Bijective Memory Address Encryption via Modular Multiplication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing memory and address encryption techniques face challenges in smartcards and security devices due to power, area, and timing constraints, requiring improved concepts for efficient encryption that balance security and performance.

Innovation Solution

An apparatus and method utilizing a bijective map for memory address encryption, achieved through multiplication and modulo operations with cryptographic keys and divisors, allowing for efficient address scrambling while maintaining cryptographic strength and reducing power and area consumption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional memory encryption methods are used, then security is improved, but power consumption and area increase

Engineering Contradiction:
ImprovesecurityVSAvoidpower consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent transforms the encryption approach by changing the mathematical parameters used - specifically employing multiplication and modulo operations with carefully selected divisors that are powers of 2. This parameter change allows the encryption to be implemented efficiently in hardware with reduced power consumption while maintaining cryptographic strength through the bijective mapping property.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent replaces traditional complex encryption mechanisms with a simplified mathematical model based on modular multiplication. This substitution of the encryption mechanism with a more efficient mathematical operation reduces the hardware complexity and power requirements while preserving the essential security function of address encryption.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If traditional memory encryption methods are used, then security is improved, but device area increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice area
Core Design Contradiction:
ReliabilityVSArea of stationary object

Solution Approach 1:

By changing the mathematical parameters to use modulo operations with divisors that are powers of 2, the patent enables implementation using simple shift and add circuits rather than complex encryption logic. This parameter transformation dramatically reduces the hardware area required while maintaining the bijective mapping property essential for security.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent substitutes complex encryption circuitry with a streamlined mathematical operation system based on modular multiplication. This replacement reduces the physical device area by eliminating the need for large lookup tables or complex logic circuits, achieving area-efficient encryption suitable for smartcard implementations.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If complex encryption algorithms are used, then security is improved, but timing constraints are violated

Engineering Contradiction:
ImprovesecurityVSAvoidtiming performance
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent changes the computational parameters to use multiplication and modulo operations that can be executed in a fixed, small number of clock cycles. By selecting divisors that are powers of 2, the modulo operation becomes a simple bitwise AND operation, dramatically reducing the timing required while maintaining the cryptographic properties needed for security.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10176121B2Apparatus and method for memory address encryption
Publication Date: 2019.01.08 INFINEON TECHNOLOGIES AG
  • US10176121B2 patent drawing
  • US10176121B2 patent drawing
  • US10176121B2 patent drawing

AI summary

An apparatus for encrypting an input memory address to obtain an encrypted memory address is provided. The apparatus comprises an input interface for receiving the input memory address being an address of a memory. Moreover, the apparatus comprises an encryption module for encrypting the input memory address depending on a cryptographic key to obtain the encrypted memory address. The encryption module is configured to encrypt the input memory address by applying a map mapping the input memory address to the encrypted memory address, wherein the encryption module is configured to apply the map by conducting a multiplication and a modulo operation using the cryptographic key and a divisor of the modulo operation, such that the map is bijective.