IP Library Granted Patent US 9,767,277
Granted Patent B2
US 9,767,277 · App. 15/405,044 · Granted Sep 19, 2017

Detection of fault injections in a random number generator

Inventor: Yannick Teglia (Belcodene, FR)
Assignee: STMicroelectronics (Rousset) SAS
G06F21/55G06F7/58
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,767,277
App. No.
15/405,044
Granted
Sep 19, 2017
Kind
B2
Abstract

A method for detecting a fault injection in a circuit, wherein a bit pattern is mixed in a bit stream originating from a noise source and the presence of this pattern is detected in a signal sampled downstream of the mixing.

Claims (59)

1. A method, comprising:

mixing a bit pattern with a bit stream originating from a noise source to generate a mixed bit sequence;

sampling the mixed bit sequence to detect the bit pattern in the mixed bit sequence;

detecting fault injection based on whether the sampling detects the bit pattern in the mixed hit sequence; and

taking one or more actions to protect a circuit in response to detection of fault injection.

2. The method of claim 1 wherein when the bit pattern is present in the mixed bit sequence, the method comprises generating a random number using the mixed bit sequence.

3. The method of claim 2 wherein generating the random number using the mixed bit sequence comprises:

encrypting the mixed bit sequence to generate a word; and

applying a resilient function to the word to generate the random number.

4. The method of claim I wherein the detecting fault injection comprises detecting fault injection when the sampling does not detect the bit pattern in the mixed bit sequence.

5. The method of claim 1 wherein the one or more actions comprises inhibiting one or more operations in response to detection of fault injection.

6. The method of claim 1 wherein when fault injection is not detected, the method comprises performing at least one of an encryption operation and a decryption operation based at least part of the mixed bit sequence.

7. A device, comprising:

a bit mixer, which, in operation, mixes a bit pattern with a bit stream originating from a noise source to generate a mixed bit sequence;

circuitry, which, in operation,

samples the mixed bit sequence;

generates a signal indicating detection of fault injection based on whether the sampling indicates the bit pattern is present in the mixed bit sequence; and

selectively takes one or more actions based on the generated signal indicating detection of fault injection.

8. The device of claim 7 wherein the bit mixer is configured to interpose one or several bits of the bit pattern between one or several bits of the bit stream.

9. The device of claim 7 wherein the circuitry is configured to store said bit pattern.

10. The device of claim 7 wherein the bit pattern comprises at least one of:

a determined bit sequence;

a randomly generated bit sequence; and

a secret key.

11. The device of claim 7 wherein when the bit pattern is missing from the mixed bit sequence, the generated signal indicates fault injection has been detected.

12. The device of claim 7 wherein the circuitry, in operation, generates a word when the generated signal does not indicate detection of fault injection.

13. The device of claim 12 wherein the generating the word comprises using at least part of the mixed bit sequence.

14. The device of claim 13 wherein the circuitry, in operation, generates a random number based on the generated word.

15. The device of claim 14 wherein the circuitry, in operation, applies a resilient function to the word to generate the random number.

16. The device of claim 7 wherein the circuitry, in operation, generates a random number based on whether the generated signal indicates detection of fault injection.

17. The device of claim 7 , comprising:

a second bit mixer configured to mix a second bit pattern into the mixed bit stream.

18. The device of claim 7 wherein the one or more actions comprises inhibiting one or more functions of the circuitry when the generated signal indicates fault injection has been detected.

19. The device of claim 7 wherein the circuitry, in operation, performs at least one of an encryption operation and a decryption operation based on at least part of the mixed bit sequence when the generated signal does not indicate detection of fault injection.

20. A system, comprising:

a noise source, which, in operation, generates a bit stream; and

circuitry, which, in operation:

mixes a bit pattern with the bit stream to generate a mixed bit sequence;

samples the mixed bit sequence;

detects fault injection based on whether the sampling indicates the bit pattern is present in the mixed bit sequence; and

selectively takes one or more actions based on whether fault injection is detected.

21. The system of claim 20 wherein the circuitry, in operation:

generates a random number when fault injection is not detected; and

inhibits random number generation when fault injection is detected.

22. The system of claim 20 wherein the circuitry, in operation:

performs a cryptographic operation when fault injection is not detected; and

inhibits cryptographic operations when fault injection is detected.

23. The system of claim 20 comprising an integrated circuit including the circuitry and the noise source.

24. A non-transitory computer-readable medium having contents which configure a processing device to perform a method, the method comprising:

mixing a bit pattern with a bit stream originating from a noise source to generate a mixed bit sequence;

sampling the mixed bit sequence to detect the bit pattern in the mixed bit sequence;

detecting fault injection based on whether the sampling detects the bit pattern in the mixed bit sequence; and

selectively taking one or more actions based on whether fault injection is detected.

25. The non-transitory computer-readable medium of claim 24 wherein the method comprises at least one of:

inhibiting one or more functions of the processing device when fault injection is detected;

generating a random number based on at least part of the mixed bit sequence when fault injection is not detected;

generating a word based on at least part of the mixed bit sequence when fault injection is not detected; and

performing a cryptographic operation using at least part of the mixed bit sequence when fault injection is not detected.

26. The non-transitory computer-readable medium of claim 24 wherein the detecting fault injection comprises detecting fault injection when the sampling does not detect the bit pattern in the mixed bit sequence.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 10, 2023
From: STMICROELECTRONICS (ROUSSET) SAS
To: STMICROELECTRONICS INTERNATIONAL N.V.
Reel/Frame 063282/0118 →
Priority Claims (2)
FR 13 55354 · Jun 11, 2013 · national
FR 13 55355 · Jun 11, 2013 · national
Continuity (2)
Continuation 14299943 · Jun 9, 2014
Related Publication 20170124323A1 · May 4, 2017