Obfuscating cryptographic parameters used in elliptic curve cryptography and related systems and devices

By using randomized scalars and non-zero constants in elliptic curve cryptography to blind the private key, the problem of side-channel attacks is solved, effective obfuscation of private key information and maintenance of computational efficiency are achieved, and cryptographic security is improved.

CN114830597BActive Publication Date: 2025-09-19MICROCHIP TECHNOLOGY INC
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202080086611.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2019-12-17
Filing Date
2020-10-30
Publication Date
2025-09-19
Estimated Expiration
2040-10-30

AI Technical Summary

Technical Problem

In existing elliptic curve cryptography, side-channel attacks obtain private key information by observing the physical and electrical process characteristics of the device, threatening the security of the password. In addition, existing obfuscation methods are inefficient or affect the computing speed.

Method used

An obfuscation process is used to blind the private key by using a randomized scalar and a non-zero constant to ensure that the private key presents a non-zero feature in point multiplication, reducing the correlation between device characteristics and calculation inputs. The new formula f = e + w + z is used to perform point multiplication to ensure that computational efficiency is not reduced.

Benefits of technology

Effectively obfuscate private key information, reduce the success rate of side-channel attacks, while maintaining computational efficiency, preventing private key information from being reverse analyzed, and improving cryptographic security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114830597B_ABST
    Figure CN114830597B_ABST
Patent Text Reader

Abstract

This disclosure describes an obfuscation process for obfuscating cryptographic parameters of cryptographic operations, such as calculations used in elliptic curve cryptography and elliptic curve point multiplication. This obfuscation process can be used to obfuscate device characteristics that might otherwise reveal information about the cryptographic parameters, the cryptographic operations, or cryptographic operations more generally, such as information sometimes gleaned from side-channel and lattice attacks.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] CROSS-REFERENCE TO RELATED APPLICATIONS

[0002] This application claims the benefit under 35 U.S.C. §199(e) of U.S. Provisional Patent Application Serial No. 62 / 949,285, filed on December 17, 2019, the disclosures of each of which are hereby incorporated by reference in their entirety. Technical Field

[0003] One or more embodiments relate generally to elliptic curve cryptography, and more particularly, some embodiments relate more generally to obfuscating parameters and device operations when performing elliptic curve cryptography. Background Art

[0004] Cryptography uses a wide range of computations, including calculating private, shared, and public keys. Devices that perform these computations are used to facilitate secure and trusted communications between devices.

[0005] With the development of network communications, cryptographic schemes have become more advanced and complex. Methods for attacking and circumventing such cryptographic schemes have also become more sophisticated, necessitating further advancements in technical security. Side-channel attacks are a form of attack that uses information gleaned from a system's implementation rather than exploiting weaknesses in the algorithm itself. Therefore, the inventors of the present disclosure recognized that it would be advantageous to obfuscate and blind the physical and electrical processes exhibited by devices performing cryptographic calculations. BRIEF DESCRIPTION OF THE DRAWINGS

[0006] To easily identify the discussion of any particular element or act, the most significant digit or digits in a reference number refer to the figure number in which the element is first introduced.

[0007] Figure 1 is a flow chart depicting a specific exemplary encryption and information sharing process that can be improved according to an embodiment.

[0008] Figure 2A is a flow chart depicting a specific exemplary process that can be improved according to an embodiment.

[0009] Figure 2B is a flow chart depicting a specific exemplary process that can be improved according to an embodiment.

[0010] Figure 3 is a flow chart depicting a general process for performing obfuscated cryptographic operations according to one embodiment.

[0011] Figure 4A and Figure 4B is a flow chart depicting a process for obfuscating cryptographic operations according to one or more embodiments.

[0012] Figure 5 is a functional block diagram depicting circuitry for obfuscating cryptographic operations according to one or more embodiments.

[0013] Figure 6 is a block diagram depicting a system including an encryption engine of an electronic system according to one embodiment, the electronic system being configured according to Figure 3 as well as Figure 4A and Figure 4B The process described and Figure 5 The circuit depicted is used to obfuscate cryptographic operations.

[0014] Figure 7 are block diagrams depicting circuits that, in some embodiments, may be used to implement the various functions, operations, actions, processes and / or methods disclosed herein, including in hardware circuits. DETAILED DESCRIPTION

[0015] In the following detailed description, reference is made to the accompanying drawings that form a part of the present disclosure, and specific examples of embodiments in which the present disclosure may be implemented are shown by way of example in the accompanying drawings. These embodiments are described in sufficient detail to enable one of ordinary skill in the art to practice the present disclosure. However, other embodiments may be utilized, and changes in structure, materials, and processes may be made without departing from the scope of the present disclosure. The illustrations presented herein are not intended to be actual views of any particular method, system, device, or structure, but are merely idealized representations for describing embodiments of the present disclosure. The drawings presented herein are not necessarily drawn to scale. For the convenience of the reader, similar structures or components in the various figures may retain the same or similar numbering; however, the similarity of numbering does not mean that the structures or components must be identical in size, composition, configuration, or any other attribute.

[0016] It should be readily understood that the components of the embodiments as generally described herein and illustrated in the accompanying drawings may be arranged and designed in many different configurations. Therefore, the following description of various embodiments is not intended to limit the scope of the present disclosure, but rather is merely representative of various embodiments. Although various aspects of the embodiments may be presented in the accompanying drawings, the drawings are not necessarily drawn to scale unless otherwise indicated.

[0017] In addition, the specific embodiments shown and described are examples and should not be construed as the only way to implement the present disclosure, unless otherwise indicated herein. Components, circuits, and functions may be shown in block diagram form so as not to obscure the present disclosure with unnecessary detail. On the contrary, the specific embodiments shown and described are merely exemplary and should not be construed as the only way to implement the present disclosure, unless otherwise indicated herein. In addition, the block definitions and the partitioning of logic between the various blocks are examples of specific embodiments. It will be apparent to one of ordinary skill in the art that the present disclosure can be practiced through many other partitioning solutions. In most cases, details regarding timing considerations, etc. have been omitted where such details are not required for a complete understanding of the present disclosure and are within the capabilities of one of ordinary skill in the relevant art.

[0018] Those skilled in the art will appreciate that information and signals may be represented using any of a variety of different technologies and techniques. For example, data, instructions, commands, information, signals, bits, symbols, and chips that may be referenced throughout this specification may be represented by voltages, currents, electromagnetic waves, magnetic fields or particles, optical fields or particles, or any combination thereof. For clarity of presentation and description, some figures may illustrate signals as single signals. Those skilled in the art will appreciate that a signal may represent a signal bus, where the bus may have a variety of bit widths, and that the present disclosure may be implemented on any number of data signals, including a single data signal.

[0019] The various illustrative logical blocks, modules, and circuits described in conjunction with the embodiments disclosed herein may be implemented or executed with a general-purpose processor, a special-purpose processor, a digital signal processor (DSP), an integrated circuit (IC), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic device, discrete gate or transistor logic components, discrete hardware components, or any combination thereof designed to perform the functions described herein. A general-purpose processor (also referred to herein as a host processor or simply a host) may be a microprocessor, but in the alternative, the processor may be any conventional processor, controller, microcontroller, or state machine. The processor may also be implemented as a combination of computing devices, such as a combination of a DSP and a microprocessor, a plurality of microprocessors, one or more microprocessors combined with a DSP core, or any other such configuration. A general-purpose computer including a processor is considered a special-purpose computer when it is configured to execute computing instructions (e.g., software code) related to the embodiments of the present disclosure.

[0020] The embodiment can be described according to a process depicted as a flow chart, a flow diagram, a structure diagram or a block diagram. Although a flow chart can describe an operational action as a continuous process, many of these actions can be performed in another sequence, in parallel or substantially simultaneously. In addition, the order of the actions can be rearranged. The process can correspond to a method, a thread, a function, a process, a subroutine, a subprogram, etc. In addition, the method disclosed herein can be implemented by hardware, software or both. If implemented in software, these functions can be stored or transmitted as one or more instructions or codes on a computer-readable medium. Computer-readable media includes both computer storage media and communication media, and the communication media includes any medium that is conducive to transferring a computer program from one location to another.

[0021] Any reference to an element herein using designations such as "first," "second," etc. does not limit the quantity or order of those elements unless such limitations are explicitly stated. Rather, these designations may be used herein as a convenient method of distinguishing between two or more elements or instances of an element. Thus, reference to a first element and a second element does not mean that only two elements can be employed there, or that the first element must precede the second element in some manner. Furthermore, a group of elements may include one or more elements unless otherwise indicated.

[0022] As used herein, the term "substantially" with respect to a given parameter, property, or condition refers to and includes the degree to which a person of ordinary skill in the art would understand that the given parameter, property, or condition is satisfied with a small degree of variance, such as, for example, within acceptable manufacturing tolerances. By way of example, depending on the specific parameter, property, or condition that is substantially satisfied, the parameter, property, or condition may be satisfied by at least 90%, by at least 95%, or even by at least 99%.

[0023] As used herein, reference to a "cryptographic process" refers to operations that include computations that form part or all of a protocol related to performing encryption and decryption, generating and resolving keys, subkeys, or performing any other steps or computations related to cryptography or cryptography. A cryptographic process may be performed by a device, such as a cryptographic processor or general-purpose processor that performs a portion of the protocol based on firmware or software. Non-limiting examples of cryptographic processes include algorithms for generating cryptographic information (e.g., for generating public keys, private keys, shared keys, and any various intermediate keys, but not limited thereto), and protocols for exchanging cryptographic information, identity information, and for agreeing on a protocol.

[0024] As used herein, "obfuscate device characteristics" means obscuring or clarifying any externally observable characteristics of a device and the information gleaned therefrom, including but not limited to characteristics of the device during operation. Such characteristics may include, but are not limited to, power consumption, timing information, magnetic field information, thermal signature information, other similar characteristics, and combinations thereof. Obfuscation does not mean that information cannot be discerned from the device characteristics, although that may be the case. Instead, obfuscation is intended to include rendering such information less useful or requiring more processing to render such information useful.

[0025] Long strings of zeros in the private key allow hackers to gather information about the private key by analyzing the chip's power signature during calculations. To completely conceal the value of the private key used in cryptographic operations, the private key's value is obfuscated using a random number of the same length as the private key. Additionally, a dedicated constant value is added to the private key to ensure that any relevant portion of the key is non-zero. A modified algorithm for processing the private key is then used to extract the correct information from the obfuscated private key.

[0026] Figure 1 is a swim-lane flow chart depicting a cryptographic information exchange process 100 between two parties (Party A and Party B) according to the prior art known to the inventors of this disclosure (eg, public / private key authentication and / or key agreement protocol, but not limited thereto). Figure 1 It is also a non-limiting example of an encrypted information exchange process that can be improved by the obfuscation disclosed herein.

[0027] Figure 1 The depicted information exchange may occur over any suitable communication link for sending and receiving messages established via any suitable combination / subcombination of connections via wired / wireless pathways. Connections may include, but are not limited to, network connections such as the Internet or a private network, local connections that do not require Internet or network access, communication interfaces such as interfaces for serial and parallel communication, and combinations / subcombinations thereof.

[0028] In operation 102, parties A and B of process 100 exchange their public keys with each other. As non-limiting examples, party A and / or party B may retrieve respective previously generated public keys or use previously generated private keys to generate their respective public keys and send such public keys to each other.

[0029] In operations 104 and 106, parties A and B of process 100 each compute a shared secret key using their respective private keys and the public key received from operation 102. As non-limiting examples, the computations performed in operations 104 and 106 may include cryptographic operations based on cryptographic algorithms used for public / private key authentication (e.g., so-called "sign and verify," but not limited thereto) or for a particular cryptographic agreement protocol implemented by parties A and B. Non-limiting examples of cryptographic agreement protocols include Elliptic Curve Diffie-Hellman or the Elliptic Curve Digital Signature Algorithm. Non-limiting examples of cryptographic algorithms include Elliptic Curve Point Multiplication and Modular Exponentiation.

[0030] exist Figure 1 In the depicted example, once the necessary cryptographic information for the key agreement protocol is successfully calculated in operation 114 and a secure communication link is established, Party A and Party B can, in theory, communicate with each other using the secure communication link, and more specifically, using public key encryption such as "sign and verify." In operation 108, Party A of process 100 encrypts information using the shared key calculated in operation 104. In operation 110, Party A sends a message to Party B that includes the encrypted information from operation 108. In operation 112, Party B decrypts the encrypted information received from Party A using the shared key calculated in operation 106 and any other tools previously agreed upon by both parties (such as Party A's public key shared in operation 102).

[0031] In a process such as process 100 , where parties exchange encrypted information, party A and party B may perform any one of a number of cryptographic operations, and these cryptographic operations may be observed by an attacker. Figure 2A and Figure 2B Depicting two non-limiting examples of cryptographic processes that can be observed: Figure 2A Depicts a process 200a for obtaining a public key using elliptic curve point multiplication, and Figure 2B A process 200b of obtaining a shared secret key using elliptic curve point multiplication is depicted.

[0032] In the case of elliptic curve cryptographic point multiplication, the private key is a cryptographic parameter "a" that specifies the transformation from a generator point G to a destination point P on a given elliptic curve. A non-limiting example of an algorithm that can be used to get from a generator point G to a destination point P on an elliptic curve is to multiply the generator point G by itself a certain number of times or to double it and then add it to itself (so-called "double addition"). In this case, the private key is the number of times the generator point G is multiplied by itself. Note that by convention, additive algorithms fall under the term "elliptic curve point multiplication", so dG can refer to exponential operations G1, G2...Gd, and can refer to additive operations G, 2G, 3G...dG. The specific non-limiting example used herein is additive, but other forms of point multiplication (including exponential) are within the scope of this disclosure and are specifically contemplated. Elliptic curve point multiplication will be discussed mathematically later in this article.

[0033] Go to Figure 2A In the specific example depicted, in operation 202, process 200a obtains a generator point G on a given elliptic curve. As non-limiting examples, the generator point G and elliptic curve function can be obtained from an organization that shares the generator point G and elliptic curve function, or shares the elliptic curve function and parameters for calculating the generator point G. The parties to the encrypted communication can agree in advance to use a predetermined generator point G or elliptic curve function, a generator point G or elliptic curve function provided by a specific organization, or the calculation method and parameters thereof. Generator point G is sometimes also referred to as a base point Q.

[0034] In operation 204, process 200a obtains a private key "a". The private key can be a number or a string of characters. The private key can be pre-calculated and stored as needed, or calculated on the fly.

[0035] In operation 206, process 200a calculates a public key "Ha" based at least in part on its private key "a." The relationship between the public key Ha, the private key "a," and the generator point G is represented by Equation 1:

[0036] aG=H a

[0037] Equation (1)

[0038] More specifically, the public key Ha may be calculated by performing a point multiplication algorithm using the private key 'a' and the generator point G.

[0039] In operation 208, the process 200a shares the public key Ha with the other party and obtains the other party's public key "Hb".

[0040] Go to Figure 2BIn the specific example depicted in operation 210, process 200b calculates a shared key "S." For example, process 200b may calculate the shared key "S" using the other party's public key Hb and its own private key "a" according to Equation 2:

[0041] aH b =S equation (2)

[0042] Similarly, the other party uses its private key and public key Ha to calculate another shared key "S." Note that if each party uses its own private key to calculate its public key, and uses the other party's public key and its own private key to calculate the shared key "S," then each party's corresponding calculation of the shared key S is affected by the other party's private key.

[0043] In operation 212, the shared key "S" obtained from operation 210 is stored. If the key agreement protocol is executed as expected, the shared key "S" is known to both parties A and B. Because the shared key "S" is never actually exchanged between the parties executing the key agreement protocol, an unauthorized party eavesdropping on their communications has no opportunity to intercept it. Therefore, the shared key "S" can be securely used to encrypt and decrypt information transmitted between parties A and B. For example, in a typical implementation of an Elliptic Curve Diffie-Hellman key exchange, the shared key "S" can be used to derive a session key for encrypted communications.

[0044] Each of the cryptographic processes illustrated by process 200a and process 200b may include one or more cryptographic operations. For example, elliptic curve point multiplication may be used to calculate the public key Ha in operation 206 of process 200a and may also be used to calculate the shared key "S" in operation 210 of process 200b.

[0045] An attacker wishes to discern information about cryptographic operations that rely on secret cryptographic parameters and cryptographic information, such as, but not limited to, private keys and shared keys. One technique used by some attackers is to observe characteristics exhibited by a device that performs cryptographic operations that use secret cryptographic information. Non-limiting examples of characteristics exhibited by a device that can be observed include the timing, power consumption, thermal variations, and magnetic field generation of the device, which can be used by an observer to obtain information about the cryptographic operations performed by the device. Utilizing information observed from the device and a known (or suspected) relationship between the observed information and the inputs to the cryptographic operations, an attacker can obtain the inputs to the cryptographic operations. As a non-limiting example, an attacker can learn the inputs from timing / power characteristics of a device during a computation based at least in part on a known relationship between such inputs and timing / power characteristics.

[0046] By obfuscating one or more cryptographic operations, the known or suspected relationship between the input and the exhibited characteristics becomes weaker, so that the calculation, key, and other secret cryptographic information can be further hidden from attackers.

[0047] Sometimes shortcuts are used to speed up cryptographic operations, for example, to accommodate limitations on processors, power supplies, or memory. The inventors of the present disclosure recognized that these shortcuts can create signatures and resulting characteristics of the device that can be observed and exploited by attackers, including those designed to circumvent or overcome attempts to obfuscate cryptographic processes.

[0048] An important aspect of elliptic curve cryptography (ECC) is elliptic curve point multiplication (ECPM) (ECC using ECPM is also referred to herein as elliptic curve cryptography point multiplication or "ECCPM"). ECPM generates a destination point P on the curve, and the relationship between a base point Q (called a generator point G in ECC) and the destination point P (called a public key Ha in ECC) is a scalar "d" (called a private key "a" in ECC).

[0049] In this disclosure, "point multiplication" is used as a shorthand for "elliptic curve point multiplication." It is not beyond the scope of this disclosure to use point multiplication with other curves for cryptographic operations, such as modular exponentiation, but not limited thereto. It is contemplated that it may be used with non-double-add algorithms (e.g., so-called "compact algorithms," such as X25519 Diffie-Hellman as specified in Internet Research Task Force (IRTF) Request for Comments (RFC)-7748, January 2016, but not limited thereto) and is not beyond the scope of this disclosure, for example, with a converter for converting to and from double-add formats.

[0050] Different methods can be used to prevent the disclosure of a party's private key when performing point multiplication. For example, assuming the elliptic curve E is represented by equation 3:

[0051] E:y 2 =x 3 +ax+b

[0052] Equation (3)

[0053] Assuming that a base point Q on the elliptic curve E is multiplied to reach the destination point P, the relationship between Q and P is expressed by Equation 4, where “*” is the mathematical operator of point multiplication:

[0054] P=d*Q

[0055] Equation (4)

[0056] Algorithm 1 defines a left-to-right binary window-based algorithm for performing point multiplication:

[0057]

[0058] Algorithm 1

[0059] Sometimes shortcuts are used in ECC point multiplication to speed up calculations. As a non-limiting example, to speed up calculations in Algorithm 1, two or more bits (but fewer than all bits) of the scalar "d" are sometimes used for each step. This number of bits is referred to as the u-bit window size, and u bits of the scalar d and the base point Q are used for each iteration of Algorithm 1. Fixed and variable window sizes can be used without exceeding the scope, but unless explicitly stated otherwise, fixed window sizes and fixed windows are used in the embodiments and examples discussed herein.

[0060] Sometimes step 2.2 of Algorithm 1 is skipped, but skipping step 2.2 can result in an observable timing disclosure of the device (e.g., one or more observable characteristics exhibited by the device that can be used to determine timing information). More specifically, to obtain a timing constant-point multiplication, if step 2.2 is skipped, a dummy addition can be added to Algorithm 1. This can obfuscate the timing disclosure, but the dummy computation is the only modification, and the device performing such computation can exhibit observable power signatures corresponding to the only modification. These power signatures can be observed through a side channel attack (SCA), and the zero bit of the scalar can therefore be obtained. After identifying the zero bit, a mesh attack or another attack can be used to recover other bits of the scalar, in some cases including the plaintext bits (i.e., bits that have not been blinded or otherwise transformed).

[0061] As another non-limiting example, in some cases, a plain text scalar can be used for point multiplication. If the same scalar is used and reused for point multiplication, profile attacks and other clustering and related methods can be used to obtain the scalar.

[0062] To address the potential disclosure of scalars, a technique known to the inventors of the present disclosure is to "blind" the scalar before providing it as a parameter of a point multiplication, so that a different blinded scalar is used for each specific point multiplication. Assuming the base point "Q" (a 2-dimensional scalar) of Equation 3 has an order "n" (a 1-dimensional scalar), one method known to the inventors is to form a new randomized scalar k (the scalar "d" may also be referred to herein as a "plain text scalar" to distinguish it from a randomized scalar or a further processed scalar) by simply adding a random number r and the order n, as represented by Equation 5:

[0063] k=d+r*n

[0064] Equation (5)

[0065] By convention, the order "n" is a one-dimensional scalar satisfying n*Q = ∞. Therefore, r*n*Q = ∞, and Equation 5 can be rewritten and expressed as Equation 6:

[0066] k*Q=d*Q+r*n*Q=d*Q+∞=d*Q

[0067] Equation (6)

[0068] Each time a point multiplication is performed, a new random scalar is generated and used. While this approach does obfuscate the contents of the plain text scalar, the inventors of the present disclosure have recognized several shortcomings in these techniques:

[0069] First, if the selected scalar includes runs of consecutive zeros (ie, return-to-zero bits), then special power characteristics may be present and observed if any special addition (ie, virtual addition) is applied to the return-to-zero bits.

[0070] Second, typically, the plaintext scalar d and the order n have the same bit length, and the random number r is typically at least 32 bits long. Therefore, according to Equations 5 and 6, the randomized scalar k will be at least 32 bits longer than the plaintext scalar d, which slows down the ECPM computation (compared to a smaller randomized scalar k). As a specific, non-limiting example, if the plaintext scalar is 8×32 bits, then the ECPM process will be slowed down by 12.5% ​​if the randomized scalar k is generated and used.

[0071] Next, for some ECC curves and base point Q, the order "n" may have a very long, uninterrupted sequence of zero-valued bits. As a specific, non-limiting example, assume that "n" is a 64-bit number with a long, uninterrupted sequence of zero-valued bits. If a 32-bit random number "r" is used to blind "d", at least 32 bits of "d" will not be blinded. In contrast, if a 64-bit random number "r" is used to blind the scalar "d", the randomized scalar "k" will be 64 bits longer than "d", and therefore the calculation will be much slower (more bits of the cryptographic dictionary (crunch) to be generated). In practice, the uninterrupted sequence of zero-valued bits is very long. Therefore, any previously known obfuscation method may not be sufficiently effective (e.g., computationally effective, but not limited to). As a specific, non-limiting example, "n" for the secp224k1 key pair from Equation 5 is n=01 00000000 00000000 00000000 0001DCE8 D2EC6184CAF 0A971 769FB1F7. To obfuscate the entire plaintext scalar "d" using Equation 5 using this order "n," more than 96 bits are added to the plaintext scalar "d," which greatly reduces the efficiency of ECPM.

[0072] Generally speaking, the inventors of the present disclosure recognized a need for an obfuscation process that does not suffer from some or all of the disadvantages described above.

[0073] One or more embodiments of the present invention are generally directed to an obfuscation process that can be applied to cryptographic parameters (eg, but not limited to, private keys) to obtain fully blinded, obfuscated cryptographic parameters, and thereby obfuscate the cryptographic operations of the cryptographic process.

[0074] Figure 3 is a flow chart depicting a general process 300 for obfuscating cryptographic operations of a cryptographic process according to one or more embodiments. As non-limiting examples, process 300 may be applied to the operations of process 200a or process 200b.

[0075] In operation 302, process 300 obtains one or more obfuscation parameters. In one or more embodiments, the obfuscation parameters may include, but are not limited to, one or more of a window size (e.g., in bit length) for a window-based ECPM, a length of the cryptographic parameter to be obfuscated, or a degree of randomness to be applied by the obfuscation process. In one or more embodiments, the length of a private key, a public key, or any other cryptographic parameter may be represented by the number of bits used to represent the parameter, but is not limited thereto.

[0076] In operation 304, process 300 applies an obfuscation process to cryptographic parameters of the cryptographic process (e.g., a private key or a shared key, but not limited thereto) to obtain obfuscated cryptographic parameters. The obfuscation process is applied to the entire cryptographic parameters, and more specifically, may be applied directly or indirectly to continuous, discrete, or window-sized portions of the cryptographic parameters as discussed herein. In one or more embodiments, the window-sized portion of the cryptographic parameters and / or derivatives thereof (e.g., a first obfuscated cryptographic parameter, but not limited thereto) may be continuous or non-continuous.

[0077] Obfuscated cryptographic parameters can be obtained that have a bit length that is substantially the same as the bit length of the cryptographic parameters, i.e., the bit length of the obfuscated cryptographic parameters is not substantially increased relative to the bit length of the original cryptographic parameters. Figure 4A and Figure 4B The first obfuscated cryptographic parameter discussed), a non-zero constant w for the window size, and a random number r for the window size are used to calculate the window size portion of the variable e, the sum of each iteration of these components (e.g., fi) being the window size, and the string of the window size sum (i.e., fi = v->0) having the same bit length as the randomized scalar k and thus the scalar d (the cryptographic parameter). The obfuscation parameters obtained in operation 302 are used as parameters for the obfuscation process applied to the cryptographic parameters. Other parameters may also be used with the obfuscation process without exceeding the scope of the present disclosure.

[0078] In operation 306, process 300 performs a cryptographic operation of the cryptographic process to obtain cryptographic information of the cryptographic process. The obfuscated cryptographic parameters obtained in response to applying the obfuscation process to the cryptographic parameters in operation 304 are used as parameters of the cryptographic operation. The cryptographic operation may include a point multiplication calculation of the ECC discussed herein.

[0079] By performing cryptographic operations using obfuscated cryptographic parameters, device characteristics that may disclose information about the cryptographic operations, cryptographic obfuscation parameters, and cryptographic processes more generally can be obfuscated. As a non-limiting example, if an attacker learns the relationship between the inputs to specific cryptographic operations and the power characteristics exhibited by the devices performing those operations, obfuscation of the cryptographic operations will destroy that relationship and / or the informative value of the power characteristics.

[0080] Figure 4A is a flow chart depicting an obfuscation process 400a for ECC according to one or more embodiments. Obfuscation process 400a is a non-limiting example of an obfuscation process applied to the cryptographic parameters in process 300.

[0081] By way of general discussion, a "naive" or "first" obfuscated cryptographic parameter is generated according to Equation 5A (below) and reformatted into an expression having three components: a random number, a non-zero constant, and a variable component. The random number provides a degree of randomness to the obfuscated cryptographic parameter. The non-zero constant ensures that there are no runs of zeros, and the variable component ensures that the obfuscated cryptographic parameter is related to the first obfuscated cryptographic parameter, and therefore to the cryptographic parameter. Furthermore, by selecting a length for each component and optionally pre-calculating certain results of the ECPM, the entire cryptographic parameter can be blinded without substantially increasing its size (i.e., the obfuscated cryptographic parameter is not significantly longer (in bit length) than the cryptographic parameter), and thus with negligible impact, if any, on the complexity of performing ECPM.

[0082] In operation 402, the obfuscation process 400a obtains one or more obfuscation parameters, such as, but not limited to, a cryptographic parameter length, a window size for each window portion of the cryptographic parameter, and a degree of randomness.

[0083] In operation 404, the obfuscation process 400a applies the first obfuscation process to the cryptographic parameters, thereby obtaining first obfuscated cryptographic parameters. In one embodiment, the first obfuscation process is a transformation of the scalar d into a randomized scalar k according to Equation 5A. A one-dimensional random number r is generated, simply multiplied by the order n and added to the scalar d to generate a new scalar k. The algorithm is generally represented by Equation 5A:

[0084] k=d+r×n

[0085] Equation 5A

[0086] As described above, the degree to which the scalar d is blinded by Equation 5A depends on the number of zero-valued bits of order n and the length of the random number r. Preferably, the bit length of the random number r will be smaller than the order n to simplify processing. Assuming that Equation 7 (discussed below) includes a randomly generated component z, multiplying the order n by the random number r in Equation 5A is optional, in which case k will be the new scalar k, rather than the randomized scalar k.

[0087] In operation 406, the obfuscation process 400a reformats the first obfuscated cryptographic parameter into a randomized expression corresponding to the first obfuscated cryptographic parameter.

[0088] Figure 4B is a flow chart depicting a process 400b for reformatting first obfuscated cryptographic parameters according to one or more embodiments. The randomization expression may have at least three components: a positive non-zero constant w, a random number z, and a variable e relating w and z to k. The randomization expression corresponds to Equation 7:

[0089] k=e+w+z

[0090] Equation 7

[0091] Assuming that the new scalar k has the same bit length as the scalar d, then for Equation 7 to be true, e, w, and z should have the same bit length as the new scalar k and, therefore, scalar d, respectively. The variable e can be calculated by subtracting a nonzero constant w and a random number z from the new scalar k. Each of these components e, w, and z can be stored and used to perform ECCPM. In other words, the right side of the expression in Equation 7 is the input to a standard left-to-right ECCPM.

[0092] For clarity, the reformatted k will be referred to as the new formula f hereinafter. After reformatting, fi(i=v-1,…,0) can be expressed as Equation 8, where v is the number of u-bit-sized parts to be processed, and therefore the number of iterations performed:

[0093] f i=v→0 =((e i,u-1 ...e i,0 )+(w i,u-1 ...w i,0 )+(z i,u-1 ...z i,0 ))

[0094] Equation 8

[0095] Continue to refer Figure 4BAt operation 412, process 400b obtains a first component of an expression corresponding to a first obfuscated cryptographic parameter, the first component having a non-zero constant value. This first component may also be referred to herein as a "non-zero constant w." Using binary arithmetic to minimize computations is preferred, however, using a signed (i.e., positive or negative) binary representation is not beyond the scope of this disclosure.

[0096] The non-zero constant w ensures that the input to the ECPM block as a whole is non-zero, which could otherwise cause the cryptographic hardware executing ECPM to expose unusual power characteristics. The non-zero constant w can be a stored integer that is pre-calculated in advance or calculated for each cryptographic process. The non-zero constant w has a bit length of the window size (i.e., u bits). As a non-limiting example, if a window size of u bits = 3 is used, each window used in the left-to-right binary arithmetic is 3 bits long, and 3 bits are used to represent the non-zero constant w, which can have values ​​from 1 to 7.

[0097] At operation 414, process 400b obtains a second component of the expression corresponding to the first obfuscated cryptographic parameter, the second component having a randomly generated value. This second component may also be referred to herein as a "random number z." The random number z ensures a certain degree of randomness in each operation. The random number z is a randomly generated integer (e.g., using non-deterministic number generation, deterministic number generation, or a combination thereof, but not limited thereto) having the same bit length as the random scalar k or scalar d, or generated for each window-sized portion of the new formula f. For example, if v is the number of discrete (i.e., no common bits between portions) window-sized portions in the first obfuscated cryptographic parameter, and in the non-limiting example, v=10, then the random number z may have v window-sized portions, or the random number zv=0->10 may include ten randomly generated digits, each represented by a number of bits equal to the window size.

[0098] At operation 416, process 400b obtains a third component of the expression corresponding to the first obfuscated cryptographic parameter. The third component has a value corresponding to the difference between the corresponding values ​​of the first obfuscated cryptographic parameter, the first component, and the second component. Because each random number z is generated for a portion of a given window size, the portion of the variable e (i.e., ei) for a particular window size can be calculated by taking the difference between the portion of the first obfuscated cryptographic parameter k (i.e., ki) for a particular window size and the sum of the random number z and a non-zero constant w. Note that the concatenation of ei=v through e0 has a bit length that is substantially the same as the corresponding bit lengths of the first obfuscated cryptographic parameter and the cryptographic parameter.

[0099] When the window-sized portion of e+w+z and the base point Q are successively processed by a binary algorithm from left to right according to the new formula f, the processing is represented by Algorithm 2:

[0100]

[0101] Algorithm 2

[0102] In this new formula, fi(i=v-1,…,0) will no longer be between 0 and (2u-1). The part of each u-bit window size from left to right will never be zero (to avoid recognizable power characteristics and / or the need for dummy calculations), and its actual value can be between 1 and (2u+1-1), in other words, in the case of 2 bits and constant w=1, it is between 1 and 7 due to the effect of the non-zero constant w and the additional randomness z on Equation 7.

[0103] Return to Figure 4A Obfuscation process 400a: For a given window size of u bits, there are a finite number of integer values ​​represented by the expression e+w+z for a given window size portion, and therefore each iteration of Algorithm 2 has a finite number of results, namely 1*Q, 2*Q, 3*Q, ... m*Q, where m is the largest integer represented by the u-bit portion of f. Optionally, in operation 408, obfuscation process 400a calculates and stores the results of at least some cryptographic operations performed in response to the expression having the obtained first component (operation 412 of process 400b), second component (operation 414 of process 400b), and third component (operation 416 of process 400b). As a non-limiting example, obfuscation process 400a calculates and stores the results of performing ECPM in response to the new formula f and window size u. These stored pre-calculated values, or "pre-calculations," can be used for fi*Q (step 2.2) in each iteration of Algorithm 2 to reduce computational complexity.

[0104] The result, and therefore the precomputed quantity, is proportional to the degree of randomness introduced via the random number z. In one or more embodiments, the precomputed quantity m calculated and stored can be selected based on the degree of randomness introduced via the random number z. In various embodiments, the degree of randomness can be reduced by setting the binary value of the bit positions of a portion of the window size of the random number z (e.g., the most significant bit) to binary 1, or can be increased by adding more different random numbers z.

[0105] At operation 410, the obfuscation process 400a performs a fixed-window-based cryptographic operation (eg, fixed-window ECPM or ME, but not limited thereto) of a cryptographic process to obtain cryptographic information of the cryptographic process. Parameters of the cryptographic operation include randomized expressions.

[0106] As used herein, the term "random number" includes both true random numbers and pseudorandom numbers, unless the context would indicate a specific type of random number to one of ordinary skill in the art. As non-limiting examples, random number generation may involve an on-chip non-recursive random number generator, a linear feedback shift register, random number generation software, and combinations thereof. Non-limiting examples of random number generation include deterministic random number generation, non-deterministic random number generation, and combinations thereof.

[0107] Note that, according to the possible conditions discussed above, there are no zero-valued cases, and therefore, unlike conventional techniques known to the inventors of the present disclosure, no special additions are required. The original scalar d is completely / absolutely obfuscated into the new formula f, and the length of uninterrupted zero-valued bits (e.g., consecutive uninterrupted zero-valued bits) from the order n will not affect the obfuscation. This reduces the strength of the correlation between the discrete window-sized parts used in Algorithm 2 when obfuscation has been performed according to the disclosed process. Reducing the strength of the correlation makes it more difficult to perform side-channel attacks (SCA) or other correlation or clustering attacks to obtain the scalar d (more specifically, the cryptographic parameter it represents) relative to conventional obfuscation processes known to the inventors of the present disclosure. Note that the bit length of the new formula f can be the same as or shorter than the bit length of the original scalar d, and therefore, the disclosed obfuscation process does not adversely affect speed (e.g., the computational rate of the cryptographic hardware) compared to conventional obfuscation processes that obtain obfuscated scalars that are longer than the original scalar. Pre-calculation also saves some processing when performing left-to-right binary arithmetic for ECPM, so there may be some trade-off in the time and memory space required to calculate and store the pre-calculation.

[0108] Note that the differences in power characteristics exhibited by devices performing pre-calculations can arise from reading the pre-calculated content, but can also arise from different pre-calculated addresses. In some embodiments, to further blind the content and addresses used for pre-calculations, the pre-calculations can be periodically or randomly blinded / unblinded with different random numbers for each iteration, without adversely affecting the efficiency of the ECC point multiplication.

[0109] Note that in some use cases, there may be physical elements in place to stop attempts to manipulate the original scalar d. In such cases, it may not be necessary to include the random number z in the new formula f, as this would make it more difficult to discern timing information that could be used to attempt to manipulate the scalar d. In such cases, a non-zero offset (i.e., a non-zero constant w) can still be added for each u bits of the original scalar d to limit the number of pre-calculations. Limiting the number of pre-calculations simplifies any blinding of pre-calculated addresses and address contents with different random numbers (e.g., stored pre-calculations).

[0110] It is noted that the available memory space, the degree to which power characteristics are exhibited, the degree to which the cryptographic process is susceptible to external manipulation, and the processing power of the cryptographic hardware vary from device to device and application to application. It is specifically contemplated that one of ordinary skill in the art may modify the various characteristics discussed above (such as, but not limited to, the degree of randomness of the random number z, the value of the constant w, and the number of pre-calculations) to suit a particular use case, all without departing from the scope of this disclosure.

[0111] Figure 5 4 is a functional block diagram depicting a circuit 500 configured to perform the obfuscation process 400a. As shown, the circuit 500 includes functional blocks of a simple blinding multiplier 502, an adder 504, a transformer 506, an ECCPM 508, and a pre-computer ECPM 510, which are selected to emphasize the functionality of the processing logic corresponding to each block and its inputs and outputs.

[0112] The simple blinded multiplier 502 is a one-dimensional multiplier configured to generate a result of a simple multiplication of inputs r and n. Here, the simple blinded multiplier 502 is configured to generate a result Y by performing a binary multiplication of the input (here, the random number r and the order n). The adder 504 is configured to perform a binary addition of the input (here, the result Y generated by the simple blinded multiplier 502) and the scalar d. The adder 504 generates a randomized scalar k in response to the addition of the result Y and the scalar d. The transformer 506 is a processing logic configured to transform (e.g., reformat, but not limited to) the randomized scalar k generated by the adder 504 into a new formula f (having three components, a variable e, a non-zero constant w, and a random number z) corresponding to the expression in Equation 7.

[0113] Pre-computer ECPM 510 is an elliptic curve point multiplier configured to perform ECPM on a new formula f (labeled as input 512) and a window-sized portion of a base point Q to generate pre-calculations (e.g., 1Q, 2Q, ..., mQ) that are available to ECCPM 508. ECCPM 508 is an elliptic curve cryptography point multiplier that can use the pre-calculations generated by pre-computer ECPM 510 to perform ECPM on the new formula f (labeled as input 512) and the base point Q to generate a point P. In various embodiments, the ECPM performed by ECCPM 508 and pre-computer ECPM 510 can be a left-to-right binary method for point multiplication of Algorithm 2, as described above.

[0114] Figure 6is a block diagram depicting a system 600 including a cryptographic engine 606 configured to perform ECCPM using obfuscation as disclosed herein (eg, performing process 400b and / or including circuit 500), according to one or more embodiments.

[0115] Cryptographic engine 606 may be or form part of an electronic system, such as a system on a chip or other microelectronic device, configured to provide cryptographic services to user device 602 (e.g., a microcontroller or higher level system component, but not limited thereto) via interface 604 .

[0116] The cryptographic engine 606 includes a memory 608, which may be a read-only memory, including a memory 618, which may be a static random access memory, and a processor 628. As a non-limiting example, processor-executable instructions 610 for performing cryptographic operations 614 and obfuscation processes 612 are stored at the memory 608 as microcode or another hardware-level instruction for implementing machine code instructions or internal state machine sequencing to perform some or all of the operations discussed herein for obfuscating cryptographic parameters or for performing ECPM and ECCPM. Elliptic curve information 616 is also stored at the memory 608, which includes information such as the base point Q, coefficients, order n, modulus prime number of the ECM, and the standard name and type of ECCPM or ECCM, which are used for cryptographic processes such as ECDH and ECDSA, respectively.

[0117] Varying information is stored at memory 618, such as pre-calculations 620, scalars 622 (i.e., scalar d), temporary variables 624 (e.g., first obfuscated cryptographic parameters (i.e., new or randomized scalar k); fully obfuscated cryptographic parameters (i.e., new formula f) and its components (i.e., variable e, non-zero constant w and random number z), and points on the elliptic curve P); and cryptographic information 626 (e.g., public private keys, shared secrets, session keys, but not limited thereto).

[0118] Figure 7is a block diagram depicting circuitry 700, which, in some embodiments, can be used to implement various functions, operations, actions, processes, and / or methods disclosed herein, including in hardware circuitry. Circuitry 700 includes one or more processors (sometimes referred to herein as "processor 702") operatively coupled to one or more devices (sometimes referred to herein as "storage devices 704") (such as, but not limited to, data storage devices). Storage devices 704 include machine-executable code 706 stored thereon (e.g., stored on a computer-readable memory), and processor 702 includes logic circuitry 708. Machine-executable code 706 includes information describing functional elements that can be implemented by (e.g., executed by) logic circuitry 708. Logic circuitry 708 is suitable for implementing (e.g., executing) the functional elements described by machine-executable code 706. When executing the functional elements described by the machine-executable code 706, the circuit 700 should be considered to be dedicated hardware configured to perform the functional elements disclosed herein, such as the operations of process 100, process 200a, process 200b, process 300, process 400a, and process 400b, as well as the functional blocks of the obfuscated processes of circuit 500 and blocks of system 600. In some embodiments, the processor 702 can be configured to execute the functional elements described by the machine-executable code 706 sequentially, simultaneously (e.g., on one or more different hardware platforms), or in one or more parallel process streams.

[0119] When implemented by logic circuitry 708 of processor 702, machine executable code 706 is configured to adjust processor 702 to perform operations of the embodiments disclosed herein. For example, machine executable code 706 may be configured to adjust processor 702 to perform at least a portion or all of the operations discussed with respect to process 300, process 400a, process 400b, and circuit 500.

[0120] The processor 702 may include a general-purpose processor, a special-purpose processor, a central processing unit (CPU), a microcontroller, a programmable logic controller (PLC), a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic device, discrete gate or transistor logic, discrete hardware components, other programmable devices or any combination thereof designed to perform the functions disclosed herein. When a general-purpose computer is configured to execute computing instructions (e.g., software code) related to the embodiments of the present disclosure, a general-purpose computer including a processor is considered to be a special-purpose computer. It should be noted that the general-purpose processor (also referred to as a host processor or simply host in this article) can be a microprocessor, but in an alternative, the processor 702 may include any conventional processor, controller, microcontroller or state machine. The processor 702 may also be implemented as a combination of computing devices, such as a combination of a DSP and a microprocessor, a plurality of microprocessors, one or more microprocessors combined with a DSP core, or any other such configuration.

[0121] In some embodiments, the memory 704 includes volatile data storage (e.g., random access memory (RAM)), non-volatile data storage (e.g., flash memory, hard disk drive, solid-state drive, erasable programmable read-only memory (EPROM), etc.). In some embodiments, the processor 702 and the storage device 704 can be implemented as a single device (e.g., a semiconductor device product, a system on a chip (SOC), but not limited thereto). In some embodiments, the processor 702 and the storage device 704 can be implemented as separate devices.

[0122] In some embodiments, machine executable code 706 may include computer-readable instructions (e.g., software code, firmware code). As a non-limiting example, the computer-readable instructions may be stored by storage device 704, directly accessed by processor 702, and executed by processor 702 using at least logic circuitry 708. Also as a non-limiting example, the computer-readable instructions may be stored on storage device 704, transferred to a memory device (not shown) for execution, and executed by processor 702 using at least logic circuitry 708. Thus, in some embodiments, logic circuitry 708 includes logic circuitry 708 that is electrically configurable.

[0123] In some embodiments, the machine executable code 706 may describe the hardware (e.g., circuitry) to be implemented in the logic circuit 708 to perform the functional elements. The hardware can be described at any of a variety of abstraction levels, from low-level transistor layouts to high-level description languages. At a high level of abstraction, a hardware description language (HDL) such as, but not limited to, an Institute of Electrical and Electronics Engineers (IEEE) standard hardware description language (HDL) may be used. As non-limiting examples, Verilog™, SystemVerilog™, or a very large scale integration (VLSI) hardware description language (VHDL™) may be used.

[0124] The HDL description can be converted into a description at any of a variety of other levels of abstraction as needed. As non-limiting examples, the high-level description can be converted into a logic-level description such as a register transfer language (RTL), a gate-level (GL) description, a layout-level description, or a mask-level description. As non-limiting examples, the micro-operations performed by the hardware logic circuits (e.g., gates, flip-flops, registers, but not limited thereto) of the logic circuit 708 can be described in RTL and then converted into a GL description by a synthesis tool, and the GL description can be converted into a layout-level description by a placement and routing tool, which corresponds to the physical layout of an integrated circuit, discrete gate or transistor logic components, discrete hardware components, or a combination thereof of a programmable logic device. Thus, in some embodiments, the machine executable code 706 may include an HDL, RTL, GL description, a mask-level description, other hardware description, or any combination thereof.

[0125] In embodiments where the machine-executable code 706 includes a hardware description (at any level of abstraction), a system (not shown, but including the storage device 704) can be configured to implement the hardware description described by the machine-executable code 706. As a non-limiting example, the processor 702 can include a programmable logic device (e.g., an FPGA or a PLC), and the logic circuitry 708 can be electronically controlled to implement circuitry corresponding to the hardware description into the logic circuitry 708. Also as a non-limiting example, the logic circuitry 708 can include hard-wired logic components that are manufactured by a manufacturing system (not shown, but including the storage device 704) according to the hardware description of the machine-executable code 706.

[0126] Regardless of whether the machine-executable code 706 includes computer-readable instructions or a hardware description, the logic circuit 708 is adapted to perform the functional elements described by the machine-executable code 706 when implementing the functional elements of the machine-executable code 706. It should be noted that although the hardware description may not directly describe the functional elements, the hardware description indirectly describes the functional elements that the hardware elements described by the hardware description are capable of performing.

[0127] As a non-limiting example, circuit 700 may be implemented in a secure cryptographic system utilizing an ECC algorithm that implements elliptic curve point multiplication, such as a key fob token (such as RSA SecurID, as a non-limiting example), an ATM, financial transactions involving keys, hardware locks, software licenses, etc.

[0128] Those of ordinary skill in the art will appreciate many applications of the embodiments discussed herein.

[0129] As a non-limiting example, cryptographic processes obfuscated according to one or more embodiments may be used with key agreement protocols involving elliptic curve point multiplication and modular exponentiation, such as, but not limited to, Elliptic Curve Diffie-Hellman (ECDH), Elliptic Curve Digital Signature Algorithm (ECDSA), Universal Elliptic Curve Cryptography (ECC) algorithms, and Rivest–Shamir–Adleman (RSA).

[0130] As another non-limiting example, the obfuscation process discussed herein can be used to automatically instruct a processor to obfuscate parameters used in a cryptographic process in response to a query from the processor. For example, the disclosed obfuscation process can be automatically initiated in response to receiving cryptographic parameters at an aliasing register, which is memory-mapped to logic circuitry for applying the obfuscation process to the cryptographic parameters to obtain obfuscated cryptographic parameters. The aliasing register can be associated with one or more cryptographic processes. The obfuscated cryptographic parameters can then be used as parameters for cryptographic operations of the cryptographic processes.

[0131] As another non-limiting example, obfuscation and cryptographic processes using the same processes discussed herein may be used for public key signature systems and signature verification, such as generating session keys.

[0132] As another non-limiting example, techniques for obfuscating externally observable characteristics of a device include, but are not limited to, techniques applicable to any computation involving elliptic curve point multiplication (ECPM). Other similar scenarios are not beyond the scope of this disclosure. As a non-limiting example, the disclosed embodiments may be applied to modular exponentiation used in a Rivest-Shamir-Adleman (RSA) modular exponentiation engine application chip. In this case, the correlation between readings of different pre-calculations is reduced, and thus it will be more difficult for an attacker to obtain a scalar by observing the power signature during the reading of an obfuscated pre-calculation (by the device).

[0133] Although the bit length of the obfuscated cryptographic parameter (e.g., the randomized expression or the new formula f, but not limited thereto) is substantially the same as the bit length of the cryptographic parameter, it should be understood that the disclosed embodiments provide one of ordinary skill in the art with the option of controlling the bit length to be the same as the bit length of the cryptographic parameter. As a non-limiting example, if desired, one of ordinary skill in the art can modify the disclosed embodiments to increase the range of available random numbers with a corresponding increase in the window size and bit length (relative to the bit length of the cryptographic parameter or the first obfuscated cryptographic parameter).

[0134] As used in this disclosure, the term "combination" referring to multiple elements may include all of the elements in combination or any of various subcombinations of certain elements. For example, the phrase "A, B, C, D, or a combination thereof" may refer to any one of A, B, C, or D; a combination of each of A, B, C, and D; and any subcombination of A, B, C, or D, such as A, B, and C; A, B, and D; A, C, and D; B, C, and D; A and B; A and C; A and D; B and C; B and D; or C and D.

[0135] The terms used in this disclosure, especially in the appended claims (e.g., the subject matter of the appended claims, but not limited thereto) are generally intended to be “open” terms (e.g., the term “including” should be interpreted as “including but not limited to,” the term “having” should be interpreted as “having at least,” and the term “comprising” should be interpreted as “including but not limited to,” but not limited thereto).

[0136] In addition, if a specific number of introduced claim recitations is intended, such intent will be expressly recited in the claim, and in the absence of such recitation, no such intent is present. For example, as an aid to understanding, the following appended claims may contain the use of the introductory phrases "at least one" and "one or more" to introduce claim recitations. However, the use of such phrases should not be construed to imply that a claim recitation introduced by the indefinite article "a" or "an" will limit any particular claim containing such introduced claim recitation to embodiments containing only one such recitation, even when the same claim includes the introductory phrases "one or more" or "at least one" and an indefinite article, such as "a" or "an" (e.g., "a" and / or "an" may be interpreted to mean "at least one" or "one or more," but are not limited thereto); the same is true when a definite article is used to introduce a claim recitation.

[0137] In addition, even if a specific number of an introduced claim recitation is explicitly recited, one skilled in the art will recognize that such recitation should be interpreted as intending at least the recited number (e.g., the unmodified recitation "two recitations," without other modifiers, intends at least two recitations, or two or more recitations, but is not limited thereto). Moreover, in those instances where a convention similar to "at least one of A, B, and C, etc." or "one or more of A, B, and C, etc." is used, such construction is generally intended to include only A, only B, only C, both A and B, both A and C, both B and C, or all three of A, B, and C, etc.

[0138] Furthermore, any discrete word or phrase presenting two or more alternative terms, whether in the specification, claims, or drawings, should be understood to include the possibility of one, either, or both of the terms. For example, the phrase "A or B" should be understood to include the possibility of "A" or "B" or "A and B."

[0139] Additional non-limiting embodiments of the present disclosure include:

[0140] Embodiment 1: A method of obfuscating at least a portion of a cryptographic process, the method comprising: obtaining an obfuscation parameter; applying an obfuscation process to the entire cryptographic parameter of the cryptographic process to obtain an obfuscated cryptographic parameter having a bit length substantially the same as a bit length of the cryptographic parameter, wherein the parameters of the obfuscation process include the obfuscation parameter; and performing a cryptographic operation of the cryptographic process to obtain cryptographic information, wherein the parameters of the cryptographic operation include the obfuscated cryptographic parameter.

[0141] Embodiment 2: The method of embodiment 1, wherein applying the obfuscation process to the entire cryptographic parameter comprises applying an obfuscation operation to discrete window-sized portions of the cryptographic parameter.

[0142] Embodiment 3: The method of any one of Embodiments 1 and 2, wherein obtaining the obfuscation parameter comprises obtaining one or more of a cryptographic parameter length, a window size, and a degree of randomness.

[0143] Embodiment 4: The method according to any one of embodiments 1 to 3, wherein applying the obfuscation process to the entire cryptographic parameters of the cryptographic process to obtain the obfuscated cryptographic parameters includes: applying a first obfuscation process to the cryptographic parameters to obtain first obfuscated cryptographic parameters; and reformatting the first obfuscated cryptographic parameters into a randomized expression corresponding to the first obfuscated cryptographic parameters.

[0144] Embodiment 5: A method according to any one of embodiments 1 to 4, wherein reformatting the first obfuscated cryptographic parameter into the randomized expression corresponding to the first obfuscated cryptographic parameter includes: obtaining a first component of the expression corresponding to the first obfuscated cryptographic parameter, the first component having a non-zero value; obtaining a second component of the expression corresponding to the first obfuscated cryptographic parameter, the second component having a randomly generated value; and obtaining a third component of the expression corresponding to the first obfuscated cryptographic parameter, the third component having a value corresponding to the difference between the values ​​of the first obfuscated cryptographic parameter, the first component, and the second component.

[0145] Embodiment 6: The method according to any one of Embodiments 1 to 5 further includes: ensuring that the length of the obfuscated cryptographic parameter is the same as the length of the cryptographic parameter.

[0146] Embodiment 7: The method according to any one of Embodiments 1 to 6 further includes: obtaining a third component having the same bit length as the bit length of the cryptographic parameter.

[0147] Embodiment 8: The method of any one of Embodiments 1 to 7, wherein performing the cryptographic operation comprises performing one of: an elliptic curve point multiplication operation or a modular exponentiation operation.

[0148] Embodiment 9: The method according to any one of embodiments 1 to 8 further includes: pre-calculating the results obtained by performing at least some of the cryptographic operations in response to the randomized expression.

[0149] Embodiment 10: The method according to any one of embodiments 1 to 9 also includes: adjusting the degree of randomness associated with the obfuscation process by setting the most significant bit of a component of an expression corresponding to the obfuscated cryptographic parameter, the component having a randomly generated value.

[0150] Embodiment 11: The method according to any one of embodiments 1 to 10 also includes: performing a fixed window-based cryptographic operation in response to a randomized expression corresponding to the cryptographic parameters.

[0151] Embodiment 12: An encryption engine of an electronic system comprises: a processor; a first memory having processor-executable instructions stored thereon, wherein the processor-executable instructions, when executed by the processor, cause the processor to: apply an obfuscation process to entire cryptographic parameters of a cryptographic process to obtain obfuscated cryptographic parameters, wherein the bit length of the obfuscated cryptographic parameters is substantially the same as the bit length of the cryptographic parameters; and perform a cryptographic operation of the cryptographic process to obtain cryptographic information, wherein the parameters of the cryptographic operation include the obfuscated cryptographic parameters.

[0152] Embodiment 13: A cryptographic engine according to embodiment 12, wherein the cryptographic operation includes an operation for elliptic curve point multiplication or modular exponentiation.

[0153] Embodiment 14: An encryption engine according to any one of embodiments 12 and 13, wherein the obfuscation process is configured to: apply a first obfuscation process to the cryptographic parameters to obtain first obfuscated cryptographic parameters; and reformat the first obfuscated cryptographic parameters into a randomized expression corresponding to the first obfuscated cryptographic parameters.

[0154] Embodiment 15: An encryption engine according to any one of Embodiments 12 to 14, wherein the obfuscation process is configured to: obtain a first component of an expression corresponding to the first obfuscated cryptographic parameter, wherein the first component has a non-zero value; obtain a second component of the expression corresponding to the first obfuscated cryptographic parameter, wherein the second component has a randomly generated value; and obtain a third component of the expression corresponding to the first obfuscated cryptographic parameter, wherein the third component has a value corresponding to the difference between the values ​​of the first obfuscated cryptographic parameter, the first component, and the second component.

[0155] Embodiment 16: An encryption engine according to any one of Embodiments 12 to 15, wherein the obfuscation process is configured to: pre-calculate the results obtained by performing at least some of the cryptographic operations; and store the pre-calculated results in a writable memory.

[0156] Embodiment 17: A computer-readable storage device having machine-executable instructions, which, when executed by a processor, are configured to enable the processor to perform operations comprising: obtaining an obfuscation parameter; applying an obfuscation process to entire cryptographic parameters of a cryptographic process to obtain an obfuscated cryptographic parameter without increasing the bit length of the obfuscated cryptographic parameter relative to the bit length of the cryptographic parameter, wherein the parameters of the obfuscation process include the obfuscation parameter; and performing a cryptographic operation of the cryptographic process to obtain cryptographic information, wherein the parameters of the cryptographic operation include the obfuscated cryptographic parameter.

[0157] Embodiment 18: A computer-readable storage device according to embodiment 17, wherein the operation further comprises: applying a first obfuscation process to the cryptographic parameters to obtain first obfuscated cryptographic parameters; and reformatting the first obfuscated cryptographic parameters into a randomized expression corresponding to the first obfuscated cryptographic parameters.

[0158] Embodiment 19: A computer-readable storage device according to any one of embodiments 17 and 18, wherein the operation further comprises: obtaining a first component of an expression corresponding to the first obfuscated cryptographic parameter, wherein the first component has a non-zero value; obtaining a second component of the expression corresponding to the first obfuscated cryptographic parameter, wherein the second component has a randomly generated value; and obtaining a third component of the expression corresponding to the first obfuscated cryptographic parameter, wherein the third component has a value corresponding to a difference between the values ​​of the first obfuscated cryptographic parameter, the first component, and the second component.

[0159] Although the present invention is described herein with respect to certain illustrated embodiments, those skilled in the art will recognize and understand that the present invention is not so limited. Rather, many additions, deletions, and modifications may be made to the illustrated embodiments and the described embodiments without departing from the scope of the invention as claimed below and its legal equivalents. Furthermore, features from one embodiment may be combined with features from another embodiment while still being included within the scope of the invention as contemplated by the inventors.

Claims

1. A method of obfuscating at least a portion of a cryptographic process, the method comprising: Get obfuscation parameters; applying an obfuscation process to an entire cryptographic parameter of a cryptographic process to obtain an obfuscated cryptographic parameter having a bit length substantially the same as a bit length of the cryptographic parameter, wherein the parameter of the obfuscation process includes the obfuscated parameter; reformatting an obfuscated cryptographic parameter into an expression comprising a random number, a non-zero constant, and a variable component having a value based at least in part on the obfuscated cryptographic parameter, wherein a bit length of each of the random number, the non-zero constant, and the variable component is selected based at least in part on the cryptographic parameter; and A cryptographic operation of the cryptographic process is performed to obtain cryptographic information, wherein parameters of the cryptographic operation include the obfuscated cryptographic parameters.

2. The method of claim 1 , wherein applying the obfuscation process to the entire cryptographic parameter comprises applying an obfuscation operation to discrete window-sized portions of the cryptographic parameter. 3 . The method of claim 1 , wherein obtaining the obfuscation parameter comprises obtaining one or more of a cryptographic parameter length, a window size, and a degree of randomness.

4. The method according to claim 1, wherein The expression is a randomized expression corresponding to the obfuscated cryptographic parameters.

5. The method of claim 4 , wherein the reformatting the obfuscated cryptographic parameters into the randomized expression corresponding to the obfuscated cryptographic parameters comprises: obtaining a first component of an expression corresponding to the obfuscated cryptographic parameter, the first component having a non-zero value; obtaining a second component of the expression corresponding to the obfuscated cryptographic parameter, the second component having a randomly generated value; as well as A third component of the expression corresponding to the obfuscated cryptographic parameter is obtained, the third component having a value corresponding to a difference between the values ​​of the obfuscated cryptographic parameter, the first component, and the second component.

6. The method according to claim 1, further comprising: Ensure that the bit length of the obfuscated cryptographic parameter is the same as the bit length of the cryptographic parameter.

7. The method according to claim 1, further comprising: A component having the same bit length as the bit length of the cryptographic parameter is obtained.

8. The method of claim 1, wherein the performing the cryptographic operation comprises performing one of: an elliptic curve point multiplication operation or a modular exponentiation operation.

9. The method according to claim 4, further comprising: Results of performing at least some of the cryptographic operations in response to the randomized expression are pre-computed.

10. The method according to claim 1, further comprising: A degree of randomness associated with the obfuscation process is adjusted by setting a most significant bit of a component of an expression corresponding to the obfuscated cryptographic parameter, the component having a randomly generated value.

11. The method according to claim 1 , further comprising: A fixed window based cryptographic operation is performed in response to a randomized expression corresponding to the cryptographic parameters.

12. An encryption engine for an electronic system, comprising: processor; a first memory having processor-executable instructions stored thereon, wherein the processor-executable instructions, when executed by the processor, cause the processor to: applying an obfuscation process to an entire cryptographic parameter of the cryptographic process to obtain an obfuscated cryptographic parameter, wherein a bit length of the obfuscated cryptographic parameter is substantially the same as a bit length of the cryptographic parameter; reformatting an obfuscated cryptographic parameter into an expression comprising a random number, a non-zero constant, and a variable component having a value based at least in part on the obfuscated cryptographic parameter, wherein a bit length of each of the random number, the non-zero constant, and the variable component is selected based at least in part on the cryptographic parameter; and A cryptographic operation of the cryptographic process is performed to obtain cryptographic information, wherein parameters of the cryptographic operation include the obfuscated cryptographic parameters.

13. The cryptographic engine of claim 12, wherein the cryptographic operation comprises an operation for elliptic curve point multiplication or modular exponentiation.

14. The encryption engine of claim 12, wherein The expression is a randomized expression corresponding to the obfuscated cryptographic parameters.

15. The encryption engine of claim 14, wherein the obfuscation process is configured to: obtaining a first component of an expression corresponding to the obfuscated cryptographic parameter, wherein the first component has a non-zero value; obtaining a second component of the expression corresponding to the obfuscated cryptographic parameter, wherein the second component has a randomly generated value; as well as A third component of the expression corresponding to the obfuscated cryptographic parameter is obtained, wherein the third component has a value corresponding to a difference between the values ​​of the obfuscated cryptographic parameter, the first component, and the second component.

16. The encryption engine of claim 12, wherein the obfuscation process is configured to: pre-calculating results of performing at least some of the cryptographic operations; and The pre-calculated results are stored in a writable memory.

17. A computer-readable storage device having machine-executable instructions that, when executed by a processor, are configured to cause the processor to perform operations comprising: Get obfuscation parameters; applying an obfuscation process to an entire cryptographic parameter of a cryptographic process to obtain an obfuscated cryptographic parameter without increasing a bit length of the obfuscated cryptographic parameter relative to a bit length of the cryptographic parameter, wherein the parameters of the obfuscation process include the obfuscated parameter; reformatting an obfuscated cryptographic parameter into an expression comprising a random number, a non-zero constant, and a variable component having a value based at least in part on the obfuscated cryptographic parameter, wherein a bit length of each of the random number, the non-zero constant, and the variable component is selected based at least in part on the cryptographic parameter; and A cryptographic operation of the cryptographic process is performed to obtain cryptographic information, wherein parameters of the cryptographic operation include the obfuscated cryptographic parameters.

18. The computer-readable storage device of claim 17, wherein the expression is a randomized expression corresponding to the obfuscated cryptographic parameters.

19. The computer-readable storage device of claim 18, wherein the operations further comprise: obtaining a first component of an expression corresponding to the obfuscated cryptographic parameter, wherein the first component has a non-zero value; obtaining a second component of the expression corresponding to the obfuscated cryptographic parameter, wherein the second component has a randomly generated value; as well as A third component of the expression corresponding to the obfuscated cryptographic parameter is obtained, wherein the third component has a value corresponding to a difference between the values ​​of the obfuscated cryptographic parameter, the first component, and the second component.

20. The computer-readable storage device of claim 18, wherein the operations further comprise: pre-calculating results obtained by performing at least some of the cryptographic operations; as well as The pre-calculated results are stored in a writable memory.

Citation Information

Patent Citations

  • Countermeasure method in an electronic component using a public key cryptography algorithm on an elliptic curve

    US20010048742A1

  • Hardening of direct anonymous attestation from side-channel attack

    US20140095883A1