Configurable Cryptographic Component for Dynamic DPA Countermeasure Activation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cryptographic systems face performance degradation when implementing Differential Power Analysis (DPA) countermeasures, as they often require additional components or reduced data throughput to protect against DPA attacks, which is inefficient for operations not requiring such measures.

Innovation Solution

Configurable cryptographic components that can dynamically switch between providing DPA countermeasures and standard operations based on control signals, allowing for flexible utilization of resources and maintaining performance without unnecessary countermeasures when not required.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If DPA countermeasures are implemented in cryptographic operations, then security against DPA attacks is improved, but device complexity and resource overhead increase

Engineering Contradiction:
Improvesecurity against DPA attacksVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic configuration of cryptographic components where DPA countermeasures can be enabled or disabled based on operational requirements. The system transitions from static always-on countermeasures to dynamic conditional activation, allowing the device to adjust its security posture according to the specific cryptographic operation being performed and the threat model.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent applies DPA countermeasures selectively to specific cryptographic operations or components rather than uniformly across the entire system. Different cryptographic operations can be configured with different levels of protection, applying countermeasures only where necessary based on the sensitivity and risk assessment of each operation.

Inventive Principle:
Principle #3Local quality

2Reliability

If DPA countermeasures are implemented in cryptographic operations, then security against DPA attacks is improved, but data throughput decreases

Engineering Contradiction:
Improvesecurity against DPA attacksVSAvoiddata throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system dynamically adjusts the level of DPA countermeasure activation based on the operational context. When countermeasures are not required, the system operates at full speed without security overhead. When protection is needed, the system activates appropriate countermeasures, creating a dynamic balance between security and performance.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent implements partial DPA countermeasures that provide sufficient protection without requiring full-scale countermeasure implementation. By applying countermeasures only to the extent necessary for the specific threat level and operational context, the system maintains acceptable performance while achieving adequate security.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If DPA countermeasures are always implemented, then security is consistently maintained, but resource overhead increases unnecessarily

Engineering Contradiction:
Improvesecurity consistencyVSAvoidresource overhead
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The system transitions from static always-on security to dynamic conditional security activation. The configuration mechanism allows the system to automatically adjust its security posture based on the specific cryptographic operation, the required security level, and the operational context, thereby eliminating unnecessary resource consumption.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent implements configurable parameters that allow dynamic adjustment of countermeasure intensity and activation thresholds. By changing these parameters based on operational requirements, the system optimizes the balance between security coverage and resource consumption, avoiding both under-protection and over-engineering.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11228422B2Configuring a device based on a DPA countermeasure
Publication Date: 2022.01.18 CRYPTOGRAPHY RESEARCH INC
  • US11228422B2 patent drawing
  • US11228422B2 patent drawing
  • US11228422B2 patent drawing

AI summary

Input signals may be received. Furthermore, a control signal controlling the implementation of a Differential Power Analysis (DPA) countermeasure may be received. One of the input signals may be transmitted as an output signal based on the control signal. A cryptographic operation may be performed based on the first output signal that is transmitted based on the control signal.