to detect deviations from authorized execution of software in a digital processor.

WO2012061663A2, drawing sheet 1
Sheet 1 of 53

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Published
  4. Today

13 claims: 3 independent, 10 dependent

  1. 1
    CLAIMS [0209] Having thus described our invention, what we claim as new and desire to secure by Letters Patent is as follows:1. A method for performing real-time integrity assessment of execution of a routine in a computer processing platform, comprising: monitoring execution of the routine by tracing power consumption of a processor by sampling during execution of the routine;using a platform characterization technique that further comprises detecting sections of the traces that display the largest dependence on state transitions in the processor;using said sections to select features carrying the most information;obtaining from a characterization of selected features of the routine contained in said sections a set of trusted power fingerprints of the routine;establishing a threshold for a specific false alarm rate based on the probability distribution of distance from a signature comprised of said trusted fingerprints;comparing a library of said trusted fingerprints to features extracted from traces from the execution of untrusted code determining a distance between said fingerprints and the extracted features;and reporting an exception if the distance exceeds the threshold.
  2. 7
    A system for performing real-time integrity assessment of execution of a routine in a computer processing platform, comprising:means for monitoring execution of the routine by tracing power consumption of a processor by sampling during execution of the routine;means for using a platform characterization technique that further comprises means for detecting sections of the traces that display the largest dependence on state transitions in the processor;means for using said sections to select features carrying the most information;means for obtaining from a characterization of the selected features contained in said sections a set of trusted power fingerprints of the routine;means for establishing a threshold for a specific false alarm rate based on the probability distribution of distance from a signature comprised of said trusted fingerprints;means for comparing a library of said trusted fingerprints to features extracted from traces from the execution of un trusted code means for determining a distance between said fingerprints and the extracted features;and means for reporting an exception if the distance exceeds the threshold.
  3. 13
    A method for detecting deviations from authorized execution of software in a digital processor, comprising:observing power consumption of the processor during execution of at least one routine of the software in a known setting;determining a sequence of bit transitions characterizing the power consumption of said at least one routine;and using the power consumption characterization as a fingerprint for comparison against observed execution of the software to determine deviation.