Implementing a test

By employing at least two cascaded correspondence tables to compare and process data in logic tests, the vulnerabilities of existing logic test implementations to data leakage and attacks are mitigated, resulting in a more secure and reliable test implementation.

FR3156931A1Pending Publication Date: 2025-06-20STMICROELECTRONICS INT NV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
FR2023014454
Authority / Receiving Office
FR · FR
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-12-19
Publication Date
2025-06-20

AI Technical Summary

Technical Problem

Existing logic test implementations in electronic circuits and devices are vulnerable to data leakage, covert channel attacks, and fault injection attacks, which compromise their security and reliability.

Method used

The implementation of logic tests using at least two cascaded correspondence tables, where the first correspondence table compares parts of the data word with corresponding parts of reference words, and the second correspondence table compares the results of the first comparisons, enhancing security against data leakage and attacks.

Benefits of technology

This approach significantly enhances the security of logic test implementations by making them more resistant to covert channel attacks and fault injection attacks, while also protecting against data leakage, thereby ensuring the integrity and reliability of the tests.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

Implementing a test The present description relates to a method for implementing a test for comparing a first data word (Tested_Word) to at least one second data word, comprising the following successive steps: - dividing said first data word (Tested_Word) into at least one part (T_Wordj); - comparing each of said at least one part (T_Wordj) of said first data word (Tested_Word) with at least one corresponding part of said at least one second data word, using, for each comparison, a first correspondence table (LUTj); - comparing the results of each of said first correspondence tables using a second correspondence table (F_LUT). Figure for abstract: Fig. 3
Need to check novelty before this filing date? Find Prior Art

Description

Title of the invention: Implementation of a test Technical field

[0001] The present description relates generally to electronic circuits and devices and the implementation of logic functions by these electronic circuits and devices. The present description relates more particularly to the implementation of logic tests. Prior art

[0002] To implement programs and software, it is common for electronic circuits and devices to use combinational logic functions. More particularly, logic tests are very often used.

[0003] It would be desirable to be able to improve, at least in part, certain aspects of the implementation of logic tests by electronic devices. Summary of the invention

[0004] There is a need for a logic test implementation that is protected against data leakage.

[0005] There is a need for a logic test implementation that is protected against covert channel attacks.

[0006] There is a need for a logic test implementation protected against fault injection attacks.

[0007] There is a need for electronic circuits and devices suitable for such implementations.

[0008] One embodiment overcomes all or part of the drawbacks of known test implementations.

[0009] An embodiment overcomes all or part of the drawbacks of known circuits and devices suitable for implementing logic tests.

[0010] One embodiment provides for an implementation of logic tests using at least two cascaded correspondence tables.

[0011] One embodiment provides a method for implementing a test for comparing a first data word to at least one second data word, comprising the following successive steps: - dividing said first data word into at least one part; - comparing each of said at least one part of said first data word with at least one corresponding part of said at least one second data word, using, for each comparison, a first correspondence table; - comparing the results of each of said first correspondence tables using a second correspondence table.

[0012] Another embodiment provides an electronic device adapted to implement a comparison test of a first data word with at least one second data word, comprising the following successive steps: - dividing said first data word into at least one part; - comparing each of said at least one part of said first data word with at least one corresponding part of said at least one second data word, using, for each comparison, a first correspondence table; - comparing the results of each of said first correspondence tables using a second correspondence table.

[0013] According to one embodiment, during the division step, said first data word is divided into at least one part.

[0014] According to one embodiment, each result of said first correspondence tables is a third binary word.

[0015] According to one embodiment, said third binary word comprises one bit.

[0016] According to one embodiment, said third binary word comprises at least two bits.

[0017] According to one embodiment, each of said at least two parts of said first binary word comprises at least two bits, and each of said at least one corresponding part of said at least one second binary word comprises at least two bits.

[0018] According to one embodiment, said test is chosen from the group comprising: a logical equality test, a logical test of the “greater than” type, a logical test of the “greater than or equal” type, a logical test of the “less than” type, a logical test of the “less than or equal” type, a logical test of the “is between” type, a test of divisibility of an integer by another integer, a logical test concerning the Hamming weight of a binary data item, and any combination of one or more of these preceding tests with each other.

[0019] According to one embodiment, the results of each of said first correspondence tables are concatenated into a fourth data word to be compared using said second correspondence table. Brief description of the drawings

[0020] These characteristics and advantages, as well as others, will be explained in detail in the following description of particular embodiments given without limitation in relation to the attached figures among which:

[0021] [Fig.l] represents an embodiment of an electronic device adapted to execute an implementation mode of a method for implementing logic tests;

[0022] [Fig.2] represents, very schematically and in the form of blocks, an implementation of a test;

[0023] [Fig. 3] represents, very schematically and in the form of blocks, a first general example of a mode of implementation of a method for implementing logical tests;

[0024] [Fig.4] represents, very schematically and in the form of blocks, a second practical example of a mode of implementation of a method for implementing logical tests;

[0025] [Fig.5] represents, very schematically and in the form of blocks, a third practical example of a mode of implementation of a method for implementing logical tests;

[0026] [Fig. 6] represents, very schematically and in the form of blocks, a fourth practical example of a mode of implementation of a method for implementing logical tests; and

[0027] [Fig.7] represents, very schematically and in the form of blocks, a fifth practical example of a mode of implementation of a method for implementing logical tests. Description of the embodiments

[0028] The same elements have been designated by the same references in the different figures. In particular, the structural and / or functional elements common to the different embodiments may have the same references and may have identical structural, dimensional and material properties.

[0029] For the sake of clarity, only the steps and elements useful for understanding the embodiments described have been represented and are detailed.

[0030] Unless otherwise specified, when referring to two elements connected between them, it means directly connected without intermediate elements other than conductors, and when referring to two elements connected (in English "coupled") between them, it means that these two elements can be connected or be linked through one or more other elements.

[0031] In the following description, when reference is made to absolute position qualifiers, such as the terms "front", "back", "top", "bottom", "left", "right", etc., or relative position qualifiers, such as the terms "above", "below", "upper", "lower", etc., or to orientation qualifiers, such as the terms "horizontal", "vertical", etc., reference is made unless otherwise specified to the orientation of the figures.

[0032] Unless otherwise specified, the expressions "about", "approximately", "substantially", and "of the order of" mean to within 10%, preferably to within 5%.

[0033] The embodiments described below relate to the implementation of a test, such as a logic test or an arithmetic test, in a more secure manner, i.e. an implementation of a test in which the data used are less likely to be recovered by an outsider, or an implementation of a test which is less vulnerable to covert channel attacks, and, in particular, to fault injection attacks. For this purpose, the embodiments described below are based on the use of at least two “stages” of look-up tables (LUTs, Look Up Tables). A general example of implementation is described in relation to [Fig. 3], specific examples are described in relation to Figures 4 to 7.

[0034] Furthermore, these embodiments can be applied to any electronic devices implementing logic tests.

[0035] [Fig.l] is a block diagram representing, very schematically, an architecture of an example of an electronic device 100 adapted to implement one or more logic tests.

[0036] The electronic device 100 comprises a processor 101 (CPU) adapted to implement different processing of data stored in memories and / or provided by other circuits of the device 100. According to one embodiment, the processor 101 is adapted to implement one or more logic tests from data that it receives.

[0037] The electronic device 100 further comprises different types of memories 102 (MEM), including, for example, a non-volatile memory, a volatile memory, and / or a read-only memory. Each memory 102 may be adapted to store different types of data.

[0038] In the remainder of the description, a data word is a data item comprising several bits. A part of a data word corresponds to one or more bits of this data word.

[0039] The electronic device 100 further comprises, for example, a secure element 103 (SE) adapted to process sensitive and / or secret data. The secure element 103 may comprise its own processor(s), its own memory(s), etc. According to one embodiment, the secure element 101 may be adapted to implement logic tests.

[0040] The electronic device 100 may further comprise interface circuits 104 (IN / OUT) adapted to send and / or receive data originating from outside the device 100. The interface circuits 104 may further be adapted to implement a data display, for example, a display screen.

[0041] The electronic device 100 further comprises different circuits 105 (FCT1) and 106 (FCT2) adapted to perform different functions. For example, the circuits 105 and 106 may comprise measurement circuits, data conversion circuits, etc. According to one embodiment, the circuits 105 and 106 may comprise a circuit adapted to implement a method of transposing a matrix.

[0042] The electronic device 100 further comprises one or more data buses 107 adapted to transfer data between its different components.

[0043] According to a particular example, the electronic device 100 is adapted to implement computer programs, and in particular a computer program making it possible to implement one or more logic tests.

[0044] [Fig.2] represents, very schematically and in block form, the implementation of a test 200 (TEST).

[0045] The test 200 receives, as input, a data word Tested_Word to be tested and one or more reference words Ref_Words for comparison.

[0046] According to one embodiment, the test 200 makes it possible, from the data word to be tested Tested_Word, to carry out a binary function whose result can be a binary data item 201 (True) representing the TRUE information or a binary data item 202 (False) representing the FALSE information. Here, a binary data item is a data item composed of one or more data bits.

[0047] According to one embodiment, the test 200 makes it possible to compare the data word to be tested Tested_Word with one or more reference data words chosen from among the reference words Ref_Words. According to one embodiment, the test 200 can be a logical test or an arithmetic test. According to one example, the test 200 can verify the equality of the data word to be tested Tested_Word with one or more reference data words chosen from among the reference words Ref_Words. According to another example, the test 200 can compare a numerical value represented by the data word to be tested Tested_Word with one or more reference data words chosen from among the reference words Ref_Words.In other words, according to one embodiment, the test 200 implements a binary function chosen from the group comprising: a logical equality test, a logical test of the “greater than” type, a logical test of the “greater than or equal” type, a logical test of the “less than” type, a logical test of the “less than or equal” type, a logical test of the “is between” type, a test of divisibility of an integer by another integer, a logical test concerning the Hamming weight of a binary data item, and any combination of one or more of these preceding tests between them. In general, the list of reference words Ref_Words can represent any property to be verified for the word Tested_Word including ad-hoc properties which are neither arithmetic properties nor logical properties, for example a test of the “less than or equal to and different from N and divisible by K” type.

[0048] According to one embodiment, the data word to be tested Tested_Word is a binary word comprising K bits, K being a positive integer. According to a preferred embodiment, K is an integer greater than or equal to two. The bits of the data word Tested_Word are referenced B1 to B K.

[0049] According to one embodiment, the test 200 is adapted to receive N reference data words Ref_Words, N being an integer greater than or equal to one. Each individual reference word is referenced Ref_Wordn, n being an integer varying from 1 to N. Each reference data word Ref_Wordl, ..., Ref_WordN is a binary word comprising K bits like the data word to be tested Tested_Word. The bits of each reference data word Ref_Wordn are referenced Rbnl, to RbnK.

[0050] [Fig.3] illustrates a method 300 for implementing the test 200 described in relation to [Fig.2], according to one embodiment.

[0051] To be implemented, the method 300 uses correspondence tables. More particularly, the method 300 uses J primary correspondence tables LUTj, J being a positive integer, preferably an integer greater than or equal to two, and j being an integer between 1 and J, and at least one secondary correspondence table F_LUT. The secondary correspondence table F_LUT can also be called the final correspondence table. Practical examples of implementation of the method are described in relation to FIGS. 4 to 7.

[0052] To be implemented, the method 300 begins with a step of dividing the data word to be tested Tested_Word into J parts T_Wordl to T_WordJ. Each part T_Wordj is a binary data item comprising at least one bit, preferably at least two bits. We also speak of a part of order j to refer to the part T_Wordj. It should be noted that the J parts can have different numbers of bits. In the example shown in [Fig.3], each part T_Wordj is a binary data item comprising two bits.

[0053] According to one embodiment, when the integer J is equal to one, the division step is a division step into a single part T_Wordl of the data word to be tested Tested_Word. This part T_Wordl corresponds to the complete data word to be tested Tested_Word.

[0054] Then, a first step of comparing each part T_Wordj is carried out by implementing the primary correspondence table LUTj. Each correspondence table LUTj has been generated to provide the result of comparing a binary data of the type of a part T_Wordj with the corresponding parts of the reference data words Ref_Words. More particularly, to obtain the correspondence table LUTj the reference data words Ref_Words are divided into J parts in the same way as the data word to be tested Tested_Word, i.e. say in J parts of the same number of bits as the J parts of the data word to be tested Tested_Word.

[0055] Each primary correspondence table LUTj comprises 2ANBits values, NBits being an integer representing the number of bits of the T_WordJ part to be compared, illustrating all possible comparison results. "A" here represents the mathematical operation power. In the case illustrated in [Fig.3], as all the T_Wordj parts comprise two bits, each correspondence table LUTj comprises four values ​​distributed in two rows and two columns. The values ​​of the correspondence tables LUTj are referenced Aj[p; q], p being an integer representing the index of the column of the value and q being an integer representing the index of the row of the value.

[0056] Each value Aj[p; q] indicates whether the comparison is a success or a failure. According to one example, the value Aj[p; q] is represented by a binary data comprising at least one bit. According to one embodiment, when the test 200 compares the data word to be tested Tested_Word to several reference data words Ref_Words, the value Aj[p; q] can take distinct values ​​to differentiate the comparison of a part T_Wordj with the corresponding parts of different reference words Ref_Words. This concept is described in more detail with the practical example of [Fig.7].

[0057] At the end of the first comparison step, each primary correspondence table LUTj provides as output the value Aj[p; q] corresponding to the part T_Wordj of the data word to be tested Tested_Word.

[0058] Then, a second comparison step is implemented using the final correspondence table F_LUT which receives the values ​​Al[p; q] to AJ[p; q] provided by the primary correspondence tables LUT1 to LUTJ. According to one example, the binary data forming the values ​​Al[p; q] to AJ[p; q] are concatenated into a data word T_WordF. The size of the final correspondence table F_LUT depends on the total number of bits in the data word T_WordF. Practical examples of the final correspondence table F_LUT are detailed in relation to Figures 4 to 7.

[0059] The final correspondence table F_LUT stores values ​​F[pf; qf], pf being an integer representing the index of the column of the value and qf being an integer representing the index of the row of the value. The values ​​F[pf; qf] represent the result of the comparison of the data word T_WordF with the reference words Ref_Words. According to an example, when the test 200 compares the data word to be tested Tested_Word to several reference data words Ref_Words, the value Fj[p; q] can take different values ​​to distinguish, if necessary, the different reference words Ref_Words.

[0060] In summary, the method 300 for implementing the test 200 for comparing the data word to be tested Tested_Word to one or more reference data words Ref_Words, comprises the following successive steps: - divide the data word to be tested Tested_Word into the J parts T_Wordl to T_WordJ; - compare each of said parts T_Wordl to T_WordJ of the data word to be tested Tested_Word to a corresponding part of the reference data words Ref_Words, using, for each comparison, one of the correspondence tables LUT1 to LUT J; - compare the results of each of the LUT1 to LUTJ correspondence tables using the final F_LUT correspondence table.

[0061] An advantage of the method 300 is that it makes it possible to implement the test 200 by making it more resistant to covert channel attacks, and in particular to fault injection attacks. Indeed, during such an attack, it is possible to locally modify a data word. If the targeted data word is the or one of the reference words Ref_Words, the test can be implemented, since the primary correspondence tables LUT1 to LUTJ have been generated beforehand. If the targeted data word is a value of one of the primary or secondary correspondence tables, it is more difficult to come across a data word that actually modifies the operation of the test 200.

[0062] [Fig.4] illustrates a practical example 400 of the method 300 for implementing the test 200 described in relation to [Fig.2].

[0063] In the example of [Fig.4], the test carried out is the verification of the equality between the data word to be tested Tested_Word401 and a reference data word equal to 1011. The data word to be tested Tested_Word401 therefore comprises four bits B1, B2, B3 and B4.

[0064] In the example of [Fig.4], it was decided to divide the data word to be tested Tested_Word401 into a part T_Word4011 comprising bits B1 and B2, and a part T_Word4012 comprising bits B3 and B4.

[0065] To implement the first comparison step, the method 400 uses two correspondence tables LUT401 and LUT402.

[0066] The correspondence table LUT401 receives, as input, the part T_Word4011 and compares it with the bits 10. It has been arbitrarily chosen that when the part T_Word4011 is equal to 10 the output data of the correspondence table LUT401 is the binary value 01, and, that when the part T_Word4011 is different from 10, the output data of the correspondence table LUT401 is the binary value 10.

[0067] The LUT402 correspondence table receives, as input, the part T_Word4012 and compares it with bits 11. It has been arbitrarily chosen that when the part T_Word4012 is equal to 11 the output data of the LUT402 correspondence table is the binary value 10, and that when the T_Word4012 part is different from 11 the output data of the LUT402 correspondence table is the binary value 00.

[0068] As described above, the lookup tables LUT401 and LUT402 output the values ​​corresponding to the comparisons of the parts T_Word4011 and T_Word4012 with the data 10 and 11 to a final lookup table LUT403. According to one example, the output values ​​of the lookup tables LUT401 and LUT402 are concatenated into a data word T_WordF401.

[0069] In the example illustrated in [Fig.4], test 200 is verified only if the data word T_WordF401 is equal to 0110. Thus, the final correspondence table LUT403 compares the data word T_WordF401 with the bits 0110. It has been arbitrarily chosen that when the data word T_WordF401 is equal to 0110 the output data of the correspondence table LUT403 is the binary value 1111, and that when the data word T_WordF401 is equal to 0100, 1000 or 1010 the output data of the correspondence table LUT401 is the binary value 1010 which indicates that test 200 is not verified. It is not possible for the data word T_WordF401 to be equal to the other values ​​proposed by the LUT403 correspondence table, so it was arbitrarily chosen that when the data word T_WordF401 is equal to one of these values ​​the output data of the LUT403 correspondence table is the binary value 0000.The binary value 0000 therefore indicates that the test was not executed correctly, and may allow, for example, the detection of an attack.

[0070] [Fig. 5] illustrates a practical example 500 of the method 300 for implementing the test 200 described in relation to [Fig. 2]. [Fig. 5] illustrates, in particular, the case of dividing the data word to be tested into parts of different sizes.

[0071] In the example of [Fig.5], the test carried out is the verification of the equality between the data word to be tested Tested_Word501 and a reference data word equal to 10110. The data word to be tested Tested_Word501 therefore comprises five bits B1, B2, B3, B4 and B5.

[0072] In the example of [Fig.5], it was decided to divide the data word to be tested Tested_Word501 into a part T_Word5011 comprising bits B1 and B2, and a part T_Word5012 comprising bits B3, B4 and B5.

[0073] To implement the first comparison step, the method 500 uses two correspondence tables LUT501 and LUT502.

[0074] The correspondence table LUT501 receives, as input, the part T_Word5011 and compares it with the bits 10. It has been arbitrarily chosen that when the part T_Word5011 is equal to 10, the output data of the correspondence table LUT501 is the binary value 01, and that when the part T_Word5011 is different from 10 the output data of the correspondence table LUT501 is the binary value 10.

[0075] The correspondence table LUT502 receives, as input, the part T_Word5012 and compares it with the bits 110. It has been arbitrarily chosen that when the part T_Word5012 is equal to 110 the output data of the correspondence table LUT502 is the binary value 10, and that when the part T_Word5012 is different from 110 the output data of the correspondence table LUT502 is the binary value 00.

[0076] As described above, the lookup tables LUT501 and LUT502 output the values ​​corresponding to the comparisons of the parts T_Word5011 and T_Word5012 with the data 10 and 110 to a final lookup table LUT503. According to one example, the output values ​​of the lookup tables LUT501 and LUT502 are concatenated into a data word T_WordF501.

[0077] In the example illustrated in [Fig.5], test 200 is verified only if the data word T_WordF501 is equal to 0110. Thus, the final correspondence table LUT503 compares the data word T_WordF501 with the bits 0110. It has been arbitrarily chosen that when the data word T_WordF501 is equal to 0110 the output data of the correspondence table LUT503 is the binary value 1111, and that when the data word T_WordF501 is equal to 0100, 1000 or 1010 the output data of the correspondence table LUT501 is the binary value 1010 which indicates that test 200 is not verified. As before, it is not possible for the data word T_WordF501 to be equal to the other values ​​proposed by the correspondence table LUT503, so it has been arbitrarily chosen that when the data word T_WordF501 is equal to one of these values ​​the output data of the correspondence table LUT503 is the binary value 0000.The binary value 0000 therefore indicates that the test was not executed correctly, and may allow, for example, the detection of an attack.

[0078] [Fig. 6] illustrates a practical example 600 of the method 300 for implementing the test 200 described in relation to [Fig. 2]. [Fig. 5] illustrates, in particular, the case of dividing the data word to be tested into more than two parts.

[0079] In the example of [Fig.6], the test carried out is the verification of the equality between the data word to be tested Tested_Word601 and a reference data word equal to 101101. The data word to be tested Tested_Word601 therefore comprises six bits B1, B2, B3, B4, B5 and B6.

[0080] In the example of [Fig.6], it was decided to divide the data word to be tested Tested_Word601 into a part T_Word6011 comprising bits B1 and B2, into a part T_Word6012 comprising bits B3 and B4, and into a part T_Word6013 comprising bits B5 and B6.

[0081] To implement the first comparison step, the method 600 uses three correspondence tables LUT601, LUT602 and LUT603.

[0082] The correspondence table LUT601 receives, as input, the part T_Word6011 and compares it with bits 10. It has been arbitrarily chosen that when the part T_Word6011 is equal to 10, the output data of the correspondence table LUT601 is the binary value 0, and that when the part T_Word6011 is different from 10 the output data of the correspondence table LUT601 is the binary value 1.

[0083] The LUT602 correspondence table receives, as input, the part T_Word6012 and compares it with bits 11. It has been arbitrarily chosen that when the part T_Word6012 is equal to 11 the output data of the LUT602 correspondence table is the binary value 1, and that when the part T_Word6012 is different from 11 the output data of the LUT602 correspondence table is the binary value 0.

[0084] The LUT603 correspondence table receives, as input, the part T_Word6013 and compares it with the bits 01. It has been arbitrarily chosen that when the part T_Word6013 is equal to 01 the output data of the LUT603 correspondence table is the binary value 1, and that when the part T_Word6013 is different from 01 the output data of the LUT603 correspondence table is the binary value 0.

[0085] As described above, the lookup tables LUT601, LUT602 and LUT603 output the values ​​corresponding to the comparisons of the parts T_Word6011, T_Word6012 and T_Word6013 with the data 10, 11 and 01 to a final lookup table LUT604. According to one example, the output values ​​of the lookup tables LUT601, LUT602 and LUT603 are concatenated into a data word T_WordF601.

[0086] In the example illustrated in [Fig.6], test 200 is verified only if the data word T_WordF601 is equal to 011. Thus, the final correspondence table LUT604 compares the data word T_WordF601 with the bits 011. It has been arbitrarily chosen that when the data word T_WordF601 is equal to 011 the output data of the correspondence table LUT604 is the binary value 11, and that when the data word T_WordF601 is different from 011, the output data of the correspondence table LUT601 is the binary value 10 which indicates that test 200 is not verified.

[0087] [Fig.7] illustrates a practical example 700 of the method 300 for implementing the test 200 described in relation to [Fig.2]. [Fig.5] illustrates, in particular, the case of comparing the data word to several reference data words.

[0088] In the example of [Fig.7], the test carried out is the verification of the equality between the data word to be tested Tested_Word701 and a reference data word equal to 101101 or a reference data word equal to 100100. The data word to be tested Tested_Word701 therefore comprises six bits B1, B2, B3, B4, B5 and B6.

[0089] In the example of [Fig.7], it was decided to divide the data word to be tested Tested_Word701 into a part T_Word7011 comprising bits B1 and B2, into a part T_Word7012 comprising bits B3 and B4, and into a part T_Word7013 comprising bits B5 and B6.

[0090] To implement the first comparison step, the method 700 uses three correspondence tables LUT701, LUT702 and LUT703.

[0091] The correspondence table LUT701 receives, as input, the part T_Word7011 and compares it with the bits 10. It has been arbitrarily chosen that when the part T_Word7011 is equal to 10, the output data of the correspondence table LUT701 is the binary value 1, and that when the part T_Word7011 is different from 10 the output data of the correspondence table LUT701 is the binary value 0.

[0092] The correspondence table LUT702 receives, as input, the part T_Word7012 and compares it with the bits 11 or with the bits 01. It has been arbitrarily chosen that when the part T_Word7012 is equal to 11 the output data of the correspondence table LUT702 is the binary value 10, and that when the part T_Word7012 is equal to 01 the output data of the correspondence table LUT702 is the binary value 11. In addition, when the part T_Word7012 is different from 11 and 01 the output data of the correspondence table LUT702 is the binary value 00.

[0093] The correspondence table LUT703 receives, as input, the part T_Word7013 and compares it with the bits 01 or with the bits 00. It has been arbitrarily chosen that when the part T_Word7013 is equal to 01 the output data of the correspondence table LUT703 is the binary value 11, and that when the part T_Word7013 is equal to 00 the output data of the correspondence table LUT703 is the binary value 10. In addition, when the part T_Word7013 is different from 01 and 00 the output data of the correspondence table LUT703 is the binary value 00.

[0094] As described previously, the lookup tables LUT701, LUT702 and LUT703 output the values ​​corresponding to the comparisons of the parts T_Word7011, T_Word7012 and T_Word7013 with the data 10, 11 and 01 or 10, 01 and 00 to a final lookup table LUT704. According to one example, the output values ​​of the lookup tables LUT701, LUT702 and LUT703 are concatenated into a data word T_WordF701.

[0095] In the example illustrated in [Fig.7], test 200 is checked if the data word T_WordF701 is equal to 11110 or 11011. Thus, the final correspondence table LUT704 compares the data word T_WordF701 with the bits 11110 and 11011. It has been arbitrarily chosen that when the data word T_WordF701 is equal to 11110 or 11011 the output data of the correspondence table LUT704 is the binary value 10, and that when the data word T_WordF701 is different from 11110 and 11011, the output data of the correspondence table LUT701 is the binary value 01 which indicates that test 200 is not verified. As before, it is not possible for the data word T_WordF701 to be equal to the other values ​​proposed by the correspondence table LUT704, it was therefore arbitrarily chosen that when the data word T_WordF701 is equal to one of these values, the output data of the correspondence table LUT703 is the binary value 00. The binary value 00 therefore indicates that the test was not executed correctly, and can allow for example the detection of an attack.

[0096] Various embodiments and variations have been described. Those skilled in the art will understand that certain features of these various embodiments and variations could be combined, and other variations will occur to those skilled in the art.

[0097] Finally, the practical implementation of the embodiments and variants described is within the reach of those skilled in the art from the functional indications given above.

Claims

Claims

1. Method for implementing, by an electronic device comprising a processor, a test (200) for comparing a first data word (Tested_Word) with at least one second data word (Ref_Words), comprising the following successive steps: - dividing said first data word (Tested_Word) into at least two parts (T_Wordj); - comparing each of said at least two parts (T_Wordj) of said first data word (Tested_Word) with at least two corresponding parts of said at least one second data word (Ref_Words), using, for each comparison, a first correspondence table (LUTj); - comparing the results of each of said first correspondence tables using a second correspondence table (F_LUT).

2. Method according to claim 1, wherein each result of said first correspondence tables (LUTj) is a third binary word (Aj[pq]).

3. The method of claim 2, wherein said third binary word (Aj[pq]) comprises one bit.

4. The method of claim 2, wherein said third binary word (Aj[pq]) comprises at least two bits.

5. A method according to any one of claims 1 to 4, wherein each of said at least two parts (T_Wordj) of said first data word comprises at least two bits, and each of said at least two corresponding parts of said at least one second data word comprises at least two bits.

6. Method according to any one of claims 1 to 5, wherein said test (200) is selected from the group comprising: a logical equality test, a logical test of type "greater than", a logical test of type "greater than or equal", a logical test of type "less than", a logical test of type "less than or equal", a logical test of type "is between", a test of divisibility of an integer by another integer, a logical test concerning the Hamming weight of a binary data, and any combination of one or more of these preceding tests between them.

7. A method according to any one of claims 1 to 6, wherein the results of each of said first lookup tables are concatenated into a fourth data word (T_WordF) to be compared using said second lookup table (F_LUT).

8. Electronic device, comprising a processor, adapted to implement a test (200) for comparing a first data word (Tested_Word) with at least one second data word (Ref_Words), comprising the following successive steps: - dividing said first data word (Tested_Word) into at least two parts (T_Wordj); - comparing each of said at least two parts (T_Wordj) of said first data word (Tested_Word) with at least two corresponding parts of said at least one second data word (Ref_Words), using, for each comparison, a first correspondence table (LUTj); - comparing the results of each of said first correspondence tables using a second correspondence table (F_LUT).

9. Device according to claim 8, in which each result of said first correspondence tables (LUTj) is a third binary word (Aj[pq]).

10. Device according to claim 9, wherein said third binary word (Aj[pq]) comprises one bit.

11. Device according to claim 9, wherein said third binary word (Aj[pq]) comprises at least two bits.

12. A device according to any one of claims 8 to 11, wherein each of said at least two parts (T_Wordj) of said first data word comprises at least two bits, and each of said at least one corresponding part of said at least one second data word comprises at least two bits.

13. Device according to any one of claims 8 to 12, wherein said test (200) is selected from the group comprising: a logical equality test, a logical test of the “greater than” type, a logical test of the “greater than or equal” type, a logical test of the “less than” type, a logical test of the “less than or equal” type, a logical test of the “is between” type, a test of divisibility of an integer by another integer, a logical test concerning the weight of

14. Hamming of a binary data, and any combination of one or more of these previous tests between them. Device according to any one of claims 8 to 13, wherein the results of each of said first look-up tables are concatenated into a fourth data word (T_WordF) to be compared using said second look-up table (F_LUT).

Citation Information

Patent Citations

  • Verification of the resistance of an electronic circuit to covert channel attacks

    EP3139365A1

  • Method for partitioning a block of data into subblocks and for storing and communicating such subblocks

    WO1996025801A1