Systems, methods, and apparatuses for intrusion detection and analytics using power characteristics such as side-channel information collection
First Claim
1. An apparatus, comprising:
- a power management circuit configured to be operatively coupled to a processor, the power management circuit configured to send to the processor a first power signal and a second power signal that is generated by varying the first power signal based on a regulatory function of the power management circuit, the regulatory function of the power management circuit including a set of policies to regulate the first power signal within operating parameters of the power management circuit;
a sensor in communication with or included within at least one of the power management circuit or the processor, the sensor configured to detect a first side-channel information of the processor based on the first power signal and a second side-channel information of the processor that is based on the second power signal; and
a notification circuit in communication with the sensor, the notification circuit configured to send a notification signal indicative of an anomaly of the processor when the anomaly of the processor is detected based on at least one of the first side-channel information or the second side-channel information.
1 Assignment
0 Petitions
Accused Products
Abstract
Some embodiments described herein include a system that collects and learns reference side-channel normal activity, process it to reveal key features, compares subsequent collected data and processed data for anomalous behavior, and reports such behavior to a management center where this information is displayed and predefine actions can be executed when anomalous behavior is observed. In some instances, a physical side channel (e.g. and indirect measure of program execution such as power consumption or electromagnetic emissions and other physical signals) can be used to assess the execution status in a processor or digital circuit using an external monitor and detect, with extreme accuracy, when an unauthorized execution has managed to disrupt the normal operation of a target system (e.g., a computer system, etc.).
84 Citations
21 Claims
-
1. An apparatus, comprising:
-
a power management circuit configured to be operatively coupled to a processor, the power management circuit configured to send to the processor a first power signal and a second power signal that is generated by varying the first power signal based on a regulatory function of the power management circuit, the regulatory function of the power management circuit including a set of policies to regulate the first power signal within operating parameters of the power management circuit; a sensor in communication with or included within at least one of the power management circuit or the processor, the sensor configured to detect a first side-channel information of the processor based on the first power signal and a second side-channel information of the processor that is based on the second power signal; and a notification circuit in communication with the sensor, the notification circuit configured to send a notification signal indicative of an anomaly of the processor when the anomaly of the processor is detected based on at least one of the first side-channel information or the second side-channel information. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13)
-
-
14. A method, comprising:
-
sending, from a power management circuit to a processor, a first power signal and a second power signal that is generated by varying the first power signal based on a regulatory function of the power management circuit, the regulatory function of the power management circuit including a set of policies to regulate the first power signal within operating parameters of the power management circuit; receiving a first side-channel information of the processor based on the first power signal and a second side-channel information of the processor that is based on the second power signal; and sending a notification signal indicative of an anomaly of the processor when the anomaly of the processor is detected based on at least one of the first side-channel information or the second side-channel information. - View Dependent Claims (15, 16, 17, 18, 19, 20)
-
-
21. An apparatus, comprising:
-
a power management circuit configured to be operatively coupled to a processor and adjust a level of power provided to the processor, the power management circuit configured to send to the processor a first power signal and a second power signal that is generated by varying the first power signal and based on a regulatory function of the power management circuit, the regulatory function of the power management circuit including a set of policies to regulate the first power signal within operating parameters of the power management circuit, the power management circuit in communication with a sensor configured to detect a first side-channel information of the processor based on the first power signal and a second side-channel information of the processor that is based on the second power signal; and a notification circuit in communication with the sensor, the notification circuit configured to send a notification signal indicative of an anomaly of the processor when the anomaly of the processor is detected based on at least one of the first side-channel information or the second side-channel information.
-
Specification