Semiconductor Device
By duplicating critical circuits in the cryptographic IP core, the semiconductor device enhances security against fault injection attacks by ensuring the number of rounds is maintained, thus preventing reduced-round attacks.
Patent Information
- Application Number
- JP2021186709
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-11-16
- Publication Date
- 2025-05-21
- Estimated Expiration
- 2041-11-16
AI Technical Summary
Fault injection attacks can reduce the number of rounds in cryptographic algorithms below the specified number, compromising security.
Duplicating specific circuits in the cryptographic IP core, such as the second flip-flop, decision circuit, and output buffer circuit, to ensure that operation results are only output when the number of rounds matches across duplicated components, preventing faulty outputs due to fault injection attacks.
The solution effectively reduces the risk of round reduction due to fault injection attacks, maintaining security without significant area increase.
Smart Images

Figure 0007680941000001 
Figure 0007680941000002 
Figure 0007680941000003
Abstract
Description
[Technical field]
[0001] The present disclosure relates to a semiconductor device and is applicable to, for example, a semiconductor device including a cryptographic processing circuit. [Background technology]
[0002] An example of an encryption algorithm is AES (Advanced Encryption Standard). AES is a common key block cipher with variable key length and block length. As parameters, there are three key lengths: 128 bits, 192 bits, and 256 bits, and only one block length: 128 bits. Therefore, it is referred to in three different ways depending on the key length: "AES-128", "AES-192", and "AES-256".
[0003] There has been extensive research into the extent to which security decreases when the number of loops specified in the process of a cryptographic algorithm is less than the default number. For example, the latest research results have been reported as follows: In AES-128, the normal number of loops is 11 rounds, but if this is reduced to 5 rounds, 2 22 A key recovery attack can be performed with a computational effort of about 2. In addition, in the case of SHA-256 (Secure Hash Algorithm 256-bit), the usual number of loops is 64 rounds, but if this is reduced to 31 rounds, the key recovery attack can be performed in 2 65.5 A collision is found with about the amount of calculation required. At the research level, there is no discussion of what would cause the operation to fall below the specified number of loops (rounds). [Prior art documents] [Patent documents]
[0004] [Patent Document 1] JP 2016-58777 A Summary of the Invention [Problem to be solved by the invention]
[0005] As described in Patent Document 1, a device that performs fault injection using a laser or the like can be used to perform attacks such as inverting specific bits. Therefore, if the specifications of the encryption algorithm are implemented as is, a fault injection attack can result in behavior that is less than the number of rounds.
[0006] Other objects and novel features will become apparent from the description of this specification and the accompanying drawings. [Means for solving the problem]
[0007] A representative aspect of the present disclosure can be briefly outlined as follows. That is, the semiconductor device includes an arithmetic circuit that repeats an operation related to cryptographic processing a predetermined number of rounds, a holding circuit that holds data related to the number of rounds of the operation of the arithmetic circuit, a determination circuit that determines whether the number of rounds is the predetermined number of rounds, and an output buffer circuit that outputs operation result data of the arithmetic circuit when the determination circuit determines that the number of rounds is the predetermined number of rounds. The holding circuit is duplicated, and is configured not to output the operation result data when the two outputs of the duplicated holding circuits do not match. Effect of the Invention
[0008] According to the semiconductor device, it is possible to reduce behavior that falls below the number of rounds due to a fault injection attack. [Brief description of the drawings]
[0009] [Figure 1] FIG. 1 is a block diagram showing a configuration of a cryptographic IP core in a comparative example. [Diagram 2] FIG. 2 is a block diagram showing the configuration of the cryptographic IP core in the first embodiment. [Diagram 3] FIG. 3 is a block diagram showing the configuration of a cryptographic IP core in the second embodiment. [Figure 4]FIG. 4 is a block diagram showing the configuration of a cryptographic IP core in the third embodiment. [Diagram 5] FIG. 5 is a block diagram showing the configuration of a cryptographic IP core in the fourth embodiment. [Figure 6] FIG. 6 is a block diagram showing the configuration of a cryptographic IP core in the fifth embodiment. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0010] Hereinafter, comparative examples and examples will be described with reference to the drawings. In the following description, the same components are designated by the same reference numerals, and repeated description may be omitted.
[0011] First, in order to clarify this embodiment, an outline of the encryption process flow will be described using AES as an example. Encryption consists of the following processes.
[0012] (a) Splitting the input data and replacing the split data (SubBytes) (b) Swapping data positions by byte (ShiftRows) (c) Data conversion using calculation processing (MixColumns) (d) Arithmetic processing (AddRoundKey)
[0013] The above processes (a) to (d) are counted as one round, and encryption is performed by repeating a predetermined number of rounds according to the key length. Decryption is performed by inversely transforming the above processes (a) to (d) in the reverse order.
[0014] Next, the configuration of a cryptographic IP core (Intellectual Property Core) that realizes the above-mentioned encryption process will be described with reference to Fig. 1. Fig. 1 is a block diagram showing the configuration of a cryptographic IP core in a comparative example.
[0015] The cryptographic IP core 10 is built into a semiconductor device such as a microcontroller. The cryptographic IP core 10 includes a first flip-flop 11, a second flip-flop 12, a third flip-flop 13, a round function circuit (RNF) 14, and a decision circuit (JDG) 15.
[0016] The first flip-flop 11 has a first data input terminal (D1) 11a, a second data input terminal (D2) 11b, a first enable input terminal (EN1) 11c, a second enable input terminal (EN2) 11d, a clock input terminal (CK) 11e, and a data output terminal (DO) 11f. The output data (Dr) of the round function circuit 14 is input to the first data input terminal (D1) 11a. The initial data (Di) is input to the second data input terminal (D2) 11b. The signal (S1) indicating that an operation is in progress is input to the first enable input terminal (EN1) 11c. The signal (S0) indicating the start of an operation is input to the second enable input terminal (EN2) 11d. The clock signal (CLK) is input to the clock input terminal (CK) 11e.
[0017] The first flip-flop 11 takes in output data from the round function circuit 14 from the first data input terminal (D1) 11a when a signal (S1) indicating an operation in progress is activated (e.g., at a high level) at the rising or falling edge of the clock signal (CLK). The first flip-flop 11 also takes in initial data (Di) from the second data input terminal (D2) 11b when a signal (S0) indicating the start of an operation is activated (e.g., at a high level) at the rising or falling edge of the clock signal (CLK). The first flip-flop 11 holds intermediate data or final data of the encryption process, and outputs the intermediate data or final data as output data (Dm) from the data output terminal (DO) 11f.
[0018] The second flip-flop 12 has an increment enable input terminal (+1) 12a, a clock input terminal (CK) 12b, and a data output terminal (DO) 12c. An input signal (S01) obtained by ORing a signal (S0) indicating the start of calculation and a signal (S1) indicating that calculation is in progress is input to the increment enable input terminal (+1) 12a. A clock signal (CLK) is input to the clock input terminal (CK) 12b.
[0019] The second flip-flop 12 captures the input signal (S01) at the rising or falling edge of the clock signal (CLK). When the input signal (S01) is activated (e.g., at a high level), it increments. The second flip-flop 12 holds the round number and outputs the round number (RN) from the data output terminal (DO) 12c.
[0020] The third flip-flop 13 has a data input terminal (D) 13a, an enable input terminal (EN) 13b, a clock input terminal (CK) 13c, and a data output terminal (DO) 13d. The output data (Dm) of the first flip-flop 11 is input to the data input terminal (D) 13a. The operation end signal (S3), which is the output signal of the decision circuit 15, is input to the enable input terminal (EN) 13b. The clock signal (CLK) is input to the clock input terminal (CK) 13c.
[0021] When the operation end signal (S3) is activated (for example, at high level) at the rising or falling edge of the clock signal (CLK), the third flip-flop 13 takes in the output data (Dm) of the first flip-flop 11 from the data input terminal (D) 13a. The third flip-flop 13 forms an output buffer and outputs data (Dout) from a data output terminal (DO) 13d.
[0022] The round function circuit 14 is an arithmetic circuit that performs the above processes (a) to (d) on the initial data (Di) and the output data (Dm) as intermediate data.
[0023] The determination circuit 15 includes a circuit 15a in which the maximum value of the number of rounds (RNmax) corresponding to the key length is stored, and a comparison circuit 15b, and is a circuit that determines whether the number of rounds has reached a predetermined value (maximum value). When the number of rounds has reached the predetermined value, the determination circuit 15 activates an operation end signal (S3).
[0024] When a fault injection attack is performed on the second flip-flop 12, for example, a bit inversion may occur in the most significant bit (the leftmost bit) of 4-bit binary data, as in the following abnormal operation:
[0025] Normal operation: 0000→0001→0010→0011 Abnormal operation: 0000→0001→1010→1011
[0026] In this case, an output that is 8 rounds shorter will be observed, making a reduced round attack possible.
[0027] Therefore, in this embodiment, the following circuit (A), the following circuits (A) and (B), or the following circuits (A) to (C) of the cryptographic IP core in the comparative example are duplicated. In other words, the cryptographic IP core in this embodiment does not duplicate all of its circuits.
[0028] (A) Circuit that manages the number of rounds (second flip-flop 12) (B) A circuit (decision circuit 15) that compares whether the number of rounds specified in the specifications has been calculated. (C) Circuit that configures the output buffer (third flip-flop)
[0029] In this embodiment, some circuits of the cryptographic IP core are duplicated, so the area increase is about 1 to 2%, but the security risk due to fault injection attacks can be reduced. Therefore, it is possible to provide a highly secure cryptographic IP core that can prevent one of the side channel countermeasures without increasing the cost associated with the area increase. EXAMPLES
[0030] The cryptographic IP core in the first embodiment will be described with reference to Fig. 2. Fig. 2 is a block diagram showing the configuration of the cryptographic IP core in the first embodiment.
[0031] The cryptographic IP core 10 in the first embodiment has a configuration in which the second flip-flop 12, which is the circuit (A) above, is duplicated. The cryptographic IP core 10 in the first embodiment further includes another second flip-flop 12 and a comparison circuit (CMP) 16 in comparison with the cryptographic IP core in the comparative example. The comparison circuit 16 compares the outputs of the two second flip-flops 12, and if the two outputs match, outputs the output (RN) of the second flip-flop 12 to the decision circuit 15. If the two outputs do not match, the comparison circuit 16 prevents the decision circuit 15 from activating the operation end signal (S3).
[0032] When the output of the second flip-flop 12 changes due to a fault injection attack, there is a high possibility that the outputs of the two second flip-flops 12 will not match. By detecting that the two outputs do not match, the third flip-flop 13 will not output an operation result, and round reduction can be suppressed. EXAMPLES
[0033] The cryptographic IP core in the second embodiment will be described with reference to Fig. 3. Fig. 3 is a block diagram showing the configuration of the cryptographic IP core in the second embodiment.
[0034] The cryptographic IP core 10 in the second embodiment has a configuration in which the second flip-flop 12, which is the circuit in (A) above, and the decision circuit 15, which is the circuit in (B) above, are duplicated. The cryptographic IP core IP10 in the second embodiment further includes another second flip-flop 12, another decision circuit 15, and a comparison circuit (CMP) 26 in addition to the cryptographic IP core in the comparative example. The comparison circuit 26 compares the outputs of the two decision circuits 15, and if the two outputs match, outputs the operation end signal (S3), which is the output of the decision circuit 15, to the third flip-flop 13. If the two outputs do not match, the comparison circuit 26 inactivates and outputs the operation end signal (S3).
[0035] If the output of the second flip-flop 12 or the decision circuit 15 changes due to a fault injection attack, there is a high possibility that the outputs of the two decision circuits 15 will not match. By detecting that the two outputs do not match, the third flip-flop 13 will not output an operation result, and round reduction can be suppressed. EXAMPLES
[0036] The cryptographic IP core in the third embodiment will be described with reference to Fig. 4. Fig. 4 is a block diagram showing the configuration of the cryptographic IP core in the third embodiment.
[0037] The cryptographic IP core 10 in the third embodiment has a configuration in which the second flip-flop 12, which is the circuit (A), the decision circuit 15, which is the circuit (B), and the third flip-flop 13, which is the circuit (C), are duplicated. The cryptographic IP core IP10 in the third embodiment further includes another second flip-flop 12, another decision circuit 15, another third flip-flop 13, and a comparison circuit (CMP) 36 in addition to the cryptographic IP core in the comparative example. The comparison circuit 36 compares the outputs of the two third flip-flops 13, and if the two outputs match, it outputs data (Dout), which is the output of the third flip-flop 13. If the two outputs do not match, the comparison circuit 36 stops outputting the data (Dout).
[0038] When the output of the second flip-flop 12, the decision circuit 15, or the third flip-flop 13 changes due to a fault injection attack, there is a high possibility that the two outputs of the third flip-flop 13 will not match. By detecting that the two outputs do not match, the third flip-flop 13 will not output an operation result, and round reduction can be suppressed. EXAMPLES
[0039] The cryptographic IP core in the fourth embodiment will be described with reference to Fig. 5. Fig. 5 is a block diagram showing the configuration of the cryptographic IP core in the fourth embodiment.
[0040] The cryptographic IP core 10 in the fourth embodiment has a configuration in which the circuits (A) and (B) are duplicated, as in the second embodiment. However, in the cryptographic IP core 10 in the fourth embodiment, the second flip-flop 12 in the cryptographic IP core in the second embodiment is replaced with a second flip-flop 22, the decision circuit 15 is replaced with a decision circuit 25, the comparison circuit 26 is deleted, and the third flip-flop 13 is replaced with a third flip-flop 23.
[0041] The second flip-flop 12 has a decrement enable input terminal (-1) 22a, a clock input terminal (CK) 22b, a data output terminal (DO) 22c, and a data input terminal (D) 22d. An input signal (S01) obtained by ORing a signal (S0) indicating the start of an operation and a signal (S1) indicating that an operation is in progress is input to the decrement enable input terminal (-1) 22a. A clock signal (CLK) is input to the clock input terminal (CK) 22b. An initial value (RNi) is input to the data input terminal (D) 22d. Here, the initial value (RNi) is the maximum value (RNmax) of the number of rounds corresponding to the key length.
[0042] The second flip-flop 22 takes in an initial value (RNi) from the data input terminal (D) 22d when the input signal (S01) is inactivated (e.g., at a low level) at the rising or falling edge of the clock signal (CLK). The second flip-flop 22 also takes in an input signal (S01) at the rising or falling edge of the clock signal (CLK). When the input signal (S01) is activated (e.g., at a high level), it decrements. The second flip-flop 22 holds a value related to the number of rounds (RM=RNmax-RN) and outputs the value related to the number of rounds (RM) from the data output terminal (DO) 22c.
[0043] The third flip-flop 23 has a data input terminal (D) 23a, a first enable input terminal (EN1) 23b, a second enable input terminal (EN2) 23e, a clock input terminal (CK) 23c, and a data output terminal (DO) 23d. The data input terminal (D) 23a receives the output data (Dm) of the first flip-flop 11. The first enable input terminal (EN1) 23b receives an operation end signal (S3), which is an output signal of one decision circuit 25. The second enable input terminal (EN2) 23e receives an operation end signal (S3), which is an output signal of the other decision circuit 25. The clock input terminal (CK) 13c receives a clock signal (CLK).
[0044] The third flip-flop 23 takes in the output data (Dm) of the first flip-flop 11 from the data input terminal (D) 23a when both of the two operation end signals (S3) are activated (for example, at high level) at the rising or falling edge of the clock signal (CLK). The third flip-flop 13 constitutes an output buffer and outputs data (Dout) from a data output terminal (DO) 23d.
[0045] The decision circuit 25 is a circuit that includes a comparison circuit that compares the output (RM) of the second flip-flop 22 with "0" and determines whether the number of rounds has reached a predetermined value (maximum value). When the number of rounds has reached the predetermined value, the decision circuit 25 activates an operation end signal (S3).
[0046] The third flip-flop 23 captures the operation result (Dm) when the operation end signals (S3) output from the two decision circuits 15 match. When the two operation end signals (S3) do not match, the third flip-flop 23 does not capture the operation result (Dm). This makes the comparison circuit 26 in the second embodiment unnecessary.
[0047] If the output of the second flip-flop 22 or the decision circuit 25 changes due to a fault injection attack, there is a high possibility that the outputs of the two decision circuits 25 will not match. By detecting that the two outputs do not match, the third flip-flop 13 will not output the operation result, and round reduction can be suppressed. EXAMPLES
[0048] The cryptographic IP core in the fifth embodiment will be described with reference to Fig. 6. Fig. 6 is a block diagram showing the configuration of the cryptographic IP core in the fifth embodiment.
[0049] The cryptographic IP core 10 in the fifth embodiment has a configuration in which the circuits (A), (B), and (C) are duplicated, as in the third embodiment. However, in the cryptographic IP core IP10 in the fifth embodiment, the second flip-flop 12 of the cryptographic IP core in the third embodiment is replaced with the second flip-flop 22 of the fourth embodiment, and the decision circuit 15 is replaced with the decision circuit 25 of the fourth embodiment.
[0050] When the output of the second flip-flop 22, the decision circuit 25, or the third flip-flop 13 changes due to a fault injection attack, there is a high possibility that the outputs of the two third flip-flops 13 will not match. By detecting that the two outputs do not match, the third flip-flop 13 will not output an operation result, and round reduction can be suppressed.
[0051] Note that the cryptographic IP core 10 in the first embodiment may be configured to replace the second flip-flop 12 with the second flip-flop 22 in the fourth embodiment. Also, the cryptographic IP core 10 in the second embodiment may be configured to replace the second flip-flop 12 with the second flip-flop 22 in the fourth embodiment, and the judgment circuit 15 with the judgment circuit 25 in the fourth embodiment. Also, the cryptographic IP core 10 in the third embodiment may be configured to replace the second flip-flop 12 with the second flip-flop 22 in the fourth embodiment, and the judgment circuit 15 with the judgment circuit 25 in the fourth embodiment. Also, the cryptographic IP core 10 in the fourth embodiment may be configured to replace the second flip-flop 22 with the second flip-flop 12 in the second embodiment, and the judgment circuit 25 with the judgment circuit 15 in the second embodiment.
[0052] The disclosure made by the present disclosure has been specifically described above based on embodiments and examples. However, the present disclosure is not limited to the above embodiments and examples, and it goes without saying that various modifications can be made without departing from the spirit of the present disclosure.
[0053] For example, although AES has been described as an example in the embodiment and examples, the present invention can also be applied to an encryption algorithm that performs calculations by repeating a predetermined loop, such as SHA. [Explanation of symbols]
[0054] 12 Second flip-flop (holding circuit) 13 Third flip-flop (output buffer circuit) 14 Round function circuit (arithmetic circuit) 15. Determination circuit
Claims
1. an arithmetic circuit that repeats an operation related to cryptographic processing a predetermined number of rounds; a holding circuit for holding data relating to the number of rounds of the operation of the arithmetic circuit; a determination circuit for determining whether the number of rounds is the predetermined number of rounds; an output buffer circuit that outputs operation result data of the arithmetic circuit when the determination circuit determines that the number of rounds is the predetermined number of rounds; Equipped with The holding circuit and the determination circuit are duplicated, The semiconductor device is configured not to output the operation result data when the two outputs of the duplicated decision circuits do not match.
2. An arithmetic circuit that repeats an operation related to cryptographic processing a predetermined number of rounds; a holding circuit for holding data relating to the number of rounds of the operation of the arithmetic circuit; a determination circuit for determining whether the number of rounds is the predetermined number of rounds; an output buffer circuit that outputs operation result data of the arithmetic circuit when the determination circuit determines that the number of rounds is the predetermined number of rounds; Equipped with the holding circuit, the determination circuit and the output buffer circuit are duplicated; The semiconductor device is configured not to output the operation result data when the two outputs of the duplicated output buffer circuits do not match.
3. 2. The semiconductor device according to claim 1, the output buffer circuit is comprised of a flip-flop circuit having a first enable input terminal and a second enable input terminal; one output of the duplicated determination circuit is input to the first enable input terminal, and the other output of the duplicated determination circuit is input to the second enable input terminal; The output buffer circuit is configured to take in the operation result data when an enable condition of the first enable input terminal and the second enable input terminal is satisfied.
4. 4. The semiconductor device according to claim 1, The holding circuit is a semiconductor device having an increment circuit or a decrement circuit.
5. 2. The semiconductor device according to claim 1, A semiconductor device comprising a comparison circuit for comparing two outputs of the duplicated decision circuits.
6. 3. The semiconductor device according to claim 2, A semiconductor device comprising a comparison circuit for comparing two outputs of the duplicated output buffer circuits.
7. 3. The semiconductor device according to claim 1, further comprising an intermediate value holding circuit for holding intermediate calculation results of the calculation circuit, The intermediate value holding circuit is configured to output the operation result data.
Citation Information
Patent Citations
Portable electronic device and method of controlling the same
JP2012060615A
Semiconductor device
JP2016058777A
Fault attack resistant cryptographic systems and methods
US20200112425A1