IP Library › Granted Patent US 12,743,520
Granted Patent B2
US 12,743,520 · App. 18/711,181 · Granted Sep 22, 2026

Method for detecting anomalies suggesting a manipulation during a secure starting operation of a software-controlled device

Inventors: Marc Sebastian Patric Stöttinger (Oestrich-Winkel, DE); Steffen Sanwald (Darmstadt, DE)
Assignee: AUMOVIO Germany GmbH
G06F21/575G06F21/566G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,743,520
App. No.
18/711,181
Granted
Sep 22, 2026
Kind
B2
Abstract

A method for recognizing anomalies suggesting a manipulation during a secure booting operation of a software-controlled device comprises, inter alia, checking operating parameters of system components necessary for the operation of a microprocessor, checking a flag indicating an improperly concluded booting operation, and signature-based authenticity checking of software to be loaded or software components to be loaded. In the case of multistage booting operations, counter values assigned to a respective stage are compared with associated reference values. In the event of a fault, each check can output a signal on the basis of which, optionally together with further signals, the type of an attack can be recognized, so that specific countermeasures can be initiated.

Claims (38)

1 . A method for recognizing a type of an attack on a secure booting operation of a microprocessor-controlled device, comprising:

reading out at least one operating parameter from at least one system component necessary for an operation of the microprocessor, and comparing the at least one operating parameter read out with corresponding stored reference values, wherein, if the comparison shows a difference, a first signal, which signals a recognized side channel attack and a failed booting operation, is output and the method is ended and the further booting operation is terminated,

checking a state of a flag that is set during an as yet unsuccessfully concluded booting operation, wherein, if the flag is set, a second signal, which signals a recognized fault injection attack and a failed booting operation, is output and the method is ended and the further booting operation is terminated, wherein, if the flag is not set, the flag is set after the check,

calculating a hash value or a checksum over at least one block of a software or software component, and comparing with a hash value or checksum stored for a same at least one block of the software or software component during a preceding booting operation, or calculating an authentication code of software to be loaded or a software component to be loaded, and comparing the calculated authentication code with the authentication code of the preceding booting operation read out from a memory, wherein, if the comparison shows a difference, a third signal, which signals a recognized attack and a failed booting operation, is output and the method is ended and the further booting operation is terminated,

calculating, if not already done previously, an authentication code of software to be loaded or a software component to be loaded, and comparing the calculated authentication code with a reference code read out from a memory, wherein, if the comparison shows a difference, a fourth signal, which signals a recognized fault injection attack and a failed booting operation, is output and the method is ended and the further booting operation is terminated,

replacing the authentication code of the preceding booting operation read out from the memory with the authentication code calculated for the current booting operation, and deleting the flag that is set during an as yet unsuccessfully concluded booting operation.

2 . The method as claimed in claim 1 , additionally comprising, if the booting operation is of multistage design:

comparing a current stage of a multistage booting operation with a reference value assigned to this stage, wherein, if the comparison shows a difference, a fifth signal, which signals a recognized fault injection attack and a failed booting operation, is output and the method is ended and the further booting operation is terminated, and wherein otherwise the execution of the booting operation and the loading of subsequent stages are continued until a last stage of the booting operation indicated by the corresponding reference value has been loaded.

3 . The method as claimed in claim 1 , additionally comprising:

storing unique time information at a beginning and/or after successful conclusion of the booting operation,

comparing, for each new booting operation, present time information with a time information stored during a previous booting operation, wherein, if the comparison shows a difference which is less than a predefined value, a sixth signal, which signals a recognized attack and a failed booting operation, is output and the method is ended and the further booting operation is terminated.

4 . The method as claimed in claim 1 , additionally comprising:

storing unique time information at a beginning and/or after successful conclusion of the booting operation,

comparing, for each new booting operation, a number of preceding rebooting operations within a predefined time with a permissible maximum value, wherein, if the number of preceding rebooting operations is above the permissible maximum value, a sixth signal, which signals a recognized attack and a failed booting operation, is output and the method is ended and the further booting operation is terminated.

5 . The method as claimed in claim 4 , wherein the beginning and/or the successful conclusion of a booting operation are/is ascertained on a basis of a power consumption that is typical of these events.

6 . The method as claimed in claim 4 , wherein the beginning of a booting operation is determined on a basis of a reset signal output by a microprocessor.

7 . The method as claimed in claim 4 , additionally comprising:

monitoring the allocation of at least one system resource of a first device during the booting operation, and

comparing a number of allocations of a same system resource to a same process within a predetermined second time period with a maximum value predefined for this system resource, wherein, if the number of allocations of the same system resource to the same process exceeds the predefined maximum value, a seventh signal, which signals a recognized attack and a failed booting operation, is output and the method is ended and the further booting operation is terminated.

8 . A device comprising at least one processor, volatile and nonvolatile memory and at least one further system component necessary for the operation of the microprocessor, which are communicatively connected to one another via one or more data lines or one or more data buses, wherein computer program instructions are retrievably stored in the nonvolatile memory and, when the instructions are executed by the at least one processor, configure the device to carry out a method comprising:

reading out at least one operating parameter from at least one system component necessary for an operation of the microprocessor, and comparing the at least one operating parameter read out with corresponding stored reference values, wherein, if the comparison shows a difference, a first signal, which signals a recognized side channel attack and a failed booting operation, is output and the method is ended and the further booting operation is terminated,

checking a state of a flag that is set during an as yet unsuccessfully concluded booting operation, wherein, if the flag is set, a second signal, which signals a recognized fault injection attack and a failed booting operation, is output and the method is ended and the further booting operation is terminated, wherein, if the flag is not set, the flag is set after the check,

calculating a hash value or a checksum over at least one block of a software or software component, and comparing with a hash value or checksum stored for a same at least one block of the software or software component during a preceding booting operation, or calculating an authentication code of software to be loaded or a software component to be loaded, and comparing the calculated authentication code with the authentication code of the preceding booting operation read out from a memory, wherein, if the comparison shows a difference, a third signal, which signals a recognized attack and a failed booting operation, is output and the method is ended and the further booting operation is terminated,

calculating, if not already done previously, an authentication code of software to be loaded or a software component to be loaded, and comparing the calculated authentication code with a reference code read out from a memory, wherein, if the comparison shows a difference, a fourth signal, which signals a recognized fault injection attack and a failed booting operation, is output and the method is ended and the further booting operation is terminated,

replacing the authentication code of the preceding booting operation read out from the memory with the authentication code calculated for the current booting operation, and deleting the flag that is set during an as yet unsuccessfully concluded booting operation.

9 . The device of claim 8 , wherein the method further comprises:

comparing a current stage of a multistage booting operation with a reference value assigned to this stage, wherein, if the comparison shows a difference, a fifth signal, which signals a recognized fault injection attack and a failed booting operation, is output and the method is ended and the further booting operation is terminated, and wherein otherwise the execution of the booting operation and the loading of subsequent stages are continued until a last stage of the booting operation indicated by the corresponding reference value has been loaded.

10 . The device of claim 8 , wherein the method further comprises:

storing unique time information at a beginning and/or after successful conclusion of the booting operation,

comparing, for each new booting operation, present time information with a time information stored during a previous booting operation, wherein, if the comparison shows a difference which is less than a predefined value, a sixth signal, which signals a recognized attack and a failed booting operation, is output and the method is ended and the further booting operation is terminated.

11 . The device of claim 8 , wherein the method further comprises:

storing unique time information at a beginning and/or after successful conclusion of the booting operation,

comparing, for each new booting operation, a number of preceding rebooting operations within a predefined time with a permissible maximum value, wherein, if the number of preceding rebooting operations is above the permissible maximum value, a sixth signal, which signals a recognized attack and a failed booting operation, is output and the method is ended and the further booting operation is terminated.

12 . The device of claim 11 , wherein the beginning and/or the successful conclusion of a booting operation are/is ascertained on a basis of a power consumption that is typical of these events.

13 . The device of claim 11 , wherein the beginning of a booting operation is determined on a basis of a reset signal output by a microprocessor.

14 . The device of claim 11 , wherein the method further comprises:

monitoring the allocation of at least one system resource of a first device during the booting operation, and

comparing a number of allocations of a same system resource to a same process within a predetermined second time period with a maximum value predefined for this system resource, wherein, if the number of allocations of the same system resource to the same process exceeds the predefined maximum value, a seventh signal, which signals a recognized attack and a failed booting operation, is output and the method is ended and the further booting operation is terminated.

Assignments (2)
CHANGE OF NAME Recorded Aug 3, 2026
From: CONTINENTAL AUTOMOTIVE TECHNOLOGIES GMBH
To: AUMOVIO GERMANY GMBH
Reel/Frame 076110/0789 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 21, 2024
From: STÖTTINGER, MARC SEBASTIAN PATRIC
To: CONTINENTAL AUTOMOTIVE TECHNOLOGIES GMBH
Reel/Frame 067472/0511 →
Priority Claims (1)
DE 10 2021 212 994.3 · Nov 18, 2021 · national
Continuity (1)
Related Publication 20250013752A1 · Jan 9, 2025
References Cited (25)
US 9165143B1 · Sanders · 2015 [cited by applicant]
US 9740863B2 · Sherman · 2017 [cited by applicant]
US 9773115B2 · Jacobs · 2017 [cited by examiner]
US 11487872B2 · McDonough · 2022 [cited by examiner]
US 20120210115A1 · Park · 2012 [cited by examiner]
US 20140215196A1 · Berlin · 2014 [cited by examiner]
US 20160357963A1 · Sherman · 2016 [cited by applicant]
US 20200193028A1 · Norem et al. · 2020 [cited by applicant]
DE 102009000874A1 · 2010 [cited by applicant]
DE 102019008059A1 · 2020 [cited by applicant]
DE 102019127856A1 · 2021 [cited by applicant]
JP 2004206683A · 2004 [cited by applicant]
JP 2018503157A · 2018 [cited by applicant]
JP 2020091698A · 2020 [cited by applicant]
JP 2021505097A · 2021 [cited by applicant]
WO 2020209714A1 · 2020 [cited by applicant]
WO 2020251542A1 · 2020 [cited by applicant]
Search dated Mar. 31, 2025 from corresponding Japanese patent application No. 2024-529707. [cited by applicant]
Notice of Reasons for Refusal dispatched on Apr. 1, 2025 from corresponding Japanese patent application No. 2024-529707. [cited by applicant]
Decision to Grant issued on May 27, 2025 from corresponding Japanese patent application No. 2024-529707. [cited by applicant]
German Office Action dated Oct. 22, 2022 for the priority German Patent Application No. 10 2021 212 994.3 and machine translation of same. [cited by applicant]
The International Search Report and the Written Opinion of the International Searching Authority mailed on Feb. 7, 2023 for the PCT Application No. PCT/DE2022/200269 which this application claims priority. [cited by applicant]
German Notice of Allowance dated Nov. 1, 1023 for the priority German Patent Application No. 10 2021 212 994.3 and machine translation of same. [cited by applicant]
Niek Timmers et al., “Bypassing Secure Boot using Fault Injection”, Black Hat Europe 2016, Nov. 4, 2016. [cited by applicant]
Job De Haas, “20 ways past secure boot”, Riscure, 2013. [cited by applicant]