Scalar Multiplication Constant-Time ECC Controller

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing scalar multiplication processing in elliptic curve cryptography is computationally expensive and time-dependent on the scalar value, making it insecure for applications like digital signatures where constant-time processing is required, especially when dealing with confidential scalar values.

Innovation Solution

The proposed solution involves a computing apparatus that performs scalar multiplication by processing bits in the scanning order from most significant to least significant, using a transformation unit to convert the scalar into signed odd numbers, and executing loop processing for high-speed computation, allowing for efficient scalar multiplication and signature generation/verification in constant time.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If scalar multiplication is performed using conventional methods, then computation can be completed, but computation time varies depending on the scalar value which compromises security

Engineering Contradiction:
ImprovesecurityVSAvoidcomputation time variability
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent transforms the scalar value from a conventional binary representation into a non-adjacent form (NAF) representation, changing the parameter structure of the scalar. This transformation ensures that the computation follows a fixed pattern regardless of the scalar's actual value, making the computation time constant and independent of the secret key, thereby resolving the security vulnerability while maintaining computational efficiency.

Inventive Principle:
Principle #35Parameter changes

2Productivity

If scalar multiplication is performed at high speed, then productivity improves, but security may be compromised if computation time depends on scalar value

Engineering Contradiction:
Improvecomputation speedVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent performs a preliminary transformation of the scalar value into non-adjacent form before executing the scalar multiplication. This preprocessing step ensures that the subsequent computation follows a predetermined, fixed sequence of operations, achieving both high speed (through optimized computation paths) and security (through constant-time execution that leaks no information about the scalar value).

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

By changing the representation parameter of the scalar from standard binary to non-adjacent form, the patent enables a computation method that is both faster and more secure. The NAF representation reduces the number of non-zero digits, decreasing the number of addition operations required, while simultaneously ensuring constant-time execution for security.

Inventive Principle:
Principle #35Parameter changes

3Ease of manufacture

If conventional scalar multiplication is used, then implementation is simple, but computation cost is high and security is compromised

Engineering Contradiction:
Improveimplementation simplicityVSAvoidsecurity
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent modifies the scalar representation parameter to non-adjacent form, which maintains implementation simplicity while dramatically improving security. The transformation algorithm is straightforward and can be easily integrated into existing cryptographic systems, providing constant-time computation that prevents timing attacks without adding significant complexity to the overall implementation.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20220300576A1Computing apparatus and method
Publication Date: 2022.09.22 KIOXIA CORP
  • US20220300576A1 patent drawing
  • US20220300576A1 patent drawing
  • US20220300576A1 patent drawing

AI summary

A controller of a computing apparatus calculates aP by multiplying an integer a being 2 or more and less than 2w and a coordinate value P; reads out, by w bits, a multiplication value k being a bit string and generates a string of signed odd numbers d of w+1 bits; calculates dP by multiplying a head of the d and the P and inputs the dP to a variable; executes looping between processing for inputting, to the variable, a value obtained by doubling the variable w times and processing for calculating dP by multiplying the P and a second or after of the d and inputting, to the variable, an addition result of the dP and the variable; and calculates a value by multiplying the P and a value based on lower 2 bits of the k and outputs kP by adding the calculated value and the variable.