WEBVTT

1
00:00:00.000 --> 00:00:05.026
The failed image from lesson 3 still needs a
closed fetch gate.

2
00:00:05.026 --> 00:00:09.295
This time, the verifier sends four bits instead
of one.

3
00:00:09.295 --> 00:00:14.585
The receiver must decide which of sixteen values
means permission.

4
00:00:14.585 --> 00:00:18.462
That decision matters as much as the encoder.

5
00:00:18.750 --> 00:00:23.366
A multi-bit control is one decision represented
by a codeword.

6
00:00:23.366 --> 00:00:27.032
Our four-bit example uses FAIL=1001 and
PASS=0110.

7
00:00:27.032 --> 00:00:29.782
These values differ in four positions.

8
00:00:29.782 --> 00:00:34.148
Hamming distance counts those differing
positions; it describes codeword separation, not

9
00:00:34.148 --> 00:00:35.769
physical attack difficulty.

10
00:00:36.042 --> 00:00:39.467
The receiver can compare all four bits with PASS.

11
00:00:39.467 --> 00:00:41.984
This strict decoder grants only 0110.

12
00:00:41.984 --> 00:00:46.468
Another receiver might grant whenever the value
differs from FAIL.

13
00:00:46.468 --> 00:00:51.661
That loose decoder grants fifteen values,
including fourteen invalid codes.

14
00:00:51.661 --> 00:00:56.282
The same four wires now have very different
behavior.

15
00:00:56.542 --> 00:00:59.719
Flip the lowest bit of FAIL with mask 0001.

16
00:00:59.719 --> 00:01:01.420
The receiver sees 1000.

17
00:01:01.420 --> 00:01:03.462
Strict decoding rejects it.

18
00:01:03.462 --> 00:01:05.419
Loose decoding permits it.

19
00:01:05.419 --> 00:01:12.054
An invalid-code detector can raise an alert, but
the loose example deliberately leaves that

20
00:01:12.054 --> 00:01:14.266
detector out of the grant path.

21
00:01:14.266 --> 00:01:20.080
A visible alert therefore does not make this
example safe.

22
00:01:20.333 --> 00:01:25.633
OpenTitan names distinct strict and loose MuBi
tests in its source.

23
00:01:25.633 --> 00:01:28.227
Its four-bit constants are 6 and 9.

24
00:01:28.227 --> 00:01:34.937
Our exercise uses those public values to explain
the choice; it does not test OpenTitan or

25
00:01:34.937 --> 00:01:38.963
establish that a loose test is wrong in every
context.

26
00:01:38.963 --> 00:01:43.872
Denial conditions can require a different
interpretation.

27
00:01:44.125 --> 00:01:48.798
The storage experiment starts with a captured
FAIL code.

28
00:01:48.798 --> 00:01:52.711
One event XORs one four-bit register after edge
0.

29
00:01:52.711 --> 00:01:56.904
The changed code persists until the request at
edge 1.

30
00:01:56.904 --> 00:02:01.843
All sixteen masks are enumerated, including zero
as a control.

31
00:02:01.843 --> 00:02:05.817
The request is valid and ready at that edge.

32
00:02:06.083 --> 00:02:11.163
A claim for at most three flipped bits excludes
mask 1111.

33
00:02:11.163 --> 00:02:18.077
Every nonzero mask within that budget makes FAIL
invalid under strict decoding.

34
00:02:18.077 --> 00:02:20.619
Mask 1111 reaches legal PASS.

35
00:02:20.619 --> 00:02:26.474
If one physical event can invert the entire word,
a four-bit code cannot rely on the three-bit

36
00:02:26.474 --> 00:02:27.314
budget.

37
00:02:27.583 --> 00:02:33.126
The image, independent reference, completion
status, encoder, decoder, clock/reset and

38
00:02:33.126 --> 00:02:36.664
accepted handshake are trusted in this storage
experiment.

39
00:02:36.664 --> 00:02:41.105
The reference records the failed image and never
copies the corrupted code.

40
00:02:41.105 --> 00:02:46.968
Without that separation, a wrong PASS can also
rewrite the test oracle.

41
00:02:47.250 --> 00:02:49.417
Now move the target upstream.

42
00:02:49.417 --> 00:02:53.510
One boolean authorization input is inverted
before capture.

43
00:02:53.510 --> 00:02:56.737
The encoder receives true and stores legal PASS.

44
00:02:56.737 --> 00:03:00.986
Strict equality succeeds because the code is
perfectly formed.

45
00:03:00.986 --> 00:03:04.327
The failure entered before the code existed.

46
00:03:04.583 --> 00:03:08.624
This is a separate experiment with one source
target.

47
00:03:08.624 --> 00:03:11.014
It does not also flip stored bits.

48
00:03:11.014 --> 00:03:15.623
A second expanded experiment inverts only final
grant at edge 1.

49
00:03:15.623 --> 00:03:18.781
Both keep the accepting interface trusted.

50
00:03:18.781 --> 00:03:24.430
These cases identify two boundaries that storage
distance cannot protect.

51
00:03:24.708 --> 00:03:31.167
A designer can keep encoded decisions along more
of the path, check provenance, or use separately

52
00:03:31.167 --> 00:03:33.533
generated evidence at the consumer.

53
00:03:33.533 --> 00:03:36.510
Each choice needs an explicit trust argument.

54
00:03:36.510 --> 00:03:43.097
Encoding one faulted boolean four times does not
create four independent decisions.

55
00:03:43.375 --> 00:03:46.737
Open the lab and leave authorization false.

56
00:03:46.737 --> 00:03:49.984
Select code target, strict policy and mask 1.

57
00:03:49.984 --> 00:03:52.462
Inspect raw, seen, bad and commit.

58
00:03:52.462 --> 00:03:54.769
Change only the policy to loose.

59
00:03:54.769 --> 00:03:59.982
The accepting edge changes while the source and
fault remain identical.

60
00:03:59.982 --> 00:04:04.463
Export both traces and explain the gate
responsible.

61
00:04:04.750 --> 00:04:10.197
The executed Node campaign found one unauthorized
mask under strict decoding and fifteen under

62
00:04:10.197 --> 00:04:12.465
loose decoding across the sixteen masks.

63
00:04:12.465 --> 00:04:15.510
These counts include the weight-four
counterexample.

64
00:04:15.510 --> 00:04:18.619
They are enumeration counts, not attack
probabilities.

65
00:04:18.619 --> 00:04:24.135
Fault-free authorized PASS is accepted;
fault-free FAIL is rejected.

66
00:04:24.417 --> 00:04:30.599
Switch to source and then grant, using a nonzero
mask as the injection enable.

67
00:04:30.599 --> 00:04:37.134
Here mask magnitude does not count source bits:
each expanded target is one boolean.

68
00:04:37.134 --> 00:04:40.908
Keep those traces out of the storage-mask table.

69
00:04:40.908 --> 00:04:48.417
Finally set authorized true and mask zero to
check that the strict gate can open normally.

70
00:04:48.667 --> 00:04:51.683
This RTL/SVA fragment is proposed, not compiled.

71
00:04:51.683 --> 00:04:57.316
Four-state X propagation, synthesis of equality
logic, encoded AND/OR semantics and post-decode

72
00:04:57.316 --> 00:04:58.859
faults need separate work.

73
00:04:58.859 --> 00:05:02.614
The full source-to-consumer path must be mapped
after synthesis.

74
00:05:02.614 --> 00:05:07.590
Lesson 5 examines whether redundant producers
actually fail independently.

75
00:05:07.875 --> 00:05:12.479
One persistent four-bit storage XOR after edge 0;
accepting edge 1.

76
00:05:12.479 --> 00:05:18.273
At most three bits for the bounded rejection
claim, with four-bit and source/grant cases

77
00:05:18.273 --> 00:05:19.741
reported separately.

78
00:05:19.741 --> 00:05:23.567
The oracle and non-target circuitry remain
trusted.

79
00:05:23.833 --> 00:05:29.432
Node executed all sixteen masks, source/grant
witnesses and fault-free positive/negative

80
00:05:29.432 --> 00:05:30.047
controls.

81
00:05:30.047 --> 00:05:33.746
RTL/SVA and physical implementation remain
unverified.

82
00:05:34.000 --> 00:05:38.796
Two-state word substitution excludes timing
glitches, physical independence and decoder

83
00:05:38.796 --> 00:05:41.385
implementation faults in the main campaign.
