DPA-Resistant Key Derivation via Expanded Diversification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional cryptographic key derivation functions are vulnerable to side-channel attacks, particularly differential power analysis (DPA), as they generate multiple keys with varying diversification information, allowing attackers to infer secret keys by analyzing power consumption patterns.
Innovation Solution
The expansion of diversification information to limit the number of possible input values, making emanations more homogeneous and reducing the attacker's ability to collect sufficient statistical data, thereby enhancing protection against DPA attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If conventional key derivation functions generate multiple keys with varying diversification information, then key variety and adaptability are improved, but vulnerability to DPA attacks increases due to observable power consumption patterns
Solution Approach 1:
The patent applies local quality by making the diversification information dependent on the specific key index being generated. Each key derivation operation uses diversification information that is locally adapted to the current key index, ensuring that power consumption patterns remain consistent across different keys while maintaining key variety. This resolves the contradiction by allowing multiple keys to be generated with different diversification information (improving adaptability) while the local adaptation prevents observable power consumption variations (reducing DPA vulnerability).
Solution Approach 2:
The patent inverts the conventional approach by instead of varying the diversification information to achieve key variety, it keeps the diversification information consistent and varies the key index counter. This inversion ensures that the power consumption pattern remains constant across different key generation operations, making DPA attacks ineffective, while still generating multiple distinct keys through the counter variation (maintaining adaptability).
2Reliability
If diversification information is expanded to limit possible input values, then homogeneity of input values is improved and DPA protection is enhanced, but computational complexity increases
Solution Approach 1:
The patent applies parameter changes by modifying the diversification information parameter through expansion. The diversification information is expanded to a larger parameter space, which limits the number of possible input values and creates more homogeneous power consumption patterns. This parameter expansion enhances DPA protection without requiring complex computational operations, thus resolving the contradiction between reliability (DPA protection) and device complexity (computational complexity).
Data Source
AI summary
Aspects of the present disclosure involve a method and a system to support execution of the method to obtain a first N cryptographic key, receive a key diversification information comprising a first plurality of bits, obtain an expanded key diversification information (EKDI) comprising a second plurality of bits, wherein a number of bits in the second plurality of bits is greater than a number of bits in the first plurality of bits, and wherein a value of each bit of the second plurality of bits is deterministically obtained in view of values of the first plurality of bits, and apply, by the processing device, a key derivation function to the first cryptographic key and the EKDI to obtain a second cryptographic key.


