AES Accelerator Processor Resisting Power Side-Channel Attacks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional techniques for mitigating power side-channel attacks in cryptographic hardware, such as random masking and dual-rail logic, consume significant energy and require large hardware areas, failing to effectively disrupt correlations between data and power consumption signatures.

Innovation Solution

The implementation of a power side-channel attack-resistant AES accelerator processor using multiple heterogeneous Galois-field arithmetic based S-box operations, which randomize byte dataflow and employ an on-chip random number generator to permute data processing order, reducing correlations between data and power signatures without the need for on-chip storage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional techniques such as random masking and dual-rail logic are used to mitigate power side-channel attacks, then security against power analysis is improved, but energy consumption increases significantly and hardware area expands

Engineering Contradiction:
Improvesecurity against power side-channel attacksVSAvoidenergy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent changes the operational parameters of the AES accelerator by implementing multiple heterogeneous Galois-field arithmetic based S-box operations with different computational characteristics. This creates variable power consumption patterns that do not directly correlate with data values, thereby mitigating power side-channel attacks without requiring additional masking hardware or dual-rail logic structures that would increase energy consumption

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces dynamic dataflow switching where the processing path of data bytes is randomly permuted using an on-chip random number generator. This dynamic reconfiguration of the computational flow ensures that power consumption patterns change independently of the processed data, providing security against power analysis while maintaining efficient hardware utilization without expanding hardware area

Inventive Principle:
Principle #15Dynamics

2Reliability

If conventional techniques such as random masking and dual-rail logic are used to mitigate power side-channel attacks, then security against power analysis is improved, but hardware area increases significantly

Engineering Contradiction:
Improvesecurity against power side-channel attacksVSAvoidhardware area
Core Design Contradiction:
ReliabilityVSArea of stationary object

Solution Approach 1:

The patent makes the existing S-box modules multi-functional by implementing heterogeneous Galois-field arithmetic operations within the same hardware structure. The same physical S-box units can perform different types of cryptographic operations with different power signatures, eliminating the need for separate dedicated hardware for each operation type and avoiding hardware area expansion while maintaining security

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent employs an on-chip random number generator that uses minimal hardware resources to produce random permutation patterns for dataflow switching. This self-contained randomization mechanism provides security against power analysis without requiring external randomization hardware or additional large-area masking circuits, as the system generates its own randomization patterns using compact on-chip resources

Inventive Principle:
Principle #25Self-service

3Reliability

If multiple heterogeneous Galois-field arithmetic based S-box operations are implemented, then correlations between data and power signatures are reduced, but device complexity increases

Engineering Contradiction:
Improveresistance to power side-channel attacksVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the AES encryption process into distinct operational phases with different dataflow patterns. By dividing the computation into multiple rounds with heterogeneous S-box operations and random permutation steps, the complex security function is broken into manageable segments that can be implemented using standard AES accelerator components, thereby reducing overall device complexity while maintaining high resistance to power side-channel attacks

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10103873B2Power side-channel attack resistant advanced encryption standard accelerator processor
Publication Date: 2018.10.16 INTEL CORP
  • US10103873B2 patent drawing
  • US10103873B2 patent drawing
  • US10103873B2 patent drawing

AI summary

A processing system includes a processing core and a hardware accelerator communicatively coupled to the processing core. The hardware accelerator includes a random number generator to generate a byte order indicator. The hardware accelerator also includes a first switching module communicatively coupled to the random value indicator generator. The switching module receives an byte sequence in an encryption round of the cryptographic operation and feeds a portion of the input byte sequence to one of a first substitute box (S-box) module or a second S-box module in view of a byte order indicator value generated by the random number generator.