IP Library Granted Patent US 9,652,611
Granted Patent B2
US 9,652,611 · App. 14/712,777 · Granted May 16, 2017

Mitigating a compromised network on chip

Inventors: Dean Michael Ancajas (Logan, UT); Koushik Chakraborty (Logan, UT); Sanghamitra Roy (Logan, UT)
Assignee: Utah State University
G06F21/55G06F21/56G06F21/85
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,652,611
App. No.
14/712,777
Granted
May 16, 2017
Kind
B2
Abstract

For mitigating a compromised network-on-chip, code appends a node identifier of a destination node to a packet transmitted in a multiprocessor system-on-chip (MPSOC). The MPSOC may include third-party components such as a network-on-chip. The code may detect a copy of the packet from the node identifier. In addition, the code may drop the copy of the packet in response to the copy of the packet being routed to an unintended node.

Claims (35)

1. An apparatus comprising:

a processor;

a memory that stores code executable by the processor to perform:

appending a node identifier of a destination node to a packet transmitted in a multiprocessor system-on-chip (MPSOC) comprising third-party components, the third-party components comprising a third-party network-on-chip (NoC) interconnect, wherein the node identifier is embedded in a packet payload of the packet and is distinct from a packet header that specifies routing the packet to the destination node, the node identifier is encrypted, and the packet is scrambled with an encryption;

receiving the packet;

decrypting the node identifier;

detecting a copy of the packet if the node identifier does not match the packet header;

in response to detecting the copy of the packet, dropping the copy of the packet;

detecting an unintended node from the packet header if the node identifier does not match the packet header; and

in response to detecting the unintended node, identifying the unintended node as a malicious node.

2. The apparatus of claim 1 , wherein the processor further periodically moves a process from a first node to a second node in the MPSOC.

3. The apparatus of claim 1 , wherein the processor further scrambles the packet for transmission within the MPSOC.

4. The apparatus of claim 1 , wherein the process is moved after an obfuscation time interval.

5. The apparatus of claim 1 , wherein the processor further isolates the malicious node.

6. The apparatus of claim 1 , wherein the processor further disables the malicious node.

7. The apparatus of claim 1 , wherein the processor further blocks outside communications with the malicious node.

8. The apparatus of claim 1 , wherein the processor further identifies an accomplice node of the malicious node.

9. A method comprising:

appending, by use of a processor, a node identifier of a destination node to a packet transmitted in a multiprocessor system-on-chip (MPSOC) comprising third-party components, the third-party components comprising a third-party network-on-chip (NoC) interconnect, wherein the node identifier is embedded in a packet payload of the packet and is distinct from a packet header that specifies routing the packet to the destination node, the node identifier is encrypted, and the packet is scrambled with an encryption;

receiving the packet;

decrypting the node identifier;

detecting a copy of the packet if the node identifier does not match the packet header;

in response to detecting the copy of the packet, dropping the copy of the packet;

detecting an unintended node from the packet header if the node identifier does not match the packet header; and

in response to detecting the unintended node, identifying the unintended node as a malicious node.

10. The method of claim 9 , the method further comprising periodically moving a process from a first node to a second node in the MPSOC.

11. A program product comprising a non-transitory computer readable storage medium that stores code executable by a processor, the executable code comprising code to perform:

appending a node identifier of a destination node to a packet transmitted in a multiprocessor system-on-chip (MPSOC) comprising third-party components, the third-party components comprising a third-party network-on-chip (NoC) interconnect, wherein the node identifier is embedded in a packet payload of the packet and is distinct from a packet header that specifies routing the packet to the destination node, the node identifier is encrypted, and the packet is scrambled with an encryption;

receiving the packet;

decrypting the node identifier;

detecting a copy of the packet if the node identifier does not match the packet header;

in response to detecting the copy of the packet, dropping the copy of the packet;

detecting an unintended node from the packet header if the node identifier does not match the packet header; and

in response to detecting the unintended node, identifying the unintended node as a malicious node.

12. The program product of claim 11 , the code further periodically moving a process from a first node to a second node in the MPSOC.

Assignments (3)
CONFIRMATORY LICENSE Recorded Jan 28, 2021
From: UTAH STATE UNIVERSITY
To: NATIONAL SCIENCE FOUNDATION
Reel/Frame 055063/0305 →
CONFIRMATORY LICENSE Recorded Nov 20, 2019
From: UTAH STATE UNIVERSITY
To: NATIONAL SCIENCE FOUNDATION
Reel/Frame 051061/0245 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 15, 2015
From: ANCAJAS, DEAN MICHAEL; CHAKRABORTY, KOUSHIK; ROY, SANGHAMITRA
To: UTAH STATE UNIVERSITY
Reel/Frame 035653/0026 →
Continuity (2)
Provisional Application 62002482 · May 23, 2014
Related Publication 20150339485A1 · Nov 26, 2015