System, method and device for preventing side channel attack
The system employs a hashing function with multiple hashing modules and data registers to generate a dynamic number of rounds, alternating between dummy and actual datasets, effectively preventing Side Channel Attacks and ensuring data security.
Patent Information
- Application Number
- PCT/IN2024/052368
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-15
- Filing Date
- 2024-12-11
- Publication Date
- 2025-06-19
AI Technical Summary
Side Channel Attacks (SCA) exploit physical characteristics like electromagnetic emissions to extract sensitive information from computer architectures, posing a significant threat to data security.
A system and method that utilize a hashing function with multiple pre-defined hashing modules and pre-existing data registers to generate a dynamic number of rounds, alternating between dummy and actual datasets, to camouflage the actual data transmission and prevent SCA.
Effectively prevents Side Channel Attacks by masking the actual dataset transmission through a dynamic and randomized process, thereby maintaining the integrity and security of the data.
Smart Images

Figure IN2024052368_19062025_PF_FP_ABST
Abstract
Description
SYSTEM, METHOD AND DEVICE FOR PREVENTING SIDE CHANNELATTACKFIELD OF THE INVENTION
[0001] The present invention generally relates to preventing Side Channel Attack (SCA), more particularly relates to system, method and device for preventing SCA.BACKGROUND OF THE INVENTION
[0002] Generally, a Side Channel Attack (SCA) is an attack enabled by leakage of information from a physical cryptosystem. Characteristics that could be exploited in a side-channel attack include timing, power consumption, electromagnetic and acoustic emissions.
[0003] With reference to analyzing physical parameters such as electromagnetic emission across the chip of the computer architecture, the third-party hacker may use a probe which is placed across the chip in order to extract secrets which may be transmitted as data across the chip. Data is usually transmitted across the chip in the format of the binary system as either one or zero. In the event of transmission of data as either one or zero or whenever there is a switch between one and zero and vice versa, a certain amount of electromagnetic noise is generated. Therefore, using the probe placed on the bus of the chip, the third-party hacker can detect the variations in the data transmission across the chip such as switch between zero to one and vice versa due to generation of electromagnetic noise and extract any secret from the data without the consent of the owner of the computer architecture, and hence compromising the system.
[0004] In view of the above, there is a dire need for a system, method and device for Side Channel Attack (SCA) resistant which overcomes the above indicated problems associated with data extraction from computer architecture.SUMMARY OF THE INVENTION
[0005] One or more embodiments of the present invention, provide system, method and device for preventing side channel attack (SCA).
[0006] In one aspect of the invention, a system for Side Channel Attack (SCA) resistant of data is provided. The system comprising: a memory including executable instructions; and at least one processor in communication with the memory and configured to receive the executable instructions and configured to: receive, a hashing request from an external entity, the hashing request representative of data that requires to be secured from SCA; utilize, a plurality of pre-existing data registers, for storing at least one of an input and an output generated by a hashing function, based on the hashing request, the hashing function including a plurality of hashing modules arranged in a pre-defined order; generate, a dynamic number of rounds for conducting the hashing function, wherein each round of the dynamic number of rounds representative of either dummy dataset or actual dataset intended to be transmitted between a source and a destination; and perform, the hashing function for each round of the dynamic number of rounds by providing one of the dummy dataset or actual dataset as one of the input and output to the plurality of hashing modules arranged in the pre-defined order utilizing the respective plurality of pre-existing data registers in order to prevent SCA of the actual dataset.
[0007] In yet another aspect of the invention, a method to prevent Side Channel Attack (SCA) of data is provided. The method includes the steps of, receiving, a hashing request from an external entity, the hashing request representative of data that requires to be secured from SCA;, utilizing, a plurality of pre-existing data registers, for storing at least one of an input and an output generated by a hashing function based on the hashing request, the hashing function including a plurality of hashing modules arranged in a pre-defined order; generating, a dynamic number of rounds for conducting the hashing function, wherein each round of the dynamic number of rounds representative of either dummy dataset or actual dataset intended to be transmitted between a source and a destination; and performing, the hashingfunction for each round of the dynamic number of rounds by providing one of the dummy dataset or actual dataset as one of the input and output to the plurality of hashing modules arranged in the pre-defined order utilizing the respective plurality of pre-existing data registers in order to prevent SCA of the actual dataset.
[0008] Other features and aspects of this invention will be apparent from the following description and the accompanying drawings. The features and advantages described in this summary and in the following detailed description are not all- inclusive, and particularly, many additional features and advantages will be apparent to one of ordinary skill in the relevant art, in view of the drawings, specification, and claims hereof. Moreover, it should be noted that the language used in the specification has been principally selected for readability and instructional purposes, and may not have been selected to delineate or circumscribe the inventive subject matter, resort to the claims being necessary to determine such inventive subject matter.BRIEF DESCRIPTION OF THE DRAWINGS
[0009] Reference will be made to embodiments of the invention, examples of which may be illustrated in the accompanying figures. These figures are intended to be illustrative, not limiting. The accompanying figures, which are incorporated in and constitute a part of the specification, are illustrative of one or more embodiments of the disclosed subject matter and together with the description explain various embodiments of the disclosed subject matter and are intended to be illustrative. Further, the accompanying figures have not necessarily been drawn to scale, and any values or dimensions in the accompanying figures are for illustration purposes only and may or may not represent actual or preferred values or dimensions. Although the invention is generally described in the context of these embodiments, it should be understood that it is not intended to limit the scope of the invention to these particular embodiments.
[0010] FIG. 1 illustrates a block diagram of a system for Side Channel Attack (SCA) resistant of data, according to one or more embodiments of the present invention;
[0011] FIG. 2 illustrates a plurality of hashing modules of a hashing function, according to one or more embodiments of the present invention;
[0012] FIG. 3 illustrates a primary cycle of hashing function performed on dataset, according to one or embodiments of the present invention; and
[0013] FIG. 4 illustrates a primary cycle and an imitation cycle of hashing function performed simultaneously, according to one or more embodiments of the present invention; and
[0014] FIG. 5 illustrates a flowchart of a method to prevent Side Channel Attack (SCA) of data, according to one or more embodiments of the present invention.DETAILED DESCRIPTION OF THE INVENTION
[0015] Reference will now be made in detail to specific embodiments or features, examples of which are illustrated in the accompanying drawings. Wherever possible, corresponding or similar reference numbers will be used throughout the drawings to refer to the same or corresponding parts. References to various elements described herein, are made collectively or individually when there may be more than one element of the same type. However, such references are merely exemplary in nature. It may be noted that any reference to elements in the singular may also be construed to relate to the plural and vice-versa without limiting the scope of the invention to the exact number or type of such elements unless set forth explicitly in the appended claims. Moreover, relational terms such as first and second, and the like, may be used to distinguish one entity from the other, without necessarily implying any actual relationship or between such entities.
[0016] Various embodiments of the invention provide a system, method and device for preventing side channel attack, thereby ensuring integrity of data is maintained.In accordance with an embodiment of the invention, FIG. 1 illustrates a system which may also be a device 100. The system 100 includes a processor 102 and a memory 104. The memory 104 includes executable instructions and the processor 102 which is coupled to the memory 104 is configured to receive the executable instructions and configured to perform multiple steps in order to prevent Side Channel Attack (SCA) of data which may be transmitted from a source to a destination. Further, the system 100 includes a random number generation module 106. Further, the system 100 includes an application specific Integrated Circuit (IC) / Crypto Co-processor 108 which employs a hashing function such as, a Secure Hashing Algorithm 3 (SHA3) in order to carry out the steps of the invention, thereby ensuring that integrity and security of the data is maintained when the data is being transmitted from the source to a destination. Further, it is pertinent to note that the hashing function, SHA3 is just a mere hashing function and has no contribution in carrying out the rest of the inventive features of the invention. The application specific Integrated Circuit (IC) / Crypto Co-processor 108 is a pure digital circuit (gates) on silicon level and no software is involved on the silicon level.
[0017] The system 100 of the present invention using SHA3 carries out the inventive steps in order to solve the issues of attack by leakage of information. The SHA3 is used for hashing the data and it is well known in the art that any data pursuant to being hashed using the hashing function produces a unique hash that is non-duplicable by any other piece of data.
[0018] In a preferred embodiment, the application specific IC / crypto co-processor 108 which employs the SHA3 hashing function includes at least a plurality of hardware hashing modules arranged in a pre-defined order. The plurality of hashing modules includes Theta, Rho, Pi, Chi and Iota in the pre-defined order as shown in FIGs. 1 and 2. Each of the plurality of hashing modules are independent entities configured to perform a specific computational function. Since there are five hashing modules pertaining to the hashing function, five pre-existing data registers are utilized for the same as shown in FIG. 3. For example, data register 1 is used to storeat least one of an input and an output generated by the hashing module Theta. Similarly, the data register 2 is used to store at least one of an input and an output generated by the hashing module Rho. Similarly, the data register 3 is used to store at least one of an input and an output generated by the hashing module Pi. Similarly, the data register 4 is used to store at least one of an input and an output generated by the hashing module Chi. Similarly, the data register 5 has been used to store at least one of an input and an output generated by the hashing module Iota. Since each of the plurality of hashing modules are hardware in nature, as soon as the system is powered on, each of the hashing modules runs automatically and continuously.
[0019] Further, in a preferred embodiment, each of the plurality of pre-existing data registers at any point in time is not empty. In the above indicated example, each of the five data registers 1, 2, 3, 4 and 5 are not empty. In particular, even before the first dataset is received at the data register 1 and before running of the hashing module ‘Theta’, all the other data registers from data register 2 to data register 5 are not empty and filled with a dataset by the processor 102 in combination with the crypto co-processor 108, preferably dummy datasets are filled at the pre-existing data registers 1-5. Advantageously, this prevents the attacker knowing which specific function starts running first when the first dataset of the plurality of datasets is sent for hashing.
[0020] In the event, any entity could be owner of the data or any third-party data source intending to transmit the data securely from a source to a destination, may transmit a hashing request to the processor. The hashing request is representative of data that requires to be secured from Side Channel Attack (SCA). In an embodiment, with the hashing request, actual dataset which requires to be transmitted from a source to a destination is transmitted by the entity and which is received at the processor 102.
[0021] In response to the hashing request along with the actual dataset which is transmitted from the entity to the processor 102. As indicated above, data register 1 is used to store at least one of an input and an output generated by the hashingmodule Theta. Similarly, the data register 2 is used to store at least one of an input and an output generated by the hashing module Rho. Similarly, the data register 3 is used to store at least one of an input and an output generated by the hashing module Pi. Similarly, the data register 4 is used to store at least one of an input and an output generated by the hashing module Chi. Similarly, the data register 5 has been utilized to store at least one of an input and an output generated by the hashing module Iota.
[0022] Once the plurality of pre-existing data registers have been utilized for storing at least one of an input and an output generated by a hashing function based on the hashing request, the processor 102 generates, a dynamic number of rounds for conducting the hashing function. In an embodiment, each round of the dynamic number of rounds represents of either dummy dataset or actual dataset intended to be transmitted between a source and a destination.
[0023] In a preferred embodiment, each round of the dynamic number of rounds is dynamically generated using a random number generation module 106 by the processor 104, wherein each round is randomly fed with one of, the dummy dataset or the actual dataset.
[0024] In a preferred embodiment, first few rounds of the dynamic number of rounds are fed with dummy dataset. Thereafter, 24 rounds are generated wherein each of the 24 rounds having actual data set. Finally, few last rounds of the dynamic number of rounds are fed with dummy dataset. By doing this, the system 100 camouflages the actual dataset which is being transmitted from the source to the destination, thereby any hacker intending to steal the actual dataset will not be able to do so, due to the confusion created by each round being either the dummy dataset or the actual dataset. Further, by mixing dummy datasets with actual datasets, prevents the attacker from determining which input is the actual dataset and which is not.
[0025] Once the dynamic number of rounds are generated, the processor performs, the hashing function for each round of the dynamic number of rounds. In an embodiment, the hashing function is performed by the processor by providing one ofthe dummy dataset or actual dataset as one of the input and output to the plurality of hashing modules arranged in the pre-defined order utilizing the respective plurality of pre-existing data registers in order to prevent SCA of the actual dataset. In a preferred embodiment, each of the plurality of hashing modules arranged in the predefined order is configured to receive input from the respective pre-existing data register, perform the hashing function and output the result as input via the subsequent pre-existing data register to the subsequent hashing module arranged in the pre-defined order. For example as per FIG. 3, let us consider that the dynamic number of rounds generated is 30, wherein first 3 rounds contain dummy datasets, followed by 24 rounds of actual dataset and ending with again 3 rounds of dummy dataset. Based on the generated dynamic number of rounds, for the first round (let us say dummy dataset 1) the hashing function is performed. The dummy dataset 1 is stored in data register 1. The dummy dataset 1 is fed to the hashing module Theta as input via the data register 1. The hashing module Theta performs the hashing function and outputs the result as input via the subsequent data register 2 to the subsequent hashing module Rho. The hashing module Rho performs the hashing function and outputs the result as input via the subsequent data register 3 to the subsequent hashing module Pi. The hashing module Pi performs the hashing function and outputs the result as input via the subsequent data register 4 to the subsequent hashing module Chi. The hashing module Chi performs the hashing function and outputs the result as input via the subsequent data register 5 to the subsequent hashing module Iota. The hashing module Iota performs the hashing function and outputs the result and stores the same at a storage device. The process of performing the hashing functions for the 30 rounds of the datasets for example is done in a cyclic manner as shown in FIG. 3, which is a primary cycle.
[0026] Further in order to increase the security level pertaining to the actual dataset, the processor is configured to modify the number of rounds of the dynamic number of rounds for performing the hashing function. For example, instead of 24 rounds, additional number of rounds may be added. In an alternate embodiment, fewrounds of the dynamic number of rounds may be deleted. Advantageously, the system 100 can be customized to suite with user requirements.
[0027] Furthermore, in order to increase the security level pertaining to the actual dataset, the processor is configured to modify the number of cycles of the hashing function by generating one or more imitation cycles simultaneously along with the at least one primary cycle in real time as shown in FIG. 4. For example, if the primary cycle includes 30 rounds, wherein 24 rounds containing actual dataset, each of the imitation cycle may include 24 rounds of actual dataset, preceded or followed by rounds containing dummy dataset as well running simultaneously with the primary cycle. In one embodiment, the primary cycle modifies the number of cycles utilizing the random number generation module 106. Further the imitation cycle modifies the number of cycles by allowing the dummy and actual rounds to run simultaneously. Advantageously, increasing the integrity and security of transmitting actual dataset between a source and a destination. Further, the system enables data exchange in between the primary and the imitation cycle.
[0028] FIG. 5 illustrates a flowchart of a method 500 to prevent Side Channel Attack (SCA) of data. The method is executed utilizing system 100 which includes the processor 102 and the memory 104. The method illustrated below is purely exemplary and should nowhere be construed as limiting the scope of the present disclosure.
[0029] At step 502, receiving, by the processor, a hashing request from an external entity, the hashing request representative of data that requires to be secured from SCA.
[0030] At step 504, utilizing, by a processor, a plurality of pre-existing data registers for storing at least one of an input and an output generated by a hashing function based on the hashing request, the hashing function including a plurality of hashing modules arranged in a pre-defined order.
[0031] At step 506, generating, by the processor, a dynamic number of rounds for conducting the hashing function, wherein each round of the dynamic number of rounds representative of either dummy dataset or actual dataset intended to be transmitted between a source and a destination.
[0032] At step 508, performing, by the processor, the hashing function for each round of the dynamic number of rounds by providing one of the dummy dataset or actual dataset as one of the input and output to the plurality of hashing modules arranged in the pre-defined order utilizing the respective plurality of pre-existing data registers in order to prevent SCA of the actual dataset.
[0033] In the embodiments, said system may include one or more processors coupled with a memory, wherein the memory may store instructions which when executed by the one or more processors may cause the system to perform root cause analysis of errors in networks. The one or more processor(s) may be one or more microprocessors, microcomputers, microcontrollers, edge or fog microcontrollers, digital signal processors, central processing units, logic circuitries, any combination of said components and / or any devices that process data based on operational instructions. The one or more processor(s) may be configured to fetch and execute computer-readable instructions stored in a memory of the system and compatible with AI / ML to assess and monitor. The memory may be configured to store one or more computer-readable instructions or routines in a non-transitory computer readable storage medium, which may be fetched and executed to create or share data packets over a network service. The memory may comprise any non-transitory storage device including, for example, volatile memory such as Random-Access Memory (RAM), or non-volatile memory such as Electrically Erasable Programmable Read-only Memory (EPROM), flash memory, and the like. In an embodiment, the system may include an interface(s). The interface(s) may comprise a variety of interfaces, for example, interfaces for data input and output devices, referred to as input / output (I / O) devices, storage devices, and the like. The interface(s) may facilitate communication for the system. The interface(s) may also provide a communication pathway for one or more components of the system.Examples of such components include, but are not limited to, processing unit / engine(s) and a database. The processing unit / engine(s) may be implemented as a combination of hardware and programming (for example, programmable instructions) to implement one or more functionalities of the processing engine(s). In examples described herein, such combinations of hardware and programming may be implemented in several different ways to analyze root cause of an error in a network.
[0034] While aspects of the present invention have been particularly shown and described with reference to the embodiments above, it will be understood by those skilled in the art that various additional embodiments may be contemplated by the modification of the disclosed machines, systems and methods without departing from the scope of what is disclosed. Such embodiments should be understood to fall within the scope of the present invention as determined based upon the claims and any equivalents thereof.
Claims
CLAIMSWe Claim:
1. A method to prevent Side Channel Attack (SCA) of data, the method comprising the steps of: receiving, by a processor, a hashing request from an external entity, the hashing request representative of data that requires to be secured from SCA; utilizing, by the processor, a plurality of pre-existing data registers for storing at least one of an input and an output generated by a hashing function based on the hashing request, the hashing function including a plurality of hashing modules arranged in a pre-defined order; generating, by the processor, a dynamic number of rounds for conducting the hashing function, wherein each round of the dynamic number of rounds representative of either dummy dataset or actual dataset intended to be transmitted between a source and a destination; and performing, by the processor, the hashing function for each round of the dynamic number of rounds by providing one of the dummy dataset or actual dataset as one of the input and output to the plurality of hashing modules arranged in the pre-defined order utilizing the respective plurality of pre-existing data registers in order to prevent SCA of the actual dataset.
2. The method as claimed in claim 1, wherein each of the plurality of pre- existing data registers at any point in time is not empty.
3. The method as claimed in claim 1, wherein each round of the dynamic number of rounds is dynamically generated using random number generation module by the processor, wherein each round is randomly fed with either one of, the dummy dataset or the actual dataset.
4. The method as claimed in claim 1, wherein the hashing function is at least one of a SHA3 (Secure Hashing Algorithm), wherein the SHA3 includes at least the plurality of hashing modules arranged in the pre-defined order as Theta, Rho, Pi, Chi and Iota.
5. The method as claimed in claim 3, wherein each hashing module is configured to compute a value pertaining to each dataset being one of dummy dataset or the actual dataset of each round of the dynamic number of rounds.
6. The method as claimed in claim 3, wherein each of the plurality of hashing modules arranged in the pre-defined order is configured to receive input from the respective pre-existing data register, perform the hashing function and output the result as input via the subsequent pre-existing data register to the subsequent hashing module arranged in the pre-defined order.
7. The method as claimed in claim 1, wherein the plurality of hashing modules of the hashing function is configured to perform the hashing function for at least one primary cycle, wherein each round of the dynamic number of rounds is exposed to the hashing module for the at least one primary cycle.
8. The method as claimed in claim 6, wherein in order to increase the security level pertaining to the actual dataset, the processor is configured to at least one of: modify the number of rounds of the dynamic number of rounds for performing the hashing function; and modify the number of cycles of the hashing function by generating one or more imitation cycles simultaneously along with the at least one primary cycle in real time.
9. A system for Side Channel Attack (SCA) resistant of data, the method comprising: a memory including executable instructions; and at least one processor in communication with the memory and configured to receive the executable instructions and configured to: receive, a hashing request from an external entity, the hashing request representative of data that requires to be secured from SCA; utilize, a plurality of pre-existing data registers for storing at least one of an input and an output generated by a hashing function based on the hashing request, the hashing function including a plurality of hashing modules arranged in a predefined order; generate, a dynamic number of rounds for conducting the hashing function, wherein each round of the dynamic number of rounds representative of either dummy dataset or actual dataset intended to be transmitted between a source and a destination; and perform, the hashing function for each round of the dynamic number of rounds by providing one of the dummy dataset or actual dataset as one of the input and output to the plurality of hashing modules arranged in the pre-defined order utilizing the respective plurality of pre-existing data registers in order to prevent SCA of the actual dataset.
Citation Information
Patent Citations
System and methods for side-channel attack prevention
US8781111B2
Preventing data extraction by side-channel attack
US9135453B2