Crypto Hardware Hardening Control for Security-Performance Tradeoffs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cryptographic implementations in semiconductor devices face challenges in balancing security, performance, and regulatory compliance, with hardening measures often leading to trade-offs and varying security requirements across different use cases and jurisdictions.

Innovation Solution

A method and semiconductor device that implement cryptographic functionalities with adaptable robustness levels based on configuration information, allowing flexible security adjustments and dynamic performance optimization, using hardware-based circuits and non-volatile memory for secure configuration, with attestation for external verification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If hardening measures (multiple computations, randomized delays, masked implementations) are applied to improve cryptographic security, then robustness against attacks is improved, but performance and power consumption deteriorate

Engineering Contradiction:
Improvecryptographic security robustnessVSAvoidprocessing performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements dynamic selection of hardening measures through configuration registers that allow the cryptographic unit to adapt its robustness level based on operational requirements. The system can switch between different security configurations (e.g., no masking, single masking, double masking) and adjust randomized delay parameters dynamically, enabling optimization between security and performance for different operational contexts

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes key parameters of the cryptographic implementation including the degree of masking (0, 1, 2, 3 layers), repetition count (1, 2, 3, 4 computations), and randomized delay ranges. These parameters are configurable through control registers, allowing the system to adjust the intensity of hardening measures to achieve the desired balance between security robustness and processing performance

Inventive Principle:
Principle #35Parameter changes

2Reliability

If hardening measures (multiple computations, masked implementations) are applied to improve cryptographic security, then robustness against attacks is improved, but power consumption increases

Engineering Contradiction:
Improvecryptographic security robustnessVSAvoidpower consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent implements dynamic power management for cryptographic operations by allowing the system to adjust hardening measures based on security requirements. When high security is not needed, the system can reduce or disable masking and repetition, thereby significantly reducing power consumption while maintaining adequate security for the given context

Inventive Principle:
Principle #15Dynamics

3Reliability

If different levels of hardening (single masking, double masking, triple masking) are applied to achieve varying degrees of protection, then security robustness is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity protection levelVSAvoidimplementation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal cryptographic unit that can perform multiple cryptographic algorithms (AES, DES, RSA, ECC, SHA) with configurable hardening measures. The same hardware infrastructure supports different security levels through configuration registers, avoiding the need for separate dedicated circuits for each algorithm and security level, thereby managing complexity while providing comprehensive security options

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP4700626A1Method for implementing a cryptographic functionality in a semiconductor component, and semiconductor component
Publication Date: 2026.02.25 SIEMENS AG
  • EP4700626A1 patent drawingFigure 1
  • EP4700626A1 patent drawing
  • EP4700626A1 patent drawing

AI summary

A semiconductor device with configurable hardening of a crypto implementation is provided. The semiconductor device comprises a hardware-based semiconductor circuit that implements a crypto algorithm and non-volatile memory that stores configuration information. The robustness of the crypto implementation is adjusted based on the configuration information. The semiconductor device includes control logic configured to activate a variant or quality of hardening when performing a crypto operation. The hardening measures can include self-tests, side-channel hardening, re-computation, random delays, tamper sensor monitoring, and clock signal manipulation. The semiconductor device provides a cryptographically protected attestation confirming the activated hardening quality.A manipulation data recorder can record raw data during the execution of crypto operations or security-critical calculations for subsequent verification.