Crypto Hardware Hardening Control for Security-Performance Tradeoffs
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cryptographic implementations in semiconductor devices face challenges in balancing security, performance, and regulatory compliance, with hardening measures often leading to trade-offs and varying security requirements across different use cases and jurisdictions.
Innovation Solution
A method and semiconductor device that implement cryptographic functionalities with adaptable robustness levels based on configuration information, allowing flexible security adjustments and dynamic performance optimization, using hardware-based circuits and non-volatile memory for secure configuration, with attestation for external verification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If hardening measures (multiple computations, randomized delays, masked implementations) are applied to improve cryptographic security, then robustness against attacks is improved, but performance and power consumption deteriorate
Solution Approach 1:
The patent implements dynamic selection of hardening measures through configuration registers that allow the cryptographic unit to adapt its robustness level based on operational requirements. The system can switch between different security configurations (e.g., no masking, single masking, double masking) and adjust randomized delay parameters dynamically, enabling optimization between security and performance for different operational contexts
Solution Approach 2:
The patent changes key parameters of the cryptographic implementation including the degree of masking (0, 1, 2, 3 layers), repetition count (1, 2, 3, 4 computations), and randomized delay ranges. These parameters are configurable through control registers, allowing the system to adjust the intensity of hardening measures to achieve the desired balance between security robustness and processing performance
2Reliability
If hardening measures (multiple computations, masked implementations) are applied to improve cryptographic security, then robustness against attacks is improved, but power consumption increases
Solution Approach 1:
The patent implements dynamic power management for cryptographic operations by allowing the system to adjust hardening measures based on security requirements. When high security is not needed, the system can reduce or disable masking and repetition, thereby significantly reducing power consumption while maintaining adequate security for the given context
3Reliability
If different levels of hardening (single masking, double masking, triple masking) are applied to achieve varying degrees of protection, then security robustness is improved, but device complexity increases
Solution Approach 1:
The patent implements a universal cryptographic unit that can perform multiple cryptographic algorithms (AES, DES, RSA, ECC, SHA) with configurable hardening measures. The same hardware infrastructure supports different security levels through configuration registers, avoiding the need for separate dedicated circuits for each algorithm and security level, thereby managing complexity while providing comprehensive security options
Data Source
Figure 1

AI summary
A semiconductor device with configurable hardening of a crypto implementation is provided. The semiconductor device comprises a hardware-based semiconductor circuit that implements a crypto algorithm and non-volatile memory that stores configuration information. The robustness of the crypto implementation is adjusted based on the configuration information. The semiconductor device includes control logic configured to activate a variant or quality of hardening when performing a crypto operation. The hardening measures can include self-tests, side-channel hardening, re-computation, random delays, tamper sensor monitoring, and clock signal manipulation. The semiconductor device provides a cryptographically protected attestation confirming the activated hardening quality.A manipulation data recorder can record raw data during the execution of crypto operations or security-critical calculations for subsequent verification.