Constant-Weight Chip Card Encoding for Low-Memory Secure Operations

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing encryption methods for smart cards, such as constant weight codes and Dual Rail encryption, are ineffective in preventing side-channel attacks and error injection attacks due to memory constraints, making it difficult to perform operations on encoded data in low-memory devices like smart cards.

Innovation Solution

A method that encodes data into code words with a predefined constant Hamming weight by decomposing the data into multiple sequences, coding each sequence into partial code words, and concatenating them to form a code word, allowing for operations to be performed on the encoded data while maintaining security against side-channel attacks and error injection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If Dual Rail encryption is used to encrypt data, then security against side-channel attacks is improved, but the size of encoded data doubles making operations impossible on smart cards

Engineering Contradiction:
Improvesecurity against side-channel attacksVSAvoidsize of encoded data
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The invention divides the data into multiple sequences (e.g., 4 sequences of 2 bits each from an 8-bit datum) and encodes each sequence separately into a partial code word. This segmentation allows the total code word size to be controlled and kept smaller than what would be required by Dual Rail encryption, while still providing security against side-channel attacks through constant Hamming weight encoding.

Inventive Principle:
Principle #1Segmentation

2Reliability

If constant weight codes are used to protect against side-channel attacks, then power consumption becomes constant, but operations on encoded data require too much memory for smart cards

Engineering Contradiction:
Improveprotection against side-channel attacksVSAvoidmemory requirements for operations
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

By segmenting data into multiple smaller sequences that are independently encoded into partial code words, the invention enables operations to be performed on these smaller units. The partial code words can be manipulated with lower memory requirements compared to operating on fully expanded constant weight codes, making smart card implementation feasible while maintaining security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The invention transitions from operating on complete code words to operating on partial code words derived from segmented sequences. This dimensional change in the operational space allows for more efficient memory usage during cryptographic operations while maintaining the security benefits of constant Hamming weight encoding.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Reliability

If data is encoded with constant Hamming weight, then detection of error injection attacks becomes possible, but the encoding size becomes too large for practical smart card implementation

Engineering Contradiction:
Improvedetection of error injection attacksVSAvoidencoding size
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The invention segments the original data into multiple smaller sequences before encoding each into partial code words. This segmentation maintains the constant Hamming weight property for error detection capability while keeping the total encoding size manageable for smart card implementation by controlling the number and length of sequences.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9886597B2Method for encoding data on a chip card by means of constant-weight codes
Publication Date: 2018.02.06 IDEMIA FRANCE SAS
  • US9886597B2 patent drawing
  • US9886597B2 patent drawing
  • US9886597B2 patent drawing

AI summary

The invention relates to a data-processing method that includes encoding a plurality of data of n bits into code words having a predefined constant Hamming weight, characterized in that said method also includes using (4000) encryption operations or arithmetic operations on the resulting code word(s) and also in that encoding each datum includes: decomposing (100) the datum into a plurality of m bit sequences to be encoded, m strictly being less than n; encoding (300) each bit sequence into a partial code word, each having a predefined Hamming weight, such that the sum of the Hamming weights of the partial code words are equal to the Hamming weights of the code word; and concatenating (300) the partial code words such as to produce the code word corresponding to the datum. The invention also relates to a data transmission method and to an electronic circuit configured to implement said methods.