IP Library Granted Patent US 12,585,763
Granted Patent B2
US 12,585,763 · App. 18/166,706 · Granted Mar 24, 2026

Detecting and responding to environmental condition-induced security attacks on semiconductor packages

Inventors: Theodore F. Emerson (Spring, TX); Christopher M. Wesneski (The Colony, TX); Daniel J. Zink (Spring, TX)
Assignee: Hewlett Packard Enterprise Development LP
G06F21/554G06F21/572G06F21/575G06F21/577G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,585,763
App. No.
18/166,706
Filed
Feb 9, 2023
Granted
Mar 24, 2026
Kind
B2
Examiner
SONG, HEE K
Art Unit
2497
USPC
726/23
Abstract

A process incudes generating, by a canary circuit of a semiconductor package, an output value. The semiconductor package includes a hardware root-of-trust engine for an electronic system. The process includes comparing, by the canary circuit, the output value to an expected value. The process incudes, responsive to a result of the comparison, regulating, by the semiconductor package, a response of the electronic system to a reset request.

Claims (74)

1 . A method comprising:

generating, by a canary circuit of a semiconductor package, an output value, wherein the semiconductor package comprises a hardware root-of-trust engine for an electronic system;

comparing, by the canary circuit, the output value to an expected value;

receiving, by the electronic system, a reset request directed to placing a component of the electronic system in a reset state; and

responsive to a result of the comparison, regulating, by the semiconductor package, a response of the electronic system to the reset request.

2 . The method of claim 1 , wherein generating the output value comprises:

providing an input to a chain of serially-coupled stages to cause the chain to provide the output value, wherein each stage of the chain is associated with a cryptographic transform.

3 . The method of claim 1 , wherein generating the output comprises:

providing an input to a chain of serially-coupled Advanced Encryption Standard (AES) block cipher transform stages or a chain of serially-coupled Secure Hash Algorithm-3 (SHA-3) block cipher transform stages to cause the chain to provide the output value.

4 . The method of claim 1 , further comprising providing a clock signal to a processing core of the semiconductor package,

wherein:

the clock signal has a clock period; and

generating the output value comprises performing the generation within a time less than the clock period.

5 . The method of claim 1 , wherein generating the output comprises:

providing an input to logic of the canary circuit;

using the logic to generate the output for each cycle of a plurality of cycles of a clock signal;

varying the input over the plurality of cycles; and

varying the expected value over the plurality of cycles corresponding to the variation of the input.

6 . The method of claim 1 , further comprising:

responsive to the reset request, placing the hardware root-of-trust engine in a reset,

wherein regulating the response of the semiconductor package to the reset signal comprises regulating a delay between a first time that the hardware root-of-trust engine is placed in the reset and a second time that the hardware root-of-trust engine is released from the reset.

7 . The method of claim 1 , wherein generating the output value comprises:

providing an input to logic gates of the canary circuit, wherein the logic gates of the canary circuit are spatially commingled with logic gates of the hardware root-of-trust engine; and

using the logic gates of the canary circuit to generate the output.

8 . The method of claim 1 , wherein generating the output value comprises:

providing an input to logic gates of the canary circuit, wherein the logic gates of the canary circuit are spatially commingled with logic gates of a security processing core of the semiconductor package; and

using the logic gates of the canary circuit to generate the output.

9 . The method of claim 1 , further comprising:

a processing core of a security processor of the semiconductor package executing machine-readable instructions to provide a security service for the electronic system; and

the canary circuit malfunctioning due to an environmental condition-based security attack on the semiconductor package, wherein the malfunctioning comprises the comparing providing a result representing that the output value does not correspond to the expected value,

wherein regulating the response of the semiconductor package to the reset signal comprises increasing a reset hold time for the semiconductor package responsive to the result.

10 . A baseboard management controller comprising:

a management processor; and

a secure enclave separate from the management processor, wherein the secure enclave has an associated cryptographic boundary and comprises:

a security processing core;

a root-of-trust engine to validate machine-readable instructions to be executed by the security processing core, wherein the root-of-trust engine comprises a first plurality of logic gates;

a canary circuit comprising a second plurality of logic gates spatially commingled with the first plurality of logic gates, wherein the canary circuit to detect tampering with the secure enclave, wherein detection of the tampering comprises generating, by the canary circuit, an output value and comparing, by the canary circuit, the output value to an expected value to provide a tampering indication; and

a controller to perform a responsive action in response to the tampering indication.

11 . The baseboard management controller of claim 10 , wherein the controller comprises a reset governor, and the reset governor to regulate a reset hold time of the secure enclave responsive to the tampering indication.

12 . The baseboard management controller of claim 11 , wherein the security processing core comprises a third plurality of logic gates, the baseboard management further comprising:

an additional canary circuit comprising a fourth plurality of logic gates, wherein the fourth plurality of logic gates are spatially commingled with the third plurality of logic gates, and the fourth plurality of logic gates to generate an additional output value and compare the additional output value to another expected value to provide a tampering indication,

wherein the controller to perform a corrective action responsive to the tampering indication provided by the additional canary circuit.

13 . The baseboard management controller of claim 11 , wherein:

the security processing core comprises a semiconductor die having an associated first dimension corresponding to a first axis and an associated second dimension corresponding to a second axis, wherein the second axis is orthogonal to the first axis;

the logic gates of the first plurality are commingled along a first path parallel to the first axis; and

the logic gates of the second plurality are commingled along a second path parallel to the second axis.

14 . The baseboard management controller of claim 13 , wherein the semiconductor die is associated with a third axis, the third axis is orthogonal to the first axis, the third axis is orthogonal to the second axis, and the third axis corresponds to a thickness dimension of the semiconductor die.

15 . A computer platform comprising:

a main processing core; and

a security processor comprising:

a security processing core;

a root-of-trust engine, wherein the root-of-trust engine comprises a first plurality of logic gates to validate a first firmware instruction portion to be executed by the security processing core, the first firmware instruction portion is part of a chain of trust, and the chain of trust includes a second firmware instruction portion to be executed by the main processing core; and

a canary circuit comprising a second plurality of logic gates to generate an output value and compare the output value to an expected value to provide a tampering indication, wherein logic gates of the second plurality of logic gates are spatially commingled with logic gates of the first plurality of logic gates; and

a reset governor to regulate a reset hold time of the security processor responsive to the tampering indication.

16 . The computer platform of claim 15 , wherein the root-of-trust engine comprises a reset input, and the reset governor to further:

receive a reset request;

responsive to the reset request, provide a signal to the reset input to place the root-of-trust engine in reset; and

responsive to the tampering indication, relative the reset hold time to regulate a time that the root-of-trust engine is held in the reset before being released from the reset.

17 . The computer platform of claim 15 , wherein the canary circuit comprises:

a chain of serially-coupled cryptographic processing stages, wherein the chain to receive an input and provide the output value responsive to the input vector.

18 . The computer platform of claim 17 , wherein the canary circuit to generate the output for each cycle of a clock signal, and the canary circuit further comprises:

a controller to vary the input on alternate cycles of the clock signal.

19 . The computer platform of claim 17 , wherein each stage comprises logic to perform an Advanced Encryption Standard (AES) cipher block transformation or perform a Secure Hash Algorithm-3 (SHA-3) block cipher transformation.

20 . The computer platform of claim 16 , wherein the main processing core to provide a host instance, and the computer platform further comprising a management controller to provide a management service for the host instance, wherein the management controller comprises the security processor.

21 . The method of claim 1 , further comprising:

placing the component in the reset state; and

releasing the component from the reset state,

wherein regulating the response of the electronic system to the reset request comprises regulating a release of the component from the reset state.

22 . The baseboard management controller of claim 10 , wherein:

the root-of-trust engine is placed in a reset; and

the controller to further, responsive to the tampering indication, regulate a delay between a first time that the root-of-trust engine is placed in the reset and a second time that the root-of-trust engine is released from the reset.

23 . The computer platform of claim 15 , wherein:

the security processor is placed in a reset; and

the reset governor to further regulate a delay between a first time that the security processor is placed in the reset and a second time that the security processor is released from the reset.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 9, 2023
From: EMERSON, THEODORE F.; WESNESKI, CHRISTOPHER M.; ZINK, DANIEL J.
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 062642/0336 →
Continuity (2)
Provisional Application 63412005 · Sep 30, 2022
Related Publication 20240111862A1 · Apr 4, 2024
References Cited (26)
US 9298947B2 · Dent et al. · 2016 [cited by applicant]
US 9459314B1 · Chang · 2016 [cited by applicant]
US 10466275B1 · Vundavalli · 2019 [cited by examiner]
US 10523418B2 · Hamburg et al. · 2019 [cited by applicant]
US 10671763B2 · Patki · 2020 [cited by applicant]
US 10785122B2 · Inamdar et al. · 2020 [cited by applicant]
US 10977379B1 · Williams et al. · 2021 [cited by applicant]
US 11212119B2 · Bhandari et al. · 2021 [cited by applicant]
US 11256807B2 · Sun et al. · 2022 [cited by applicant]
US 20120131673A1 · Caci · 2012 [cited by examiner]
US 20170085368A1 · Saab · 2017 [cited by examiner]
US 20180260564A1 · Porteboeuf · 2018 [cited by applicant]
US 20190318094A1 · Sun et al. · 2019 [cited by applicant]
US 20200322145A1 · Sheth et al. · 2020 [cited by applicant]
US 20200322176A1 · Bhandari et al. · 2020 [cited by applicant]
US 20210182729A1 · George et al. · 2021 [cited by applicant]
US 20220006459A1 · Bautista Gabriel · 2022 [cited by examiner]
US 20220292228A1 · Johnson · 2022 [cited by examiner]
US 20230198754A1 · Wu · 2023 [cited by examiner]
US 20240111350A1 · Herberholz · 2024 [cited by examiner]
US 20240111909A1 · Emerson · 2024 [cited by examiner]
WO WO2020086087 · 2020 [cited by applicant]
Chen et al., “VoltPillager: Hardware-based fault injection attacks against Intel SGX Enclaves using the SVID voltage scaling interface”, 30th USENIX Security Symposium, Aug. 11-13, 2021, 19 pages. [cited by applicant]
Colin O'Flynn, “Fault Injection using Crowbars on Embedded Systems”, IACR Cryptol, 2016, 12 pages. [cited by applicant]
Platform Security Architecture Security Model 1.0; psacertified; Document No. DEN 0079; Release No. 3; Date of issue: Feb. 25, 2020; 32 pp. [cited by applicant]
Buhren, Robert; “One Glitch to Rule Them All: Fault Injection Attacks Against AMD's Secure Encrypted Visualization”; Technische Universitat Berline—SECT; arXiv:2108.04575v4 [cs.CR]; Aug. 26, 2021; 15 pp. [cited by applicant]