Cryptographic Round Counter Redundancy Against Fault Injection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cryptographic processing systems are vulnerable to fault injection attacks that can reduce the number of rounds in cryptographic algorithms, compromising security, especially in AES-128 and SHA-256, where fewer rounds can lead to key recovery attacks or collisions.
Innovation Solution
A semiconductor device is designed with a duplicated holding circuit and judgement circuit to detect mismatches in output data, preventing the output of arithmetic results when a fault injection attack alters the number of rounds, thereby maintaining the predetermined number of rounds in cryptographic processing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If cryptographic processing is implemented with a holding circuit to control the number of rounds, then the security against fault injection attacks is improved, but the device complexity increases due to circuit duplication
Solution Approach 1:
The holding circuit is duplicated to create redundant copies that can be compared for fault detection. The patent uses multiple identical holding circuits (e.g., two or more) that each independently hold the round count, and their outputs are compared to detect any faults that may have altered the round number, thereby preventing security vulnerabilities without requiring complex monitoring systems
Solution Approach 2:
The patent implements a feedback mechanism where the outputs of duplicated holding circuits are continuously compared, and any mismatch triggers a security response. The comparison result feeds back to control whether the cryptographic output is valid, creating a closed-loop system that automatically detects and responds to fault injection attempts
2Productivity
If the number of rounds in cryptographic algorithms is reduced to improve processing speed, then the productivity is improved, but the security is worsened due to vulnerability to key recovery attacks
Solution Approach 1:
The patent performs preliminary verification of the round count before allowing cryptographic output. By using duplicated holding circuits to pre-validate that the correct number of rounds has been executed, the system prevents security vulnerabilities from reduced-round attacks while maintaining efficient processing, as the verification occurs automatically without adding significant overhead to the core cryptographic operations
Data Source
AI summary
A semiconductor device includes: an arithmetic circuit that repeats an operation related to a cryptographic processing for the predetermined number of rounds; a holding circuit that holds data related to the number of rounds of an operation of the arithmetic circuit; a judgement circuit that determines whether the number of rounds is the predetermined number of rounds; and an output buffer circuit that outputs the arithmetic result data of the arithmetic circuit when the judgement circuit determines that the number of rounds is the predetermined number. It is configured to duplicate the holding circuit, and not to output the arithmetic result data when two outputs of the duplicated holding circuit are not matched.


