Enhancing security of cryptographic components
By introducing diverse computing module configurations and microarchitectural protection into the computing system, the vulnerability of cryptographic components to side-channel attacks is solved, achieving higher security and protection.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- QUALCOMM INC
- Filing Date
- 2024-09-12
- Publication Date
- 2026-04-21
AI Technical Summary
In existing technologies, cryptographic components are vulnerable to side-channel attacks, leading to the leakage of secure information assets. This is especially true in reuse and self-similar operations, where attackers can obtain sensitive information by measuring characteristics such as the voltage and power of computing devices.
By introducing diverse computing module configurations into the computing system and utilizing different configuration and rotation techniques, the reuse of secure information assets can be avoided, and automatic protection can be achieved at the microarchitecture level, such as by rotating different multiplier units and microcode versions to enhance the security of cryptographic components.
It effectively reduces the success rate of side-channel attacks, protects secure information assets, prevents them from being leaked during reuse, and improves the security of computing devices.
Smart Images

Figure CN121909623A_ABST
Abstract
Description
Technical Field
[0001] Various aspects of this disclosure relate to systems and techniques for enhancing the security of cryptographic components. For example, according to some aspects, the systems and techniques can provide a microarchitecture for secure computing systems. Background Technology
[0002] Computing devices typically employ various techniques to protect data. As examples, encryption and decryption techniques can be applied to data in various scenarios, such as writing data to or reading data from storage devices, encrypting and decrypting data blocks and / or volumes, encrypting and decrypting digital content, and performing inline encryption operations. Such encryption and decryption operations are typically performed, at least in part, using secure information assets such as cryptographic keys and derived cryptographic keys. There are scenarios where attacks are launched to attempt to gain access to such secure information assets. Therefore, it is generally advantageous to implement systems and techniques that protect such secure information assets. Summary of the Invention
[0003] The following is a simplified summary of the invention relating to one or more aspects disclosed herein. Therefore, this summary should not be considered an exhaustive overview relating to all conceived aspects, nor should it be considered to identify key or decisive elements relating to all conceived aspects or to depict the scope associated with any particular aspect. Accordingly, the following outline presents certain concepts in a simplified form relating to one or more aspects of the mechanisms disclosed herein, preceding the detailed description that follows.
[0004] Systems, methods, apparatuses, and computer-readable media for securely performing cryptographic operations are disclosed.
[0005] According to at least one example, a method for securely performing cryptographic operations is provided. The method includes: obtaining public data and a security information asset; performing a Boolean operation on the public data and the security information asset by a first computing module to generate an output; obtaining the public data and the security information asset; and performing the Boolean operation on the public data and the security information asset by a second computing module to generate the output, wherein the first computing module has a first configuration, and the second computing module has a second configuration different from the first configuration.
[0006] In another example, an apparatus for securely performing cryptographic operations is provided, the apparatus including at least one memory and one or more processors coupled to the at least one memory. The one or more processors are configured to: obtain public data and security information assets; perform Boolean operations on the public data and the security information assets by a first computing module to generate an output; obtain the public data and the security information assets; and perform the Boolean operations on the public data and the security information assets by a second computing module to generate the output, wherein the first computing module has a first configuration and the second computing module has a second configuration different from the first configuration.
[0007] In another example, a non-transitory computer-readable medium is provided having instructions stored thereon that, when executed by one or more processors, cause the one or more processors to: obtain public data and security information assets; perform a Boolean operation on the public data and the security information assets by a first computing module to generate an output; obtain the public data and the security information assets; and perform the Boolean operation on the public data and the security information assets by a second computing module to generate the output, wherein the first computing module has a first configuration and the second computing module has a second configuration different from the first configuration.
[0008] In another example, an apparatus for performing cryptographic operations is provided. The apparatus includes: components for obtaining public data and security information assets; a first component for performing Boolean operations on the public data and security information assets to generate an output; components for obtaining the public data and security information assets; and a second component for performing the Boolean operation on the public data and security information assets to generate the output, wherein the first component for performing the Boolean operation on the public data and security information assets to generate the output has a first configuration, and the second component for performing the Boolean operation on the public data and security information assets to generate the output has a second configuration different from the first configuration.
[0009] In some aspects, one or more of the devices described herein are, are a part of, or include the following: mobile devices (e.g., mobile phones or so-called "smartphones," tablet computers, or other types of mobile devices), wearable devices, extended reality devices (e.g., virtual reality (VR) devices, augmented reality (AR) devices, or mixed reality (MR) devices), personal computers, laptop computers, video servers, television sets (e.g., network-connected television sets), vehicles (or computing devices or systems of vehicles), or other devices. In some aspects, the device includes at least one camera for capturing one or more images or video frames. For example, the device may include one or more cameras (e.g., an RGB camera) for capturing one or more images and / or one or more videos including video frames. In some aspects, the device includes a display for displaying one or more images, videos, notifications, or other displayable data. In some aspects, the device includes a transmitter configured to transmit one or more video frames and / or syntax data to at least one device via a transmission medium. In some aspects, the processor includes a neural processing unit (NPU), a central processing unit (CPU), a graphics processing unit (GPU), or other processing devices or components.
[0010] The features and technical advantages of the examples according to this disclosure have been summarized rather broadly above in order to better understand the detailed description below. Additional features and advantages will be described below. The disclosed concepts and specific examples can be readily used as the basis for modifying or designing other structures for achieving the same purpose as this disclosure. Such equivalent constructions do not depart from the scope of the appended claims. The characteristics of the concepts disclosed herein, in both their organization and manner of operation, and the associated advantages, will be better understood by considering the following description in conjunction with the accompanying drawings. Each of the drawings provided is for illustrative and descriptive purposes and not as a definition of limitation of the claims.
[0011] While aspects are described herein by way of example, those skilled in the art will understand that such aspects can be implemented in many different arrangements and scenarios. The techniques described herein can be implemented using different platform types, devices, systems, shapes, sizes, and / or package arrangements. For example, some aspects can be implemented via integrated chip implementations or other devices based on non-modular components (e.g., end-user equipment, vehicles, communication equipment, computing devices, industrial equipment, retail / shopping devices, medical devices, and / or artificial intelligence devices). Aspects can be implemented in chip-level components, modular components, non-modular components, non-chip-level components, device-level components, and / or system-level components. Devices incorporating the described aspects and features may include additional components and features for implementing and practicing the claimed and described aspects. For example, the transmission and reception of wireless signals may include one or more components for analog and digital purposes (e.g., hardware components including antennas, radio frequency (RF) chains, power amplifiers, modulators, buffers, processors, interleavers, adders, and / or summers). The aspects described herein are intended to be practiced in a wide variety of devices, components, systems, distributed arrangements, and / or end-user equipment of various sizes, shapes, and configurations.
[0012] Based on the accompanying drawings and detailed description, other objects and advantages associated with the aspects disclosed herein will be apparent to those skilled in the art. Attached Figure Description
[0013] Examples of specific implementations are described in detail below with reference to the accompanying figures:
[0014] Figure 1 This is a block diagram illustrating the data flow of security information assets in a computing system according to some examples of this disclosure.
[0015] Figure 2 This is a block diagram illustrating example cryptographic operations that combine public data with security information assets, according to some examples of this disclosure;
[0016] Figure 3 These are examples illustrating how secure operations according to some examples of this disclosure can reveal waveforms at specific moments during the processing of sensitive data;
[0017] Figure 4A This is a block diagram illustrating example security operations that could introduce vulnerabilities to side-channel attacks, according to some examples of this disclosure;
[0018] Figure 4B This is an example circuit model of a silicon gate and associated wiring that can introduce leakage vulnerabilities that are susceptible to side-channel attacks, based on some examples of this disclosure.
[0019] Figure 5This is a block diagram illustrating an example secure computing system including cryptographic components with enhanced security, according to some examples of this disclosure;
[0020] Figure 6A This is a block diagram illustrating a variety of cryptographic components for performing cryptographic operations according to some examples of this disclosure;
[0021] Figure 6B This is an additional block diagram illustrating, according to some examples of this disclosure, a variety of cryptographic components for performing cryptographic operations with individual key shares;
[0022] Figure 7 These are examples illustrating, according to some examples of this disclosure, of how to calculate n from n key shares. 2 A block diagram illustrating an example architecture that uses n key shares to enhance the security of secure operations, where the n key shares may introduce vulnerabilities that are susceptible to side-channel attacks.
[0023] Figure 8A This is a block diagram illustrating an example structure of a bilinear operation performed on a combination of public and secret data according to some examples of this disclosure;
[0024] Figure 8B These are examples illustrating some aspects relative to this disclosure. Figure 8A The block diagram is a block diagram of an alternative example structure for performing bilinear operations on a combination of public and secret data to enhance security;
[0025] Figure 9 This is a flowchart illustrating examples of processes for handling cryptographic operations according to some examples of this disclosure;
[0026] Figure 10 This is a diagram illustrating an example of a computing system according to some examples of this disclosure. Detailed Implementation
[0027] Certain aspects and embodiments of this disclosure are provided below. Some of these aspects and embodiments may be applied independently, and some may be combined, as will be apparent to those skilled in the art. Specific details are set forth in the following description for purposes of explanation in order to provide a thorough understanding of the various embodiments of this application. However, it will be apparent, however, that the various embodiments may be practiced without these specific details. The accompanying drawings and descriptions are not intended to be limiting.
[0028] The following description provides only exemplary embodiments and is not intended to limit the scope, applicability, or configuration of this disclosure. Rather, the subsequent description of exemplary embodiments will provide those skilled in the art with enabling descriptions for implementing the exemplary embodiments. It should be understood that various changes may be made to the function and arrangement of the elements without departing from the spirit and scope of this application as set forth in the appended claims.
[0029] Cryptographic encryption can be used to encrypt, decrypt, and / or ensure the authenticity of electronic data. Symmetric cryptography uses the same key (e.g., referred to as a secret key or private key) for both encryption and decryption. Asymmetric cryptography uses a private key and a public key shared between the parties. "Private key" and "public key" refer to asymmetric encryption keys, where the private key is known only to a first device (e.g., a peripheral device), and the public key is known to both the first and second devices (e.g., a host device), as well as potentially other devices. The second device uses the public key to encrypt the data. The first device uses the private key to decrypt the data. Asymmetric cryptography can also be referred to as public-key cryptography (PKC). Examples of symmetric cryptography include Advanced Encryption Standard (AES), Data Encryption Standard (DES), Blowfish, Ascon, Keccak, and the International Data Encryption Standard (IDEA). In some examples, symmetric cryptography such as AES can be used to achieve fast and efficient encryption and decryption. However, because the same key is used for both encryption and decryption, the private key in symmetric cryptography must be distributed to the parties in a way that protects the confidentiality of the private key. For example, PKC or asymmetric cryptography techniques are often used to perform key distribution for symmetric cryptography (e.g., Diffie-Hellman).
[0030] As an example, secure information assets can be cryptographic keys, subkeys, auxiliary keys, derived keys, and / or any other secure information assets used to encrypt and / or decrypt data and / or ensure the authenticity of data used by a computing device. Such secure information assets can be stored in a secure information storage device. In an exemplary example, secure information assets may include a private key for a symmetric cryptographic key (also referred to herein as a secret key) and / or a private key for an asymmetric cryptographic key. In some cases, the secure information storage device may include a secure information asset storage device (e.g., an one-time programmable (OTP) storage device, a non-volatile memory device, a flash memory device, etc.). Secure information assets may be obtained from the secure information asset storage device during the execution of the computing device (e.g., at startup, restart, and / or during updates), stored in a separate storage device, and provided as needed to security components (e.g., encryption engines, key tables, key derivation functions, etc.) for performing secure operations (e.g., encryption and / or decryption of data). The security information assets thus obtained can be used directly by any number of security components and / or can be used to derive additional security information assets (e.g., derived keys used by an encryption engine to encrypt and / or decrypt data), which is an example of a security operation. In some cases, without departing from the scope of this disclosure, a security operation may include additional steps or transformations using the security information assets.
[0031] In some cases, a computing system may include multiple identical bilinear cryptographic components with the same trace structure (e.g., such as...). Figure 4B (See schematic diagram 450). In some cases, attackers can exploit the self-similarity of different bilinear cryptographic components to obtain information about secure information assets in side-channel attacks. As used herein, "self-similarity" refers to the similarity of the same operation performed by different bilinear cryptographic modules. In some cases, the self-similarity of the same operation performed by different bilinear cryptographic models can indicate the same trace structure. In some cases, the traces used in bilinear cryptographic components can be grouped in the periphery of a small silicon. As used herein, "lack of diffusion" refers to the grouping of circuits used in sensitive operations (e.g., secure operations) in the periphery of a small silicon. In some cases, self-similarity, lack of diffusion, and / or any combination thereof can be exploited to obtain information about secure information assets in side-channel attacks.
[0032] Figure 1A simplified block diagram 100 is illustrated, illustrating the data flow of secure information assets in a computing system. In some examples, secure information assets are obtained from secure information asset storage device 102. As an example, secure information assets may be obtained from secure information asset storage device 102 when the computing device is started, restarted, and / or updated for various security operations (e.g., encryption and / or decryption operations, key derivation operations, other steps or transformations performed using secure information assets, etc.). In some examples, secure information assets are obtained at a randomization engine. In some examples, the randomization engine is any hardware, software, firmware, or any combination thereof existing within the secure execution environment of the computing device. In some examples, the secure execution environment is any part of the computing device that is a secure area of the computing device. Examples of secure execution environments include, but are not limited to, trusted management environments, trusted execution environments, trusted zones, trusted platform modules, secure components, secure elements, etc. In some examples, the secure information asset storage device is a read-only storage device, such as a read-only memory device, a one-time programmable storage device, etc. In some examples, the security information asset storage device 102 is a reprogrammable storage device, such as a non-volatile memory device, a flash memory device, etc. In some examples, the security information assets can be obtained from the security information asset storage device each time the computing device is started or restarted. The security information assets (e.g., cryptographic keys) can be stored on the security information asset storage device in a masked or unmasked form.
[0033] Simplified block diagram 100 illustrates a copy / mask / refresh module 104 communicatively coupled to a secure information asset storage device 102. In some cases, the copy / mask / refresh module 104 can perform the copying of secure information assets. For example, the copy / mask / refresh module 104 can copy variables to be reused at different logic gates (e.g., create copies). In some cases, duplicate variables may be used at multiple different times. In some cases, the reuse of duplicate variables can lead to... Figure 3 The illustrated repeating pattern is 315.
[0034] In some cases, the copy / mask / refresh module 104 may mask security information assets obtained from the security information asset storage device 102. As used herein, “mask” refers to the process of obfuscating the contents of a data item. Any suitable form of data masking may be used without departing from the scope of the examples described herein. In some examples, data masking refers to altering data represented in binary form such that if read by any entity not configured to understand the applied masking, the data does not represent the original data (e.g., security information asset), but an entity configured to know the masking (e.g., an encryption engine) can demask and subsequently use the original data (e.g., a cryptographic key). Examples of data masking processes include, but are not limited to, techniques such as replacement, data shuffling, adding data to the original data, altering data using various parameters (e.g., date, time, etc.), splitting and randomizing the order in which data is sent, splitting data into separate parts and adding additional data to each part (e.g., random numbers), and combinations of all or any of the foregoing techniques.
[0035] In some examples, the copy / mask / refresh module 104 may transform and / or re-decode secure information assets into different forms (e.g., different data values) representing the same secure information asset. As used herein, "refresh" means ensuring that the form of a secure information asset does not remain static. For example, but not limited to, secure information assets may be refreshed based on the elapsed time intervals in which the information security asset exists in a particular form (e.g., periodic intervals, pseudo-random intervals), based on the amount of use of the secure information asset in a particular form, based on storing the secure information asset in a new location, at startup, at restart, during updates, and / or any combination thereof. In some cases, systematically refreshing secure information assets can help protect them from the detection of side-channel attacks. In some cases, refreshing secure information assets may include changing the value of the secure information asset in a manner that alters the stored value of the secure information asset in the secure information asset storage device 102 while still maintaining the security functionality of the secure information asset.
[0036] In an exemplary example, the secret key H can be represented by two random values H1 and H2 (also called “shares” of the secret key H). In some cases, H can be expressed as a combination of shares H1 and H2 according to the following equation (1):
[0037] H = H1 XOR H2 (1)
[0038] XOR stands for bitwise XOR. In some cases, it is preferable to avoid actually performing the calculation shown in equation (1), which may reveal H in a demasking manner.
[0039] In some cases, one or more of shares H1 and H2 can be masked by changing the value of each individual share while keeping the result of equation (1) the same. For example, the copy / mask / refresh module 104 can mask share H1 according to the following equation (2a):
[0040] H 1,m = H1 XOR R1 (2a)
[0041] Where H 1,m It is the masking form of H1 and R1 is a random value. Similarly, the copy / mask / refresh module 104 can mask share H2 according to the following equation (2b):
[0042] H 2,m = H2 XOR R2 (2b)
[0043] Where H 2,m H2 is the masking form and R2 is a random value. Many different implementations can be used to generate masking shares H, provided that the masking shares satisfy the following equation (3). 1,m and H 2,m :
[0044] H = H 1,m XOR H 2,m (3)
[0045] It should be understood that the masking operations illustrated in equations (2a) and (2b) are for illustrative purposes, and other masking operations may be used without departing from the scope of this disclosure.
[0046] In some cases, the masking share H can be refreshed. 1,m and H 2,m One or more of them to prevent the masking share H 1,m and H 2,m Remain static. For example, the copy / mask / refresh module 104 can use the refreshed masking share H in the secure information asset storage device 102. 1,r and H 2,r Replacement share H 1,m and H 2,m As long as the refresh share satisfies the following equation (4), many different implementations can be used to generate the refresh share H. 1,r and H 2,r :
[0047] H = H 1,r XOR H 2,r (4)
[0048] return Figure 1The copy / mask / refresh module 104 can assign security information assets (e.g., secret keys, secret keys, masked secret keys, shares of derived secret keys) to the cryptographic component 106. In some cases, the cryptographic component 106 can use the security information assets as input to perform security operations. In some cases, the cryptographic component 106 can use a combination of security information assets (e.g., one or more secret keys) and public data to perform security operations. As used herein, "public data" means explicitly public data (e.g., public keys) and / or data that an attacker can infer from explicitly public data.
[0049] In some respects, as discussed above, the security components of a computing device may require security information assets (e.g., secret keys) to perform one or more security operations (e.g., encrypting and / or decrypting data, generating derived cryptographic keys, any other steps and / or transformations performed using the security information assets, etc.).
[0050] However, the repeated reuse of secure information assets can allow attackers to obtain all or any part of these assets using various techniques, potentially compromising the security of computing devices. As an example, an attacker could perform a side-channel attack by using measuring devices (e.g., an oscilloscope) to measure any number of characteristics of the computing device during its operation (e.g., voltage, power, electromagnetic output, timing information, sound, temperature, etc.). As another example, an attacker could employ fault injection techniques. In some cases, attackers can leverage machine learning (ML) models (e.g., deep learning neural networks) to aid in side-channel attacks.
[0051] Such attacks may have limited impact when executed once or a relatively few times, but they can become more effective when executed more frequently. Therefore, when using such techniques, secure information assets become more vulnerable to attack when reused. For example, when performing operations that transmit secure information assets, or when using secure information assets to perform operations (collectively referred to as secure operations), measuring one or more characteristics of the operation of a computing device may allow an attacker to obtain all or any part of the secure information assets, potentially compromising the security of the computing device.
[0052] In some cases, when a cryptographic key is being sent and / or received (e.g., when obtained from a secure information asset storage device at startup, when obtained from a different storage device, when provided to a security component for performing security operations, etc.), used to derive other cryptographic keys, an attacker engaging in a side-channel attack or fault injection attack can be able to deduce that cryptographic key and thus be able to use the key to decrypt data on a computing device and / or encrypt potentially malicious data using the correct key, which can then be used by the computing device. In some cases, the derivation of a cryptographic key may include bilinear operations. For example, the derivation of a cryptographic key may include multiplying a public key and a private key to generate a derived key.
[0053] In some cases, if an attacker can determine the timing of the operation delivering the secure operation, the measurement device can capture the characteristics of the computing device at high resolution on a timescale. In some cases, the amount of data an attacker can capture may be limited by the amount of storage available in the measurement device. In an exemplary example, the oscilloscope may include a measurement buffer (e.g., memory) capable of storing up to one million measurements. In some cases, if an attacker can determine the timing of a 100ms secure operation within one millisecond (ms), the measurement timescale may be approximately 100 nanoseconds (ns). However, if the attacker does not know the timing of the 100ms operation, the measurement timescale (e.g., 1 microsecond, 10 microseconds, and / or any other suitable timescale) can be significantly longer than when the timing information is known. In some cases, for longer measurement timescales, the data delivery, data storage, and / or data processing requirements for storing and processing on the attacker's device (e.g., high-order differential power analysis, deep learning ML attacks, etc.) to extract useful information relative to attacks with known timing information may be significantly more expensive.
[0054] Figure 2 This is a block diagram 200 illustrating an example cryptographic operation that combines public data with security information assets. For example... Figure 2 As illustrated, secret key 202 (e.g., secure information assets) can be input into AES cryptographic module 206 along with zero data block 204 (e.g., 128 bits all with values "0"). As illustrated, AES cryptographic module 206 can generate hash subkey (H) (e.g., a 128-bit value) based on secret key 202. Figure 2 As illustrated, H is assigned to two different computation modules 208. In some cases, computation module 208 may correspond to... Figure 1 The cryptographic component 106. In an exemplary example, each computing module 208 may also access the storage device 210 (e.g., Figure 10 System memory 1015, storage device 1030, Figure 5The memory 514) obtains one or more common data values A. i (For example, common data values A0 and A1). In an exemplary example, the calculation module 208 may be based on the common data value A0. i The computation is performed using the hash subkey H, and in some cases, the common data value A of each computation module 208. i These can be the same public data value or different public data values. In some cases, the calculation module 208 can implement calculations relative to the public data value A. i A bilinear function of the hash subkey H. Exemplary examples of bilinear functions include, but are not limited to, matrices from Dilithium. Vector multiplication, AES MixColumns, GF(2) for AES-GCM mode 128 A in ) H, any other bilinear function, and / or any combination thereof. In some cases, by Figure 2 The operations performed by the computing module 208 may occur at different times. In some cases, the structure of the computing module 208 (e.g., the physical arrangement of the logic gates and wiring traces used) may be the same.
[0055] Figure 3 A waveform 300 is illustrated for a secure operation that could reveal power consumption and / or timing information to an attacker. For example, an attacker might attempt to analyze waveform 300 to obtain information about one or more precise moments when the most sensitive security assets are processed. As illustrated, the power fluctuations between the start 305 and end 310 of an AES encryption operation (e.g., a secure operation) may differ from the power fluctuations before the start 305 and after the end 310 of the AES encryption operation. In some cases, due to the reuse of variables (e.g., public keys), (e.g., by...) Figure 2 The self-similarity of operations performed at different times by the same computational module 208 and / or the lack of diffusion of components used to perform cryptographic operations outside the small silicon periphery (which may lead to repetitive patterns 315 in power fluctuations) can keep secure operations identifiable. In some cases, the reuse of variables can improve the signal-to-noise ratio of information obtained in side-channel attacks, which may benefit attackers. In some examples, the lack of diffusion within cryptographic operations can allow for the analysis of joint combinational leaks within the small silicon periphery via machine learning and / or AI. In some cases, side-channel attacks can capture measurements targeting the small silicon periphery to avoid interference from external components.
[0056] While AES encryption is provided as an example, other secure operations, including but not limited to number-theoretic transformation (NTT) computations and matrix-vector multiplication (AES), are also included. y), r and rG multiplication (e.g., elliptic curve point multiplication) events (e.g. for Elliptic Curve Digital Signature Algorithm (ECDSA)), secure hash algorithms (e.g., SHA-256, SHA-3), McEliece cryptography, bit-flipped key encapsulation (BIKE), Hamming quasi-cyclic (HQC) encryption, hash-based message authentication codes (e.g., HMAC-512), RNG seeding, and / or any combination thereof can also reveal information to an attacker through side-channel attacks.
[0057] Many techniques have been developed to reduce vulnerabilities in secure operations. For example, some techniques may include hiding secure operations, imposing variable timing, performing specialized operations, adding redundant operations, etc. In some cases, one or more techniques can be implemented in software executed by a computing system. However, as mentioned above, in some cases, secure operations can remain identifiable due to variable reuse, the self-similarity of operations performed at different times, and / or the lack of diffusion of cryptographic operations.
[0058] For example, Figure 4A This is a block diagram illustrating an example security operation 400 that could introduce a vulnerability to side-channel attacks. In an illustrative example, security operation 400 could represent a specific implementation of the Dilithium signature scheme described in Migliore et al., “Masking Dilithium: Efficient Implementation and Side-Channel Evaluation,” Applied Cryptography and Network Security, 2019, pp. 344–362, the entire contents of which are incorporated herein by reference and used for all purposes. Figure 4A In the example illustration, masking functions (e.g., additional generator module 404) and / or variables (e.g., Y, S1) are illustrated with double lines, while unmasking functions (e.g., generator module 402, hash function (H) 412) and / or variables (e.g., ρ, W, C) are illustrated with single lines. Figure 4A As illustrated, generation module 402 generates variable A based on a publicly available seed ρ. Additional generation module 404 secretly generates matrix Y. (As shown...) Figure 4AAs illustrated, multiplier 406 multiplies variable A and matrix Y together to generate a masked version of variable W. In some cases, demasking module 408 generates a demasked version of variable W. As illustrated, "high-order" module 410 outputs the high-order bits of the demasked variable W. As illustrated, H 412 obtains the high-order bits of W, seed ρ, derived variable T1, and message μ. In some cases, derived variable T1 can be generated based on variable A and secret key shares S1, S2. As illustrated, H 412 generates challenge variable C. As illustrated, multiplier 416 multiplies challenge variable C with secret key share S1, and adder 418 adds the result to matrix Y to generate variable Z. In some cases, the multiplication operations of multipliers 406 and 416 can be implemented by bilinear cryptographic components. In some specific implementations, the multiplication operation can mix "common" data with highly sensitive values.
[0059] exist Figure 4A In the illustrated examples, the unmasked common variables (e.g., A, C) from generation module 402 and / or H 412 can be operands in bilinear operations that may not be protected by masking. As illustrated, there are cases where unmasked common variables (e.g., variable A, challenge variable C) are combined with masked secret variables (e.g., secret key, secret key share, derived key variable, derived key share variable) in bilinear multiplication operations (e.g., via multipliers 406, 416). In some cases, the apparent lack of protection for modules performing operations involving masked secret variables presents an opportunity to develop new countermeasures. For example, defensive countermeasures can be added to bilinear multipliers 406, 416. In some cases, the same unmasked common variables can be reused in operations that utilize masked secret variables. In some cases, the reuse of unmasked common variables by bilinear cryptographic components in bilinear operations (e.g., multiplication) can lead to a repetition pattern 315 in power consumption, which can be exploited to obtain information about secure information assets in a side-channel attack. In some cases, the more frequently a masked secret variable (or a share of a masked secret variable) interacts with one or more common variables (e.g., variables known in advance and / or expected to be known by an attacker) in a bilinear operation, the easier it may become for an attacker to discern patterns in power consumption and / or timing during a side-channel attack. In some specific implementations, masking some or all of the common variables can be used to enhance security by preventing an attacker from knowing that the masked variable corresponding to the common variable is being used in one or more operations.
[0060] Figure 4BAn example schematic diagram 450 illustrates two circuits 452, 454 used to process two adjacent data bits within a cryptographic operation. Many protected implementations prevent first-order power analysis and assume that the two logically distinct circuits are sufficiently isolated and do not interact. When two logically distinct circuits are sufficiently isolated (e.g., through physical separation, shielding, etc.), masking or randomizing all individual bits within the computation may be sufficient to prevent the leakage of any useful information to an attacker. However, in some cases, bit pairs within a cryptographic operation may leak additional information through electrical coupling. In an illustrative example, electrical coupling between bits within a cryptographic operation can be achieved by two wires (e.g., Figure 4B The electrical coupling is caused by the proximity of wires 456 and 458. In some cases, the electrical coupling can be mutual capacitive coupling, represented as Cj,j+1 in schematic 450, and / or mutual inductive coupling, represented as Lj,j+1 in schematic 450. In some cases, the values of capacitance Cj,j+1 and / or inductance Lj,j+1 can be functions of the wire geometry and / or distance of wires 456 and 458. In some examples, this coupling interaction can be used to recover the original unmasked secret bit value. In some cases, the two circuits 452 and 454 illustrated in schematic 450 can carry two masked bits of secure information assets within a specific bilinear cryptographic component. In an illustrative example, if wires 456 and 458 happen to carry two masked bits processed concurrently in an XOR operation, the electrical coupling between wires 456 and 458 can reveal information to an attacker.
[0061] In some cases, a computing system may include multiple identical bilinear cryptographic components having the same trace structure as schematic diagram 450. In some cases, an attacker may exploit the self-similarity of different bilinear cryptographic components with masked data to obtain information about unmasked secret security information assets in a side-channel attack through real-time interaction caused by simultaneity and / or various forms of coupling. As used herein, “self-similarity” refers to the similarity of the same operations performed by different bilinear cryptographic modules. In some cases, the self-similarity of the same operations performed by different bilinear cryptographic models may indicate the same trace structure. In some cases, the traces used in the bilinear cryptographic components may be grouped in a small silicon periphery. In some cases, self-similarity, lack of diffusion, and / or any combination thereof may be exploited to obtain information about security information assets in a side-channel attack.
[0062] In view of the foregoing, there is a need for systems and techniques to enhance the security of cryptographic components (e.g., linear and / or bilinear components).
[0063] This document describes systems, apparatuses, electronic devices, methods (also referred to as processes), and computer-readable media (collectively referred to herein as "systems and techniques") for enhancing security in cryptographic components. In some examples, the microarchitecture of a secure computing system (e.g., within a secure execution environment) may be designed with microarchitectural protections that automatically prevent the repeated deterministic use of sensitive security information assets at the processor level. In some cases, the systems and techniques described herein may be implemented automatically at the runtime and processor levels. For example, in some implementations, the systems and techniques may be implemented using rotations between several different multiplier units and / or microcode versions.
[0064] Various aspects of the systems and technologies described herein will be discussed below with reference to the accompanying drawings. Based on various examples, Figure 5 This is an illustration of an example computing device 500. The computing device 500 may include, but is not limited to, any of the following: one or more processors (e.g., components including integrated circuits, memory, input and output devices (not shown)), non-volatile storage hardware, one or more physical interfaces, any number of other hardware components (not shown), and / or any combination thereof. Examples of computing devices include, but are not limited to, mobile devices (e.g., laptops, smartphones, personal digital assistants, tablets, automotive computing systems, and / or any other mobile computing devices), Internet of Things (IoT) devices, servers (e.g., blade servers in blade server chassis, rack servers in racks, etc.), desktop computers, storage devices (e.g., disk drive arrays, Fibre Channel storage devices, Internet Small Computer System Interface (iSCSI) storage devices, tape storage devices, flash storage arrays, network-attached storage devices, etc.), network devices (e.g., switches, routers, multi-layer switches, etc.), wearable devices (e.g., network-connected watches or smartwatches, or other wearable devices), robotic devices, smart TVs, smart appliances, extended reality (XR) devices (e.g., augmented reality (AR), virtual reality (VR), etc.), any device including one or more SoCs, and / or any other type of computing device having the foregoing requirements. In one or more examples, any or all of the examples foregoing may be combined to create systems of such devices, which may be collectively referred to as computing devices. Other types of computing devices may be used without departing from the scope of the examples described herein.
[0065] like Figure 5As illustrated, computing device 500 may include one or more antennas 502, one or more wireless communication modules 506, processor 510, memory 514, application module 518, user interface 550, microphone / speaker 552, keypad 554, display 556, secure information storage device 570, trusted execution environment 580, and security component 590.
[0066] As shown in the figure, computing device 500 may include one or more wireless communication modules 506 that can be connected to one or more antennas 502. The one or more wireless communication modules 506 include suitable devices, circuits, hardware and / or software for communicating with access points, networks, base stations and / or detecting signals to / from access points, networks, base stations and / or for communicating directly with other wireless devices within the network.
[0067] In some implementations, one or more wireless communication modules 506 may include a communication system (e.g., a CDMA system) suitable for communicating with a network of wireless base stations (e.g., a CDMA network). In some implementations, the wireless communication system may include other types of cellular telephone networks, such as TDMA, GSM, WCDMA, 4G / LTE, 5G / NR, etc. Additionally, any other type of wireless networking technology may be used, including, for example, WiMax (802.16), Wi-Fi (802.11), etc.
[0068] Processor (also referred to as controller) 510 may be connected to one or more wireless communication modules 506. Processor 510 may include one or more microprocessors, microcontrollers, and / or digital signal processors that provide processing functions as well as other computing and control functions. Processor 510 may be coupled to a storage medium (e.g., memory) 514 for storing data and software instructions for executing programmed functions within a mobile device. Memory 514 may be onboard on processor 510 (e.g., within the same IC package), and / or memory may be external memory of the processor and functionally coupled via a data bus.
[0069] Multiple software engines and data tables may reside in memory 514 and may be utilized by processor 510 to manage communication, perform location determination functionality, and / or perform device control functionality. In some cases, memory 514 may include application module 518. It should be noted that the functionality of modules and / or data structures may be combined, separated, and / or structured in different ways depending on the specific implementation of computing device 500.
[0070] Application module 518 may include a process running on processor 510 of computing device 500, which may request data from one of the other modules of computing device 500. Applications typically run within a higher layer of the software architecture and can be implemented in the rich execution environment of computing device 500, and may include indoor navigation applications, shopping applications, financial services applications, social media applications, location-aware service applications, etc.
[0071] In some examples, computing device 500 includes a secure information storage device 570. In some examples, secure information storage device 570 can be any storage device configured to store secure information assets (e.g., cryptographic keys, metadata, etc.). For example, secure information storage device 570 is a device that stores secure information assets and from which the secure information assets are initially retrieved when needed on the computing device (e.g., for encrypting and / or decrypting data). In some cases, secure information storage device 570 may include a key repository or key table. Examples of secure information storage device 570 include, but are not limited to, various types of read-only memory, one-time programmable memory devices (e.g., one-time programmable fuses or other types of one-time programmable memory devices), non-volatile memory, etc. Secure information storage device 570 can be operatively connected to trusted execution environment 580 and / or security component 590. Although Figure 5 The computing device 500 is shown as including a single secure information storage device 570, but without departing from the scope of the examples described herein, the computing device 500 may include any number of secure information storage devices.
[0072] Processor 510 may include a Trusted Execution Environment 580. The Trusted Execution Environment 580 may also be referred to as a Trusted Management Environment, Trust Zone, Trusted Platform Module, etc. The Trusted Execution Environment 580 may be implemented as a secure area of processor 510, which can be used to process sensitive data and store such sensitive data in an environment isolated from the Rich Execution Environment, where the operating system and / or applications (such as applications in application module 518) can execute. The Trusted Execution Environment 580 may be configured to execute secure applications (also referred to as trusted applications), which provide end-to-end security for sensitive data by enforcing confidentiality, integrity, and protection on the sensitive data stored therein. The Trusted Execution Environment 580 may be used to store encryption keys, access tokens, and other sensitive data.
[0073] Computing device 500 may include one or more security components 590 (e.g., Figure 2 Calculation module 208 Figure 6A The computing modules 608A, 608B, and 608C Figure 6B The computing modules 658A, 658B, and 658C... Figure 8AThe computing module 806 and / or Figure 8B (Alternative computing module 856). In some cases, security component 590 may be referred to as a trusted component, secure element, trusted element, etc. Computing device 500 may include security component 590 as a complement to or alternative to trusted execution environment 580. Security component 590 may include autonomous and tamper-proof hardware that can be used to execute secure applications and confidential data associated with such applications. Security component 590 may be used to store encryption keys, access tokens, and other sensitive data. Security component 590 may include near field communication (NFC) tags, subscriber identity module (SIM) cards, or other types of hardware devices that can be used to securely store data. Security component 590 may be integrated with the hardware of computing device 500 in a permanent or semi-permanent manner, or in some implementations, it may be a movable component of computing device 500 that can be used to securely store data and / or provide a secure execution environment for applications.
[0074] Examples of security applications that can be executed by computing device 500, processor 510, secure information storage device 570, trusted execution environment 580, security component 590, and / or any combination thereof include, but are not limited to, encrypting data, decrypting data, key derivation, performing data integrity verification, and performing certified encryption and decryption. In some examples, computing device 500 and / or portions thereof may be configured to perform various cryptographic service types by being configured to execute one or more cryptographic algorithms. As an example, to perform encryption and decryption, one or more components of computing device 500 (e.g., secure information storage device 570, trusted execution environment 580, security component 590) may be configured to perform one or more of the following: Advanced Encryption Standard XOR-Encryption-XOR Adjustable Block Ciphertext Stealing (AES-XTS) algorithm, AES-Cryptographic Block Chaining (AES-CBC) algorithm, AES-Electronic Codebook (AES-EBC) algorithm, Cryptographic Salt-Sector Initialization Vector-AES-CBC (ESSIV-AES-CBC) algorithm, etc., including any variants of such algorithms (e.g., 128-bit, 192-bit, 256-bit, etc.). As another example, to perform integrity verification, one or more components of computing device 500 may be configured to perform hash algorithms, such as one or more members of the SHA hash algorithm family. As yet another example, to perform authenticated encryption, one or more components of computing device 500 may be configured to perform the AES-Galois / Counter Mode (GCM) algorithm. In some respects, without departing from the scope of the examples described herein, one or more components of computing device 500 may be configured to perform any other cryptographic algorithms.
[0075] The computing device 500 may also include a user interface 550 that provides a suitable interface system allowing users to interact with the computing device 500, such as a microphone / speaker 552, a keypad 554, and / or a display 556. The microphone / speaker 552 may provide voice communication services (e.g., using one or more wireless communication modules 506). The keypad 554 may include suitable buttons for user input. The display 556 may include a suitable display, such as, for example, a backlit LCD display, and may also include a touchscreen display for additional user input modes.
[0076] Although Figure 5 A specific number of components in a particular configuration is shown; however, those skilled in the art will understand that the computing device 500 may include more or fewer components, and / or components arranged in any number of alternative configurations, without departing from the scope of the examples described herein. Furthermore, although Figure 5 Although not shown, those skilled in the art will understand that computing device 500 can execute any amount or type of software or firmware (e.g., bootloader, operating system, hypervisor, virtual machine, computer application, mobile device application, etc.). Therefore, the examples disclosed herein should not be limited to... Figure 5 The configuration of the components shown. Figure 5 The components shown may or may not be discrete components. In some aspects, one or more of these components may be combined into distinct hardware elements, implemented in software, and / or otherwise implemented using software and / or hardware. As used herein, the term "device" may be a discrete component or apparatus, or may not be a discrete component. In some aspects, other devices may exist within, be part of, and / or utilize the same hardware components as the device.
[0077] Figure 6A This is a block diagram 600 illustrating a variety of cryptographic components used to perform secure operations. Figure 6A In the example, secret key 602 can be similar to Figure 2 The secret key 202 performs a similar function, the zero data block 604 can perform a similar function to the zero data block 204, the AES cryptographic module 606 can perform a similar function to the AES cryptographic module 206, and the storage device 610 can perform a similar function to the secret key 202. Figure 2 The storage device 210 performs similar functions.
[0078] like Figure 6AAs shown, the hash subkey (H) (e.g., the secure information asset) can be shared with three computing modules 608A, 608B, and 608C. Computing modules 608A, 608B, and 608C can each perform the same logical function. In an exemplary example, all three computing modules 608A, 608B, and 608C can be configured to compute the GF(2) of the AES-GCM. 128 In A*H, for the same common input A, in some cases, the input A*H is the same as the input A*H. i (For example, A0, A1, A2), H, each of the calculation modules 608A, 608B, and 608C can produce the same result. However, as Figure 6A As illustrated, the internal structure (e.g., logic gates, wiring traces, etc.) of each computing module 608A, 608B, 608C can be diversified using different microarchitectures. In some cases, the diversification of the structure within computing modules 608A, 608B, 608C can reduce the ability of side-channel attacks to detect the similarity between operations that produce the same result when presented with the same input. In some cases, the common input A multiplied by H in each computing module 608A, 608B, 608C... i They can have the same or different public values.
[0079] like Figure 6A As illustrated, the computing module 608A includes a logic gate 612. The logic gate 612 may include one or more transistors 614 and traces 616. In some cases, when A is executed... During H calculation, the calculation module 608A can exhibit the first power signature, and upon receiving input A... i The first timing between H and the generated result.
[0080] In the illustrated example, the computation module 608B includes three logic gates 618, 620, and 622. In some cases, logic gates 618 and 620 may perform operations on inputs A and H in the first computation stage and generate intermediate values passed to logic gate 622. As illustrated, logic gate 622 may perform operations on the intermediate values to generate a result. In some aspects, when A is executed... During H calculation, the calculation module 608B can exhibit a second power signature, and upon receiving input A... i A second timing interval between H and the generated result. In some cases, the second power signature and / or the second timing interval may differ from the first power signature and / or the first timing interval. For example, the two-stage operation of the computing module 608B may add the received input A compared to the computing module 608A. i The delay between H and the generated result.
[0081] like Figure 6AAs shown, computation module 608B includes logic gate 624. As illustrated, logic gate 624 may include one or more transistors 626 and wiring traces 628. In the illustrated example, unlike the straight wiring trace 616 of logic gate 612 in computation module 608A, wiring trace 628 is illustrated as having a tortuous path. In some cases, when performing A... During H calculation, the calculation module 608C can exhibit a third power signature, and upon receiving input A... i A third timing between H and the resulting power signature. In some cases, the third power signature and / or the third timing may differ from the first power signature, the first timing, the second power signature, and / or the second timing. For example, the difference between wiring trace 616 and wiring trace 628 may result in different capacitances, resistances, inductances, conductances, mutual capacitances, and / or mutual inductances (e.g., as shown in the original text). Figure 4B (as illustrated), which in turn can lead to different signatures between computing module 608A and computing module 608C.
[0082] In some cases, although Figure 6A Although not shown, the structures of computing modules 608A, 608B, and 608C can be configured such that the two inputs are asymmetrical and the inputs are switched to perform the calculation H. A instead of A H can have different power signatures and / or timings. In some respects, the asymmetry between inputs can provide another form of diversification, which can reduce the effectiveness of side-channel attacks.
[0083] Figure 6B This is block diagram 650 illustrating additional, diverse cryptographic components used to perform secure operations. Figure 6B In the example, the modified AES cryptographic module 656 can generate three shares of H: H1, H2, and H3, as follows: Figure 6B As illustrated, the public variable A can be multiplied by H2 in calculation module 658B. In some embodiments, A can optionally be multiplied by H1 in calculation module 658A. In some embodiments, A can optionally be multiplied by H3 in calculation module 658C. Although Figure 6B The illustrated configuration does not show that public key A is multiplied by the same secret key in each of the computing modules 658A, 658B, and 658C, but Figure 6B The configuration shown can benefit from, for example, relative to Figure 6A The computing modules 608A, 608B, and 608C described in the computing modules 658A, 658B, and 658C are diverse. It should be understood that, without departing from the scope of this disclosure, [the following is a possible interpretation of the meaning of the terms:] ...relative to... Figure 6AThe static diversity described in the computation modules 608A, 608B, and 608C can be applied to the configuration of other cryptographic components that enable multiplication between public data and secure information assets.
[0084] It should be understood that Figure 6A The computing modules 608A, 608B, 608C and Figure 6B The computation modules 658A, 658B, and 658C are simplified for illustrative purposes, and computation modules containing more or fewer logic gates and / or traces may be used without departing from the scope of this disclosure. Although wiring trace 628 is illustrated as a meandering path and wiring trace 616 as a straight line, it should be understood that other differences between the wiring of two logic gates may lead to diversification between different computation modules performing the same computation, while remaining within the scope of this disclosure. Relative to Figure 6A and Figure 6B The examples of diversification illustrated and described should not be considered limiting, and it should be understood that other types of diversification may be used without departing from the scope of this disclosure.
[0085] Figure 7 This is a block diagram illustrating an example of an architecture 700 used to enhance the security of secure operations by utilizing multiple key shares. In some specific implementations, Figure 7 The architecture 700 can be used to access data based on n sensitive asset shares H. i and n public data shares a i Combination n 2 A product is used to enhance the security of the full masking operation, where n is an integer. Figure 7 In the example, the public data "a" can be divided into three public shares (e.g., n=3): a1, a2, and a3. As mentioned above, in some specific implementations, during execution... Figure 7 Masking the public share prior to a secure operation can potentially enhance security by making it more difficult for an attacker to know that a known value of the public share is being used in the computation. In some examples, the hash subkey (H) can be similarly divided into three secret shares (e.g., n=3) H1, H2, and H3. In some aspects, additional steps are taken to generate n... 2 Additional hardware for each product increases the amount of computation, silicon area, and / or power consumption in exchange for increased security.
[0086] In some cases, Architecture 700 can be used to obfuscate secret shares H1, H2, and H3 to prevent them from being revealed in side-channel attacks. However, even in Figure 7In the example, each of the secret shares H1, H2, H3 is used three times (e.g., once with each public share a1, a2, a3). In some cases, if there is no diversification within the computation modules 702, 704, 706, 708, 710, the computation may suffer from problems such as variable reuse, self-similarity, and / or diffusion as described herein.
[0087] exist Figure 7 In the examples, computation modules 702, 704, 706, 708, and 710 can perform bilinear computations on one of the public shares and one of the secret shares. In one exemplary example, computation modules 702, 704, 706, 708, and 710 can perform 128-bit multiplication. As illustrated, computation module 702 receives public share a3 and secret share H3, computation module 704 receives public share a1 and secret share H3, and computation module 706 receives public share a3 and secret share H1.
[0088] As illustrated, the outputs of calculation modules 702, 704, and 706 can be combined by adder 712 (e.g., bitwise XOR) to generate variable Z2. Similarly, the output of calculation module 708 can be combined by adder 714 to generate variable Z1, and the output of calculation module 710 can be combined by adder 716 to generate variable Z3.
[0089] like Figure 7 As shown, architecture 700 utilizes nine computational modules, which are equal to the square of the number of shares S (e.g., S = three shares). In some cases, the number of computations is increased by S. 2 Times (e.g., S) 2 =9) can be expensive. However, different computing modules 702, 704, 706, 708, and 710 can benefit from diversity to provide enhanced security. In some respects, instead of such Figure 7 The nine different computing modules 702, 704, 706, 708, and 710 shown can be used in a serial manner with different inputs, allowing a single computing module (e.g., computing module 702) to reuse S along with different inputs. 2 Next. In some respects, using a single computing module to execute S serially, relative to different computing modules. 2 Individual calculations can reduce the area used. However, in some cases, using a single calculation module to perform the calculation may not yield the same benefits as relative to... Figure 6A The described structures are diverse.
[0090] Figure 8AThis is a block diagram 800 illustrating an example structure for a bilinear operation performed on a combination of public and secret data. As illustrated, the diagram includes security components (e.g., secure information storage device 570, trusted execution environment 580, security component 590) within a secure environment 802. In some specific implementations, the secure environment 802 may include a computing module 806, a secure information asset storage device 812 (e.g., ... Figure 1 102. Secure information asset storage device Figure 5 (e.g., secure information storage device 570), copy / mask / refresh module 814) Figure 1 The copy / mask / refresh module 104) and the copy / mask module 816. As illustrated, the public environment 804 may include a storage device 808 (e.g., Figure 2 Storage device 210, Figure 10 System memory 1015, storage device 1030, Figure 5 (Memory 514). In some examples, block diagram 800 may include randomization module 810. As illustrated, randomization module 810 may be included in secure environment 802, public environment 804, and / or any combination thereof. Figure 8A As illustrated, the copy / mask module 816 can obtain the common data variable A from the storage device 808.
[0091] In some cases, the copy / masking module 816 may obtain random and / or pseudo-random numbers from the randomization module 810 for use in performing copying and / or masking of the common variable A. For illustrative purposes, variable A may be represented as an i-bit wide vector Ai, where i is an integer. In some cases, the copy / masking module 816 may output individual bits of a masked version of vector Ai to the computation module 806.
[0092] In some cases, if a different computation module that performs the same computation as computation module 806 has the same structure as computation module 806, an attacker may be able to decipher information about the secret key H based on variable reuse, self-similarity of operations, lack of diffusion, and / or any combination thereof.
[0093] As illustrated, the copy / mask / refresh module 814 can obtain the secret key H from the secure information asset storage device 812. In some cases, the copy / mask / refresh module 814 can be similar to... Figure 1 The copy / mask / refresh module 814 performs similar functions. As illustrated, the copy / mask / refresh module 814 can output the individual bits of a masked version of the secret key H to the calculation module 806. For illustrative purposes, the secret key H can be represented as a j-bit wide vector H. j , where j is an integer.
[0094] As illustrated, 806 includes multiple unit multiplication elements 818, which can multiply an i-bit wide vector A i The single bit is multiplied by the corresponding bit of the j-bit-wide vector Hj. In some cases, each of the multiple unit multiplication elements 818 can output the product to a chain of XOR gates 820. As illustrated, the structure of the multiple unit multiplication elements 818 and XOR gates 820 can be highly structured. For example, the multiple unit multiplication elements 818 and XOR gates 820 can be arranged in a repeating pattern, with uniform spacing between the elements and / or wiring traces. In some specific implementations, adjacent multiplication elements and adjacent XOR gates can be assigned to the j-bit-wide vector Hj in a predetermined order. j A vector A with width of 1 and 1 bit i The bits. For example, as illustrated, the leftmost multiplication element in a plurality of unit multiplication elements 818 can operate on bits H0, A0, the next adjacent multiplication element in a plurality of unit multiplication elements 818 can operate on bits H1, A1, and so on.
[0095] Figure 8B This is an example relative to Figure 8A Block diagram 800 has an alternative example structure for bilinear operations performed on a combination of public and secret data to enhance security, as shown in block diagram 850. Figure 8B In exemplary examples, the public environment 804, storage device 808, randomization module 810, secure information asset storage device 812, and copy / mask / refresh module 814 may be similar to Figure 8A Components with the same number and performing similar functions. Figure 8B In the example, Figure 8A The copy / masking module 816 and the computation module 806 have been replaced by the alternative computation module 856 and the copy / masking / randomization module 858.
[0096] In some specific implementations, the copy / mask / randomization module 858 can be executed. Figure 8A The copy / masking module 816 provides the copy / masking function. In some cases, the copy / masking / randomization module 858 can add extra bits to the public variable A. In some cases, the dummy bits can be randomly generated (e.g., by a pseudo-random number transmitter (PRNG)) and / or obtained from a computing device (e.g., Figure 5 Export the internal state of the computing device (500).
[0097] As illustrated, the alternative computation module 856 may include multiple unit multiplication elements 818, and additional unit multiplication elements 819, 860. In the illustrated example, the additional unit multiplication element 860 may use a dummy bit D generated by the copy / mask / randomization module 858. kTo replace the bits from the public variable A and the secret key H, where k is an integer. In an exemplary example, the leftmost additional unit multiplication element 860 in alternative computation module 856 can generate a dummy product. In some examples, this can be achieved by replacing D0 with... A dummy product is generated by multiplying the two dummy bits of D1. In some implementations, a dummy product can be generated by multiplying the dummy bit D0 with a bit of the common variable A3. In some aspects, a dummy product can be generated by multiplying the dummy bit D0 with a variable derived from the common variable A and / or any other common variable available in alternative calculation module 856. As used herein, the output of the additional unit multiplication element 860 based on the dummy bit input can be referred to as a dummy product. In some aspects, the additional unit multiplication element 860, in the illustrated example, generates a product using actual bits of the common variable A as input bits. As illustrated, in some cases, the dummy product can be combined with the product generated by the additional unit multiplication element 819 via XOR gate 862. In some cases, the output of XOR gate 862 can then be provided to one of XOR gates 820 for combination with the outputs of multiple unit multiplication elements 818. As illustrated, in some cases, by incorporating an even number of dummy products, the output of a long XOR operation performed by XOR gate 820 may remain unchanged. However, using dummy products within alternative computation module 856 may result in changes relative to... Figure 8A The operation of the alternative computing module 856 of the computing module 806 is a change in power signature and / or timing.
[0098] In some cases, alternative calculation module 856 can be combined as relative to the above. Figure 6A The described structures are diverse. For example, the arrangement of individual multiplication elements 818 and / or individual XOR gates 820 may differ from... Figure 8A The computation module 806. As used herein, the term "computation element" refers to the individual logic gates included in the computation module. Exemplary examples of computation elements include, but are not limited to, unity multiplication elements, XOR gates, Boolean logic gates, arithmetic computation modules, and / or any combination thereof.
[0099] In some examples, the order of inputs and / or outputs of adjacent multiplicative elements 818, additional unit multiplicative elements 819, and / or additional unit multiplicative elements 860 can be randomized. In one exemplary example, each of the wires input from the copy / mask / refresh module 814 and the copy / mask / randomization module 858 to the alternative computation module 856 can be defined as an input wire. In an exemplary example, the outputs of multiplicative elements 818, 819, and / or 860 can be defined as product wires. In some specific implementations, a randomly generated order (e.g., based on a PRNG seed) can be used to impose a predetermined and strictly fixed order on the input wires and / or product wires. Figure 8B As illustrated, the order in which the product of bits H0, A0 and bits H1, A1 is calculated is already relative to... Figure 8A The order illustrated in computation module 806 has been swapped. In some cases, the order of the product wires input to XOR gate 820 can be similarly randomized, as illustrated in trace 821, thereby swapping the order of the inputs to the third and fourth XOR gates provided to XOR gate 820. In some cases, randomizing the order of the input wires and / or product wires within computation module 856 may result in a change relative to the order of the product wires. Figure 8A The operation of the alternative computing module 856 of the computing module 806 is a change in power signature and / or timing.
[0100] In some examples (not shown), the product pairs each sum of products in the sequence (or a selected subset of the sums of products, such as a) i h j +a k h l ) can optionally be accessed via a dedicated shared random r jl Re-decode as shown in equation (3) below:
[0101] a i h j +a k h l = (a i +a k )r jl +a i (h j +r jl ) + a k (h l +r jl (3)
[0102] In some cases, the number of distinct products that have not been transformed can be reduced by implementing re-decoding as shown in equation (3). As illustrated in equation (3), this includes dedicated shared random r jl The addition of operations does not change equation a. i h j+a k h l The result is the sum of the products on the left side. In an illustrative example, the sum of 100 products that would result without the transformation of equation (3) can be reduced to approximately five distinct products a without the transformation. h j In some cases, dedicated shared random r jl The value can be generated by the copy / mask / randomization module 858. In some respects, the calculation of the merge equation (3) may lead to a relative... Figure 8A The operation of the alternative computing module 856 of the computing module 806 is a change in power signature and / or timing.
[0103] As described above, the computing device 500 and related technologies described herein allow the system to support cryptographic components (e.g., Figure 1 Cryptographic component 106 Figure 5 The security component 590 provides enhanced security. In some cases, the systems and techniques described herein can be used to enhance the security of components performing linear and / or bilinear computations. For example, the systems and techniques can enhance the security of cryptographic components performing bilinear operations on public data and / or shares of public data as first inputs and on security keys and / or shares of security keys as second inputs. In some cases, the systems and techniques can be used to provide structural diversity in cryptographic components performing the same function. For example, diversity may include the use of different logic gates, transistors, wiring, and / or any combination thereof. In some cases, structural diversity may result in the same operation having different power signatures and / or timing between receiving inputs and generating outputs.
[0104] In some cases, systems and techniques may include diversification based on providing dummy variables within the logic of the computation module, which alter the power signature and / or timing without affecting the generated output. For example, if the computation module performs a linear multiplication of a public and private key, the dummy product generated by multiplying by the dummy variable d at two different locations within the computation module can alter the power signature and / or timing of the operation performed by the computation module.
[0105] In some cases, systems and techniques may include diversification based on locally derived random masking. In some cases, using locally derived random masking can significantly reduce the number of times a particular product of public variables and secret keys is not transformed (e.g., reducing variable reuse).
[0106] In some cases, the system and techniques may include diversification based on an even number of dummy products. In some cases, the system and techniques may re-decode each sum of products in a sequence of product pairs via dedicated shared randomness.
[0107] Figure 9 This is a flowchart illustrating an example of a process 900 for securely performing cryptographic operations. Process 900 and / or other processes described herein may be performed by a computing device (or apparatus) or a component of a computing device (e.g., chipset, codec, etc.). A computing device may be an extended reality (XR) device (e.g., a virtual reality (VR) device or an augmented reality (AR) device), a mobile device (e.g., a mobile phone), a network-connected wearable device such as a watch, a vehicle or a component or system of a vehicle, or other types of computing devices. In one example, process 900 and / or other processes described herein may be performed by... Figure 5 The computational device 500 performs the operation. In another example, one or more processes may be performed by... Figure 10 The computing system 1000 shown is executed. For example, it has... Figure 10 The computing device of the computing system 1000 shown may include components of the computing device 500 and can realize Figure 9 The operation of process 900 and / or other processes described herein. The operation of process 900 may be implemented in one or more processors (e.g., Figure 10 Software components executed and running on the processor 1010, processors such as DSPs, GPUs, NPUs, etc., or other processors. Furthermore, the transmission and reception of signals by the computing device in process 900 may be achieved, for example, through one or more antennas, one or more transceivers (e.g., wireless transceivers) and / or other communication components of the computing device (e.g., [missing information]). Figure 10 It is implemented using the communication interface 1040.
[0108] At box 902, the computing device (or a component thereof) can be accessed via a first computing module (e.g., Figure 1 Cryptographic component 106 Figure 2 Calculation module 208 Figure 5 The processor 510, secure information storage device 570, trusted execution environment 580, and security component 590 obtain public inputs (e.g., public key) and / or secure information asset inputs (e.g., secret key, secret key share, derived key). In some cases, each of the multiple public bits has a fixed value.
[0109] At box 904, the computing device (or a component thereof) may perform Boolean operations (e.g., XOR, unit multiplication) on common inputs and security information assets to generate an output. In some examples, the Boolean operation includes combining multiple common bits of common data with multiple bits of security information assets in a bilinear computation.
[0110] At box 906, the computing device (or its components) can obtain public input and security information asset input through the second computing module.
[0111] At box 908, the computing device (or a component thereof) can perform Boolean operations on common inputs and security information assets to generate outputs. In some respects, the first computing module has a first configuration, and the second computing module has a second configuration different from the first configuration.
[0112] In some examples, the first configuration includes a first internal structure of the first computing module. In some cases, the second configuration includes a second internal structure of the second computing module. In some cases, the first computing module includes a first plurality of logic gates (e.g., Figure 8A and Figure 8B The first plurality of logic gates includes a unit multiplication element 818 and an XOR gate 820, and the second computation module includes a second plurality of logic gates. In some aspects, the first plurality of logic gates includes at least one logic gate that is different from any of the logic gates in the second plurality of logic gates (e.g., Figure 8B Additional unit multiplication element 860, XOR gate 862).
[0113] In some specific implementations, the first computing module implements Boolean operations through a first set of logic gates in the first configuration, and the second computing module implements Boolean operations through a second set of logic gates in a second configuration that is different from the first configuration.
[0114] In some examples, public data and security information assets obtained by the first and second computing modules are masked (e.g., by...). Figure 1 (Refresh module 104).
[0115] In some cases, the second computation module is configured to generate an even number of dummy products during the execution of Boolean operations, which are then eliminated in the output generated by the second computation module.
[0116] In some respects, the first computation module is configured to generate multiple products between bits of public data and bits of security information assets, and to generate multiple sums of products between product pairs included in the multiple products. In some cases, the multiple sums of products can be re-decoded using dedicated shared random variables.
[0117] In some implementations, the first computation module includes multiple computational elements configured to generate output based on a predetermined order of operations. In some examples, the predetermined order of operations includes one or more of the following: an order in which bits of public data are computed to multiply bits of security information assets; or an order in which multiple products are added. In some cases, a pseudo-random seed is extended to a list specifying the predetermined order of operations. In some implementations, the multiple computational elements include unit multiplication elements. In some aspects, the unit multiplication element includes one or more NAND gates or AND gates.
[0118] In some examples, the processes described herein (e.g., process 900 and / or any other processes described herein) may be computed by a computing device or apparatus (e.g., Figure 5 The computing device 500) performs the operation. In another example, it can be executed by a device with... Figure 10 The computing device of the computing system 1000 shown executes process 900.
[0119] Figure 10 This is a diagram illustrating an example of a computing system used to implement certain aspects of this technology. Specifically, Figure 10 An example of a computing system 1000 is illustrated. This computing system can be any computing device, such as constituting an internal computing system, a remote computing system, a camera, or any component thereof, wherein the components of the system communicate with each other using connection 1005. Connection 1005 can be a physical connection using a bus, or a direct connection to processor 1010, such as in a chipset architecture. Connection 1005 can also be a virtual connection, a networking connection, or a logical connection.
[0120] In some embodiments, the computing system 1000 is a distributed system, wherein the functions described herein may be distributed across a data center, multiple data centers, a peer-to-peer network, etc. In some embodiments, one or more system components described represent a plurality of such components that each perform some or all of the functions described for which the component is used. In some embodiments, the components may be physical devices or virtual devices.
[0121] The example computing system 1000 includes at least one processing unit (CPU or processor) 1010 and a connection 1005 that communicatively couples various system components, including system memories 1015 such as read-only memory (ROM) 1020 and random access memory (RAM) 1025, to the processor 1010. The computing system 1000 may include a cache 1012 of high-speed memory that is directly connected to, closely proximate to, or integrated into the processor 1010. The example computing system 1000 also includes one or more cryptographic function blocks 1011 connected to the processor 1010. For example, one or more cryptographic function blocks 1011 may include cryptographic blocks for performing, but not limited to, NTT computation, matrix-vector multiplication (A*y), r and rG multiplication (e.g., elliptic curve point multiplication), events (e.g., for Elliptic Curve Digital Signature Algorithm (ECDSA)), secure hash algorithms (e.g., SHA-256, SHA-3), McEliece cryptography, bit-flipped key encapsulation (BIKE), Hamming quasi-cyclic (HQC) encryption, hash-based message authentication codes (e.g., HMAC-512), and RNG seeding. In some cases, multiple cryptographic function blocks 1011 may be directly or indirectly connected to each other. In some specific implementations, one or more cryptographic function blocks 1011 may include one or more cooperative processing units.
[0122] Processor 1010 may include any general-purpose processor and hardware or software services, such as services 1032, 1034, and 1036 stored in storage device 1030, which are configured to control processor 1010 and dedicated processors (e.g., arithmetic processors, cryptographic processors, and / or any combination thereof) in which software instructions are incorporated into the actual processor design. Processor 1010 may be a substantially completely independent computing system containing multiple cores or processors, buses, memory controllers, caches, etc. Multi-core processors may include different computing units of variable size and characteristics. In some cases, multi-core processors may be symmetric or asymmetric. In some examples, one or more cryptographic function blocks 1011 may be symmetric or asymmetric.
[0123] To enable user interaction, the computing system 1000 includes an input device 1045 that can represent any number of input mechanisms, such as a microphone for voice, a touch-sensitive screen for gesture or graphic input, a keyboard, a mouse, motion input, and voice input. The computing system 1000 may also include an output device 1035 that can be one or more of a plurality of output mechanisms. In some cases, a multimodal system allows the user to provide multiple types of input / output to communicate with the computing system 1000.
[0124] The computing system 1000 may include a communication interface 1040, which typically controls and manages user input and system output. The communication interface 1040 may perform or facilitate the reception and / or transmission of wired or wireless communications using wired and / or wireless transceivers, including via audio jacks / plugs, microphone jacks / plugs, Universal Serial Bus (USB) ports / plugs, Apple™ Lightning™ ports / plugs, Ethernet ports / plugs, fiber optic ports / plugs, dedicated wired ports / plugs, 3G, 4G, 5G and / or other cellular data network wireless signal transmission, Bluetooth™ wireless signal transmission, Bluetooth™ Low Energy (BLE) wireless signal transmission, IBEACON™ wireless signal transmission, Radio Frequency Identification (RFID) wireless signal transmission, Near Field Communication (NFC) wireless signal transmission, Dedicated Short Range Communication (DSRC) wireless signal transmission, and 802.11. Communication interfaces 1040 may include one or more Global Navigation Satellite System (GNSS) receivers or transceivers for determining the location of computing system 1000 based on signals received from one or more satellites associated with one or more GNSS systems. GNSS systems include, but are not limited to, the U.S. Global Positioning System (GPS), Russia's Global Navigation Satellite System (GLONASS), China's BeiDou Navigation Satellite System (BDS), and Europe's Galileo GNSS. There are no limitations on operation on any particular hardware arrangement, and therefore the basic features here can be easily replaced to obtain improved hardware or firmware arrangements as they are developed.
[0125] Storage device 1030 may be a non-volatile and / or non-transitory and / or computer-readable storage device, and may be a hard disk or other type of computer-readable medium capable of storing data accessible by a computer, such as magnetic tape, flash memory cards, solid-state storage devices, digital versatile discs, cartridges, floppy disks, hard disks, magnetic tapes, magnetic stripes, any other magnetic storage media, flash memory, memristor memory, any other solid-state storage, CD-ROM, rewritable CD, DVD, Blu-ray Disc, holographic disc, another optical medium, secure digital (SD) cards, microSD cards, Memory Stick. ® Cards, smart card chips, EMV chips, Subscriber Identity Module (SIM) cards, mini / micro / nano / micro SIM cards, another integrated circuit (IC) chip / card, random access memory (RAM), static RAM (SRAM), dynamic RAM (DRAM), read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), flash EPROM, cache memory (e.g., layer 1 (L1) cache, layer 2 (L2) cache, layer 3 (L3) cache, layer 4 (L4) cache, layer 5 (L5) cache, other (L#) cache), resistive random access memory (RRAM / ReRAM), phase change memory (PCM), spin-transfer torque RAM (STT-RAM), another memory chip or cassette and / or combinations thereof.
[0126] Storage device 1030 may include software services, servers, services, etc., which enable the system to perform functions when the code defining such software is executed by processor 1010. In some embodiments, hardware services performing specific functions may include software components for performing functions stored in a computer-readable medium connected to necessary hardware components such as processor 1010, connection 1005, output device 1035, etc. The term "computer-readable medium" includes, but is not limited to, portable or non-portable storage devices, optical storage devices, and various other media capable of storing, containing, or carrying instructions and / or data. Computer-readable media may include non-transitory media in which data can be stored and which does not include carrier waves and / or transient electronic signals propagated wirelessly or via a wired connection. Examples of non-transitory media may include, but are not limited to, disks or magnetic tapes, optical storage media such as optical discs (CDs) or digital universal discs (DVDs), flash memory, non-volatile memory express (NVMe) memory, write-once-read-many (WORM) memory, electronically programmable (eFuse) one-time (OTP) memory, memory, I-fuse OTP memory, gate oxide breakdown antifuse memory, Intel Optane memory, memory, or memory devices. Computer-readable media may store code and / or machine-executable instructions thereon, which may represent procedures, functions, subroutines, programs, routines, subroutines, modules, software packages, classes, or any combination of instructions, data structures, or program statements. A code segment may be coupled to another code segment or hardware circuitry by passing and / or receiving information, data, arguments, parameters, or memory contents. Information, arguments, parameters, data, etc., may be passed, forwarded, or transmitted via any suitable means, including memory sharing, message passing, token passing, network transmission, etc.
[0127] Specific details have been provided in the foregoing description to offer a thorough understanding of the various embodiments and examples presented herein, but those skilled in the art will recognize that this application is not limited thereto. Therefore, although exemplary embodiments of this application have been described in detail herein, it is to be understood that the inventive concept can be embodied and adopted in a variety of other ways, and the appended claims are intended to be construed as including such variations, unless limited by prior art. Various features and aspects of the applications described above may be used individually or in combination. Furthermore, without departing from the broader scope of this specification, the embodiments can be used in any number of environments and applications beyond those described herein. Therefore, the specification and drawings should be considered illustrative rather than restrictive. For illustrative purposes, the methods are described in a particular order. It should be understood that in alternative embodiments, the methods may be performed in a different order than described.
[0128] For clarity, in some instances, this technology may be presented as comprising various functional blocks, which include devices, device components, steps, or routines embodied in a method, either in software or a combination of hardware and software. Additional components may be used in addition to those shown in the figures and / or described herein. For example, circuits, systems, networks, processes, and other components may be shown as components in block diagram form to avoid obscuring these embodiments with unnecessary detail. In other cases, well-known circuits, processes, algorithms, structures, and techniques may be shown without necessary detail to avoid obscuring the embodiments.
[0129] Furthermore, those skilled in the art will understand that the various exemplary logic blocks, modules, circuits, and algorithm steps described in connection with the aspects disclosed herein can be implemented as electronic hardware, computer software, or a combination of both. To clearly illustrate this interchangeability between hardware and software, various exemplary components, blocks, modules, circuits, and steps have been described above in general terms of their functionality. Whether such functionality is implemented as hardware or software depends on the specific application and the design constraints imposed on the overall system. Those skilled in the art may implement the described functionality in different ways for each specific application, but such specific implementation decisions should not be construed as departing from the scope of this disclosure.
[0130] Individual implementations may be described above as processes or methods depicted as flowcharts, flow diagrams, data flow diagrams, structure diagrams, or block diagrams. Although flowcharts may describe operations as sequential processes, many operations within an operation may be executed in parallel or concurrently. Furthermore, the order of operations may be rearranged. A process terminates when its operations are completed, but a process may have additional steps not included in the accompanying drawings. A process may correspond to a method, function, procedure, subroutine, subroutine, etc. When a process corresponds to a function, the termination of the process may correspond to the function returning to the calling function or the main function.
[0131] The processes and methods described in the examples above can be implemented using stored computer-executable instructions or computer-executable instructions otherwise available from a computer-readable medium. Such instructions may include, for example, instructions and data that configure, or otherwise configure, a general-purpose computer, special-purpose computer, or processing device to perform a function or group of functions. The portion may be accessible via a network of the computer resources used. The computer-executable instructions may be, for example, binary files, intermediate format instructions such as assembly language, firmware, or source code. Examples of computer-readable media that can be used to store the instructions, the information used, and / or information created during the methods according to the described examples include disks or optical discs, flash memory, USB devices with non-volatile memory, networked storage devices, etc.
[0132] In some implementations, computer-readable storage devices, media, and memories may include cables or wireless signals containing bit streams, etc. However, when referred to, non-transitory computer-readable storage media explicitly excludes media such as power consumption, carrier signals, electromagnetic waves, and the signals themselves.
[0133] Those skilled in the art will understand that information and signals can be represented using any of a variety of different techniques and arts. For example, data, instructions, commands, information, signals, bits, symbols, and chips that may be referred to throughout the above description may, in some cases, be represented by voltage, current, electromagnetic waves, magnetic fields or magnetic particles, light fields or light particles, or any combination thereof, depending in part on the specific application, in part on the desired design, in part on the corresponding technology, etc.
[0134] The various exemplary logic blocks, modules, and circuits described in conjunction with the aspects disclosed herein can be implemented or executed using hardware, software, firmware, middleware, microcode, hardware description languages, or any combination thereof, and can take any form factor of various form factors. When implemented in software, firmware, middleware, or microcode, program code or code segments (e.g., computer program products) for performing necessary tasks can be stored in a computer-readable or machine-readable medium. A processor can perform the necessary tasks. Examples of form factors include: laptop computers, smartphones, mobile phones, tablet devices, or other small form factor personal computers, personal digital assistants, rack-mounted devices, self-contained devices, etc. The functionality described herein can also be embodied in peripheral devices or interlocking cards. By further example, such functionality can also be implemented on circuit boards in different chips or different processes running on a single device.
[0135] Instructions, media for transmitting such instructions, computing resources for executing them, and other structures for supporting such computing resources are example components for providing the functionality described in this disclosure.
[0136] The techniques described herein can also be implemented in electronic hardware, computer software, firmware, or any combination thereof. Such techniques can be implemented in any of a variety of devices, such as general-purpose computers, wireless communication devices (mobile phones), or integrated circuit devices with multiple uses, including applications in wireless communication devices (mobile phones) and other devices. Any feature described as a module or component can be implemented together in an integrated logic device or separately as discrete but interoperable logic devices. If implemented in software, the techniques can be implemented at least in part by a computer-readable data storage medium comprising program code including instructions that, when executed, perform one or more of the methods, algorithms, and / or operations described above. The computer-readable data storage medium can form part of a computer program product, which may include packaging material. The computer-readable medium may include memory or data storage media, such as random access memory (RAM) (such as synchronous dynamic random access memory (SDRAM)), read-only memory (ROM), non-volatile random access memory (NVRAM), electrically erasable programmable read-only memory (EEPROM), flash memory, magnetic or optical data storage media, etc. Additionally or alternatively, the technology may be implemented at least in part by a computer-readable communication medium that carries or conveys program code in the form of instructions or data structures that can be accessed, read and / or executed by a computer, such as propagated signals or waves.
[0137] The program code can be executed by a processor, which may include one or more processors, such as one or more digital signal processors (DSPs), general-purpose microprocessors, application-specific integrated circuits (ASICs), field-programmable arrays (FPGAs), or other equivalent integrated or discrete logic circuits. Such processors can be configured to perform any of the techniques described in this disclosure. A general-purpose processor may be a microprocessor; however, in alternatives, the processor may be any conventional processor, controller, microcontroller, or state machine. The processor may also be implemented as a combination of computing devices, such as a combination of a DSP and a microprocessor, multiple microprocessors, one or more microprocessors combined with a DSP core, or any other such configuration. Therefore, as used herein, the term "processor" may refer to any of the foregoing structures, any combination of the foregoing structures, or any other structure or means suitable for implementing the techniques described herein.
[0138] Those skilled in the art will understand that the less than ("<") and greater than (">") symbols or terms used herein may be replaced with less than or equal to ("≤") and greater than or equal to ("≥") symbols without departing from the scope of this specification.
[0139] When a component is described as being “configured” to perform certain operations, such configuration can be achieved, for example, by designing electronic circuits or other hardware to perform the operations, by programming programmable electronic circuits (e.g., microprocessors or other suitable electronic circuits) to perform the operations, or any combination thereof.
[0140] The phrase “coupled to” or “communicatively coupled to” means that any component is physically connected directly or indirectly to another component, and / or that any component communicates directly or indirectly with another component (e.g., via a wired or wireless connection and / or other suitable communication interface).
[0141] Claim language or other languages that state "at least one of" and / or "one or more of" in a set indicate that one member of the set or multiple members of the set (in any combination) satisfy the claim. For example, claim language stating "at least one of A and B" or "at least one of A or B" means A, B, or A and B. In another example, claim language stating "at least one of A, B, and C" or "at least one of A, B, or C" means A, B, C, or A and B, or A and C, or B and C, A and B and C, or any repetition is information or data (e.g., A and A, B and B, C and C, A and A and B, etc.), or any other ordering, repetition, or combination of A, B, and C. The language "at least one of the set" and / or "one or more of the set" does not limit the set to the items listed in the set. For example, the language of a claim stating "at least one of A and B" or "at least one of A or B" may refer to A, B, or A and B, and may additionally include items not listed in the set of A and B. The phrases "at least one" and "one or more" are used interchangeably herein.
[0142] Claim language or other languages that state "at least one processor, the at least one processor being configured to," "at least one processor being configured to," "one or more processors, the one or more processors being configured to," etc., indicate that one or more processors (in any combination) are capable of performing associated operations. For example, claim language that states "at least one processor, the at least one processor being configured to: X, Y, and Z" means that a single processor can be used to perform operations X, Y, and Z; or that multiple processors are each assigned a specific subset of tasks of operations X, Y, and Z, such that the multiple processors together perform X, Y, and Z; or that a group of multiple processors work together to perform operations X, Y, and Z. In another example, claim language that states "at least one processor, the at least one processor being configured to: X, Y, and Z" may mean that any single processor can perform only a subset of operations X, Y, and Z.
[0143] When referring to one or more elements that perform functions (e.g., steps of a method), one element may perform all functions, or more than one element may jointly perform these functions. When more than one element jointly performs these functions, each function does not need to be performed by every single element (e.g., different functions may be performed by different elements), and / or each function does not need to be performed by only one element as a whole (e.g., different elements may perform different sub-functions of a function). Similarly, when referring to one or more elements configured to cause another element (e.g., a device) to perform functions, one element may be configured to cause another element to perform all functions, or more than one element may be jointly configured to cause another element to perform these functions.
[0144] When referring to an entity that performs or is configured to perform functions (e.g., steps of a method) (e.g., any entity or device described herein), the entity may be configured to cause one or more elements (individually or collectively) to perform those functions. One or more components of the entity may include at least one memory, at least one processor, at least one communication interface, another component configured to perform one or more of those functions, and / or any combination thereof. When referring to an entity that performs functions, the entity may be configured to cause one component to perform all functions, or to cause more than one component to perform those functions collectively. When the entity is configured to cause more than one component to perform those functions collectively, each function does not need to be performed by every single component (e.g., different functions may be performed by different components), and / or each function does not need to be performed by only one component as a whole (e.g., different components may perform different sub-functions of a function).
[0145] The exemplary aspects of this disclosure include:
[0146] Aspect 1. An apparatus for securely performing cryptographic operations, the apparatus comprising: a memory; and a processor coupled to the memory, the processor comprising: a first computing module configured to: acquire public data and security information assets; and perform Boolean operations on the public data and the security information assets to generate an output; and a second computing module configured to: acquire the public data and the security information assets; and perform the Boolean operations on the public data and the security information assets to generate the output, wherein the first computing module has a first configuration and the second computing module has a second configuration different from the first configuration.
[0147] Aspect 2. The apparatus according to aspect 1, wherein the Boolean operation includes combining a plurality of common bits of the common data with a plurality of bits of the security information asset in a bilinear computation.
[0148] Aspect 3. The apparatus according to any one of aspects 1 to 2, wherein each of the plurality of common bits has a fixed value.
[0149] Aspect 4. The apparatus according to any one of Aspects 1 to 3, wherein the first configuration includes a first internal structure of the first computing module, and wherein the second configuration includes a second internal structure of the second computing module.
[0150] Aspect 5. The apparatus according to any one of Aspects 1 to 4, wherein the first computing module implements the Boolean operation through a first plurality of logic gates in a first configuration, and the second computing module implements the Boolean operation through a second plurality of logic gates in a second configuration different from the first configuration.
[0151] Aspect 6. The apparatus according to any one of Aspects 1 to 5, wherein the first computing module includes a first plurality of logic gates, and the second computing module includes a second plurality of logic gates, wherein the first plurality of logic gates includes at least one logic gate that is different from any of the second plurality of logic gates.
[0152] Aspect 7. The apparatus according to aspect 6, wherein the at least one logic gate, which is different from any of the second plurality of logic gates, performs the same function as one or more different logic gates included in the second plurality of logic gates.
[0153] Aspect 8. The apparatus according to any one of Aspects 1 to 7, wherein the public data and the security information assets obtained by the first computing module and the second computing module are masked.
[0154] Aspect 9. The apparatus according to any one of Aspects 1 to 8, wherein the second computing module is configured to generate an even number of dummy products during the execution of the Boolean operation, the even number of dummy products being eliminated in the output generated by the second computing module.
[0155] Aspect 10. The apparatus according to aspect 9, wherein the input data for generating the even number of dummy products includes one or more of bits of common data or bits derived from bits of common data.
[0156] Aspect 11. The apparatus according to any one of Aspects 1 to 10, wherein the first computing module is configured to generate a plurality of products between bits of the public data and bits of the security information asset and to generate a plurality of sums of products between product pairs included in the plurality of products, wherein the plurality of sums of products can be re-decoded by a dedicated shared random variable.
[0157] Aspect 12. The apparatus according to any one of Aspects 1 to 11, wherein the first computing module comprises a plurality of computing elements configured to generate the output based on a predetermined order of operations.
[0158] Aspect 13. The apparatus according to aspect 12, wherein the predetermined sequence of operation includes one or more of an order of calculating a plurality of products of bits of the public data and bits of the security information asset or an order of adding the plurality of products.
[0159] Aspect 14. The apparatus according to aspect 12, wherein the pseudo-random seed is expanded into a list of the predetermined order of the specified operations.
[0160] Aspect 15. The apparatus according to aspect 12, wherein the plurality of computing elements includes a unit multiplication element, wherein the unit multiplication element includes one or more of a NAND gate or an AND gate.
[0161] Aspect 16. The apparatus according to aspect 12, wherein the plurality of computing elements includes an XOR gate.
[0162] Aspect 17. The apparatus according to any one of Aspects 1 to 16, the apparatus further comprising an additional processor coupled to the memory, wherein the additional processor includes a third computing module configured to: obtain the public data and the security information asset; and perform the Boolean operation on the public data and the security information asset to generate the output, wherein the third computing module has a third configuration different from the first configuration.
[0163] Aspect 18. A method for securely performing cryptographic operations, the method comprising: obtaining public data and security information assets; performing a Boolean operation on the public data and the security information assets by a first computing module to generate an output; obtaining the public data and the security information assets; and performing the Boolean operation on the public data and the security information assets by a second computing module to generate the output, wherein the first computing module has a first configuration and the second computing module has a second configuration different from the first configuration.
[0164] Aspect 19. The method according to aspect 18, wherein the Boolean operation includes combining a plurality of common bits of the common data with a plurality of bits of the security information asset in a bilinear computation.
[0165] Aspect 20. The method according to any one of aspects 18 to 19, wherein each of the plurality of common bits has a fixed value.
[0166] Aspect 21. The method according to any one of Aspects 18 to 20, wherein the first configuration includes a first internal structure of the first computing module, and wherein the second configuration includes a second internal structure of the second computing module.
[0167] Aspect 22. The method according to any one of Aspects 18 to 21, wherein the first computing module implements the Boolean operation through a first plurality of logic gates in a first configuration, and the second computing module implements the Boolean operation through a second plurality of logic gates in a second configuration different from the first configuration.
[0168] Aspect 23. The method according to any one of Aspects 18 to 22, wherein the first computing module includes a first plurality of logic gates, and the second computing module includes a second plurality of logic gates, wherein the first plurality of logic gates includes at least one logic gate that is different from any of the second plurality of logic gates.
[0169] Aspect 24. The method according to aspect 23, wherein the at least one logic gate, which is different from any of the second plurality of logic gates, performs the same function as one or more different logic gates included in the second plurality of logic gates.
[0170] Aspect 25. The method according to any one of Aspects 18 to 24, wherein the public data and the security information assets obtained by the first computing module and the second computing module are masked.
[0171] Aspect 26. The method according to any one of Aspects 18 to 25, wherein the second computation module is configured to generate an even number of dummy products during the execution of the Boolean operation, the even number of dummy products being eliminated in the output generated by the second computation module.
[0172] Aspect 27. The method according to aspect 26, wherein the input data for generating the even number of dummy products includes one or more of bits of common data or bits derived from bits of common data.
[0173] Aspect 28. The method according to any one of Aspects 18 to 27, wherein the first computing module is configured to generate a plurality of products between bits of the public data and bits of the security information asset and to generate a plurality of sums of products between product pairs included in the plurality of products, wherein the plurality of sums of products can be re-decoded by a dedicated shared random variable.
[0174] Aspect 29. The method according to any one of Aspects 18 to 28, wherein the first computing module comprises a plurality of computing elements configured to generate the output based on a predetermined order of operations.
[0175] Aspect 30. The method according to aspect 29, wherein the predetermined order of operations includes one or more of an order of calculating a plurality of products of bits of the public data and bits of the security information asset or an order of adding the plurality of products.
[0176] Aspect 31. The method according to aspect 29, wherein the pseudo-random seed is expanded into a list of the predetermined order of the specified operations.
[0177] Aspect 32. The method according to aspect 29, wherein the plurality of computing elements includes a unit multiplication element, wherein the unit multiplication element includes one or more of a NAND gate or an AND gate.
[0178] Aspect 33. The method according to aspect 29, wherein the plurality of computing elements includes an XOR gate.
[0179] Aspect 34. A non-transitory computer-readable storage medium having instructions stored thereon, the instructions causing the one or more processors, when executed, to perform any of the operations described in aspects 1 to 33.
[0180] Aspect 35. An apparatus comprising components for performing the method according to any one of aspects 1 to 33.
Claims
1. An apparatus for securely performing cryptographic operations, the apparatus comprising: Memory; as well as A processor, coupled to the memory, comprising: A first computing module, configured as follows: Acquisition of public data and security information assets; and Perform Boolean operations on the public data and the security information assets to generate output; and The second computing module is configured as follows: Obtain the public data and the security information assets; and The Boolean operation is performed on the public data and the security information assets to generate the output, wherein the first computing module has a first configuration and the second computing module has a second configuration different from the first configuration.
2. The apparatus of claim 1, wherein the Boolean operation comprises combining a plurality of common bits of the common data with a plurality of bits of the security information asset in a bilinear computation.
3. The apparatus of claim 2, wherein each of the plurality of common bits has a fixed value.
4. The apparatus of claim 3, wherein the first configuration includes a first internal structure of the first computing module, and wherein the second configuration includes a second internal structure of the second computing module.
5. The apparatus of claim 1, wherein the first computing module implements the Boolean operation through a first plurality of logic gates in a first configuration, and the second computing module implements the Boolean operation through a second plurality of logic gates in a second configuration different from the first configuration.
6. The apparatus of claim 1, wherein the first computing module includes a first plurality of logic gates, and the second computing module includes a second plurality of logic gates, wherein the first plurality of logic gates includes at least one logic gate that is different from any of the second plurality of logic gates.
7. The apparatus of claim 6, wherein the at least one logic gate, which is different from any of the second plurality of logic gates, performs the same function as one or more different logic gates included in the second plurality of logic gates.
8. The apparatus of claim 1, wherein the public data and the security information assets obtained by the first computing module and the second computing module are masked.
9. The apparatus of claim 1, wherein the second computation module is configured to generate an even number of dummy products during the execution of the Boolean operation, the even number of dummy products being eliminated in the output generated by the second computation module.
10. The apparatus of claim 9, wherein the input data for generating the even number of dummy products includes one or more bits of common data or bits derived from the bits of common data.
11. The apparatus of claim 1, wherein the first computing module is configured to generate a plurality of products between bits of the public data and bits of the security information asset and to generate a plurality of sums of products between product pairs included in the plurality of products, wherein the plurality of sums of products can be re-decoded by a dedicated shared random variable.
12. The apparatus of claim 1, wherein the first computing module comprises a plurality of computing elements configured to generate the output based on a predetermined order of operations.
13. The apparatus of claim 12, wherein the predetermined sequence of operation includes one or more of an order of calculating a plurality of products of bits of the public data and bits of the security information asset, or an order of adding the plurality of products.
14. The apparatus of claim 12, wherein the pseudo-random seed is expanded into a list of the predetermined order of the specified operations.
15. The apparatus of claim 12, wherein the plurality of computing elements comprises a unit multiplication element, wherein the unit multiplication element comprises one or more of a NAND gate or an AND gate.
16. The apparatus of claim 12, wherein the plurality of computing elements comprises an XOR gate.
17. The apparatus of claim 1, further comprising an additional processor coupled to the memory, wherein the additional processor includes a third computing module configured to: Obtain the public data and the security information assets; and The Boolean operation is performed on the public data and the security information assets to generate the output, wherein the third computing module has a third configuration different from the first configuration.
18. A method for securely performing cryptographic operations, the method comprising: Acquiring public data and security information assets; The first calculation module performs Boolean operations on the public data and the security information assets to generate output; Obtain the public data and the security information assets; as well as The second computing module performs the Boolean operation on the public data and the security information assets to generate the output, wherein the first computing module has a first configuration and the second computing module has a second configuration different from the first configuration.
19. The method of claim 18, wherein the Boolean operation comprises combining a plurality of common bits of the common data with a plurality of bits of the security information asset in a bilinear computation.
20. The method of claim 19, wherein each of the plurality of common bits has a fixed value.
21. The method of claim 20, wherein the first configuration includes a first internal structure of the first computing module, and wherein the second configuration includes a second internal structure of the second computing module.
22. The method of claim 18, wherein the first computing module implements the Boolean operation through a first plurality of logic gates in a first configuration, and the second computing module implements the Boolean operation through a second plurality of logic gates in a second configuration different from the first configuration.
23. The method of claim 18, wherein the first computing module includes a first plurality of logic gates, and the second computing module includes a second plurality of logic gates, wherein the first plurality of logic gates includes at least one logic gate that is different from any of the second plurality of logic gates.
24. The method of claim 23, wherein the at least one logic gate, which is different from any of the second plurality of logic gates, performs the same function as one or more different logic gates included in the second plurality of logic gates.
25. The method of claim 18, wherein the public data and the security information assets obtained by the first computing module and the second computing module are masked.
26. The method of claim 18, wherein the second computation module is configured to generate an even number of dummy products during the execution of the Boolean operation, the even number of dummy products being eliminated in the output generated by the second computation module.
27. The method of claim 26, wherein the input data for generating the even number of dummy products includes one or more of bits of common data or bits derived from bits of common data.
28. The method of claim 18, wherein the first computing module is configured to generate a plurality of products between bits of the public data and bits of the security information asset and to generate a plurality of sums of products between product pairs included in the plurality of products, wherein the plurality of sums of products can be re-decoded by a dedicated shared random variable.
29. The method of claim 18, wherein the first computing module comprises a plurality of computing elements configured to generate the output based on a predetermined order of operations.
30. The method of claim 29, wherein the predetermined order of operations includes one or more of an order of calculating a plurality of products of bits of the public data and bits of the security information asset, or an order of adding the plurality of products.