Cipher Processor Guard Rounds Side-Channel Attack Obfuscation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern cryptographic systems are vulnerable to side-channel attacks that exploit power consumption and electromagnetic emanations to obtain secret information about cryptographic keys, which can compromise the security of the system.

Innovation Solution

The method involves inserting extra data, known as guard rounds, within the cipher processor's operations to obfuscate the output data and expand the secret key, ensuring that the processing of data streams is interleaved and includes dummy rounds to make it difficult for adversaries to analyze the power signatures and timing of the encryption process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional cipher processing is used, then processing speed and efficiency are maintained, but the system becomes vulnerable to side-channel attacks that can extract secret key information

Engineering Contradiction:
Improvesecurity against side-channel attacksVSAvoidcipher processing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by performing guard rounds before the actual cipher processing of secret data. These preliminary operations initialize the cipher state and consume power in a predictable pattern that masks subsequent operations, preventing attackers from correlating power consumption with specific cryptographic operations on secret data.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses intermediary data (dummy data and guard rounds) as mediators between the attacker and the secret key processing. These intermediaries create noise and confusion in the power consumption profile, making it difficult for attackers to extract meaningful information about the secret key while the actual cryptographic operations proceed normally.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If guard rounds and dummy data are inserted to obfuscate processing, then resistance to side-channel attacks increases, but processing time and computational overhead increase

Engineering Contradiction:
Improveresistance to side-channel attacksVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies partial action by inserting a specific number of guard rounds (at least one) and dummy data operations that provide sufficient masking against side-channel attacks without excessively prolonging processing time. The number of guard rounds is calibrated to provide adequate security coverage while minimizing performance degradation.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent changes operational parameters by dynamically adjusting the number of guard rounds and dummy data insertions based on security requirements and performance constraints. This allows optimization of the balance between security strength and processing speed for different application scenarios.

Inventive Principle:
Principle #35Parameter changes

3Object-affected harmful factors

If extra data is inserted within the cipher processor for obfuscation, then power consumption analysis becomes more difficult, but energy consumption increases

Engineering Contradiction:
Improvevulnerability to power analysisVSAvoidenergy consumption
Core Design Contradiction:
Object-affected harmful factorsVSUse of energy by moving object

Solution Approach 1:

The patent converts the harmful effect of power consumption (which leaks information) into a beneficial masking mechanism. By intentionally introducing dummy operations and guard rounds that consume power in predictable patterns, the actual power consumption signature of secret key operations is obscured, turning energy consumption from an attack vector into a security feature.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Data Source

PatentUS10740497B2System and method for cryptographic processing in a time window
Publication Date: 2020.08.11 SYNOPSYS INC
  • US10740497B2 patent drawing
  • US10740497B2 patent drawing
  • US10740497B2 patent drawing

AI summary

A method is disclosed for providing first data and a first secret key to a cipher processor for ciphering. The first data is ciphered in accordance with a first cipher process and the first secret key to provide output data. Before ciphering of the first data, extra data is inserted within the cipher processor for ciphering in accordance with at least a portion of said first cipher process. The extra data is inserted within a sequence of cipher processor operations for obfuscating the output data.