Leakage information suppressing circuit

The leakage information suppression circuit addresses the insufficiencies of WDDL by using symmetric logic gates and self-timer circuits to stabilize power consumption and reduce signal delay, thereby enhancing resistance to side-channel attacks.

JP2025109566APending Publication Date: 2025-07-25OSAKA UNIVERSITY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2024003538
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-01-12
Publication Date
2025-07-25

AI Technical Summary

Technical Problem

Conventional Wave Dynamic Differential Logic (WDDL) circuits face challenges in completely reducing the dependency of measurable power consumption and signal delay on input data, making them insufficiently resistant to side-channel attacks due to asymmetric static CMOS circuits, imbalanced cell layouts, and variations in power and signal delay.

Method used

A leakage information suppression circuit incorporating a WDDL circuit with symmetric logic gates, precharge circuits, and self-timer circuits that output clock signals only when differential outputs are determined, ensuring balanced power consumption and reduced signal delay.

Benefits of technology

The proposed circuit significantly enhances resistance to side-channel attacks by minimizing power and signal delay dependencies on input data, ensuring stable operation and improved security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025109566000001_ABST
    Figure 2025109566000001_ABST
Patent Text Reader

Abstract

To easily improve resistance to side channel attacks.SOLUTION: A leakage information suppressing circuit 100, which is a WDDL circuit, comprises a plurality of logic gates 1, a plurality of precharge circuits 2, and one or more self-retimer circuits 3. Each of the plurality of precharge circuits 2 outputs two differential outputs having the same level during a precharge period, and outputs two differential outputs having different levels during a logic evaluation period to each of the plurality of logic gates 1. The one or more self-retimer circuits 3 do not output a clock signal until the two differential outputs from a preceding logic gate 1 are determined, and output the clock signal to operate a succeeding logic gate 1 when the two differential outputs are determined.SELECTED DRAWING: Figure 7
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a leakage information suppression circuit including a WDDL (Wave Dynamic Differential Logic) circuit.

Background Art

[0002] Non-Patent Document 1 discloses circuit design using WDDL.

[0003] Non-Patent Document 2 discloses performance evaluation of a circuit using WDDL.

Prior Art Documents

Non-Patent Documents

[0004]

Non-Patent Document 1

Non-Patent Document 2

Summary of the Invention

Problems to be Solved by the Invention

[0005] An object of the present invention is to provide a leakage information suppression circuit that is easily improved in resistance to side channel attacks.

Means for Solving the Problems

[0006] A leakage information suppression circuit according to an aspect of the present invention is a WDDL (Wave Dynamic Differential Logic) circuit, and includes a plurality of logic gates, a plurality of precharge circuits, and one or more self-timer circuits. Each of the plurality of precharge circuits outputs two differential outputs that are at the same level during the precharge period and two differential outputs that are at different levels from each other during the logic evaluation period for each of the plurality of logic gates. The one or more self-timer circuits do not output a clock signal until two differential outputs from a preceding logic gate are determined, and when the two differential outputs are determined, output the clock signal to operate a succeeding logic gate.

Advantages of the Invention

[0007] According to the leakage information suppression circuit of the present invention, there is an advantage that it is easy to improve the resistance to side-channel attacks.

Brief Description of the Drawings

[0008]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Figure 12

Figure 13

Figure 14

Figure 15

Figure 16

Figure 17

Figure 18

DETAILED DESCRIPTION OF THE INVENTION

[0009] [1. Findings on which the present invention is based] First, the inventor's point of view will be described below.

[0010] WDDL is one of the pioneering technologies in the field of circuit design for hardware security. WDDL includes, for example, an encryption circuit and its complementary circuit, and is a technology that cancels out the correlation between information to be concealed in a circuit, such as an encryption key, and power consumption by making the power consumption constant regardless of the input.

[0011] Logic gates in a WDDL circuit are implemented in a dual-rail differential logic form with a precharge (PC) circuit (see FIG. 4 described later). After performing a precharge operation, the WDDL circuit equalizes the power consumption by reducing the difference in the consumed current caused by the difference in the bit values during the operation by means of a complementary circuit. That is, in the WDDL circuit, the operation of any one of the two differential paths activated by each logic gate included in the WDDL circuit is guaranteed, and the switching probabilities of all the logic gates along the data path are made equal.

[0012] As disclosed in Non-Patent Document 2, a prototype of an AES (Advanced Encryption Standard) cryptographic processor based on WDDL shows a certain degree of resistance to side-channel attacks. However, in conventional WDDL, it is difficult to completely reduce the dependency of the measurable power consumption or signal delay on the input data. In other words, there is a problem that the resistance to side-channel attacks in conventional WDDL is not sufficient.

[0013] This is considered to be caused by 1) the data path of logic gates composed of asymmetric static CMOS circuits, 2) the imbalance in cell layout and the mismatch in inter-cell wiring in the encryption circuit, and 3) the accumulation of variations in power and signal delay between logic gates in a deep cryptographic logic path.

[0014] In view of the above, the inventor has created the present invention.

[0015] Hereinafter, the leakage information suppression circuit according to the embodiment will be specifically described with reference to the drawings.

[0016] Note that all of the embodiments described below show comprehensive or specific examples. The numerical values, shapes, materials, components, arrangement positions and connection forms of the components, steps, order of steps, etc. shown in the following embodiments are merely examples and are not intended to limit the scope of the claims. In addition, among the components according to the following embodiments, the components not described in the independent claims indicating the uppermost concept are described as optional components.

[0017] Also, each figure is a schematic diagram and is not necessarily drawn precisely. In each figure, the same reference numerals are given to the same constituent members.

[0018] [2. Composite S-Box] First, prior to describing the leakage information suppression circuit according to the embodiment, as an example of a circuit in which the leakage information suppression circuit according to the embodiment is used, the composite S-Box used in 128-bit AES will be described. The composite S-Box is a SubBytes conversion circuit that outputs 8 bits different from the input for an 8-bit input. The composite S-Box treats an 8-bit input as an element of the Galois field GF(2 8 )(the irreducible polynomial is x 8 +x 4 +x 3 +x + 1), calculates its multiplicative inverse, and outputs 8 bits by calculating the affine transformation of the multiplicative inverse.

[0019] FIG. 1 is a diagram showing the processing of the composite S-Box. As shown in FIG. 1, the composite S-Box first executes an operation of a homomorphism δ that converts an element of the Galois field GF(2 8 ) into an element of the Galois field GF(((2 2 ) 2 ) 2 ) (S1). Next, the composite S-Box executes an operation of calculating the multiplicative inverse of the Galois field GF(((2 2 ) 2 ) 2 ) (S2). Next, the composite S-Box executes an operation of calculating the multiplicative inverse of the Galois field GF(((2 2 ) 2 ) 2) elements to the elements of the Galois field GF(2 8 ) performs the inverse isomorphism transformation δ to convert to the elements of -1 . Then, the composite S-Box further performs an affine transformation (S4) to obtain an 8-bit output.

[0020] Figure 2 is a block diagram showing an example of a multiplicative inverse operation circuit using a Galois field. (a) of Figure 2 shows a multiplicative inverse operation circuit of the Galois field GF(((2 2 ) 2 ) 2 ), and (b) of Figure 2 shows a multiplicative inverse operation circuit of the Galois field GF((2 2 ) 2 ). In (a) of Figure 2, block A1 described as "x -1 " corresponds to the multiplicative inverse operation circuit of the Galois field GF((2 2 ) 2 ) shown in (b) of Figure 2. Also, in (a) of Figure 2, block A2 described as "×" corresponds to the multiplication circuit of the Galois field GF(2 2 ) shown in (b) of Figure 3 described later.

[0021] Also, in (a) of Figure 2, the block described as "x 2 " corresponds to a circuit that calculates the square of the Galois field GF((2 2 ) 2 ), the block described as "×λ" corresponds to a circuit that multiplies λ of the Galois field GF((2 2 ) 2 ), and the block described as "+" corresponds to an addition circuit of the Galois field GF((2 2 ) 2 ). Also, in (b) of Figure 2, the block described as "x 2 " corresponds to a circuit that calculates the square of the Galois field GF(2 2 ), the block described as "×φ" corresponds to a circuit that multiplies φ of the Galois field GF(2 2 ), and the block described as "+" corresponds to an addition circuit of the Galois field GF(2 2 ).

[0022] FIG. 3 is a block diagram showing an example of a multiplication circuit using a Galois field. (a) of FIG. 3 shows a multiplication circuit of a Galois field GF((2 2 ) 2 ), and (b) of FIG. 3 shows a multiplication circuit of a Galois field GF(2 2 ). In (a) of FIG. 3, block A3 described by "×" corresponds to the multiplication circuit of the Galois field GF(2 2 ) shown in (b) of FIG. 3. Also, in (a) of FIG. 3, the block described by "×φ" corresponds to a circuit that multiplies φ of the Galois field GF(2 2 ), and the block described by "+" corresponds to an addition circuit of the Galois field GF(2 2 ). Further, in (b) of FIG. 3, block A4 described by "+" corresponds to a 2-input XOR circuit, and block A5 described by "·" corresponds to a 2-input AND circuit.

[0023] [3. Leakage Information Suppression Circuit of Comparative Example] Next, the leakage information suppression circuit 200 of the comparative example will be described with reference to FIG. 4. FIG. 4 is a circuit diagram showing the leakage information suppression circuit 200 of the comparative example. The leakage information suppression circuit 200 of the comparative example corresponds to a circuit in which the multiplication circuit of the Galois field GF(2 2 ) shown in (b) of FIG. 3 is configured by a WDDL circuit. The leakage information suppression circuit 200 of the comparative example includes four differential XOR circuits 201, three differential AND circuits 202, and four precharge circuits 203 to which four true inputs "A[1]", "A[0]", "B[1]", "B[0]" are respectively input, and calculates two true outputs "O[0]", "O[1]".

[0024] The four differential XOR circuits 201 respectively correspond to the four blocks A4 described by "+" in the multiplication circuit of the Galois field GF(2 2 ) shown in (b) of FIG. 3. Each differential XOR circuit 201 has an XOR circuit 201A and a complementary XOR circuit 201B.

[0025] The XOR circuit 201A corresponds to an XOR circuit that calculates one true output for two true inputs and is composed of three NAND circuits. Here, the XOR circuit 201A calculates one true output "XOR" for two true inputs "A", "B" and two false inputs "A bar", "B bar". Note that "A bar" corresponds to "A" with a negation bar, and "B bar" corresponds to "B" with a negation bar.

[0026] The complementary XOR circuit 201B corresponds to a circuit that calculates one false output different from the output of the XOR circuit 201A and is composed of three NOR circuits. The complementary XOR circuit 201B is an additional circuit paired with the XOR circuit 201A. Here, the complementary XOR circuit 201B calculates one false output "XOR bar" for two true inputs "A", "B" and two false inputs "A bar", "B bar". Note that "XOR bar" corresponds to "XOR" with a negation bar.

[0027] The three differential AND circuits 202 each correspond to the three blocks A5 described by "·" in the multiplication circuit of the Galois field GF(2 2 ) shown in Fig. 3(b). Each differential AND circuit 202 has an AND circuit 202A and a complementary AND circuit 202B.

[0028] The AND circuit 202A corresponds to an AND circuit that calculates one true output for two true inputs and is composed of one NAND circuit and one NOT circuit. Here, the AND circuit 202A calculates one true output "AND" for two true inputs "A", "B".

[0029] The complementary AND circuit 202B corresponds to a circuit that calculates one false output different from the output of the AND circuit 202A, and is composed of one NOR circuit and one NOT circuit. The complementary AND circuit 202B is an additional circuit paired with the AND circuit 202A. Here, the complementary AND circuit 202B calculates one false output "AND bar" for two false inputs "A bar" and "B bar". Note that "AND bar" corresponds to "AND" with a negation bar attached.

[0030] FIG. 5 is a circuit diagram showing the precharge circuit 203 in the leakage information suppression circuit 200 of the comparative example. The four precharge circuits 203 are circuits that calculate two differential outputs "Out" and "Out bar" for one true input "In" and one false input "In bar", respectively, and are composed of two NAND circuits. One of the two NAND circuits calculates the output "Out bar" for the true input "In" and the clock signal "Clk". The other of the two NAND circuits calculates the output "Out" for the false input "In bar" and the clock signal "Clk". Note that "In bar" corresponds to "In" with a negation bar attached, and "Out bar" corresponds to "Out" with a negation bar attached.

[0031] In the leakage information suppression circuit 200 of the comparative example, in the precharge period when the operation is stopped in each precharge circuit 203, "Clk" becomes low level, and the two outputs become high level regardless of the input. Also, in the logic evaluation period when the operation is started in each precharge circuit 203, "Clk" becomes high level, and one of the two outputs switches to low level. Hereinafter, it will be described assuming that the high level is "1" and the low level is "0". That is, each precharge circuit 203 outputs two differential outputs that are at the same level during the precharge period, and outputs two differential outputs with different levels from each other during the logic evaluation period.

[0032] Thus, in the leakage information suppression circuit 200 of the comparative example, each precharge circuit 203 alternately repeats the precharge period and the logic evaluation period, thereby equalizing the power consumption in the leakage information suppression circuit 200 of the comparative example. For this reason, in the leakage information suppression circuit 200 of the comparative example, the dependency of power consumption on input data is suppressed, and the resistance to side channel attacks is improved.

[0033] Here, the plurality of logic gates (NAND circuits and NOR circuits) included in the leakage information suppression circuit 200 of the comparative example are all composed of static CMOS circuits. And in the leakage information suppression circuit 200 of the comparative example, since each of the plurality of logic gates is an asymmetric circuit, there is a problem that it is difficult to sufficiently suppress the dependency of power and signal delay on input data. Hereinafter, this problem will be described with reference to FIG. 6.

[0034] FIG. 6 is a circuit diagram showing an example of a static CMOS circuit. The circuit shown in FIG. 6 is a 2-input NAND circuit composed of a static CMOS circuit, and includes two enhancement-type pMOS transistors P1 connected in parallel to a reference voltage source to form a pull-up circuit, and two enhancement-type nMOS transistors N1 connected in series to the ground to form a pull-down circuit.

[0035] In the static CMOS circuit as shown in FIG. 6, any one of the two nMOS transistors N1 connected in series according to the two inputs "A" and "B" is turned on, but there is a difference in the distance (data path) that the signal propagates to the output according to the turned-on nMOS transistor N1. For this reason, in the static CMOS circuit as shown in FIG. 6, a difference in power and signal delay occurs due to the difference in the data path for each input, and it is difficult to sufficiently suppress the dependency of power and signal delay on input data.

[0036] [4. Leakage Information Suppression Circuit] Hereinafter, the leakage information suppression circuit 100 according to an embodiment capable of solving the problems of the leakage information suppression circuit 200 of the comparative example will be described with reference to FIG. 7. FIG. 7 is a circuit diagram showing an example of the leakage information suppression circuit 100 according to the embodiment. The circuit shown in FIG. 7 is a WDDL circuit 10, which corresponds to a circuit in which the multiplication circuit of the Galois field GF(2 2 ) shown in FIG. 3(b) is configured by the WDDL circuit 10, similar to the leakage information suppression circuit 200 of the comparative example. The WDDL circuit 10 includes a plurality (here, 7) of logic gates 1, a plurality (here, 10) of precharge circuits 2, and one or more (here, 3) self-timer circuits 3.

[0037] The plurality of logic gates 1 includes four differential XOR circuits 11 and three differential AND circuits 12. The four differential XOR circuits 11 respectively correspond to the four blocks A4 described as “+” in the multiplication circuit of the Galois field GF(2 2 ) shown in FIG. 3(b), similar to the leakage information suppression circuit 200 of the comparative example. The three differential AND circuits 12 respectively correspond to the three blocks A5 described as “·” in the multiplication circuit of the Galois field GF(2 2 ) shown in FIG. 3(b), similar to the leakage information suppression circuit 200 of the comparative example.

[0038] To the four precharge circuits 2A to 2D, four true inputs “A[1]”, “A[0]”, “B[1]”, and “B[0]” are input respectively, similar to the leakage information suppression circuit 200 of the comparative example. Also, to the two precharge circuits 2E and 2F, the two outputs of the two differential XOR circuits 11A and 11B are input respectively. Also, to the two precharge circuits 2G and 2H, the two outputs of the two differential AND circuits 12A and 12C are input respectively. Also, to the two precharge circuits 2I and 2J, the two outputs of the two differential AND circuits 12A and 12B are input respectively.

[0039] The differential XOR circuit 11A outputs two signals and the clock signal "Clk" are input to the self-timer circuit 3A. Also, the output signal of the self-timer circuit 3A corresponds to the clock signal in the precharge circuit 2E. The differential XOR circuit 11B outputs two signals and the clock signal "Clk" are input to the self-timer circuit 3B. Also, the output signal of the self-timer circuit 3B corresponds to the clock signal in the precharge circuit 2F. The differential AND circuit 12C outputs two signals and the clock signal "Clk" are input to the self-timer circuit 3C. Also, the output signal of the self-timer circuit 3C corresponds to the clock signal in each of the precharge circuits 2G to 2J.

[0040] FIG. 8 is a circuit diagram showing the differential XOR circuit 11 in the leakage information suppression circuit 100 according to the embodiment. Each differential XOR circuit 11 includes an XOR circuit 110 and a complementary XOR circuit 111. The XOR circuit 110 corresponds to an XOR circuit that calculates one true output for two true inputs. Here, the XOR circuit 110 calculates one true output "XOR" for two true inputs "A", "B" and two false inputs "A bar", "B bar". The XOR circuit 110 includes two nMOS transistors N1A, N1B, two pMOS transistors P1A, P1B, and one latch circuit L1 (here, the latch circuit L1A).

[0041] In the XOR circuit 110, the upper nMOS transistor N1A and pMOS transistor P1A form a PTL and function as a switch that determines whether to pass the true input "A" according to the false input "B bar". Also, in the XOR circuit 110, the lower nMOS transistor N1B and pMOS transistor P1B form a PTL and function as a switch that determines whether to pass the false input "A bar" according to the true input "B".

[0042] The complementary XOR circuit 111 corresponds to a circuit that calculates one false output different from the output of the XOR circuit 110. The complementary XOR circuit 111 is an additional circuit paired with the XOR circuit 110. Here, the complementary XOR circuit 111 calculates one false output "XOR bar" for two true inputs "A", "B" and two false inputs "A bar", "B bar". The complementary XOR circuit 111 includes two nMOS transistors N1C, N1D, two pMOS transistors P1C, P1D, and one latch circuit L1 (here, the latch circuit L1B).

[0043] In the complementary XOR circuit 111, the upper nMOS transistor N1C and pMOS transistor P1C constitute a PTL and function as a switch that determines whether to pass the false input "B bar" according to the false input "A bar". Also, in the complementary XOR circuit 111, the lower nMOS transistor N1D and pMOS transistor P1D constitute a PTL and function as a switch that determines whether to pass the true input "B" according to the true input "A".

[0044] Here, the advantages and problems of configuring each logic gate 1 with a plurality of pairs of MOS transistors constituting a PTL will be described with reference to FIG. 9. FIG. 9 is a circuit diagram showing an XOR circuit including a plurality of pairs of MOS transistors constituting a PTL. In the XOR circuit shown in FIG. 9, the upper nMOS transistor N11 and pMOS transistor P11 constitute a PTL and function as a switch that determines whether to pass the false input "A bar" according to the true input "B" and the false input "B bar". Also, the lower nMOS transistor N12 and pMOS transistor P12 constitute a PTL and function as a switch that determines whether to pass the true input "A" according to the true input "B" and the false input "B bar".

[0045] A logic gate (here, an XOR circuit) composed of multiple sets of MOS transistors constituting a PTL as shown in FIG. 9 is a symmetric circuit in which there is no difference between the upper data path and the lower data path for any input. Therefore, in the logic gate shown in FIG. 9, unlike the static CMOS circuit shown in FIG. 6, differences in power and signal delay are less likely to occur due to differences in the data paths for each input, and it is possible to sufficiently suppress the dependence of power and signal delay on the input data.

[0046] However, the logic gate shown in FIG. 9 has a problem that it does not operate normally in a WDDL circuit. That is, in a WDDL circuit, as described in the explanation of the leakage information suppression circuit 200 of the comparative example, due to the operation of the precharge circuit during the precharge period, all the inputs to each logic gate become the same value (here, high level). That is, during the precharge period, both the true input and the false input become high level.

[0047] Here, in the logic gate shown in FIG. 9, when the true input “B” and the false input “B bar” become high level, the pMOS transistors P11, P12 turn off while the nMOS transistors N11, N12 turn on. In this case, since only one of the nMOS transistors N11, N12 among the nMOS transistors N11, N12 and the pMOS transistors P11, P12 constituting the PTL is on, the nMOS transistors N11, N12 cannot output a complete high level, and the WDDL circuit does not operate normally.

[0048] Therefore, in the embodiment, each logic gate 1 (here, the XOR circuit 110 and the complementary XOR circuit 111) includes a latch circuit L1 (here, the latch circuits L1A and L1B) as shown in FIG. 8. In other words, each logic gate 1 is configured by LPL (Load-Balanced Pass-Gate Logic) in which a latch circuit L1 is added to a plurality of pairs of MOS transistors configured by PTL. The latch circuit L1 includes a NOT circuit, and is configured such that the input of the NOT circuit is connected to the output of the logic gate 1. By including the latch circuit L1, the logic gate 1 can output a complete high level even during the precharge period, so that the WDDL circuit 10 can operate normally.

[0049] FIG. 10 is a circuit diagram showing the differential AND circuit 12 in the leakage information suppression circuit 100 according to the embodiment. Each differential AND circuit 12 has an AND circuit 120 and a complementary AND circuit 121. The AND circuit 120 corresponds to an AND circuit that calculates one true output for two true inputs. Here, the AND circuit 120 calculates one true output "AND" for two true inputs "NA", "NB", two false inputs "NA bar", "NB bar", and two virtual inputs "C", "Cx".

[0050] Note that "NA bar" corresponds to "NA" with a negation bar, and "NB bar" corresponds to "NB" with a negation bar. Also, "NA" and "NA bar" correspond to the outputs during the logic evaluation period of the precharge circuit 2 to which "A" and "A bar" are input, which are in the previous stage of the differential AND circuit 12. Also, "NB" and "NB bar" correspond to the outputs during the logic evaluation period of the precharge circuit 2 to which "B" and "B bar" are input, which are in the previous stage of the differential AND circuit 12. Also, the virtual inputs "C" and "Cx" correspond to the outputs during the logic evaluation period of the precharge circuit 2 to which a reference voltage is input, and maintain a low level during the logic evaluation period.

[0051] The AND circuit 120 includes four nMOS transistors N1E, N1F, N1G, N1H, two pMOS transistors P1E, P1F, and one latch circuit L1 (here, the latch circuit L1C).

[0052] In the AND circuit 120, the upper nMOS transistors N1E, N1F constitute a PTL and function as switches that determine whether to pass either the true input "NB" or the virtual input "C" according to the true input "NA" and the false input "NA bar". Also, in the AND circuit 120, the lower nMOS transistors N1G, N1H constitute a PTL and function as switches that determine whether to pass either the true input "NA" or the virtual input "Cx" according to the true input "NB" and the false input "NB bar".

[0053] In the AND circuit 120, the latch circuit L1C includes a NOT circuit, and is configured such that the input of the NOT circuit is connected to the output of the AND circuit 120, and the output of the NOT circuit is connected to the gate of each of the pair of pMOS transistors P1E, P1F.

[0054] The complementary AND circuit 121 corresponds to a circuit that calculates one false output different from the output of the AND circuit 120. The complementary AND circuit 121 is an additional circuit paired with the AND circuit 120. Here, the complementary AND circuit 121 calculates one false output "AND bar" for two true inputs "NA", "NB", and two false inputs "NA bar", "NB bar". Note that "AND bar" corresponds to "AND" with a negation bar attached.

[0055] The complementary AND circuit 121 includes four nMOS transistors N1I, N1J, N1K, N1L, two pMOS transistors P1G, P1H, and one latch circuit L1 (here, the latch circuit L1D).

[0056] In the complementary AND circuit 121, the upper nMOS transistors N1I and N1J form a PTL and function as switches that determine whether to pass either the false input "NB bar" or the reference voltage according to the true input "NA" and the false input "NA bar". Also, in the complementary AND circuit 121, the lower nMOS transistors N1K and N1L form a PTL and function as switches that determine whether to pass either the false input "NA bar" or the reference voltage according to the true input "NB" and the false input "NB bar".

[0057] Also, in the complementary AND circuit 121, the latch circuit L1D includes a NOT circuit, and is configured such that the input of the NOT circuit is connected to the output of the complementary AND circuit 121, and the output of the NOT circuit is connected to the gates of each of the pair of pMOS transistors P1G and P1H.

[0058] Here, as already described, both the XOR circuit 110 and the complementary XOR circuit 111 are realized as symmetric circuits in which there is no difference between the upper data path and the lower data path for any input by including a plurality of pairs of MOS transistors that form a PTL. However, there is a problem that neither the AND circuit nor the complementary AND circuit can realize a symmetric circuit only by including a plurality of pairs of MOS transistors that form a PTL. That is, the AND circuit is a logic circuit whose output becomes "1" only when all inputs are "1", and becomes "0" for other inputs, and is logically degenerate and has an asymmetric logic structure, so it is difficult to realize a symmetric circuit.

[0059] Therefore, in the differential AND circuit 12 of the embodiment, two virtual inputs "C" and "Cx" that maintain a low level during the logic evaluation period are input to two sets of MOS transistors (here, the set of nMOS transistors N1E and N1F, and the set of nMOS transistors N1G and N1H) that form a PTL in the AND circuit 120, thereby solving the above problem. Hereinafter, it will be described with reference to FIG. 11 that the differential AND circuit 12 solves the above problem.

[0060] FIG. 11 is an explanatory diagram of the operation of the differential AND circuit 12 in the leakage information suppression circuit 100 according to the embodiment. FIG. 11 shows the operation of the differential AND circuit 12 with respect to "A" and "B" input to the precharge circuit 2 in the previous stage of the differential AND circuit 12. In FIG. 11, the MOS transistors shown by solid lines are driving.

[0061] As shown in FIG. 11, when "A" = 0 and "B" = 0, in the AND circuit 120, two nMOS transistors N1F and N1H are driven to output "0", and in the complementary AND circuit 121, two nMOS transistors N1J and N1L are driven to output "1". Also, when "A" = 0 and "B" = 1, in the AND circuit 120, two nMOS transistors N1F and N1G are driven to output "0", and in the complementary AND circuit 121, two nMOS transistors N1J and N1K are driven to output "1". Also, when "A" = 1 and "B" = 0, in the AND circuit 120, two nMOS transistors N1E and N1H are driven to output "0", and in the complementary AND circuit 121, two nMOS transistors N1I and N1L are driven to output "1". Also, when "A" = 1 and "B" = 1, in the AND circuit 120, two nMOS transistors N1E and N1G are driven to output "1", and in the complementary AND circuit 121, two nMOS transistors N1I and N1K are driven to output "0".

[0062] As described above, in the embodiment, each of the AND circuit 120 and the complementary AND circuit 121 is a symmetric circuit in which two nMOS transistors symmetrically arranged with respect to any input are driven, so that no difference occurs between the upper data path and the lower data path in any input.

[0063] Also, similar to the XOR circuit 110 and the complementary XOR circuit 111, since the AND circuit 120 and the complementary AND circuit 121 each include latch circuits L1C and L1D, they can output a complete high level even during the precharge period, and the WDDL circuit 10 can operate normally.

[0064] FIG. 12 is a circuit diagram showing the precharge circuit 2 in the leakage information suppression circuit 100 according to the embodiment. In the embodiment, each precharge circuit 2 is a circuit that calculates two outputs "Out" and "Out bar" for one true input "In" and one false input "In bar", similar to the precharge circuit 203 in the leakage information suppression circuit 200 of the comparative example. Also, in the embodiment, each precharge circuit 2 is composed of two NAND circuits, similar to the precharge circuit 203 of the comparative example.

[0065] One of the two NAND circuits calculates the output "Out bar" for the true input "In" and the clock signal "Clk". Also, the other of the two NOR circuits calculates the output "Out" for the false input "In bar" and the clock signal "Clk".

[0066] In the embodiment, during the precharge period, "Clk" becomes low level for each precharge circuit 2, and the two differential outputs become high level regardless of the input. Also, during the logic evaluation period, "Clk" becomes high level for each precharge circuit 2, and one of the two differential outputs switches to low level.

[0067] Thus, in the embodiment, each precharge circuit 2 is configured such that the output is at a high level during the precharge period, similar to the precharge circuit 203 of the comparative example. Therefore, in the embodiment, compared with the case where each precharge circuit 2 is configured such that the output is at a low level during the precharge period, each logic gate 1 can be configured with an nMOS transistor having a faster operation speed than a pMOS transistor for PTL, so that the entire WDDL circuit 10 can be speeded up.

[0068] Note that each precharge circuit 2 may be configured such that the output is at a low level during the precharge period, and PTL in each logic gate 1 may be configured with a pMOS transistor. Even in this case, the WDDL circuit 10 can operate sufficiently.

[0069] FIG. 13 is a circuit diagram showing a self-timer circuit 3 in the leakage information suppression circuit 100 according to the embodiment. Each self-timer circuit 3 is a dynamic OR gate circuit and includes one pMOS transistor P13, four nMOS transistors N13, N14, N15, N16, and two inverter elements I1, I2.

[0070] Each self-timer circuit 3 uses two differential outputs from the preceding logic gate 1 as two inputs "In" and "In bar", and outputs a clock signal to the precharge circuit 2 corresponding to the succeeding logic gate 1. Then, each self-timer circuit 3 does not output a clock signal until the two differential outputs from the preceding logic gate 1 are determined (that is, either one of the two differential outputs becomes a low level), and when the two differential outputs are determined, outputs a clock signal to operate the succeeding logic gate 1.

[0071] Thus, in the embodiment, since the self-timer circuit 3 is provided, the operation timing can be autonomously adjusted in each logic gate 1, the accumulation of power and signal delay between the logic gates 1 can be reduced, and the dependency of power and signal delay on the input data can be sufficiently suppressed.

[0072] Note that it is not necessary to provide the self-timer circuit 3 for all the logic gates 1, and it is sufficient to provide the self-timer circuit 3 for the logic gates 1 in which the delay of the two differential outputs becomes relatively large.

[0073] FIG. 14 is a diagram showing an example of the layout of the composite S-Box used in 128-bit AES using the leakage information suppression circuit 100 according to the embodiment. In the example shown in FIG. 14, the leakage information suppression circuit 100 according to the embodiment corresponds to the multiplication circuit of the Galois field GF(2 2 ). This composite S-Box has a plurality of layers (here, the first layer to the fourth layer) in which the region where the circuit is implemented in the upper layer and the region where the circuit is implemented in the lower layer have a nested structure.

[0074] FIG. 14(a) represents the first layer of the composite S-Box and includes three first regions 100A and one second region 100B. In the first layer, the multiplication inverse operation circuit of the Galois field GF(((2 2 )) 2 )) 2 ) shown in FIG. 2(a) is implemented. Each first region 100A is a region where the multiplication circuit of the Galois field GF((2 2 )) 2 ) shown in FIG. 3(a) is implemented. The second region 100B is a region where the multiplication inverse operation circuit of the Galois field GF((2 2 )) 2 ) shown in FIG. 2(b) is implemented. As shown in FIG. 14(a), the plurality of first regions 100A and the second region 100B are arranged on the mounting substrate so as to be line-symmetrical with respect to the straight line B1 in plan view.

[0075] FIG. 14(b) represents the second layer of the composite S-Box and includes three third regions 100C. In the second layer, the multiplication inverse operation circuit of the Galois field GF((2 2 )) 2 ) shown in FIG. 2(b) is implemented. And each third region 100C is the Galois field GF(2 2) is the area where the multiplication circuit is implemented. As shown in Fig. 14(b), a plurality of third regions 100C are arranged on the mounting substrate so as to be line-symmetrical with respect to the straight line B2 in plan view.

[0076] Fig. 14(c) shows the second layer of the composite S-Box and includes three third regions 100C. In the second layer, a multiplication circuit of the Galois field GF((2 2 ) 2 ) is further implemented. Each third region 100C is an area where a multiplication circuit of the Galois field GF(2 2 ) is implemented. As shown in Fig. 14(c), a plurality of third regions 100C are arranged on the mounting substrate so as to be line-symmetrical with respect to the straight line B3 in plan view.

[0077] Fig. 14(d) shows the third layer of the composite S-Box and includes three fourth regions 100D and four fifth regions 100E. In the third layer, a multiplication circuit of the Galois field GF(2 2 ) is implemented. Each fourth region 100D is an area where the differential AND circuit 12 shown in Fig. 7 is implemented. And each fifth region 100E is an area where the differential XOR circuit 11 shown in Fig. 7 is implemented. As shown in Fig. 14(d), a plurality of fourth regions 100D and a plurality of fifth regions 100E are arranged on the mounting substrate so as to be line-symmetrical with respect to the straight line B4 in plan view.

[0078] Fig. 14(e) shows the fourth layer of the composite S-Box. In the fourth layer, the differential AND circuit 12 (「LPL」 in Fig. 14(e)) shown in Fig. 10 and the precharge circuit 2 corresponding to the differential AND circuit 12 (「PC」 in Fig. 14(e)) are implemented. As shown in Fig. 14(e), the differential AND circuit 12 and the precharge circuit 2 are arranged on the mounting substrate so as to be line-symmetrical with respect to the straight line B5 in plan view.

[0079] (f) of FIG. 14 shows the fourth layer of the composite S-Box. In the fourth layer, a differential XOR circuit 11 shown in FIG. 8 ("LPL" in (f) of FIG. 14) and a precharge circuit 2 corresponding to the differential XOR circuit 11 ("PC" in (f) of FIG. 14) are implemented. As shown in (f) of FIG. 14, the differential XOR circuit 11 and the precharge circuit 2 are arranged on the mounting substrate so as to be line-symmetrical with respect to the straight line B6 in plan view.

[0080] As described above, the composite S-Box using the leakage information suppression circuit 100 according to the embodiment arranges one or more regions in each layer so as to be line-symmetrical in plan view. Therefore, in the composite S-Box using the leakage information suppression circuit 100 according to the embodiment, it is possible to sufficiently suppress the imbalance in the cell layout, the mismatch in the wiring load between the mismatched cells in the cell-to-cell wiring, and improve the resistance to side-channel attacks.

[0081] [5. Performance of Leakage Information Suppression Circuit] Hereinafter, the performance of the leakage information suppression circuit 100 according to the embodiment will be described in comparison with the leakage information suppression circuit 200 of the comparative example. First, a full analog post-layout simulation considering the parasitic RC components extracted for each of the composite S-Box used in 128-bit AES using the leakage information suppression circuit 100 according to the embodiment (hereinafter also referred to as "the composite S-Box according to the embodiment") and the composite S-Box used in 128-bit AES using the leakage information suppression circuit 200 of the comparative example (hereinafter also referred to as "the composite S-Box of the comparative example") was performed.

[0082] FIG. 15 is an explanatory diagram of the result of the simulation of the supply current of the composite S-Box using the leakage information suppression circuit 100 according to the embodiment. In FIG. 15, the vertical axis represents the supply current by simulation (Supply Current Draw), and the horizontal axis represents time. Here, it shows the result of tracing all the supply currents of the composite S-Box for all 256 combinations of 8-bit inputs. Also, the upper graph in FIG. 15 represents the simulation result of the composite S-Box of the comparative example, and the lower graph in FIG. 15 represents the simulation result of the composite S-Box according to the embodiment.

[0083] As shown in the upper graph of FIG. 15, in the composite S-Box of the comparative example, the supply current varies for each input during both the logic evaluation period ("Evaluation" in FIG. 15) and the pre-charge period ("Pre-Charge" in FIG. 15). It can be seen that this variation in the supply current is due to the signal delay and that the dependence of power and signal delay on the input data cannot be fully suppressed. In contrast, as shown in the lower graph of FIG. 15, in the composite S-Box according to the embodiment, the supply current is almost the same for each input during both the logic evaluation period and the pre-charge period, indicating that the dependence of power and signal delay on the input data can be sufficiently suppressed.

[0084] Next, the composite S-Box according to the embodiment and the composite S-Box of the comparative example were each fabricated using a 180 nm standard CMOS process, and the operation of each fabricated composite S-Box was confirmed in the range of a standard power supply voltage of 0.65V - 1.8V. The results will be described.

[0085] FIG. 16 is an explanatory diagram of measurement results of the basic performance of the leakage information suppression circuit 100 according to the embodiment. In the upper graph of FIG. 16, the vertical axis represents the maximum clock frequency (Max. Clock Frequency), and the horizontal axis represents the supply voltage. In the lower graph of FIG. 16, the vertical axis represents the energy efficiency, and the horizontal axis represents the supply voltage. In FIG. 16, the dashed line represents the measurement results of the composite S-Box of the comparative example (\"Conventional\" in FIG. 16), and the solid line represents the measurement results of the composite S-Box according to the embodiment (\"Proposed\" in FIG. 16).

[0086] As shown in the upper graph of FIG. 16, when the power supply voltage is 1.8 V, the maximum clock frequency of the composite S-Box of the comparative example is about 143 MHz, while the maximum clock frequency of the composite S-Box according to the embodiment is about 57 MHz. Thus, the composite S-Box according to the embodiment has a lower operating speed than the composite S-Box of the comparative example. Also, as shown in the lower graph of FIG. 16, when the power supply voltage is 1.8 V, the energy efficiency of the composite S-Box of the comparative example is about 6.2 pJ / b, while the energy efficiency of the composite S-Box according to the embodiment is about 13.1 pJ / b. Thus, the composite S-Box according to the embodiment has a larger power overhead than the composite S-Box of the comparative example.

[0087] As shown in FIG. 16, the composite S-Box according to the embodiment has a lower operating performance than the composite S-Box of the comparative example. However, as will be described below, the composite S-Box according to the embodiment has improved resistance to side-channel attacks compared to the composite S-Box of the comparative example. Hereinafter, the results of measuring the resistance to side-channel attacks by capturing the traces of the waveforms of the power supply voltages of the composite S-Box of the comparative example and the composite S-Box using an active probe and a high-speed real-time oscilloscope will be described.

[0088] FIG. 17 is an explanatory diagram of measurement results of the resistance of the leakage information suppression circuit 100 according to the embodiment against side-channel attacks. In the upper graph of FIG. 17, the vertical axis represents the power supply voltage, and the horizontal axis represents time. Also, the left graph in the upper part of FIG. 17 shows the measurement results of the composite S-Box of the comparative example, and the right graph in the upper part of FIG. 17 shows the measurement results of the composite S-Box according to the embodiment.

[0089] As shown in the upper graph of FIG. 17, the trace of the waveform of the power supply voltage indicates that spikes occur in each of the logical evaluation period and the precharge period, and particularly large spikes occur in the precharge period. As a result of performing TVLA (Test Vector Leakage Assessment) and CPA (Correlation Power Analysis) on the spikes in this precharge period, it was confirmed that the side-channel leakage is very small compared to the side-channel leakage in the logical evaluation period in both cases.

[0090] Note that TVLA is a method for statistically evaluating the side-channel leakage of an encryption circuit. Also, CPA is a method for obtaining confidential information (secret key) by observing a plurality of waveforms of the power consumption during the operation of the encryption circuit and statistically processing them.

[0091] The middle graph of FIG. 17 shows the results of performing CPA on the trace of the waveform of the power supply voltage during the logical evaluation period. In the middle graph of FIG. 17, the vertical axis represents the correlation coefficient, and the horizontal axis represents the number of waveform traces. Also, the left graph in the middle part of FIG. 17 shows the measurement results of the composite S-Box of the comparative example, and the right graph in the middle part of FIG. 17 shows the measurement results of the composite S-Box according to the embodiment.

[0092] As shown in the graph on the left side in the middle part of FIG. 17, in the composite S-Box of the comparative example, as the number of waveform traces increases, the correlation coefficient increases, and the secret key has been identified by 16,800 waveform traces ("Correct Guess" in FIG. 17). On the other hand, as shown in the graph on the right side in the middle part of FIG. 17, in the composite S-Box according to the embodiment, even as the number of waveform traces increases, the correlation coefficient remains very small, and the secret key has not been identified even by 100,000 waveform traces.

[0093] The graph in the lower part of FIG. 17 shows the result of performing TVLA on the waveform trace of the power supply voltage during the logical evaluation period. In the graph in the lower part of FIG. 17, the vertical axis represents the maximum value of the t-value (Maximum |t-Value|), and the horizontal axis represents the number of waveform traces. Also, in the graph in the lower part of FIG. 17, the dashed line represents the measurement result of the composite S-Box of the comparative example, and the solid line represents the measurement result of the composite S-Box according to the embodiment.

[0094] As shown in the graph in the lower part of FIG. 17, in the composite S-Box of the comparative example, the maximum value of the t-value reaches the threshold "4.5" with less than 200 waveform traces. Note that the maximum value of the t-value exceeding the threshold indicates a high possibility that side-channel leakage has occurred. On the other hand, in the composite S-Box according to the embodiment, the maximum value of the t-value slightly reaches the threshold with 17,000 waveform traces, and the resistance to side-channel attacks is improved by about 100 times compared to the composite S-Box of the comparative example.

[0095] FIG. 18 is an explanatory diagram of the performance of the leakage information suppression circuit 100 according to the embodiment. As shown in FIG. 18, the composite S-Box according to the embodiment is inferior to the composite S-Box of the comparative example in terms of the maximum clock frequency, energy efficiency, and the size of the cell layout area. However, as can be seen from the implementation results of TVLA and CPA, the composite S-Box according to the embodiment has significantly improved resistance to side-channel attacks compared to the composite S-Box of the comparative example.

[0096] [6. Advantages] The advantages of the leakage information suppression circuit 100 according to the embodiment will be described below. As described above, the leakage information suppression circuit 100 according to the embodiment does not output a clock signal until the two differential outputs from the preceding logic gate 1 are determined, and outputs a clock signal when the two differential outputs are determined to operate the subsequent logic gate 1, and includes a self-timer circuit 3. Therefore, in the leakage information suppression circuit 100 according to the embodiment, the operation timing can be autonomously adjusted in each logic gate 1, the accumulation of power and signal delay between the logic gates 1 can be reduced, and the dependence of power and signal delay on the input data can be sufficiently suppressed. That is, the leakage information suppression circuit 100 according to the embodiment has an advantage that it is easy to improve the resistance to side-channel attacks by including the self-timer circuit 3.

[0097] Further, in the leakage information suppression circuit 100 according to the embodiment, each of the plurality of logic gates 1 is composed of a plurality of sets of MOS transistors constituting a PTL. And, in the leakage information suppression circuit 100 according to the embodiment, each of the plurality of logic gates 1 includes a latch circuit L1 that maintains the output at a high level during the precharge period. Therefore, in the leakage information suppression circuit 100 according to the embodiment, a complete high level can be output even during the precharge period, so that the WDDL circuit 10 can operate normally. Also, in the leakage information suppression circuit 100 according to the embodiment, a difference in power and signal delay is less likely to occur due to a difference in the data path for each input, and the dependence of power and signal delay on the input data can be sufficiently suppressed. That is, the leakage information suppression circuit 100 according to the embodiment has an advantage that it is easy to improve the resistance to side-channel attacks by including a plurality of sets of MOS transistors and the latch circuit L1 that constitute the PTL in each logic gate 1.

[0098] In addition, the composite S-Box according to the embodiment has a plurality of hierarchical levels in which the region where the circuit is implemented in the upper layer and the region where the circuit is implemented in the lower layer have an embedded structure. Further, in the composite S-Box according to the embodiment, one or more regions (first region 100A to fifth region 100E) in each layer are arranged to be line-symmetric in plan view. Therefore, the composite S-Box according to the embodiment has the advantage that it can sufficiently suppress an unbalanced cell layout and a mismatch in wiring load between mismatched cells between cells, and it is easy to improve the resistance to side-channel attacks.

[0099] [7. Modification Example] As described above, the leakage information suppression circuit of the present invention has been described based on the embodiment, but the present invention is not limited to this embodiment. As long as the gist of the present invention is not deviated from, various modifications conceived by those skilled in the art applied to this embodiment or other forms constructed by combining some components in the embodiment are also included in the scope of the present invention.

[0100] For example, even if the leakage information suppression circuit 100 according to the above embodiment only includes the self-timer circuit 3, it is possible to improve the resistance to side-channel attacks.

[0101] Further, for example, even if the leakage information suppression circuit 100 according to the above embodiment only includes a plurality of sets of MOS transistors and the latch circuit L1 in which each logic gate 1 constitutes the PTL, it is possible to improve the resistance to side-channel attacks. That is, the leakage information suppression circuit 100 is a WDDL circuit 10 including a plurality of logic gates 1, and each of the plurality of logic gates 1 may include a plurality of sets of MOS transistors constituting the PTL and a latch circuit L1 that maintains the output at a high level during the precharge period.

[0102] In addition, for example, the composite S-Box using the leakage information suppression circuit 100 according to the above-described embodiment can improve the resistance to side-channel attacks even if it only has a configuration in which one or more regions are arranged to be line-symmetric in a plan view at each layer. That is, the composite S-Box has a plurality of layers in which the regions where the circuits are implemented in the upper layer and the regions where the circuits are implemented in the lower layer have a nested structure, and in each of the plurality of layers, one or more regions may be arranged to be line-symmetric in a plan view.

[0103] In addition, in the above-described embodiment, the leakage information suppression circuit 100 is a circuit included in the composite S-Box used in 128-bit AES, but it is not limited to this. For example, the leakage information suppression circuit 100 is not limited to the circuit used in AES, and may be various WDDL circuits.

[0104] (Summary) As described above, the leakage information suppression circuit 100 according to the first aspect is a WDDL circuit 10, and includes a plurality of logic gates 1, a plurality of precharge circuits 2, and one or more self-timer circuits 3. Each of the plurality of precharge circuits 2 outputs two differential outputs that become the same level during the precharge period and two differential outputs that have different levels from each other during the logic evaluation period for each of the plurality of logic gates 1. The one or more self-timer circuits 3 do not output a clock signal until the two differential outputs from the previous-stage logic gate 1 are determined, and when the two differential outputs are determined, output a clock signal to operate the subsequent-stage logic gate 1.

[0105] According to this, the operation timing can be autonomously adjusted at each logic gate 1, the accumulation of power and signal delay between the logic gates 1 can be reduced, and the dependence of power and signal delay on the input data can be sufficiently suppressed. Therefore, according to this, there is an advantage that it is easy to improve the resistance to side-channel attacks.

[0106] In the leakage information suppression circuit 100 according to the second aspect, in the first aspect, each of the plurality of logic gates 1 includes a plurality of sets of MOS transistors constituting the PTL, and a latch circuit L1 that maintains the output at a high level during the precharge period.

[0107] According to this, since a complete high level can be output even during the precharge period, the WDDL circuit 10 can operate normally. Further, according to this, differences in power and signal delay are less likely to occur due to differences in the data path for each input, and it is possible to sufficiently suppress the dependency of power and signal delay on the input data. Therefore, according to this, there is an advantage that it is easy to improve the resistance to side channel attacks.

[0108] In the leakage information suppression circuit 100 according to the third aspect, in the second aspect, one or more of the plurality of logic gates 1 is a differential AND circuit 12 having an AND circuit 120 and a complementary AND circuit 121 paired with the AND circuit 120. Two virtual inputs ("C", "Cx") that maintain a low level during the logic evaluation period are input to two sets of MOS transistors (the set of nMOS transistors N1E and N1F, and the set of nMOS transistors N1G and N1H) constituting the PTL in the AND circuit 120, respectively.

[0109] According to this, there is an advantage that an AND circuit having a logically degenerate and asymmetric logic structure can be realized as a symmetric circuit.

[0110] In the leakage information suppression circuit 100 according to the fourth aspect, in any one of the first to third aspects, each of the plurality of precharge circuits 2 outputs two differential outputs whose outputs are at a high level during the precharge period.

[0111] According to this, since each logic gate 1 can be configured with nMOS transistors that operate faster than pMOS transistors in the PTL, there is an advantage that the entire WDDL circuit 10 can be speeded up.

[0112] Also, in the leakage information suppression circuit 100 according to the fifth aspect, in any one of the first to fourth aspects, the leakage information suppression circuit 100 is used in the composite S-Box used in AES. The composite S-Box has a plurality of layers (first layer to fourth layer) in which the region where the circuit is implemented in the upper layer and the region where the circuit is implemented in the lower layer have an embedded structure. In each of the plurality of layers, one or more regions (first region 100A to fifth region 100E) are arranged to be line-symmetric in plan view.

[0113] According to this, there is an advantage that it is possible to sufficiently suppress the imbalance in cell layout and the mismatch in wiring load between mismatched cells, and it is easy to improve the resistance to side channel attacks.

Industrial Applicability

[0114] The present invention can be used for WDDL circuits.

Explanation of Signs

[0115] 1 Logic gate 11, 11A, 11B, 11C, 11D Differential XOR circuit 110 XOR circuit 111 Complementary XOR circuit 12, 12A, 12B, 12C Differential AND circuit 120 AND circuit 121 Complementary AND circuit 2, 2A, 2B, 2C, 2D, 2E, 2F, 2G, 2H, 2I, 2J Precharge circuit 3, 3A, 3B, 3C Self-timer circuit 10 WDDL circuit 100 Leakage information suppression circuit 100A First region 100B Second region 100C Third region 100D Fourth region 100E Fifth region Leakage information suppression circuit of Comparative Example 200 Differential XOR circuit 201 XOR circuit 201A Complementary XOR circuit 201B Differential AND circuit 202 AND circuit 202A Complementary AND circuit 202B Precharge circuit 203 Blocks A1, A2, A3, A4, A5 Straight lines B1, B2, B3, B4, B5, B6 Inverter elements I1, I2 Latch circuits L1, L1A, L1B, L1C, L1D nMOS transistors N1, N11, N12, N13, N14, N15, N16, N1A, N1B, N1C, N1D, N1E, N1F, N1G, N1H, N1I, N1J, N1K, N1L pMOS transistors P1, P11, P12, P13, P1A, P1B, P1C, P1D, P1E, P1F, P1G, P1H

Claims

1. A WDDL (Wave Dynamic Differential Logic) circuit, comprising a plurality of logic gates, for each of the plurality of logic gates, a plurality of precharge circuits that output two differential outputs having the same level during a precharge period and output two differential outputs having different levels from each other during a logic evaluation period, one or more self-timer circuits that do not output a clock signal until two differential outputs from a preceding-stage logic gate are determined, and output the clock signal to operate a succeeding-stage logic gate when the two differential outputs are determined, a leakage information suppression circuit.

2. Each of the plurality of logic gates comprises a plurality of sets of MOS transistors that constitute PTL (Pass Transistor Logic), and a latch circuit that maintains an output at a high level during the precharge period, the leakage information suppression circuit according to Claim 1.

3. One or more of the plurality of logic gates are differential AND circuits having an AND circuit and a complementary AND circuit paired with the AND circuit, wherein two virtual inputs that maintain a low level during the logic evaluation period are respectively input to two sets of MOS transistors that constitute PTL in the AND circuit, the leakage information suppression circuit according to Claim 2.

4. Each of the plurality of precharge circuits outputs the two differential outputs whose outputs become high level during the precharge period, the leakage information suppression circuit according to any one of Claims 1 to 3.

5. The leakage information suppression circuit is used in a composite S-Box used in AES, the composite S-Box has a plurality of layers in which a region where a circuit is implemented in an upper layer and a region where a circuit is implemented in a lower layer are in an nested structure, in each of the plurality of layers, one or more of the regions are arranged to be line-symmetric in a plan view, the leakage information suppression circuit according to any one of Claims 1 to 3.