TL;DR: Reboot-Oriented IoT (RO-IoT), which updates the total OS image autonomously to recover from compromise (rootkit or otherwise), and manages the life cycle of the device using Trusted Execution Environment (TEE) and PKI-based certificates (i.e., CA, server, and client certificates which are linked to device, software, and service).
Abstract: Many IoT devices are geographically distributed without human administrators, which are maintained by a remote server to enforce security updates, ideally through machine-to-machine (M2M) management. However, malware often terminates the remote control mechanism immediately after compromise and hijacks the device completely. The compromised device has no way to recover and becomes part of a botnet. Even if the IoT device remains uncompromised, it is required to update due to recall or other reasons. In addition, the device is desired to be automatically disposable after the expiration of its service, software, or device hardware to prevent being cyber debris. We present Reboot-Oriented IoT (RO-IoT), which updates the total OS image autonomously to recover from compromise (rootkit or otherwise), and manages the life cycle of the device using Trusted Execution Environment (TEE) and PKI-based certificates (i.e., CA, server, and client certificates which are linked to device, software, and service). RO-IoT is composed of three TEE-protected components: the secure network bootloader, periodic memory forensics, and life cycle management. The secure network bootloader downloads and verifies the OS image by the TEE. The periodic memory forensics causes a hardware system-reset (i.e., reboot) after detecting any un-registered binary or a time-out, which depends on a TEE-protected watchdog timer. The life cycle management checks the expiration of PKI-based certificates for the device, software, and service, and deactivates the device if necessary. These features complement each other, and all binaries and certificates are encrypted or protected by TEE. We implemented a prototype of RO-IoT on an ARM Hikey board with the open source trusted OS OP-TEE. The design and implementation take account of availability (over 99.9%) and scalability (less than 100MB traffic for a full OS update, and estimated at a cent per device), making the current prototype specifically suitable for the AI-Edge (Artificial Intelligence on the Edge) IoT devices.
TL;DR: This paper presents some of the challenges in the existing methodology for RDC analysis and proposes a new methodology to reduce RDC results noisiness and achieve more accurate results that leads to faster verification closure.
Abstract: Reset architecture of a digital design can be quite complex. Typically, SoC designs have multiple sources of reset, such as power-on reset, hardware resets, debug resets, software resets, and watchdog timer reset. These multiple reset domains make the design potentially exposed to metastability issues, so the designer must perform the reset domain crossing (RDC) analysis and resolve any RDC issues in the early stages of designing. This can quite be challenging, because of the effort needed for this analysis and how noisy it can be. In this paper, we present some of the challenges in the existing methodology for RDC analysis and propose a new methodology to reduce RDC results noisiness and achieve more accurate results. This leads to faster verification closure. The results are concluded by applying the proposed methodology on a set of real designs.
TL;DR: In this article, the automatic diagnostic mode iteratively isolates subsystems of the system in coordination with a baseboard management controller to identify a potential cause of a boot problem of a system.
Abstract: Example implementations relate to automatic diagnostic mode to identify a potential cause of a boot problem of a system. In an example, the automatic diagnostic mode iteratively isolates subsystems of the system in coordination with a baseboard management controller. For each iteration of subsystem isolation, a system boot is executed while a subsystem is isolated. The system boot is monitored against a watchdog timer of the baseboard management controller to determine if the system boot is successful. If the system boot is successful, the isolated subsystem is marked as a potential cause of the boot problem of the system. If the system boot is unsuccessful, the automatic diagnostic mode continues to iteratively isolate the subsystems.
TL;DR: In this article, a drone with proximity sensors which comprises of an infrared emitter and an infrared detector was used to detect and recover from computer malfunctions or program errors, and the watchdog timer was used for corrective action for the drone to avoid one or more obstacles.
Abstract: In this invention we have a drone with proximity sensors which comprises of an infrared emitter and an infrared detector, wherein the proximity sensor is configured to emit infrared light using the infrared emitter and sense reflected light having specific properties using the infrared detector to determine proximity of the sensor to an object or obstacle in air Also here we have a watchdog timer which is an electronic timer that is used to detect and recover from computer malfunctions or program errors On detecting the obstacle in air, the drone, due to a program error state, will not reset the watchdog timer, and the watchdog timer will elapse and generate a timeout signal The timeout signal is used to initiate corrective action for the drone to avoid one or more obstacles
TL;DR: In this article, a method for processing data is provided that includes starting a processor from an off state and loading watchdog timer handler code into a processor memory, and determining whether a catastrophic error has occurred during execution of the watchdog timers handler code.
Abstract: A method for processing data is provided that includes starting a processor from an off state and loading watchdog timer handler code into a processor memory. Executing the watchdog timer handler code and determining whether a catastrophic error has occurred during execution of the watchdog timer handler code. Invoking a system management module to update error code if it is determined that the catastrophic error has occurred and invoking a first phase dispatcher to set up a first stack frame associated with a first phase if it is determined that a catastrophic error has not occurred.
TL;DR: In this article, a watchdog timer is used to detect and recover from computer malfunctions, such as a hardware failure or program error, and a timeout signal is generated to initiate corrective actions.
Abstract: In this invention we signal the drone to start to descend for landing when there is a program error or a hardware fault. Here we use a watchdog timer which is an electronic timer to detect and recover from computer malfunctions. During normal operation, the computing system of the drone regularly resets the watchdog timer to prevent it from elapsing. If, due to a hardware fault or program error, the computing system fails to reset the watchdog, the timer will elapse and generate a timeout signal. The timeout signal is used to initiate corrective actions. The corrective actions here would include transitioning the drone into a state to begin descend for landing and triggering control actions for the same using a dedicated control unit for it. Also here we can use a proactive approach where different hardware sensors part of the drone predict component hardware failure beforehand or an error condition is passed to the computing system of the drone from a remote centralised controller system about a hardware or software failure, due to which the computing system of the drone will fail to reset the watchdog timer and a timeout signal will be generated to trigger descend of the drone for landing purposes.
TL;DR: In this article, a method for establishing and maintaining a security policy for a device can include establishing a secure channel between a secure execution environment (SEE) operating on the device and a security entity external to the device.
Abstract: A method for establishing and maintaining a security policy for a device can include establishing a secure channel between a secure execution environment (SEE) operating on the device and a security entity external to the device. The method can also include configuring, by a security manager executing on the SEE, access to sensitive operations of an environment interactor coupled to the device based on a security policy provided from the security entity. The method can further include resetting, by the security manager, a secure watchdog timer in response to a reset authorization token provided from the secure entity. If the secure watchdog timer expires a given predetermined number of times since a last reset authorization token is received, the security manager executes a given prescriptive operation dictated by the security policy.
TL;DR: In this paper, a multi-logic device system, an electronic engine controller, and a method of operating the multilog device system is presented. But the primary logic device is configured to run, for each secondary logic device, a respective watchdog timer, which is restarted upon receipt of a restart signal from the respective secondary logic devices.
Abstract: A multi-logic device system, an electronic engine controller, and a method of operating the multi-logic device system. The multi-logic device system includes a primary logic device which is more resilient to single event effects, and one or more secondary logic devices, each secondary logic device being powered by a respective power supply unit and being more susceptible to single event effects. The primary logic device is configured to run, for each secondary logic device, a respective watchdog timer. Each watchdog timer is restarted upon receipt of a restart signal from the respective secondary logic device. The primary logic device is also configured, in response to a watchdog timer timing out, to identify and reset the secondary logic device corresponding to the timed out watchdog timer.
TL;DR: In this paper, an electronic control device that can perform fault diagnosis on a watchdog circuit without delaying the start of the normal processes of a computer is presented. But this device cannot be used to diagnose faults in the watchdog circuit.
Abstract: Provided is an electronic control device that can perform fault diagnosis on a watchdog circuit without delaying the start of the normal processes of a computer. A microcomputer termination processing unit 200 stops the output of a pulse to a watchdog timer circuit 101 in response to the implementation of a termination process of a microcomputer 100. A watchdog timer circuit fault diagnosis unit 201 writes anomaly information, which indicates that an anomaly has occurred in the watchdog timer circuit 101, to non-volatile memory 102 if a reset signal is not output from the watchdog timer circuit 101 even after a prescribed amount of time has passed after the output of the pulse being stopped.
TL;DR: In this paper, a method of performing a built-in test on a watchdog circuit including a watchdog timer is described, where the watchdog counters are reset when the watchdog counter expires by providing a signal to a reset input of the processor.
Abstract: A method of performing a built in test on a watchdog circuit including a watchdog timer includes: initiating the built in test with a processor being monitored by the watchdog circuit, wherein initiating includes enabling a watchdog circuit built in test reset inhibit circuit (WD BIT reset inhibit circuit) connected between an output of an active watchdog integrated reset circuit connected to the processor and a reset input of the processor; and ceasing to provide a strobe signal to the active watchdog integrated reset circuit that resets a watchdog counter in the active watchdog integrated reset circuit, the active watchdog integrated reset circuit causing a reset of the processor via its output when the watchdog counter expires by providing a signal to a reset input of the processor.
TL;DR: In this article, a power supply circuit consisting of a watchdog timer which is an electronic timer to detect and recover from computer malfunctions is presented, and the watchdog timer is used to switch on the standby or backup power supply for the rack.
Abstract: In this invention we have a power supply circuit consisting of a watchdog timer which is an electronic timer to detect and recover from computer malfunctions During normal operation the power supply circuit for the rack regularly resets the watchdog timer to prevent it from elapsing or timing out If due to hardware fault or power supply failure, the power supply circuit fails to reset the watchdog timer, then the watchdog timer will elapse and generate a timeout signal The timeout signal is used to switch on the standby or backup power supply for the rack
TL;DR: In this article, a watchdog timer which is an electronic timer that is used to detect and recover from computer malfunctions is introduced. But the watchdog timer is only used for detecting and recovering from computer failures.
Abstract: In this invention we have a watchdog timer which is an electronic timer that is used to detect and recover from computer malfunctions. During normal operation, the computer regularly resets the watchdog timer to prevent it from elapsing, or timing out. If due to a program error it times out, a time out signal is triggered which is used to take corrective actions. Here we have the hypervisor or virtual machine monitor which monitors the health check responses, system state, etc. of the virtual machine and if it detects an error it does not reset the watchdog timer associated specifically for that virtual machine. The time out signal generated by that watchdog timer is used to reset the virtual machine and data verification is performed after boot up sequence of the virtual machine with another up to date backup of the virtual machine to check for data corruption.
TL;DR: In this paper, the automatic diagnostic mode iteratively isolates subsystems of the system in coordination with a baseboard management controller to identify a potential cause of a boot problem of a system.
Abstract: Example implementations relate to automatic diagnostic mode to identify a potential cause of a boot problem of a system. In an example, the automatic diagnostic mode iteratively isolates subsystems of the system in coordination with a baseboard management controller. For each iteration of subsystem isolation, a system boot is executed while a subsystem is isolated. The system boot is monitored against a watchdog timer of the baseboard management controller to determine if the system boot is successful. If the system boot is successful, the isolated subsystem is marked as a potential cause of the boot problem of the system. If the system boot is unsuccessful, the automatic diagnostic mode continues to iteratively isolate the subsystems.
TL;DR: In this paper, the purpose of a watchdog timer is to detect and fix a malfunction of a battery management system, and a device and a method for diagnosing the watchdog timer are described.
Abstract: A device and a method for diagnosing a watchdog timer are disclosed. The purpose of a watchdog timer is to detect and fix a malfunction of a battery management system. The watchdog timer diagnosis device according to one embodiment of the present invention outputs an invalid trigger signal to a watchdog timer before entering a shutdown mode according to a shutdown command from an external device, and then diagnoses, according to whether the watchdog timer outputs a reset signal, whether the watchdog timer is malfunctioning.
TL;DR: In this paper, a system and method of power mode management for a processor providing safe and robust transitioning between normal and low power modes to meet low current requirements and to ensure accurate power mode transition communications is presented.
Abstract: A system and method of power mode management for a processor providing safe and robust transitioning between normal and low power modes to meet low current requirements and to ensure accurate power mode transition communications. A two step process includes receiving a digital code, starting a standby entry timer, and receiving a low power request indication before timeout of the standby entry timer to ensure a valid request, and otherwise resetting upon timer timeout. A watchdog timer ensures that a maximum standby duration is not exceeded. An acknowledge timer ensures valid communication between modules of a power management IC. Memory elements ensure and maintain valid states of reset and safe state pins during standby. Self tests are performed in which test failure prevents transition to the low power mode. A power good indication ensures the processor that the supply voltages are suitable for both low power and normal operation.
TL;DR: In this article, a watchdog timer is used to automatically count a number and to generate a reset trigger signal to a processor if the number counted by the watchdog timer was higher than a threshold; the processor can then copy registry information from at least one of processor, flash memory interface controller, and protocol controller.
Abstract: A method used in a flash memory controller includes: using a watchdog timer to automatically count a number and to generate a reset trigger signal to a processor if the number counted by the watchdog timer is higher than a threshold; after receiving the reset trigger signal from the watchdog timer, using the processor to copy registry information from at least one of processor, flash memory interface controller, and protocol controller, and then to control the memory controller to write the copied registry information into the dynamic random access memory device without rebooting a system of the flash memory controller.
TL;DR: In this paper, a trusted platform module (TPM) is configured with a cryptographic watchdog timer which forces a device reset if the TPM fails to solve a cryptographic challenge before the expiration of the timer.
Abstract: A computing device's trusted platform module (TPM) is configured with a cryptographic watchdog timer which forces a device reset if the TPM fails to solve a cryptographic challenge before the expiration of the timer. The computing device's TPM is configured to generate the cryptographic challenge, to which the computing device does not possess the cryptographic token for resolution. While the watchdog timer counts down, the computing device requests a cryptographic token from a remote service to solve the challenge. The remote service transmits the cryptographic token to the computing device so long as the remote service identifies no reason to withhold the token, such as the computing device being infected with malware. The interoperability of the computing device and remote service enables the remote service to exercise control and reset capabilities over the computing device.
TL;DR: In this paper, a hardware watchdog timer (WDT) provided on a system platform of an information handling system (IHS) is configured to store and execute boot firmware, an operating system (OS) and one or more user applications.
Abstract: Embodiments of information handling systems and methods are provided herein to selectively control ownership of a hardware watchdog timer (WDT) provided on a system platform of an information handling system (IHS), which is configured to store and execute boot firmware, an operating system (OS) and one or more user applications. One embodiment of a method disclosed herein may include receiving user input in a boot setup utility of the boot firmware to select between OS-ownership and user application-ownership of the hardware WDT during OS runtime, and controlling ownership of the hardware WDT during OS runtime based on the user input received in the boot setup utility. Another embodiment of a method disclosed herein may authorize one or more user applications prior to controlling ownership of the hardware WDT during OS runtime, so that only authorized user applications are enabled to use the hardware WDT.