Radio transmitter device having a cryptographic engine

By dividing the cryptographic operation into two stages and controlling the operation of the cryptographic engine according to the status of the radio transmitter, the problem of difficulty in alleviating side channel attacks in the prior art is solved, and higher security is achieved for the integrated circuit radio transmitter chip.

CN115244891BActive Publication Date: 2025-05-13NORDIC SEMICONDUCTOR
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202180020008.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2020-03-09
Filing Date
2021-03-09
Publication Date
2025-05-13
Estimated Expiration
2041-03-09

AI Technical Summary

Technical Problem

The prior art is difficult to effectively mitigate side channel attacks on integrated circuit radio transmitter chips, especially remote side channel attacks, and traditional methods may introduce additional complexity and are not sufficient to prevent successful attacks.

Method used

By dividing the cryptographic operation into at least two stages, performing the first component process when the radio transmitter is active, performing the second component process when the radio transmitter is inactive, and using the radio state input to control the operation of the cryptographic engine, ensuring that the output data depends on the results of the two processes, making it difficult for the attacker to obtain complete cryptographic operation information.

Benefits of technology

This method can prevent local side channel attacks and remote side channel attacks at the same time, reducing the possibility of attackers obtaining password operation information and improving the security of the chip.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115244891B_ABST
    Figure CN115244891B_ABST
Patent Text Reader

Abstract

An integrated circuit radio transmitter chip (2) includes a transmitter (7), a cryptographic engine (12), and a control circuit system (13) for the cryptographic engine. The cryptographic engine (12) performs a cryptographic operation by receiving input data, executing a first process that generates first result data, and a second process that generates second result data. The first and second result data are used to generate output data. In response to determining that the transmitter (7) is active, the control circuit system (13) controls the cryptographic engine (12) to perform the first process and prevents the cryptographic engine from performing the second process when the transmitter is active. In response to determining that the transmitter (7) is inactive, the control circuit system (13) controls the cryptographic engine (12) to perform the second process.
Need to check novelty before this filing date? Find Prior Art

Description

Background Art

[0001] The present invention relates to a radio transmitter device having a cryptographic engine.

[0002] It is known to integrate a radio transmitter, a main processor, and a cryptographic engine separate from the main processor on a single integrated circuit (IC) chip. Such on-chip radios may facilitate efficient and secure radio communications by using the cryptographic engine to encrypt and / or sign data for transmission by the radio transmitter without burdening the main processor with this task. Such chips may also include a radio receiver and may use the cryptographic engine to decrypt and / or authenticate incoming radio messages.

[0003] A cryptographic engine should seek to protect sensitive data, such as cryptographic keys and unencrypted plaintext messages, from attackers.

[0004] Some attacks are applied purely to intercepted radio message data - such as brute force, trial-and-error methods to discover encryption keys. Other attacks, called side-channel attacks, also use measurements that reveal detailed information about the actual cryptographic processes performed by the chip.

[0005] Some side-channel attacks involve monitoring the current consumed by a chip while performing cryptographic operations. Fluctuations in the current can reveal details about the mathematical calculations the chip is performing as it applies cryptographic operations to sensitive data. Statistical analysis of multiple observations of the operations might allow an attacker to discover the sensitive data itself. However, these types of attacks require the attacker to be close to the chip.

[0006] A side-channel attack that has recently been identified as a potential threat to on-chip radios is the "screaming channel" attack. This can be performed from a great distance away. It is based on the observation that electrical noise in the digital logic portion of a chip, such as a processor, can cause unintended amplitude and / or frequency modulation of a radio signal that the chip happens to transmit simultaneously with the cryptographic operations being performed. This can occur if digital switching noise is coupled to a baseband radio signal or a local oscillator signal and then up-converted to radio frequency. This unintentional modulation can be amplified and transmitted through the radio antenna.

[0007] An attacker may use a remotely located radio receiver to analyze the unintended modulation of the radio signal resulting from the use of cryptographic operations to process sensitive data. In some cases, an attacker may be able to discover sensitive data by analyzing the unintended radio modulation. The cryptographic operations need not be related to the intended message content of the radio signal.

[0008] Attempts to mitigate side channel attacks have traditionally used hiding or masking techniques to make statistical analysis less feasible. However, these techniques can introduce significant additional complexity, which may be undesirable, and may still not be sufficient to prevent successful attacks.

[0009] The present invention aims to provide a different approach to mitigate the threat of side channel attacks on integrated circuit radio transmitter chips. Summary of the invention

[0010] According to a first aspect, the present invention provides an integrated circuit radio transmitter chip comprising:

[0011] Radio transmitters;

[0012] Cryptographic Engine; and

[0013] Control logic for controlling the cryptographic engine,

[0014] The cryptographic engine is configured to perform cryptographic operations by:

[0015] receiving input data for a cryptographic operation;

[0016] executing a first component process to generate first result data;

[0017] executing a second component process to generate second result data;

[0018] generating output data representing a result of the cryptographic operation using the first and second result data; and

[0019] Output output data,

[0020] wherein the control logic comprises a radio state input for receiving a signal indicating whether the radio transmitter is in an active state for transmitting one or more radio signals, and

[0021] Where the control logic is configured to use the radio status input to:

[0022] In response to determining that the radio transmitter is in an active state, controlling the cryptographic engine to execute the first component process so that the radio transmitter outputs a radio frequency signal when the cryptographic engine executes the first component process; and

[0023] In response to determining that the radio transmitter is not in an active state, the cryptographic engine is controlled to perform the second component process such that the cryptographic engine performs the second component process when the radio transmitter is not outputting a radio frequency signal.

[0024] According to a second aspect, the invention provides an electrical device comprising such an integrated circuit radio transmitter chip.

[0025] It will thus be seen that according to the present invention, the cryptographic operation is divided into at least two phases, a first component process being performed when the radio transmitter is active, and a second component process being performed when the radio transmitter is inactive. Importantly, the output data depends on the results of both processes, so even if one of the component processes is compromised by an attacker, the attacker cannot discover complete information about the entire cryptographic operation.

[0026] This approach protects against both local side-channel attacks and remote side-channel attacks. The threat from remote side-channel attacks, in which an attacker analyzes the transmitted radio signals, is mitigated by performing the second component process when the radio transmitter is inactive, because the radio transmitter will not amplify and broadcast any side-channel information to the attacker about this process. The threat from local side-channel attacks, in which the attacker directly monitors the power consumption of the chip, is mitigated by performing the first component process when the radio transmitter is active. The additional current consumed by the radio transmitter when the transmitter is active, as well as the associated localized electromagnetic radiation, will make it more difficult for an attacker to obtain useful information about the operations performed by the cryptographic engine in the second component process. In particular, the power consumption signal from the radio transmitter is typically much larger than the power consumption signal of the cryptographic engine, resulting in a very low signal-to-noise ratio for any potential side-channel leakage from the cryptographic engine.

[0027] The control logic may be configured to prevent the cryptographic engine from executing the second component process while the radio transmitter is active. This may be useful to ensure that the second component process is not executed while the radio transmitter is transmitting a radio signal, for example, if the chip includes a component or mechanism separate from the control logic, such as a processor, that may otherwise be able to cause the cryptographic engine to execute the second component process at an inappropriate time.

[0028] The cryptographic operation may be any of the following: an encryption operation, a decryption operation, a signing operation, a signature verification operation, a hashing operation, a message authentication code (MAC) operation, or any other cryptographic operation. It may be a standardized operation such as AES, SNOW 3G, RSA, etc. The operation may use key data, such as a symmetric key or an asymmetric key. The input data may include one or more of the following: key data, plaintext data, ciphertext data, signature data, hash data, or MAC data.

[0029] The first component process may be performed before the second component process, or the second component process may be performed before the first component process. The order may be fixed, or the control logic may be configured to determine the order in which the first and second component processes are performed based on whether the radio transmitter is active at a predetermined point within the cryptographic operation, such as at the beginning of the cryptographic operation. This may result in more efficient performance of the cryptographic operation by waiting for only one change in transmit state rather than two changes during the cryptographic operation.

[0030] If the radio transmitter is not active, the control logic may be configured to wait until the radio transmitter is active and then perform the first component process. It may be configured to repeatedly determine the state of the transmitter during this waiting period, for example at regular intervals. If the radio transmitter is active, the control logic may be configured to wait until the radio transmitter is not active before performing the second component process. It may be configured to repeatedly determine the state of the transmitter during this waiting period, for example at regular intervals.

[0031] The first and second component processes may together comprise all steps performed by the cryptographic engine on the input data to generate the output data. However, in some embodiments, the cryptographic operation may comprise one or more additional component processes, which may be performed before, after, or between the first and second processes. The execution of each additional component process may depend on the state of the radio transmitter, or it may be performed independently of whether the radio transmitter is active. One of the first and second result data may be output data, although this is not required.

[0032] The first and second component processes can be distinguished by the processing steps they perform and / or what data they act on. In particular, they can perform different corresponding groups of one or more steps from an ordered sequence of steps that form part of a cryptographic operation. Alternatively or additionally, the first and second component processes can act on different corresponding portions of the input data.

[0033] These processes may be continuous. In some embodiments, the first result data may be used by the second component process to generate the second result data. Alternatively, if the second process is performed before the first process, the second result data may be used by the first component process to generate the first result data. The second result data may depend on the first result data, and vice versa.

[0034] The cryptographic operation may be an operation comprising multiple identical rounds (such as rounds in an AES encryption operation). In this case, the first process may comprise performing a first group of one or more rounds, and the second process may comprise performing a second group of one or more rounds, wherein the first and second groups are non-overlapping groups.

[0035] In some embodiments, the first result data depends on the first portion of the input data but not on the second portion of the input data. Similarly, the second result data may depend on the second portion of the input data but not on the first portion of the input data. The first and second portions may be corresponding portions of a cryptographic key, or they may be corresponding portions of non-key data such as plaintext data, ciphertext data, or signature data.

[0036] The cryptographic operation may be an operation performed on multiple blocks of input data of a predetermined size (e.g., a 128-bit AES encryption operation, which operates on 128-bit plaintext blocks). In this case, the first process may include performing a cryptographic algorithm - which may be a standardized algorithm, such as AES encryption - on a first group of one or more blocks of input data, and the second process may include performing a cryptographic algorithm on a second group of one or more blocks of input data, wherein the first and second groups are non-overlapping groups.

[0037] The cryptographic operation may use a block operation mode (such as cipher block chaining, CBC) in which one of the first and second result data depends on the other of the first and second result data. This may further mitigate the threat posed by an attacker who seeks to disrupt one of the component processes.

[0038] The output data need not be output all at once, but may be output incrementally over time. Similarly, the cryptographic engine may receive input data incrementally over time.

[0039] The integrated circuit chip may be a silicon chip. It may include a radio receiver. The chip may include an on-chip antenna for transmitting radio signals directly from the chip, or it may include pins for connecting the chip to an off-chip antenna, optionally via an off-chip power amplifier. In this case, the on-chip radio transmitter may output an electrical radio frequency signal. The chip may include one or more processors. It may include volatile and non-volatile memory. It may be a system on a chip (SoC).

[0040] The cryptographic engine may include a software engine (e.g., cryptographic firmware) stored in a memory of the chip for execution by the chip's processor. It may be executed by a main processor (i.e., a processor that also executes other software) or a dedicated cryptographic processor. The cryptographic engine may include a cryptographic processor. It may include memory for storing software instructions for the cryptographic processor; the chip's main processor may not have access to this memory.

[0041] However, in some embodiments, the cryptographic engine is a hardware engine.The cryptographic engine may include electronic circuitry, such as registers and logic gates, configured to perform the first and second component processes.

[0042] Similarly, the control logic engine may include software logic stored in the chip's memory for execution by the chip's processor. This may be a main processor or a dedicated cryptographic processor. The control logic may include a cryptographic processor. The control logic may be a component of the cryptographic engine. The radio state input may be determined using an output register of the radio transmitter, which may be read by the processor via the chip's bus system.

[0043] However, in some embodiments, the control logic is a hardware state machine.The control logic may include electronic circuitry, such as registers and logic gates, configured to control the cryptographic engine.

[0044] The chip may include a processor and a bus for transmitting data to and from the processor. The control logic may be coupled to the bus to receive control signals from the processor. The control logic may receive a signal indicating whether the radio transmitter is in an active state via the bus. However, in some embodiments, the radio status input may be coupled to the radio transmitter via a connection separate from the bus. This may provide greater security against malware executing on the processor, which may otherwise trick the control logic into believing that the radio transmitter is active when in fact it is not. The separate connection may include a dedicated line between the radio transmitter and the control logic, or it may be established via a peripheral interconnect system or an inter-processor communication system (e.g., if the radio transmitter and the control logic include respective processors).

[0045] The radio transmitter may be configured to be active when and only when the radio transmitter is outputting a radio frequency (RF) signal. However, in some embodiments, the radio transmitter may signal an active state when it is ready to output an RF signal or shortly after it stops outputting an RF signal. If so, there is preferably a predetermined maximum time period during which the radio transmitter may be active but not actively transmitting. This allows the control logic to implement a corresponding delay to ensure that the radio is transmitting when the cryptographic engine is executing the first component process, and is not transmitting when the cryptographic engine is executing the second component process.

[0046] The control logic may be configured to initiate the first component process within a predetermined time of determining that the radio transmitter is in an active state or detecting that the state of the radio transmitter has changed to an active state. The control logic may be configured to initiate the second component process within a predetermined time of determining that the radio transmitter is in an inactive state or detecting that the state of the radio transmitter has changed to an inactive state.

[0047] In some embodiments, the radio transmitter may start and / or stop transmitting at times that are unpredictable by the control logic. In this case, if the transmit state becomes inactive, the control logic may suspend processing of the first process until the state becomes active again. Similarly, if the transmit state becomes active, it may suspend processing of the second process until the state becomes inactive again. However, this is not required, and it is important to recognize that, as disclosed herein, the identities of the first and second component processes are not necessarily predetermined, but may be defined by the behavior of the radio transmitter - that is, as long as the control logic can control the cryptographic engine to perform some portion of the cryptographic operation in response to determining that the radio transmitter is in an active state, this portion can be considered a first component process; and as long as the control logic can control the cryptographic engine to perform some other portion of the cryptographic operation in response to determining that the radio transmitter is not in an active state, this other portion can be considered a second component process.

[0048] The control logic may be configured to vary how many cryptographic operations are performed in the first component process between consecutive cryptographic operations. The control logic may be configured to vary how many cryptographic operations are performed in the second component process between consecutive cryptographic operations. The control logic may be configured to vary these quantities based on pseudo-random values. The chip may include a pseudo-random number generator for generating pseudo-random values. Unpredictably varying how many operations are performed with the radio transmitter active may provide additional protection against statistical cryptanalysis attacks that require an attacker to observe multiple repetitions of the same process by varying the amount that an attacker can observe each time.

[0049] The device may include a power source for the chip, such as a battery. The chip may include a power management unit for supplying power to the radio transmitter and the cryptographic engine. Powering the radio transmitter and the cryptographic engine from a common power rail on the chip helps prevent a local attacker from being able to observe the power consumption of the cryptographic engine separately from the power consumption of the radio transmitter.

[0050] Under certain conditions, the control logic may be configured to perform cryptographic operations entirely when the radio transmitter is in an active state, or to perform cryptographic operations entirely when the radio transmitter is in an inactive state. In particular, the control logic may be configured to perform this operation if a timeout period has elapsed without the radio transmitter changing to or from an active state. This may ensure that cryptographic operations may be completed even if the radio transmitter is prevented from turning on or off - for example by an attacker jamming the radio so that it remains on at all times.

[0051] The electrical device including the integrated circuit radio transmitter chip may be a computer, a household appliance, a vehicle, a wireless sensor or any other suitable device. It may include an antenna. It may include a power amplifier arranged to receive an RF signal from the chip for radio transmission from the antenna.

[0052] Features of any aspect or embodiment described herein may be applied to any other aspect or embodiment described herein where appropriate.When referring to different embodiments or sets of embodiments, it should be understood that these embodiments are not necessarily different, but may overlap. BRIEF DESCRIPTION OF THE DRAWINGS

[0053] Certain preferred embodiments of the present invention will now be described, by way of example only, with reference to the accompanying drawings, in which:

[0054] Figure 1 is a schematic diagram of a wireless temperature sensor including a radio chip embodying the present invention;

[0055] Figure 2 Schematic diagram of a wireless temperature sensor being attacked by a local side channel;

[0056] Figure 3 Schematic diagram of a wireless temperature sensor being attacked by a remote side channel;

[0057] Figure 4 A flow chart of the steps performed by the cryptographic engine of the radio chip; and

[0058] Figure 5 Flowchart of the steps performed for the cryptographic engine of a variant radio chip. DETAILED DESCRIPTION

[0059] Figure 1 A wireless temperature sensor 1 is shown which contains an integrated circuit radio chip 2 embodying the present invention, as well as a battery 3 and a thermometer 4. It should be understood that the sensor 1 may also contain other components such as a PCB, a quartz oscillator, capacitors, resistors, a housing, user interface features, etc., which are shown for simplicity. Figure 1 Not shown.

[0060] The radio chip 2 integrates a processor 5, a random access memory 6, a non-volatile memory (NVM) 16, an LTE Cat-M1 (LTE-M) radio 7, a cryptographic engine 8, and various peripheral devices 9, such as timers, USB interfaces, digital-to-analog converters, etc. These components are connected to a system bus 10.

[0061] The LTE radio 7 includes transmitter circuitry and receiver circuitry for sending and receiving LTE-M data packets. It may include local oscillators, low noise amplifiers, mixers, power amplifiers, filters, modulation and demodulation logic, and other appropriate modules. The radio 7 may include only dedicated digital logic, or it may include one or more processors for executing radio firmware stored in a memory area of ​​the radio 7. The radio antenna 11 is connected to the radio 7 via appropriate off-chip components (not shown).

[0062] The cryptographic engine 8 includes an AES unit 12 for performing Advanced Encryption Standard (AES) encryption and decryption operations, and control logic 13 for controlling the operation of the AES unit 12, and a secure key storage area 14 for storing private encryption keys. In addition to the AES unit 12, the cryptographic engine 8 may include other units for performing other cryptographic operations, such as hash operations, signature operations, message authentication code operations, asymmetric cryptography, etc. The AES unit 12 may be implemented at least in part in software executed on a processor within the cryptographic engine 8. However, in this example, the AES unit 12 is implemented purely in hardware - that is, using dedicated digital logic. Similarly, the control logic 13 may be implemented at least in part in software executed on a processor within the cryptographic engine 8. However, in this example, the control logic 13 is pure hardware - that is, a finite state machine implemented with dedicated digital logic.

[0063] The control logic 13 is connected to the LTE radio 7 via a communication channel 15 for receiving information about the transmit state of the LTE radio 7. This channel 15 may be implemented on the system bus 10 - for example, if the LTE radio 7 is the bus master of the bus 10 and uses the bus 10 to write to the register interface of the control logic 13. However, in this example, the channel 15 comprises a physical link separate from the system bus 10. It may comprise one or more dedicated lines, or it may be a channel within a more complex peripheral-to-peripheral interconnect system, such as the programmable peripheral interconnect described in WO 2013 / 088121 or WO 2020 / 002423 of Nordic Semiconductor. In embodiments where both the LTE radio 7 and the cryptographic engine 8 include respective processors for executing software instructions, the channel 15 may be provided by an inter-processor communication (IPC) link, such as described by Nordic Semiconductor in WO 2019 / 149731.

[0064] The radio 7 may switch to the active state just when it begins transmitting a radio signal, or, in some embodiments, a predetermined period of time before it begins transmitting (e.g., when it wakes up ready to transmit). In some embodiments, the radio 7 may remain in the active state during brief pauses between successive transmissions, or it may switch to an inactive, non-transmitting state during any interval. Once the transmission session is over, the radio 7 leaves the active state (i.e., switches to the inactive state), which may correspond to a low-power sleep state of the radio 7. It may switch to the inactive state just when it finishes transmitting a radio signal, or, in some embodiments, within a predetermined period of time after it stops transmitting.

[0065] NVM 16 stores software executed by processor 5 to control the operation of wireless temperature sensor 1. In use, processor 5 uses I / O peripheral 9 to obtain temperature readings from thermometer 4 at regular intervals and stores these readings in NVM 16. Wireless temperature sensor 1 periodically transmits a log of temperature information to a network base station (not shown) using LTE-M radio 7, which can be relayed to a destination (e.g., a server on the Internet). Before transmitting the log data over the radio, processor 5 instructs cryptographic engine 8 to encrypt the log data using AES to protect user confidentiality.

[0066] Figure 2 Sensor 1 is shown to be subject to a local side-channel attack. An attacker has physically connected a probe 20 between an external computer 21 and the power line between the battery 3 and the microchip 2 of the sensor 1. Computer 21 uses probe 20 to monitor the current consumption of chip 2. By analyzing fluctuations in the current, such as occurring at frequencies corresponding to switching frequencies within AES unit 12, the attacker can use computer 21 to apply statistical cryptanalysis techniques to attempt to discover the private AES key and / or confidential input data processed by AES unit 12. In some attacks, a tightly coupled electromagnetic (EM) field sensor can be used instead of electrical probe 20; this can be used to detect current fluctuations without physical contact; however, it still requires proximity to sensor 1. By using the methods disclosed herein, the threat from such local attacks is significantly reduced.

[0067] Figure 3 Sensor 1 is shown to be subject to a remote side channel attack. An attacker uses a radio scanning system 30 to analyze radio transmissions emanating from antenna 11 of sensor 1. Scanning system 30 may be remote from sensor 1 - for example, tens of meters, hundreds of meters, or even kilometers. Scanning system 30 detects unintentional amplitude modulation of a radio carrier transmitted by radio 2, which may reveal information about operations occurring within AES unit 12 due to unintentional coupling of switching frequencies in AES unit 12 with the analog transmission path. An attacker may use computer applied statistical cryptanalysis techniques to attempt to discover the private AES key and / or confidential input data processed by AES unit 12. By using the methods disclosed herein, the threat from such remote attacks is significantly reduced.

[0068] Figure 4 This paper outlines the main steps that the cryptographic engine 8 performs during an AES encryption operation to reduce the threat from side channel attacks, both local and remote. The same principles may apply to other operations such as AES decryption, other symmetric key operations, asymmetric key cryptographic operations, etc.

[0069] In a first step 40, the control logic 13 causes the AES unit 12 to receive the private AES key (e.g., by instructing the key storage area 14 to load the key into a key register of the AES unit 12) and begin receiving plaintext data for encryption (e.g., from the RAM 6 or NVM 16, via the main bus 10, using direct memory access, DMA).

[0070] The control logic 13 then uses the communication channel 15 from the LTE radio 7 to determine 41 whether the radio 7 is active. If the radio is not active, the control logic 13 enters a loop in which it continues to check at intervals (e.g. every millisecond). The control logic 13 prevents the AES unit 12 from processing AES keys or plaintext data at this stage.

[0071] When the radio is determined to be transmitting, the control logic 13 instructs the AES unit 12 to begin performing 42 AES encryption. If the radio 7 signals an active state a short period of time before it actually begins transmitting (e.g., a warm-up period), the control logic 13 may implement a delay before instructing the AES unit 12 to ensure that the radio 7 actively sends encryption operations before they begin.

[0072] Importantly, the AES unit 12 performs only a portion of the full encryption operation - namely, the first component process in the operation. This first component process may be specified in different ways depending on the usage requirements. For example, the AES unit 12 may perform only a portion of a single block operation - e.g., only the first n rounds of ten rounds of 128-bit AES block operations for n<10. Alternatively, where there are many blocks of plaintext data to be encrypted, the AES unit 12 may encrypt only the first n% of the blocks for n<100. The control logic 13 prevents the AES unit 12 from completing the encryption operation until instructed to do so.

[0073] The control logic 13 then uses the communication channel 15 again to determine 43 whether the radio device 7 is still actively transmitting. While the radio continues to transmit, the control logic 13 enters a loop in which it continues to check every once in a while - for example every millisecond. It prevents the AES unit 12 from continuing the AES operation at this stage.

[0074] When it is determined that the radio has stopped transmitting, control logic 13 instructs AES unit 12 to continue performing 44 AES encryption - i.e., to perform the second component process in the complete AES operation. For example, AES unit 12 may perform the remaining single block encryption rounds, or may continue to encrypt the remaining plaintext blocks.

[0075] After the full encryption operation is completed, the ciphertext is output as 45.

[0076] Of course, the receipt of plaintext data may be ongoing throughout the operation, not just at the beginning. Similarly, the output of ciphertext may be ongoing, not just at the end.

[0077] By performing the first stage of AES encryption while the radio transmitter is active, such as Figure 2 Any current signal detected by the probe 20 shown will be dominated by the current drawn by the amplifier and other components within the LTE radio 7. This can mask any signal leakage from the AES unit 12, making it more difficult to perform a successful local cryptanalysis attack on this first part of the encryption operation, and therefore more difficult to attack the entire encryption operation.

[0078] By performing the second stage of AES encryption when the radio transmitter is inactive, side channel emissions from the AES unit 12 during this second stage are not amplified and transmitted as a radio signal from the antenna 11. Figure 3 A remote attacker of the illustrated radio scanning system 30 would therefore be unable to determine any information about the second portion of the cryptographic operation, making it more difficult or impossible to perform a successful remote cryptanalytic attack on the cryptographic operation as a whole.

[0079] When the first and second component processes are distinguished by processing different blocks of plaintext data, the protection provided by this approach can be enhanced by using a block operation mode that more closely links the respective block operations of the two processes together, such as cipher block chaining (CBC), propagated cipher block chaining (PCBC), cipher feedback (CFB), output feedback (OFB), or counter (CTR) modes. This helps ensure that even if an attacker discovers information about one component process of the operation, this is unlikely to facilitate an attack on the other component process.

[0080] In some embodiments, the amount of processing performed in the first component cryptographic process (in step 42) may vary between consecutive cryptographic operations. The second component process (in step 44) may be adjusted accordingly. For example, in one AES encryption operation, the first component process may perform the first five rounds of 256-bit AES block encryption operations and the second process may perform the remaining nine rounds, while in the next AES encryption operation, the first process may perform the first eight rounds of 256-bit AES block encryption operations and the second process may perform the remaining six rounds. The control logic 13 may use a pseudo-random number generator to determine a random split between the first and second component processes, which may vary between consecutive operations.

[0081] Many side-channel attacks rely on the attacker monitoring many instances of the same operation - for example, encrypting the same plaintext data with the same key, albeit with a different random initialization vector each time. By varying the percentage of complete operations that an attacker (local or remote) might be able to observe, such statistical attacks can be made much less likely to succeed in a realistic time frame.

[0082] Further randomness may be introduced by the control logic 13 by not necessarily starting the first process 42 or the second process 44 immediately upon detecting that the radio 7 is in an appropriate state to transmit, but rather after a random time delay (optionally with a guaranteed minimum value). This may make masking of local transmissions from the AES unit 12 when the radio 7 is transmitting more effective by avoiding the presence of a predictable time connection between the action of the AES unit 12 and the action of the radio transmitter 7.

[0083] The order in which the component processes are performed may be reversed. Figure 5 Shown with Figure 4 A very similar variant of the process in , but in which the control logic 13 first waits 51 until the radio 7 is not transmitting before starting the first cryptographic process 52, then waits 53 until the radio 7 actively transmits 53, and then continues with the second cryptographic process 54 to complete the entire cryptographic operation.

[0084] The cryptographic operation may be divided into more than two stages, with the transition from each stage to the next occurring only after the radio 7 changes transmit state. However, in some circumstances this may delay successful completion of the operation by an unacceptable amount and so having only two stages may be preferable.

[0085] The control logic 13 may continue to monitor the transmit state of the radio 7 while the AES unit 12 is operating, and in some embodiments may suspend the first or second component process - by one of the processes - if it detects a partial change in the transmit state of the radio 7. It may then instruct the AES unit 12 to continue the suspended process upon detecting a reversal in the transmit state of the radio 7.

[0086] In some embodiments, it may be important that cryptographic operations complete within a reasonable period of time, even if the transmit state of the radio 7 has not changed. Therefore, the control logic 13 may use a timer to implement a timeout period while waiting to detect a change in transmit state. Upon timeout, the control logic 13 may signal a fault, or it may instruct the AES unit 12 to complete the operation. The latter approach may reduce security, but from a user experience perspective, it may be a necessary compromise to prevent the sensor 1 from being indefinitely blocked from performing cryptographic operations when there is a fault in the radio 7 or an attacker has control of the radio 7.

[0087] The cryptographic engine 8 may additionally employ hiding or masking techniques in conjunction with these approaches to provide even greater protection against side-channel attacks.

[0088] Those skilled in the art will appreciate that the invention has been illustrated by describing one or more specific embodiments thereof, but is not limited to these embodiments; many variations and modifications are possible within the scope of the appended claims.

Claims

1. An integrated circuit radio transmitter chip, comprising: Radio transmitters; Cryptographic engine; and Control logic for controlling the cryptographic engine, The cryptographic engine is configured to perform cryptographic operations by: receiving input data for said cryptographic operation; executing a first component process to generate first result data; executing a second component process to generate second result data; and generating output data representing a result of the cryptographic operation using the first result data and the second result data; and outputting the output data, wherein the control logic comprises a radio state input for determining whether the radio transmitter is in an active state in which the radio transmitter transmits one or more radio signals, and wherein the control logic is configured to use the radio status input to: In response to determining that the radio transmitter is in the active state, controlling the cryptographic engine to execute the first component process so that the radio transmitter transmits a radio signal when the cryptographic engine executes the first component process; preventing the cryptographic engine from executing the second component process when the radio transmitter is in the active state, so that the radio transmitter does not transmit any radio signals when the cryptographic engine executes the second component process; and In response to determining that the radio transmitter is not in the active state, controlling the cryptographic engine to perform the second component process.

2. An integrated circuit radio transmitter chip according to claim 1, wherein the cryptographic operation is any one of an encryption operation, a decryption operation, a signing operation, a signature verification operation, a hashing operation or a message authentication code operation.

3. An integrated circuit radio transmitter chip according to claim 1 or 2, wherein the input data comprises one or more of key data, plaintext data, ciphertext data, signature data, hash data or message authentication code data.

4. An integrated circuit radio transmitter chip according to claim 1 or 2, wherein the control logic is configured to control the cryptographic engine to perform the second component process before the first component process.

5. An integrated circuit radio transmitter chip according to claim 1 or 2, wherein the control logic is configured to control the cryptographic engine to execute the first component process and the second component process in an order depending on whether the radio transmitter is in the active state at a predetermined point within the cryptographic operation.

6. An integrated circuit radio transmitter chip according to claim 1 or 2, wherein the control logic is configured to: if the radio transmitter is not in the active state, cause the cryptographic engine to wait until the radio transmitter is in the active state and then execute the first component process.

7. An integrated circuit radio transmitter chip according to claim 1 or 2, wherein the control logic is configured to: if the radio transmitter is in the active state, cause the cryptographic engine to wait until the radio transmitter is not in the active state and then execute the second component process.

8. An integrated circuit radio transmitter chip according to claim 1 or 2, wherein the first component process and the second component process together include all steps performed by the cryptographic engine to generate the output data from the input data.

9. An integrated circuit radio transmitter chip according to claim 1 or 2, wherein the second component process uses the first result data in determining the second result data, or wherein the first component process uses the second result data in determining the first result data.

10. An integrated circuit radio transmitter chip according to claim 1 or 2, wherein the cryptographic operation comprises a plurality of identical rounds, and wherein the first component process comprises performing a first group of one or more of the rounds, and the second component process comprises performing a second group of one or more of the rounds, wherein the first group and the second group are non-overlapping groups.

11. An integrated circuit radio transmitter chip according to claim 1 or 2, wherein the first result data depends on a first part of the input data but not on a second part of the input data, and wherein the second result data depends on the second part of the input data but not on the first part of the input data.

12. An integrated circuit radio transmitter chip according to claim 1 or 2, wherein: The cryptographic engine is configured to perform the cryptographic operation on a plurality of blocks of input data, each block having a predetermined size; The first component process comprises performing a cryptographic algorithm on a first group of one or more blocks of input data; The second component process comprises performing the cryptographic algorithm on a second group of one or more blocks of the input data; and The first group and the second group are non-overlapping groups.

13. An integrated circuit radio transmitter chip according to claim 1 or 2, wherein the cryptographic engine is a hardware engine comprising electronic circuitry configured to perform the first component process and the second component process.

14. The integrated circuit radio transmitter chip of claim 1 or 2, further comprising: Processor; and a bus for transferring data to and from the processor, Wherein the radio status input is coupled to the radio transmitter via a connection separate from the bus.

15. The integrated circuit radio transmitter chip according to claim 1 or 2, wherein the control logic is configured to start the first component process within a predetermined time of determining that the radio transmitter is in the active state or detecting that the state of the radio transmitter becomes the active state.

16. The integrated circuit radio transmitter chip of claim 1 or 2, wherein the control logic is configured to start the second component process within a predetermined time of determining that the radio transmitter is not in the active state or detecting that the state of the radio transmitter becomes not in the active state.

17. An integrated circuit radio transmitter chip according to claim 1 or 2, further comprising a pseudo-random number generator for generating a pseudo-random value, and wherein the control logic is configured to change how many of the cryptographic operations are performed in the first component process or how many of the cryptographic operations are performed in the second component process between consecutive cryptographic operations performed by the cryptographic engine according to the pseudo-random value generated by the pseudo-random number generator.

18. An integrated circuit radio transmitter chip according to claim 1 or 2, further comprising a power management unit for supplying power to the radio transmitter and the cryptographic engine.

19. A wireless communication electronic device comprising an integrated circuit radio transmitter chip according to claim 1 or 2, and further comprising a power supply for providing power to the integrated circuit radio transmitter chip.

Citation Information

Patent Citations

  • Peripheral communication

    WO2013088121A1

  • Inter-processor communication

    WO2019149731A1

  • Peripheral power domains

    WO2020002423A1

  • An integrated circuit chip for encryption and decryption having a secure mechanism for programming on-chip hardware

    CN101014923A

  • Methods and nodes in a wireless communication network

    CN106922217A