Cryptographic Component Side-Channel Attack Mitigation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cryptographic systems are vulnerable to side-channel attacks due to the reuse of security information assets and identical trace structures in bi-linear cryptographic components, which can reveal sensitive information to attackers.
Innovation Solution
Implementing a microarchitecture with diversified cryptographic components and microarchitectural protections that rotate between different multiplier units and microcode versions to avoid deterministic usage of security information assets, and using dummy variables and locally derived random masks to change power signatures and timing without affecting output.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If identical trace structures are used in cryptographic components, then device complexity is reduced and manufacturing is easier, but security against side-channel attacks deteriorates
Solution Approach 1:
The patent applies asymmetry by introducing diversified trace structures in cryptographic components. Different cryptographic components have different trace structures (e.g., different gate arrangements, wiring patterns, or circuit topologies) even though they perform the same cryptographic function. This makes side-channel attacks more difficult because attackers cannot rely on identical patterns across components, while still maintaining functional correctness through proper cryptographic design.
2Productivity
If security information assets are reused, then device complexity is reduced and operations are more efficient, but vulnerability to side-channel attacks increases
Solution Approach 1:
The patent applies dynamics by implementing randomization of trace structures. The trace structures are not fixed but are randomly generated or varied for each cryptographic operation or component instance. This dynamic approach allows efficient reuse of security information assets while preventing deterministic patterns that attackers could exploit. The randomization ensures that even repeated operations have different physical traces, masking side-channel information.
3Stability of the object's composition
If deterministic usage of security information assets is implemented, then operational consistency is improved, but detectability by attackers increases
Solution Approach 1:
The patent introduces an intermediary layer of randomization between the deterministic cryptographic operations and the physical trace. The trace structure serves as an intermediary that obscures the relationship between consistent operational inputs and physical measurements. This intermediary randomization layer allows operational consistency to be maintained at the cryptographic level while preventing detectability at the physical measurement level, as the trace varies independently of the operational determinism.
Data Source
AI summary
Systems and techniques for securely performing cryptographic operations are described herein. For example, a process can include obtaining a public data and a security information asset. The process can include performing, by a first computation module, a Boolean operation on the public data and the security information asset to generate an output. The process can include obtaining the public data and the security information asset. The process can include performing, by a second computation module, the Boolean operation on the public data and the security information asset to generate the output. The first computation module has a first configuration and the second computation module has a second configuration, different from the first configuration.


