Clock Period Randomizer for Cryptographic Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern cryptographic systems are vulnerable to side-channel and fault injection attacks, which can compromise security by extracting secret keys due to their reliance on fixed clock periods, making it easier for attackers to determine key bits and disrupt device operations.

Innovation Solution

Implementing a clock period randomizer that generates a variable clock period during cryptographic operations, using a combination of fixed and variable delay generators controlled by a trim code generator, which includes a random number or pseudorandom number generator to vary the clock signal, making it difficult for attackers to predict the clock cycle and inject faults effectively.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a fixed clock period is used in cryptographic operations, then the device operates efficiently and predictably, but the device becomes vulnerable to side-channel and fault injection attacks

Engineering Contradiction:
Improvesecurity against cryptographic attacksVSAvoidclock period randomization mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent changes the clock period parameter from a fixed value to a variable value that can be randomly selected from multiple possible periods. This is achieved by implementing a clock period randomizer that selects different clock periods based on random or pseudorandom values, making it difficult for attackers to predict the clock cycle timing and successfully execute timing-based cryptographic attacks.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If the clock period is varied randomly during cryptographic operations, then the difficulty for attackers to extract keys increases, but the predictability and efficiency of device operation decreases

Engineering Contradiction:
Improvesecurity against key extraction attacksVSAvoidpredictability of clock cycle
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements dynamic clock period adjustment by introducing a clock period randomizer that can change the clock period during operation. The system dynamically selects from multiple predefined clock periods (e.g., first clock period, second clock period, third clock period) based on random or pseudorandom selection, allowing the clock characteristics to adapt and change rather than remaining static and predictable.

Inventive Principle:
Principle #15Dynamics

3Object-affected harmful factors

If multiple clock periods are implemented with random selection, then fault injection attacks become less effective, but the device complexity and control mechanism increase

Engineering Contradiction:
Improveeffectiveness of fault injection attacksVSAvoidclock period control mechanism
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent introduces a clock period randomizer as an intermediary component between the clock source and the cryptographic processing unit. This intermediary selectively applies different clock periods to the cryptographic operations, adding a layer of indirection that prevents attackers from directly controlling or predicting the clock timing, thereby reducing the effectiveness of fault injection and timing attacks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11750361B2Clock period randomization for defense against cryptographic attacks
Publication Date: 2023.09.05 GOOGLE LLC
  • US11750361B2 patent drawing
  • US11750361B2 patent drawing
  • US11750361B2 patent drawing

AI summary

Methods, systems, and apparatuses for defending against cryptographic attacks using clock period randomization. The methods, systems, and apparatuses are designed to make side channel attacks and fault injection attacks more difficult by using a clock with a variable period during a cryptographic operation. In an example embodiment, a clock period randomizer includes a fixed delay generator and a variable delay generator, wherein a variable delay generated by the variable delay generator is based on a random or pseudorandom value that is changed occasionally or periodically. The methods, systems, and apparatuses are useful in hardware security applications where fault injection and/or side channel attacks are of concern.