Dynamic Masking for In-Line RAM Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cryptographic systems using in-line processor RAM encryption are vulnerable to attacks on the cipher block, particularly due to limited customization options and static data in ROM units, which can be analyzed to compromise the entire product line if one sample is compromised.
Innovation Solution
A circuit utilizing read-write memory units with dynamically customizable masks generated from initial masks and random values, incorporating permutation operations and Physically Unclonable Functions, allowing for adaptive and flexible customization of cipher blocks to enhance security against side-channel attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If ROM units are used to store cipher tables with predefined values, then manufacturing precision and production efficiency are improved, but security is worsened because the static data can be analyzed by imaging techniques to compromise the entire product line
Solution Approach 1:
The patent replaces static ROM storage with dynamic RAM storage for cipher tables. The masks are no longer fixed but are dynamically generated using Physically Unclonable Functions (PUF) and permutation operations. This dynamic approach ensures that even if one chip is compromised, the static analysis of ROM data cannot be performed, as the data changes between operations and between chips.
Solution Approach 2:
The patent changes the fundamental parameter of mask storage from static (ROM) to dynamic (RAM). Additionally, it introduces parameter changes through the use of PUF-generated random values and permutation operations that transform the mask data before storage. This ensures that the same cipher algorithm produces different mask values on different chips and at different times, preventing product line compromise.
2Manufacturing precision
If customization is made offline at the development stage for mass production, then manufacturing precision is improved, but adaptability is worsened because flaws are associated with entire product lines
Solution Approach 1:
The patent enables each chip to self-generate its unique mask values through integrated PUF circuits during operation. Instead of requiring offline customization at the development stage, the system performs self-customization at runtime using physical characteristics of each specific chip. This eliminates the need for pre-programming masks while maintaining high precision customization for each individual chip.
Solution Approach 2:
The patent performs preliminary generation of random values using PUF circuits during chip initialization or manufacturing, but the actual mask customization occurs dynamically when needed. The permutation operations and mask generation are prepared in advance but executed adaptively, combining elements of both offline preparation and online flexibility.
3Reliability
If volatile memory units are used to store masks dynamically, then security is improved by preventing imaging analysis, but device complexity increases due to the need for dynamic mask management
Solution Approach 1:
The patent extracts the mask generation function from the main cipher logic and implements it as a separate PUF-based subsystem. The PUF circuit generates random values that are then used by permutation operations to create masks. This separation simplifies the overall system architecture by dedicating specific components to specific functions, reducing the complexity of dynamic mask management despite the increased security measures.
Solution Approach 2:
The patent implements a nested structure where PUF-generated random values are nested within permutation operations, which in turn are nested within the mask generation process, which is finally nested within the cipher operation. This hierarchical nesting organizes the complexity into manageable layers, where each layer handles a specific aspect of mask management, making the overall system more tractable despite the multiple security mechanisms.
Data Source
AI summary
A circuit includes a cipher accessing a plurality of read-write memory units configured to handle data tables obtained from a modified mask; wherein the modified mask is being determined from an initial mask and a random value, the random value selecting one or more modifications of the initial mask amongst a plurality of predefined modifications including permutation operations. Developments of the invention describe the use of mathematically optimal or equivalent masks; the use of random values; a range of permutation operations comprising offset shifting and/or rotation and/or XOR operations and/or coprime construction; the use of round masks; the use of a Physically Unclonable Function; the refresh or update of modified masks and/or round masks; and verifications of the optimality and/or integrity of masks. System features (e.g. CPU, co-processor, local and/or remotely accessed external memory storing masks, volatile memory) and computer program products are described.


