Dynamic Cryptographic Countermeasure Adaptation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data processing methods, particularly cryptographic operations, face performance and energy consumption issues due to countermeasures aimed at preventing attacks, which are not effectively scaled to the risk of attack, leading to unnecessary penalties on performance.

Innovation Solution

A data processing method that dynamically implements countermeasures based on a numerical value indicative of the risk of attack, such as the number of iterations or time elapsed since the last operation, using a counter to increment or reset values to adapt countermeasure intensity, thereby optimizing performance and energy usage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If countermeasures are systematically implemented during sensitive phases to disturb attacker observation, then security is improved, but performance and energy consumption deteriorate due to increased calculations and processing time

Engineering Contradiction:
ImprovesecurityVSAvoidperformance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements dynamic adaptation of countermeasure intensity based on detected attack risk levels. The system monitors indicators such as frequency of cryptographic operations and dynamically adjusts the application of countermeasures like masking and substitution tables. During normal operation, countermeasures are minimized or disabled; during detected attacks, countermeasures are intensified, resolving the contradiction between constant security protection and performance maintenance.

Inventive Principle:
Principle #15Dynamics

2Reliability

If masking is applied to cryptographic operations to complicate attacker analysis, then security is improved, but execution time increases due to recalculation of substitution tables

Engineering Contradiction:
ImprovesecurityVSAvoidexecution time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent changes the parameter of mask application from constant to conditional based on attack detection. The system monitors operational parameters such as the frequency of cryptographic operations and only applies masking when attack indicators are present. This selective parameter change avoids the time cost of masking during normal operations while maintaining security during attacks.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If cryptographic operations are repeated multiple times to increase entropy and complicate attacks, then security is improved, but energy consumption increases

Engineering Contradiction:
ImprovesecurityVSAvoidenergy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent applies partial action by implementing countermeasures only to the extent necessary based on detected attack risk. Instead of systematically applying maximum countermeasures to all operations, the system monitors attack indicators and applies countermeasures proportionally - using minimal or no countermeasures during normal operation and intensifying them only when attacks are detected, thus avoiding excessive energy consumption.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP2164018B1Data processing method and associated device
Publication Date: 2019.08.14 IDEMIA FRANCE SAS
  • EP2164018B1 patent drawingFigure 1~2
  • EP2164018B1 patent drawingFigure 3
  • EP2164018B1 patent drawingFigure 4

AI summary

The method involves determining a value i.e. digital value, representing a risk that an attack aiming a sensitive operation e.g. cryptographic operation, is in course of realization, where the value is related to an execution parameter of the operation. Interference of a physical parameter observable during execution of the sensitive operation is provoked based on the value. A counter (COMPT) storing the value is incremented in case of implementation of the operation. An independent claim is also included for a device for processing data, comprising a determination unit.