Decryption Device Sideband Attack Masking via False Operations

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

RSA decryption devices are vulnerable to sideband attacks, where attackers can estimate the operations performed by measuring signals like voltage or power to acquire the RSA private key used for decryption.

Innovation Solution

A decryption method and device that incorporates a sequence of operations including decryption multiplication and square calculations, along with false operations such as false multiplication and square calculations, making it difficult for attackers to identify the actual decryption operations and the corresponding RSA private key through signal measurement.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If RSA decryption operations are performed using standard algorithms, then decryption efficiency is maintained, but the device becomes vulnerable to sideband attacks where attackers can measure voltage or power signals to estimate operations and acquire the RSA private key

Engineering Contradiction:
Improvesecurity against sideband attacksVSAvoidcomplexity of decryption operations
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by performing false operations before actual decryption operations. The control circuit executes false multiplication operations and false square operations that consume power and generate signals similar to real operations, thereby masking the characteristics of subsequent genuine decryption operations and preventing attackers from distinguishing them through sideband analysis

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent changes operational parameters by introducing false operations with different computational characteristics than actual decryption operations. The control circuit dynamically adjusts the sequence and type of operations (multiplication vs. square operations) to alter power consumption patterns and signal characteristics, making it difficult for attackers to correlate measured signals with the actual private key operations

Inventive Principle:
Principle #35Parameter changes

2Reliability

If false operations are inserted to mask decryption operations, then security against sideband attacks is improved, but the decryption time increases

Engineering Contradiction:
Improvesecurity against sideband attacksVSAvoiddecryption time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies partial action by inserting only a limited number of false operations (specifically one false multiplication operation and one false square operation) rather than excessive masking. This partial approach provides sufficient security enhancement while minimizing the time overhead, as the false operations are performed selectively at critical points in the decryption process rather than continuously

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10057063B2Decryption device, method, and circuit
Publication Date: 2018.08.21 REALTEK SEMICON CORP
  • US10057063B2 patent drawing
  • US10057063B2 patent drawing
  • US10057063B2 patent drawing

AI summary

A decryption method includes receiving encrypted data, in which the encrypted data is encrypted according to an RSA public key; and performing a plurality of operations in sequence according to an RSA private key and the encrypted data to acquire a decrypted data. The operations include a plurality of decryption operations and at least one false operation. The decryption operations include at least one decryption multiplication operation and at least one decryption square calculation, and the at least one false operation includes at least one of at least one first false multiplication operation and at least one first false square calculation.