Cryptographic Round Counter Redundancy Against Fault Injection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cryptographic processing systems are vulnerable to fault injection attacks that can reduce the number of rounds in cryptographic algorithms, compromising security, especially in AES-128 and SHA-256, where fewer rounds can lead to key recovery attacks or collisions.

Innovation Solution

A semiconductor device is designed with a duplicated holding circuit and judgement circuit to detect mismatches in output data, preventing the output of arithmetic results when a fault injection attack alters the number of rounds, thereby maintaining the predetermined number of rounds in cryptographic processing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cryptographic processing is implemented with a holding circuit to control the number of rounds, then the security against fault injection attacks is improved, but the device complexity increases due to circuit duplication

Engineering Contradiction:
Improvesecurity against fault injection attacksVSAvoidcircuit duplication
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The holding circuit is duplicated to create redundant copies that can be compared for fault detection. The patent uses multiple identical holding circuits (e.g., two or more) that each independently hold the round count, and their outputs are compared to detect any faults that may have altered the round number, thereby preventing security vulnerabilities without requiring complex monitoring systems

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent implements a feedback mechanism where the outputs of duplicated holding circuits are continuously compared, and any mismatch triggers a security response. The comparison result feeds back to control whether the cryptographic output is valid, creating a closed-loop system that automatically detects and responds to fault injection attempts

Inventive Principle:
Principle #23Feedback

2Productivity

If the number of rounds in cryptographic algorithms is reduced to improve processing speed, then the productivity is improved, but the security is worsened due to vulnerability to key recovery attacks

Engineering Contradiction:
Improveprocessing speedVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent performs preliminary verification of the round count before allowing cryptographic output. By using duplicated holding circuits to pre-validate that the correct number of rounds has been executed, the system prevents security vulnerabilities from reduced-round attacks while maintaining efficient processing, as the verification occurs automatically without adding significant overhead to the core cryptographic operations

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12095461B2Semiconductor device
Publication Date: 2024.09.17 RENESAS ELECTRONICS CORP
  • US12095461B2 patent drawing
  • US12095461B2 patent drawing
  • US12095461B2 patent drawing

AI summary

A semiconductor device includes: an arithmetic circuit that repeats an operation related to a cryptographic processing for the predetermined number of rounds; a holding circuit that holds data related to the number of rounds of an operation of the arithmetic circuit; a judgement circuit that determines whether the number of rounds is the predetermined number of rounds; and an output buffer circuit that outputs the arithmetic result data of the arithmetic circuit when the judgement circuit determines that the number of rounds is the predetermined number. It is configured to duplicate the holding circuit, and not to output the arithmetic result data when two outputs of the duplicated holding circuit are not matched.