Cryptographic Circuit Isolation for IoT Side-Channel Attack Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

IoT devices with embedded sensors are vulnerable to a new class of side-channel attacks that do not require physical access, allowing attackers to remotely compromise cryptographic keys by exploiting leakage of crypto information between cryptographic circuits and sensors or ADC circuits, potentially affecting a large number of devices.

Innovation Solution

Integrating cryptographic circuits with isolated operations relative to embedded sensors and ADC circuits, using electrical or logical isolation techniques such as separate power supply circuits, clock, and reset circuits, and time-division multiplexing to prevent the leakage of crypto information, thereby mitigating side-channel attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If cryptographic circuits are integrated with embedded sensors and ADC circuits on the same IC, then device functionality and versatility are improved, but vulnerability to remote side-channel attacks increases

Engineering Contradiction:
Improvedevice functionalityVSAvoidvulnerability to side-channel attacks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent divides the integrated circuit into separate operational domains: a first domain for sensor and ADC operations, and a second domain for cryptographic operations. This segmentation prevents crypto information from leaking into sensor data while maintaining all functionalities on the same IC chip.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a domain separation mechanism as an intermediary between the sensor/ADC circuits and cryptographic circuits. This intermediary prevents direct information flow that could carry crypto leakage, allowing both functionalities to coexist securely on the same chip.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If separate power supply circuits, clock circuits, and reset circuits are used for cryptographic circuits, then security against side-channel attacks is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidcircuit complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the power supply, clock, and reset circuits into separate domains for cryptographic operations versus sensor/ADC operations. This segmentation ensures that power consumption patterns and timing information from cryptographic operations cannot be observed through sensor data, enhancing security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different quality characteristics to different parts of the circuit: cryptographic circuits receive isolated power, clock, and reset signals with specific timing and voltage characteristics, while sensor circuits receive different signals. This local differentiation ensures security without requiring complete system redesign.

Inventive Principle:
Principle #3Local quality

3Reliability

If time-division multiplexing is used to isolate cryptographic operations from sensor operations, then side-channel attack resistance is improved, but operational speed decreases

Engineering Contradiction:
Improveattack resistanceVSAvoidoperational speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent implements time-division multiplexing where cryptographic operations and sensor operations are separated into different time periods. During cryptographic time periods, sensor operations are suspended, and vice versa. This periodic separation prevents information leakage while allowing both functions to operate at their respective optimal speeds.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The patent dynamically controls the operation timing of different circuit blocks based on security requirements. The system can adjust the timing and duration of cryptographic versus sensor operations to balance security and performance needs in different operational contexts.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11663366B2Side-channel attack mitigation for secure devices with embedded sensors
Publication Date: 2023.05.30 SILICON LABORATORIES INC
  • US11663366B2 patent drawing
  • US11663366B2 patent drawing
  • US11663366B2 patent drawing

AI summary

Embodiments include cryptographic circuits having isolated operation with respect to embedded sensor operations to mitigate side-channel attacks. A cryptographic circuit, a sensor, and an analog-to-digital converter (ADC) circuit are integrated into an integrated circuit along with a cryptographic circuit. A sensed signal is output with the sensor, and the sensed signal is converted to digital data using the ADC circuit. Further, cryptographic data is generated using one or more secret keys and the cryptographic circuit. The generation of the cryptographic data has isolated operation with respect to the operation of the sensor and the ADC circuit. The isolated operation mitigates side-channel attacks. The isolated operation can be achieved using power supply, clock, and/or reset circuits for the cryptographic circuit that are electrically isolated from similar circuits for the sensor and ADC circuit. The isolated operation can also be achieved using time-division multiplex operations. Other variations can also be implemented.