Cryptographic Device Side-Channel Attack Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cryptographic devices are vulnerable to side-channel attacks that exploit physical properties like power consumption to extract secret information, with existing countermeasures like noise generators being insufficient in preventing successful attacks.
Innovation Solution
A method is introduced where a cryptographic device leaks a set of possible intermediate results generated by a processing unit, using a signal engine to intentionally leak all possible values of the intermediate result, which increases the difficulty for attackers to distinguish between correct and incorrect key candidates, thereby enhancing resistance against side-channel attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a noise generator is used to dominate total power consumption, then the signal-to-noise ratio of secret information is reduced, but the countermeasure remains insufficient against sophisticated side-channel attacks
Solution Approach 1:
Instead of trying to hide the secret information by adding noise, the invention inverts the approach by deliberately leaking all possible intermediate values through a controlled channel. This creates a situation where the attacker cannot distinguish the actual intermediate value from the set of possible values, effectively neutralizing the side-channel attack while maintaining normal cryptographic operations.
Solution Approach 2:
The invention introduces an intermediary component (the leakage register controlled by the signal engine) that mediates between the cryptographic unit and the external observer. This intermediary deliberately releases information about all possible intermediate values, creating a controlled information leak that prevents attackers from extracting useful information through physical side-channels.
2Reliability
If all possible intermediate values are leaked to confuse attackers, then key extraction becomes difficult, but information leakage increases
Solution Approach 1:
The invention converts the harmful effect of information leakage into a beneficial security feature. By deliberately leaking all possible intermediate values through the signal engine and leakage register, the system creates a situation where any side-channel measurement contains no useful information for key extraction, as all possible values are already known to the attacker.
Solution Approach 2:
The invention changes the parameter of information availability by making all possible intermediate values publicly known through the leakage mechanism. This parameter change transforms the security model from hiding information to making information redundant, thereby preventing successful side-channel attacks while maintaining cryptographic security.
3Reliability
If a processing unit generates possible key values and leaks them, then the cryptographic device resists side-channel attacks, but the processing unit requires faster operation and additional resources
Solution Approach 1:
The invention segments the processing workload by separating the cryptographic operations (performed by the cryptographic unit) from the possible value generation (performed by the processing unit). This segmentation allows the processing unit to operate independently at higher speeds to generate and leak possible intermediate values, while the cryptographic unit maintains its security-critical operations without performance penalty.
Data Source
AI summary
In accordance with a first aspect of the present disclosure, a method of protecting a cryptographic device against side-channel attacks is conceived, the cryptographic device comprising a cryptographic unit and a processing unit, and the method comprising: performing, by the cryptographic unit, a cryptographic operation on input data, wherein said cryptographic operation generates at least one intermediate result; generating, by the processing unit, a set of possible values of the intermediate result; leaking, by the cryptographic device, said set of possible values of the intermediate result. In accordance with a second aspect of the present disclosure, a computer program is provided for carrying out said method. In accordance with a third aspect of the present disclosure, a corresponding cryptographic device is provided.


