OBFUSCATION THROUGH SOFT-COMPUTING-BASED IMPLEMENTATION

DE502018015864D1Active Publication Date: 2025-06-26ROBERT BOSCH GMBH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
DE502018015864
Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Priority Date
2017-04-20
Filing Date
2018-04-04
Publication Date
2025-06-26
Estimated Expiration
2038-04-04

AI Technical Summary

Technical Problem

Existing cryptographic implementations are vulnerable to side-channel attacks and reverse engineering, as attackers can exploit physical quantities like power consumption and electromagnetic emanation to infer internal states and secret keys.

Method used

The method employs soft computing techniques, specifically artificial neural networks (ANNs), to obscure computational operations, breaking the connection between secret data and observable information, thereby concealing the internal state from attackers.

Benefits of technology

This approach effectively protects both hardware and software implementations from cryptanalytic attacks by adding noise and obfuscation, making it difficult for attackers to determine useful information from the internal state of the cryptographic operations.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader
Need to check novelty before this filing date? Find Prior Art

Description

[0001] The present invention relates to a method for protecting a computing unit configured to execute at least one computing operation against cryptanalytic attacks, in particular side-channel attacks and reverse engineering, as well as a computing unit and a computer program for carrying out the same. State of the art

[0002] With the proliferation of strong, standardized cryptographic mechanisms in commercial applications, the focus of attackers has shifted from breaking the cryptographic algorithm (i.e., the mathematics behind the algorithm) to breaking the implementation of the algorithm on the target device.

[0003] A typical example of such implementation attacks are so-called side-channel attacks (SCA). side channel attacks or side channel analysis attacks ). In SCA attacks, the adversary records the so-called side-channel leakage (SCL). side channel leakage ) of the target device (usually an integrated circuit or a microprocessor / microcontroller, e.g., a chip card, a security token, or a hardware security module of a control unit) while it is performing cryptographic operations. The side-channel leakage can be any physical quantity—for example, power consumption, electromagnetic emanation, execution time, etc.—related to the internal switching activity of the integrated circuit, e.g., the switching activity of the CMOS gates in a hardware implementation of a cryptographic algorithm. This information can then be used by the attacker to determine parts of the internal state of the integrated circuit and from this to determine the secret key used by the cryptographic algorithm, typically in the range of a few minutes to several hours.Essentially, an SCA attack becomes possible because an attacker who has physical access to the target device can gather information about the internal state of the cryptographic algorithm during execution.

[0004] Power analysis methods examine the energy consumption of a microprocessor during cryptographic calculations. Energy consumption varies depending on the microprocessor instructions being executed. This allows conclusions to be drawn about the operations performed and the underlying key. The resulting "traces" (a specific set or number of energy consumption measurements obtained from a cryptographic calculation operation over time) can be used to uncover patterns, such as DES rounds or RSA operations. Differences in the respective traces allow conclusions to be drawn about the key used. In addition to simple power analysis, differential power analysis (DPA) in particular allows such conclusions to be drawn.

[0005] Electromagnetic analysis (EM) is based on a corresponding evaluation of electromagnetic radiation.

[0006] Another class of attacks based on the attacker's ability to access the internal state of the target algorithm are so-called Reverse Engineering-basierte Attacks. In this case, the attacker typically examines the binary of the target algorithm, as well as the values ​​of the machine registers and its memory during the execution of the binary.

[0007] With this information, the attacker can easily break the target algorithm. For example, if the secret key used by a cryptographic algorithm is contained in the binary file, the attacker can extract this key by statically analyzing the binary file. Alternatively, if the key is embedded in the binary file in a way that is not understandable using static analysis techniques, the attacker can execute the binary file, record the software traces (i.e., the values ​​of the registers and the contents of the memory during the execution of the binary file), and use this 'dynamic' information to extract the key. Such techniques are also known as Differential Computation Analysis known.

[0008] US 2016 / 127123 discloses a system and method for dynamic data masking. The methods and system can be used to dynamically mask data in cryptographic operations, such as Advanced Encryption Standard (AES), Data Encryption Standard (DES), or Triple DES operations.

[0009] A method is known from US 2017 / 0103236 which can be used to design secure integrated circuits.

[0010] US 2003 / 161467 discloses a compact dual-function random number generator and a stream encryption generator comprising a crypto engine having a controller for controlling the engine.

[0011] CN 103 646 219 discloses a power consumption compensation and attack resistance circuit based on the prediction of the power consumption of a neural network and a control method.

[0012] EP 2721763 discloses a method for data transmission, comprising receiving a control signal that triggers transmission of a secret value into an element of a circuit. In response to the control signal, a dummy value and the secret value are sequentially inserted into the element of the circuit. Disclosure of the invention

[0013] According to the invention, a method for protecting a computing unit configured to execute at least one computing operation against cryptanalytic attacks, as well as a computing unit and a computer program for implementing the method, are proposed, having the features of the independent patent claims. Advantageous embodiments are the subject of the dependent claims and the following description.

[0014] The invention presents a method for protecting against attacks during the execution of computational operations performed within the framework of a cryptographic method. The invention utilizes the measure of enforcing at least one computational operation using so-called "crypto-attacks." Soft-Computing- To implement techniques so that the underlying computational operations are hidden (obfuscation).

[0015] The invention breaks the connection between the secrets stored in or processed by the implementation of the applied algorithm and the information based on the internal state that can be observed or recorded by the attacker. The invention can protect both hardware and software implementations.

[0016] Soft computing techniques are well known in themselves. However, they have typically been used to simulate processes that are not clearly calculable using computer implementations (keywords: learning, artificial intelligence). They are thus artificial intelligence (AI) techniques for numerically determining approximate solutions. Soft-Computing It primarily encompasses the areas of fuzzy logic, artificial neural networks, probabilistic reasoning, evolutionary strategies, genetic algorithms, hidden Markov models, and random forest methods. Within the scope of the invention, however, it has now been recognized that these techniques are also particularly well suited to concealing computational operations. The solution does not require random measures.

[0017] Advantageously, any arithmetic operation can be implemented using a soft computing technology. Bit operations are particularly suitable, where a specific number of output bits is generated from a specific number of input bits, e.g., an output bit or output byte is generated from one input bit, or an output bit or output byte is generated from one input byte. For example, eight such arithmetic operations together can generate an output byte from one input byte. It is understood that any ratio between the number of input and output bits is possible here.

[0018] Preferably, the at least one calculation function is a step or sub-step of a cryptographic method, in particular those that are linked to a key or operate with a secret key, e.g. encryption or decryption, hash value calculation, signing, etc.

[0019] At least one calculation function is a step of an AES block cipher algorithm, such as AddRoundKey, SubBytes or, in particular, MixColumns.

[0020] According to the present invention, an artificial neural network (ANN) is used. artificial neural network ). Artificial neural networks, or the techniques for representing computational operations as such, are known per se. Within the scope of the invention, these can now be used particularly advantageously to effectively conceal cryptographic computational operations. In particular, they are very well suited for the aforementioned bit operations, in which each input and output neuron represents a bit.

[0021] The invention can be further improved by Soft-Computing- Any number of elements that are not related to the computation to be protected can be added to the implementation. For example, in an implementation as an ANN, additional input or output neurons can be incorporated that have nothing to do with the actual computational operation. Accordingly, any large internal state of the ANN may be unrelated to the actual computational operation, thus further complicating analysis. As a result, in the final representation of the computational operation, only an (arbitrary) small subset of the ANN's internal state actually contains information that is useful to the attacker. However, the attacker is unable to determine which subset this is. In this way, (arbitrary amounts of) noise can be added to data obtained during attacks, making a successful attack difficult or even impossible.

[0022] A computing unit according to the invention, e.g. a microcontroller, e.g. in a control unit of a motor vehicle, is set up, in particular in terms of programming, to carry out a method according to the invention.

[0023] Implementing the method in the form of a computer program is also advantageous, as this results in particularly low costs, especially if an executing processing unit is also used for other tasks and is therefore already present. Suitable data storage devices for providing the computer program include, in particular, magnetic, optical, and electrical storage devices, such as hard disks, flash memories, EEPROMs, DVDs, and others. Downloading a program via computer networks (Internet, intranet, etc.) is also possible.

[0024] Further advantages and embodiments of the invention will become apparent from the description and the accompanying drawings.

[0025] The invention is illustrated schematically in the drawing using an embodiment and is described below with reference to the drawing. Short description of the drawings

[0026] Figur 1 schematically shows a preferred embodiment of an artificial neural network which performs a cryptographic calculation operation. Figur 2 shows schematically a preferred embodiment of an AES method in which selected computing operations are implemented by means of artificial neural networks. Embodiment(s) of the invention

[0027] In particular, the invention can be implemented in practice by implementing a cryptographic computational operation or the entire algorithm (with numerous operations) using soft computing techniques. As an example, the SubBytes step of the FIPS-197 AES algorithm is mapped to a representation based on artificial neural networks (ANNs).

[0028] In the SubBytes step, an input byte B IN is replaced by an output byte B OUT using a so-called S-box. The S-box in this case consists of 256 bytes in 16 columns and 16 rows, in hexadecimal notation starting with 0x63 at position (00), etc.

[0029] A preferred implementation is based on the idea of ​​generating each of the eight bits b 0 , b 1 , ..., b 7 of the output byte B OUT using a separate ANN, with the eight bits of the input byte B IN being fed to the input node of each of these eight ANNs. Thus, the SubBytes step is broken down into eight bit operations, with one output bit being generated from each of the eight input bits.

[0030] For example, in Figur 1 schematically shows an exemplary structure of such an ANN 100 for generating the bit b 0 .

[0031] The ANN 100 has three levels: an input level with 9 nodes ("neurons") (numbered 0 to 8), an intermediate level with 12 neurons, and an output level with 1 neuron. Each neuron can take the value "0" or "1." As is typical for an ANN, there are numerous connections with different weights between the individual neurons. For a better overview, Figur 1 Only very few connections are shown, although a total of 129 connections exist. In a learning step underlying the implementation, the weights of the connections necessary to maintain the function of the above S-box are learned.

[0032] It can be seen that the ANN has nine input neurons, of which only eight are required to implement the cryptographic computation. According to the illustrated embodiment, the additional ninth input neuron (8) serves for additional obfuscation or noise generation. Accordingly, part of the ANN's internal state is unrelated to the actual cryptographic computation.

[0033] Similarly, the AddRoundKey step and / or the ShiftRows step and / or the MixColumns step can also be implemented as ANN as cryptographic operations for encryption.

[0034] Similarly, the InvSubBytes step and / or the InvShiftRows step can also be implemented as ANN as cryptographic operations for decryption.

[0035] For example, if a computational operation is to be implemented using Random Forest classification, the classifier would be trained with training data similar to an ANN, constructing a decision tree with the appropriate thresholds for each bit. This decision tree can then be used in normal operations, for example, to map the input for the SubBytes step to the corresponding output. In principle, with Random Forest classification, you can project a set of input data onto an n-dimensional surface and then intersect it.

[0036] Another example of soft computing techniques is genetic algorithms. This class of soft computing techniques is characterized by the fully automated creation of "offspring generations" from a possibly randomly selected initial population and their evaluation using a so-called fitness function. The offspring that are particularly viable according to the fitness function are retained as gene donors for the next generation. Thus, the principle of natural evolution is applied here. In this case, the fitness function is chosen to minimize side-channel information (e.g., correlation between the processed data and power consumption or data-dependent runtime).The evolutionary principle of genetic algorithms now allows for the fully automated generation of implementations that can be implemented in both software and hardware, while minimizing the amount of side-channel information. For example, it would be possible to incorporate the electromagnetic radiation values ​​of components into the fitness function and then determine these during evolution using SPICE simulations, for example, and optimize them for the final result.

[0037] A preferred implementation of the entire procedure is in Figur 2 shown.

[0038] On the left side, the encryption process is shown, starting from a plaintext 200 via the well-known round-based AES encryption (N rounds) to a ciphertext 201, and on the right side, the corresponding decryption back to the plaintext 200.

[0039] Here, individual steps, here ShiftRows steps 210 and MixColumns steps 220 as well as InvShiftRows steps 211 and InvMixColumns steps 221, are implemented in a conventional manner, and other steps according to a preferred embodiment of the invention are implemented as ANN 300. According to the present invention, the steps associated with the S-box or its inverts (namely AddRoundKey, SubBytes, and InvSubBytes) are implemented as ANNs in order to prevent attacks based on the known S-box structure. However, the aforementioned steps implemented in a conventional manner (here ShiftRows, MixColumns, InvShiftRows, and InvMixColumns) are also preferably implemented as ANNs in places, for example, during transitions between individual rounds and in particular at the beginning and end of the method (see box 300 in Figur 2 ).

[0040] The invention thus makes it possible to protect any cryptographic calculation operations or entire cryptographic methods or algorithms from attacks by means of Soft-Computing -techniques are implemented.

Claims

1. Method for protecting a computing unit configured for executing at least one cryptographic computing operation (300) against cryptoanalytic attacks, characterized in that the at least one cryptographic computing operation (300) is implemented by means of a soft computing technique (100), wherein the soft computing technique comprises an artificial neural network (100), wherein the at least one cryptographic computing operation (300) is a step of an AES block cipher algorithm, and wherein the at least one cryptographic computing operation (300) comprises a SubBytes step and / or an AddRoundKey step.

2. Method according to Claim 1, wherein the at least one cryptographic computing operation (300) comprises a bit operation in which a specific number of output bits (b0) are generated from a specific number of input bits (0, ..., 8).

3. Method according to Claim 2, wherein the number of input bits (0, ..., 8) is at least equal to the number of output bits (b0).

4. Method according to any of the preceding claims, wherein at least one input neuron (8) and / or output neuron which does not belong to the at least one cryptographic computing operation (300) is added to the artificial neural network (100).

5. Method according to any of the preceding claims, wherein the at least one computing operation (300) furthermore comprises a ShiftRows step and / or an InvSubBytes step and / or an InvShiftRows step and / or a MixColumns step.

6. Method according to any of the preceding claims, wherein the cryptoanalytic attacks include side channel attacks and / or reverse engineering.

7. Computing unit comprising means for carrying out any of the preceding claims.

8. Computer program which causes a computing unit to carry out a method according to any of Claims 1 to 7 when said computer program is executed on the computing unit.

9. Machine-readable storage medium with a computer program according to Claim 8 stored thereon.