Cryptographic Operation Concealment via Noise Injection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current defense measures are inadequate against Machine Learning-assisted Differential Power Analysis (DPA) and Electro-Magnetic Interference (EMI) attacks on hardware cryptographic accelerators, as they fail to effectively conceal operations and mask electromagnetic and power noise, allowing attackers to target sensitive parts of a system on a chip.

Innovation Solution

The implementation of operation concealment features in cryptographic systems, which involve selecting cryptographic operation blocks using pseudorandom or truly random sequences, adding noise to input data or keys, and distributing sensitive operations across a chip to create randomness and mask emissions, making it difficult for attackers to correlate measurements and apply models across devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If cryptographic operation blocks are concentrated in a single location on the chip, then operational efficiency is improved, but vulnerability to side-channel attacks increases

Engineering Contradiction:
Improveoperational efficiencyVSAvoidvulnerability to side-channel attacks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The cryptographic system is divided into multiple operation blocks (first cryptographic operation block, second cryptographic operation block, etc.) distributed across different locations on the chip. Each block can independently perform cryptographic operations, allowing the system to maintain high productivity through parallel processing while reducing vulnerability to side-channel attacks by spatially separating the operations.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent transitions from a single-location concentrated architecture to a multi-location distributed architecture by adding the spatial dimension to the system design. This dimensional change allows operations to be spread across the chip surface, maintaining operational efficiency through concurrency while effectively counteracting side-channel attacks that rely on localized electromagnetic or power analysis.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Device complexity

If cryptographic operations are performed using a single operation block, then device complexity is reduced, but the ability to mask electromagnetic emissions is weakened

Engineering Contradiction:
Improvenumber of operation blocksVSAvoidelectromagnetic emission masking capability
Core Design Contradiction:
Device complexityVSObject-generated harmful factors

Solution Approach 1:

Multiple cryptographic operation blocks are merged into a single cryptographic system that works cooperatively. The blocks share common interfaces and coordination mechanisms, allowing them to function as a unified system. This merging approach enables effective electromagnetic emission masking through correlated operations while maintaining manageable device complexity through standardized interfaces and control logic.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces selection circuitry and control logic as intermediaries that coordinate between multiple cryptographic operation blocks. These intermediary components manage the complexity of having multiple blocks by providing standardized selection and control mechanisms, allowing the system to leverage the emission-masking benefits of multiple blocks without proportionally increasing overall system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If deterministic routing is used between cryptographic blocks, then ease of operation is improved, but the ability to conceal operation patterns is reduced

Engineering Contradiction:
Improverouting predictabilityVSAvoidoperation pattern concealment
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The routing between cryptographic operation blocks is made dynamic rather than static. Selection circuitry controlled by pseudorandom sequences dynamically determines which blocks receive keys and perform operations at any given time. This dynamic routing conceals operation patterns from side-channel attackers while maintaining ease of operation through automated control logic and standardized interfaces.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system incorporates feedback mechanisms where the output of one cryptographic block can be fed back as input to another block in subsequent operations. This feedback loop, combined with pseudorandom selection, creates complex operation patterns that are difficult to predict or analyze through side-channel attacks, while the automated feedback control maintains operational simplicity.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11599679B2Electromagnetic and power noise injection for hardware operation concealment
Publication Date: 2023.03.07 ARM LTD
  • US11599679B2 patent drawing
  • US11599679B2 patent drawing
  • US11599679B2 patent drawing

AI summary

A method of operation concealment for a cryptographic system includes randomly selecting which one of at least two cryptographic operation blocks receives a key to apply a valid operation to data and outputs a result that is used for subsequent operations. Noise can be added by operating the other of the at least two cryptographic operation blocks using a modified key. The modified key can be generated by mixing the key with a block-unique-identifier, a device secret, a slowly adjusting output of a counter, or a combination thereof. In some cases, noise can be added to a cryptographic system by transforming input data of the other cryptographic operation block(s) by mixing the input data with the block-unique-identifier, device secret, counter output, or a combination thereof. A cryptographic system with operation concealment can further include a distributed (across a chip) or interweaved arrangement of subblocks of the cryptographic operation blocks.