CRT RSA Cryptography DFA Attack Protection via Pre-computed Lookup Tables

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for preventing differential fault analysis (DFA) attacks on Chinese Remainder Theorem (CRT) Rivest, Shamir, and Adleman (RSA) cryptography are time-consuming and ineffective, allowing unauthorized access to sensitive information.

Innovation Solution

The system performs modular exponentiation using composites of a private key and reconstructs the original message, incorporating a verification component that determines equivalence between received and reconstructed messages through CRT computations, thereby preventing DFA attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional methods are used to prevent DFA attacks, then security against attacks is improved, but processing time increases and effectiveness decreases

Engineering Contradiction:
Improvesecurity against DFA attacksVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-computing and storing lookup tables containing pre-calculated modular exponentiation results and CRT reconstruction values before actual cryptographic operations. When a signature operation is needed, the system retrieves pre-computed values from these lookup tables rather than performing time-consuming real-time calculations, thus maintaining security while significantly reducing processing time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system performs preliminary computation of multiple candidate private key components and stores them in lookup tables indexed by public key parameters. During actual operations, these pre-computed candidates are quickly retrieved and verified, eliminating the need for time-consuming iterative computations while maintaining resistance against DFA attacks through the use of multiple pre-vetted candidates.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If conventional methods are used to prevent DFA attacks, then security against attacks is improved, but attack effectiveness increases due to multiple executions requirement

Engineering Contradiction:
Improvesecurity against DFA attacksVSAvoidattack resistance efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent pre-computes multiple candidate private key components and stores them in lookup tables with indexes based on public key parameters. During cryptographic operations, the system retrieves these pre-computed candidates and performs verification using CRT reconstruction, eliminating the need for attackers to rely on multiple executions to detect faults, thus significantly improving resistance efficiency against DFA attacks.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms where CRT reconstruction results are verified against expected values, and lookup tables are dynamically updated based on verification outcomes. This feedback loop ensures that only valid private key candidates are used, providing immediate detection and rejection of faulty computations, thereby enhancing productivity in resisting DFA attacks without requiring multiple external executions.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If CRT RSA cryptography is implemented on embedded devices, then device functionality is improved, but vulnerability to DFA attacks increases

Engineering Contradiction:
Improveembedded device compatibilityVSAvoidvulnerability to DFA attacks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent pre-computes and stores multiple candidate private key components in lookup tables specifically optimized for embedded device constraints. These pre-computed candidates incorporate CRT parameters and are indexed for quick retrieval based on public key information. During operations on embedded devices, the system retrieves these pre-vetted candidates and performs verification, maintaining embedded device compatibility while eliminating vulnerability to DFA attacks through the use of pre-validated candidates.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system introduces lookup tables as an intermediary structure between the embedded device's cryptographic operations and the security requirements. These lookup tables store pre-computed CRT parameters and candidate values that mediate between the limited computational resources of embedded devices and the need for robust DFA attack resistance, enabling secure operations without requiring complex real-time computations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8774400B2Method for protecting data against differntial fault analysis involved in rivest, shamir, and adleman cryptography using the chinese remainder theorem
Publication Date: 2014.07.08 SPANSION LLC
  • US8774400B2 patent drawing
  • US8774400B2 patent drawing
  • US8774400B2 patent drawing

AI summary

Systems and methods for effectively protecting data against differential fault analysis involved in Rivest, Shamir, and Adleman (“RSA”) cryptography using the Chinese Remainder Theorem (“CRT”) are described herein. A CRT RSA component facilitates modular exponentiation of a received message, and a verification component reconstructs the received message. An exponentiation component performs a first modular exponentiation and a second modular exponentiation of the received message. A recombination component performs a recombination step utilizing CRT computation as a function of the first and second modular exponentiations. A modular exponentiation component performs first and second public exponent derivations as a function of a private exponent. The verification component can reconstructs the received message as a function of the first and second public exponent derivations. The verification component calculates the received message utilizing Chinese Remainder Theorem computation.