Processing system and method using adjustable code-based masking

By using the encoding matrix A in the processing system to encode the input information word and the operands of the basic operation, and using the pseudo-inverse matrix and pseudo-inverse transpose matrix of the encoding matrix A in the multiplication operation, the problem that the processing system in the prior art is difficult to prevent non-invasive attacks when executing the processing function, and effectively protects the execution of the processing function.

CN120162800APending Publication Date: 2025-06-17SECURE IC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411839163.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-12-15
Filing Date
2024-12-13
Publication Date
2025-06-17

AI Technical Summary

Technical Problem

Existing processing systems are difficult to effectively prevent non-invasive attacks when executing processing functions, especially when noise levels are low, Boolean masking lacks protection, common transitional leakage reduces the protection level, and processing systems also face the risk of physical interference and failure.

Method used

A processing system is provided that is configured to execute a processing function f(x) in response to receiving the input information word x. The system includes a protection device, determines the information code and the masking code through the encoding matrix, generates an encoding matrix A, and uses the matrix to encode the input information word and the operand of the basic operation, and masks it using the pseudo-inverse matrix of the encoding matrix A and the pseudo-inverse transpose matrix of the encoding matrix A when performing the multiplication operation.

Benefits of technology

Through improved masking scheme, the execution of processing functions is effectively protected from side channel attacks and fault injection attacks, and the security and reliability of processing systems are improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120162800A_ABST
    Figure CN120162800A_ABST
Patent Text Reader

Abstract

Processing systems and methods using adjustable code-based masking are disclosed. A processing system configured to execute a processing function f (x) in response to receiving an input information word x comprising k information symbols, comprising: a protection device configured to protect execution of the processing function; and a processing unit for performing a processing function by decomposing its execution into one or more base operations, the base operations including one or more base operations, the base operations including at least a component-by-component multiplication operation, the processing unit including a multiplier performing the multiplication operation. The protection device determines an encoding matrix A from an information code that is linear and is randomly determined and a masking code, and the processing device comprises an encoder configured to encode an input information word x and each operand of a base operation using the encoding matrix A prior to execution thereof. The multiplication performed by the multiplier is further masked using a pseudo-inverse matrix A-1 of the coding matrix A and a pseudo-inverse matrix A-T of the coding matrix A such that (AT)-1 = (A-1) T.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention generally relates to the protection of processing devices, and more particularly, to a processing system configured to protect the execution of processing functions. Background Art

[0002] As part of a great effort to enhance the security of processing systems such as smart cards, mobile devices, and smart Internet of Things devices, security implementations must comply with international / national standards before being put on the market.

[0003] A processing system such as an encryption system can implement a processing function applied to an input information word. For example, in the AES encryption algorithm, the algorithm applies the AES function to the input information word.

[0004] To implement a processing function, several basic operations such as addition and multiplication are usually performed.

[0005] However, the basic operations performed to execute a processing function must be protected against non-invasive attacks that attempt to correlate the leakage of some operations with a hypothesized model.

[0006] Non-invasive attacks can use power consumption, electromagnetic (EM) radiation, and timing measurements to extract information. The measurement techniques rely on the data-dependent internal behavior of the underlying system. Exemplary non-invasive attacks include power analysis attacks. Power analysis can be used to identify specific parts of the program being executed to trigger timing faults that can be used to bypass key checks.

[0007] A known solution to protect arithmetic operations from such attack threats is masking, as described in Stefan Mangard, Elisabeth Oswald, and Thomas Popp, "Power Analysis Attacks: Revealing the Secrets of Smart Cards," Springer, December 2006, ISBN 0-387-30857-1. "Masking" refers to changing the intermediate variables of a computation to random versions, thus decorrelating them from the unprotected variables, each of which is a potential target for side-channel attacks.

[0008] In particular, mainstream methods include using pure Boolean masking (BM). This is the case for widely used and standardized ciphers such as DES (Data Encryption Standard) and AES (Advanced Encryption Standard). In both examples of DES and AES, most cryptographic operations (except for simple data movement, which does not leak by itself) are implemented using XOR and lookup tables (LUTs). Boolean masking (BM) should be configured to achieve high-order protection. However, when the noise level is low, Boolean masking offers no protection at all, and common transition leaks reduce the protection level.

[0009] Another method of performing masking is called Inner Product Masking (IPM). IPM will reduce or even prevent transition leaks. However, this method is also affected by the noise level dependency. More generally, IPM can be further enhanced by using better linear codes and extended to other masking schemes.

[0010] In addition, the processing system can also be a victim of physical interference, which may lead to result corruption. Such faults are harmful to both processing system security and network security. In fact, from a security perspective, incorrect results may produce undefined behavior, which will have serious consequences unless detected. From a network security perspective, an attack may lead to an exploitation path for cryptanalysis. Detection is a technique to prevent such destructive consequences. However, generally, detection is difficult to build into the processing system and may also conflict with passive side-channel protection.

[0011] Therefore, there is a need for improved systems, methods, and computer program products for improving the protection of processing functions implemented by a processing system against non-invasive attacks. SUMMARY OF THE INVENTION

[0012] To solve these and other problems, a processing system is provided that is configured to execute a processing function f(x) in response to receiving an input information word x including k information symbols. The processing system includes protection means configured to protect the execution of the processing function. The processing system includes a processing unit configured to execute the processing function, the processing unit being configured to decompose the processing function f into one or more basic operations, the one or more basic operations including one or more elementary operations between two operands, the elementary operations including at least a component-wise multiplication operation. The processing unit includes a multiplier configured to execute the multiplication operation, and the protection means at least includes:

[0013] - a coding matrix determination unit configured to: randomly determine an information code C and a masking code D as linear codes, the information code and the masking code satisfying one or more predefined code attributes; and determine a coding matrix A from the information code and the masking code, the coding matrix A being determined by vertically stacking the vectors of the information code and the vectors of the masking code;

[0014] - An encoder configured to apply an encoding operation to an encoder input including information symbols, the encoding operation including encoding the encoder input using an encoding matrix A, which provides an encoded word corresponding to the encoder input.

[0015] A processing device is configured to apply the encoder to an input information word x and to each operand of a basic operation, each basic operation being applied to an encoded word determined by the encoder for each operand.

[0016] The multiplication operation performed by the multiplier further uses the pseudo-inverse matrix A of the encoding matrix A -1 and the pseudo-transpose matrix A of the encoding matrix A -T to be masked such that (A T ) -1 =(A -1 ) T .

[0017] In some embodiments, the encoding matrix A can be applied by the encoder to fill k information symbols of the encoder input with m random numbers, and the output of the encoder is a masked vector where n≥k+m, the masked vector belongs to the encoding matrix A is a (k+m)×n matrix over the field .

[0018] In some aspects, in response to receiving an encoder input X, the encoder is configured to determine a random mask and an error indicator and encode the encoder input using the encoding matrix A, the random mask M X and the error indicator ∈ X .

[0019] In some embodiments, the encoder output can be determined as:

[0020]

[0021] The encoding matrix belongs to and n′=k+m+e.

[0022] In some aspects, in response to receiving two inputs masked by the encoder and the multiplier can be configured to:

[0023] - Determine the cross product W of the masked vectors and the cross product W of the random matrices as

[0024] - For A-T W applies the flatten function, which provides the flattened matrix T, defined as T = flatten(A -T W), where A -T is the pseudo-inverse transpose matrix of the encoding matrix A;

[0025] - The matrix T and the matrix are flattened by performing The product of the multiplication is determined by Make

[0026] In response to receiving two inputs masked by the encoder and The multiplier can be configured as:

[0027] -exist The random seed sd is uniformly determined in;

[0028] - Determine the random matrix from the random seed

[0029] -Determine the cross product of the masked vector and the sum of the random matrix W as

[0030] -To A -T W applies the flatten function, which provides the flattened matrix T, defined as T = flatten(A -T W), where A -T is the pseudo-inverse transpose matrix of the encoding matrix A;

[0031] - The matrix T and the matrix are flattened by performing The product of the multiplication is determined by Make

[0032] In some aspects, the elementary operation may further include a component-wise addition operation, and the processing device may include an adder configured to perform the addition operation using input previously encoded by the encoder.

[0033] In some aspects, the protection device may further include a decoder configured to decode a character previously encoded by the encoder. Applying the decoding operation, the decoder is configured to use the encoded word and the pseudo-inverse matrix A of the encoder matrix A -1 A decoder output comprising the original data X is provided.

[0034] The decoder output may also include a random mask associated with the output raw data X and error indicators and the decoding operation DEC applied by the decoder msk It can be defined by the following formula:

[0035]

[0036] In some aspects, the protection device may further include a refresh unit configured to perform a refresh operation at one or more instants during the execution of the processing function, the refresh operation including determining a refreshed encoded word for an encoder input word X that was previously applied to the decoder. To determine the encoded word Such that the encoded word and the refreshed encoded word both correspond to the same input information word X, the refresh unit being configured to replace the encoded word with the refreshed encoded word

[0037] In some aspects, the protection device may further include a checking unit configured to perform a checking operation, the checking operation including checking whether a calculation error has occurred in an operation performed by an encoder, an adder, or a multiplier.

[0038] The checking unit may be configured to: check whether an error indication variable ∈X associated with the word X satisfies the condition ∈X = cst, where cst is a predefined constant; and detect whether an error has occurred based on the condition.

[0039] Wherein, if ∈x = cst, no error is detected, and if the error indication variable ∈X is different from the predefined constant cst, the checking unit may be configured to further apply syndrome decoding techniques using the syndromes of linear codes to determine whether an error has occurred.

[0040] In some aspects, the masking code may have the maximum possible dual distance in the finite field of interest to the application to meet the security code standard, and / or the masking code may be sparse or structured to meet the performance power area (PPA) code standard.

[0041] In some aspects, the information code and the random code for generating the encoding matrix A have no intersection of non-zero codewords.

[0042] In one embodiment, the encoding matrix A may be generated from a Vandermonde matrix.

[0043] There is also provided a method implemented in a processing system for executing a processing function f(x) in response to receiving an input information word x including k information symbols, the method including protecting the execution of the processing function. The execution of the processing function includes decomposing the processing function f into one or more basic operations, the basic operations including one or more elementary operations between two operands, the elementary operations at least including a multiplication operation, the multiplication being a component-wise multiplication, and the processing function execution steps include:

[0044] - Randomly determine an information code and a masking code as linear codes, where the information code and the masking code satisfy one or more predefined code attributes;

[0045] - Determine an encoding matrix A from the information code and the masking code, where the matrix A is determined by vertically stacking the vector of the information code and the vector of the masking code;

[0046] - Before performing a basic operation, apply an encoding operation to an input information word x for each operand of the basic operation, where the encoding operation includes encoding the input received in the encoding step using the encoding matrix A;

[0047] - Perform one or more basic operations by applying the basic operation to the encoded operands in the encoding step;

[0048] wherein, the multiplication operation further uses the pseudo-inverse matrix A 11 of the encoding matrix A and the pseudo-inverse transpose matrix A -T of the encoding matrix A to be masked. BRIEF DESCRIPTION OF THE DRAWINGS

[0049] The drawings incorporated in this specification and constituting a part of this specification illustrate various embodiments of the present invention and, together with the general description of the present invention given above and the detailed description of the embodiments given below, are used to explain the embodiments of the present invention.

[0050] Figure 1 depicts a processing system according to an embodiment of the present invention.

[0051] Figure 2 is a detailed diagram of a protected system according to some embodiments.

[0052] Figure 3 is a flowchart depicting a masked encoding method according to some embodiments of the present invention.

[0053] Figure 4 is a flowchart depicting a masked multiplication method according to some embodiments of the present invention.

[0054] Figure 5 is a flowchart depicting a masked multiplication method using internal randomness according to some embodiments of the present invention.

[0055] Figure 6 is a flowchart depicting a method for detecting errors implemented by an inspection unit according to some embodiments of the present invention.

[0056] Figure 7 is a flowchart depicting a method for executing a processing function according to some embodiments of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0057] Embodiments of the present invention provide a processing system and a method that use an improved masking scheme to protect processing functions implemented by the processing system.

[0058] Referring Figure 1 , an operating environment according to an embodiment of the present invention is shown. The operating environment includes a processing system 1 according to an embodiment of the present invention. The processing system 1 is configured to perform a processing function f on an input information word X including k information symbols (the input information word may also be represented as X in ).

[0059] The processing function f can be any function executed by the processing system 1, which can be decomposed into basic operations and possibly additional operations. The basic operations include one or more additions and / or multiplications. The processing function can be, for example, an encryption function (such as an AES or SM4 function), an inference function, a statistical function for input data, a mean function, or a variance function, etc.

[0060] In fact, these two basic operations (addition and multiplication) are universal because any digital calculation involved in the processing executed by the processing system 1 can be achieved by interleaving them. They are equivalent to evaluating arbitrary polynomials that interpolate the processing function. More additional operations can be added, such as scaling (i.e., multiplying by a constant), exponentiation (i.e., iterative multiplication), etc. Decomposing the processing function into basic operations (basic operations and additional operations) can be determined to optimize performance.

[0061] The processing system 1 can be any information processing system, device, chip, or circuit that executes the processing function, such as, for example but not limited to, a smart card, a mobile device, a smart Internet of Things device, or an encryption system. Some embodiments of the present invention will be mainly described with reference to an encryption system for illustrative purposes only.

[0062] The processing system 1 includes a protection device 10 configured to protect the execution of the processing function by applying an improved masking scheme (hereinafter referred to as an adjustable code-based masking (TCBM) scheme) simultaneously against non-invasive physical attacks (such as side-channel attacks) and against (semi-) invasive attacks (such as fault injection attacks) in an appropriate configuration.

[0063] Advantageously, the masking scheme relies on an encoded matrix A, which is generated using at least two linear codes, including an information code C and a masking code D, with no non - zero codewords in their intersection (i.e., the information code C and the random code D used to generate the encoded matrix A have no intersection of non - zero codewords). The masking scheme uses these two linear codes to determine a random sharing of a key - related sensitive variable by confusing an information word with a random word. The random word can be generated by an on - chip true random number generator (TRNG) or directly input into the protection device 10.

[0064] The processing system 1 includes a processing device 11 configured to execute a processing function, which is configured to decompose the processing function f into one or more basic operations and possibly one or more additional operations, where the basic operations include one or more elementary operations.

[0065] The additional operations can be operations such as, but not limited to, scaling operations (such as multiplication by a constant), exponentiation operations (such as self - multiplication performed a given number of times), inverse operations, etc.

[0066] As used herein, an elementary operation refers to an addition operation or a multiplication operation. The addition operation and the multiplication operation are component - wise operations.

[0067] Figure 2 Represents the detailed structure of the processing system 1 according to some embodiments.

[0068] As Figure 2 shown, the processing device 11 may include an adder 104 configured to execute an addition operation and a multiplier 105 configured to execute a multiplication operation.

[0069] The protection device 10 may include an encoding matrix determination unit 101, which is configured to randomly determine an information code C and a masking linear code D. The information code C and the masking code D satisfy predefined code attributes. The encoding matrix determination unit 101 is also configured to determine the encoded matrix A based on the linear codes C and D.

[0070] Each of the information code C and the masking code D can be represented by a vector structure including a set of vectors. The matrix A is determined by vertically stacking the vectors of the information code C and the vectors of the masking code D.

[0071] The protection device 10 further includes an encoder 102 configured to apply an encoding operation to the original input information word X and each input (operand) of the basic operations (addition, multiplication), the encoding operation including encoding the received input using an encoding technique, which provides the encoded information word. Advantageously, the encoded operation applied by the encoder 102 is masked by an encoding matrix A. The encoding matrix A used by the encoder can then remain unchanged to perform a series of basic operations (addition and multiplication) into which the processing function is decomposed. Specifically, the encoding matrix A should always remain consistent until the calculation of the processing function terminates, at which time the decoder 110 can be invoked. It should be noted that decoding and re-encoding (i.e., with a new matrix A) are technically feasible. However, refreshing the encoding matrix A during the execution of the processing function may lead to intermediate vulnerabilities, i.e., leakage of unmasked variables or undetected variable corruption, in both cases, the "internal calculation" variables may become sensitive (i.e., dependent on the secret, or critical to the computational integrity).

[0072] In addition, the multiplication operation performed by the multiplier 105 uses the pseudo-inverse matrix A of the encoding matrix A -1 and the pseudo-transpose matrix A of the encoding matrix A -T to be masked. As used herein, A -T is a shorthand form of (A -1 ) T .

[0073] In an embodiment where A is a square matrix, the pseudo-inverse matrix A of the encoding matrix A -T is the inverse matrix, and the pseudo-transpose matrix A of the encoding matrix A -T is the transpose inverse matrix (therefore, the term "pseudo-inverse" is used herein for the general case where the encoding matrix is rectangular).

[0074] In some aspects, the encoder 102 can be configured to encode all internal variables involved in the execution of the basic operations (including internal variables involved in additional operations). In such an embodiment, only the initial data input X (also denoted as X in ) and the final output of f(X) can be plain text (uncoded). The initial data input X can initially be plain text (uncoded), but when it is used to execute the processing function, the initial data input X is encoded.

[0075] In some embodiments, the encoding matrix A specifies a general code-based masking (CBM) scheme, including filling k symbols with m random numbers to determine a masked vector of length n (n≥k + m) belonging to , and the encoding matrix A is a (k + m)×n matrix with elements in the domain .

[0076] In some embodiments, the random determination of the information code C and the masking code D includes selecting the information code C and the random D such that the codes C and D satisfy one or more code attributes, which may include security attributes and / or efficiency attributes in terms of PPA (performance, power, and area).

[0077] For example, in one aspect, the masking code D can be determined such that it has the maximum possible dual distance in the finite field of interest to the application to satisfy the security attribute.

[0078] In another aspect, the masking code D can be sparse (even in its subfields, such as when the main field is composite) or be constructed to meet the performance power area (PPA) criteria.

[0079] In some embodiments, the information code C and the masking code D are determined such that they do not overlap (except in {0}) and span the subspace.

[0080] The protection device 10 may further include a decoder 110 configured to apply a decoding operation to a word that has been previously encoded by the encoder 102 during the execution of a processing function (the input data x received by the processing system 1 and / or the input of the basic function). In response to the received encoded input The decoder 110 is configured to use the received encoded input and the pseudo-inverse matrix A of the encoder matrix A -1 to provide a decoder output including the original data X.

[0081] In some aspects, the protection device 10 may further include a refresh unit 106 configured to perform a refresh operation at one or more instants during the execution of the processing function, the refresh operation including determining a refreshed encoded word for the encoder input word X that has been previously applied to the encoder 102 to transmit the encoded word such that the encoded word and the refreshed encoded word both correspond to the same input information word X, and the refresh unit 106 is configured to replace the encoded word with the refreshed encoded word

[0082] The protection device 10 may further include a check unit 108 (also referred to as a "fault detection unit") configured to perform a check operation, the check operation including checking whether a calculation error has occurred in the operations performed by the encoder 102, the adder 104, and / or the multiplier 105.

[0083] ​Embodiments of the present invention can use masking to protect information from side-channel analysis (SCA) and fault injection attacks (FIA). Protection against side-channel analysis requires code-based masking using random numbers, while protection against fault injection attacks requires error detection coding on top of the masked information.

[0084] The protection device 10 is configured to ensure side-channel protection against side-channel attacks and perform fault injection detection.

[0085] To facilitate the description of some of the following embodiments, the following definitions are provided.

[0086] It is considered that the information processing system 1 manipulates an information word represented as a vector of information symbols, and the information symbols belong to a finite field which can be:

[0087] - The binary field, i.e., when the symbol is a bit vector of length q, or simply

[0088] - The prime field, i.e., where p is a prime number, when the symbol itself is an integer modulo p.

[0089] The following description of some embodiments of the present invention will mainly refer to any finite field of characteristic p (p is a prime number, equal to or greater than 2) Therefore, the symbol will be used to represent the finite field under consideration. For example:

[0090] - In an application of the present invention where the processing function is the AES or SM4 function, (byte-oriented),

[0091] - In an application of the present invention where the processing function is the lightweight cipher PRESENT function, (nibble-oriented),

[0092] - In an application of the present invention where the processing function is a post-quantum cryptographic algorithm, such as the Crystals Kyber function, or the Crystals Dilithium function,

[0093] The input information word x to be applied to execute the function f includes k symbols, which can be protected together (e.g., using the concept of "cost amortization").

[0094] Side-channel protection utilizes m independent random masks y.

[0095] Fault detection is applied to the top and allows the insertion of some redundancy so as to be able to verify that the data z has not been changed. It consists of applying a word of e symbols and checking its value at some points in the function execution method. For example, these e words are empty. The fact that the redundant "coverage" masks the data allows avoiding the weakening of this protection (which has a negative impact).

[0096] In the description of some of the following embodiments, the following symbols will be used:

[0097] - Capital letters (e.g., X) will be used for random variables, while lower-case letters (e.g., x) will be used for their realizations.

[0098] - Vectors and matrices (e.g., X) are generally written in bold characters, and subscripts (e.g., X i or X i,j ) are used to index the elements of such data structures.

[0099] - The parameters k, m, e, and n will be used respectively to denote the size of the information symbols, the size of the random mask, the size of the error detection indicator, and the size of the masked share.

[0100] The parameters k, m, e, and n are such that n ≥ k + m + e. In the following description, for simplicity and for illustrative purposes only, n′ = k + m + e will be considered, such that n ≥ n′.

[0101] All calculations performed by the protection device 10 and the processing device 11 are performed in a finite field .

[0102] Furthermore:

[0103] - The symbol X will denote any information variable (also called "information word") encoded by the protection device 10, which includes the initial input received by the processing system 1 to which the processing function f is to be applied, but also includes one of the inputs to which a basic operation is to be applied (the other input is denoted Y);

[0104] - Then, the symbol M X will be used to denote the mask variable associated with X;

[0105] - The symbol ∈ X will be used to denote the error indication variable associated with X;

[0106] - The symbol will be used to denote the encoded variable( for the other input Y);

[0107] - The symbol or will be used to denote the output produced by performing the basic operation, corresponding respectively to the original data l or l′.

[0108] In addition, some intermediate functions used in connection with embodiments of the present invention are further defined.

[0109] The first intermediate function is called the flatten function. The flatten function serializes a matrix into a vector by concatenating each row in the matrix. Specifically, the operator flatten transforms an I×J matrix M (with elements in ) into a vector containing all the elements, although these elements are in a linear arrangement:

[0110]

[0111] Taking the matrix M in Equation (1), the operation of the flatten function is defined according to Equation (2):

[0112]

[0113] The inverse operation of the flatten function (denoted as flatten -1 ) reshapes the vector into a matrix. More specifically, taking the (row) vector The inverse flatten function flatten -1 operates according to Equation (3):

[0114]

[0115] As used herein, the superscript 1×IJ on the symbol is used to indicate that the vector is horizontal.

[0116] The second intermediate function used in connection with embodiments of the present invention is called the "pick function". The pick function picks some elements from a vector. The pick function can be represented by a vectorized operation of multiplying by a matrix S.

[0117] While the flatten operator will produce a vector of length I·J when fed an I×J matrix, the pick operator picks the first element in the first J-symbol block, then the second element in the second J-symbol block, and so on. It will be considered that I≤J in the following description.

[0118] By induction, the matrix S in the pick operator is defined as:

[0119]

[0120] In Equation (4), each term S i is of size J×I and has only a single non-zero element (S i ), i,i where 1≤i≤I. If I≠J, then S is not a square matrix, but the pick operator remains unchanged.

[0121] More formally, take the vectors The pick function is defined according to Equation (5):

[0122]

[0123] By combining the two operators flatten and pick, take two vectors x, and I = J, the following nominal operations to be performed can be obtained:

[0124] pick(flatten(x T y)) = flatten((x T y)S = (x1y1,..., x I y I ) (6A)

[0125] The combined operator pick(f1atten(x T y)) actually selects the diagonal elements of the target matrix in a vector manner, so that:

[0126] diag(x T y) = pick(flatten(x T y)) = flatten((x T y)S (6B)

[0127] In the description of some of the following embodiments, the size of S will be specified according to the operation context.

[0128] The coding matrix A used by the adjustable code-based masking scheme is a matrix that converts k information symbols and m masking material symbols into a masked vector of length m (recall that n ≥ n’ = k + m + e)), which will detect e faults. Thus, the matrix A is a rectangular n′×n matrix in

[0129] In some embodiments, the coding matrix A can be, for example, a square matrix.

[0130] The coding matrix A specifies a general code-based masking scheme.

[0131] The inverse matrix of A is denoted as A -1 , and the pseudo-inverse transpose matrix of A is denoted as A -T . Thus A -1 and A -T satisfy the following equation:

[0132] (A T ) -1 = (A -1 ) T

[0133] Note that if the encoding matrix A is not square, a Vandermonde matrix V of size n×n can be used to define the encoding matrix A. The Vandermonde matrix V is related to Reed-Solomon codes because the generator matrix of Reed-Solomon codes is a Vandermonde matrix. Using a Vandermonde matrix to generate the encoding matrix is particularly advantageous because Reed-Solomon codes are optimal codes as they achieve the Singleton bound. Additionally, random Vandermonde matrices are easy to construct. As long as n distinct non-zero field elements α1,..., α n , are chosen and the matrix V is defined as V=(α j i-1 ), where 1≤i≤n is the row index and 1≤j≤n is the column index. In this case, the encoding matrix A can be written as:

[0134]

[0135] Therefore, the pseudo-inverse matrix of A (also denoted as A -1 ) is equal to:

[0136]

[0137] As mentioned above, a Vandermonde matrix is a matrix where each row has terms in geometric progression (a sequence of non-zero numbers where each term after the first term in a row is obtained by multiplying the previous term by a fixed non-zero number (also called the "common ratio")). Thus, for all zero-based indices i and j, the entry of the V matrix denoted as V i,j satisfies the relation where is the j-th power of the number v i .

[0138] Considering the above construction of A and A -1 , then:

[0139]

[0140] For each received input vector the protection device is further configured to determine a random mask and an error indicator The random mask can be refreshed as frequently as possible. The error indicator ∈ X can be set to a zero constant, for example. The random mask M X can be initialized by taking random values uniformly distributed over .

[0141] The random mask is generated (initialized) randomly.

[0142] Matrix A can be pre-computed and then used to encode any input data X.

[0143] Figure 3 is a flowchart depicting a masked encoding operation applied using the encoding matrix A generated by encoder 102 according to some embodiments.

[0144] The encoding matrix A is capable of processing the input information word x with k information symbols and filling these symbols with m random numbers and e null values to obtain a masked vector

[0145] In step 300, an input information vector is received

[0146] In step 301, a related random mask is determined and a related error indicator

[0147] In step 302, the generated encoding matrix A is received.

[0148] In step 303, using the encoding matrix A and the random mask M X to encode (or mask) the input information vector More specifically, given the information random mask and error indicator apply the encoder matrix in step 202 to mix X, M X and ∈ X , such that the unprotected input information vector X becomes a masked vector which is defined by:

[0149]

[0150] In equation (8), (X, M X , ∈ X ) is multiplied by matrix A.

[0151] In step 304, return the masked also hereinafter referred to as the vector protected by CBM. The masked vector can advantageously resist side-channel attacks of up to the highest order d s = d - 1, where d is the dual distance of the linear code D generated by the matrix and is equal to the m rows after the first k rows of A (i.e., the linear code D is generated by rows k + 1 to k + m in the encoding matrix A).

[0152] Specifically, if A has full rank, then d s can be equal to m.

[0153] Multiplication with matrix A as defined in equations (7) and (8) implements the general encoder 102, where n′ is defined by n′ = k + m + e.

[0154] The protection device 10 may include further fault detection capabilities implemented by the checking unit 108 with d f denoted such that d f = e.

[0155] Among the basic operations into which a processing function can be decomposed, multiplication is usually the most expensive operation in masking schemes.

[0156] The multiplication operation performed by the multiplier 105 corresponds to a component-wise product. The component-wise product of k information symbols is not a natural operation. The outer product is, but it produces k 2 cross-coupled products. Therefore, it is necessary to manage the return from the k 2 intermediate results to the important k results.

[0157] In the prior art, an unmasked component-wise product refers to an operation performed on two input vectors X and Y of the same length k:

[0158]

[0159] It should be noted that the parameter k in equation (9) is an arbitrary positive integer and is not limited to the length of the information word. In the presence of masking, the component-wise product involves all n shares and is thus more complex to implement.

[0160] The basic operations performed by the adder 104 or by the multiplier 105 involve two operands, which will be denoted hereinafter as x and y, or in their vector representations as X and Y, and which correspond to the input variables to which the basic operations associated with the execution of the processing function are applied. Although the same symbols x or X are used to specify one of the inputs to the adder or the multiplier, and the initial input received by the processing system 1 to which the execution function f is to be applied, it should be noted that they refer to different variables. This similar notation is used specifically to simplify the description of the encoding performed by the encoder 4, as it applies not only to the initial data received by the processing system 1 (also referred to as X in ), but also to the inputs received by the adder 104 or by the multiplier 105 before performing the addition or multiplication operations.

[0161] In fact, according to some aspects, the two inputs respectively received by the adder 104 or the multiplier 105 before performing the addition operation or the multiplication operation, namely the vectors x and y, are protected by the encoder 102 according to the encoding method described with reference to Figure 3 such that the encoder 102 provides the masked vectors and or its vector representation and are respectively defined by and . Additionally, any intermediate variables involved in the multiplication can be similarly masked.

[0162] The multiplier 105 is configured to apply the masked per-component product function prod msk to the inputs and where the inputs and are the masked vectors of X and Y respectively, defined as:

[0163]

[0164] Equation (10) is such that the unmasked variable is defined by:

[0165] l = prod(X, Y) = (X1Y1, X2Y2,..., X k Y k ).

[0166] The masked per-component product function can be redefined as:

[0167]

[0168] In Equation (11), the matrix S is the initialization of Equation (4), where I = J = n′, and is defined according to Equation (12):

[0169]

[0170] In fact, Equation (8) can be simplified using the following notation:

[0171]

[0172] Therefore, it follows that:

[0173]

[0174] Therefore, the right-hand side of Equation (11) can be written according to Equation (15) as:

[0175]

[0176] Figure 4 depicts a method for determining the masked per-component multiplication and from two masked variables received as inputs is a flowchart of the method.

[0177] In step 410, two masked variables are received and

[0178] In step 412, the pseudo-inverse matrix A of A is retrieved -1 the pseudo-inverse transpose matrix A of A -T and the matrix defined by Equation 12 The pseudo-inverse matrix A of A -T the pseudo-inverse transpose matrix A of A -T and the matrix defined by Equation 12 can be pre-computed and used for the complete execution of the processing function (which may include a series of elementary operations such as a series of additions and multiplications in the case of the AES algorithm).

[0179] In step 414, the cross product W of the masked vectors is determined from the first masked variable and the second masked variable such that

[0180] In step 416, the result of the multiplication is flattened by applying the flattening function to A T W, which yields the flattened matrix T defined as T = flatten(A -T W).

[0181] In step 418, the protected multiplication is determined by performing the product of the flattened matrix T and the matrix such that such that

[0182] In step 410, the result is returned

[0183] The end-to-end masked Equation (11) is inspired by the computation specified in Equation (6).

[0184] In Equation (15), the following variables are all masked:

[0185] - variables (aA) and (bA);

[0186] - variable (flatten(a T b)S)A.

[0187] In Equation (11), the expressions will be evaluated in the order controlled by the parentheses. Additionally, in some embodiments, the application of the left side of A in Equation (11) can be delayed. -T

[0188] It should be noted that the matrix ​It can be pre-computed to speed up the online computation instead of computing the pseudo-inverse matrix A of A in step 412 -1 and the pseudo-inverse transpose matrix A of A -T in the same step.

[0189] In some cases, if step 416 is not executed as expected, some vulnerabilities may occur (e.g., accidentally or unmasking). To prevent such vulnerabilities, in some embodiments, some internal randomness can be added to enhance the side-channel resistance in step 416 (the flattening step).

[0190] In such embodiments using internal randomness, the method for determining the masked element-wise multiplication may include generating a random matrix and using the random matrix in step 416 to enhance the side-channel resistance.

[0191] To introduce internal randomness and generate a random matrix, a parameter γ ∈ {0,..., n 2 -1} can be introduced, representing the linear index of a matrix of size n×n and defined by γ = μn + λ, where μ and λ ∈ {0,..., n - 1}. For simplicity, the notations B = A -T and B′ = A -1 will also be used.

[0192] The random matrix can be determined such that where diag represents the diagonal elements of the matrix, and 0 n′ is a zero vector of length n′.

[0193] For 0 ≤ i < n′, the element (i, i) of

[0194]

[0195] In equation (16), is the linearized vector of the matrix 2 of length n and is defined by . Then the solution exists in:

[0196]

[0197] In equation (17), M is an n 2 ×n′ matrix whose (i, j) coefficient is:

[0198] M i,j = B′ i÷n,j B′ i mod n,j (18)

[0199] For example, in the Magma computer algebra system, the solution of Equation (18) can be given by using the kernel matrix (kernelMatrix).

[0200] Then, the generation of the random matrix can include:

[0201] - Determining a random seed sd uniformly in ;

[0202] - Determining the kernel matrix of M, denoted as ker(M);

[0203] - Determining the random matrix

[0204] Using Equations (16) and (17), for 1 ≤ i < n′, each element (i, i) of is equal to 0. Therefore, the generated random matrix satisfies the following Equation (19):

[0205]

[0206] The determination of the masked component-wise product defined in Equation (11) can be enhanced by adding internal randomness according to Equation (20):

[0207]

[0208] The matrices S and used in Equation (20) are the same as the matrices used in Equation 11.

[0209] In fact, given the matrix M, according to Equation (6B), the diagonal elements of the matrix M are defined by the following equation:

[0210] diag(M) = pick(flatten(M)) = flatten(M)S

[0211] Equation (19) further indicates flattening

[0212] Therefore:

[0213]

[0214]

[0215] Therefore, according to Equation (20), the determination of the masked component-wise product defined in Equation (11) can be enhanced by adding internal randomness:

[0216]

[0217] The matrix S and Same as the matrix used in Equation (11).

[0218] Figure 5 Is a flowchart depicting a method for using the generated random matrix To determine the masked component-wise multiplication The method is implemented by the multiplier 105 in response to receiving two inputs previously encoded by the encoder 102 And And is implemented.

[0219] In step 501, retrieve the pseudo-inverse matrix A of A -1 The pseudo-inverse transpose matrix A of A -T And the matrix defined by Equation 12 The pseudo-inverse matrix A of A -T The pseudo-inverse transpose matrix A of A -T And the matrix May have been pre-computed and be used for all calculations performed by the encoder 102, adder 104, multiplier 105, and decoder 110 during the execution of the processing function.

[0220] In step 502, the matrix M and the matrix ker(M) are pre-computed according to Equation (18).

[0221] In step 503, determine the random seed sd, which is determined uniformly in .

[0222] In step 504, determine the random matrix By performing

[0223] In step 505, according to the first masked variable The second masked variable And the random matrix Determine the cross product of the masked vectors and the sum W of the random matrix such that

[0224] In step 506, flatten the multiplication result by applying the flattening function to A- T W, which yields the flattened matrix T, defined as T = flatten(A -T W).

[0225] In step 507, receive two masked variables And

[0226] In step 508, determine the protected multiplication By performing the product of the flattened matrix T and the matrix Such that

[0227] In step 510, the result is returned

[0228] With respect to the flowchart of FIG. NN, steps 502, 503, 504, and 505 have been added or modified. By using a random matrix Due to the elimination of and the indirect de-masking, potential vulnerabilities are repaired.

[0229] It should be noted that during the execution of the method, matrix M and ker(M) can be alternatively pre-computed instead of computing them in step 502.

[0230] Embodiments of the present invention provide an adjustable code-based masking (TCBM) method and apparatus for providing high-order protection to an encryption system against side-channel attacks. Advantageously, the TCBM method and apparatus are configured to detect faults against fault injection attacks.

[0231] Returning to Figure 1 , by using different blocks of protection device 10 and processing device 11, any function f of processing system 1 (e.g., any encryption function, such as AES(X), or any other function, such as sqrt(X)) can be protected and securely implemented.

[0232] The adjustable code-based masking (TCBM) scheme enables the efficient use of masked protection and processing operations, including:

[0233] - The masked encoding operation ENC applied by encoder 102 msk ;

[0234] - The masked decoding operation DEC applied by decoder 110 msk ;

[0235] - The masked addition operation ADD applied by adder 102 msk ; and / or

[0236] - The masked multiplication operation MULT applied by multiplier 105 msk .

[0237] The masked protection and processing operations using the TCBM scheme may further include:

[0238] - The masked refresh operation REF applied by refresh unit 106 msk ; and / or

[0239] - The masked check operation CHK applied by check unit 108msk 。

[0240] Note that although some aspects of the present disclosure are described herein in combination (notably the different components 102, 104, 105, 106, 108, 110), they may be used separately or independently or in different combinations depending on the components.

[0241] As referenced Figure 3 above, the encoder 102 is configured to apply a masked encoding operation ENC using the encoding matrix A defined by Equation (8) msk 。Given an input information word vector X, the masked encoding operation comprises encoding X into a masked variable X in accordance with X, a random mask M X , an error indicator ∈ and the encoder matrix A such that:

[0242]

[0243] In some aspects, the decoder 110 may be configured to apply a masked decoding operation DEC msk to the encoded input using the encoding matrix A. More specifically, given an input encoded word vector the masked decoding operation uses and the inverse matrix A -1 of the encoder matrix A to output the original data X such that:

[0244]

[0245] In Equation (23), A -1 is the pseudo-inverse matrix of A, defined according to Equation (7).

[0246] In some aspects, the adder 104 may be configured to determine a masked addition operation ADD msk using the encoder matrix A. The masked addition operation performed by the adder 104 is a component-wise addition. More specifically, the adder 102 is configured to: receive two encoded word vectors and which respectively correspond to original data X and Y previously encoded by the encoder 102 according to Equation (20) using the encoding matrix A; and apply the masked addition operation in accordance with and to determine an encoded word such that:

[0247]

[0248] The masked addition ADDmsk It is also component - by - component addition.

[0249] It should be noted that the symbol ‘+’ used in the above two equations is equivalent to the XOR in

[0250] According to other aspects, the multiplier 105 can be configured to apply a masked multiplication operation MULT ms k using the encoding matrix A. The multiplier 105 is more specifically configured to: receive two vectors and which correspond to the original data X and Y previously encoded by the encoder 102 according to Equation (20) using the encoding matrix A; and apply a masked multiplication operation to determine the encoded word, such as corresponding to Z such that is defined according to Equation (25):

[0251]

[0252] 2 can be determined accordingly according to Figure 4 or Figure 5 the multiplication method of, which determines

[0253] In some embodiments, the refresh unit 106 can be configured to determine a masked refresh operation REF msk using the encoding matrix A. Given an input encoded word vector which was previously encoded by the encoder 102 according to Equation (20), the refresh unit 106 is configured to output a new encoded word (‘refreshed encoded word’) using the encoder matrix A such that:

[0254]

[0255] Thus, the refreshed encoded word can be determined by applying component - by - component addition between (0, M′X, 0)A and the initially determined encoded word

[0256] The refresh calculation can be performed at any time for any input of the adder and / or multiplier and / or only for the initially received input word. The frequency of the refresh calculation can vary according to the application of the present invention.

[0257] In some aspects, the check unit 108 can be configured to perform a masked check operation CHK msk .

[0258] Figure 6is a flowchart depicting an inspection method implemented by an inspection unit according to some embodiments.

[0259] In step 600, an input encoded word vector is received Step 600 may further include receiving a predefined constant cst. The input encoded word vector received in step 600 can be any word encoded by the encoding unit 102, which can be decoded and then inspected. Specifically, step 600 can be applied to any encoded variable, including those input to the adder 104 and / or the multiplier 105.

[0260] In step 602, the decoder 110 performs according to Equation (23) by using the encoding matrix A to determine the first decoding of, which results in the original vector X.

[0261] Step 603 includes checking whether the error indication variable ∈X associated with X satisfies ∈X = cst, where cst is the predefined constant received in step 600.

[0262] In step 604, if it is determined that ∈X = cst, no error is detected (block 605).

[0263] In step 606, if it is determined that ∈X is different from cst (∈X ≠ cst), the syndrome decoding technique of using the syndrome of the linear code is used to check whether an error has occurred during the calculation. Syndrome decoding is a method of decoding a linear code on a noisy channel where errors may occur. Syndrome decoding is minimum distance decoding using a reduced lookup table.

[0264] If an error has occurred (block 607), the error can be notified (block 608). Otherwise, no error is detected (block 609).

[0265] For example, it can be regarded as the encoding matrix A generated by the Vandermonde matrix. Using the Vandermonde matrix as A has special advantages because the linear code generated by the Vandermonde matrix is an MDS (Maximum Distance Separable) code with a maximized distance. The dual code of the MDS code is also an MDS code, so the dual distance can be maximized, and thus the best side-channel protection d can be obtained s For example, A is a (transposed) Vandermonde matrix, which can be generated as follows:

[0266]

[0267] In the encoding matrix A according to Definition (29), for any different i, j ∈ [1, n], α i ≠ αj The encoding matrix A can be optimized by selecting the best element α for 1 ≤ i ≤ n such that d i is maximized at the bit level (e.g., at s ).

[0268] In addition, the following example will consider q = 8, and as in block ciphers such as AES or SM4, and the irreducible polynomial is: P(α) = α 8 = α 4 + α 3 + α 2 + 1. In addition, the parameters k, m, e, n, and n' are defined by k = 2, m = 2, e = 1, and n = 6, so n' = 5 < n.

[0269] An irreducible polynomial is a polynomial that cannot be factored into the product of two non-constant polynomials and is used to generate a finite field.

[0270] Then, the encoding matrix A is randomly generated as follows:

[0271]

[0272] Then the inverse matrix A -1 of the encoding matrix A is determined as:

[0273]

[0274] Then consider the following two random vectors:

[0275] (x, m x , ∈ x ) = (α 27 , α 147 , α 212 , α 8 , α 151 )

[0276] (y, m y , ∈ y ) = (α 226 , α 137 , α 65 , α 62 , α 6 )

[0277] Then, the encoder 102 will determine the corresponding masked vectors and as follows:

[0278]

[0279] ​Then, the adder 104 can use the masked addition operation ADD according to the following formula msk to determine the sum of and

[0280]

[0281] By using DEC msk to decode it can be verified that

[0282]

[0283] where z′ = (x1 + x1, x2 + y2) = (α 102 , α 158 ).

[0284] The multiplier 105 can further use the masked multiplication operation MULT according to Figure 5 the method of using a random matrix msk to determine the product of and

[0285] To simplify the description of this example, the matrices M and ker(M) are not shown below.

[0286] In Figure 5 step 503 of i.e., n 2 - n′ = 31, the random seed sd is determined as shown below

[0287]

[0288] In Figure 5 step 504 of then the random matrix is determined by performing

[0289]

[0290] which can be verified

[0291]

[0292] In step 505, then according to the first masked variable the second masked variable and the random matrix the matrix W is determined as which results in

[0293]

[0294] In step 506, by applying the flattening function to A -T W is used to flatten the multiplication result, which yields the following flattened matrix T, defined as T = flatten(A -T W):

[0295]

[0296] In step 508, the flattened matrix T and the matrix The product of Make

[0297]

[0298] In step 510, the result is returned

[0299] By using DEC msk decoding It can be verified:

[0300]

[0301] where l = (x1.x2, y1.y2) = (α 253 , α 29 ).

[0302] As formally analyzed in the prior art (such as Information Leakages in Code-based Masking: A Unified Quantification Approach by WeiCheng, Sylvain Guilley, Claude Carlet, Jean-Luc Danger, and Sihem Mesnager, IACR Trans. Cryptogr. Hardw. Embed. Syst., 2021(3): 465-495, 2021; or Optimizing Inner Product Masking Scheme by a Coding Theory Approach by WeiCheng, Sylvain Guilley, Claude Carlet, Sihem Mesnager, and Jean-Luc Danger, IEEE Trans. Inf. Forensics Secur., 16: 220-235, 2021), the upper bound of the side-channel resistance of a processing system is limited by the security order in the encoding (or decoding) of CBM.

[0303] The protection device 10 according to an embodiment of the present invention is based on an improved TCBM scheme, and its security order is determined by the dual distance of the underlying linear code generated by the coding matrix A.

[0304] Considering d s representing the side-channel security order, the coding matrix A can be split (or partitioned) into three submatrices as follows:

[0305]

[0306] In Equation (27), the submatrix The submatrix and the submatrix

[0307] Each submatrix obtained by the partitioning of the coding matrix A corresponds to a linear code respectively (i.e., each submatrix generates a corresponding linear code). Thus, the submatrix A k is associated with the linear code C, the submatrix A m is associated with the linear code D, and the submatrix A e is associated with the linear code E.

[0308] Considering the matrix subdivision defined by Equation (27), the side-channel security order of TCBM is defined by the following formula:

[0309]

[0310] In Equation (28), the linear code D is generated by the submatrix A m .

[0311] Advantageously, the protection device 10 can provide a fault detection capability against fault injection attacks, which is another important threat to cryptographic implementations.

[0312] In some embodiments, the checking unit 108 may be configured to cover computations performed by different components of the protection device 10 and the processing device 11, in particular computations performed inside the different components 102, 104, 105, 106, 110. For example, given two masked input vectors (x, m x , ∈ x ) and (y, m y , ∈ y ), the masked multiplication performed by the multiplier 105 returns not only the k pairwise products of the information, but also the m pairwise products of the masks and the e pairwise products of ∈ x and ∈ y . In addition, the refresh operation performed by the refresh unit 106 may occur on the complete codeword or selectively on the encoding of (information, mask). This allows the redundancy in the e elements injected not to be changed.

[0313] The checking unit 108 can implement several fault detection strategies.

[0314] For example, randomness can be (independently of the sensitive information) input into the e elements, and it can be checked at any point in the method implemented by the protection device 10 or the processing device 11 whether the operations performed on the random elements are the same as those performed on the actual data. Such random elements are also referred to as "canaries" in the security field. For example, if the processing function is related to AES and k = e, a protected AES and another AES can be performed on other unrelated data. Since end-to-end masking destroys the k elements and the e elements, and errors on the codeword are likely to affect the independent AESs, verification can be performed at the end of the ciphertext.

[0315] The e elements can also be the checksum of the masked data, which allows the freshness of the canaries, but leads to more leakage if the implementation is inadequate or defective.

[0316] A constant cst can be injected so that there is no need to verify an additional AES because the output is the same in the AES call.

[0317] According to another fault detection strategy, fault detection analysis can be performed in the basic operations of addition and multiplication, such as those performed by adder 104 and multiplier 105.

[0318] For example, consider two input vectors (x, m x , ∈ x ) and (y, m y , ∈ y ) and a constant cst:

[0319] - For the addition operation performed by adder 104, since addition uses two input operands (even), if there is no fault, the parameters ∈ x and ∈ y will be canceled out, such that the constant cst can be compensated again. For example, taking e = 1 to detect a single uniformly distributed fault, if there is any fault such that ∈ x ≠ cst or ∈ y ≠ cst, then the fault can be detected at the end, and for the fault coverage probability of the previous error indicator is 100%.

[0320] - For the multiplication operation performed by multiplier 105, after component-wise multiplication, we get ∈′ = prod(∈ x , ∈ y ). Assuming no fault, ∈′ is component-wise squared; then it must be multiplied by the reciprocal of cst for compensation. This can be achieved by performing a multiplication with the null information and a mask, but the error indicator part is the reciprocal of cst. In this case, cst is a non-zero element. For the detection of a single uniformly distributed fault, with the same setting (e = 1), the fault coverage probability is given by:

[0321] (The first part is for ∈ x ≠ 0, and the second part is for ∈ x = 0).

[0322] For one error indicator on y the same reasoning also applies.

[0323] Therefore, the fault detection ability implemented by the check unit 108 can be mainly determined by e error indicators ∈, which generally leads to a high fault detection coverage rate in the calculations under mild conditions.

[0324] Figure 7 depicts, according to some embodiments, in response to receiving an initial information word x (also denoted as x in)Flowchart of the method for executing the f processing function. This method is implemented to securely determine f(x) (also denoted as f(x in ))

[0325] In step 700, an initial information word x (also denoted as x in ) containing k information symbols is received

[0326] In step 702, the encoding matrix A is determined according to the information code C and the masking code D

[0327] In step 704, the processing function is decomposed into a basic operation including one or more basic operations and possibly one or more additional operations. The basic operations include one or more basic operations including at least a multiplication operation. The basic operations may also include one or more addition operations

[0328] It should be noted that steps 702 and 704 can be executed in a different order (reverse order or in parallel). In addition, step 704 can be executed first, and step 704 can be replaced by a step including decomposing the processing function into basic operations and additional operations using a pre-computed processing function

[0329] In step 706, the encoding operation ENC msk is applied to the initial information word x (also denoted as x in ) and each input of the basic operations resulting from the decomposition, thereby providing the encoded variables

[0330] In step 708, the basic operations are performed using the variables encoded in step 706 (protected variables) instead of the corresponding original variables (unprotected variables). The basic operations may include one or more addition ADD msk (step 709) and / or one or more multiplication MULT msk (step 710). Specifically, the multiplication operation MULTms k uses the pseudo-inverse matrix A of the encoding matrix A -1 and the pseudo-transpose matrix A of the encoding matrix A -T for masking

[0331] The additional operations may also be executed until all the basic operations are completed. The encoded variables may be refreshed once or at different instants

[0332] In step 712, in response to the calculation of all the basic operations, the decoding operation DEC msk () may be used to decode the variables encoded in step 706 or only some of them

[0333] The checking step can be implemented to detect whether a failure has occurred in previous calculations at different stages of processing, and if an error is detected, an error notification can be generated.

[0334] In step 714, if an error is detected, an error notification is returned. Otherwise, the result of executing the function f(x) (also denoted as f(x in )) is returned.

[0335] The processing system can be used in various applications, such as various consumer, commercial, industrial, and infrastructure applications. Those skilled in the art will readily understand that the present invention is not limited to cryptographic systems and can be applied to other processing systems 1, such as safety-critical systems (industrial systems, automotive systems, satellite systems, etc.) that comply with standards such as IEC 62443, ISO 26262, and ISO / SAE 21434. These standards require fault detection capabilities while also being able to resist attacks, including side-channel attacks.

[0336] Embodiments of the present disclosure may take the form of embodiments that include only software, only hardware, or both hardware and software elements.

[0337] In addition, the methods described herein can be implemented by computer program instructions provided to a processor of any type of computer to produce a machine having a processor that executes the instructions to implement the functions / actions specified herein. These computer program instructions can also be stored in a computer-readable medium that can direct a computer to operate in a specific manner. To this end, the computer program instructions can be loaded onto a computer to cause a series of operational steps to be executed, thereby producing a computer-implemented process such that the instructions executed provide a process for implementing the functions specified herein. Specifically, the methods described herein can be implemented in a computer system.

[0338] It should be noted that the functions, actions, and / or operations specified in the flowcharts, sequence diagrams, and / or block diagrams can be reordered, serially processed, and / or processed simultaneously in accordance with the embodiments of the present disclosure. For example, steps 410 and 412 can be executed in a different order or even in parallel. In addition, any flowchart, sequence diagram, and / or block diagram can include more or fewer blocks than shown in accordance with the embodiments of the present disclosure.

[0339] Although the embodiments of the present disclosure have been illustrated by descriptions of various examples and these embodiments have been described in considerable detail, the intention of the applicant is not to limit or in any way restrict the scope of the appended claims to such details. Specifically, the present invention is not limited to the encoding matrix A generated using a Vandermonde matrix. In fact, the encoding matrix can generally be generated from any matrix that satisfies a plurality of properties including at least security properties, and the encoding matrix A is generated to meet security objectives in terms of dual distance. These properties can also include properties related to the PPA metric, and the encoding matrix A is generated to achieve a structure or sparsity so as to improve the PPA metric.

[0340] Other advantages and modifications will be readily apparent to those skilled in the art. Accordingly, the present disclosure in its broader aspects is not limited to the specific details, representative methods, and illustrative examples shown and described.

Claims

1. A processing system (1) configured to execute a processing function f(x) in response to receiving an input information word x comprising k information symbols, the processing system comprising protection means (10) configured to protect the execution of the processing function, wherein: The processing system (1) comprises a processing unit (11) configured to execute the processing function, the processing unit is configured to decompose the processing function f into one or more basic operations, the basic operation comprises one or more basic operations between two operands, the basic operation comprises at least a component-by-component multiplication operation, the processing unit comprises a multiplier (105) configured to execute the multiplication operation, wherein the protection device (10) comprises at least: - a coding matrix determination unit (101), which is configured to: randomly determine an information code and a masking code as linear codes, the information code and the masking code satisfying one or more predefined code properties; and determine a coding matrix A from the information code and the masking code, the coding matrix A being determined by vertically stacking a vector of the information code and a vector of the masking code; - an encoder (102) configured to apply an encoding operation to an encoder input comprising information symbols, said encoding operation comprising encoding said encoder input using said encoding matrix A, which provides an encoded word corresponding to said encoder input; wherein the processing means are configured to apply the encoder to the input information word x and to each operand of a basic operation, each basic operation being applied to the encoded word determined by the encoder (102) for each operand, The multiplication operation performed by the multiplier (105) further uses the pseudo-inverse matrix A of the encoding matrix A. -1 and the pseudo inverse transposition matrix A of the encoding matrix A -T to be masked, so that (A T ) -1 =(A -1 ) T .

2. The processing system according to claim 1, wherein: The encoding matrix A is applied by the encoder (102) to fill the k information symbols input by the encoder with m random numbers, and the output of the encoder (102) is a masked vector of length n. Where n≥k+m, the masked vector belong The encoding matrix A is the field The (k+m)×n matrix in .

3. A processing system according to any preceding claim, wherein: In response to receiving an encoder input X, the encoder (102) is configured to determine a random mask associated with the encoder input X. and error indicators And using the encoding matrix A, the random mask M X and the error indicator ∈ X The encoder input is encoded.

4. The processing system according to claim 3, wherein: The encoder output Determined as:

5. A processing system according to any preceding claim, wherein: In response to receiving (410) two inputs masked by the encoder (102) and The multiplier (105) is configured as: - Determine (414) the cross product W of the masked vector and the cross product W of the random matrix as -To A -T W applies (416) the flatten function, which provides a flattened matrix T, defined as T = flatten (A -T W), where A -T is the pseudo inverse transpose matrix of the encoding matrix A; - by performing the flattened matrix T and the encoded matrix The product of (418) is used to determine the multiplication result. Make Corresponding to the encoding of the original matrix by the encoder (102), The matrix S is divided into I sub-matrices S i , so that for 1≤i≤I, each submatrix S i is of size J×I and has only a single nonzero element (S i ) i,i .

6. A processing system according to any preceding claim from 1 to 4, wherein: In response to receiving two inputs masked by the encoder (102) and The multiplier (105) is configured as: -exist Uniformly determine (503) a random seed sd; - determining (504) a random matrix from the random seed - Determine (505) the sum W of the cross product of the masked vector and the random matrix as -To A -T W applies (506) the flatten function, which provides a flattened matrix T, defined as T = flatten (A -T W), where A -T is the pseudo inverse transpose matrix of the encoding matrix A; - by performing the flattened matrix T and the encoded matrix The multiplication result is determined by the product of Make Corresponding to the encoding of the original matrix by the encoder (102), The matrix S is divided into I sub-matrices S i , so that for 1≤i≤I, each submatrix S i is of size J×I and has only a single nonzero element (S i ) i,i .

7. A processing system according to any preceding claim, wherein: The basic operations also include a component-wise addition operation, and the processing device includes an adder (104) configured to perform the addition operation using input previously encoded by the encoder (102).

8. A processing system according to any preceding claim, wherein: The protection device further comprises a decoder (110) configured to decode a word previously encoded by the encoder (102). Applying a decoding operation, the decoder (110) is configured to use the encoded word and the pseudo-inverse matrix A of the encoder matrix A -1 to provide a decoder output, the decoder output comprising the original data 1.

9. The processing system according to claims 3 and 8, wherein: The decoder output also includes a random mask associated with the original data output 1 and error indicators and the decoding operation DEC applied by the decoder (102) msk Defined by:

10. A processing system according to any preceding claim, wherein: The protection device (10) further comprises a refresh unit (106) configured to perform a refresh operation at one or more instants during the execution of the processing function, the refresh operation comprising determining a refreshed encoded word for the encoder input word 1 previously applied to the decoder To determine the coded word In order to make the coded word and the refreshed coded word Both correspond to the same input information word X, and the refresh unit (106) is configured to refresh the encoded word Replace the encoded word 11. A processing system according to any preceding claim, wherein: The protection device (10) further includes a checking unit (108) configured to perform a checking operation, the checking operation including checking whether a calculation error occurs in an operation performed by the encoder (102), the adder (104) or the multiplier (105).

12. The processing system according to claims 3 and 11, wherein: The checking unit (108) is configured to check (603) an error indication variable ∈ associated with the word X X Whether the condition ∈ is satisfied X =cst, where cst is a predefined constant; and detecting whether an error occurs from the condition.

13. The processing system of claim 12, wherein: If ∈ X = cst, then no error is detected (604, 605), and if the error indicator variable ∈ X Different from the predefined constant cst, the checking unit is configured to further apply a syndrome decoding technique using syndromes of a linear code to determine whether an error has occurred.

14. A processing system according to any preceding claim, wherein: The encoding matrix A is generated from the Vandermonde matrix.

15. A method implemented in a processing system (1) for executing a processing function f(x) in response to receiving an input information word x comprising k information symbols, the method comprising protecting the execution of the processing function, wherein the execution of the processing function comprises decomposing the processing function f into one or more elementary operations, the elementary operations comprising one or more elementary operations between two operands, the elementary operations comprising at least a multiplication operation, the multiplication being a component-wise multiplication, the processing function execution step comprising: - randomly determining an information code and a masking code as linear codes, the information code and the masking code satisfying one or more predefined code properties; - determining a coding matrix A from the information code and the masking code, wherein the matrix A is determined by vertically stacking the vectors of the information code and the vectors of the masking code; - before executing said elementary operation, applying a coding operation to said input information word x and to each operand of the elementary operation, said coding operation consisting in coding the input received in the coding step using said coding matrix A; - performing said one or more elementary operations by applying elementary operations to said operands encoded in said encoding step; The multiplication operation further uses the pseudo-inverse matrix A of the encoding matrix A. -1 and the pseudo inverse transposition matrix A of the encoding matrix A -T Come to be covered.