Concurrent Encryption Decryption Scheduler Obfuscating Power Traces
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Portable, battery-powered devices used in artificial reality systems, such as head-mounted displays and peripheral devices, are vulnerable to side-channel attacks due to their low-power designs and portable form factors, which exploit timing information, power consumption, and electromagnetic traces.
Innovation Solution
Implementing a scheduler that causes the encryption and decryption engines within a System on a Chip (SoC) to operate simultaneously using different keys, creating cross-interference that garbles power signatures and renders side-channel attacks unsuccessful by scheduling concurrent encryption and decryption operations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Use of energy by moving object
If the device uses low-power design and portable form factor, then battery life and portability are improved, but vulnerability to side-channel attacks increases
Solution Approach 1:
The patent converts the harmful power consumption signals that leak to side-channels into a beneficial obfuscation mechanism. By intentionally introducing power variations through concurrent encryption/decryption operations with different keys, the system transforms the previously exploitable power traces into scrambled, unintelligible signals that prevent side-channel attacks while maintaining low-power operation
Solution Approach 2:
The system performs preliminary anti-action by proactively executing encryption and decryption operations simultaneously with different keys before any side-channel attack can occur. This preliminary concurrent operation pre-establishes the obfuscation effect, ensuring that power traces are already scrambled when attackers attempt to measure them
2Device complexity
If encryption and decryption engines operate sequentially, then hardware resource usage is reduced, but processing throughput decreases
Solution Approach 1:
The patent merges the encryption and decryption operations into a single concurrent execution unit. By combining both operations to run simultaneously on different data with different keys, the system achieves better hardware utilization and eliminates idle time between operations, thereby increasing throughput without requiring separate dedicated hardware pipelines
Solution Approach 2:
The system performs preliminary scheduling actions to prepare encryption and decryption operations for concurrent execution. The scheduler预先 arranges data availability and operation timing so that both engines can start simultaneously without resource conflicts, maximizing throughput while managing hardware resources efficiently
3Object-affected harmful factors
If a scheduler is added to manage concurrent operations, then side-channel attack resistance is improved, but device complexity increases
Solution Approach 1:
The scheduler is designed with multi-functionality to reduce overall system complexity. It simultaneously performs task scheduling, key management coordination, and power trace obfuscation control within a single component. This universal approach consolidates multiple functions that could have been separate, thereby limiting the increase in device complexity while achieving comprehensive side-channel attack resistance
Data Source
AI summary
This disclosure describes systems on a chip (SOCs) that prevent side channel attacks on encryption and decryption engines of an electronic device. The SoCs of this disclosure concurrently operate key-diverse encryption and decryption datapaths to obfuscate the power trace signature exhibited by the device that includes the SoC. An example SoC includes an encryption engine configured to encrypt transmission (Tx) channel data using an encryption key and a decryption engine configured to decrypt encrypted received (Rx) channel data using a decryption key that is different from the encryption key. The SoC also includes a scheduler configured to establish concurrent data availability between the encryption and decryption engines and activate the encryption engine and the decryption engine to cause the encryption engine to encrypt the Tx channel data concurrently with the decryption engine decrypting the encrypted Rx channel data using the decryption key that is different from the encryption key.


