Cryptographic Device Side-Channel Attack Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cryptographic devices are vulnerable to side-channel attacks that exploit physical properties like power consumption to extract secret information, with existing countermeasures like noise generators being insufficient in preventing successful attacks.

Innovation Solution

A method is introduced where a cryptographic device leaks a set of possible intermediate results generated by a processing unit, using a signal engine to intentionally leak all possible values of the intermediate result, which increases the difficulty for attackers to distinguish between correct and incorrect key candidates, thereby enhancing resistance against side-channel attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a noise generator is used to dominate total power consumption, then the signal-to-noise ratio of secret information is reduced, but the countermeasure remains insufficient against sophisticated side-channel attacks

Engineering Contradiction:
Improveresistance against side-channel attacksVSAvoidcomplexity of countermeasure implementation
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Instead of trying to hide the secret information by adding noise, the invention inverts the approach by deliberately leaking all possible intermediate values through a controlled channel. This creates a situation where the attacker cannot distinguish the actual intermediate value from the set of possible values, effectively neutralizing the side-channel attack while maintaining normal cryptographic operations.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The invention introduces an intermediary component (the leakage register controlled by the signal engine) that mediates between the cryptographic unit and the external observer. This intermediary deliberately releases information about all possible intermediate values, creating a controlled information leak that prevents attackers from extracting useful information through physical side-channels.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If all possible intermediate values are leaked to confuse attackers, then key extraction becomes difficult, but information leakage increases

Engineering Contradiction:
Improvesecurity against key extractionVSAvoidinformation leakage about intermediate values
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The invention converts the harmful effect of information leakage into a beneficial security feature. By deliberately leaking all possible intermediate values through the signal engine and leakage register, the system creates a situation where any side-channel measurement contains no useful information for key extraction, as all possible values are already known to the attacker.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Solution Approach 2:

The invention changes the parameter of information availability by making all possible intermediate values publicly known through the leakage mechanism. This parameter change transforms the security model from hiding information to making information redundant, thereby preventing successful side-channel attacks while maintaining cryptographic security.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If a processing unit generates possible key values and leaks them, then the cryptographic device resists side-channel attacks, but the processing unit requires faster operation and additional resources

Engineering Contradiction:
Improveresistance against side-channel attacksVSAvoidprocessing speed and resource requirements
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The invention segments the processing workload by separating the cryptographic operations (performed by the cryptographic unit) from the possible value generation (performed by the processing unit). This segmentation allows the processing unit to operate independently at higher speeds to generate and leak possible intermediate values, while the cryptographic unit maintains its security-critical operations without performance penalty.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20240235808A1Method of protecting a cryptographic device against side-channel attacks
Publication Date: 2024.07.11 NXP BV
  • US20240235808A1 patent drawing
  • US20240235808A1 patent drawing
  • US20240235808A1 patent drawing

AI summary

In accordance with a first aspect of the present disclosure, a method of protecting a cryptographic device against side-channel attacks is conceived, the cryptographic device comprising a cryptographic unit and a processing unit, and the method comprising: performing, by the cryptographic unit, a cryptographic operation on input data, wherein said cryptographic operation generates at least one intermediate result; generating, by the processing unit, a set of possible values of the intermediate result; leaking, by the cryptographic device, said set of possible values of the intermediate result. In accordance with a second aspect of the present disclosure, a computer program is provided for carrying out said method. In accordance with a third aspect of the present disclosure, a corresponding cryptographic device is provided.