AES Accelerator Processor Resisting Power Side-Channel Attacks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional techniques for mitigating power side-channel attacks in cryptographic hardware, such as random masking and dual-rail logic, consume significant energy and require large hardware areas, failing to effectively disrupt correlations between data and power consumption signatures.
Innovation Solution
The implementation of a power side-channel attack-resistant AES accelerator processor using multiple heterogeneous Galois-field arithmetic based S-box operations, which randomize byte dataflow and employ an on-chip random number generator to permute data processing order, reducing correlations between data and power signatures without the need for on-chip storage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional techniques such as random masking and dual-rail logic are used to mitigate power side-channel attacks, then security against power analysis is improved, but energy consumption increases significantly and hardware area expands
Solution Approach 1:
The patent changes the operational parameters of the AES accelerator by implementing multiple heterogeneous Galois-field arithmetic based S-box operations with different computational characteristics. This creates variable power consumption patterns that do not directly correlate with data values, thereby mitigating power side-channel attacks without requiring additional masking hardware or dual-rail logic structures that would increase energy consumption
Solution Approach 2:
The patent introduces dynamic dataflow switching where the processing path of data bytes is randomly permuted using an on-chip random number generator. This dynamic reconfiguration of the computational flow ensures that power consumption patterns change independently of the processed data, providing security against power analysis while maintaining efficient hardware utilization without expanding hardware area
2Reliability
If conventional techniques such as random masking and dual-rail logic are used to mitigate power side-channel attacks, then security against power analysis is improved, but hardware area increases significantly
Solution Approach 1:
The patent makes the existing S-box modules multi-functional by implementing heterogeneous Galois-field arithmetic operations within the same hardware structure. The same physical S-box units can perform different types of cryptographic operations with different power signatures, eliminating the need for separate dedicated hardware for each operation type and avoiding hardware area expansion while maintaining security
Solution Approach 2:
The patent employs an on-chip random number generator that uses minimal hardware resources to produce random permutation patterns for dataflow switching. This self-contained randomization mechanism provides security against power analysis without requiring external randomization hardware or additional large-area masking circuits, as the system generates its own randomization patterns using compact on-chip resources
3Reliability
If multiple heterogeneous Galois-field arithmetic based S-box operations are implemented, then correlations between data and power signatures are reduced, but device complexity increases
Solution Approach 1:
The patent segments the AES encryption process into distinct operational phases with different dataflow patterns. By dividing the computation into multiple rounds with heterogeneous S-box operations and random permutation steps, the complex security function is broken into manageable segments that can be implemented using standard AES accelerator components, thereby reducing overall device complexity while maintaining high resistance to power side-channel attacks
Data Source
AI summary
A processing system includes a processing core and a hardware accelerator communicatively coupled to the processing core. The hardware accelerator includes a random number generator to generate a byte order indicator. The hardware accelerator also includes a first switching module communicatively coupled to the random value indicator generator. The switching module receives an byte sequence in an encryption round of the cryptographic operation and feeds a portion of the input byte sequence to one of a first substitute box (S-box) module or a second S-box module in view of a byte order indicator value generated by the random number generator.


