Dynamic Data Masking for Cryptographic Power Analysis Resistance
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cryptographic algorithms are vulnerable to power analysis attacks, such as simple power analysis (SPA), differential power analysis (DPA), differential frequency analysis (DFA), and differential spectrogram analysis (DSA), which can extract keys and expose nominally protected data.
Innovation Solution
Implementing dynamic data masking in cryptographic operations, such as AES, DES, or triple DES, by using unlimited and continuously changing masks for cryptographically sensitive values (CSVs), combined with an orbital RAM algorithm and no-operation clocks to make power analysis attacks more difficult.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If static masking is used for cryptographic data, then data protection is provided, but power analysis attacks can still extract keys by capturing power consumption patterns
Solution Approach 1:
The patent applies dynamic masking by continuously changing mask values during cryptographic operations. Instead of using a fixed mask, the system generates new mask values at regular intervals, making it impossible for attackers to capture consistent power consumption patterns. This dynamic approach resolves the contradiction by maintaining data protection while eliminating the vulnerability to power analysis attacks.
Solution Approach 2:
The system implements periodic mask changes at predetermined time intervals during cryptographic operations. This periodic action ensures that even if an attacker captures power consumption data at different times, the varying mask values prevent pattern recognition. The periodic renewal of masks maintains security against power analysis while preserving data protection capabilities.
2Object-affected harmful factors
If dynamic mask changes are implemented, then power analysis resistance is improved, but computational complexity increases
Solution Approach 1:
The system employs a self-service approach where the mask generation is automated based on predetermined criteria or time intervals. The mask management function operates autonomously without requiring complex external control mechanisms. This self-service mechanism reduces the practical complexity of implementing dynamic masking while maintaining power analysis resistance.
Solution Approach 2:
The patent changes the parameter of mask values dynamically during operation. By modifying the mask parameter at predetermined intervals, the system achieves power analysis resistance without requiring complex architectural changes. This parameter-based approach simplifies the overall system complexity while effectively addressing the security requirement.
3Reliability
If masks are changed frequently, then key extraction difficulty increases, but processing time for cryptographic operations increases
Solution Approach 1:
The system uses periodic mask changes at predetermined time intervals rather than continuous changes. This periodic approach ensures that masks are updated frequently enough to prevent key extraction through power analysis, while avoiding the excessive processing overhead of continuous mask generation. The timing interval is optimized to balance security with processing efficiency.
Solution Approach 2:
The mask generation is performed in advance at predetermined intervals, allowing the masking to be ready before the next cryptographic operation begins. This preliminary action reduces the processing time during actual cryptographic operations, as the mask is already prepared and can be applied immediately, thus protecting against key extraction without significant time penalty.
Data Source
AI summary
Systems and methods for dynamic data masking are disclosed. The disclosed methods and systems can be used to dynamically mask data in cryptographic operations, such as advanced encryption standard (AES) operations, data encryption standard (DES) operations or triple DES operations. Specifically, data in cryptographic operations can be covered with unlimited and continuously changing masks. As an example, the Substitution table, key schedule, and state register in AES, or key schedule and selection functions in a DES or triple DES can be covered with unlimited and constantly changing masks. In an aspect, dynamic masking operations can be combined with orbital RAM algorithm and no-operation clocks to make power signature analysis in cryptographic attacks even more difficult.


