Fault attack countermeasures using unified mask logic
By using random masks in a single circuit to cover up differences in logic execution characteristics, the problem of fault injection attacks damaging cryptographic keys is solved, achieving higher security protection for cryptographic keys.
Patent Information
- Application Number
- CN202480011419.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-02-14
- Filing Date
- 2024-02-02
- Publication Date
- 2025-09-16
AI Technical Summary
It is difficult for existing technologies to effectively prevent fault injection attacks from damaging cryptographic keys, especially because the ability to determine whether standard logic or inverted logic is used through side-channel observation is not sufficiently reduced.
A single circuit is used to implement standard logic or inverted logic. Random masks are used to mask differences in execution characteristics, ensuring consistency in characteristics such as power consumption. Masked comparison outputs are used to determine fault injection, and failed outputs are randomized to prevent information leakage.
This effectively reduces the ability of side-channel observation to determine logic types, prevents fault injection attackers from obtaining cryptographic key information, and improves the security of computing devices.
Smart Images

Figure CN120660318A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure generally relates to mitigating fault attacks that attempt to compromise secure assets, such as cryptographic keys. For example, aspects of the present disclosure relate to systems and techniques for performing fault attack countermeasures using unified masking logic. Background Art
[0002] Computing devices typically employ various techniques to protect data. As an example, data may be subjected to encryption and decryption techniques in various scenarios, such as writing data to a storage device, reading data from a storage device, writing data to a memory device or reading data from a memory device, encrypting and decrypting data blocks and / or data volumes, encrypting and decrypting digital content, performing inline cryptographic operations, and the like. Such encryption and decryption operations are typically performed, at least in part, using secure information assets, such as cryptographic keys, derived cryptographic keys, and the like. As computing devices become more advanced, more advanced techniques for protecting data may be employed. In some examples, attackers employ fault attacks (e.g., various forms of fault injection techniques) to ascertain information about cryptographic keys. In some examples, if an attacker successfully obtains a cryptographic key used when executing a cryptographic algorithm on a computing device, the security of any data protected using the cryptographic key may be considered to have failed. Therefore, it may be advantageous to develop techniques for protecting computing devices from such attacks. Summary of the Invention
[0003] This document describes systems and techniques for performing security processing. For example, a cryptographic algorithm can be executed using a single circuit that implements either standard logic or inverted logic based on a mask provided to the logic. By using a single circuit, the performance characteristics (e.g., power consumption) can be the same regardless of whether standard logic or inverted logic is used, which reduces the ability of various side-channel observations to determine which type of logic is being used.
[0004] According to at least one example, a process for security processing is provided. The process includes: obtaining a password input; obtaining a first mask and a second mask; executing a first logic circuit using the first mask and the password input to obtain a first output; executing a second logic circuit using the second mask and the password input to obtain a second output; and performing a comparison between the first output and the second output to determine whether the comparison is successful.
[0005] In another illustrative example, an apparatus for security processing is provided. The apparatus may include at least one memory and at least one processor coupled to the at least one memory. The apparatus may be configured to: obtain a password input; obtain a first mask and a second mask; execute a first logic circuit using the first mask and the password input to obtain a first output; execute a second logic circuit using the second mask and the password input to obtain a second output; and compare the first output with the second output to determine whether the comparison is successful.
[0006] In another illustrative example, a non-transitory computer-readable medium is provided having instructions stored thereon that, when executed by one or more processors, cause the processors to perform the following operations: obtain a password input; obtain a first mask and a second mask; execute a first logic circuit using the first mask and the password input to obtain a first output; execute a second logic circuit using the second mask and the password input to obtain a second output; and perform a comparison of the first output and the second output to determine whether the comparison is a successful comparison.
[0007] In another illustrative example, a device for security processing is provided that includes a unit for performing the following operations: obtaining a password input; obtaining a first mask and a second mask; executing a first logic circuit using the first mask and the password input to obtain a first output; executing a second logic circuit using the second mask and the password input to obtain a second output; and performing a comparison of the first output and the second output to determine whether the comparison is a successful comparison.
[0008] In some aspects, one or more apparatuses described herein are, are part of, and / or include a mobile or wireless communication device (e.g., a mobile phone or other mobile device), an extended reality (XR) device or system (e.g., a virtual reality (VR) device, an augmented reality (AR) device, or a mixed reality (MR) device), a wearable device (e.g., a connected watch or other wearable device), a vehicle or computing device or a component of a vehicle, a camera, a personal computer, a laptop computer, a server computer or server device (e.g., an edge or cloud-based server, a personal computer acting as a server device, a mobile device (such as a mobile phone acting as a server device), an XR device acting as a server device, a vehicle acting as a server device, a network router, or other device acting as a server device), a system on a chip (SoC), any combination thereof, and / or other types of devices. In some aspects, the apparatus includes a display for displaying one or more images, notifications, and / or other displayable data. In some aspects, the apparatus may include one or more sensors (e.g., one or more inertial measurement units (IMUs) such as one or more gyroscopes, one or more gyrometers, one or more accelerometers, any combination thereof, and / or other sensors).
[0009] This summary is not intended to identify key or essential features of the claimed subject matter, nor is it intended to be used alone to determine the scope of the claimed subject matter. The subject matter should be understood by reference to appropriate portions of the entire specification of this patent, any or all of the drawings, and each claim.
[0010] The foregoing and other features and examples will become more apparent after reference to the following description, claims, and accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0011] Illustrative examples of the present application are described in detail below with reference to the following drawings:
[0012] Figure 1 is a block diagram illustrating certain components of a computing device according to some examples.
[0013] Figure 2 is a diagram illustrating an example of a logic circuit for mitigating fault injection attacks according to some examples;
[0014] Figure 3 is a diagram illustrating an example of a logic circuit for mitigating fault injection attacks according to some examples;
[0015] Figure 4 is a diagram illustrating an example of a logic circuit for mitigating fault injection attacks according to some examples;
[0016] Figure 5 is a diagram illustrating an example of a logic circuit for mitigating fault injection attacks according to some examples;
[0017] Figure 6 is a flow chart illustrating an example process for providing countermeasures against fault injection attacks according to some examples;
[0018] Figure 7 is a diagram illustrating an example of a computing system for implementing certain aspects described herein. DETAILED DESCRIPTION
[0019] Provided below are certain aspects and examples of the present disclosure. As will be apparent to those skilled in the art, some of these aspects and examples can be applied independently, and some of them can be applied in combination. In the following description, for the purpose of explanation, specific details are set forth in order to provide a comprehensive understanding of aspects of the application. However, it will be apparent that each example can be implemented without these specific details. The accompanying drawings and description are not intended to be restrictive. Additionally, certain details known to those of ordinary skill in the art may be omitted to avoid ambiguous descriptions.
[0020] In the following description of the drawings, in the various examples described herein, any component described with respect to a drawing may be equivalent to one or more similarly named (or numbered) components described with respect to any other drawing. For the sake of brevity, the description of these components may not be repeated in full with respect to each drawing. Therefore, each and every example of a component of each drawing is incorporated by reference and is assumed to be optionally present in each other drawing with one or more similarly named components. Additionally, according to the various examples described herein, any description of a component of a drawing will be interpreted as an optional example that can be implemented in addition to, in conjunction with, or in place of the example described with respect to a corresponding similarly named component in any other drawing.
[0021] The description that follows provides only illustrative examples and is not intended to limit the scope, applicability or configuration of the present disclosure. On the contrary, the description that follows of the illustrative examples will provide a feasible description for realizing exemplary embodiments for those skilled in the art. It should be understood that, without departing from the spirit and scope of the present application as set forth in the appended claims, various changes may be made to the function and arrangement of elements.
[0022] As used herein, the phrase "operably connected" or "operably connected" (or any variation thereof) means that there is a direct or indirect connection between an element / component / device, etc. that allows the elements to interact with each other in some way. For example, the phrase "operably connected" can refer to any direct (e.g., directly wired between two devices or components) or indirect (e.g., a wired and / or wireless connection of a device that is operably connected, connected between any number of devices or components). Therefore, any path that information can travel through can be considered to be an operational connection. Additionally, devices and / or components that are operably connected can exchange things, and / or can unintentionally share things other than information, such as, for example, electric current, radio frequency signals, power supply interference, interference due to proximity, interference due to reuse of the same wire and / or physical medium, interference due to reuse of the same register and / or other logical media, etc.
[0023] This document describes systems, apparatus, processes (also referred to as methods), and computer-readable media (collectively, "systems and techniques") for providing countermeasures to mitigate the possibility of fault attacks compromising the security of computing devices. In some examples, cryptographic algorithms are used as building blocks for the security of computing devices, protocols executed thereon, and the like.
[0024] A cryptographic algorithm is an algorithm used to perform cryptographic operations (e.g., encryption and / or decryption of data). Examples of cryptographic algorithms include, but are not limited to, symmetric key algorithms (e.g., the Advanced Encryption Standard (AES) family of algorithms) and asymmetric key algorithms (e.g., public-private key cryptography). Cryptographic algorithms typically use cryptographic keys to perform cryptographic operations, such as encryption and decryption of data. Encryption refers to the process of converting plaintext into ciphertext using cryptographic keys and logic implemented in hardware (e.g., circuitry), software, firmware, or any combination thereof. Decryption refers to the reverse process, in which ciphertext is decoded back into plaintext, which can then be consumed by the relevant entity (e.g., computing device, software, etc.). Many cryptographic algorithms are designed so that, within reasonable limits of computing resources, it may be impossible to recover protected data without the cryptographic key, and it may be impossible to create the intended ciphertext without the cryptographic key. Therefore, the security of such cryptographic keys is important for protecting computing devices.
[0025] Techniques for preventing attackers from obtaining cryptographic keys typically include measures such as key lifecycle management, limiting physical and logical access to stored keys, limiting and protecting any transmission of keys to / from computing devices and / or within computing devices. However, such measures may not prevent types of attacks such as fault injection attacks. A fault injection attack can introduce a fault into a computing device and observe the results of the injection to obtain information about the cryptographic keys being used and / or the logic executing the cryptographic algorithm. As an example, certain bits used during the execution of a cryptographic algorithm can be flipped and / or intentionally maintained at a certain value (e.g., always zero or always one) during the execution of the cryptographic algorithm. Monitoring the effects of such fault injection can allow an attacker to obtain information that may ultimately lead to damage to the cryptographic keys and / or the logic executing the cryptographic algorithm.
[0026] Faults can be injected in any of a variety of ways. Techniques for injecting faults may include, but are not limited to, applying voltage, changing environmental conditions (e.g., temperature), applying electromagnetic pulses, modifying connections within the logic, and the like. A cryptographic key can be recovered by injecting a fault into one execution of a cryptographic algorithm without injecting it into another execution, and finding a difference in the output (e.g., a differential fault attack) or the absence of a difference (e.g., an invalid fault attack), either of which can be used to obtain information about the cryptographic key. Such information may include, for example, obtaining the key over time, narrowing the search space to find the key, and the like.
[0027] Solutions are needed to mitigate the effects of fault injection attacks that attempt to compromise cryptographic keys. Fault injection mitigation techniques have been proposed, such as circuit duplication, error-correcting codes, and secure multi-party computation, each of which involves some form of circuit duplication. Such techniques execute a cryptographic algorithm twice and compare the outputs. If the outputs match, the output can be used. If the outputs do not match, a fault injection may have occurred, in which case the output is randomized and not used for its intended purpose. However, such measures may be ineffective against fault attacks that do not alter the output (e.g., statistically invalid fault attacks). Such attacks can be somewhat mitigated by executing the cryptographic algorithm in both standard (e.g., non-inverting) logic and inverting logic, where the choice of which logic to use is determined by a randomly generated bit. For example, standard logic can be used when the random bit is zero, while inverting logic is used when the random bit is one. In this technique, whichever logic is used is executed twice, and the outputs can be compared. If the outputs of the two executions do not match, the output can be randomized and not used, while if the outputs match, the output can be used. As a result, an attacker may not be able to determine which logic was used, and therefore the impact of the fault injection. However, such logic (e.g., standard and inverted) may be implemented in separate circuits, meaning that an attacker may be able to determine which logic is used by using a side-channel attack (e.g., when the two circuit implementations have different power consumption characteristics, timing characteristics, electromagnetic characteristics, etc.).
[0028] The systems and techniques described herein provide countermeasures against such side-channel attacks used in conjunction with fault injection to obtain information about cryptographic keys. In some examples, a cryptographic algorithm is executed using a single circuit that implements either standard logic or inverted logic based on a mask provided to the logic. By using a single circuit, the characteristics of the execution (e.g., power consumption) can be the same regardless of whether standard logic or inverted logic is used, which reduces the ability of various side-channel observations to determine which type of logic is being used.
[0029] In some examples, any number of inputs (e.g., bits) are provided along with a random mask to a circuit that implements non-inverting (e.g., standard) and inverting logic for performing a cryptographic algorithm. In some examples, the non-inverting logic is any hardware (e.g., circuitry), software, firmware, or any combination thereof that implements logic configured to perform at least a portion of a cryptographic algorithm to produce an output, while the inverting logic produces an output that is an inverted version of the output of the standard logic. As a simplified, non-limiting example, a logic gate can be implemented (e.g., in a field programmable gate array (FPGA)) that, when implementing standard logic, produces any number of bits as output, while, when using inverting logic, the output is such that each bit is the opposite of the output produced using the standard logic (e.g., 10101010 (standard) versus 01010101 (inverted)). In some examples, when the mask indicates that standard logic is to be used, the input bits are provided to the circuit being used, but when the random mask being used indicates that inverted logic is to be used, the input bits are inverted before being provided to the circuit, resulting in an inverted output relative to the output obtained using standard logic, thereby allowing a single circuit to be used as standard logic or inverted logic. In some examples, a single random mask (e.g., a zero bit or a one bit) can be used to determine whether standard logic or inverted logic is used for all inputs. In some examples, there can be any number of bits in the random mask, each bit being used to determine whether standard logic or inverted logic is used for a portion of the inputs and outputs. As an example, the random mask can be a set of random bits whose number matches the number of input bits plus the number of output bits, and each bit of the random mask controls whether standard logic or inverted logic is used from the corresponding input bit or output bit. In such an example, the mask bits corresponding to the input bits can determine whether the input bits to be provided to the logic are inverted, and the mask bits corresponding to the output bits can be used to determine whether the output bits are inverted.
[0030] In some examples, two instances of a unique circuit are used, one of which is provided with a mask indicating that standard logic should be implemented, and the other mask is an inverted instance of the first mask, thereby indicating that inverted logic should be implemented. For any given execution, which circuit implements which type of logic is randomly selected based on the mask, so that any circuit can implement the standard logic for a given execution, while the corresponding other circuit implements inverted logic (via inverting the input bits, as described above). In some examples, two instances of the circuit are executed in parallel. In an example using a mask, in which the bits of the mask corresponding to the input bits and the output bits (as described above) are each random, different random masks can be used for two separate executions of the circuit instance, which can be executed in parallel or sequentially. In this example, the execution can be performed sequentially because the two multi-bit random masks are random and unrelated.
[0031] Thus, in some examples, an attacker attempting to obtain information about the cryptographic key being used via side-channel measurements to determine whether standard logic or inverted logic is being used cannot discern which type of logic is being used in which circuit. Additionally, in some examples, because the two circuits are identical, it can be ascertained that there are no differences in characteristics during execution (e.g., power, timing, etc.), further limiting the attacker's ability to learn which logic is being implemented, thereby preventing the attacker from being able to discern the effects of any invented faults, or the lack thereof.
[0032] In some aspects, to determine whether a potential fault injection attack has occurred, the outputs of the standard logic execution and the inverted logic execution are compared to determine whether the output of the inverted logic is indeed the inverse of the output of the standard logic. In some cases, if the comparison is successful, the output can be used. In some examples, if the comparison is unsuccessful (e.g., the inverted logic output is not the inverse of the standard logic output), the output can be randomized so that even if the output is obtained, it does not provide any useful information that could allow an attacker using fault injection to obtain any information about the cryptographic key or the logic being executed. As an example, randomization can include multiplying each output by a randomly generated number and then using the two randomized outputs to perform a logic operation (e.g., an exclusive OR (XOR) operation). In some examples where the random mask is a set of random bits corresponding to various input and output bits, the comparison may require knowing the mask applied to the individual logic executions in order to be able to perform the comparison.
[0033] Various aspects of the technology described herein are discussed below with respect to the accompanying figures. Figure 1 is a block diagram illustrating an example of a computing device 100. As shown, the computing device 100 includes a processor 102, a universal flash storage (UFS) device 104, a memory device 108, an additional storage device 110, a password input component 112, a mask provider 114, a cryptographic algorithm execution component 116, a comparison component 118, and a randomizer 120. Each of these components is described below.
[0034] Computing device 100 is any device, portion of a device, or any collection of devices capable of processing instructions electronically, and may include, but is not limited to, any of the following: one or more processors (e.g., components including integrated circuits, memory, input and output devices (not shown), non-volatile storage hardware, one or more physical interfaces, any number of other hardware components (not shown), and / or any combination thereof). Examples of computing devices include, but are not limited to, mobile devices (e.g., laptops, smartphones, personal digital assistants, tablet computers, automotive computing systems, and / or any other mobile computing devices), Internet of Things (IoT) devices, servers (e.g., blade servers in blade server chassis, rack servers in racks, etc.), desktop computers, storage devices (e.g., disk drive arrays, Fibre Channel storage devices, Internet Small Computer System Interface (iSCSI) storage devices, tape storage devices, flash storage arrays, network attached storage devices, etc.), network devices (e.g., switches, routers, multilayer switches, etc.), wearable devices (e.g., connected watches or smart watches or other wearable devices), robotic devices, smart TVs, smart appliances, extended reality (XR) devices (e.g., augmented reality, virtual reality, etc.), any device including one or more SoCs, and / or any other type of computing device having the above requirements. In one or more examples, any or all of the foregoing examples may be combined to create a system of such devices, which may be collectively referred to as a computing device. Other types of computing devices may be used without departing from the scope of the examples described herein.
[0035] In some examples, processor 102 is any component that includes circuitry for executing instructions (e.g., of a computer program). As an example, such circuitry can be an integrated circuit implemented at least in part using transistors that implement components such as an arithmetic logic unit, a control unit, logic gates, registers, a first-in-first-out (FIFO) buffer, a data and control buffer, and the like. In some examples, the processor can include additional components, such as, for example, flash memory. In some examples, the processor retrieves and decodes instructions and then executes them. Execution of instructions can include performing operations on data, which can include reading and / or writing data. In some examples, the instructions and data used by the processor are stored in a memory (e.g., memory device 108) of computing device 100. The processor can perform various operations for executing software, such as an operating system, an application program, and the like. Processor 102 can write data from memory to a storage device of computing device 100 and / or read data from a storage device via memory. Examples of processors include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), a neural processing unit, a tensor processing unit, a display processing unit, a digital signal processor (DSP), a finite state machine, and the like. The processor 102 may be operatively connected to the memory device 108, any storage device of the computing device 100 (e.g., the UFS device 104, the additional storage device 110), and / or to all or any portion of the password input component 112, the mask provider 114, the cryptographic algorithm execution component 116, the comparison component 118, and the randomizer 120. Figure 1 Computing device 100 is shown with a single processor 102 , but a computing device may include any number of processors without departing from the scope of the examples described herein.
[0036] In some examples, computing device 100 includes a UFS device 104. In some examples, UFS device 104 is a flash memory device that complies with the UFS specification. UFS device 104 can be used to store any type of data. Data can be written to UFS device 104 and / or read from UFS device 104. As an example, a UFS device can store an operating system image, a software image, application data, etc. UFS device 104 can store any other type of data without departing from the scope of the examples described herein. In some examples, UFS device 104 includes a NAND flash memory device. Without departing from the scope of the examples described herein, UFS device 104 can use any other type of storage technology. In some examples, UFS device 104 can have a relatively faster data rate than other storage devices of computing device 100 (e.g., additional storage device 110). The UFS device 104 may be operatively connected to the processor 102, the memory device 108, the additional storage device 110, and / or all or any portion of the following: a password input component 112, a mask provider 114, a cryptographic algorithm execution component 116, a comparison component 118, and a randomizer 120. Figure 1 The computing device 100 is shown with a single UFS device 104, but the computing device may include any number of UFS devices without departing from the scope of the examples described herein. Figure 1 A UFS device 104 is shown, but the computing device 100 may include any other type of flash storage device without departing from the scope of the examples described herein.
[0037] In some examples, computing device 100 includes additional storage device 110. In some examples, additional storage device is a non-volatile storage device. Additional storage device 110 may be, for example, a persistent memory device. In some examples, additional storage device 110 may be any type of computer storage device. Examples of types of computer storage devices include, but are not limited to, hard drives, solid-state drives, flash memory, tape drives, removable disk drives, universal serial bus (USB) storage devices, secure digital (SD) cards, optical storage devices, read-only memory devices, and the like. Although Figure 1The additional storage device 110 is shown as part of the computing device 100, but the additional storage device can be separate from the computing device 100 and operably connected to the computing device 100 (e.g., an external drive array, cloud storage, etc.). In some examples, the additional storage device 110 operates at a relatively slower data rate than the UFS device 104. In some examples, the additional storage device 110 is also a UFS storage device. In some examples, the additional storage device 110 is operably connected to the processor 102, the UFS device 104, the memory device 108, and / or all or any portion of the following: the password input component 112, the mask provider 114, the cryptographic algorithm execution component 116, the comparison component 118, and the randomizer 120. Although Figure 1 Computing device 100 is shown with a single additional storage device 110 , but computing device 100 may have any number of additional storage devices without departing from the scope of the examples described herein.
[0038] In some examples, the computing device 100 includes a memory device 108. The memory device can be any type of computer memory. In some examples, the memory device 108 is a volatile storage device. As an example, the memory device 108 can be a random access memory (RAM). In one or more examples, data stored in the memory device 108 is located at a memory address and is therefore accessible by the processor 102 using the memory address. Similarly, the processor 102 can use the memory address to write data to the memory device 108 and / or read data from the memory device 108. The memory device 108 can be used to store any type of data, such as, for example, computer programs, calculation results, etc. In some examples, the memory device 108 is operably connected to the processor 102, the UFS device 104, the additional storage device 110, and / or to all or any portion of the following: the password input component 112, the mask provider 114, the cryptographic algorithm execution component 116, the comparison component 118, and the randomizer 120. Although Figure 1 The computing device 100 is shown with a single memory device 108 , but the computing device 100 may have any number of memory devices without departing from the scope of the examples described herein.
[0039] In some examples, computing device 100 includes a cryptographic input component 112. Cryptographic input component 112 can be any hardware (e.g., circuitry), software, firmware, or any combination thereof configured to obtain a cryptographic input (e.g., a cryptographic key) and provide it to a cryptographic algorithm execution component (described below). As an example, cryptographic input component 112 can obtain a cryptographic key represented by any number of bits from a secure storage location on computing device 100 and provide the bits as input to cryptographic algorithm execution component 116.
[0040] In some examples, the computing device 100 includes a mask provider 114. The mask provider 114 can be any hardware (e.g., circuit), software, firmware, or any combination thereof configured to generate a mask that will be used as an additional input by the cryptographic algorithm execution component 116 to determine whether the execution of the cryptographic algorithm should use standard logic or inverted logic. In some examples, the mask is a random mask. In some examples, the mask is a single randomly generated bit that is provided as an input to a logic circuit to determine whether the logic circuit will be executed using standard logic by not inverting the input bits of the cryptographic input (e.g., a cryptographic key). In such an example, another instance of the same logic is executed in parallel using the opposite bits of the single random mask bit. In some examples, the mask is a randomly generated mask that has multiple randomly generated bits for the corresponding input bits and output bits to be applied to the logic. As an example, the mask can be 101, and the logic can receive two inputs a and b for generating an output c. In this case, the first bit 1 of the mask can indicate that the first bit a of the input is to be inverted before being used to execute the logic, and the second bit 0 of the mask can be used to indicate that the second bit b of the input is not to be inverted, and the output of the logic is to be inverted. In some examples, such a mask can be a more fine-grained mask. When using such a mask, the comparison component 118 (described below) may require the mask in order to efficiently perform a comparison of the output of one instance of the logic circuit with the output of another instance of the logic circuit to which a separate unique mask is applied. When using a multi-bit random mask, the two logic instances can be executed in parallel or sequentially because the two separate random masks are generally unique relative to each other.
[0041] In some examples, the computing device 100 includes a cryptographic algorithm execution component 116. The cryptographic algorithm execution component 116 can be any hardware (e.g., circuitry), software, firmware, or any combination thereof configured to execute a cryptographic algorithm. Such execution can include using all or any portion of the hardware, software, and / or firmware to implement two instances of a logic circuit, each capable of implementing standard logic, inverted logic, or a combination thereof in the case of a multi-bit mask. In some examples, when a single-bit random mask is used, one of the logic circuit instances is executed using standard or inverted logic as indicated by the random mask bit, while the other of the logic circuit instances is executed using any logic type not used to execute the first instance of the circuit. In some examples, when a multi-bit random mask is used, the multi-bit mask is used to determine whether to invert each input bit and output bit of the first circuit instance, and a second randomly generated multi-bit mask bit is used to determine whether to invert the input bits and output bits of the second instance of the logic circuit, and the two separate masks are provided to the comparison component 118 for performing a comparison of the outputs of the two logic circuit instances.
[0042] In some examples, computing device 100 includes a comparison component 118. Comparison component 118 can be any hardware (e.g., circuitry), software, firmware, or any combination thereof configured to perform a comparison of the outputs of two logic circuits used in executing a cryptographic algorithm. In some examples, where a single-bit mask is used to determine whether the logic is standard or inverted for each of the two logic circuits, one of the two logic circuits will be standard and the other will be inverted. In this scenario, the inverted logic and standard logic circuits are two instances of the same circuit, and a non-inverted cryptographic input is provided to the standard logic, while an inverted cryptographic input is provided to the inverted logic. Thus, a successful comparison of the outputs occurs when one of the outputs is the inverted of the other. A failed comparison occurs when the output of one of the outputs is not equal to the inverted of the other. In some examples, where a separate multi-bit mask is used for each logic circuit to determine whether the input and output are individually inverted, the comparison can include obtaining two multi-bit masks and using the multi-bit masks by comparison component 118 to invert the masks by reapplying the corresponding masks to the output of each of the two outputs. In this scenario, if the results of the two outputs after inversion match, the comparison succeeds, and if they do not match, the comparison fails. In either scenario, a successful comparison can indicate that the output can be used because no circuit appears to have been subjected to a fault injection that would result in a failed comparison. Additionally, the use of random masks and separate instances of the same logic circuit can prevent side-channel attacks that attempt to obtain information about whether inverted logic or standard logic is used in a given logic circuit (of the two used) because the two circuits have the same (e.g., in terms of power, timing, voltage, etc.) characteristics during execution.
[0043] In some examples, the computing device 100 includes a randomizer 120. The randomizer 120 can be configured as any hardware (e.g., circuitry), software, firmware, or any combination thereof that performs randomization of the output of the execution of the cryptographic algorithm when the comparison component 118 determines that the comparison has failed. Without departing from the scope of the examples described herein, any type of randomization can be performed. As an example, the randomizer 120 can generate a random number, multiply the two outputs by the random number, and perform XOR on the result. In some examples, randomization further reduces the possibility that an attacker can obtain any information about the execution of the cryptographic algorithm, even if the output after the comparison and randomization fails is obtained.
[0044] Although Figure 1A particular number of components in a particular configuration is shown, but one of ordinary skill in the art will understand that the computing device 100 may include more components, fewer components, and / or components arranged in any number of alternative configurations without departing from the scope of the examples described herein. Additionally, some or all of the components shown may be part of a single component, and any single component shown may be implemented as any number of discrete components. Additionally, although Figure 1 Although not shown, it will be understood by those skilled in the art that the computing device 100 can execute any number or type of software or firmware (e.g., boot loaders, operating systems, hypervisors, virtual machines, computer applications, mobile device applications, etc.). Therefore, the examples disclosed herein should not be limited to Figure 1 Configuration of components shown.
[0045] Figure 2 is a diagram illustrating a logic circuit for mitigating fault injection attacks according to one or more examples described herein. The following examples are for illustrative purposes only and are not intended to limit the scope of the examples described herein. Additionally, while the examples illustrate certain aspects of the examples described herein, not all possible aspects of such examples may be illustrated in this particular example.
[0046] Figure 2 Two logic circuits are shown, 200 and 202. Figure 2 As shown, the logic circuit itself is identical. For the purposes of this example, the circuit is intentionally simplified to illustrate certain aspects described herein. The logic circuit is an XOR logic gate, which is supplied with two cryptographic inputs, a and b, to produce a single output: the XOR of the inputs. In logic circuit 200, a single-bit random mask of 0 is supplied to logic circuit 200. Therefore, the logic circuit operates as a standard logic circuit by not inverting inputs a and b. Therefore, the output is the XOR of the non-inverted a and b. For example, if a is 1 and b is 0, the output is 1. In logic circuit 202, a single-bit random mask of 1 is supplied to logic circuit 202. Therefore, logic circuit 202 operates as an inverting logic circuit by inverting inputs a and b. The inversion of inputs a and b is represented by the lines above the a and b inputs in logic circuit 202. As a result, the output is the inverted XOR of the inverted a and b. If a is 1, the inverted a is 0, and if b is 0, the inverted b is 1. The result of XOR of inverted a and inverted b is therefore 1. The inverted 1 is 0. Therefore, the output of 200 is 1 and the output of 202 is 0, so the comparison of the outputs is successful because the outputs are inverted versions of each other, and the outputs can be used.
[0047] Figure 3is a diagram illustrating a logic circuit for mitigating fault injection attacks according to one or more examples described herein. The following examples are for illustrative purposes only and are not intended to limit the scope of the examples described herein. Additionally, while the examples illustrate certain aspects of the examples described herein, not all possible aspects of such examples may be illustrated in this particular example.
[0048] Figure 3 shows two instances of the same circuit being implemented as cryptographic algorithm execution components (e.g., Figure 1 In this scenario, the password input component (e.g., Figure 1 The password input component 112) obtains and provides the password input to the password algorithm execution component. Figure 3 In the example above, for simplicity, the input is two bits A and B. However, the cryptographic input can be any number of bits, such as the bits of a cryptographic key. In addition, the mask provider (e.g., Figure 1 Mask provider 114 (also known as a mask provider) provides mask M to the cryptographic algorithm execution device. The value of mask M indicates whether circuit X 300 or circuit Z 302 will execute using inverted logic or standard logic. In this case, M is 0, indicating that circuit X 300 will use standard logic. Therefore, circuit Z 302 will use inverted logic. Therefore, circuit X 300 is provided with non-inverted input bits A and B, while circuit Z 302 is provided with inverted bits A and B. The input bits are used to execute the circuits in parallel. Output 1 of circuit X 300 is not inverted, while output 2 of circuit Z 302 is inverted. Comparison component 304 compares the results to determine whether output 2 is the inverse of output 1. If the comparison is successful, the output can be used without randomization by randomizer 306. If the comparison is unsuccessful, the output is randomized to prevent an attacker from using the output to obtain any information about the cryptographic inputs of either circuit.
[0049] Figure 4 is a diagram illustrating a logic circuit for mitigating fault injection attacks according to one or more examples described herein. The following examples are for illustrative purposes only and are not intended to limit the scope of the examples described herein. Additionally, while the examples illustrate certain aspects of the examples described herein, not all possible aspects of such examples may be illustrated in this particular example.
[0050] Figure 4 A simple XOR logic circuit 400 is shown to illustrate various aspects of the examples described herein. Figure 2In the logic circuits 200 and 202 of FIG, the logic circuit 400 is provided with two input bits a and b and produces a single output c. However, the logic circuit 400 is provided with a multi-bit mask [ma, mb, mc], which in this scenario is 101. The mask bit ma corresponds to the input bit a, the mask bit mb corresponds to the input bit b, and the mask bit mc corresponds to the output bit c. Therefore, each mask bit corresponds to an input or output bit, so that all input and output bits have corresponding random masks. Here, ma is 1 to indicate that input a should be inverted, mb is 0 to indicate that input b should not be inverted, and mc is 1 to indicate that output c should be inverted. As will be shown below Figure 5 As further discussed in the description of , two instances of logic circuit 400 can be used to implement certain examples described herein in which multi-bit masks are used. Each of the two instances can use a separate mask. Thus, the circuit can be executed in parallel or sequentially because the two masks are independent.
[0051] Figure 5 shows two instances of the same circuit being implemented as cryptographic algorithm components (e.g., Figure 1 For example, each of circuit X 500 and circuit Z 502 may be Figure 4 An example of the logic circuit 400 shown in and discussed above. In this scenario, the password input component (e.g., Figure 1 The password input component 112 of the circuit 100 obtains the password input and provides the password input to each of the circuit X 500 and the circuit Z 502 to the password algorithm execution component. Figure 5 In , for simplicity, the input is two bits A and B. However, the cryptographic input can be any number of bits, such as the bits of a cryptographic key.
[0052] Additionally, a mask provider (e.g., Figure 1 A mask provider 114 (of the embodiment) provides masks M1 and M2 to the cryptographic algorithm execution device. Mask M1 is used for circuit X 500, and mask M2 is used for circuit Z 502. Each of masks M1 and M2 is a separate multi-bit mask that is independent of the other. The bits of mask M1 indicate whether A, B, and output 1 are inverted. The bits of mask M2 indicate whether A, B, and output 2 are inverted. After applying the corresponding bits of mask M1 to inputs A and B, circuit X 500 is executed, and after obtaining output 1, the corresponding bits of mask M1 are applied to output 1. After applying the corresponding bits of mask M2 to inputs A and B, circuit Z 502 is executed, and after obtaining output 2, the corresponding bits of mask M2 are applied to output 2.
[0053] In this scenario, circuit X 500 and circuit Z 502 are executed sequentially. Output 1 and output 2 are compared by comparison component 504 to determine whether output 2 matches output 1. The comparison includes reapplying mask M1 to output 1 and reapplying mask M2 to output 2 to account for the separate multi-bit masks. When the comparison is successful (e.g., the outputs match), the outputs can be used without randomization by randomizer 506. When the comparison is unsuccessful, the outputs are randomized to prevent an attacker from using the outputs to obtain any information about the cryptographic inputs of the two circuits.
[0054] Figure 6 is a flow chart illustrating an example of a process 600 for providing countermeasures against fault injection attacks according to one or more examples described herein. The process 600 may be performed at least in part by Figure 1 computing device 100 or any component thereof (e.g., Figure 1 Cryptographic algorithm execution component 116) and / or Figure 7 The computing system 700 is used to execute.
[0055] At block 602, process 600 includes obtaining a cryptographic input. In some examples, the cryptographic input (e.g., a cryptographic key) is generated by a cryptographic algorithm execution component (e.g., Figure 1 The cryptographic algorithm execution component 116) receives the cryptographic algorithm from the cryptographic input component (e.g., Figure 1 As an example, the password input component can be obtained from a computing device (e.g., Figure 1 The cryptographic key represented by an arbitrary number of bits is obtained from a secure storage location on the computing device 100 and the bits are provided as input to the cryptographic algorithm execution component 116.
[0056] At block 604, process 600 includes obtaining a first mask and a second mask. In some examples, the first mask and the second mask are generated by a cryptographic algorithm execution component (e.g., Figure 1 In some examples, the mask provider (e.g., Figure 1 The first mask and the second mask are obtained by a mask provider 114. In some examples, the first mask is a single-bit mask, and obtaining the second mask includes inverting the first mask to obtain the inverted second mask. In some examples, the first mask and the second mask are each a multi-bit mask randomly generated. In such an example, the number of bits in the first mask and the second mask can match the number of bits of the password input.
[0057] At block 606, process 600 includes executing a first logic circuit using the first mask and the cryptographic input to obtain a first output. The first logic circuit may be comprised of a cryptographic algorithm execution component (e.g., Figure 1In some examples, executing the first logic circuit includes using standard logic to obtain the first output based on the first mask.
[0058] At block 608, process 600 includes executing a second logic circuit using the second mask and the cryptographic input to obtain a second output. The second logic circuit may be comprised of a cryptographic algorithm execution component (e.g., Figure 1 The cryptographic algorithm execution component 116 executes the first logic circuit. In some examples, the first logic circuit and the second logic circuit are separate instances of the same circuit and have the same bypass characteristics when executed. In some examples, executing the second logic circuit includes using inverting logic based on the inverted second mask to obtain the second output. In some examples, the second logic circuit inverts the cryptographic input and the second output to obtain the inverted second output.
[0059] At block 610, process 600 includes performing a comparison of the first output and the second output to determine whether the comparison is a successful comparison. In some examples, the comparison is performed by a comparison component (e.g., Figure 1 In some examples, performing a successful comparison includes reapplying the first mask to the first output and reapplying the second mask to the second output, and determining whether the first output matches the second output. In some examples, if the comparison is unsuccessful, randomization of the first and second outputs can be performed (e.g., by Figure 1 randomizer 120).
[0060] In some examples, process 600 or any other process described herein may be performed by a computing device or apparatus and / or one or more components therein and / or to which the computing device is operatively connected.
[0061] The computing device can be any suitable device, include any suitable device, or be a component of any suitable device, such as a vehicle or a computing device of a vehicle (e.g., a driver monitoring system (DMS) of a vehicle), a mobile device (e.g., a mobile phone), a desktop computing device, a tablet computing device, a wearable device (e.g., a VR headset, an AR headset, AR glasses, a connected watch or smartwatch or other wearable device), a server computer, a robotic device, a television, a smart speaker, a voice assistant device, a SoC, and / or any other device having the resource capability to perform the processes described herein (including process 600) and / or other processes described herein. In some cases, a computing device or apparatus (including a hardware identity impersonator) can include various components, such as one or more input devices, one or more output devices, one or more processors, one or more microprocessors, one or more microcomputers, one or more cameras, one or more sensors, and / or (multiple) other components configured to perform the operations of the processes described herein. In some examples, the computing device can include a display, a network interface configured to transmit and / or receive data, an RF sensing component, any combination thereof, and / or (multiple) other components. The network interface may be configured to transmit and / or receive Internet Protocol (IP) based data or other types of data.
[0062] Computing devices (e.g. Figure 1 Components of the computing device 100 may be implemented at least in part in circuitry. For example, a component may include and / or be implemented using electronic circuitry or other electronic hardware, which may include one or more programmable electronic circuits (e.g., a microprocessor, a graphics processing unit (GPU), a digital signal processor (DSP), a central processing unit (CPU), a finite state machine, and / or other suitable electronic circuitry), and / or a component may include and / or be implemented at least in part using computer software, firmware, or a combination thereof for performing the various operations described herein.
[0063] Figure 6The process 600 in FIG. 5 is illustrated as a logical flow diagram, the operations of which represent a sequence of operations that can be implemented in hardware, computer instructions, or a combination thereof. In the context of computer instructions, the operations represent computer-executable instructions stored on one or more computer-readable storage media that, when executed by one or more processors, perform the recited operations. Generally, computer-executable instructions include routines, programs, objects, components, data structures, etc. that perform specific functions or implement specific data types. The order in which the operations are described is not intended to be construed as limiting, and any number of the described operations may be combined in any order and / or performed in parallel to implement the processes.
[0064] Additionally, process 600 and / or other processes described herein can be performed under the control of one or more computer systems configured with executable instructions, and can be implemented as code (e.g., executable instructions, one or more computer programs, or one or more applications) that executes together on one or more processors, implemented in hardware, or a combination thereof. As noted above, the code can be stored on a computer-readable or machine-readable storage medium, for example, in the form of a computer program comprising a plurality of instructions that can be executed by one or more processors. The computer-readable or machine-readable storage medium can be non-transitory.
[0065] Figure 7 is a schematic diagram illustrating an example of a system for implementing certain aspects of the present technology. Specifically, Figure 7 An example of a computing system 700 is shown, which can be any computing device, for example, constituting an internal computing system, a remote computing system, a camera, or any component thereof, wherein the components of the system communicate with each other using a connection 705. The connection 705 can be a physical connection using a bus, or a direct connection (such as in a chipset architecture) into the processor 710. The connection 705 can also be a virtual connection, a networked connection, or a logical connection.
[0066] In some examples, computing system 700 is a distributed system, in which the functions described in this disclosure can be distributed across a data center, multiple data centers, a peer-to-peer network, and the like. In some examples, one or more of the described system components represent a plurality of such components, each of which performs some or all of the functions described for that component. In some examples, a component can be a physical device or a virtual device.
[0067] The example system 700 includes at least one processing unit (CPU or processor) 710 and connections 705 that couple various system components including system memory 715, such as read-only memory (ROM) 720 and random access memory (RAM) 725, to the processor 710. The computing system 700 may include a cache 712 of high-speed memory directly connected to, immediately adjacent to, or integrated as part of the processor 710.
[0068] Processor 710 may include any general-purpose processor and hardware or software services configured to control processor 710 (such as services 732, 734, and 736 stored in storage device 730), as well as special-purpose processors in which software instructions are incorporated into the actual processor design. Processor 710 may essentially be a completely self-contained computing system, including multiple cores or processors, buses, memory controllers, caches, etc. Multi-core processors may be symmetric or asymmetric.
[0069] To enable user interaction, computing system 700 includes input device 745, which can represent any number of input mechanisms or sensors, such as a microphone for voice (e.g., user speaking), a touch-sensitive screen for gesture or graphical input (e.g., user performing sign language, user shaking the phone, etc.), a keyboard (e.g., user pressing keys), a mouse, motion input, determining that the user is at a location indicated by a positioning system or modem subsystem, etc., which can be used to activate the measures described in the previous section and enable / disable the asset delivery chain at any stage described previously. Computing system 700 can also include output device 735, which can be one or more of several output mechanisms. In some instances, a multimodal system can enable a user to provide multiple types of input / output to communicate with computing system 700. Computing system 700 can include communication interface 740, which can generally handle and manage user input and system output. The communication interface may use wired and / or wireless transceivers to perform or facilitate receiving and / or transmitting wired or wireless communications, including using audio jacks / plugs, microphone jacks / plugs, Universal Serial Bus (USB) ports / plugs, Ports / plugs, Ethernet ports / plugs, fiber optic ports / plugs, proprietary wired ports / plugs, Wireless signal transmission, Low energy (BLE) wireless signal transmission, The communication interface 440 may also include a wired and / or wireless transceiver for wireless signal transmission, radio frequency identification (RFID) wireless signal transmission, near field communication (NFC) wireless signal transmission, dedicated short range communication (DSRC) wireless signal transmission, 802.11 Wi-Fi wireless signal transmission, wireless local area network (WLAN) signal transmission, visible light communication (VLC), world interoperability for microwave access (WiMAX), infrared (IR) communication wireless signal transmission, public switched telephone network (PSTN) signal transmission, integrated services digital network (ISDN) signal transmission, 3G / 4G / 5G / LTE cellular data network wireless signal transmission, ad-hoc network signal transmission, radio wave signal transmission, microwave signal transmission, infrared signal transmission, visible light signal transmission, ultraviolet light signal transmission, wireless signal transmission along the electromagnetic spectrum, or some combination thereof. The communication interface 440 may also include one or more global navigation satellite system (GNSS) receivers or transceivers for determining the location of the computing system 700 based on one or more signals received from one or more satellites associated with one or more GNSS systems. GNSS systems include, but are not limited to, the United States-based Global Positioning System (GPS), the Russian-based Global Navigation Satellite System (GLONASS), the Chinese-based BeiDou Navigation Satellite System (BDS), and the European-based Galileo GNSS. There is no restriction on operation with any particular hardware arrangement, so the basic features herein may be readily replaced with improved hardware or firmware arrangements as they are developed.
[0070] The storage device 730 may be a non-volatile and / or non-temporary and / or computer-readable storage device and may be a hard disk or other type of computer-readable medium capable of storing computer-accessible data, such as a magnetic cassette, a flash memory card, a solid-state storage device, a digital versatile disk, a magnetic tape, a floppy disk, a flexible disk, a hard disk, a magnetic tape, a magnetic stripe / strip, any other magnetic storage medium, flash memory, a memristor memory, any other solid-state memory, a compact disc read-only memory (CD-ROM) disc, a rewritable compact disc (CD) disc, a digital video disc (DVD) disc, a Blu-ray disc (BDD) disc, a holographic disc, another optical medium, a secure digital (SD) card, a micro secure digital (microSD) card, The memory device 730 may include a card, a smart card chip, an EMV chip, a subscriber identity module (SIM) card, a mini / micro / nano / pico SIM card, another integrated circuit (IC) chip / card, a random access memory (RAM), a static RAM (SRAM), a dynamic RAM (DRAM), a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), a flash EPROM (FLASHEPROM), a cache memory (L1 / L2 / L3 / L4 / L5 / L#), a resistive random access memory (RRAM / ReRAM), a phase change memory (PCM), a spin transfer torque RAM (STT-RAM), another memory chip or cartridge, and / or a combination thereof. The memory device 730 may include software instructions or code that can be executed by the processor 710 to enable the system 700 to perform functions.
[0071] As used herein, the term "computer-readable medium" includes, but is not limited to, portable or non-portable storage devices, optical storage devices, and various other media capable of storing, containing, or carrying instructions and / or data. Computer-readable media may include non-transitory media that can store data, but does not include carrier waves and / or temporary electronic signals that are transmitted wirelessly or through a wired connection. Examples of non-transitory media may include, but are not limited to: magnetic disks or tapes, optical disk storage media (such as compact discs (CDs) or digital versatile discs (DVDs)), flash memory, memory, or storage devices. Computer-readable media may store code and / or machine-executable instructions thereon, which may represent any combination of procedures, functions, subroutines, programs, routines, subroutines, modules, software packages, classes, or instructions, data structures, or program statements. A code segment may be coupled to another code segment or hardware circuit by passing and / or receiving information, data, independent variables, parameters, or memory contents. Information, independent variables, parameters, data, etc. may be transmitted, forwarded, or sent using any suitable means including memory sharing, message passing, token passing, network transmission, etc.
[0072] In some examples, computer-readable storage devices, media, and memories may include cables or wireless signals containing bit streams, etc. However, when referred to, non-transitory computer-readable storage media explicitly excludes media such as energy, carrier signals, electromagnetic waves, and signals themselves.
[0073] Specific details are provided in the foregoing description to provide a thorough understanding of the examples and examples provided herein. However, it will be understood by those skilled in the art that examples can be implemented without these specific details. For clarity of explanation, in some cases, the technology herein can be presented as a separate functional block comprising the following functional blocks, which include devices, device components, operations, steps or routines in the method embodied in software or hardware, or a combination of hardware and software. Additional components other than those shown in the accompanying drawings and / or described herein can be used. For example, circuits, systems, networks, processes and other components can be shown as components in block diagram form, so as not to obscure examples in unnecessary details. In other cases, known circuits, processes, algorithms, structures and techniques may be shown as not having unnecessary details, so as to avoid obscuring these examples.
[0074] The above text may describe each example as a process or method, which is depicted as a flow chart, flow diagram, data flow diagram, structure diagram or block diagram. Although the operations are described as a sequential process using a flow chart, many operations can be performed in parallel or simultaneously. Additionally, the order of these operations can be rearranged. When these operations are completed, the process is terminated, but it may have other operations not included in the accompanying drawings. A process can correspond to a method, function, process, subroutine, subprogram, etc. When a process corresponds to a function, its termination can correspond to the function returning to the calling function or main function.
[0075] The process and method according to the above-mentioned example can be implemented using computer-executable instructions stored in a computer-readable medium or otherwise obtainable from a computer-readable medium. For example, such instructions can include instructions and data that make a general-purpose computer, a special-purpose computer or a processing device or otherwise configure a general-purpose computer, a special-purpose computer or a processing device to perform a certain function or function group. The part of the computer resource used can be accessible through a network. Computer-executable instructions can be, for example, binary, intermediate format instructions (such as assembly language, firmware, source code, etc.). The example of a computer-readable medium that can be used to store instructions, information used and / or information created during the method according to the described example includes a disk or optical disk, a flash memory, a USB device provided with a non-volatile memory, a network storage device, etc.
[0076] The equipment implementing the processes and methods according to these disclosures can include hardware, software, firmware, middleware, microcode, hardware description language or any combination thereof, and can adopt any of a variety of form factors. When implemented in software, firmware, middleware or microcode, the program code or code segments (e.g., computer program products) for performing the necessary tasks can be stored in a computer-readable medium or a machine-readable medium. One (or more) processors can perform the necessary tasks. Typical examples of form factors include personal computers, personal digital assistants, rack-mounted devices, stand-alone devices, etc., of laptop computers, smart phones, mobile phones, tablet devices or other small form factors. The functions described herein can also be embodied in peripheral devices or add-on cards. By further example, such functions can also be implemented on a circuit board between different chips or different processes performed in a single device.
[0077] Instructions, media for transmitting such instructions, computing resources for executing them, and other structure for supporting such computing resources are example means for providing the functionality described in this disclosure.
[0078] In the foregoing description, various aspects of the present application have been described with reference to specific examples of the present application, but it will be appreciated by those skilled in the art that the present application is not limited thereto. Therefore, although the illustrative examples of the present application have been described in detail herein, it should be understood that these inventive concepts may be embodied and adopted differently in other ways, and the appended claims are intended to be interpreted as including such variations, except as limited by the prior art. The various features and aspects of the above-mentioned applications may be used individually or in combination. Further, without departing from the broader spirit and scope of this specification, the various examples described herein may be utilized in any number of environments and applications other than those described herein. Therefore, the description and accompanying drawings should be considered to be illustrative rather than restrictive. For illustration purposes, the method is described in a particular order. It should be understood that, in alternative examples, the method may be performed in an order different from the described order.
[0079] Those of ordinary skill in the art will understand that the less than ("<") and greater than (">") symbols or terms used herein may be replaced by the less than or equal to ("≤") and greater than or equal to ("≥") symbols, respectively, without departing from the scope of the present specification.
[0080] When a component is described as being “configured to” perform certain operations, such configuration may be achieved, for example, by designing electronic circuits or other hardware to perform the operation, by programming a programmable electronic circuit (e.g., a microprocessor or other appropriate electronic circuit) to perform the operation, or any combination thereof.
[0081] The phrase "coupled to" refers to any component that is directly or indirectly physically connected to another component and / or any component that is directly or indirectly in communication with another component (e.g., connected to another component through a wired or wireless connection and / or other appropriate communication interface).
[0082] Claim language or other language that refers to “at least one of” a set and / or “one or more of” a set indicates that one member of the set or multiple members of the set (in any combination) satisfies the claim. For example, claim language that recites “at least one of A and B” or “at least one of A or B” refers to A, B, or A and B. In another example, claim language that recites “at least one of A, B, and C” or “at least one of A, B, or C” refers to A, B, C, or A and B, or A and C, or B and C, or A, B, and C. The language “at least one of” a set and / or “one or more of” a set does not limit the set of items listed in the set. For example, claim language that recites “at least one of A and B” or “at least one of A or B” may mean A, B, or A and B, and may additionally include items not listed in the set of A and B.
[0083] The various illustrative logic blocks, modules, circuits, and algorithmic operations described in conjunction with the examples disclosed herein can be implemented as electronic hardware, computer software, firmware, or a combination thereof. In order to clearly illustrate this interchangeability of hardware and software, the above has been generally described around the functionality of various illustrative components, blocks, modules, circuits, and operations. Whether such functionality is implemented as hardware or software depends on the specific application and the design constraints imposed on the entire system. Technicians can implement the described functions in different ways for each specific application, but such implementation decisions should not be interpreted as resulting in a departure from the scope of this application.
[0084] The techniques described herein may also be implemented in electronic hardware, computer software, firmware, or any combination thereof. Such techniques may be implemented in any of a variety of devices, such as a general-purpose computer, a wireless communication device, a handheld device, or an integrated circuit device with multiple uses, including applications in wireless communication devices, handheld devices, and other devices. Any features described as modules or components may be implemented together in an integrated logic device or separately as discrete but interoperable logic devices. If implemented in software, the techniques may be implemented at least in part by a computer-readable data storage medium comprising program code that, when executed, includes instructions for performing one or more of the methods described above. The computer-readable data storage medium may form part of a computer program product, which may include packaging materials. The computer-readable medium may include memory or data storage media, such as random access memory (RAM) (e.g., synchronous dynamic random access memory (SDRAM)), read-only memory (ROM), non-volatile random access memory (NVRAM), electrically erasable programmable read-only memory (EEPROM), FLASH memory, magnetic or optical data storage media, and the like. Additionally or alternatively, these techniques may be implemented at least in part through a computer-readable communication medium that carries or communicates program code in the form of instructions or data structures, such as propagated signals or waves, and which can be accessed, read, and / or executed by a computer.
[0085] The program code may be executed by a processor, which may include one or more processors, such as one or more digital signal processors (DSPs), general-purpose microprocessors, application-specific integrated circuits (ASICs), field-programmable logic arrays (FPGAs), or other equivalent integrated logic circuits or discrete logic circuits. Such a processor may be configured to perform any of the techniques described in this disclosure. A general-purpose processor may be a microprocessor; however, in an alternative embodiment, the processor may be any conventional processor, controller, microcontroller, or state machine. The processor may also be implemented as a combination of computing devices, for example, a combination of a DSP and a microprocessor, a plurality of microprocessors, one or more microprocessors in combination with a DSP core, or any other such configuration. Thus, the term "processor," as used herein, may refer to any of the foregoing structures, any combination of the foregoing structures, or any other structure or device suitable for implementing the techniques described herein.
[0086] Illustrative aspects of the disclosure include:
[0087] Aspect 1: A method for security processing, the method comprising: obtaining a password input; obtaining a first mask and a second mask; executing a first logic circuit using the first mask and the password input to obtain a first output; executing a second logic circuit using the second mask and the password input to obtain a second output; and performing a comparison of the first output and the second output to determine whether the comparison is a successful comparison.
[0088] Aspect 2: The method of aspect 1, wherein the first logic circuit and the second logic circuit are separate instances of the same circuit, wherein the same circuit has the same bypass characteristics when executed.
[0089] Aspect 3: The method according to any one of aspects 1 or 2, wherein the first mask is a single-bit mask, and wherein obtaining the second mask comprises: inverting the first mask to obtain an inverted second mask.
[0090] Aspect 4: A method according to any one of Aspects 1-3, wherein executing the first logic circuit includes using standard logic based on the first mask to obtain the first output; and wherein executing the second logic circuit includes using inverting logic based on the inverted second mask to obtain the second output, wherein the second logic circuit inverts the password input and the second output to obtain an inverted second output.
[0091] Aspect 5: The method of any one of aspects 1 to 4, wherein the successful comparison comprises determining that the inverted second output is an inverted instance of the first output.
[0092] Aspect 6: The method according to any one of aspects 1-5, wherein the cryptographic input is a cryptographic key.
[0093] Aspect 7: The method according to any one of aspects 1-6, wherein the first value of the first mask is a first randomly generated multi-bit mask, and the second value of the second mask is a second randomly generated multi-bit mask.
[0094] Aspect 8: A method according to any one of Aspects 1-7, wherein performing the comparison to determine whether the comparison is a successful comparison includes: reapplying the first mask to the first output and reapplying the second mask to the second output, and determining whether the first output matches the second output.
[0095] Aspect 9: A method according to any one of Aspects 1-8, wherein the first number of bits in the first mask matches the second number of bits in the password input and the first output, and also matches the second number of bits in the password input and the second output.
[0096] Aspect 10: The method according to any one of aspects 1-9, further comprising: determining that the comparison is unsuccessful; and performing randomization of the first output and the second output based on the determination.
[0097] Aspect 11: A device for security processing, the device comprising: at least one memory; and at least one processor, coupled to the at least one memory and configured to: obtain a password input; obtain a first mask and a second mask; execute a first logic circuit using the first mask and the password input to obtain a first output; execute a second logic circuit using the second mask and the password input to obtain a second output; and perform a comparison of the first output and the second output to determine whether the comparison is a successful comparison.
[0098] Aspect 12: The apparatus of aspect 11, wherein the first logic circuit and the second logic circuit are separate instances of the same circuit, wherein the same circuit has the same bypass characteristics when executed.
[0099] Aspect 13: The apparatus according to aspect 11 or 12, wherein the first mask is a single-bit mask, and wherein obtaining the second mask comprises: inverting the first mask to obtain an inverted second mask.
[0100] Aspect 14: An apparatus according to any one of Aspects 11-13, wherein, to execute the first logic circuit, the at least one processor is configured to use standard logic based on the first mask to obtain the first output; and wherein executing the second logic circuit includes using inverting logic based on the inverted second mask to obtain the second output, wherein the second logic circuit inverts the password input and the second output to obtain an inverted second output.
[0101] Aspect 15: The apparatus of any one of aspects 11-14, wherein, to determine that the comparison is successful, the at least one processor is configured to determine that the inverted second output is an inverted instance of the first output.
[0102] Aspect 16: The apparatus of any one of aspects 11-15, wherein the cryptographic input is a cryptographic key.
[0103] Aspect 17: The apparatus of any of aspects 11-16, wherein the first value of the first mask is a first randomly generated multi-bit mask, and the second value of the second mask is a second randomly generated multi-bit mask.
[0104] Aspect 18: An apparatus according to any one of Aspects 11-17, wherein, in order to perform the comparison to determine whether the comparison is a successful comparison, the at least one processor is configured to: reapply the first mask to the first output and reapply the second mask to the second output, and determine whether the first output matches the second output.
[0105] Aspect 19: An apparatus according to any one of Aspects 11-18, wherein the first number of bits in the first mask matches the second number of bits in the password input and the first output, and also matches the second number of bits in the password input and the second output.
[0106] Aspect 20: The apparatus of any one of aspects 11-19, wherein the at least one processor is configured to: determine that the comparison is unsuccessful; and perform randomization of the first output and the second output based on the determination.
[0107] Aspect 21: A non-transitory computer-readable medium having instructions stored thereon, which, when executed by one or more processors, cause the one or more processors to perform the following operations: obtain a password input; obtain a first mask and a second mask; execute a first logic circuit using the first mask and the password input to obtain a first output; execute a second logic circuit using the second mask and the password input to obtain a second output; and perform a comparison of the first output and the second output to determine whether the comparison is a successful comparison.
[0108] Aspect 22: The non-transitory computer-readable medium of aspect 21, wherein the first logic circuit and the second logic circuit are separate instances of the same circuit, wherein the same circuit has the same bypass characteristics when executed.
[0109] Aspect 23: The non-transitory computer-readable medium of aspect 21 or 22, wherein the first mask is a single-bit mask, and wherein obtaining the second mask comprises inverting the first mask to obtain an inverted second mask.
[0110] Aspect 24: A non-transitory computer-readable medium according to any one of Aspects 21-23, wherein executing the first logic circuit includes using standard logic based on the first mask to obtain the first output; and wherein executing the second logic circuit includes using inverting logic based on the inverted second mask to obtain the second output, wherein the second logic circuit inverts the password input and the second output to obtain an inverted second output.
[0111] Aspect 25: The non-transitory computer-readable medium of any one of aspects 21-24, wherein the successful comparison comprises determining that the inverted second output is an inverted instance of the first output.
[0112] Aspect 26: The non-transitory computer-readable medium of any one of aspects 21-25, wherein the cryptographic input is a cryptographic key.
[0113] Aspect 27: The non-transitory computer-readable medium of any one of aspects 21-26, wherein the first value of the first mask is a first randomly generated multi-bit mask and the second value of the second mask is a second randomly generated multi-bit mask.
[0114] Aspect 28: The non-transitory computer-readable medium of any one of Aspects 21-27, wherein performing the successful comparison comprises reapplying the first mask to the first output and reapplying the second mask to the second output, and determining whether the first output matches the second output.
[0115] Aspect 29: Non-transitory computer-readable medium according to any one of Aspects 21-28, wherein the first number of bits in the first mask matches the second number of bits in the password input and the first output, and also matches the second number of bits in the password input and the second output.
[0116] Aspect 30: A non-transitory computer-readable medium according to any one of Aspects 21-29, having additional instructions stored thereon, which, when executed by the one or more processors, cause the one or more processors to perform the following operations: determine that the comparison is unsuccessful; and perform randomization of the first output and the second output based on the determination.
[0117] Aspect 31: An apparatus for security processing, comprising one or more units for performing the operations according to any one of aspects 1-10.
Claims
1. A method for security processing, the method comprising: Get password input; Get the first mask and the second mask; executing a first logic circuit using the first mask and the password input to obtain a first output; executing a second logic circuit using the second mask and the password input to obtain a second output; as well as A comparison of the first output and the second output is performed to determine whether the comparison is a successful comparison.
2. The method according to claim 1, wherein The first logic circuit and the second logic circuit are separate instances of the same circuit, wherein the same circuit has the same bypass characteristics when executed.
3. The method according to claim 1, wherein The first mask is a single-bit mask, and wherein obtaining the second mask comprises inverting the first mask to obtain an inverted second mask.
4. The method according to claim 3, wherein: Executing the first logic circuit includes using standard logic based on the first mask to obtain the first output; and wherein executing the second logic circuit includes using inverted logic based on the inverted second mask to obtain the second output, wherein the second logic circuit inverts the password input and the second output to obtain an inverted second output.
5. The method according to claim 4, wherein Determining that the comparison is the successful comparison includes determining that the inverted second output is an inverted instance of the first output.
6. The method according to claim 1, wherein The cryptographic input is a cryptographic key.
7. The method according to claim 1, wherein The first value of the first mask is a first randomly generated multi-bit mask, and the second value of the second mask is a second randomly generated multi-bit mask.
8. The method according to claim 7, wherein: Performing the comparison to determine whether the comparison is the successful comparison includes reapplying the first mask to the first output and reapplying the second mask to the second output, and determining whether the first output matches the second output.
9. The method according to claim 7, wherein: A first number of bits in the first mask matches a second number of bits in the password input and the first output, and also matches the second number of bits in the password input and the second output.
10. The method according to claim 1, further comprising: making a determination that the comparing was unsuccessful; as well as Based on the determination, randomization of the first output and the second output is performed.
11. A device for security processing, the device comprising: at least one memory; as well as at least one processor coupled to the at least one memory and configured to: Get password input; Get the first mask and the second mask; executing a first logic circuit using the first mask and the password input to obtain a first output; executing a second logic circuit using the second mask and the password input to obtain a second output; as well as A comparison of the first output and the second output is performed to determine whether the comparison is a successful comparison.
12. The device according to claim 11, wherein The first logic circuit and the second logic circuit are separate instances of the same circuit, wherein the same circuit has the same bypass characteristics when executed.
13. The device according to claim 11, wherein The first mask is a single-bit mask, and wherein obtaining the second mask comprises inverting the first mask to obtain an inverted second mask.
14. The device according to claim 13, wherein To execute the first logic circuit, the at least one processor is configured to use standard logic based on the first mask to obtain the first output; and wherein executing the second logic circuit includes using inverted logic based on the inverted second mask to obtain the second output, wherein the second logic circuit inverts the password input and the second output to obtain the inverted second output.
15. The device according to claim 14, wherein To perform the comparison to determine whether the comparison is the successful comparison, the at least one processor is configured to determine that the inverted second output is an inverted instance of the first output.
16. The device according to claim 11, wherein The cryptographic input is a cryptographic key.
17. The device according to claim 11, wherein The first value of the first mask is a first randomly generated multi-bit mask, and the second value of the second mask is a second randomly generated multi-bit mask.
18. The device according to claim 17, wherein To determine that the comparison is the successful comparison, the at least one processor is configured to reapply the first mask to the first output and reapply the second mask to the second output, and make a determination whether the first output matches the second output.
19. The device according to claim 17, wherein A first number of bits in the first mask matches a second number of bits in the password input and the first output, and also matches the second number of bits in the password input and the second output.
20. The device according to claim 11, wherein The at least one processor is configured to: making a determination that the comparing was unsuccessful; and Based on the determination, randomization of the first output and the second output is performed.
21. A non-transitory computer-readable medium having stored thereon instructions that, when executed by one or more processors, cause the one or more processors to: Get password input; Get the first mask and the second mask; executing a first logic circuit using the first mask and the password input to obtain a first output; executing a second logic circuit using the second mask and the password input to obtain a second output; as well as A comparison of the first output and the second output is performed to determine whether the comparison is a successful comparison.
22. The non-transitory computer readable medium of claim 21, wherein: The first logic circuit and the second logic circuit are separate instances of the same circuit, wherein the same circuit has the same bypass characteristics when executed.
23. The non-transitory computer-readable medium of claim 21, wherein: The first mask is a single-bit mask, and wherein obtaining the second mask comprises inverting the first mask to obtain an inverted second mask.
24. The non-transitory computer readable medium of claim 23, wherein: Executing the first logic circuit includes using standard logic based on the first mask to obtain the first output; and wherein executing the second logic circuit includes using inverted logic based on the inverted second mask to obtain the second output, wherein the second logic circuit inverts the password input and the second output to obtain an inverted second output.
25. The non-transitory computer readable medium of claim 24, wherein: The successful comparison includes determining that the inverted second output is an inverted instance of the first output.
26. The non-transitory computer-readable medium of claim 21, wherein: The cryptographic input is a cryptographic key.
27. The non-transitory computer-readable medium of claim 21, wherein: The first value of the first mask is a first randomly generated multi-bit mask, and the second value of the second mask is a second randomly generated multi-bit mask.
28. The non-transitory computer readable medium of claim 27, wherein: Performing the successful comparison includes reapplying the first mask to the first output and reapplying the second mask to the second output, and making a determination whether the first output matches the second output.
29. The non-transitory computer-readable medium of claim 27, wherein: A first number of bits in the first mask matches a second number of bits in the password input and the first output, and also matches the second number of bits in the password input and the second output.
30. The non-transitory computer-readable medium of claim 27 having further instructions stored thereon that, when executed by the one or more processors, cause the one or more processors to: making a determination that the comparing was unsuccessful; and Based on the determination, randomization of the first output and the second output is performed.