Cryptographic Unit Fault Detection via Asymmetric AES Processing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cryptographic systems, particularly those using the AES algorithm, face significant challenges in detecting and mitigating fault attacks, especially multiple bit faults, which can compromise encryption and decryption processes, leading to security vulnerabilities and reduced data throughput.
Innovation Solution
The implementation of a cryptographic unit with separate processing units generating comparison signals through distinct operations, such as Subbyte, ShiftRows, MixColumns, and AddRoundKey, and their inverse operations, allows for enhanced fault detection by ensuring that comparison signals are related in a predetermined way, enabling defense measures against output tapping and improving fault detection capabilities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple repetition of encryption and decryption is used for fault detection, then fault detection capability is improved, but data throughput is reduced by approximately half
Solution Approach 1:
The cryptographic unit is divided into multiple independent processing units (first processing unit, second processing unit, third processing unit, fourth processing unit), each handling specific rounds of the AES algorithm. This segmentation allows parallel processing of different data paths, achieving fault detection without sequential repetition that would halve throughput.
Solution Approach 2:
The invention transitions from temporal redundancy (repeating encryption/decryption sequences) to spatial redundancy (parallel processing paths). By using multiple processing units operating simultaneously on different data paths and comparing results, the system achieves fault detection while maintaining throughput through dimensional transformation of the redundancy approach.
2Reliability
If identical duplication with comparison is used for fault detection, then all faults are detected, but hardware effort is high and security gaps remain due to equal faults possibility
Solution Approach 1:
The invention employs asymmetric processing paths where the first processing unit executes encryption with MixColumns operation while the second processing unit executes decryption with inverse MixColumns operation. This asymmetry ensures that faults affecting both identical paths simultaneously are highly improbable, eliminating the security gap while maintaining hardware efficiency through operational diversity rather than simple duplication.
Solution Approach 2:
The invention creates functional copies of cryptographic processing through multiple processing units that perform different operations (encryption/decryption, MixColumns/inverse MixColumns). These copies are not identical but functionally equivalent in detecting faults, reducing hardware effort compared to full identical duplication while maintaining comprehensive fault detection capability.
3Productivity
If only last or last two rounds are calculated repeatedly for fault detection, then data throughput reduction is minimized, but sophisticated cryptographic analysis methods may still succeed
Solution Approach 1:
The cryptographic unit implements multi-functional processing where processing units can handle different rounds and operations (encryption, decryption, MixColumns, inverse MixColumns). This universality allows comprehensive fault detection across all rounds simultaneously through parallel processing, rather than limiting detection to only the last rounds, thereby maintaining both high throughput and robust security against sophisticated attacks.
Data Source
AI summary
A cryptographic unit includes a first processing unit for determining an output signal on the basis of the AES algorithm and for determining a first comparison signal, a second processing unit for determining a second comparison signal, and a release unit for providing the output signal, wherein the release unit is designed to perform a defense measure against an external tapping of the output signal when the first comparison signal is not related to the second comparison signal in a predetermined relationship. The first comparison signal is determined in a different way as compared to the second comparison signal, so that, in the case of the injection of faults into the cryptographic unit, these faults may be detected very easily.


