METHOD OF SELECTING A VALUE FROM TWO VALUES STORED IN TWO DIFFERENT REGISTERS
The method addresses the vulnerability of existing register selection methods to side-channel attacks by concatenating, rotating, and deleting values in a way that maintains constant execution characteristics, thereby enhancing security against such attacks.
Patent Information
- Application Number
- FR2023001610
- Authority / Receiving Office
- FR · FR
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2023-02-22
- Publication Date
- 2025-06-20
- Estimated Expiration
- 2043-02-22
AI Technical Summary
Existing methods for selecting a value from two values recorded in different registers are vulnerable to side-channel attacks, as they result in observable changes in energy consumption, execution time, or electromagnetic fields.
A method that concatenates the two values, rotates the concatenated word based on the selection bit, and then deletes the unselected value, all while maintaining a constant sequence of instructions and avoiding memory accesses dependent on the selection bit.
The method is robust against side-channel attacks, as it maintains a constant execution time and energy consumption regardless of the selection bit value, making it difficult for attackers to determine the selection bit from physical observations.
Smart Images

Figure 00000017_0000 
Figure 00000017_0001
Abstract
Description
Title of the invention: METHOD FOR SELECTING A VALUE FROM TWO VALUES RECORDED IN TWO DIFFERENT REGISTERS
[0001] Embodiments and implementations relate to computer systems, in particular a method of selecting a value from two values recorded in two different registers of the computer system from a selection bit.
[0002] Certain applications of a computer system require selecting a value from two values recorded in two different registers of this computer system. This value selection can be carried out from a selection bit that the user wishes to keep secret.
[0003] In particular, the selection of a value from two values stored in two different registers can be carried out within the framework of cryptographic methods. For example, algorithms calculating a modular exponentiation in a finite field or a scalar multiplication on an elliptic curve can implement such a selection. These algorithms are used in the “RSA” and “ElGamal” cryptosystems, the “DSA” (acronym for “Digital Signature Algorithm”) and “ECDSA” (acronym for “Elliptic curve digital signature algorithm”) algorithms and the “ECDH” (acronym for “Elliptic-curve Diffie-Hellman”) protocol. The selection bit is for example a bit of a cryptographic key that the user wishes to keep secret.
[0004] Furthermore, the manipulation of data in a computer system may result in a change in the energy consumption of the processing unit performing this data manipulation.
[0005] Data manipulation can also result in a change in execution time depending on the data manipulated. In particular, a computer system may use a cache memory. This cache memory may temporarily store data. Access to data stored in the cache is performed more quickly than access to data stored in a memory for which the cache memory serves as an intermediary.
[0006] Data manipulation may also result in a change in the electromagnetic field of the processing unit manipulating the data.
[0007] These changes are examples of physical observations that can be used by an attacker wishing to recover information from the computer system. These observations are referred to as a “side-channel attack.”
[0008] In particular, an attacker may seek to know the value of the selection bit used to select a value from two values recorded in different registers. However, the selection of a value from two values recorded in two different registers is carried out by executing computer instructions which may, for example, result in changes in energy consumption and / or execution time or electromagnetic fields. These changes may be observed by an attacker. Observing these changes may allow the attacker to determine the value of the selection bit.
[0009] Thus, for example, in the context of the previously cited cryptography methods, the attacker can observe the changes to determine each bit of the cryptographic key. This allows the attacker to recover the cryptographic key which he can then use maliciously.
[0010] Several solutions are known for making a selection between two values recorded in different registers.
[0011] A first known solution consists of implementing an if-then-else function in which the condition evaluated is the value of the selection bit.
[0012] The implementation of the if-then-else function uses instruction sequences that are different depending on the value of the selection bit. These instruction sequences can result in a different execution time, different power consumption, or even a different magnetic field. Therefore, an attacker can determine the value of the selection bit based on his observations.
[0013] A second solution consists of putting said two values in an array, then accessing the selected value in the array from the value of the selection bit. This solution may involve the use of a cache memory during memory accesses made according to the value of the selection bit. The use of the cache memory may modify the access times of the memory accesses according to the value of the selection bit. On an architecture supporting a cache, it is therefore possible for an attacker to find the value of the selection bit according to the observed memory access times.
[0014] A third solution consists of using a mask on the values to be selected, the mask used depending on the selection bit. For example, on a 32-bit architecture, the mask can have the value OxFFFFFFFFF or 0x00000000 depending on the value of the selection bit. However, these masks have very different Hamming weights (number of bits at 1). Thus, the energy consumption for using these masks can vary greatly depending on the mask selected. If the difference in energy consumption due to the use of masks is sufficient to be observed, an attacker can find the value of the selection bit.
[0015] A fourth solution is described in the US patent application published under the number n°2021 / 306134. This solution uses masks with the same Hamming weight on a 32-bit architecture. In particular, the masks correspond to an alternation of 1 bits and 0 bits. In particular, the masks have the value OxAAAAAAAA or 0x55555555 depending on the value of the selection bit. The value of the mask is obtained by performing or not performing a right shift of one bit by the value OxAAAAAAAA depending on the value of the selection bit. If the shift occurs, the 32 bits of the register change value simultaneously. Otherwise, no bit changes value. Such a difference can also cause a significant variation in energy consumption depending on the hardware considered. If the difference in energy consumption due to the use of masks is sufficient to be observed, an attacker can find the value of the selection bit.
[0016] There is therefore a need to propose a solution making it possible to select a value from two values stored in two different registers in a simple and discreet manner in order to be robust against side channel attacks.
[0017] According to one aspect, there is provided a method implemented by computer - in particular by a computer system as described below, for example a system on chip - for selecting a value from two values recorded in two different registers from a selection bit, the method comprising: - a concatenation of the two values recorded in the two registers so as to obtain a concatenated word presenting said two values in two distinct portions of the concatenated word, then - a rotation of said concatenated word according to the value of the selection bit so as to position the selected value in a given portion of the concatenated word among said two portions, then - a deletion of the unselected value in the concatenated word so as to keep only the selected value in the concatenated word by eliminating the unselected value from the concatenated word.
[0018] Such a selection method has the advantage of being implemented by a sequence of instructions independent of the value of the selection bit and does not contain memory accesses dependent on the selection bit.
[0019] In particular, such a selection method has the advantage of being robust against side channel attacks.
[0020] Preferably, said removing the unselected value in the concatenated word comprises shifting the concatenated word so as to retain only the selected value in the concatenated word by removing the unselected value from the concatenated word.
[0021] Advantageously, concatenation makes it possible to concatenate two 16-bit values of so as to obtain a 32-bit concatenated word in which the two values are included in two 16-bit portions of the concatenated word.
[0022] In an advantageous embodiment, said rotation of said concatenated word comprises: - a first rotation of the concatenated word according to a predetermined number M of bits, M being different from 0 and a multiple of 16, then - a second rotation of the concatenated word according to a number of bits depending on the selection bits so as to obtain the selected value on said given portion.
[0023] Performing a two-step rotation makes it possible to avoid performing a 0-bit rotation when the selection bit is 0. Such a rotation, not modifying the value contained in the register, could in fact be observable by an attacker.
[0024] Advantageously, the number of shift bits for the second rotation is determined by performing: - a logical OR function between the value of the selection bit and a value equal to OxNOOOOOOO where N is between 1 and F in hexadecimal system and is defined relative to the number M of bits predetermined for the first rotation, then - a 28-bit rotation on the value obtained by the logical OR function so as to obtain a value of the number of shift bits for the second rotation.
[0025] According to another aspect, there is provided a computer program product comprising instructions which, when the program is executed by a computer, cause the latter to implement a selection method as described above.
[0026] According to another aspect, there is provided a computer system comprising: - a memory in which is stored a computer program product as described above, and - a processing unit configured to execute said computer program product.
[0027] In particular, the processing unit has an architecture supporting rotation of the register contents.
[0028] Other advantages and characteristics of the invention will appear on examining the detailed description of embodiments, which are in no way limiting, and the appended drawings in which:
[0029] [Fig.l]
[0030] [Fig.2] illustrate embodiments and implementations of the invention.
[0031] [Fig.l] illustrates a mode of implementation of a method, implemented by computer (in particular by a computer system as described below), of selecting a value from two values recorded in two different registers of the computer from a selection bit.
[0032] The selection bit is stored in a register of the computer. This selection bit is a secret selection bit.
[0033] Each of these values can be represented on 16 bits. Alternatively, each of these values can be represented on 32 bits.
[0034] When each value is represented on 32 bits, the steps of the selection method described below are carried out a first time on the 16 most significant bits of each value then a second time on the 16 least significant bits of each value, or vice versa.
[0035] In other words, the steps of the method are performed a first time to select the 16 most significant bits of a value from among the two values according to the selection bit, then a second time to select the 16 least significant bits of this same value, or vice versa. The most significant bits and the least significant bits selected are then concatenated to obtain the selected value.
[0036] The method comprises a concatenation step 20 in which the two values recorded in the two different registers are concatenated. The concatenation of the two values makes it possible to obtain a concatenated word. This concatenated word then has a first portion comprising a first value and a second portion comprising the second value. The two portions comprise the same number of bits. For example, each portion comprises 16 bits so that the concatenated word comprises 32 bits.
[0037] The method then comprises a rotation step 21 in which a rotation operation is performed on the bits of the concatenated word. The rotation operation is performed according to the value of the selection bit. For example, the rotation of the concatenated word is performed so as to place the bits of the value selected by the selection bit on the most significant bits of the concatenated word. In particular, when the concatenated word comprises two 16-bit portions, the rotation performed is a 16-bit or 32-bit rotation depending on the value of the selection bit.
[0038] The operation 21 of rotating the concatenated word can be carried out in two stages. In particular, the method can comprise a first rotation 21a of the concatenated word according to a predetermined number M of bits. The number M can be between 1 and 15 for example.
[0039] Then, the method can comprise a second rotation 21b of the concatenated word according to a number of bits depending on the selection bits so as to obtain the selected value on the portion with high-weight bits of the concatenated word.
[0040] For example, the number of shift bits for the second rotation is determined by first performing a logical OR function between the value of the selection bit and a value equal to OxNOOOOOOO where N is between 1 and F in hexadecimal system and is defined relative to the number M of predetermined bits for the first rotation. The logical OR function then makes it possible to obtain a value equal to OxNOOOOOOO when the selection bit is 0, and OxNOOOOOOl when the selection bit is 1. A 28-bit rotation to the right is then performed to obtain a value equal to OxOOOOOOON when the selection bit is 0 and to 0x0000001N.
[0041] This calculated value defines the number of shift bits for the second rotation.
[0042] The first rotation and the second rotation make it possible to perform a rotation of the concatenated word of a number of bits equal to M+Ni6 if the selection bit is 0 or to M+(1N)i6. The values of M and N are chosen so that the sum M+Ni6 is equal to 16 (in decimal system) and so that the sum M+(1N)i6 is equal to 32 (in decimal system).
[0043] Performing a rotation 21 in two stages (a first rotation 21a then a second rotation of 21b) makes it possible to avoid the rotation being directly 0 bits (when the rotation is 32 bits) or 16 bits. The first rotation therefore makes it possible to have a modification of the concatenated word whatever the value of the selection bit. In this way, determining the selection bit from an observation of the rotation is made more complex.
[0044] Once the rotation operation 21 has been performed on the concatenated word, the value selected by the selection bit is located on a given portion of the concatenated word, for example the 16 most significant bits of the concatenated word, i.e. on the first portion of the concatenated word. The value not selected by the selection bit is then located on the 16 least significant bits of the concatenated word, i.e. on the second portion of the concatenated word.
[0045] The method then comprises a deletion step 22 in which the unselected value is deleted from the concatenated word. In particular, the deletion step 22 may for example comprise a shift operation on the concatenated word so as to keep only the value selected by the selection bit. For example, a 16-bit shift to the right is carried out so as to place the selected value on the 16 least significant bits of the concatenated word, i.e. on the second portion of the concatenated word. Thus, the unselected value is eliminated from the concatenated word to keep only the selected value in the concatenated word.
[0046] Alternatively, a mask may be applied to the concatenated word to remove the unselected value and retain only the selected value.
[0047] Such a selection method has the advantage, at least for certain architectures, of being able to be executed during an execution time which is the same regardless of the value of the selection bit. Indeed, the selection method comprises the same sequence of instructions to be executed regardless of the value of the selection bit.
[0048] Such a selection method has the advantage of being robust against side channel attacks.
[0049] Tables [Table 1] to [Table 4] illustrate different examples of implementation of the method described above. These tables show the instructions executed by the computer. The instructions are represented here in assembly language for an ARM Cortex®-M3 processor. Tables [Table 1] and [Table 2] illustrate examples of implementation of the same method when the selection is made between two 16-bit values according to the value of the selection bit. Tables [Table 3] and [Table 4] illustrate examples of implementation of another method in which the selection is made between two 32-bit values according to the value of the selection bit.
[0050] Table [Table 1] illustrates an example of implementation of the method when the two values vO and vl initially stored in the registers rO and rl are on 16 bits, and when the value of the selection bit Sel_bit initially stored in the register r2 is equal to 0 so as to select the value vO stored in the register rO.
[0051] [Tables 1] Sel_bit=0 N" Instruction Instruction Register rO Register ri Register r2 #0 Initial state vO vl Sel_bit = 0 #1 EOR rO,rO,r1,LSL #16 vl || vO #2 ROR rO.rO, #1 (vl II vO) »> 1 #3 ORR r2,r2,=0xF0000000 OxFOOOOOOO #4 ROR r2,r2,#28 0x0000000F =15 #5 ROR rO,rO,r2 vO || v1 #6 LSR r0,r0,#16 vO
[0052] Instruction #1 is an “EOR rO, rO, rl, LSL#16” instruction. This instruction allows the values vO and vl stored in the registers rO and rl to be concatenated so as to obtain a concatenated word vlllvO and allows this concatenated word vlllvO to be recorded in the register rO. In particular, this instruction allows the value vl represented on 16 bits to be shifted to the left by 16 bits before performing an EXCLUSIVE OR logical operation between this shifted value vl and the value vO to obtain the concatenated word vlllvO. The concatenated word then has a first portion of 16 high-order bits comprising the value vl and a second portion of 16 low-order bits comprising the value vO.
[0053] Instruction #2 is a “ROR rO, rO, #1” instruction. This instruction performs a 1-bit right rotation operation on the concatenated word vlllvO so as to obtain a concatenated word shifted by 1 bit by right rotation (v 1 IIv0)”>l. This shifted concatenated word is stored in the register rO.
[0054] Instruction #3 is an “ORR r2, r2, =0xF0000000” instruction. This instruction allows you to perform a logical OR operation between the value of the selection bit Sel_bit stored in the register r2 and the value OxFOOOOOOO (represented here according to the hexadecimal system), and allows you to record the result of this operation in the register r2. The value of the selection bit being equal to 0 here, the result of the logical OR operation is equal to OxFOOOOOOO.
[0055] Instruction #4 is a “ROR r2, r2, #28” instruction. This instruction performs a 28-bit right rotation operation on the result of the logical OR operation stored in register r2, and records the result of this rotation operation in register r2. Here, the result of the rotation operation is equal to 0x0000000F in hexadecimal system, i.e. 15 in decimal system.
[0056] Instruction #5 is a “ROR rO, rO, r2” instruction. This instruction performs a rightward rotation operation by a number of bits corresponding to the value recorded in register r2 (here 0x0000000F, i.e. a 15-bit rightward rotation) on the shifted concatenated word (vlllv0)”>l stored in register rO, and records the result of this rotation operation in register rO. Here, the result of this 15-bit rotation operation corresponds to the concatenated word vOllvl which has a first portion of 16 high-order bits comprising the value vO and a second portion of 16 low-order bits comprising the value vl. Thus, this result corresponds to a 16-bit rotation of the concatenated word vlllvO.
[0057] Instruction #6 corresponds to an instruction "LSR rO, rO, #16". This instruction allows a 16-bit right shift operation to be performed on the concatenated word vOllvl resulting from the rotation operation, and allows the result of this shift operation to be recorded in the register rO. This shift operation allows the unselected value vl to be eliminated and only the selected value vO to be kept.
[0058] Table [Table 2] illustrates an example of implementation of the method when the two values vO and vl initially stored in the registers rO and rl are on 16 bits, and when the value of the selection bit Sel_bit initially stored in the register r2 is equal to 1 so as to select the value vl.
[0059] [Tables2] Sel_bit=1 Instruction Instruction Register rO Register r1 | Register | r2 #0 Initial state v0 v1 I Sel_bit = 1 #1 EORrO.rO.rl.LSL #16 v1 II vO #2 ROR rO,rO; #1 (v1 || vO) »> 1 #3 ORR r2,r2,=0xF0000000 0xF0000001 #4 ROR r2,r2,#28 | 0x0000001F = 31 #5 ROR r0,r0,r2 v1 || vO #6 LSRrÛ,rO,#16 v1
[0060] The instructions are identical to those described in relation to the table [Table 1]. However, the results of the operations performed by the execution of these instructions differ from those in the table [Table 1] because the value of the selection bit is equal to 1 and no longer 0.
[0061] In particular, the result of the logical OR operation of instruction #3 is equal to OxFOOOOOOl, and no longer OxFOOOOOOO. Thus, the result of the rotation operation of instruction #4 is equal to 0x0000001F, that is, 31 in the decimal system.
[0062] The rotation operation performed by instruction #5 is therefore a rotation on 31 bits, and no longer on 15 bits. Thus, the result of this rotation operation corresponds to the concatenated word vlllvO. This concatenated word vlllvO has a first portion of 16 high-order bits including the value vl and a second portion of 16 low-order bits including the value vO. This result corresponds to a 32-bit rotation of the concatenated word vlllvO obtained after the execution of instruction #2.
[0063] Therefore, the result of the shift operation of instruction #6 is equal to the selected value vl.
[0064] The executed instructions are the same regardless of the value of the selection bit. Thus, the execution time of the method is the same regardless of the value of the selection bit on an architecture where the execution time of the instructions used is constant. This makes it more difficult for an attacker to identify the value of the selection bit.
[0065] Furthermore, the value of register r2 differs by only one bit depending on the values of the selection bit. It is thus complex for an attacker to identify a change in register r2 depending on the selection bit. It is therefore complex to identify the value of the selection bit by observing register r2.
[0066] Furthermore, as previously indicated, performing a rotation of the concatenated word in two stages (a first rotation of 1 bit then a second rotation of 15 or 31 bits) makes it possible to avoid the rotation being directly 0 or 16. In particular, a rotation of 0 could be detected by an attacker. Rotating the concatenated word in two stages makes it more complex to identify the value of the selection bit.
[0067] Furthermore, the method allows a constant Hamming weight to be kept in the register r0 until instruction #6. In other words, the method allows the same number of bits to be kept at 1 in the values of the register. As a result, the identification of the value of the selection bit is made more complex for an attacker.
[0068] Tables [Table 3] and [Table 4] illustrate examples of implementation of a method for selecting between two 32-bit values according to the value of the selection bit.
[0069] Table [Table 3] illustrates an example of implementation of the method when the two values vO and vl initially stored in the registers rO and rl are represented on 32 bits, and when the value of the selection bit Sel_bit initially stored in the register r2 is equal to 0 so as to select the value vO stored in the register rO. The value vO comprises 16 most significant bits v0H and 16 least significant bits v0L. value vl includes 16 high-order vlH bits and 16 low-order vlL bits.
[0070] [Tables3] Sel_bit=0 N“ Instruction i Instruction Register rO Register r1 Register r2 Register r3 #0 : Initial state vO = || vOL v1 = VlH II v1L If|_bit = 0 #1 l UXTH r3j0 v0L #2 | EOR r3j3,r1,LSL 1 #16 v1L || vO1- #3 I ROR r3,r3,#1 (v1L II vOL) »> 1 #4 i UXTH rOjO,ROR | #16 v0H #5 i LSLrO,rO.#16 v0H [| 0 #6 ! EOR rLrO.r1.LSR | #16 v0h || v1H #7 |RORr1,r1,#1 (vOH || v1H) »> 1 #8 ORR ; r2,r2,#0xF0000000 OxF0000000 #9 i ROR r2,r2,#28 OxOOOOOOOF = 15 #10 iRORr1,r1,r2 v1F Il v0H #11 I ROR r3j3,r2 v0L |[ v1L #12 i LSLr1,r1,#16 v0H #13 EORrOj1.r3.LSR #16 vO = vO* H v0L
[0071] Instruction #1 is a “UXTH r3, rO” instruction. This instruction allows the 16 most significant bits of the value vO to be set to zero and the result of this operation to be recorded in the register r3. The result of this operation allows only the 16 least significant bits v0L of the value vO to be retrieved.
[0072] Instruction #2 is an “EOR r3, r3, rl, LSL#16” instruction. This instruction allows the least significant bits vlL and v0L of the values vl and vO stored in the registers rl and rO to be concatenated so as to obtain a first concatenated word vlLllv0L and allows this concatenated word vlLllv0L to be recorded in the register r3. In particular, this instruction allows the value vlL to be shifted 16 bits to the left before performing an EXCLUSIVE OR logical operation between this shifted value vlL and the value v0L to obtain the concatenated word vlLllv0L. The concatenated word vlLllv0L then has a first portion of 16 high-order bits comprising the 16 low-order bits vlL of the value vl and a second portion of 16 low-order bits comprising the 16 low-order bits v0L of the value vO.
[0073] Instruction #3 is a “ROR r3, r3, #1” instruction. This instruction performs a 1-bit right rotation operation on the concatenated word vlLllv0L so as to obtain a concatenated word shifted by 1 bit by right rotation (vlLllv0L )>»1. This shifted concatenated word is stored in the register r3.
[0074] Instruction #4 is a “UXTH rO, rO, ROR#16” instruction. This instruction performs a 16-bit rightward rotation of the value vO so as to invert the values v0H of the most significant bits with the values v0L of the least significant bits of the value vO, before setting the 16 most significant bits of the rotation result to zero and recording the result of this operation in the register rO. The result of This operation allows only the 16 most significant bits vOH of the value vO to be recovered.
[0075] Instruction #5 is an LSL instruction r0,r0,#16. This instruction shifts the value v0H by 16 bits to the left. The result of this operation is then the concatenated word vOHIIO.
[0076] Instruction #6 is an “EOR rl, rO, rl, LSR#16” instruction. This instruction allows the most significant bits v0H and vlH of the values vO and vl to be concatenated so as to obtain a second concatenated word vOHllvlH, and allows this concatenated word vOHllvlH to be stored in the register rl. In particular, this instruction allows the 16 most significant bits of vl to be isolated by shifting vl 16 bits to the right before performing an EXCLUSIVE OR logical operation between the value vOHIIO and the value vlH to obtain the concatenated word vOHllvlH. The concatenated word vOHllvlH then has a first portion of 16 high-weight bits comprising the 16 high-weight bits v0H of the value vO and a second portion of 16 low-weight bits comprising the 16 high-weight bits vlH of the value vl.
[0077] Instruction #7 is a “ROR rl, rl, #1” instruction. This instruction performs a 1-bit right rotation operation on the concatenated word v0HllvlH so as to obtain a concatenated word shifted by 1 bit by right rotation (v0H Ilv 1H)”> 1. This shifted concatenated word is stored in the rl register.
[0078] Instruction #8 is an “ORR r2, r2, =0xF0000000” instruction. This instruction allows to perform a logical OR operation between the value of the selection bit Sel_bit stored in the register r2 and the value OxFOOOOOOO (represented here according to the hexadecimal system), and allows to record the result of this operation in the register r2. The value of the selection bit being here equal to 0, the result of the logical OR operation is equal to OxFOOOOOOO.
[0079] Instruction #9 is a “ROR r2, r2, #28” instruction. This instruction performs a 28-bit right rotation operation on the result of the logical OR operation stored in register r2, and records the result of this rotation operation in register r2. Here, the result of the rotation operation is equal to 0x0000000F in hexadecimal system, i.e. 15 in decimal system.
[0080] Instruction #10 is a “ROR rl, rl, r2” instruction. This instruction performs a rightward rotation operation of a number of bits corresponding to the value stored in register r2 (here 0x0000000F, i.e. a 15-bit rightward rotation) on the shifted concatenated word (v0HllvlH)”>l stored in register rl, and records the result of this rotation operation in register rl. Here, the result of this 15-bit rotation operation corresponds to the concatenated word vlHllv0H which has a first portion of 16 high-order bits comprising the 16 high-order bits vlH of the value vl and a second portion of 16 low-order bits comprising the 16 most significant bits vOH of the value vO. Thus, this result corresponds to a 16-bit rotation of the concatenated word vOHllvlH.
[0081] Instruction #11 is a "ROR r3, r3, r2" instruction. This instruction performs a rightward rotation operation of a number of bits corresponding to the value stored in register r2 (here 0x0000000F, i.e. a 15-bit rightward rotation) on the shifted concatenated word (v 1LIIv0L)»> 1 stored in register r3, and records the result of this rotation operation in register r3. Here, the result of this 15-bit rotation operation corresponds to the concatenated word vOLllvlL which has a first portion of 16 high-order bits comprising the 16 low-order bits v0L of the value vO and a second portion of 16 low-order bits comprising the 16 low-order bits vlL of the value vl. So this result corresponds to a 16-bit rotation of the concatenated word vlLllvOL.
[0082] Instruction #12 corresponds to an instruction "LSL rl, rl, #16". This instruction allows a 16-bit left shift operation to be performed on the concatenated word vlHllvOH resulting from the rotation operation, and allows the result of this shift operation to be recorded in the register rl. This shift operation allows the unselected value vlH to be eliminated and only the selected value v0H to be kept.
[0083] Instruction #13 corresponds to an instruction "EOR rO, rl, r3, LSR #16". This instruction allows the 16 most significant bits v0H and the 16 least significant bits v0L of the value vO to be concatenated to retrieve this selected value vO, and allows this retrieved value vO to be recorded in the register rO. In particular, this instruction first allows the concatenated word v0L Ilv 1L of the register r3 to be shifted 16 bits to the right to obtain V0L before performing an EXCLUSIVE OR logical operation with the value v0H to obtain the concatenated word v0Hllv0L corresponding to the selected value vO.
[0084] Table [Table 4] illustrates an example of implementation of the method when the two values vO and vl initially stored in the registers rO and rl are represented on 32 bits, and when the value of the selection bit Sel_bit initially stored in the register r2 is equal to 1 so as to select the value vl stored in the register rl.
[0085] [Tables4] Sel_bit=1 No. Instruction Instruction Register rO Register ri Register r2 Register r3 #0 Initial state vO = v0H || vO1- v1=v1H || v1L Sel_bit = 1 #1 UXTH r3.rO v0L #2 EOR r3,r3,r1,LSL #16 v1L|| v0L #3 ROR r3,r3,#1 ( vlL II v0L) »» 1 #4 UXTH rO,rO,ROR #16 v0H #5 LSL rO,rO,#16 vÜH || 0 #6 EOR rVO.rl.LSR #16 vO- || vl- #7 ROR ri ,r1,#1 (vQH || v'iH) »> 1 #8 ORR r2,r2,#ÜxF000000Q OxFOOOOOOl #9 ROR r2.r2.#28 0x0000001 F = 31 #10 ROR r1,r1,r2 vOH || v1- #11 ROR r3,r3,r2 v1L II v0L #12 LSL r1.rT#16 V1H #13 EOR rO,r1,r3,LSR #16 v1 =v1H II v1L
[0086] The instructions are identical to those described in relation to the table [Table 3]. However, the results of the operations performed by the execution of these instructions differ from those in the table [Table 3] because the value of the selection bit is equal to 1 and no longer 0.
[0087] In particular, the result of the logical OR operation of instruction #8 is equal to OxFOOOOOOl, and no longer OxFOOOOOOO. Thus, the result of the rotation operation of instruction #9 is equal to 0x0000001F, that is, 31 in the decimal system.
[0088] The rotation operations performed by instructions #10 and #11 are therefore rotations on 31 bits, and no longer on 15 bits.
[0089] More particularly, the result of the rotation operation of instruction #10 therefore corresponds to the concatenated word v0HllvlH. This concatenated word v0HllvlH has a first portion of 16 high-order bits comprising the 16 high-order bits v0H of the value v0 and a second portion of 16 low-order bits comprising the 16 high-order bits vlH of the value vl. This result corresponds to a 32-bit rotation of the concatenated word v0HllvlH obtained after the execution of instruction #6.
[0090] The result of the rotation operation of instruction #11 therefore corresponds to the concatenated word vlLllv0L. This concatenated word vlLllv0L has a first portion of 16 high-order bits comprising the 16 low-order bits vlL of the value vl and a second portion of 16 low-order bits comprising the 16 low-order bits v0L of the value vO. This result corresponds to a 32-bit rotation of the concatenated word vlL Ilv0L obtained after the execution of instruction #2.
[0091] Therefore, the result of the shift operation of instruction #12 is equal to the 16 most significant bits vlH of the selected value vl, and the result of the operation EXCLUSIVE OR of instruction #13 results in the concatenated word vlHll vlL corresponding to the selected value vl.
[0092] The selection methods described can be implemented within the framework of a cryptography method. In particular, the selection methods described can be implemented in the “RSA” and “ElGamal” cryptosystems, the “DS A” (acronym for “Digital Signature Algorithm”) and “ECDSA” (acronym for “Elliptic curve digital signature algorithm”) algorithms, and the “ECDH” (acronym for “Elliptic-curve Diffie-Hellman”) protocol. For example, the selection methods described can be implemented in a Montgomery ladder algorithm.
[0093] More particularly, the selection bit may be a bit of a cryptographic key that the user wishes to keep secret. For example, such a selection may be implemented to calculate a modular exponentiation or a scalar multiplication based on a bit of the cryptographic key.
[0094] [Fig.2] illustrates an embodiment of a computer system SYS, such as a system on chip for example. The computer system SYS comprises a processing unit UT and a memory MEM in which a computer program PRG is stored. The processing unit UT has an architecture supporting a rotation of the register contents.
[0095] The computer program PRG comprises instructions which, when the program is executed by the processing unit UT, cause the latter to implement a selection method such as those described previously.
Claims
Claims
1. A computer-implemented method of selecting a value from two values stored in two different registers from a selection bit, the method comprising: - a concatenation (20) of the two values stored in the two registers so as to obtain a concatenated word having said two values in two distinct portions of the concatenated word, then - a rotation (21, 21a, 21b) of said concatenated word according to the value of the selection bit so as to position the selected value in a given portion of the concatenated word among said two portions, then - a deletion (22) of the unselected value in the concatenated word so as to retain only the selected value in the concatenated word by eliminating the unselected value from the concatenated word.
2. The method of claim 1, wherein said removing the unselected value from the concatenated word comprises shifting (22) the concatenated word so as to retain only the selected value in the concatenated word by removing the unselected value from the concatenated word.
3. A method according to any one of claims 1 or 2, wherein the concatenation makes it possible to concatenate two 16-bit values so as to obtain a 32-bit concatenated word in which the two values are included in two 16-bit portions of the concatenated word.
4. Method according to claim 3, wherein said rotation of said concatenated word comprises: - a first rotation (21a) of the concatenated word according to a predetermined number M of bits, M being different from 0 and a multiple of 16, then - a second rotation (21b) of the concatenated word according to a number of bits depending on the selection bit so as to obtain the selected value on said given portion.
5. Method according to claim 4, in which the number of shift bits for the second rotation is determined by carrying out: - a logical OR function between the value of the selection bit and a value equal to OxNOOOOOOO where N is between 1 and F in hexadecimal system and is defined relative to the number M of bits predetermined for the first rotation, then - a rotation of 28 bits on the value obtained by the logical function OR to obtain a value of the number of shift bits for the second rotation.
6. Computer program product comprising instructions which, when the program is executed by a computer, cause the latter to implement a method according to one of claims 1 to 5.
7. A computer system comprising: - a memory in which a computer program product according to claim 6 is stored, and - a processing unit configured to execute said computer program product.