Method, Device, and System for Protecting Encryption Algorithms

By using a round encryption algorithm in a symmetric encryption algorithm, combining hardware and software operation methods, mask refresh is achieved using lookup tables, and the problems of high sensitivity to physical attacks and large hardware circuits in the prior art are solved, and an efficient and compact encryption solution is achieved.

CN113806762BActive Publication Date: 2025-06-13STMICROELECTRONICS (ROUSSET) SAS
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202110668105.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2021-06-14
Filing Date
2021-06-16
Publication Date
2025-06-13
Estimated Expiration
2041-06-16

AI Technical Summary

Technical Problem

Existing symmetric encryption algorithms are highly sensitive when facing physical attacks and have a large hardware circuit occupancy, making it difficult to achieve efficient and compact encryption solutions.

Method used

The round encryption algorithm is used to perform data masking and demasting operations through hardware, and linear operations are applied in software, and non-linear operations in hardware or software are combined to realize mask refresh using lookup tables.

Benefits of technology

It improves the resistance of encryption algorithms to physical attacks, reduces the use of hardware circuits, and realizes a faster and more compact encryption solution.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113806762B_ABST
    Figure CN113806762B_ABST
Patent Text Reader

Abstract

Embodiments of the present disclosure relate to the protection of encryption algorithms. A cryptographic device includes: hardware data processing circuitry; and software data processing circuitry coupled to the hardware data processing circuitry. In operation, the device performs multiple rounds of a symmetric data encryption algorithm and protects the execution of the multiple rounds of the symmetric data encryption algorithm. The protection includes: performing data masking operations and demasking operations using the hardware data processing circuitry; performing linear operations applied to data using the software data processing circuitry; performing linear operations applied to masks using the hardware data processing circuitry; and performing non-linear operations applied to data using one of the hardware data processing circuitry or the software data processing circuitry.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure generally relates to computer security, and more particularly to the implementation of encryption algorithms. More specifically, the present disclosure relates to the implementation of symmetric encryption algorithms. Background Art

[0002] In the field of information security, encryption algorithms are generally used to ensure the protection of data used by electronic devices.

[0003] Encryption algorithms typically use encryption and / or decryption keys to encrypt data. Symmetric encryption algorithms are algorithms that use the same key, which is used to encrypt and decrypt data, and then that key is referred to as the encryption and decryption key.

[0004] Among different types of known symmetric encryption algorithms, "round" or "round-based" symmetric encryption algorithms are operations in which one or more mathematical and / or logical operations are repeatedly applied to the data to be encrypted. Summary of the Invention

[0005] Embodiments facilitate the implementation of an encryption algorithm that is less sensitive to physical attacks, referred to as "rounds".

[0006] Embodiments facilitate the implementation of a faster symmetric encryption algorithm referred to as "rounds".

[0007] Embodiments facilitate the implementation of a faster symmetric encryption algorithm referred to as "rounds" using a more compact physical circuit.

[0008] One embodiment provides a method for a symmetric data encryption algorithm implemented in rounds by an electronic device, including the steps of performing the following operations:

[0009] Data masking operations and demasking operations performed in hardware;

[0010] Linear operations applied to the data in software; and

[0011] Nonlinear operations in software or hardware.

[0012] One embodiment provides an electronic device capable of implementing a symmetric encryption algorithm, including the steps of performing the following operations:

[0013] Data masking operations and demasking operations in hardware;

[0014] Linear operations applied to the data in software; and

[0015] Nonlinear operations in software or hardware.

[0016] According to an embodiment, the symmetric data encryption algorithm includes a data path and a key path, and the masking operation, the demasking operation, the linear operation, and the non-linear operation are operations of the data path.

[0017] According to an embodiment, the masking operation and the demasking operation include a masking operation, a demasking operation, and a mask refreshing operation.

[0018] According to an embodiment, a masking operation or a demasking operation follows each non-linear operation.

[0019] According to an embodiment, a mask refreshing operation follows each non-linear operation.

[0020] According to an embodiment, a masking operation follows each non-linear operation.

[0021] According to an embodiment, a masking operation and a demasking operation precede each non-linear operation.

[0022] According to an embodiment, a demasking operation precedes each non-linear operation.

[0023] According to an embodiment, a mask refreshing operation precedes each non-linear operation.

[0024] According to an embodiment, the mask refreshing operation is implemented by using a look-up table.

[0025] According to an embodiment, the encryption algorithm includes a step of implementing a look-up table refreshing operation.

[0026] According to an embodiment, the non-linear operation is implemented by using a look-up table.

[0027] According to an embodiment, the encryption algorithm is a block cipher algorithm, such as: AES (Advanced Encryption Standard), SM4, and GOST R34.12-2015, or a stream cipher algorithm.

[0028] According to an embodiment, the encryption algorithm in a round uses a logical addition function to use masking. BRIEF DESCRIPTION OF THE DRAWINGS

[0029] The foregoing exemplary features and advantages, as well as others, will be described in detail in the following description of specific embodiments, which is given by way of illustration and not limitation with reference to the accompanying drawings, in which:

[0030] Figure 1 A schematic diagram showing the execution of an embodiment of a symmetric encryption algorithm called "round" is schematically shown in the form of a block;

[0031] Figure 2 An electronic device is schematically shown in the form of a block;

[0032] Figure 3The steps of a protected implementation of a symmetric encryption algorithm are schematically shown in the form of a block diagram;

[0033] Figure 4 The steps of another protected implementation of a symmetric encryption algorithm are schematically shown in the form of a block diagram;

[0034] Figure 5 The steps of another protected implementation of a symmetric encryption algorithm are schematically shown in the form of a block diagram;

[0035] Figure 6 The steps of another protected implementation of a symmetric encryption algorithm are schematically shown in the form of a block diagram; and

[0036] Figure 7 The steps of another protected implementation of a symmetric encryption algorithm are schematically shown in the form of a block diagram. Detailed Implementation Modes

[0037] Similar features have been designated by like reference numerals in the respective drawings, unless the context indicates otherwise. Specifically, structural and / or functional features common to the various embodiments may have the same reference numerals, and similar or identical structures, dimensions, and material properties may be provided.

[0038] For clarity, only the steps and elements useful for understanding the embodiments described herein are illustrated and described in detail. Specifically, the different computational operations implemented by the encryption algorithm will not be elaborated.

[0039] Unless otherwise indicated, when referring to two elements connected together, this means a direct connection without any intermediate elements other than a conductor, and when referring to two elements coupled together, this means that the two elements may be connected, or they may be coupled via one or more other elements.

[0040] In the following disclosure, unless otherwise indicated, when referring to absolute position determiners (such as the terms "front", "rear", "top", "bottom", "left side", "right side", etc.) or relative position determiners (such as the terms "above", "below", "higher", "lower", etc.) or orientation determiners (such as "horizontal", "vertical", etc.), the orientation shown in the drawings is referred to.

[0041] Unless otherwise specified, the expressions "about", "approximately", "substantially", and "about" mean, for example, within 10%, within 5%.

[0042] Figure 1 A schematic diagram of the execution of a symmetric encryption algorithm or the symmetric encryption algorithm in a round and the encryption algorithm in a round, which is called a "round", is schematically shown in the form of a block diagram.

[0043] A symmetric encryption algorithm in a round executed by an electronic circuit can generally transform a message formed by pure data Data with a secret key Key to obtain encrypted data C_Data.

[0044] The execution of the encryption algorithm is an iterative encryption or processing process. This iterative process includes applying one or more consecutive mathematical and / or logical operations to the pure data Data and the key Key for multiple rounds or multiple loops, as Figure 1 shown as box 10. As an example, the operations of box 10 are applied N number of rounds (xN).

[0045] The encryption algorithm can, for example, start with an optional initialization step 9 (INIT) to enable the preparation of the data Data and the key Key in the next step. As an example, the initialization step can be the first masking step of the data Data to be encrypted.

[0046] In each round, it starts by calculating a sub - key SubKey based on the secret key Key or the sub - key SubKey of the previous round. The set of mathematical and / or logical operations applied to the key Key or the sub - key SubKey in each round is called the key path (box 11, key path). Then, the sub - key SubKey is used to transform or encrypt the data Data.

[0047] To encrypt the data Data, in each round, a set of mathematical and / or logical operations is applied to the data Data or the encrypted data C - Data of the previous round using the key Key or the sub - key SubKey. The set of mathematical and / or logical operations applied to the data Data or the encrypted data C_Data in each round is called the data path (box 12, data path). The set formed by the key path and the data path will then be called the round function of the encryption algorithm.

[0048] The data C_Data encrypted with the sub - key SubKey is then obtained at the end of the round. The encrypted data C_Data is then fed back into the processing or encryption process and thus plays the role of input data for applying the round function 10 in the next round. Similarly, at the output of the round, each new sub - key SubKey is fed back to enable the generation of the sub - key for the next round.

[0049] At the end of N number of rounds, the encrypted data C_Data obtained by the last application of the round function 110 forms the final encrypted data C_Data.

[0050] In other words, the symmetric encryption algorithm or process in a round sequentially includes:

[0051] Initialization step 9;

[0052] In the first round, the round function is applied to the data Data and the key Key during this first round;

[0053] Multiple intermediate rounds (N - 2 rounds in this example), for each round, a new sub - key SubKey is calculated, and during the round, the round function 10 is applied to the encrypted data C_Data and the sub - key SubKey, where the encrypted data C_Data and the sub - key SubKey are produced by applying the function in the previous round.

[0054] In the final round, processing the last encrypted data by finally applying the round function at the end of this final round results in obtaining the final encrypted data C_Data.

[0055] The number of rounds N is also referred to as the number of iterations. The number of rounds N usually depends on the encryption algorithm used and the size of the secret key Key.

[0056] The round function 10 applied in each round includes, for example, substitution, row shift, and column mixing operations, followed by a combination (such as XOR) of the sub - key SubKey for the round under consideration. The round function 10 generally aims to obtain an algorithm that is provided with the properties of confusion (i.e., as complex as possible the relationship between the secret key and the plain message) and diffusion (i.e., the statistical redundancy of the plain message is consumed in the statistical information of the encrypted message). This is usually the case for AES - or SM4 - type algorithms.

[0057] The algorithm can also include a secondary masking operation, which enables adding a protection level to the data Data to be encrypted during the application of the round function. Such an operation can protect the data from attacks during the application of the encryption algorithm.

[0058] Figure 2 The electronic device 20 is schematically shown in the form of a block.

[0059] The electronic device 20 is an electronic device capable of implementing an encryption algorithm in rounds of the type described with respect to Figure 1 The device 20 can be a security or cryptographic circuit of the system 200, as illustrated, including an application processor 202 and a system memory 204. The system 200 can be, for example, a smart phone or other electronic device, which can employ, for example, a security or cryptographic circuit 20 to authenticate transactions initiated by the application processor, communications received by the application processor, etc.

[0060] The device 20 includes components 21 (HW) of a circuit capable of performing mathematical and / or logical operations. The components 21 can include, for example, memory elements such as lookup tables, logic circuits, etc. The mathematical and / or logical operations are used, for example, to implement the encryption algorithm in rounds.

[0061] Device 20 is also capable of implementing a set 22 (SW) of instructions and software to perform mathematical and logical operations. The set 22 is implemented, for example, by a single processor (processor P, as shown) or by multiple different processors that execute one or more instruction sets stored in the memory M. As previously described, the mathematical and / or logical operations are used, for example, to implement the encryption algorithm in rounds.

[0062] As described with respect to Figure 1 the encryption algorithm implemented by device 20 applies a data path to the data to be masked and a key path to the key, and this is done for N number of rounds. More specifically, the data path and the key path of the encryption algorithm are formed by multiple mathematical and / or logical operations. Such operations can have different characteristics (such as the fact of being linear or non-linear) and different purposes, such as encrypting the data, or performing secondary masking operations and / or de-masking operations on the data. In the following description, it is considered that the data path is continuously formed by one or more linear encryption operations applied to the data to be encrypted, one or more non-linear encryption operations applied to the data to be encrypted, and one or more secondary masking operations and / or de-masking operations. Thereafter, the following terms are used:

[0063] "Linear operation" for linear mathematical and / or logical operations;

[0064] "Non-linear operation" for non-linear mathematical and / or logical operations; and

[0065] "Masking operation" or "de-masking operation" for operations for secondary masking operations or de-masking.

[0066] According to an embodiment, device 20 is capable of implementing linear operations in software form, that is, by using the set 22 of instructions and software that can be implemented. Device 20 is capable of implementing non-linear operations in software or hardware manner, that is, by using the components 21 of the circuit. The masking operations and de-masking operations are operations that can ensure masking the data to be encrypted by the mask during the execution of linear and non-linear operations. Such masking operations and de-masking operations are implemented by the device in hardware manner. According to an embodiment, the type of masking used during the execution of the encryption algorithm is the type of masking that maintains linear operations. In other words, if the mask is submitted to the same linear operation as the masked data, then de-masking can be performed by using the said mask. As an example, the type of masking that verifies this condition is the masking that performs an XOR operation, where the data to be masked is combined with the mask by a logical addition operation, such as an XOR logical operation.

[0067] As an example, a similar treatment can be applied to the operations that form the key path of the encryption algorithm.

[0068] Multiple embodiments of the encryption algorithm implemented by device 20 are regarding Figures 3 to 7 described. More specifically, in the example of Figures 3 to 7 , the data path of the encryption algorithm implemented by device 20 is continuously formed by a first linear operation, a non-linear operation, and a second linear operation. The distribution of the masking operation or the demasking operation is regarding Figures 3 to 7 described. However, as a variation, the data path of the encryption algorithm implemented by device 20 may include one or more than two linear operations and more than two non-linear operations arranged in any manner.

[0069] Figure 3 The steps of an embodiment of the symmetric encryption algorithm of device 20 regarding Figure 2 are schematically shown in the form of a block.

[0070] In the example regarding Figure 3 , the non-linear operation of the data path is implemented in software.

[0071] In Figure 3 , the operations shown on the left-hand side of the drawing are operations implemented in hardware (HW), and the operations shown on the right-hand side of the drawing are operations implemented in software (SW).

[0072] Furthermore, the upper part of the drawing shows the execution of the operations of the initialization step 101 (bounded by a dashed line) of the encryption algorithm, and the lower part of the drawing shows the execution of the operations of the data path 102 (bounded by a dashed line) during the first round.

[0073] In the initialization step 101, the data Data1 to be encrypted is masked with the mask Mask1_1 during the masking operation 1011 (masking). The masking operation 1011 delivers the masked data C_Data1. The data Data1 is represented as coming from the hardware part of the device that executes the encryption algorithm, but according to a variation, the data Data1 may come from the software part of the device.

[0074] Then, the operations of data path 102 are performed. First, a first linear operation 1021 (Op Lin 1) is applied to the masked data C_Data1 in software. The result of operation 1021 is the masked data C_Data1_lin1. The same first linear operation 1022 (Op Lin 1) as operation 1021 is applied in parallel in hardware to the mask Mask1_1 of the masked data C_Data1. The result of operation 1022 is the mask Mask1_1_lin1. At this stage, the masked data C_Data1_lin1 can be unmasked with the mask Mask1_1_lin1 to obtain the result of applying operation 1021 to the data Data1 to be encrypted.

[0075] The execution of data path 102 continues by applying a non-linear operation 1023 (Op NLin) to the data C_Data1_lin1 in software. The result of operation 1023 is the masked data C_Data1_Nlin.

[0076] The next operation is then a mask refresh operation 1024 (Refresh Mask) performed in hardware. During this operation, the data C_Data1_Nlin is modified to the data C_Data1_Nlin2 masked by another mask Mask1_2. The mask Mask1_2 can be different from or the same as the mask Mask1_1. Having a mask Mask1_2 different from the mask Mask1_1 can increase the protection of the data to be encrypted. According to an embodiment, the refresh operation 1024 includes the following consecutive steps:

[0077] Apply an operation opposite to the non-linear operation 1023 to the data C_Data1_Nlin to restore the data C_Data1_lin1;

[0078] Unmask the data C_Data1_lin1 with the mask Mask1_1_lin1;

[0079] Apply the non-linear operation 1023 to the unmasked data C_Data1_lin1; and

[0080] Mask with the mask Mask1_2 to obtain the masked data C_Data1_Nlin2.

[0081] The execution of data path 102 continues to apply the second linear operation 1025 (Op Lin 2) to the masked data C_Data1_Nlin2 in software. The result of operation 1025 is the masked data C_Data1_lin2. The same second linear operation 1026 (Op Lin 2) as operation 1025 is applied in parallel in hardware to the mask Mask1_2 of the masked data C_Data1_Nlin2. The result of operation 1026 is the mask Mask1_2_lin2. At this stage, the masked data C_Data1_lin2 can be unmasked with the mask Mask1_2_lin2.

[0082] The operations for the first round of data path 102 are completed. The data C_Data1_lin2 and the mask Mask1_2_lin2 can be fed back in place of, with respect to the data C_Data1 and the mask Mask1_2_lin2 to start the next round.

[0083] As an overview, to apply the data path, each linear operation is applied in parallel in software to the masked data and in hardware to its mask. Further, each non-linear operation is followed by a mask refresh operation. According to a variant, if a linear operation does not modify the mask, then the operation is not applied in parallel to the mask and the masked data.

[0084] An advantage of this embodiment is that it provides a protected implementation of the encryption algorithm. In other words, it provides countermeasures against some physical attacks to allow, for example, the identification of the encryption algorithm used.

[0085] Another advantage of this embodiment is that the operations of the encryption algorithm are implemented in software methods and in hardware, which makes physical attacks more difficult to implement.

[0086] Another advantage of this embodiment is that the data to be encrypted is masked during all encryption operations of the algorithm.

[0087] Another advantage of this embodiment is that it reduces the use of hardware circuits compared to a full hardware implementation of the same encryption algorithm.

[0088] Figure 4 Is schematically shown in block form with respect to Figure 2 The steps of another embodiment of the symmetric encryption algorithm of the device 20 described.

[0089] In the example described with respect to Figure 4 The encryption algorithm is based on using a lookup table to perform the mask refresh operation. The initialization steps and data path of this algorithm are similar to those with respect to Figure 3The described initialization steps and data paths, but also include lookup table initialization and refresh operations.

[0090] As Figure 3 described, in the examples described herein, the non-linear operations of the data path are implemented here in software.

[0091] In Figure 4 as in Figure 3 as shown on the left hand side of the figure, the operations are implemented in hardware (HW), and the operations shown on the right hand side of the figure are implemented in software (SW).

[0092] Further, the upper part of the figure shows the execution of the operations of the initialization step 201 (bounded by a dashed line) of the encryption algorithm, and the lower part of the figure shows the execution of the operations of the data path 202 (bounded by a dashed line) during the first round.

[0093] In the initialization step 201, the data Data2 to be encrypted is masked with the mask Mask2_1 during the masking operation 2011 (Masking). The masked data C_Data2 is then provided. The data Data2 is represented as coming from the hardware part of the device that executes the encryption algorithm, but according to a variant, the data Data2 can come from the software part of the device.

[0094] Further, the operation of the initialization 2012 (Init Tab) of the lookup table is executed, where the lookup table Tab2_1 is created. The lookup table Tab2_1 enables the execution of the mask refresh operation without having to perform calculations. More specifically, the lookup table can associate the values generated by applying one or more operations with each value that the data can take. In the appropriate case, in the Figure 4 example, the lookup table can associate the values generated by the application with each value that the data can take, coherently:

[0095] The operation of unmasking the data using the mask Mask2_1;

[0096] The non-linear operation 2023 described hereinafter; and

[0097] The operation of masking with the mask Mask2_2.

[0098] According to a variation, during the operation 2012, the lookup table can be created in this operation (e.g., without associated values) and can be filled during subsequent operations.

[0099] Then, the execution of data path 202 begins with the software application of a first linear operation 2021 (Op Lin 1) to the masked data C_Data2. The result of operation 2021 is the masked data C_Data2_lin1. The same first linear operation 2022 (Op Lin 1) as operation 2021 is applied in parallel in hardware to the mask Mask2_1 of the masked data C_Data2. The result of operation 2022 is the mask Mask2_1_lin1. At this stage, the masked data C_Data2_lin1 can be unmasked with the mask Mask2_1_lin1.

[0100] The execution of data path 202 continues with the software application of a non-linear operation 2023 (Op NLin) to the data C_Data2_lin1. The result of operation 2023 is the masked data C_Data2_Nlin.

[0101] An operation 2024 to refresh the lookup table Tab2_1 is executed. During this step, the data of the lookup table Tab2_1 is modified to enable the association of values resulting from the successive application of the following operations with each value that the data can take:

[0102] The operation opposite to the non-linear operation 2023;

[0103] The operation of unmasking the data with the mask Mask2_1_lin1;

[0104] The non-linear operation 2023; and

[0105] The operation of masking with the mask Mask2_2.

[0106] The new lookup table generated by operation 2024 is the lookup table Tab2_2.

[0107] The next operation is then a refresh operation (Refresh Mask) of mask 2025 executed in hardware. During this operation, the data C_Data2_Nlin is modified to the masked data C_Data2_Nlin2 with the mask Mask2_2. The refresh operation 2025 is to search the lookup table Tab2_2 for the value corresponding to the masked data C_Data2_Nlin to deliver the masked data C_Data2_Nlin2. According to a variant, the mask Mask2_2 can be equal to the mask Mask2_1_lin1.

[0108] The execution of data path 202 continues to apply the second linear operation 2026 (Op Lin 2) to the masked data C_Data2_Nlin2 in software. The result of operation 2025 is the masked data C_Data2_lin2. The same second linear operation 2027 (Op Lin 2) as operation 2026 is applied in parallel in hardware to the mask Mask2_2 of the masked data C_Data2_Nlin2. The result of operation 2027 is the mask Mask2_2_lin2. At this stage, the masked data C_Data2_lin2 can be unmasked with the mask Mask2_2_lin2.

[0109] The operations for the first round of data path 202 are completed. The data C_Data2_lin2, the mask Mask2_2_lin2, and the lookup table Tab2_2 can be fed back in place of, with respect to the data C_Data2, the mask Mask2_2, and the lookup table Tab2_1 to start the next round.

[0110] As an overview, as in the embodiment for Figure 3 each linear operation is applied in parallel to the masked data in software and to its mask in hardware. Further, each non-linear operation is followed by a mask refresh operation. Further, if the last operation applied to the data is a linear operation, the lookup table used to implement the mask refresh operation should be updated or refreshed before the implementation of the mask refresh operation. According to a variant, if a linear operation does not modify the mask, then the operation is not applied in parallel to the mask and the masked data.

[0111] This embodiment has the same advantages as the embodiment described with respect to Figure 3 Another advantage of this embodiment is that it enables the avoidance of masking and unmasking operations during the execution of the data path.

[0112] A further advantage of this embodiment is that it enables the cancellation of the use of masking and unmasking circuits during the execution of data path 302 using a lookup table, which can make the execution faster and reduce the physical size of component 21 of the circuit of device 20. Device 20 is then more compact and more affordable.

[0113] Another advantage of this embodiment is that the use of a lookup table enables the cancellation of the use of masking and unmasking circuits during the execution of data path 302, which can make the execution faster and reduce the physical size of component 21 of the circuit of device 20. Device 20 is then more compact and more affordable.

[0114] Figure 5 The steps of another embodiment of the symmetric encryption algorithm of device 20 described with respect to Figure 2 are schematically shown in block form.

[0115] In the case of Figure 5In the described example, the non-linear operations of the data path are implemented in hardware.

[0116] As in Figure 3 and Figure 4 in, in Figure 5 the operations shown on the left hand side of the figure are implemented in hardware (HW) and the operations shown on the right hand side of the figure are implemented in software (SW).

[0117] Furthermore, the upper part of the figure shows the execution of the operations of the initialization step 301 (bounded by a dashed line) of the encryption algorithm, and the lower part of the figure shows the execution of the operations of the data path 302 (bounded by a dashed line) during the first round.

[0118] In the initialization step 301, the data Data3 to be encrypted is masked with the mask Mask3_1 during the masking operation 3011 (masking). The masked data C_Data3 is then provided. The data Data3 is represented as coming from the hardware part of the device that executes the encryption algorithm, but according to a variant, the data Data3 can come from the software part of the device.

[0119] Then, the execution of the data path 302 starts with applying the first linear operation 3021 (Op Lin 1) to the masked data C_Data3 in software. The result of the operation 3021 is the masked data C_Data3_lin1. The same first linear operation 3022 (Op Lin 1) as the operation 3021 is applied to the mask Mask3_1 of the masked data C_Data3 in hardware in parallel. The result of the operation 3022 is the mask Mask3_1_lin1. At this stage, the masked data C_Data3_lin1 can be unmasked with the mask Mask3_1_lin1.

[0120] Then the non-linear operation 3023 (Op N Lin) applied to the data C_Data3_lin1 is executed in hardware. To minimize the number of masking operations and / or unmasking operations, the data C_Data3_lin1 is sent into the circuit component 21 and is unmasked by the unmasking operation 3024 (unmasking). The unmasking operation uses the mask Mask3_1_lin1 to unmask the data C_Data3_lin1 and outputs the unmasked data Data3_lin1. The non-linear operation 3023 is then applied to the data Data3_lin1 and outputs the data Data3_Nlin.

[0121] The data Data3_Nlin is then masked by a masking operation 3025 (masking), similar to the masking operation 3011 performed in the initialization step 301. The operation 3025 enables masking the data Data3_Nlin with a new mask Mask3_2 different from the mask Mask3_1. According to a variant, the mask Mask3_2 can be equal to the mask Mask3_1_lin1. The operation 3025 outputs the masked data C_Data3_Nlin.

[0122] The demasking operation 3024, the non-linear operation 3023, and the masking operation 3025 are performed by the same circuitry in the circuitry 21 of the device 20, in such a way that the demasked data is not available in the circuitry 21.

[0123] The execution of the data path 302 continues by applying in software a second linear operation 3026 (Op Lin 2) to the masked data C_Data3_Nlin. The result of the operation 3026 is the masked data C_Data3_lin2. The same second linear operation 3027 (Op Lin 2) as the operation 3026 is applied in hardware in parallel to the mask Mask3_2 of the masked data C_Data3_Nlin. The result of the operation 3027 is the mask Mask3_2_lin2. At this stage, the masked data C_Data3_lin2 can be demasked with the mask Mask3_2_lin2.

[0124] The operations for the first round of the data path 302 are completed. The data C_Data3_lin2 and the mask Mask3_2_lin2 can be fed back instead of the data C_Data3 and the mask Mask3_1 to start the next round.

[0125] As an overview, as in the embodiments for Figure 3 and Figure 4 each linear operation is applied in software in parallel to the masked data and in hardware to its mask in order to apply the data path. Further, each non-linear operation is surrounded by a demasking operation and an operation to mask the data to be processed. According to a variant, if a linear operation does not modify the mask, then the operation is not applied in parallel to the mask and the masked data.

[0126] This embodiment has the same advantages as the embodiment described with respect to Figure 3 Further, another advantage of this embodiment is that by implementing the non-linear operation 3023 in hardware, the use of the non-linear operation 3023 and its inverse operation is restricted compared to the embodiments described with respect to Figure 3 and Figure 4 described.

[0127] Figure 6 Schematically shown in the form of a block diagram are the steps of another embodiment of the symmetric encryption algorithm for the device 20 described Figure 2 herein.

[0128] In the example described Figure 6 herein, the initialization step and the data path of this algorithm are similar to the initialization step and the data path described Figure 5 herein, the difference being that, as in Figure 4 herein, the encryption algorithm uses a lookup table.

[0129] In the example described Figure 6 herein and as in Figure 5 herein, the non-linear operations of the data path are implemented in hardware.

[0130] As in Figures 3 to 5 herein, in Figure 6 herein, the operations shown on the left-hand side of the drawing are implemented in hardware (HW), and the operations shown on the right-hand side of the drawing are implemented in software (SW).

[0131] Further, the upper part of the drawing shows the execution of the operations of the initialization step 401 (bounded by a dashed line) of the encryption algorithm, and the lower part of the drawing shows the execution of the operations of the data path 402 (bounded by a dashed line) during the first round.

[0132] In the initialization step 401, the data Data4 to be encrypted is masked with the mask Mask4_1 during the masking operation 4011 (Masking). The masked data C_Data4 is then provided. The data Data4 is represented as coming from the hardware part of the device that executes the encryption algorithm, but according to a variant, the data Data4 can come from the software part of the device.

[0133] Further, the operation of the initialization 4012 (Init Tab) of the lookup table is executed, during which the lookup table Tab4_1 is created. The operation 4012 is similar to the operation 2012 described Figure 2 herein.

[0134] The execution of data path 402 begins with the software application of a first linear operation 4021 (Op Lin 1) to the masked data C_Data4. The result of operation 4021 is the masked data C_Data4_lin1. The same first linear operation 4022 (Op Lin 1) as operation 4021 is applied in parallel in hardware to the mask Mask4_1 of the masked data C_Data4. The result of operation 4022 is the mask Mask4_1_lin1. At this stage, the masked data C_Data4_lin1 can be unmasked with the mask Mask4_1_lin1.

[0135] The execution of data path 402 continues with the hardware application of a non-linear operation 4023 (Op NLin) to the data C_Data1_lin1. The result of operation 4023 is the masked data C_Data4_Nlin.

[0136] An operation 4024 for refreshing the look-up table Tab4_1 is executed. During this step, the data of the look-up table Tab4_1 is modified so as to be able to coherently associate the values generated by the application with each value that the data can take:

[0137] An operation contrary to the non-linear operation 4023;

[0138] An operation for unmasking the data with the mask Mask4_1_lin1;

[0139] The non-linear operation 4023; and

[0140] An operation for masking with the mask Mask4_2.

[0141] The new look-up table generated by operation 4024 is the look-up table Tab4_2.

[0142] The new look-up table Tab4_2 is then used by an operation 4025 (refresh mask) for refreshing the mask of the masked data C_Data4_Nlin. Operation 4025 modifies the mask Mask4_1_lin1 used for masking the data C_Data4_Nlin to the mask Mask4_2. The refresh operation 4025 consists of searching in the look-up table Tab4_2 for the value corresponding to the masked data C_Data4_Nlin in order to deliver the masked data C_Data4_Nlin2. According to a variant, the mask Mask4_2 can be equal to the mask Mask4_1_lin1.

[0143] The execution of data path 402 continues to apply the second linear operation 4026 (Op Lin 2) to the masked data C_Data4_Nlin in software. The result of operation 4026 is the masked data C_Data4_lin2. The same second linear operation 4027 (Op Lin 2) as operation 4026 is applied in parallel in hardware to the mask Mask4_2 of the masked data C_Data4_Nlin2. The result of operation 4027 is the mask Mask4_2_lin2. At this stage, the masked data C_Data4_lin2 can be unmasked with the mask Mask4_2_lin2.

[0144] The operations for the first round of data path 402 are completed. The data C_Data4_lin2, the mask Mask4_2_lin2, and the lookup table Tab4_2 can be fed back in place of, with respect to the data C_Data4, the mask Mask4_2, and the lookup table Tab4_1, to start the next round.

[0145] As an overview, as in the embodiment for Figures 3 to 5 each linear operation is applied in parallel to the masked data in software and to its mask in hardware. Further, each non - linear operation is followed by a table refresh operation. Further, if the last operation applied to the data is a linear operation, the lookup table used to implement the table refresh operation should be updated or refreshed before the implementation of the table refresh operation. According to a variant, if a linear operation does not modify the mask, then the operation is not applied in parallel to the mask and the masked data.

[0146] This embodiment has the same advantages as the embodiment described with respect to Figures 3 to 5 Another advantage of this embodiment is the ability to avoid masking and unmasking operations during the execution of the data path, which can make the execution faster and reduce the physical size of the circuit 21 of the device 20. The device 20 is then more compact and more affordable.

[0147] Figure 7 The steps of another embodiment of the symmetric encryption algorithm of the device 20 described with respect to Figure 2 are schematically shown in block form.

[0148] In the example described with respect to Figure 7 the initialization step and the data path of the algorithm are similar to the initialization step and the data path described with respect to Figure 6 The difference is that the data to be masked is always masked with the same permanent mask during the execution of the operations in hardware form.

[0149] As inFigures 3 to 6 As in Figure 7 In, the operations shown on the left - hand side of the drawing are implemented in hardware (HW) and the operations shown on the right - hand side of the drawing are implemented in software (SW).

[0150] Furthermore, the upper part of the drawing shows the execution of the operations of the initialization step 501 (bounded by a dashed line) of the encryption algorithm, and the lower part of the drawing shows the execution of the operations of the data path 502 (bounded by a dashed line) during the first round.

[0151] In the initialization step 501, the data Data5 to be encrypted is masked with the mask Mask5_1 during the masking operation 5011 (Masking). The masked data C_Data5 is then provided. The data Data5 is represented as coming from the hardware part of the device that executes the encryption algorithm, but according to a variant, the data Data5 can come from the software part of the device.

[0152] Furthermore, the operation 5012 (Init Tab) of initializing the lookup table Tab5_Perm is performed during step 501. The lookup table Tab5_Perm enables the association of the values taken by the said data that has been submitted to the following successive operations with each value that the data masked with the mask Mask5_Perm can take:

[0153] The unmasking operation using the mask Mask5_Perm;

[0154] The non - linear operations of the algorithm described hereinafter; and

[0155] The new masking operation using the mask Mask5_Perm.

[0156] The execution of the data path 502 begins with the software application of the first linear operation 5021 (Op Lin 1) to the masked data C_Data5. The result of the operation 5021 is the masked data C_Data5_lin1. The same first linear operation 5022 (Op Lin 1) as the operation 5021 is applied in parallel in hardware to the mask Mask5_1 of the masked data C_Data5. The result of the operation 5022 is the mask Mask5_1_lin1. At this stage, the masked data C_Data5_lin1 can be unmasked with the mask Mask5_1_lin1.

[0157] The execution of data path 502 continues to apply the non-linear operation 5023 (Op N Lin) of the algorithm to data C_Data5_lin1 in hardware. To this end, the masked data C_Data5_lin1 is submitted to a first mask refresh operation 5024 (refresh mask 1), during which the mask Mask5_1_lin1 used to mask data C_Data5_lin1 is modified to mask Mask5_Perm. More specifically, mask refresh operation 5024 includes the following operations:

[0158] A de-masking operation using mask Mask5_1_lin1; and

[0159] A new masking operation using mask Mask5_Perm.

[0160] The result of operation 5024 is masked data C_Data5_Perm.

[0161] The non-linear operation 5023 is then applied to data C_Data5_Perm by using lookup table Tab5_Perm. The result of operation 5023 is masked data C_Data5_NlinPerm. As previously explained, using lookup table Tab5_Perm enables delivering data masked by mask Mask5_Perm.

[0162] The next operation is a new mask refresh operation 5025 (refresh mask 2) applied to masked data C_Data5_NlinPerm. During this operation, the mask Mask5_Perm used to mask data C_Data5_NlinPerm is modified by using mask Mask5_2. Mask Mask5_2 is different from or the same as mask Mask5_1. More specifically, mask refresh operation 5025 includes the following operations:

[0163] A de-masking operation using mask Mask5_Perm; and

[0164] A masking operation using mask Mask5_2.

[0165] The result of operation 5025 is data C_Data5_Nlin masked by mask Mask5_2.

[0166] Execution of the data path 502 continues with the software application of a second linear operation 5026 (Op Lin 2) to the masked data C_Data5_Nlin. The result of operation 5026 is the masked data C_Data5_lin2. The same second linear operation 5027 (Op Lin 2) as operation 5026 is applied in parallel in hardware to the mask Mask5_2 of the masked data C_Data5_Nlin. The result of operation 5027 is the mask Mask5_2_lin2. At this stage, the data C_Data5_lin2 can be unmasked with the mask Mask5_2_lin2.

[0167] The operation round of the data path 502 for the first round is completed. The data C_Data5_lin2, the mask Mask5_2_lin2, and the lookup table Tab5_Perm can be fed back in place of, with respect to the data C_Data5, the mask Mask5_1, and the lookup table Tab5_Perm, to start the next round.

[0168] As an overview, as in the embodiment for Figures 3 to 6 each linear operation is applied in parallel in software to the masked data and in hardware to its mask in order to apply the data path. Further, each non - linear operation is surrounded by a mask - changing operation and implemented with the aid of a lookup table.

[0169] This embodiment has the same advantages as the embodiment described with respect to Figures 3 to 5 Further, another advantage of this embodiment is the ability to avoid the operation of refreshing the lookup table during the execution of the data path, which can make this execution faster.

[0170] Further, in some cases, the various embodiments described with respect to Figures 3 to 7 can be able to reduce the component size in the component 21 of the circuit that can implement the operations of the data path of the encryption algorithm of the device 20 while maintaining the computing performance, thus enabling the device 20 to be more compact and more affordable.

[0171] With respect to Figures 3 to 7 Another advantage of the described embodiments is that they achieve a more protected execution of known encryption algorithms. In fact, the data remains masked during all its hardware and software processing, which provides mathematical protection for the encryption algorithm. Moreover, this execution makes physical attacks more difficult, thus providing additional protection for the encryption algorithm.

[0172] Various embodiments and variations have been described. Those skilled in the art will understand that certain features of these various embodiments and variations can be combined, and those skilled in the art will think of other variations. With respect to Figures 3 to 7The described embodiments can be applied to any type of encryption algorithm in a round, i.e., encrypting an algorithm with a data path that includes at least one linear operation and at least one nonlinear operation arranged in any way. As an example, the encryption algorithm is a block cipher algorithm such as AES (Advanced Encryption Standard), SM4, and GOST R 34.12-2015 or a stream cipher algorithm.

[0173] Specifically, AES (Advanced Encryption Standard) is a known encryption algorithm in a round. The data path implemented by AES is formed by the following three consecutive encryption operations:

[0174] Substitution operation (SubBytes), which is a nonlinear operation;

[0175] Row shift operation (ShiftRows), which is a linear operation; and

[0176] Column mixing operation (MixColumns), which is a linear operation.

[0177] Finally, based on the functional indications given above, the actual implementation of the described embodiments and variations is within the capabilities of those skilled in the art. Specifically, those skilled in the art will be able to adapt the implementation to the data path of an encryption algorithm that includes multiple nonlinear operations and more than two linear operations.

[0178] Referring to the accompanying drawings and the tables provided in parentheses discussed herein, example embodiments are outlined below by way of example.

[0179] In an embodiment, a method for an electronic device (20) to implement a symmetric data encryption algorithm in rounds includes steps of performing the following operations: data masking operations and demasking operations (1011, 1024; 2011, 2025; 3011, 3024, 3025; 4011, 4025; 5011, 5024, 5025) performed in a hardware manner; linear operations (1021, 1025; 2021, 2026; 3021, 3026; 4021, 4026; 5021, 5026) applied to data in a software manner; and non-linear operations (1023; 2023; 3023; 4023; 5023) in a software or hardware manner. In an embodiment, the symmetric data encryption algorithm includes a data path (12) and a key path (11), and the masking operations and demasking operations (1011, 1024; 2011, 2025; 3011, 3024, 3025; 4011, 4025; 5011, 5024, 5025), the linear operations (1021, 1025; 2021, 2026; 3021, 3026; 4021, 4026; 5021, 5026) and the non-linear operations (1023; 2023; 3023; 4023; 5023) are operations of the data path.

[0180] In an embodiment, the masking operation and the unmasking operation include a masking operation (1011; 2011; 3011, 3025; 4011; 5011), an unmasking operation (3024), and a mask refreshing operation (1024; 2025; 4025; 5024, 5025). In an embodiment, each non-linear operation (1023; 2023; 4023; 5023) is followed by a masking operation or an unmasking operation (1024; 2025; 4025; 5025). In an embodiment, each non-linear operation (1023; 2023; 4023; 5023) is followed by a masking operation or an unmasking operation (1024; 2025; 4025; 5025), and each non-linear operation (1023; 2023; 4023; 5023) is followed by a mask refreshing operation (1024; 2025; 4025; 5025). In an embodiment, each non-linear operation (1023; 2023; 4023; 5023) is followed by a masking operation or an unmasking operation (1024; 2025; 4025; 5025), and each non-linear operation (3023) is followed by a masking operation (3025). In an embodiment, each non-linear operation (3023; 5023) is preceded by a masking operation and an unmasking operation (3024; 5024). In an embodiment, each non-linear operation (3023; 5023) is preceded by a masking operation and an unmasking operation (3024; 5024), and each non-linear operation (3023) is preceded by an unmasking operation (3024). In an embodiment, each non-linear operation (3023; 5023) is preceded by a masking operation and an unmasking operation (3024; 5024), and each non-linear operation (5023) is preceded by a mask refreshing operation (5024). In an embodiment, the mask refreshing operation (2025; 4025) is implemented by using a look-up table (Tab2_2; Tab4_2). In an embodiment, the encryption algorithm further includes a step of implementing a look-up table refreshing operation (2024; 4024). In an embodiment, the non-linear operation (5023) is implemented by using a look-up table (Tab5_Perm). In an embodiment, the encryption algorithm is a block cipher algorithm, such as: AES (Advanced Encryption Standard), SM4, and GOST R34.12-2015, or a stream cipher algorithm. In an embodiment, the encryption algorithm in a round uses a logical addition function to use masking.

[0181] In an embodiment, an electronic device (20) implements a symmetric encryption algorithm, including steps of performing the following operations: data masking operations and demasking operations (1011, 1024; 2011, 2025; 3011, 3024, 3025; 4011, 4025; 5011, 5024, 5025) in a hardware manner; linear operations (1021, 1025; 2021, 2026; 3021, 3026; 4021, 4026; 5021, 5026) applied to data in a software manner; and non-linear operations (1023; 2023; 3023; 4023; 5023) in a software or hardware manner. In an embodiment, the symmetric data encryption algorithm includes a data path (12) and a key path (11), and the masking operations and demasking operations (1011, 1024; 2011, 2025; 3011, 3024, 3025; 4011, 4025; 5011, 5024, 5025), the linear operations (1021, 1025; 2021, 2026; 3021, 3026; 4021, 4026; 5021, 5026), and the non-linear operations (1023; 2023; 3023; 4023; 5023) are operations of the data path.

[0182] In an embodiment, the masking operation and the unmasking operation include a masking operation (1011; 2011; 3011, 3025; 4011; 5011), an unmasking operation (3024), and a mask refreshing operation (1024; 2025; 4025; 5024, 5025). In an embodiment, each non-linear operation (1023; 2023; 4023; 5023) is followed by a masking operation or an unmasking operation (1024; 2025; 4025; 5025). In an embodiment, each non-linear operation (1023; 2023; 4023; 5023) is followed by a masking operation or an unmasking operation (1024; 2025; 4025; 5025), and each non-linear operation (1023; 2023; 4023; 5023) is followed by a mask refreshing operation (1024; 2025; 4025; 5025). In an embodiment, each non-linear operation (1023; 2023; 4023; 5023) is followed by a masking operation or an unmasking operation (1024; 2025; 4025; 5025), and each non-linear operation (3023) is followed by a masking operation (3025). In an embodiment, each non-linear operation (3023; 5023) is preceded by a masking operation and an unmasking operation (3024; 5024). In an embodiment, each non-linear operation (3023; 5023) is preceded by a masking operation and an unmasking operation (3024; 5024), and each non-linear operation (3023) is preceded by an unmasking operation (3024). In an embodiment, each non-linear operation (3023; 5023) is preceded by a masking operation and an unmasking operation (3024; 5024), and each non-linear operation (5023) is preceded by a mask refreshing operation (5024). In an embodiment, the mask refreshing operation (2025; 4025) is implemented by using a look-up table (Tab2_2; Tab4_2). In an embodiment, the encryption algorithm further includes a step of implementing a look-up table refreshing operation (2024; 4024). In an embodiment, the non-linear operation (5023) is implemented by using a look-up table (Tab5_Perm). In an embodiment, the encryption algorithm is a block cipher algorithm, such as: AES (Advanced Encryption Standard), SM4, and GOST R34.12-2015 or a stream cipher algorithm. In an embodiment, the encryption algorithm in a round uses a logical addition function to use masking.

[0183] In an embodiment, a method includes: performing multiple rounds of a symmetric data encryption algorithm using an electronic device that includes hardware data processing circuitry and software data processing circuitry; and protecting the execution of the multiple rounds of the symmetric data encryption algorithm, the protection including: performing a data masking operation and a demasking operation using the hardware data processing circuitry; performing a linear operation applied to data using the software data processing circuitry; performing a linear operation applied to a mask using the hardware data processing circuitry; and performing a non-linear operation applied to data using one of the hardware data processing circuitry or the software data processing circuitry. In an embodiment, a method includes: performing a linear operation on a mask in parallel with performing the same linear operation on data. In an embodiment, the symmetric data encryption algorithm employs a data path and a key path, and the data masking operation and demasking operation, the linear operation applied to data, and the non-linear operation applied to data are operations of the data path. In an embodiment, the data masking operation and demasking operation include a masking operation, a demasking operation, and a mask refreshing operation. In an embodiment, a masking operation or a demasking operation follows each non-linear operation. In an embodiment, a mask refreshing operation follows each non-linear operation. In an embodiment, a masking operation follows each non-linear operation. In an embodiment, a masking operation and a demasking operation precede each non-linear operation. In an embodiment, a demasking operation precedes each non-linear operation. In an embodiment, a mask refreshing operation precedes each non-linear operation. In an embodiment, the mask refreshing operation is implemented using one or more look-up tables. In an embodiment, the method includes performing a look-up table refreshing operation. In an embodiment, the non-linear operation performed by the hardware processing circuitry is performed using one or more look-up tables. In an embodiment, the encryption algorithm is a block cipher algorithm or a stream cipher algorithm. In an embodiment, the data masking operation is performed using a logical addition function.

[0184] In an embodiment, a device includes: hardware data processing circuitry; and software data processing circuitry coupled to the hardware data processing circuitry, wherein in operation, the device: performs multiple rounds of a symmetric data encryption algorithm; and protects the execution of the multiple rounds of the symmetric data encryption algorithm, wherein the protection includes: performing data masking and demasking operations using the hardware data processing circuitry; performing linear operations applied to data using the software data processing circuitry; performing linear operations applied to a mask using the hardware data processing circuitry; and performing non-linear operations applied to data using one of the hardware data processing circuitry or the software data processing circuitry. In an embodiment, the protection includes: applying a linear operation to a mask in parallel with applying the same linear operation to data. In an embodiment, the symmetric data encryption algorithm employs a data path and a key path, and the data masking and demasking operations, the linear operations applied to data, and the non-linear operations applied to data are operations of the data path. In an embodiment, the data masking and demasking operations include masking operations, demasking operations, and mask refreshing operations. In an embodiment, each non-linear operation is followed by a mask refreshing operation. In an embodiment, each non-linear operation is preceded by a demasking operation. In an embodiment, each non-linear operation is preceded by a mask refreshing operation. In an embodiment, the mask refreshing operation is implemented using one or more look-up tables. In an embodiment, the non-linear operations performed by the hardware processing circuitry are performed using one or more look-up tables.

[0185] In an embodiment, a system includes: an application processor; and cryptographic circuitry coupled to the application processor and including hardware processing circuitry and software processing circuitry, wherein in operation, the cryptographic circuitry: performs multiple rounds of a symmetric data encryption algorithm; and protects the execution of the multiple rounds of the symmetric data encryption algorithm, wherein the protection includes: performing data masking and demasking operations using the hardware processing circuitry; performing linear operations applied to data using the software processing circuitry; performing linear operations applied to a mask using the hardware processing circuitry; and performing non-linear operations applied to data using one of the hardware processing circuitry or the software processing circuitry. In an embodiment, the protection includes: applying a linear operation to a mask in parallel with applying the same linear operation to data. In an embodiment, the symmetric data encryption algorithm employs a data path and a key path, and the data masking and demasking operations, the linear operations applied to data, and the non-linear operations applied to data are operations of the data path. In an embodiment, the data masking and demasking operations include masking operations, demasking operations, and mask refreshing operations. In an embodiment, the hardware processing circuitry includes one or more look-up tables.

[0186] Some embodiments may take the form of, or include, a computer program product. For example, according to one embodiment, a computer-readable medium is provided that includes a computer program suitable for performing one or more of the above-described methods or functions. The medium may be a physical storage medium, such as, for example, a read-only memory (ROM) chip, or it may be a disk, such as a digital versatile disk (DVD-ROM), a compact disk (CD-ROM), a hard disk, a memory, a network, or a portable media item readable by a suitable drive or via a suitable connection, including one or more barcodes or other related codes encoded on one or more such computer-readable media and readable by a suitable reader device.

[0187] In addition, in some embodiments, some or all of the methods and / or functionality may be implemented or provided in other ways, such as at least partially in firmware and / or hardware, including but not limited to one or more application specific integrated circuits (ASICs), digital signal processors, discrete circuit devices, logic gates, standard integrated circuits, controllers (e.g., by executing appropriate instructions and including microcontrollers and / or embedded controllers), field programmable gate arrays (FPGAs), complex programmable logic devices (CPLDs), etc., as well as devices employing RFID technology and various combinations thereof.

[0188] The various embodiments described above may be combined to provide other embodiments. Aspects of the embodiments may be modified if concepts from various patents, applications, and publications are required to provide other embodiments.

[0189] In view of the description detailed above, these and other changes may be made to the embodiments. Generally, in the following claims, the terms used should not be construed as limiting the claims to the specific embodiments disclosed in this specification and the claims, but should be construed to include all possible embodiments and the full scope of equivalents to such claims. Thus, the claims are not limited by the present disclosure.

Claims

1. A method for protecting an encryption algorithm, comprising: using an electronic device to perform multiple rounds of a symmetric data encryption algorithm, the electronic device including a hardware data processing circuit device and a software data processing circuit device; and protecting the execution of the multiple rounds of the symmetric data encryption algorithm, the protection including: using the hardware data processing circuit device to perform data masking and demasking operations; using the software data processing circuit device to perform linear operations applied to data; using the hardware data processing circuit device to perform linear operations applied to masks; and using one of the hardware data processing circuit device or the software data processing circuit device to perform a non-linear operation applied to data, wherein in a current round, a mask refresh operation precedes each non-linear operation on the data, and wherein the mask refresh operation is implemented using one or more lookup tables.

2. The method according to claim 1, comprising: performing a linear operation on a mask in parallel with performing the same linear operation on data.

3. The method according to claim 1, wherein the symmetric data encryption algorithm employs a data path and a key path, and the data masking and demasking operations, the linear operations applied to data, and the non-linear operations applied to data are operations of the data path.

4. The method according to claim 1, wherein the data masking and demasking operations include a masking operation, a demasking operation, and a mask refresh operation.

5. The method according to claim 1, wherein a masking or demasking operation follows each non-linear operation.

6. The method according to claim 4, wherein a mask refresh operation follows each non-linear operation.

7. The method according to claim 4, wherein a masking operation follows each non-linear operation.

8. The method according to claim 1, wherein a masking and demasking operation precedes each non-linear operation.

9. The method according to claim 4, wherein a demasking operation precedes each non-linear operation.

10. The method according to claim 1, comprising performing a lookup table refresh operation.

11. The method according to claim 1, wherein the non-linear operation performed by the hardware data processing circuit device is performed using one or more lookup tables.

12. The method according to claim 1, wherein the encryption algorithm is a block cipher algorithm or a stream cipher algorithm.

13. The method according to claim 1, wherein the data masking operation is performed using a logical addition function.

14. A device for protecting an encryption algorithm, comprising: a hardware data processing circuit device; and a software data processing circuit device coupled to the hardware data processing circuit device, wherein in operation, the device: performs multiple rounds of a symmetric data encryption algorithm; and protects the execution of the multiple rounds of the symmetric data encryption algorithm, wherein the protection includes: using the hardware data processing circuit device to perform data masking and demasking operations; using the software data processing circuit device to perform linear operations applied to data; Use the hardware data processing circuit device to perform a linear operation applied to a mask; and Use one of the hardware data processing circuit device or the software data processing circuit device to perform a non-linear operation applied to data, wherein in the current round, a mask refresh operation precedes each non-linear operation on the data, and wherein the mask refresh operation is implemented using one or more look-up tables.

15. The apparatus according to claim 14, wherein the protection comprises: In parallel with applying the same linear operation to the data, apply a linear operation to the mask.

16. The apparatus according to claim 14, wherein the symmetric data encryption algorithm employs a data path and a key path, and the data masking and unmasking operations, the linear operations applied to the data, and the non-linear operations applied to the data are operations of the data path.

17. The apparatus according to claim 14, wherein the data masking and unmasking operations comprise a masking operation, an unmasking operation, and a mask refresh operation.

18. The apparatus according to claim 17, wherein a mask refresh operation follows each non-linear operation.

19. The apparatus according to claim 17, wherein an unmasking operation precedes each non-linear operation.

20. The apparatus according to claim 17, wherein the mask refresh operation is implemented using one or more look-up tables.

21. The apparatus according to claim 17, wherein the non-linear operations performed by the hardware data processing circuit device are performed using one or more look-up tables.

22. A system for protecting an encryption algorithm, comprising: An application processor; and A cryptographic circuit device, coupled to the application processor and comprising a hardware processing circuit device and a software processing circuit device, wherein in operation, the cryptographic circuit device: Performs multiple rounds of a symmetric data encryption algorithm; and Protects the execution of the multiple rounds of the symmetric data encryption algorithm, wherein the protection comprises: Use the hardware processing circuit device to perform data masking and unmasking operations; Use the software processing circuit device to perform linear operations applied to the data; Use the hardware processing circuit device to perform linear operations applied to a mask; and Use one of the hardware processing circuit device or the software processing circuit device to perform non-linear operations applied to the data, wherein in the current round, a mask refresh operation precedes each non-linear operation applied to the data, and wherein the mask refresh operation is implemented using one or more look-up tables.

23. The system according to claim 22, wherein the protection comprises: In parallel with applying the same linear operation to the data, apply a linear operation to the mask.

24. The system according to claim 22, wherein the symmetric data encryption algorithm employs a data path and a key path, and the data masking and unmasking operations, the linear operations applied to the data, and the non-linear operations applied to the data are operations of the data path.

25. The system according to claim 22, wherein the data masking and unmasking operations include a masking operation, an unmasking operation, and a mask refreshing operation.

26. The system according to claim 22, wherein the hardware processing circuitry includes one or more look-up tables.

Citation Information

Patent Citations

  • Cryptographic operations employing non-linear share encoding for protecting from external monitoring attacks

    US20190296898A1