Information processing apparatus, information processing method, and program

By controlling the clock based on encryption processing states to gate it during critical rounds, the encryption processing apparatus addresses side-channel attacks with minimal performance degradation.

JP7710936B2Active Publication Date: 2025-07-22CANON KK
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
JP2021144807
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-09-06
Publication Date
2025-07-22
Estimated Expiration
2041-09-06

AI Technical Summary

Technical Problem

Existing countermeasures against side-channel attacks through clock gating in cryptographic processing result in performance degradation due to continuous stopping of the cryptographic processing module during gating periods.

Method used

The encryption processing apparatus controls the clock differently based on specific encryption processing states, selectively gating the clock during critical rounds to thwart key estimation attacks while minimizing performance loss.

Benefits of technology

This approach effectively counters side-channel attacks while reducing the overall processing cycles by approximately 52% compared to continuous clock gating, thus maintaining performance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007710936000001
    Figure 0007710936000001
  • Figure 0007710936000002
    Figure 0007710936000002
  • Figure 0007710936000003
    Figure 0007710936000003
Patent Text Reader

Abstract

To take measures against a side-channel attack, while preventing a reduction in performance due to clock fluctuations.SOLUTION: An information processing apparatus performs cipher processing, and has: acquisition means that acquires a plane sentence; cipher processing means that performs cipher processing on the plane sentence acquired by the acquisition means; and control means that controls the clock of the cipher processing means. The control means makes the clock when the processing performed by the cipher processing means is in a specific cipher processing state and the clock when the processing performed by the cipher processing means is not in the specific cipher processing state different from each other.SELECTED DRAWING: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an information processing apparatus, an information processing method, and a program for performing encryption processing.

Background Art

[0002] In encryption processing, an encryption key is important information. In symmetric-key encryption such as AES (Advanced Encryption Standard), a common encryption key is used both at the time of encryption and at the time of decryption. If the encryption key leaks, a third party can decrypt the ciphertext with the leaked encryption key and obtain the information of the plaintext that was encrypted and intended to be kept secret from the third party.

[0003] On the other hand, as a method of stealing encryption keys, an attack method called side-channel attack has been devised. In this attack method, the encryption processing module observes side-channel information such as electromagnetic waves and consumed current generated during encryption processing, and estimates the key information used in the encryption processing based on the observed side-channel information. Regarding the specific method of side-channel attack, AES will be used as an example for explanation. First, using the same encryption key and multiple plaintexts, the encryption module is operated to obtain the side-channel information (trace information) during encryption processing. Based on the obtained trace information, the key is estimated and statistical processing is performed. In key estimation, the key is estimated one byte at a time. This is to reduce the combination of key patterns and shorten the processing time. For example, in the case of an AES key length of 128 bits, the total number of combinations of key patterns is 2^128. On the other hand, by estimating one byte at a time, the combination of key patterns can be reduced to 2^8. In AES, the S-Box, which is a non-linear process, is targeted for statistical processing. If the plaintext is available, the S-Box output of the first round of AES processing is targeted. The correlation between the S-Box output and the estimated key from the known plaintext is calculated. If the estimated key is correct, a high correlation is obtained, and if the estimated key is incorrect, a low correlation is obtained. On the other hand, if the ciphertext is available, the S-Box input of the final round of AES processing is targeted. At this time, the correlation between the S-Box input and the estimated key from the known ciphertext is calculated. If the estimated key is correct, a high correlation is obtained, and if the estimated key is incorrect, a low correlation is obtained. The above statistical processing is performed on multiple traces, and the estimated key with the highest correlation obtained is determined to be the correct key.

[0004] Countermeasures against side-channel attacks have been devised. One of the countermeasures is disclosed in Patent Document 1 and Patent Document 2, which is to randomly gate the clock of the cryptographic processing module. In this countermeasure, by randomly gating the clock, the processing timing of the cryptographic processing is randomly varied. As a result, when analyzing a plurality of trace information, by varying the position where a high correlation can be obtained for each trace, it becomes impossible to obtain a high correlation, thereby preventing key estimation.

Prior Art Documents

Patent Documents

[0005]

Patent Document 1

Patent Document 2

Summary of the Invention

Problems to be Solved by the Invention

[0006] In the countermeasures against side-channel attacks by clock gating disclosed in Patent Document 1 and Patent Document 2, clock gating is continuously performed during cryptographic processing. When the clock is gated, during the gating period, the cryptographic processing module stops operating, so it takes extra time for the cryptographic processing by the duration of the gating period, and the performance deteriorates. The present invention has been made in view of the above problems, and an object thereof is to perform countermeasures against side-channel attacks while suppressing performance degradation due to clock variation.

Means for Solving the Problems

[0007] In order to solve the above problems, the encryption processing apparatus according to the present invention is an information processing apparatus that performs encryption processing, and includes an acquisition unit that acquires a plaintext, an encryption processing unit that performs encryption processing on the plaintext acquired by the acquisition unit, and a control unit that controls the clock of the encryption processing unit. The control unit is characterized in that it makes the clock when the processing of the encryption processing unit is in a specific encryption processing state different from the clock when the processing of the encryption processing unit is not in a specific encryption processing state.

Effect of the Invention

[0008] According to the present invention, it is possible to take countermeasures against side channel attacks while suppressing performance degradation due to clock fluctuations.

Brief Description of the Drawings

[0009]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Modes for Carrying Out the Invention

[0010] (First Embodiment) Hereinafter, with reference to the drawings, preferred embodiments of the present invention will be described in detail. It should be noted that the following embodiments are merely examples and are not intended to limit the scope of the present invention.

[0011] FIG. 1 is a block diagram showing the configuration of an integrated circuit for communication processing. In the integrated circuit for communication processing, a CPU 10, an encryption processing device 20, a DRAM controller 30, a communication processing device 40, and an SRAM 60 are connected to a bus system 50 and perform data transfer with each other. This configuration is a typical configuration of an integrated circuit called a System-On-A-Chip, and it is also possible to replace it with an information processing device such as a general personal computer. The DRAM controller 30 is connected to a DRAM 2 outside the integrated circuit for communication and performs data transfer. The communication processing device 40 is connected to a LAN 3 outside the integrated circuit for communication and communicates with other devices.

[0012] FIG. 2 shows a configuration diagram of the encryption processing device according to the present embodiment. The encryption processing device 20 includes a data input unit 200, an encryption processing unit 201, a data output unit 202, a random number generation unit 203, a clock control unit 204, and an overall control unit 205.

[0013] Describe the typical encryption process flow in the encryption device 20. The overall control unit 205 is set with values such as the mode indicating encryption or decryption processing, the algorithm used in the encryption processing, the input data, the transfer address of the output data, and the key information used in the encryption processing from the CPU 10. The overall control unit 205 transfers the various set values set from the CPU 10 to the data input unit 200, the encryption processing unit 201, the data output unit 202, and the clock control unit 204. Then, after receiving a processing start request from the CPU 10, the overall control unit 205 instructs each module to start processing. Upon receiving the instruction to start processing, the data input unit 200 reads the input data from the external memory SRAM 60 or DRAM 2 indicated by the transfer source address of the input data instructed by the overall control unit 205 via the bus system 50. The input data is plaintext when encrypting and ciphertext when decrypting. The data input unit 200 outputs the read input data to the encryption processing unit 201. The encryption processing unit 201 performs encryption or decryption processing on the data input from the data input unit. Whether to encrypt or decrypt, as well as the algorithm and key information to be used, follow the settings from the overall control unit 205. The encryption processing unit 201 outputs the encryption processing state to the clock control unit 204 during the encryption processing. An example of the encryption processing state is shown in FIG. 3. The encryption processing unit 201 is in the Idle state indicating the initial processing wait state. Then, when input data is input from the data input unit 200, it transitions to the In state which is the data input state. Then, in each round of the round processing of the encryption processing, it transitions to RX (where X represents the round number) representing each round processing state. The number of rounds varies depending on the algorithm and key length as shown in FIG. 4. For example, if the key length of AES is 128 bits, there are a total of 10 rounds, and if the key length of AES is 256 bits, there are a total of 14 rounds. The clock control unit 204 gates the clock supplied to the encryption processing unit 201 based on the encryption processing state of the processing from the encryption processing unit 201. When the encryption processing state from the encryption processing unit 201 indicates a specific round state, the clock control unit 204 gates the clock for the number of cycles indicated by the random number from the random number generation unit 203.A specific round state that performs clock gating is the processing round that is the target of analysis. The number of rounds for clock gating is shown in FIG. 4. The number of rounds of the final round varies depending on the algorithm and the key length used. To shift the processing timing of the first round, gating is performed at the processing timings of the first round and the second round. Also, to shift the processing timing of the final round, gating is performed at the processing timings of the final round and the round immediately preceding the final round. When the encryption processing or decryption processing is completed, the encryption processing unit 201 outputs the data to the data output unit 202. The encryption processing state at this time is Out. The data output by the encryption processing unit 201 is ciphertext during encryption processing and plaintext during decryption processing. The data output unit 202 outputs the received data to the external memory SRAM60 or the DRAM2 indicated by the transfer destination address of the output data instructed by the overall control unit 205 via the bus system 50. When the output of all data is completed, the data output unit 202 notifies the overall control unit 205 of the completion of processing. The overall control unit 205, upon receiving the notification of the completion of processing, notifies the CPU10 of the completion of processing by interruption.

[0014] Using FIG. 5, the processing flow of the clock control unit 204 will be described. In S100, a round for performing clock gating is set from the CPU 10. The round for performing clock gating is as shown in FIG. 4. Subsequently, in steps S101 and S102, it is determined whether the encryption processing state is a round for performing clock gating. In step S101, it is determined whether the encryption processing state indicates R1 or R2, which represent the first round and the next round. On the other hand, in step S102, it is determined whether the encryption processing state indicates R(N - 1) or RN, which represent the final round and the round before the final round. Here, N represents the total number of rounds of the encryption processing determined by the algorithm and the key length, and is set from the CPU 10 in S101. If it is not determined in S101 or S102 that it is a round for performing clock gating, then in S103, the clock is supplied to the encryption processing unit 201. On the other hand, if it is determined in S101 or S102 that it is a round for performing clock gating, then in S104, the internal counter is initialized with the random number output from the random number generation unit 203. Subsequently, in S105, it is determined whether the counter is 0 or not. If the counter is not 0, then in S106, clock gating to the encryption processing unit 201 is performed. Subsequently, in S107, the counter value is decremented by 1, and again in S105, it is determined whether the counter value is 0 or not. If it is determined in S105 that the counter value is 0, then in S103, the clock is supplied to the encryption processing unit 201. Subsequently, in S108, it is determined whether the encryption processing has been completed. The determination of whether the encryption processing has been completed is made by the fact that the encryption processing state has transitioned to Out and then to Idle after RN. If it is not determined in S108 that the encryption processing has been completed, then it returns to S101 again, and the determination of whether the encryption processing state is a state for performing clock gating is made again. On the other hand, if it is determined in S108 that the encryption processing has been completed, then the processing is completed.

[0015] Fig. 6 shows an example of the processing of the clock control unit 204 in a timing chart. In this embodiment, an example of the key length of 128 bits of AES is shown. In cycle 1, the encryption processing state is Idle, and it is determined that the clock should be supplied to the encryption processing unit 201, so the clock is supplied to the encryption processing unit 201. In cycle 2, the encryption processing state is In, and it is determined that the clock should be supplied to the encryption processing unit 201, so the clock is supplied to the encryption processing unit 201. In cycle 3, the encryption processing state is R1, and it is determined that the clock should be gated, and the clock control signal is asserted. Also, in the same cycle, 2 which is the random number output of the random number generation unit 203 is set to the counter, and since the counter value is not 0, the clock to the encryption processing unit 201 is gated. In cycle 4, the value of the counter is decremented by 1 from 2 to 1, but since the counter value is not 0, the clock to the encryption processing unit 201 is gated. In cycles 3 and 4, the clock to the encryption processing unit 201 is gated, and the processing of the encryption processing unit 201 is in a stopped state. Therefore, the encryption processing state also continues to hold the state of R1. In cycle 5, the value of the counter is decremented by 1 from 1 to 0, and since the counter value becomes 0, the clock is supplied to the encryption processing unit 201. Subsequently, in cycle 6, the encryption processing state is R2, and it is determined that the clock should be gated, and the clock control signal is asserted. Similar to cycle 3, 1 which is the random number output of the random number generation unit 203 is set to the counter, and since the counter value is not 0, the clock to the encryption processing unit 201 is gated. Subsequently, in cycle 7, the value of the counter is decremented by 1 from 1 to 0, and since the counter value becomes 0, the clock is supplied to the encryption processing unit 201. Subsequently, from cycle 8 to cycle 13, the encryption processing state indicates rounds R3 to R8 where the clock should not be gated, so the clock control signal is de-asserted, and the clock is continuously supplied to the encryption processing unit 201. Subsequently, in cycle 14, the encryption processing state is R9, and it is determined that the clock should be gated, and the clock control signal is asserted.In the same cycle, 0 which is the random number output of the random number generation unit 203 is set to the counter. Since the counter value is 0, a clock is supplied to the encryption processing unit 201. Subsequently, in cycle 15, the encryption processing state is R10, and it is determined that the clock should be gated, and the clock control signal is asserted. In the same cycle, 3 which is the random number output of the random number generation unit 203 is set to the counter. Since the counter value is not 0, the clock to the encryption processing unit 201 is gated. In subsequent cycles 16 and 17, the counter value is decremented by 1 each, but since the counter value is not 0, the clock to the encryption processing unit 201 is gated. Subsequently, in cycle 18, since the counter value becomes 0, a clock is supplied to the encryption processing unit 201. Subsequently, in cycles 19 and 20, since the encryption processing state indicates Out and Idle where the clock should not be gated, the clock control signal is de-asserted, and the clock is continuously supplied to the encryption processing unit 201.

[0016] The effects of the invention will be described. In the prior art, the clock was randomly gated in all rounds. Assuming that the average clock gating cycle in each round is N and the total number of rounds of encryption processing is M, the processing cycle of encryption processing in the prior art is M×(1 + N)=M + M×N cycles. On the other hand, the processing cycle in this embodiment is M - 4+4(1 + N)=M + 4×N cycles. For example, in the case of AES key length 128Bit processing, if M = 10 and N = 8 cycles, the processing cycle in the prior art is 88 cycles. On the other hand, the processing cycle in this embodiment is 42 cycles, and it is possible to reduce the number of cycles by about 52% compared with the prior example.

[0017] In this embodiment, the cycles for clock gating were described as the first round, the second round, the final round, and the four rounds before the final round of the rounds of the cryptographic process. However, the number of rounds for clock gating may be limited to only the first round and the final round. Also, it may be possible to gate from the third round to the second round of the final round, but the effect of suppressing the performance degradation according to this embodiment decreases as the number of rounds for gating increases.

[0018] Also, in this embodiment, an example of clock gating was shown, but the clock period may be varied by means other than clock gating. Also, in this embodiment, an example of using AES as the cryptographic algorithm was shown, but other algorithms such as DES and Triple DES may also be used.

[0019] (Other Embodiments) The present invention can also be realized by supplying a program that realizes one or more functions of the above-described embodiment to a system or apparatus via a network or a storage medium, and having one or more processors in a computer of the system or apparatus read and execute the program. Also, it can be realized by a circuit (for example, ASIC) that realizes one or more functions.

Description of Reference Numerals

[0020] 200 Data input unit 201 Cryptographic processing unit 202 Data output unit 203 Random number generation unit 204 Clock control unit 205 Overall control unit

Claims

1. An information processing apparatus that performs encryption processing, comprising: an acquisition unit that acquires plaintext; an encryption processing unit that performs encryption processing on the plaintext acquired by the acquisition unit; a control unit that controls the clock of the encryption processing unit, wherein the control unit makes the clock when the processing of the encryption processing unit is in a specific encryption processing state different from the clock when the processing of the encryption processing unit is not in the specific encryption processing state.

2. further comprising a random number generation unit that generates a random number, wherein the control unit gates the clock of the encryption processing unit according to the random number generated by the random number generation unit.

3. when the processing of the encryption processing unit is in the specific encryption processing state, the encryption processing unit generates a signal indicating the encryption processing state, wherein the control unit controls the clock of the encryption processing unit based on the signal indicating the encryption processing state.

4. The encryption algorithm in the encryption processing unit is AES.

5. The specific encryption processing state is the processing in the first round of AES and the processing in the final round of AES.

6. The specific encryption processing state includes at least one of the processing in the first round of AES, the processing in the second round of AES, the processing in the final round of AES, and the processing immediately before the processing in the final round of AES.

7. The encryption algorithm in the encryption processing unit is DES or Triple DES.

8. An information processing method for performing encryption processing, comprising: an acquisition step in which an acquisition unit acquires plaintext; an encryption processing step in which an encryption processing unit performs encryption processing on the plaintext acquired in the acquisition step; a control step in which a control unit controls the clock in the encryption processing step. In the control step, a clock when the processing in the encryption processing step is in a specific encryption processing state is made different from a clock when the processing in the encryption processing step is not in the specific encryption processing state. An information processing method characterized by this.

9. A computer, An information processing apparatus that performs encryption processing, An acquisition means for acquiring plaintext, An encryption processing means for performing encryption processing on the plaintext acquired by the acquisition means, A control means for controlling the clock of the encryption processing means, and having, The control means functions as an information processing apparatus characterized in that a clock when the processing of the encryption processing means is in a specific encryption processing state is made different from a clock when the processing of the encryption processing means is not in the specific encryption processing state. A computer program for this.

Citation Information

Patent Citations

  • Signal processor

    JP2001094550A

  • Cipher processor, and cipher processing method

    JP2005045752A

  • Encryption device

    JP2008113130A

  • Tamper-resistant memory system

    JP2014216659A

  • random clock generator

    JP2018528719A