Asynchronous Clock Domain for Encryption Engine Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing encryption circuits are vulnerable to power analysis attacks, where fluctuations in power consumption reveal encryption keys, and existing countermeasures are costly in terms of power consumption and circuitry size.
Innovation Solution
An independent, asynchronous clock is used for the encryption engine, running at a faster rate than other clocks on the logic device, with data buffering and random noise generation to obscure power consumption patterns, ensuring the clock is not externally accessible.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing countermeasures (evening out power draw, performing unnecessary operations, adding random noise) are applied to protect circuits from power analysis attacks, then security against power analysis attacks is improved, but power consumption and circuitry size increase significantly (sometimes tripling the size of encryption circuits)
Solution Approach 1:
The patent divides the encryption system into two separate clock domains: a public clock domain for configuration and control, and a private asynchronous clock domain for the encryption engine. This segmentation isolates the power consumption of the encryption engine from the public clock domain, preventing power analysis attacks while avoiding the need for additional protective circuitry that would increase power consumption.
Solution Approach 2:
The patent introduces an asynchronous clock as an intermediary between the public control signals and the encryption engine. This intermediary clock domain acts as a barrier that decouples the power consumption patterns of the encryption engine from external observation, providing security without requiring additional protective components that would increase overall power consumption.
2Reliability
If existing countermeasures (evening out power draw, performing unnecessary operations, adding random noise) are applied to protect circuits from power analysis attacks, then security against power analysis attacks is improved, but circuitry size increases significantly (sometimes tripling the size of encryption circuits)
Solution Approach 1:
The patent segments the clocking architecture into distinct asynchronous domains, allowing the encryption engine to operate in isolation from the main system clock. This segmentation provides security through architectural design rather than through additional protective circuitry, thereby avoiding significant increases in device complexity.
Solution Approach 2:
The patent changes the fundamental parameter of clock synchronization by transitioning from a synchronized clock domain to an asynchronous clock domain for the encryption engine. This parameter change provides security through the inherent unpredictability of asynchronous operation, eliminating the need for complex protective circuitry that would increase device complexity.
3Reliability
If an asynchronous clock running at a faster rate is used for the encryption engine, then security against power analysis attacks is improved by making synchronization difficult, but data buffering requirements increase to handle clock domain transitions
Solution Approach 1:
The patent uses asynchronous FIFO buffers as intermediaries to handle data transfer between the fast asynchronous encryption engine clock domain and the slower public clock domain. These buffers efficiently manage the clock domain transitions without requiring complex synchronization circuitry, providing security while minimizing the increase in device complexity.
Solution Approach 2:
The patent employs FIFO buffers that copy data between clock domains, allowing the encryption engine to operate independently at its optimal fast rate while maintaining compatibility with the public interface. This copying mechanism simplifies the interface between clock domains compared to more complex synchronization schemes.
Data Source
AI summary
Techniques of the present invention impede power consumption measurements of an encryption engine on a logic device by running the encryption engine with an independent clock. This clock produces a signal that is decoupled from and asynchronous to clock signals feeding other circuits on the device. The clock feeding the encryption engine is not accessible externally to the device. Circuits may be employed to intentionally slow down or add jitter to one or more of the clock signals.


