Blinding Intermediate Results in Cryptographic Multiplications
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Data processing devices, such as chip cards and smart cards, are vulnerable to side-channel attacks like differential power analysis, which can reveal private keys by analyzing current traces during cryptographic operations, especially in algorithms like Rivest-Shamir-Adleman and elliptic curve cryptography, where many multiplications are performed without protection.
Innovation Solution
The solution involves blinding intermediate results with a random variable during calculations, specifically in multiplications, to prevent differential power analysis attacks, without requiring the inversion of operands, using the Montgomery reduction method for efficient modular arithmetic in cryptographic operations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If cryptographic operations are performed without protection, then calculation speed and simplicity are improved, but vulnerability to differential power analysis attacks increases
Solution Approach 1:
The patent applies preliminary action by blinding intermediate results before they are used in subsequent calculations. A random variable is introduced to mask the intermediate results of multiplications, preventing attackers from analyzing power consumption patterns to derive private keys, while maintaining the correctness of the cryptographic operation.
Solution Approach 2:
The patent uses an intermediary approach by introducing a random variable as a mediator between the cryptographic operation and the attacker's analysis. This random variable acts as a masking layer that obscures the relationship between power consumption and the secret key, making differential power analysis ineffective.
2Reliability
If intermediate results are blinded using random variables, then security against differential power analysis is improved, but device complexity increases
Solution Approach 1:
The patent applies parameter changes by modifying the mathematical parameters of the cryptographic operation. Instead of changing the hardware architecture, the invention changes the mathematical parameters by introducing random variables and modular arithmetic operations that blind intermediate results, thereby securing the system without adding physical complexity.
3Reliability
If all inputs and outputs are masked as suggested by prior art, then security against differential power analysis is improved, but calculation complexity and time increase
Solution Approach 1:
The patent applies partial action by blinding only the intermediate results of multiplication operations rather than masking all inputs and outputs throughout the entire calculation process. This selective blinding approach provides sufficient security against differential power analysis while minimizing the overhead of additional masking operations.
Data Source
AI summary
In order to further develop an arrangement for as well as a method of protecting at least one data processing device, in particular at least one embedded system, for example at least one chip card or smart card, against at least one attack, in particular against at least one side-channel attack, for example against at least one current trace analysis, the data processing device, in particular at least one integrated circuit of the data processing device, carrying out calculations, in particular cryptographic operations wherein an attack, for example an E[lectro]M[agnetic] radiation attack, or an analysis, for example a D[ifferential]P[ower]A[nalysis], such attack or such analysis in particular targeted on finding out a private key, is to be securely averted, it is proposed to blind all intermediate results of the calculations by at least one random variable, without inverting any operand of the calculations.


