Blinding Intermediate Results in Cryptographic Multiplications

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Data processing devices, such as chip cards and smart cards, are vulnerable to side-channel attacks like differential power analysis, which can reveal private keys by analyzing current traces during cryptographic operations, especially in algorithms like Rivest-Shamir-Adleman and elliptic curve cryptography, where many multiplications are performed without protection.

Innovation Solution

The solution involves blinding intermediate results with a random variable during calculations, specifically in multiplications, to prevent differential power analysis attacks, without requiring the inversion of operands, using the Montgomery reduction method for efficient modular arithmetic in cryptographic operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If cryptographic operations are performed without protection, then calculation speed and simplicity are improved, but vulnerability to differential power analysis attacks increases

Engineering Contradiction:
Improvecalculation speedVSAvoidsecurity against differential power analysis
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies preliminary action by blinding intermediate results before they are used in subsequent calculations. A random variable is introduced to mask the intermediate results of multiplications, preventing attackers from analyzing power consumption patterns to derive private keys, while maintaining the correctness of the cryptographic operation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses an intermediary approach by introducing a random variable as a mediator between the cryptographic operation and the attacker's analysis. This random variable acts as a masking layer that obscures the relationship between power consumption and the secret key, making differential power analysis ineffective.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If intermediate results are blinded using random variables, then security against differential power analysis is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity against differential power analysisVSAvoidcomplexity of cryptographic implementation
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies parameter changes by modifying the mathematical parameters of the cryptographic operation. Instead of changing the hardware architecture, the invention changes the mathematical parameters by introducing random variables and modular arithmetic operations that blind intermediate results, thereby securing the system without adding physical complexity.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If all inputs and outputs are masked as suggested by prior art, then security against differential power analysis is improved, but calculation complexity and time increase

Engineering Contradiction:
Improvesecurity against differential power analysisVSAvoidcalculation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies partial action by blinding only the intermediate results of multiplication operations rather than masking all inputs and outputs throughout the entire calculation process. This selective blinding approach provides sufficient security against differential power analysis while minimizing the overhead of additional masking operations.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS8738927B2Arrangement for and method of protecting a data processing device against an attack or analysis
Publication Date: 2014.05.27 IRDETO BV
  • US8738927B2 patent drawing
  • US8738927B2 patent drawing
  • US8738927B2 patent drawing

AI summary

In order to further develop an arrangement for as well as a method of protecting at least one data processing device, in particular at least one embedded system, for example at least one chip card or smart card, against at least one attack, in particular against at least one side-channel attack, for example against at least one current trace analysis, the data processing device, in particular at least one integrated circuit of the data processing device, carrying out calculations, in particular cryptographic operations wherein an attack, for example an E[lectro]M[agnetic] radiation attack, or an analysis, for example a D[ifferential]P[ower]A[nalysis], such attack or such analysis in particular targeted on finding out a private key, is to be securely averted, it is proposed to blind all intermediate results of the calculations by at least one random variable, without inverting any operand of the calculations.