Cryptographic Module Power Analysis Resistance via Alternating Data Selection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional cryptographic devices are vulnerable to power analysis attacks, as the power consumption patterns reveal confidential data during cryptographic operations, making it possible to retrieve sensitive information.

Innovation Solution

A cryptographic module is designed with a selection circuit that alternately selects and outputs data from two registers, one containing input data and the other containing disturbance data unrelated to the cryptographic operation, thereby creating a power consumption pattern that masks the actual data usage, making it difficult to retrieve confidential information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a register retains data to be subjected to cryptographic operations, then the cryptographic operation can be performed, but the power consumption pattern reveals confidential data making the system vulnerable to power analysis attacks

Engineering Contradiction:
Improvesecurity against power analysis attacksVSAvoidregister configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the data retention function into multiple registers: a first register for retaining input data and a second register for retaining reverse data. This segmentation allows the system to separate the retention of operational data from the retention of reverse data, enabling power analysis resistance while maintaining cryptographic functionality through coordinated operation of multiple specialized registers

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a selection circuit as an intermediary component that alternately selects and outputs contents from the first register (input data) and the second register (reverse data). This intermediary mechanism masks the power consumption patterns by creating alternating selection behavior, preventing direct correlation between power consumption and confidential data operations

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If reverse data is retained in a register, then power analysis resistance is improved, but the power consumption of the register retaining normal data and the power consumption of the register retaining reverse data do not necessarily cancel out, leaving confidential data exposed

Engineering Contradiction:
Improvepower analysis resistanceVSAvoidconfidential data exposure
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent implements dynamic alternating selection between the first register (input data) and the second register (reverse data) through the selection circuit. This dynamic switching creates time-varying power consumption patterns that do not consistently reveal confidential data, as the selection changes based on operational requirements rather than statically retaining data that would produce consistent power leakage patterns

Inventive Principle:
Principle #15Dynamics

3Productivity

If data is completely unhidden in the register, then the cryptographic operation can proceed efficiently, but power analysis attacks can easily retrieve confidential data

Engineering Contradiction:
Improvecryptographic operation efficiencyVSAvoidpower analysis attack vulnerability
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent converts the potentially harmful effect of power consumption into a beneficial masking mechanism. By having the selection circuit alternately select between input data and reverse data, the system uses the power consumption of the selection process itself to mask and obscure the power consumption patterns that would otherwise reveal confidential data, turning a vulnerability into a protective feature

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Data Source

PatentUS8457306B2Cryptographic module and IC card
Publication Date: 2013.06.04 KK TOSHIBA
  • US8457306B2 patent drawing
  • US8457306B2 patent drawing
  • US8457306B2 patent drawing

AI summary

A cryptographic module that performs a cryptographic operation is provided with: a register that retains first data related to key data to be used in the cryptographic operation; a register that retains second data without dependency on the first data; a selector that alternately selects and outputs the contents of the register retaining the first data and the register retaining the second data; and a left shift circuit that performs a predetermined shift operation on data outputted from the selector.