Hidden Compression

By dividing sensitive data into parts and applying rounding and pseudo-fractional operations, the method ensures compatibility between masking and compression, effectively protecting against side-channel attacks while maintaining data integrity.

FR3160834A1Pending Publication Date: 2025-10-03STMICROELECTRONICS INT NV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
FR2024003181
Authority / Receiving Office
FR · FR
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-03-28
Publication Date
2025-10-03

AI Technical Summary

Technical Problem

Masking operations are not compatible with compression operations, leading to ineffective protection against side-channel attacks during cryptographic operations involving sensitive data.

Method used

A method involving digital algorithms to divide sensitive data into parts, apply rounding and pseudo-fractional operations, and generate corrected compressed data through correction operations, ensuring compatibility between masking and compression.

Benefits of technology

Enables secure compression of sensitive data without altering its value, providing additional protection against side-channel attacks by maintaining the integrity of the data sum and enhancing cryptographic security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

Masked Compression The present description relates to a method comprising:- masking, on the basis of a digital algorithm, by a processing device (102, 104), a sensitive data item, the masking comprising dividing the data item into a number greater than or equal to 2 of parts, such that their arithmetic sum, modulo an integer associated with the digital algorithm, is equal to the value of the data item;- applying a compression operation to each of the data parts, comprising: applying a rounding operation to each of the data parts, resulting in integer rounding values; and applying a pseudo-fractional operation to each of the data parts, resulting in pseudo-fractional values; and- generating corrected compressed data parts by applying a correction operation to each of the rounding values, on the basis of the pseudo-fractional values. Figure for abstract: Fig. 1
Need to check novelty before this filing date? Find Prior Art

Description

Title of the invention: Masked compression Technical field

[0001] The present description relates generally to the field of cryptography and in particular to the field of compression of encrypted data. Prior art

[0002] A side channel attack carried out during a cryptographic operation involving sensitive data, such as an encryption key, can allow an external entity to deduce the value of the sensitive data.

[0003] One way to protect against these attacks is to mask sensitive data by dividing it into several shares. However, in some cases, it is also desirable to compress sensitive data, for example during encapsulation or decapsulation operations. However, masking operations are not compatible with compression operations, and combining masking and compression operations is not effective because it does not allow a result to be obtained without performing many operations.

[0004] There is a need to make masking operations and compression operations compatible. Summary of the invention

[0005] One embodiment provides a method comprising: - the masking, on the basis of a digital algorithm, by a processing device, of sensitive data, the masking comprising the division of the sensitive data into a number n of parts, n being an integer equal to or greater than 2, such that their arithmetic sum, modulo an integer Q associated with the digital algorithm, is equal to the value of the sensitive data; - the application of a first compression operation of each of the n data parts, the first compression operation comprising: applying a rounding operation to each of the n data shares, resulting in n integer rounding values; and applying a pseudo-fractional operation, on each of the n data parts, resulting in 11 pseudo-fractional values; and - the generation of n parts of corrected compressed data by applying a correction operation on each of the n rounding values, based on the n pseudo-fractional values.

[0006] According to one embodiment, the arithmetic sum, modulo an integer P associated with the numerical algorithm, between the n parts corresponds to the compressed sensitive data, on the basis of a second compression operation, associated with the numerical algorithm, the second compression operation being based on a calculation of a rounding or truncation value of the form compressq,p^ , where |the value is an integer associated with the numerical algorithm, value P is an integer corresponding to a range of the form {0, 1, ■■■, / ?- 1} expected for the result of the second compression operation and the integer value r is a term defining the compression operation, the integer r being, for example: - equal to 0 when the second compression operation associated with the digital algorithm is a truncation operation; - equal to j when the second compression operation associated with the numerical algorithm is a rounding operation.

[0007] According to one embodiment, - the rounding operation, on a part xi of the sensitive data, corresponds to the calculation of the integer pu, — p , where r> is a truncation term associated with the part and [. J is the truncation operation to the equal or immediately lower integer; and - the pseudo-fractional operation, on the part xi corresponds to the calculation of the value / , = (XiP + r^mod q.

[0008] According to one embodiment, the sum of the n truncation terms is equal to the integer r

[0009] According to one embodiment, the n truncation terms are generated by a random number generator of the first device.

[0010] According to one embodiment, the correction operation comprises: - the determination of an integer c such that c is equal to the value j, i {0, ■ ■ ■ n - 1} when the sum of the pseudo-fractional values ​​ / 0 + ■ ■ ■ + / belongs to the interval [jq, (j +!) < / [; - the generation of a correction vector, of size n, such that the arithmetic sum modulo P of the n components of the correction vector is equal to the integer c; and - for each index ie {1, fl}, the addition of the i-th component of the correction vector to the rounding value int{ of the i-th part.

[0011] According to one embodiment, the processing device is configured to control the erasure of the n pseudo-fractional values ​​following the calculation of the correction vector.

[0012] According to one embodiment, the digital algorithm is a cryptographic scheme and the processing device is a cryptographic processor or a cryptographic coprocessor.

[0013] According to one embodiment, the cryptographic scheme is a network-based encapsulation scheme.

[0014] According to one embodiment, the network is an ML-KEM type network, an ML-DSA type network, a Kyber type network or a NewHope type network.

[0015] According to one embodiment, the number ,l is equal to 2.

[0016] According to one embodiment, the above method further comprises processing, by the processing device, n parts of corrected compressed data, the processing being for example part of a decapsulation operation.

[0017] Another embodiment provides a device comprising a processing device configured to: - applying masking, based on a digital algorithm, to sensitive data, the masking comprising dividing the sensitive data into a number n of parts, n being an integer equal to or greater than 2, such that their arithmetic sum, modulo an integer # associated with the digital algorithm, is equal to the value of the sensitive data; - apply a compression operation on each of the n data parts, the compression operation comprising: applying a rounding operation to each of the n data shares, resulting in f> integer rounding values; and applying a pseudo-fractional operation, on each of the n data shares, resulting in n pseudo-fractional values; and - generate n parts of corrected compressed data by applying a correction operation on each of the n rounding values, based on the n pseudofractional values.

[0018] According to one embodiment, the processing device is configured to apply the correction operation by doing: - the determination of an integer c such that c is equal to the value j, i{0, ■■■«-!} when the sum of the pseudo-fractional values ​​ / 0+ / ;;1 belongs to the interval [jq, (j + l) < / [. ; - the generation of a correction vector, of size n, such that the arithmetic sum modulo p of the n components of the correction vector is equal to the integer c; and - for each index i G {1, n}, the addition of the i-th component of the correction vector to the rounding value inti of the i-th part.

[0019] According to one embodiment, the processing device is configured to control the erasure of the n pseudo-fractional values ​​following the calculation of the correction vector.

[0020] According to one embodiment, the processing device is further configured to process the n corrected compressed data shares, for example in a decapsulation operation.

[0021] According to one embodiment, the digital algorithm is a cryptographic scheme and the processing device is a cryptographic processor or a cryptographic coprocessor. Brief description of the drawings

[0022] These characteristics and advantages, as well as others, will be explained in detail in the following description of particular embodiments given without limitation in relation to the attached figures among which:

[0023] [Fig.l] schematically represents an example of an electronic device of the type to which the described embodiments apply;

[0024] [Fig.2] is a block diagram illustrating an operation of compressing a masked data item, according to an embodiment of the present description; and

[0025] [Fig.3] is a flowchart illustrating steps of a method for compressing masked data, according to an embodiment of the present description. Description of the embodiments

[0026] The same elements have been designated by the same references in the different figures. In particular, the structural and / or functional elements common to the different embodiments may have the same references and may have identical structural, dimensional and material properties.

[0027] For the sake of clarity, only the steps and elements useful for understanding the described embodiments have been shown and are detailed. In particular, the network-based cryptography operations are not described in detail and are known to those skilled in the art. Similarly, the encapsulation and decapsulation operations are not described in detail.

[0028] Unless otherwise specified, when referring to two elements connected to each other, this means directly connected without intermediate elements other than conductors, and when referring to two elements connected (in English "coupled") to each other, this means that these two elements can be connected or be connected by means of one or more other elements.

[0029] In the following description, when reference is made to absolute position qualifiers, such as the terms "front", "back", "top", "bottom", "left", "right", etc., or relative position qualifiers, such as the terms "above", "below", "upper", "lower", etc., or to orientation qualifiers, such as the terms "horizontal", "vertical", etc., reference is made unless otherwise specified to the orientation of the figures.

[0030] Unless otherwise specified, the expressions "about", "approximately", "substantially", and "of the order of" mean to within 10% or 10°, preferably to within 5% or 5° close.

[0031] [Fig.l] schematically illustrates a device 100 according to one embodiment. The device 100 is for example a computer, a mobile telephone or even a smart card.

[0032] The device 100 comprises, for example, a main processor 102 (MAIN PROCESSOR), which is for example a host processor of the device 100 and a cryptographic coprocessor 104 (CRYPTOGRAPHIC COPROCESSOR). The device 100 further comprises a memory 106 (MEMORY) storing instructions 108 (INSTRUCTIONS) for controlling the main processor 102 and the cryptographic coprocessor 104. A communication interface 110 (COMMUNICATIONS INTERFACE) is, for example, coupled to the main processor 102, and allows, for example, wireless communications via a wireless communication network, and / or wired communications, for example via a LAN (Local Area Network, not shown).

[0033] The device 100, and in particular the cryptographic coprocessor 104, is for example adapted to carry out cryptographic operations. For example, the device 100 further comprises a random number generator 112 (RN GENERATOR) connected to the cryptographic coprocessor 104. In another example, the cryptographic coprocessor 104 is itself configured to carry out random number generation operations.

[0034] The cryptographic coprocessor 104 is for example configured to perform encapsulation operations, for example on the basis of a random key, generated by the number generator 112. By way of example, the encapsulation operations, executed by the cryptographic coprocessor 104, are carried out on the basis of a public encryption key, for example stored in the memory 106. In other examples, the public encryption key is stored securely in the cryptographic coprocessor 104.

[0035] The cryptographic coprocessor 104 is for example configured to encrypt data based on a cryptographic encryption algorithm, herein referred to as a “cryptographic scheme”. For example, a cryptographic scheme is, furthermore, a cryptographic algorithm distributed among several devices, for example configured to perform encapsulation and decapsulation operations based on an asymmetric key pair. For example, the cryptographic scheme is a network-based scheme, such as: - an ML-KEM scheme, from the English “Module-Lattice-Based Key-Encapsulation Mechanism”, described in the publication: NIST, Module-Lattice-Based Key-Encapsulation Mechanism Standard, FIPS 203 (Initial Public Draft), August 2023, doi: 10.6028 / NIST.FIPS.203.ipd; - an ML-DSA schema: NIST, Module-Lattice-Based Digital Signature Standard, FIPS 204 (Initial Public Draft), August 2023, doi:10.6028 / NIST.FIPS.204.ipd; - a Kyber schema: Roberto Avanzi, Joppe Bos, Léo Ducas, Eike Kiltz, Tancrède Lepoint, Vadim Lyubashevsky, John M. Schanck, Peter Schwabe, Gregor Seiler, and Damien Stehlé, CRYSTALS-Kyber Algorithm Specifications And Supporting Documentation (2012), Version 2021 https: / / pq-crystals.org / kyber / data / kyber-specification-round3-20210804.pdf ; or - a NewHope scheme: Erdem Alkim, Roberto Avanzi, Joppe Bos, Léo Ducas, Antonio de la Piedra, Thomas Pôppelmann, Peter Schwabe, Douglas Stebila, Martin R. Albrecht, Emmanuela Orsini, Valéry Osheter, Kenneth G. Paterson, Guy Peer, Nigel P.Hope. Documentation (version 1.1), 2020, https: / / newhopecrypto.org / data / NewHope_2020_04_10.pdf.

[0036] Generally, the cryptographic scheme includes an integer data compression operation.

[0037] The cryptographic coprocessor 104 is further configured to perform masking operations. For example, the masking operation occurs before the device 100 transmits, for example via the interface 110, a native data item, for example the encrypted random key, to another device. The native data item is for example a sensitive data item and it is not desirable for its value to be known for example by devices other than the device 100. In particular, it is important to ensure protection against side-channel attacks on the so-called sensitive data manipulated by the cryptographic coprocessor 104. The masking operation of a native data item corresponds to its division into a number 11 of shares, n being an integer. For example, n is equal to 2. In another example, the number n is at least equal to 3.In particular, the n data shares are randomly generated, so that their sum is equal to the native data. In particular, each value of a data share is independent of the value of the native data. Thus, observations of the values ​​of "-1" data shares, for example during a side-channel attack, do not reveal any information about the value of the native data.

[0038] A Boolean type masking uses the exclusive-OR operation, denoted ® , to divide a value A into ,l random values ​​x>^, such that x = ® @ Un Arithmetic type masking uses an addition operation modulo an arbitrary number #. The value of the data x and the parts A«-i are such that X = (x0 + ■ ■ ■ + xn_ |) mod q- The type of masking performed is for example chosen according to the calculations to be performed on a native data, in accordance with the implemented cryptographic scheme. Masking operations are stable by linear transformation, linearity being understood according to the addition operation chosen in the masking. That is to say that a masking of the data x to which a linear transformation is applied, corresponds to the application of this same linear transformation to each part xi, ze {0, ■ ■ ■, n - 1}. However, the masking operations are not stable by non-linear transformation. The different types of masking, as well as their implementations are known to the person skilled in the art.

[0039] The cryptographic coprocessor 104 is further configured to perform compression operations, for example, on encrypted data. The compression operations are, for example, performed for the purpose of reducing the size of the data before, for example, transmitting it to another device.

[0040] However, the usual compression operations correspond to a calculation of a rounding value. Rounding operations are non-linear operations and are therefore not compatible with masking operations. In particular, for a compression operation f-Ompress defined as being the calculation of a rounding or truncation value on the basis of a data value, the compressed value com press (x) is not equal to the sum of the compressed values ​​compress^x^ of each part. Thus, when a device receives, from device 100, the compressed values ​​compress(Xj ), J (0, ■ • •, n - 1}, it can only reconstruct the compressed value \ For example, a compression operation comP* e!iSq^r csl tepe that, for a data value x, compressw,(x) - \mod p- where the operation [. ] is the truncation to the equal or immediately lower integer value. The value # is an integer associated with the cryptographic scheme used.For example, the value of the number Q is chosen upstream, for example by the manufacturer of the cryptographic coprocessor 104 or more generally of the device 100. The value P is an integer corresponding to the range, of the form {0, 1, ■ ■ ■, p - 1], expected for the result of the compression operation performed. For example, the value of the integer P is chosen upstream, for example by the manufacturer of the cryptographic coprocessor 104 or more generally of the device 100. The integer value r is a term defining the compression operation. In particular, if r is equal to 0, then the compression operation corresponds to a truncation and if r is equal to j the compression operation corresponds to a rounding. According to one embodiment, the cryptographic coprocessor 104 is configured to perform compression operations, for example by executing the instructions 108, compatible with the masking operations.Thus, the sum of the values ​​compressed, by the cryptographic coprocessor 104, of each part \ i G { 0, ■ ■ ■, n - 1], corresponds to the compressed value of the data x. .

[0041] [Fig.2] is a block diagram illustrating a compression operation of a hidden data, according to an embodiment of the present description.

[0042] The compression operation is for example implemented in software. For example, the instructions 108 are configured to be executed by the cryptographic coprocessor 104 in order to generate, on the basis of n parts ig {0, ■ ■ ■, n - 1} of a data A, a number n of compressed and corrected parts y In the example illustrated by figure 2, the number n of parts is equal to 2.

[0043] For example, the parts Az, z G {0, ■■■, n - 1} are generated, by the cryptographic coprocessor 104, following a masking operation, for example using an arithmetic type masking on the data A.

[0044] According to one embodiment, for each of the parts Az, i G {0, ■ ■ ■, n - 1), a rounding value inq as well as a pseudo-fractional value f. are calculated by the cryptographic coprocessor 104. The rounding values ​​and the pseudo-fractional values ​​are for example calculated by applying a separation function 200 (SPLIT).

[0045] According to one embodiment, for a part A', z G {0, ■■■,«- 1], the separation function applied is a splitp^ function such that split!pq(yX-) — ( int f ')' [Math 1] inq = [ ] mod p, and [Math 2] y — mod q, and where the operation [. ] is the truncation to the integer value equal or immediately lower. The value # is the integer associated with the cryptographic scheme used and corresponds in particular to the value used for the arithmetic masking of the shares xi. In particular, the value is the same as that defined in relation to the operation comp^ 0c same, the value P is the same as that defined in relation to the operation compressa,PJ- The integer value 1 i is a truncation term, associated with the share Az. The n truncation terms f & ' ' are such that their sum ' " + rn-i modulo Pd is for example equal to the value r, defined in relation to the operation ^comptessq,p^ (jlrc example, in the case where n — 2 and where f — j, the terms ro and ri are such that z'o = 0 and jy — j, in another example, j is an even value and the terms ro and ri are such that j — fp etc. In the general case, where the integer n is greater than or equal to 2, one of the truncation terms is for example equal to 4 j and all the others are null, in another example, II is a value divisible by 11 and all the terms are equal to I 4L I, etc. L 2 J 1 2w J Generally, any values ​​are possible for the terms 1 i, ? G {0, ■ ■ ■, n - 1} as long as their sum is equal to the value r. In particular, when the value r is equal to 0, the terms r< are, for example, all null. In another example, their sum modulo PC1 is equal to 0.

[0046] In other examples, the terms ig {0, ■ ■ ■, n - 1}, are generated randomly, for example by the random number generator 112. For example, the terms are generated on the fly, following each execution command of the instructions 108. Thus, for two different data x and X, the truncation terms associated with the parts and -¾ ■ ■ ■, £„4 vary. This random generation of the truncation terms provides additional protection against side-channel attacks.

[0047] The pseudo-fractional values ​​ / z G {0, ■ ■ ■, n - 1} each belong to the set {(), ■ ■ ■, (n - 1 )q}.

[0048] According to one embodiment, the cryptographic coprocessor 104 is further configured to calculate n correction values ​​ci, i G {0, ■■■, n- 1], on the basis of the Jl pseudo-fractional values ​​yfe |o ■ ■ ■ n - 11- As an example, the calculation of the correction values ​​is performed by applying a correction operation 202 (CORRECT) to the n pseudo-fractional values.

[0049] According to one embodiment, the correction values ​​O, z G {0, ■ ■ ■, n - 1}, are integer values ​​belonging to the set {0, ■ ■ - , p - 1} and constitute arithmetic parts modulo P of an integer c belonging to the set {0, ..., h - 1} • In other words, c — + c1 + ... + c,^imod p — j G 0, ..., n - 1. In particular, the integer c is equal to the value j, jg {0, ■ ■ ■ n - 1} when the sum of the pseudofractional values ​​ / 0+ j belongs to the interval [jq, (y+l)^[.

[0050] For example, when n — 2, an implementation of the correction function comprises the calculation of a vector § corresponding to the sum of the pseudofractional values, reduced by the value 4, under arithmetic masking modulo a number greater than or equal to 2q. For example, the vector S is equal to [ fnf \ \J 0 h JU In another example, the vector 8 is equal to (p-qlZp-qP) The calculation of correction values ​​further includes the calculation of a sign vector s. For example, the vector,ç is equal to the complement of the Boolean vector MSB( A2B(g) ), where the MSB operation corresponds to the selection of the most significant bit of each element of the provided vector and where the A2B operation corresponds to the conversion of an arithmetic masking, modulo a number greater than or equal to 2q, to ​​a Boolean masking. The correction values ​​are then obtained by converting the Boolean vector s to an arithmetic masking modulo P. In other words, a correction vector ■ ■ ■, cnA ), having as components the n correction values, is such that c = B2A(s), where the operation B2A is the conversion of Boolean values ​​to arith- metrics.

[0051] The person skilled in the art will know how to adapt the implementation of the correction function in the case where n is strictly greater than 2 from the functional indications of the present description, such as the correction values ​​ct mentioned above.

[0052] For example, once the correction vector c has been calculated, the cryptographic coprocessor 104 is configured to delete the pseudo-fractional values ​​ / 0, ■ ■ ■, / r for example stored in a buffer memory of the coprocessor 104.

[0053] According to one embodiment, the cryptographic coprocessor 104 is further configured to calculate, for any ig [0, ■ ■ ■, n - 1], a corrected compressed part 3} by adding (+) the correction value cî to the rounding value inth, the addition being considered modulo P.

[0054] The corrected compressed parts y,, i G {0, ■■■ r n- 1} are then such that their sum modulo P corresponds to the compressed data x, that is to say to compressq.pj (x} = mod p-

[0055] [Fig. 3] is a flowchart illustrating steps of a method for compressing masked data, according to an embodiment of the present description.

[0056] In a step 300 (GENERATE MASKED SECRET), a sensitive data item x is, for example, manipulated by the cryptographic coprocessor 104. For example, the sensitive data item is an intermediate variable of a cryptographic scheme. For example, the sensitive data item x is a value following a re-encryption in a step of verifying the integrity and / or authenticity of a data item.

[0057] In particular, the sensitive data is data masked according to arithmetic masking modulo ¢. The sensitive data x comprises for example a number n of parts (x0, ..., X„_|)- In another example, the sensitive data is unmasked data. The cryptographic coprocessor 104 is then configured to apply arithmetic masking modulo <7 to this value, by generating, for example via the random number generator 112, n -1 random numbers • • • ' %h-2 between 0 and t / -1. The cryptographic coprocessor 104 is then configured to generate the part xn-i such that ~ x " ro " AT " ' “ xn-2. Generally, the cryptographic coprocessor 104 is configured to generate n parts (xq, ..., xM_j) of the data x such that + ... + -Vi mod q = x.

[0058] In a step 301 (SPLIT), the cryptographic coprocessor 104 is configured to apply the separation operation 200 to each of the parts xi, i G {0, ■■■, w-1}. The rounding values ​​m / ,- and the pseudo-fractional valuesz G {0, •••, 77-1}, as described in relation to [Fig.2] are then obtained. By way of example, the cryptographic coprocessor 104 is further configured to store, for example in a buffer memory, the rounding values ​​and the pseudo-fractional values.

[0059] In a step 302 (CORRECT), the cryptographic coprocessor 104 is configured to calculate the correction values ​​c', i.e. {0, ■ ■ ■, n - 1), by calculating for example the correction vector c, as described in relation to FIG. 2. By way of example, following the calculation of the vector c, the pseudo-fractional values ​​are deleted from the memory in which they were stored. The cryptographic coprocessor 104 is further configured to, when performing step 302, generate the corrected compressed parts i.e. [0, ■ ■ ■, n - 1], by adding to each rounding value int^ i.e. {0, ■■■,«-!} the correction value ct modulo P.

[0060] In a step 303 (USE COMPRESSED SECRET), the cryptographic coprocessor 104 is for example configured to use the corrected compressed data shares y^ i G {0, ■ ■ ■, n - 1}. By way of example, the cryptographic coprocessor 104 is configured to use the corrected compressed data shares in a series of operations included in the cryptographic scheme in order to generate an output data item, for example encrypted. As a variant, when the cryptographic scheme is an ML-KEM or Kyber scheme, the cryptographic coprocessor 104 is configured to compare, in a decapsulation step, the corrected compressed data shares with an encrypted data item, for example transmitted by another device and to generate an output signal indicating the result of this comparison.

[0061] It would also be possible to transmit the corrected compressed data to another device, for example after encryption in the case of sensitive data.

[0062] In another example, the cryptographic coprocessor 104 is configured to sum, modulo P, the corrected compressed data shares to generate and output an unmasked result of the compressed value x. The compressed value x is then, for example, used in a sequence of operations included in the cryptographic scheme to generate an output data.

[0063] An advantage of the described embodiments is that they allow masked data to be compressed, without altering the value of the native data. In particular, the described embodiments allow the generation of compressed and corrected data parts whose sum modulo a value P corresponds to the compressed data. The combination of masking and compression operations has the advantage of providing additional protection against side-channel attacks.

[0064] Another advantage of the described embodiments is that the separation and correction operations described in relation to [Fig.2] are compatible with different cryptographic schemes.

[0065] Various embodiments and variations have been described. Those skilled in the art will understand that certain features of these various embodiments and variations could be combined, and other variations will occur to those skilled in the art. In particular, with respect to the choice of truncation terms, any com combination of positive or zero values ​​is possible, provided that their sum is equal to the value r, defined in the compression operation compt pr . Similarly, the calculation of the correction vector can take several forms, provided that it corresponds to an arithmetic masking modulo P of the value j when the sum of the pseudo-fractional values ​​ / 0+ ' ' A belongs to the interval

[0066] Finally, the practical implementation of the embodiments and variants described is within the reach of the person skilled in the art from the functional indications given above. In particular, with regard to the cryptographic scheme used. In addition, although encapsulation and decapsulation operations have been described, the separation and correction operations described in relation to [Fig. 2] apply in any context where it is desirable to protect the value of a data item against side-channel attacks. For example, these operations also apply in layer operations of a neural network, for example in sub-sampling operations.In non-cryptographic applications such as secure computations on neural networks, it will be possible to replace the cryptographic scheme with another type of numerical algorithm, and to omit the cryptographic coprocessor, the masking being carried out for example by a processing device, such as the main processor 102.

Claims

Claims

1. A method comprising: - masking, based on a digital algorithm, by a processing device (102, 104), a sensitive data item (x), the masking comprising dividing the sensitive data item into a number n of parts ( xo ■ ■ ■, n being an integer equal to or greater than 2, such that their arithmetic sum, modulo an integer # associated with the digital algorithm, is equal to the value of the sensitive data item; - applying a first compression operation to each of the n data parts, the first compression operation comprising: applying a rounding operation to each of the n data parts, resulting in n integer rounding values ​​(intQ, ■ ■ ■, int^ ;and applying a pseudo-fractional operation, on each of the n data shares, resulting in n pseudo-fractional values ​​(and - generating n corrected compressed data shares) by applying a correction operation on each of the n rounding values, based on the n pseudo-fractional values.;

2. The method of claim 1, wherein the arithmetic sum, modulo an integer P associated with the numerical algorithm, between the n parts ( corresponds to the compressed sensitive data (x), on the basis of a second compression operation (compresSq.pr), associated with the numerical algorithm, the second compression operation being based on a calculation of a rounding or truncation value of the form comPress^pr , where the value ? is an integer associated with the numerical algorithm, value P is an integer corresponding to a range of the form {0, h ■ ■ ■, p - 1} expected for the result of the second compression operation and the integer value r is a term defining the compression operation, the integer r being, for example: - equal to 0 when the second compression operation associated with the numerical algorithm is a truncation operation; - equal to j when the second compression operation associated with the numerical algorithm is a rounding operation.

3. Method according to claim 2, in which: - the rounding operation, on a part xi of the sensitive data, corresponds to the calculation of the integer in[. — jnwd p , °where r' is a term of

4.

5.

6.

7.

8.

9.

10.

11.

12. truncation associated with the part xt and [. J is the truncation operation towards the equal or immediately lower integer; and - the pseudo-fractional operation, on the part xi corresponds to the calculation of the value f. = ( xtp + r; ) mod q The method of claim 3, wherein the sum of the n truncation terms (ro rn-ï) is equal to the integer r. The method of claim 4, wherein the n truncation terms ( ' ' ' ' rn-i) are generated by a random number generator (112) of the first device (100). A method according to any one of claims 2 to 5, wherein the correction operation (202) comprises: - the determination of an integer c such that c is equal to the value j, i {0, ■■■»-[} when the sum of the pseudo-fractional values ​​f0 + ' ' + fnA belongs to the interval [jq, (j + IM ; - the generation of a correction vector (c<> " ' cn-^, of size ”, such that the arithmetic sum modulo P of the ” components of the correction vector is equal to the integer c; and - for each index ie[l, n}, the addition of the i-th component (ci) of the correction vector to the rounding value inti of the i-th part (x”). Method according to claim 6, in which the processing device (102, 104) is configured to control the erasure of the “pseudo-fractional values” following the calculation of the correction vector. A method according to any one of claims 1 to 7, wherein the digital algorithm is a cryptographic scheme and the processing device is a cryptographic processor or a cryptographic coprocessor. The method of claim 8, wherein the cryptographic scheme is a network-based encapsulation scheme. The method of claim 9, wherein the network is an ML-KEM type network, an ML-DSA type network, a Kyber type network or a NewHope type network. A method according to any one of claims 1 to 10, wherein the number ” is equal to 2. A method according to any one of claims 1 to 11, further comprising processing, by the processing device (102, 104), the corrected compressed data portions (¾ ' ' ' ' -V,^), the processing being for example part of a decapsulation operation.

13. Device (100) comprising a processing device (102, 104) configured to: - apply a masking, based on a digital algorithm, on a sensitive data item (x), the masking comprising the division of the sensitive data item into a number n of parts (xo " ' n being an integer equal to or greater than 2, such that their arithmetic sum, modulo an integer 9 associated with the digital algorithm, is equal to the value of the sensitive data item; - apply a compression operation on each of the n data items, the compression operation comprising: the application of a rounding operation on each of the n data items, resulting in n integer rounding values ​​■ ■ ■, int,^ ;and applying a pseudo-fractional operation, on each of the n data shares, resulting in n pseudo-fractional values ​​( 4' " ' / nJ ' and - generating n corrected compressed data shares (3V " ' ' 3^) by applying a correction operation (202) on each of the n rounding values, based on the n pseudo-fractional values.;

14. Device according to claim 13, wherein the processing device (102, 104) is configured to apply the correction operation by: - ​​determining an integer c such that c is equal to the value j, js {0, ■ ■ ■ n - 1} when the sum of the pseudo-fractional values ​​fQ + ' ' ' + f„ j belongs to the interval [jq, (J + l)^. ; - generating a correction vector (co > cn-i\ of size n, such that the arithmetic sum modulo p of the n components of the correction vector is equal to the integer c; and - for each index i G {1, n}, adding the i-th component (ci) of the correction vector to the rounding value of the i-th part (xi).

15. Device according to claim 13 or 14, in which the processing device (102, 104) is configured to control the erasure of the n pseudo-fractional values ​​following the calculation of the correction vector.

16. A device according to any one of claims 13 to 15, wherein the processing device (102, 104) is further configured to process the n corrected compressed data shares (¾ " ' ' -^-1), for example in a decapsulation operation.

17. A device according to any one of claims 13 to 16, in in which the digital algorithm is a cryptographic scheme and the processing device is a cryptographic processor or cryptographic coprocessor.