Secure Processing System and Method
The cryptographic system addresses the challenge of limited secure memory in cryptographic processing environments by implementing a key export and load module that securely manages cryptographic key shares and employs masking techniques to counter side-channel attacks, ensuring efficient and secure key operations.
Patent Information
- Application Number
- JP2024569599
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2022-05-26
- Filing Date
- 2023-05-25
- Publication Date
- 2025-06-12
AI Technical Summary
Secure processing environments face limitations in secure memory, making it challenging to store a large number of cryptographic keys, especially when these keys are represented by multiple shares, necessitating efficient key export and load operations while protecting against side-channel attacks.
The cryptographic system employs a key export module to securely export shares of a cryptographic key by generating a ciphertext that can be stored outside the secure processing environment, and a key load module to import and convert this ciphertext back into secret shares for processing, utilizing masking techniques to protect against side-channel attacks.
This approach allows for secure storage and processing of cryptographic keys with limited secure memory, effectively preventing key exposure and mitigating side-channel attacks by ensuring that sensitive data is represented as shares rather than being directly accessed.
Smart Images

Figure 2025518071000001_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to performing operations such as cryptographic processing operations within a secure processing environment. The present disclosure is related to post-quantum cryptographic systems that utilize masking as a countermeasure against side-channel attacks.
Background Art
[0002] Cryptographic processing operations involve the use of cryptographic keys. In a symmetric encryption system that uses the same key for message encryption and decryption, it is necessary to prevent the key from being exposed to malicious parties. Similarly, in the case of an asymmetric encryption system that utilizes a private key and a public key, it is necessary to prevent the private key from being exposed to malicious parties. To protect the security of cryptographic keys, it is known to perform cryptographic processing operations within a secure processing environment that includes a secure memory and a secure cryptographic processor. An example of such a secure processing environment is a hardware security module.
[0003] A problem with secure processing environments is that the amount of secure memory within the secure processing environment is limited, which may prevent a large number of cryptographic keys from being stored in the secure memory. To address this problem, it is known to encrypt cryptographic keys using short symmetric keys, generate wrapping keys, and store them in a less secure memory outside of the secure processing environment, and only store the short symmetric keys permanently in the secure memory of the secure processing environment. Examples of such less secure memories include untrusted system main memories, as well as external storage such as hard drives and cloud-based data storage.
[0004] To perform operations using a wrapping key, the secure processing environment requires an export function to encrypt the cryptographic key to generate a wrapping key and export the wrapping key to a less secure memory, and a load function to import the wrapping key from the less secure memory to the secure processing element, decrypt the wrapping key, and recover the cryptographic key. In this way, the cryptographic key is not unwrapped and revealed outside the secure processing environment.
[0005] Processes executed within a secure processing environment may be vulnerable to side-channel attacks where an attacker learns side-channel information about the physical execution of the algorithm. Side-channel information can be derived from many sources such as execution time, electromagnetic radiation, energy consumption, and acoustic emissions. One countermeasure proposed against side-channel attacks is masking, which relies on techniques from the fields of secret sharing and multiparty computation (MPC). As an example, when a
Number
Number
Number
Number
[0006] As described above, cryptographic operations can be performed within a secure processing environment using shares of a cryptographic key instead of the cryptographic key itself. The present disclosure is directed to techniques for securely exporting shares of a cryptographic key. SUMMARY OF THE INVENTION
[0007] Aspects of the invention are set out in the appended independent claims. Specific variations of the invention are then set out in the appended dependent claims.
[0008] Examples of the invention are described by way of example only with reference to the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0009]
Figure 1
Figure 2
Figure 3
Figure 4
[0010] Preamble The specific examples described herein relate to cryptographic systems implemented within a secure processing environment that form part of a communicatively coupled computing system and securely perform cryptographic operations required by the computing system. For example, the cryptographic system may be provided as a system-on-chip device for inclusion in a larger computing circuit board and / or integrated circuit. The cryptographic system may be implemented in silicon, i.e., either alone (e.g., as an application specific integrated circuit (ASIC)) or as an integrated circuit design fabricated with a larger computing system circuit and / or as a field programmable gate array (FPGA), e.g., in the form of a specific configuration of an FPGA programmed with an appropriate hardware description language. In an example, the secure processing environment of the cryptographic module is formed by a hardware security module that provides a trusted processing environment and secure memory. The hardware security module may be tamper-proof and / or tamper-evident, e.g., by using “embedded” hardware, such that attempts to physically access components within the hardware security module are prevented and / or detected.
[0011] The cryptographic system may be used as a “post-quantum” cryptographic module or coprocessor such that, for example, one or more processors of a communicatively coupled computing system are able to offload complex “post-quantum” cryptographic operations for fast and secure computations. For example, the cryptographic system may be configured to implement key establishment and digital signature functions instead of the computing system. The cryptographic system has a security boundary such that other devices and integrated circuits of the computing system, including the computing system itself, do not have access to secret data that is operated on within the cryptographic system. The cryptographic system may be configured to autonomously perform post-quantum cryptographic operations as part of a larger hardware system, such as a larger ASIC or FPGA design.
[0012] The term "post-quantum" is used herein to describe cryptographic operations and functions that provide protection from attacks by quantum computers. This is a term well-known within the field of cryptography. For example, many common public-key algorithms are not post-quantum secure and can be efficiently broken using a sufficiently powerful quantum computer. These "not quantum-secure" cryptographic algorithms include those based on the integer factorization problem, the discrete logarithm problem, or the elliptic curve discrete logarithm problem, all of which can be easily solved with a sufficiently powerful quantum computer using Shor's algorithm. Operations and functions that have been demonstrated to be post-quantum secure include those based on one or more of lattice-based cryptography, multivariate cryptography, hash-based cryptography, code-based cryptography, and supersingular isogeny-based cryptography.
[0013] These example cryptographic systems are suitable for use in a wide variety of computing systems, from Internet servers to embedded devices. In one embodiment, the cryptographic system can be provided as part of a System-on-Chip (SoC), enabling many low-cost embedded devices to implement "post-quantum" cryptography and provide a "post-quantum" secure system. For example, functions implemented by a cryptographic math unit may be able to quickly execute code or lattice-based cryptographic operations by offloading many common low-level binary logic functions such as addition, subtraction, and / or multiplication of integers. The cryptographic system may be composed of a set of available functions that may be updatable over time or may be pre-programmed. The cryptographic system can quickly compute specific functions by not having to load and interpret individual instructions required by the processors of the combined computing system. The cryptographic system can be considered a dedicated computing device (i.e., a computer) designed for integration with larger general-purpose computing devices (e.g., for use as a computer within a computer).
[0014] Exemplary Cryptosystem FIG. 1 shows a computing system 1 by way of example. The computer system 1 includes at least one processor 3, an input / output device 5, a main system memory 7, and a removable memory 9 such as a hard disk device. Further, the computing system 1 includes a cryptosystem 11 that provides a secure processing environment in which cryptographic processing operations are executed. In this example, the cryptosystem 11 is embodied within a hardware security module.
[0015] The cryptosystem 11 includes a processor 13, a secure memory 15, and an input / output device 17, and enables communication with the rest of the computer system 1. The secure memory 15 includes a data memory 17, a program memory 19, and a working memory 21. The data memory 17 stores the confidentiality key K c 21 and the integrity key K i 23. The program memory 19 stores a key export module 27, a key load module 29, and a cryptographic processing module 31.
[0016] The processor 13 may include a reduced instruction set computer (RISC) processor, such as a RISC-V central processing unit (CPU). The processor 13 may include a 32-bit or 64-bit microprocessor (e.g., an RV32-I / E- / M / C Pluto core, etc.). The processor 13 may include one or more processing cores.
[0017] In this example, the computer system 1 also has access to cloud storage via network communication, e.g., via the Internet.
[0018] The cryptographic system 11 performs cryptographic processing operations using cryptographic keys. The cryptographic processing operations include a key establishment function having one or more of encryption and decryption, a digital signature function having one or more of digital signature generation and digital signature verification, and a stateful hash-based signature. In this example, the cryptographic system 11 is optimized for not only lattice and code-based cryptography (among other post-quantum approaches) but also "large integer" operations (e.g., operations on large integer values defined by n bits, where n can be, for example, 32 or 64).
[0019] In a particular example described herein, the security of the cryptographic system 11 is improved using masked computations in which sensitive data processed by a computer system is represented within the cryptographic system by a plurality of secret shares such that all the secret shares are required to derive information about the sensitive data. The masked computations operate on shares of the sensitive data rather than the sensitive data itself to provide protection from side-channel attacks that attempt to determine the bit pattern of the data being operated on by the cryptographic system 11 based on, for example, electromagnetic radiation, variations in power usage, operation timing, or other unintended side channels. The number of data shares may be configurable or set by the parameters of the cryptographic system 11 (e.g., there may be d data shares). A common value for the number of shares d is 2 or 3, but other numbers of shares are possible.
[0020] The encryption system 11 may perform encryption operations using many different encryption keys. In particular, in the case of asymmetric encryption operations, the number of bits of each encryption key can be large. The amount of non-volatile memory in the secure memory 15 may not be sufficient to store all the encryption keys, and this problem becomes complicated when the encryption keys are represented by multiple shares. Therefore, the key export module 27 enables the encryption keys to be stored in an encrypted form outside the encryption system 11, and the key load module 29 imports the encrypted encryption keys into the encryption system 11 and converts them into a new set of secret shares for encryption processing operations within the encryption system 11. Next, the operations of the key export module 27 and the key load module 29 will be described in more detail.
[0021] Key export module The key export module 27 includes a set of processor-implementable instructions that, when implemented by the processor 13, processes multiple shares corresponding to the encryption key to generate a ciphertext that can be securely exported outside the encryption system 11. In this example, the ciphertext is exported as part of a data package that includes an integrity tag that enables verification of the integrity of the data stored in the data package.
[0022] Figure 2 is a flowchart showing the main operations performed by the key export module 27 in this example. As shown, in this example, the key export module 27, at S1, for any integer q, when inputting and outputting either a vector of uniform bits of any length or a vector of uniform numbers within the range [0, q - 1], takes in a nonce value N unique to the confidentiality key K c in a function E(K c, N) is used to generate the cover data t. Rejection sampling can be used to obtain a uniform number within the range [0, q - 1] from a uniform bit string. In this process, b = ceil(log2(q)) consecutive segments of bits are obtained. The bit string is uniform within the range 0 ≦ x < 2b and can be interpreted as an integer x where q < 2b. For each x, if the condition x < q is satisfied, x is accepted as uniform within the range [0, q - 1], and if x ≧ q, all bits of x are rejected and a new segment of bits is obtained until an x that satisfies x < q is found. This process is repeated until the entire vector is completed. Another way to generate a distribution that is nearly uniform but not strictly uniform is to select a larger b-bit string where 2b > q and reduce x from the range [0, 2b - 1] by a simple remainder operation: x mod q.
[0023] Confidentiality key K c can be a symmetric key of 128, 256, or more bits, a masked share of such a key, a hashed or protected password or passphrase, an access token, a secure key storage handle, or it may be generated by a key derivation function, or any similar mechanism. Confidentiality key K c may be hard-coded in the cryptographic system 11 and thus may not actually be passed to the function E(K c , N).
[0024] The output vector is cryptographically secure in that nothing can be determined about the confidentiality key K c from the output vector, or conversely, no statistical anomalies or additional features of the vector can be observed without the confidentiality key K c .
[0025] Function E(K c, N) can be instantiated by a secure block cipher such as AES (Advanced Encryption Standard), a stream cipher such as ChaCha20, or a hash function or XOF (Extensible Output Function) such as SHAKE. Usually, the cryptographic function E(K c , N) itself is protected from side-channel attacks by masking or other countermeasures.
[0026] Returning to Figure 2, the key export module 27, at S3, executes an addition operation sequence to generate the sum of the cover data t and the plurality of secret shares S[1..d]. Specifically, the output vector from E(K c , N) is loaded into the temporary vector t. Next, the secret shares S[1..d] are added to the temporary vector t in an addition operation sequence, and in the case of arithmetic masking, each element is decreased (mod q), and the resulting vector t is returned as the sum Sc. These processing operations can be expressed as follows:
Equation
[0027] The sum Sc satisfies Sc = S + E(K c , N). If E(K c , N) is secure and its output distribution is uniform, the confidentiality of S is fully protected. Therefore, this result is similar to a "one-time pad", and a "one-time pad" from E(K c , N) modulo q is added.
[0028] To provide side-channel security, in this example, the cover string E(K c, N) is added before the addition of the other share S[2]. In contrast, if S[1..d] are added together first before adding E(Kc, N), the numerical result is the same, but the entire secret S is temporarily stored by the cryptosystem 11 and is thus potentially vulnerable to leakage. In this example, for the cover string E(K c , N) added to S[1], it is done before the addition of the other shares. However, as long as one of the operands of the last addition operation in the addition operation sequence is one of the shares S[1..d] of the encryption key, it will be understood that the entire secret is not temporarily stored by the cryptosystem 11.
[0029] Next, the key export module 27 generates a ciphertext representing the sum Sc in S5. In this example, the ciphertext is the sum Sc, but it will be understood that an arithmetic operation decisive for the sum Sc may be performed to generate the ciphertext.
[0030] In this example, next, the key export module 27 generates an integrity tag Si in S7. In particular, in this example, the generation of the integrity tag Si involves encrypting the ciphertext and the metadata A associated with the generation of the ciphertext using the integrity key K i 23 stored in the secure memory 15. In this example, the metadata A includes the nonce N, the modulus q, the length l of the vector (number of elements mod q), the number of shares d, the algorithm identifier id, and any additional public or secret key parameters pk and sk. More specifically, in this example, the integrity tag Si is equal to MAC(K i , Sc, A), where MAC is a keyed message authentication code that can be instantiated by HMAC, KMAC, or a similar standard algorithm.
[0031] Finally, the key export module 27 exports, at S9, a data package including the ciphertext Sc, the nonce value N, and the integrity tag Si from the secure processing environment of the cryptographic system 11 to a less secure storage environment that may be within, for example, the main system memory 7, the removable memory 9, or the cloud storage 31.
[0032] Key load module When implemented by the processor 13, the key load module 29 includes a set of processor-implementable instructions that obtain, from a memory external to the cryptographic system, a data package including a ciphertext indicating the encrypted key S stored in a protected form, and generate a plurality of d secret shares S[1..d] corresponding to this encrypted key. In this example, as discussed above, the data package also includes the nonce value N and the integrity tag Si.
[0033] FIG. 3 is a flowchart showing the main operations performed by the key load module 29 in this example. As shown, in this example, the key load module 27 imports the data package at S21 and verifies the data in the data package using the integrity key Si at S23. In particular, the key load module 27 decodes the data package to recover the ciphertext Sc, the nonce N, and the integrity tag Si, constructs the metadata A, and then calculates a test tag Ti equal to MAC(K i ,Sc,A). If the test tag Ti matches the integrity tag Si, the data of the data package is verified and the key load module proceeds with the generation of the plurality of d secret shares. However, if the test tag Ti does not match the integrity tag Si, this indicates that the data of the data package has been tampered with and the key load module 29 terminates the processing operation.
[0034] Upon verifying the integrity tag, the key load module 29 generates, at S25, d - 1 uniformly random secret shares S[1..d - 1]. To generate the uniformly random secret shares S[1..d - 1], the output of the secure random bit generator is E(Kc , N) can undergo the rejection sampling process described above.
[0035] Next, in S27, the key loading module 29 uses the confidentiality key K stored in the secure memory 15 c and the nonce value N recovered from the imported data package to generate cover data using the above function E(K c , N). Next, in S29, the key loading module 29 subtracts each value of d - 1 uniform random shares and the cover data from the ciphertext value, and executes an additive inverse operation sequence to generate the final share S[d]. These processing operations can be expressed as follows:
Equation
[0036] It will be understood that in the case of Boolean masking, the additive inverse operation "-" can be replaced by the XOR operation.
[0037] Also in this case, in order to prevent the encryption key S from being temporarily stored by the encryption system, the order of the additive inverse operations is important. The subtraction of the cover vector is executed last in the routine outlined above, but it will be understood that any order that does not involve subtracting the cover data from the ciphertext will have the desired improvement in data security. In other words, the first additive inverse operation needs to include as operands the value of one of the one or more uniform random shares and the value of the ciphertext.
[0038] The random secret shares [S1..d] do not need to match the secret shares used to generate the data package. In contrast, refreshing the secret shares improves the security against side-channel attacks by making it more difficult to analyze any data leaked by such side-channel attacks. In fact, the number d of secret shares may be different when the secret shares S[1..d] are refreshed.
[0039] Encryption processing module In masked encryption calculations, arithmetic can be transformed into corresponding masked operations. For example, an unmasked (plain) arithmetic operation between variables X and Y that results in Z: Z = X op Y is transformed into a series of arithmetic operations from the shares {X i} and {Y i} to provide the share {Z i}. This example is shown in FIG. 4.
[0040] FIG. 4 shows an operation 400 performed on two input data variables 410 and 420 (shown as X and Y). Each of the two input variables 410 and 420 is split into respective sets of data shares 430 and 440. In this example, there are three data shares such that the first input variable 410 is split into data shares 432, 434, and 436 and the second input variable 420 is split into data shares 442, 444, and 446. Each of the data shares may include a bit sequence of the same length as the bit sequence representing the input variable. In the example of FIG. 4, the input variables are split into data shares using Boolean masking, but different forms of masking may be available as configurable or selectable control parameters. For example, there may be an option to generate data shares using either Boolean masking or arithmetic masking (among others). The encryption system may be further configured to convert between different forms of masking for specific operations.
[0041] Data sharing can be used to perform operation 450. Operation 450 is performed as a set of independent operations 452, 454, and 456 that each receive corresponding data shares from two sets of data shares 430 and 440. For example, operation 452 is performed using data shares 432 and 442 as inputs, operation 454 is performed using data shares 434 and 444 as inputs, and operation 456 is performed using data shares 436 and 446 as inputs. Each independent operation 452 - 456 is a repetition of the same arithmetic unit operation. Each of the masked arithmetic operations 452 - 456 (including conversion to the masked form) is designed so that all intermediate variables are statistically independent from the (secret) sum of the shares. Operations 452 - 456 are performed on secret data shares, but the data shares are not "folded" to reform the secret. Thus, the original secret is not "exposed" to side-channel attacks.
[0042] In FIG. 4, after operation 450 is performed on each pair of data shares, the results obtained from each of the individual operations 452, 454, and 456 are provided as respective outputs 462, 464, and 466. The output set of data shares 460 can be reconfigured to provide the result of operation 450 applied to input variables 410 and 420 (i.e., Z = oper(X,Y)). In the example of FIG. 4, the reconfiguration may be performed by XORing the individual data shares (i.e., [Number] ). This may be performed as an output, for example, via a set of bus interfaces 120, or as a final step after operation 450 is completed, and may be performed externally (e.g., by an external computing system), or even only if the data shares are encrypted as described below.
[0043] In certain embodiments (and / or a given configuration), the secret information may be maintained as data shares throughout the key life cycle. For example, a secret key may be generated as a share, stored as a share in memory (e.g., both internal and external memory, the latter via the cryptographic register 122), loaded as a share, and used as a share (e.g., in cryptographic operations). At the end of the key's life, the shares may be zeroed. In certain cases, only the secret information is operated on the data shares. In these cases, if the set of data shares representing the secret information is encrypted (e.g., using an encryption and / or encapsulation algorithm implemented by a cryptographic system), the data can be folded together after encryption because it is no longer "secret" (i.e., because it is protected by encryption). For example, a stream cipher may generate a ciphertext C from a plaintext P and a key stream Z = encrypt(key) where C = P XOR Z and decryption is performed as P = C XOR Z. If the encryption is implemented in a masked way, the key stream shares Z 1 , Z 2 , Z 3 may be generated from masked keys (key 1 , key 2 , key 3 ). In this case, different ciphertext portions may be encrypted using their respective key stream shares C 1 = P 1 XOR Z 1 , C 2 = P 2 XOR Z 2 , and C 3 = P 3 XOR Z 3 . Following encryption, it is possible to fold the masks without exposing the secret information, i.e., C = C 1 XOR C 2 XOR C 3 here. C can be safely exported in an encrypted form that does not reveal information about P.
[0044] The example of FIG. 4 shows the case of Boolean masking, but in other examples, arithmetic masking may be used instead. In some cases, arithmetic masking may be used in the form of addition masking to generate data shares. Addition masking is similar to XOR masking, but uses integer or modular addition. In some cases, the shares are
Number
[0045] In certain examples, the cryptographic system 110 may be arranged to perform an operation to convert between two different masking formats. For example, linear operations such as XOR or addition may be applied independently to the data shares only if the data shares are in the corresponding masking format. In some cases, Boolean masking may be converted to arithmetic masking or from arithmetic masking. When Boolean masking is converted to arithmetic masking, this is the first data share set {X iA sum equal to the XOR sum of {}, for example
Number
Number
[0046] The specific arithmetic primitives applied as operations by the arithmetic unit 136 can be achieved with the aid of conversion functions within a masked operation mode (or the conversion functions can be implemented directly by operations). For example, in the case of Boolean masked addition and subtraction, the set of output data shares {Z i} can be calculated from the input shares {X i} and {Y i} such that the XOR sum satisfies X + Y = Z or X - Y = Z (mod q). Other masked functions may follow the same pattern. Bitwise logic in the masked mode can be performed, for example, by applying AND, OR, and XOR operations to arithmetically masked data shares or Boolean masked data shares. Similarly, shifts, rotations, and bit operations can be applied to arithmetically masked data shares or Boolean masked data shares. Comparisons can be performed by analyzing the equivalence or order of masked variables (e.g., using less than or greater than). The result of a comparison can also be masked (e.g., the true or false values can be masked bits). Arithmetic and special functions in the field of post-quantum cryptography can also be applied to masked variables.
[0047] Certain post-quantum cryptographic operations operate on ring polynomials. For example, lattice-based cryptography utilizes ring polynomial and matrix multiplications. Many of these multiplications are between a secret polynomial and a public polynomial. In these cases, the secret polynomial may be masked, and there is no need to mask the public polynomial. In the case of multiplying a secret polynomial X by a public polynomial C, the secret polynomial can be split into d data shares for a masked operation mode, such as CX = CX 1 + CX 2 + CX 3 (mod q). In this case, multiplying by a constant (the public polynomial C) only increases the complexity by O(d). This means that lattice-based post-quantum cryptography is particularly suitable for the masked operation mode. By comparison, multiplying two masked representations, e.g., (X 1 + X2 +X 3 ) * (Y 1 +Y 2 +Y 3 ) incurs at least O(d 2 )(i.e., quadratic) overhead with respect to the number of shares. Similarly, in the case of many number-theoretic transforms (NTTs) used to implement the rings and module algebraic objects used in known lattice cryptoschemes, it is necessary to mask only one input of the NTT multiplication. This limits the overhead of applying the masking mode. Lattice cryptography further uses mixed bit-oriented operations such as right shifts, "rounding", and masked comparisons. These tasks can be achieved by more efficient partial masking transforms tuned per operation.
[0048] Masking is applied in the examples herein as a countermeasure against side-channel attacks. The cryptographic system 11 provides hardware-accelerated cryptographic operations with integrated hardware masking support. Masking can be configured to meet the requirements of "non-invasive attack countermeasures" described in FIPS 140-3 and ISO 19790 security standards (e.g., those defined in section 7.8 of ISO / IEC 19790:2012(E)), both of which are incorporated herein by reference. Tests of the effectiveness of countermeasures such as masking described herein may be performed using the procedures described in ISO / IEC 17825:2016(E) "Testing methods for the mitigation of non-invasive attack classes against cryptographic modules", incorporated herein by reference, or more generally, inspection procedures such as those commonly referred to as TVLA (Test Vector Leakage Assessment).
[0049] Variations and Further Examples In the above example of key export, the temporary vector t and the stored secret Sc are not themselves masked. In an alternative example, the masked temporary vector is split into e shares t[1], t[2],..t[e] that sum to the temporary vector t, and the masked stored secret [[Sc]] is stored. Next, an implementation example of the key export function and the key load function for such an arrangement will be described. In this implementation example, for simplicity, it is assumed that the ciphertext [[Sc]] also has e shares, but this is not essential.
[0050] To generate the masked temporary vector t, this implementation example utilizes a masked encryption function E(Kc,N)[i] that generates t[1], t[2]..t[e] such that t[1]+t[2] +..+t[e]=cover data, where e is less than or equal to d. The masked encryption function E(Kc,N) can be, for example, a masked implementation of a block cipher such as the hash function SHAKE or AES. Next, each of the e shares is loaded into the respective share t[i] of the temporary vector.
[0051] After generating the masked temporary vector t, the key export function executes a masked addition sequence in which each of the d shares S[1], S[2],..S[d] of the secret S is added to one of the e shares t[1], t[2]..t[e] of the temporary vector t. This can be executed in a periodic manner (such that, for example, S[1] is added to t[1], S[2] is added to t[2], etc., until S[e] is added to t[e] and then S[e+1] is added to t[1], etc., as compared to the original share t[1] output by the masked encryption function E(Kc,N), such that t[1]=t[1]+S[1]+S[e+1]). The resulting masked vector with e shares is then returned as the ciphertext [[Sc]]. These processing operations can be expressed as follows:
Equation
[0052] In this way, each share of the ciphertext corresponds to the modular addition of one share of the temporary vector t and one or more shares of the secret S, so that the share of the ciphertext corresponds to the sum of the share of the sensitive data and the share of the cover data. In the case of Boolean masking, the exclusive OR (XOR) operation replaces the modular addition of vectors.
[0053] It will be understood that the ordering of the indices i and j can be random.
[0054] In the corresponding key loading function for recovering the secret share [[S]], each of the e shares of the ciphertext is loaded into the respective share of the temporary vector t. Next, a set of d random uniform vectors S[1], S[2],.. S[d] is generated, and each random uniform vector is subtracted from one of the shares of the temporary vector by performing addition modulo the inverse with respect to q, generating a modified temporary vector with e shares. Again, this can be performed in a periodic manner. Next, after generating e shares of the cover data using the masked encryption function E(Kc,N)[i], each share of the cover data is subtracted from one of the respective e shares of the modified temporary vector. Finally, the e shares obtained as a result of the modified temporary vector are added to one of the respective set of d random uniform vectors S[1], S[2],.. S[d], and the resulting set of d vectors forms the d shares of the sensitive data S (e.g., the encryption key). These processing operations can be implemented as follows:
Number
[0055] It will be understood that in the case of Boolean masking, the additive inverse operation '-' can be replaced by the XOR operation. By using a uniform random vector u, d shares of the sensitive data S are effectively refreshed each time the key loading function is executed, providing additional protection from side-channel attacks.
[0056] Brief overview of characteristic examples The specific examples described herein provide a device (e.g., a cryptographic system or a coprocessor) that can perform post-quantum cryptography using masked arithmetic, i.e., data provided as masked data shares for side-channel protection. The masked operation mode can utilize one or more of Boolean and arithmetic masking, and the device can provide a conversion between (at least these) different masking forms. The examples described provide a novel cryptographic system structure or configuration that enables both accelerated post-quantum cryptographic processing and high security against side-channel attacks by performing masking operations in a flexible and efficient manner.
[0057] The specific examples described herein provide a device (e.g., a cryptographic system or a coprocessor) that not only assists in and / or accelerates cryptographic calculations, but can also autonomously perform certain complete post-quantum cryptographic operations. For example, the device enables key establishment and encryption of public keys such as generation of public-private key pairs, encapsulation and / or encryption, and decapsulation and / or decryption. Further, the device enables not only digital signature functions such as generation of public-private integrity key pairs, signature generation, and signature verification, but also stateful hash-based signatures such as assistance in and / or acceleration of key generation, signature generation, and / or signature verification functions. Such a device may be provided as a system-on-chip (e.g., integrated within a silicon design and / or provided as a separate FPGA / ASIC chip that can be attached).
[0058] The specific examples described herein provide a cryptographic system that can provide secure cryptographic computations. For example, it can implement one or more of the following post-quantum public-key encryption algorithms: classical McEliece, (CRYSTALS-)KYBER, NTRU, SABER, BIKE, FrodoKEM, HQC, NTRU Prime, SIKE, and SIDH (Supersingular Isogeny Diffie-Hellman), and also one or more of the following post-quantum digital signature algorithms: (CRYSTALS-)DILITHIUM, FALCON, Rainbow, GeMSS, and Picnic. Further details of these algorithms can be found in the available NIST publications of the "Post-Quantum Cryptography Project" and the publications of the CRYSTALS project, "Cryptographic Suite for Algebraic Lattices-Kyber and Dilithium", which are incorporated herein by reference.
[0059] The specific examples described herein have a control unit that controls cryptographic operations (so-called "no-touch" operations) without processing sensitive data. For example, the control unit may not have access to sensitive data within the cryptographic mathematical unit during the operation.
[0060] The specific examples further provide a way in which the control unit or processor can track the flow of sensitive information within the cryptographic system, but without having access to that data, since the control unit or processor can provide security tracking of the secret data throughout the cryptographic operation.
[0061] It will be understood that the presence of integrity tags is optional. If integrity tags are present, the confidentiality key and the integrity key are the same because the confidentiality key can be used as the integrity key rather than having a separate integrity key.
[0062] Functions provided within a secure processing environment may be implemented in software, hardware, or a combination of software and hardware. Accordingly, the key export module 27, the key load module 29, and the cryptographic processing module 31, when executed by a processor, may be implemented as processor-implementable instructions that execute the respective functions, or as hardware circuits that execute the respective functions, such as an FPGA or an ASIC, or as a combination of processor-implementable instructions and hardware.
[0063] The above examples are to be understood as illustrative. Further examples are envisioned. Although the specific components of each example have been described separately, it should be understood that the functions described with reference to one example may be suitably implemented in another example, and that the specific components may be omitted depending on the embodiment. It should be understood that any feature described in connection with any one embodiment may be used alone or in combination with other features described, and may also be used in combination with one or more features of any other embodiment, or any combination of any other embodiments. For example, features described with respect to system components may also be adapted to be implemented as part of the methods described. Further, equivalents and modifications not described above may be employed without departing from the scope of the invention as defined in the appended claims.
Claims
1. A secure processing environment configured to execute masked processing operations using a plurality of shares corresponding to sensitive data, a memory for storing a confidentiality key, a first module configured to execute at least one masked processing operation using a plurality of shares corresponding to sensitive data, configured to generate cover data, the generation including encrypting a nonce using a confidentiality key stored within the secure processing environment, subsequent to the generation of the cover data, configured to execute an addition operation sequence using the shares of the sensitive data and the cover data to generate a sum, configured to generate a ciphertext indicating the sum, a second module configured to export a data package including the ciphertext and the nonce, the secure processing environment including the above.
2. The secure processing environment according to claim 1, wherein the cover data is not masked, and one of the operands for the last addition operation of the addition operation sequence is one of the shares of the sensitive data.
3. The secure processing environment according to claim 2, wherein one of the operands for the first addition operation of the addition operation sequence is the cover data.
4. The secure processing environment according to any one of the preceding claims, wherein the addition operation sequence includes modular addition operations.
5. The modular addition operation according to claim 4 includes at least one of addition in arithmetic modulo q (where q is a prime number or a power of 2) and addition of bitwise Boolean exclusive OR.
6. The secure processing environment according to any one of the preceding claims, wherein the second module generates masked cover data having a plurality of shares, and for each of the plurality of shares of the sensitive data, executes an addition operation with the shares of the cover data to generate a plurality of shares corresponding to the sum of the shares of the sensitive data and the shares of the cover data.
7. Further including generating a completeness tag and including the completeness tag in the data package, wherein the generating of the completeness tag includes encrypting the ciphertext and the metadata associated with the ciphertext using a completeness key stored in the memory, for the secure processing environment according to any one of the preceding claims.
8. The secure processing environment according to claim 7, wherein the metadata includes the nonce value.
9. The secure processing environment according to claim 7 or claim 8, wherein the completeness key is the confidentiality key.
10. The secure processing environment according to any one of claims 7 to 9, wherein the completeness tag includes a method authentication code of the data package.
11. The memory further includes a third module, The third module, is configured to import the data package including the ciphertext and the nonce value, is configured to generate one or more uniform random shares, is configured to generate cover data, and the generating of the cover data includes encrypting the nonce value using the confidentiality key, performs an addition operation sequence for generating a plurality of shares corresponding to the sensitive data by subtracting the value of each uniform random share and the value of the cover data from the value of the ciphertext, for the secure processing environment according to any one of the preceding claims.
12. The secure processing environment according to claim 11, wherein the cover data is not masked, and the first addition operation uses the value of one of the uniform random shares and the value of the ciphertext as operands.
13. The secure processing environment according to claim 12, wherein the last operand of the addition operation sequence includes the value of the cover data.
14. The secure processing environment according to claim 12 or claim 13, wherein the addition operation sequence includes modular addition operation.
15. The secure processing environment according to claim 14, wherein the modular addition operation includes at least one of addition in arithmetic modulo q (where q is a prime number or a power of 2) and addition of bitwise Boolean exclusive OR.
16. The ciphertext includes a first plurality of shares, the generation of the cover data includes generating a second plurality of shares, and the modular addition operation changes at least a part of the uniform random shares according to the values of the first plurality of shares and the second plurality of shares. The secure processing environment according to claim 11.
17. The data package further includes an integrity tag, and by the processor-implementable instructions, before generating the plurality of shares from the ciphertext, the processor generates a verification tag by encrypting the ciphertext and the metadata associated with the ciphertext using the integrity key stored in the memory, checks that the verification tag matches the integrity tag, and generates the plurality of shares in the event that the verification tag matches the integrity tag. The secure processing environment according to any one of claims 11 to 16, verified by.
18. The secure processing environment according to claim 17, wherein the metadata includes the nonce value.
19. The secure processing environment according to claim 17 or claim 18, wherein the integrity key is the confidentiality key.
20. The secure processing environment according to any one of claims 17 to 19, wherein the integrity tag includes a method authentication code of the data package.
21. A secure processing environment configured to perform a masked processing operation using a first plurality of shares corresponding to sensitive data, a memory for storing a confidentiality key, configured to import a data package including a ciphertext and a nonce value, configured to generate one or more uniform random shares, configured to generate cover data, the generation of the cover data including encrypting the nonce value using the confidentiality key, configured to execute an additive inverse operation sequence for generating a second plurality of shares corresponding to the sensitive data by subtracting each uniform random share and the value of the cover data from the value of the ciphertext, including a module. The secure processing environment.
22. The cover data is not masked, and the first addition operation uses the value of one of the uniform random shares and the value of the ciphertext as operands, the secure processing environment according to claim 21.
23. The last operand of the addition operation sequence includes the value of the cover data, the secure processing environment according to claim 22.
24. The additive inverse operation sequence includes a modular addition operation, the secure processing environment according to claim 22 or claim 23.
25. The modular addition operation includes at least one of addition in arithmetic modulo q (where q is a prime number or a power of 2) and addition of bitwise Boolean exclusive OR, the secure processing environment according to claim 24.
26. The ciphertext includes a first plurality of shares, the generation of the cover data includes generating a second plurality of shares, and the modular addition operation changes at least a part of the uniform random shares by the values of the first plurality of shares and the second plurality of shares, the secure processing environment according to claim 21.
27. The data package further includes an integrity tag, and the module, before generating the plurality of shares from the ciphertext, generates a verification tag by encrypting the ciphertext and the metadata associated with the ciphertext using the integrity key stored in the memory, checks that the verification tag matches the integrity tag, and generates the plurality of shares in the event that the verification tag matches the integrity tag, configured to verify by, the secure processing environment according to any one of claims 17 to 20.
28. The metadata includes the nonce value, the secure processing environment according to claim 27.
29. The integrity key is the confidentiality key, the secure processing environment according to claim 27 or claim 28.
30. The integrity tag includes a method authentication code of the data package, the secure processing environment according to any one of claims 27 to 29.
31. The secure processing environment is provided by a hardware security module, the secure processing environment according to any one of the preceding claims.
32. A computing device including the secure processing environment according to any one of the preceding claims.
33. A method for storing a plurality of shares used within a secure processing environment to perform masked processing operations corresponding to sensitive data, the method comprising: generating cover data, the generating including encrypting a nonce value using a confidentiality key stored within the secure processing environment; subsequent to the generating of the cover data, performing an addition operation sequence for generating a sum of the shares of the sensitive data and the cover data; generating a ciphertext representing the sum; exporting a data package including the ciphertext and the nonce value to storage external to the secure processing environment; the method comprising the above.
34. A method for generating a plurality of shares within a secure processing environment, the plurality of shares corresponding to sensitive data and being used to perform masked processing operations within the secure processing environment, the method comprising: importing a data package including a ciphertext and a nonce value, the ciphertext being based on the sensitive data and the nonce value; generating one or more uniform random shares; generating cover data, the generating of the cover data including encrypting the nonce value using the confidentiality key; subtracting the values of each uniform random share and the cover data from the value of the ciphertext to perform an additive inverse operation sequence for generating the plurality of shares corresponding to the sensitive data; the method comprising the above.