Cryptographic Circuit Power Decoupling for DPA Resistance
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cryptographic systems are vulnerable to side-channel attacks, particularly differential power analysis (DPA), where attackers can infer encryption keys by monitoring power consumption during cryptographic operations, especially when they have physical access to the device.
Innovation Solution
A device with an integrated circuit (IC) die featuring a cryptographic processing circuit and a power storage circuit, encapsulated to prevent physical tampering, which switches between external and internal power sources during cryptographic operations to obscure power consumption patterns, using a control circuit to charge the power storage circuit only when not executing the cryptographic algorithm.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Duration of action of stationary object
If the cryptographic processing circuit is continuously connected to an external power source, then the device can operate without power interruption, but the power consumption patterns reveal information about the cryptographic algorithm and secret keys through differential power analysis attacks
Solution Approach 1:
The power supply system is segmented into multiple independent power sources (first power source and second power source) that can be selectively activated. During cryptographic operations, the circuit switches from the first power source to the second power source, dividing the operational timeline into distinct phases with different power sources to prevent continuous power monitoring attacks.
Solution Approach 2:
The cryptographic processing circuit employs periodic switching between different power sources. The control circuit periodically connects the circuit to the first power source for non-cryptographic operations and switches to the second power source for cryptographic operations, creating periodic power consumption patterns that do not directly correlate with the cryptographic processing activity.
2Reliability
If the cryptographic processing circuit is physically protected through encapsulation, then the device resists tampering and physical attacks, but the device becomes more complex and difficult to manufacture
Solution Approach 1:
The cryptographic processing circuit is nested within a secure encapsulation structure that contains the second power source. This nested configuration allows the power switching mechanism to be integrated within the protected enclosure, providing both physical security and functional operation without requiring external access during cryptographic operations.
Solution Approach 2:
The control circuit acts as an intermediary between the power sources and the cryptographic processing circuit. It manages the switching between power sources and implements the security logic for when to connect to which power source, thereby simplifying the overall system architecture while maintaining security requirements.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
Effectively thwarts side-channel attacks by decoupling the cryptographic processing circuit from external power sources during operations, preventing attackers from inferring secret keys through power consumption analysis and ensuring secure execution of cryptographic algorithms.
Implementation Method 1
a power storage circuit configured and arranged to store power sufficient for the cryptographic processing circuit to execute the cryptographic algorithm
Data Source
Figure 1
Figure 2
Figure 3
AI summary
According to an example embodiment, a device provides cryptographic processing functions using secret data. The device can include protection from differential power analysis (DPA). The encryption processing circuit and its memory can be decoupled from external power source(s) during encryption-related computations. A local power storage element, such as a capacitive element, can provide power while the encryption processing circuit is decoupled from the external power source(s). The local power storage element can then be reconnected and charged once the encryption-related computations are completed or paused.