IP Library Granted Patent US 10,599,847
Granted Patent B2
US 10,599,847 · App. 16/040,763 · Granted Mar 24, 2020

Implementations to facilitate hardware trust and security

Inventors: Lakshminarasimhan Sethumadhavan (Niskayuna, NY); Adam Waksman (Pleasantville, NY)
Assignee: The Trustees of Columbia University in the City of New York
G06F21/57G06F21/87G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,599,847
App. No.
16/040,763
Granted
Mar 24, 2020
Kind
B2
Abstract

Disclosed are devices, systems, apparatus, methods, products, media and other implementations, including a method that includes triggering a beacon circuit combined with a hardware-based protection module, included within a hardware device, the hardware-based protection module configured to provide protection against malicious implementations within the hardware device, with the beacon circuit being configured to provide a beacon output when triggered. The method further includes determining based on the beacon output provided by the triggered beacon circuit whether the hardware device includes at least one malicious implementation.

Claims (40)

1. A method comprising:

triggering a beacon circuit combined with a hardware-based protection module, included within a hardware device, the hardware-based protection module configured to provide protection against malicious implementations within the hardware device, wherein the beacon circuit is configured, upon activation of the beacon circuit with activation input, to provide a beacon output when triggered with triggering input different from the activation input, wherein the beacon output comprises one or more of: an output power profile produced by the beacon circuit, or a digital output; and

determining based on the beacon output provided by the triggered beacon circuit whether the hardware device includes at least one malicious implementation;

wherein the output power profile is produced by a plurality of power producing circuits, each of the plurality of power producing circuits comprising one or more logic gates, wherein the plurality of power producing circuits comprises a plurality of pseudo-random logic blocks, each of depth one, and wherein each of the plurality of pseudo-random logic blocks is tiled next to another of the plurality of pseudo-random logic blocks to form a grid of logic blocks.

2. The method of claim 1 , wherein determining whether the hardware device includes the at least one malicious implementation comprises:

determining if the beacon output provided by the triggered beacon circuit matches a pre-determined beacon output.

3. The method of claim 1 , wherein triggering the beacon circuit comprises:

receiving an input trigger key; and

triggering the beacon circuit in response to a determination that the received input trigger key matches a pre-determined beacon key, K B , associated with the beacon circuit.

4. The method of claim 1 , further comprising:

activating the beacon circuit and the protection module in response to receiving, at the hardware device, a pre-determined activation key K A , the beacon circuit and the hardware-based protection module of the hardware device configured to recognize the pre-determined activation key K A .

5. The method of claim 4 , further comprising:

activating one or more modules of the hardware device in response to receiving, at the hardware device, a pre-determined module activation key K M derived based on the pre-determined activation key K A , wherein the one or more modules of the hardware device are configured to recognize the pre-determined module activation key K M .

6. A system comprising:

a hardware device including a hardware-based protection module, configured to provide protection against malicious implementations within the hardware device, the hardware-based protection module combined with a beacon circuit configured, upon activation of the beacon circuit with activation input, to provide a beacon output when triggered with triggering input different from the activation input, wherein the beacon output comprises one or more of: an output power profile produced by the beacon circuit, or a digital output; and

a controller configured to, when operating, cause operations comprising:

triggering the beacon circuit combined with the hardware-based protection module included within the hardware device; and

determining based on the beacon output provided by the triggered beacon circuit whether the hardware device includes at least one malicious implementation;

wherein the output power profile is produced by a plurality of power producing circuits, each of the plurality of power producing circuits comprising one or more logic gates, wherein the plurality of power producing circuits comprises a plurality of pseudo-random logic blocks, each of depth one, and wherein each of the plurality of pseudo-random logic blocks is tiled next to another of the plurality of pseudo-random logic blocks to form a grid of logic blocks.

7. The system of claim 6 , wherein determining whether the hardware device includes the at least one malicious implementation comprises:

determining if the beacon output provided by the triggered beacon circuit matches a pre-determined beacon output.

8. The system of claim 6 , wherein the controller is further configured, when operating, to cause further operations comprising:

transmitting a pre-determined activation key K A ;

the beacon circuit and the protection module are configured to be activated in response to receiving and recognizing, at the hardware device, the pre-determined activation key K A .

9. The system of claim 8 , wherein the one or more modules of the hardware device are configured to be activated in response to receiving and recognizing, at the hardware device, a pre-determined module activation key K M derived based on the pre-determined activation key K A .

10. The system of claim 6 , further comprising:

measurement apparatus to measure the beacon output provided by the triggered beacon circuit, the measurement apparatus comprising one or more of: a current sensor, a voltage sensor, an infrared sensor, or a probe to detect the digital output.

11. The method comprising:

combining a beacon circuit with a protection module configured to provide protection against malicious implementations within a device, wherein the beacon circuit is configured, upon activation of the beacon circuit with activation input, to provide a beacon output when triggered with triggering input different from the activation input, wherein the beacon output comprises one or more of: an output power profile produced by the beacon circuit, or a digital output; and

producing the beacon circuit combined with the protection module included within the device as a hardware implementation, the hardware implementation configured to enable determination, based on the beacon output produced when the beacon circuit is triggered, whether the hardware implementation includes at least one malicious implementation;

wherein the output power profile is produced by a plurality of power producing circuits, each of the plurality of power producing circuits comprising one or more logic gates, wherein the plurality of power producing circuits comprises a plurality of pseudo-random logic blocks, each of depth one, and wherein each of the plurality of pseudo-random logic blocks is tiled next to another of the plurality of pseudo-random logic blocks to form a grid of logic blocks.

12. The method of claim 11 , wherein producing the beacon circuit combined with the protection module included within the device as the hardware implementation comprises:

producing the hardware implementation such that the protection module and the beacon circuit combined with the protection module are activated when a pre-determined activation key, K A , is provided to the hardware implementation.

13. A hardware device comprising:

one or more modules to perform pre-specified operations;

one or more protection modules configured to provide protection against potential malicious implementations within the hardware device; and

one or more beacon circuits combined with the one or more protection modules, each of the one or more beacon circuits configured, upon activation of the one or more beacon circuits with at least one activation input, to provide respective one or more beacon outputs when triggered with at least one triggering input different from the at least one activation input, to facilitate determination of whether the hardware device includes at least one malicious implementation, wherein each of the respective one or more beacon outputs comprises one or more of: an output power profile produced by the beacon circuit, or a digital output, wherein the output power profile is produced by a plurality of power producing circuits, each of the plurality of power producing circuits comprising one or more logic gates, wherein the plurality of power producing circuits comprises a plurality of pseudo-random logic blocks, each of depth one, and wherein each of the plurality of pseudo-random logic blocks is tiled next to another of the plurality of pseudo-random logic blocks to form a grid of logic blocks.

14. The hardware device of claim 13 , wherein the one or more beacon circuits and the one or more protection modules are configured to be activated in response to receiving, at the hardware device, at least one pre-determined activation key K A , associated with the hardware device.

15. The hardware device of claim 14 , wherein the each of the one or more beacon circuits is configured to be triggered subsequent to activation of the each of the one or more beacon circuits and the one or more hardware-based protection modules with the at least one pre-determined activation key K A .

16. The hardware device system of claim 14 , wherein the one or more modules of the hardware device is configured to be activated in response to receiving, at the hardware device, at least one pre-determined module activation key K M derived based on the at least one pre-determined activation key K A .

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 7, 2020
From: WAKSMAN, ADAM; SETHUMADHAVAN, LAKSHMINARASIMHAN
To: THE TRUSTEES OF COLUMBIA UNIVERSITY IN THE CITY OF NEW YORK
Reel/Frame 051754/0962 →
CONFIRMATORY LICENSE Recorded Feb 20, 2019
From: COLUMBIA UNIVERSITY
To: NATIONAL SCIENCE FOUNDATION
Reel/Frame 048379/0211 →
Continuity (3)
Continuation 15105087
Provisional Application 61920384 · Dec 23, 2013
Related Publication 20190213331A1 · Jul 11, 2019