Elliptic Curve Cryptography Side-Channel Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cryptographic data processing methods on elliptic curves are vulnerable to side-channel attacks, particularly due to variations in operation types that can be observed, such as energy consumption patterns, which can reveal sensitive information.

Innovation Solution

The method involves determining a second point on an elliptic curve using a set of operations that include squaring operations, which are faster than multiplications, while maintaining a periodic repetition of operation types to obscure the specific operations being performed, thereby reducing the time for implementing operations on the elliptic curve without compromising the ability to repeat predefined types of operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If operations on elliptic curves are implemented with varying operation types (multiplications, additions) to perform cryptographic calculations, then cryptographic functionality is achieved, but the varying operation types create observable patterns that make the system vulnerable to side-channel attacks

Engineering Contradiction:
Improvecryptographic securityVSAvoidside-channel attack vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies periodic action by organizing cryptographic operations into atomic blocks that repeat a fixed sequence of operation types (multiplication, addition, opposition, addition) regardless of the actual cryptographic operation being performed. This periodic repetition masks the true operation sequence from side-channel observers, as the observable pattern remains constant while the underlying cryptographic logic varies.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The patent changes the parameter of operation type sequence from variable to fixed/periodic. By transforming the operation sequence into a predetermined periodic pattern, the patent eliminates the information leakage that would otherwise occur through observation of operation type variations, thereby resolving the vulnerability to side-channel attacks.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If dummy operations are added to create periodic repetition of operation types to prevent side-channel attacks, then security against side-channel attacks is improved, but the computational time increases due to additional operations

Engineering Contradiction:
Improveprotection against side-channel attacksVSAvoidcomputational time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent makes the atomic block universal by designing it to serve multiple cryptographic operations (both point doubling and point addition) through the same sequence of operation types. This multi-functionality eliminates the need for separate operation sequences for different cryptographic primitives, reducing overall computational overhead while maintaining security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent changes the operational approach from using operation-specific sequences to a unified periodic sequence. By transforming the operation sequence into a fixed periodic pattern that works for multiple cryptographic operations, the patent reduces the total number of operations needed while maintaining side-channel protection.

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If standard multiplication operations are used for all Galois field operations, then operational flexibility is maintained, but computational speed decreases compared to using squaring operations

Engineering Contradiction:
Improveoperational flexibilityVSAvoidcomputational speed
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The patent applies local quality by optimizing specific operations within the atomic block. When the operands are identical (as in certain steps of the cryptographic algorithm), the patent uses squaring operations which are computationally faster than general multiplication. This localized optimization maintains operational flexibility while improving speed where applicable.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP2275925B1Method and apparatus for cryptographic data processing
Publication Date: 2013.09.18 OBERTHUR TECH SA
  • EP2275925B1 patent drawing
  • EP2275925B1 patent drawing
  • EP2275925B1 patent drawing

AI summary

The method involves determining a point i.e. scalar product, on an elliptic curve represented using three elements e.g. jacobian projective coordinates, of a Galois body from another point i.e. integer, on the elliptic curve represented using other three elements e.g. jacobian projective coordinates. An assembly of successive operations is implemented, where a sequence of the operations forms a periodic repetition of multiple types of operations including a multiplication, addition and squaring in the body. An independent claim is also included for an electronic entity for cryptographic processing of data.