Cryptographic Circuit Isolation for IoT Side-Channel Attack Mitigation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
IoT devices with embedded sensors are vulnerable to a new class of side-channel attacks that do not require physical access, allowing attackers to remotely compromise cryptographic keys by exploiting leakage of crypto information between cryptographic circuits and sensors or ADC circuits, potentially affecting a large number of devices.
Innovation Solution
Integrating cryptographic circuits with isolated operations relative to embedded sensors and ADC circuits, using electrical or logical isolation techniques such as separate power supply circuits, clock, and reset circuits, and time-division multiplexing to prevent the leakage of crypto information, thereby mitigating side-channel attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If cryptographic circuits are integrated with embedded sensors and ADC circuits on the same IC, then device functionality and versatility are improved, but vulnerability to remote side-channel attacks increases
Solution Approach 1:
The patent divides the integrated circuit into separate operational domains: a first domain for sensor and ADC operations, and a second domain for cryptographic operations. This segmentation prevents crypto information from leaking into sensor data while maintaining all functionalities on the same IC chip.
Solution Approach 2:
The patent introduces a domain separation mechanism as an intermediary between the sensor/ADC circuits and cryptographic circuits. This intermediary prevents direct information flow that could carry crypto leakage, allowing both functionalities to coexist securely on the same chip.
2Reliability
If separate power supply circuits, clock circuits, and reset circuits are used for cryptographic circuits, then security against side-channel attacks is improved, but device complexity increases
Solution Approach 1:
The patent segments the power supply, clock, and reset circuits into separate domains for cryptographic operations versus sensor/ADC operations. This segmentation ensures that power consumption patterns and timing information from cryptographic operations cannot be observed through sensor data, enhancing security.
Solution Approach 2:
The patent applies different quality characteristics to different parts of the circuit: cryptographic circuits receive isolated power, clock, and reset signals with specific timing and voltage characteristics, while sensor circuits receive different signals. This local differentiation ensures security without requiring complete system redesign.
3Reliability
If time-division multiplexing is used to isolate cryptographic operations from sensor operations, then side-channel attack resistance is improved, but operational speed decreases
Solution Approach 1:
The patent implements time-division multiplexing where cryptographic operations and sensor operations are separated into different time periods. During cryptographic time periods, sensor operations are suspended, and vice versa. This periodic separation prevents information leakage while allowing both functions to operate at their respective optimal speeds.
Solution Approach 2:
The patent dynamically controls the operation timing of different circuit blocks based on security requirements. The system can adjust the timing and duration of cryptographic versus sensor operations to balance security and performance needs in different operational contexts.
Data Source
AI summary
Embodiments include cryptographic circuits having isolated operation with respect to embedded sensor operations to mitigate side-channel attacks. A cryptographic circuit, a sensor, and an analog-to-digital converter (ADC) circuit are integrated into an integrated circuit along with a cryptographic circuit. A sensed signal is output with the sensor, and the sensed signal is converted to digital data using the ADC circuit. Further, cryptographic data is generated using one or more secret keys and the cryptographic circuit. The generation of the cryptographic data has isolated operation with respect to the operation of the sensor and the ADC circuit. The isolated operation mitigates side-channel attacks. The isolated operation can be achieved using power supply, clock, and/or reset circuits for the cryptographic circuit that are electrically isolated from similar circuits for the sensor and ADC circuit. The isolated operation can also be achieved using time-division multiplex operations. Other variations can also be implemented.


