Encryption Hardware Dummy Operation Masking
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional methods to counter side channel analysis (SCA) attacks, such as hardware mirroring and additional substitution boxes, are expensive and inefficient in preventing unauthorized access through power consumption and complexity.
Innovation Solution
Implementing a continuous exercise of hardware by immediately switching between actual and dummy values for data and keys, making it difficult for unauthorized users to identify specific substitution box access during encryption operations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If hardware mirroring is used to obtain a consistent profile, then security against SCA attacks is improved, but fabrication and development costs increase due to greater hardware complexity
Solution Approach 1:
The patent creates a dummy encryption operation that copies the structure and timing characteristics of the real encryption operation. This dummy operation is generated by taking a previous encryption operation and modifying it with dummy data and dummy keys, then re-executing it to create a timing profile that masks the real operation's timing characteristics.
Solution Approach 2:
The patent performs preliminary actions by pre-generating dummy encryption operations from previous real operations before the actual encryption takes place. These dummy operations are prepared in advance and executed to establish a consistent timing profile that will mask the real encryption operation's characteristics.
2Reliability
If additional substitution boxes are exercised to counter SCA attacks, then security is improved, but power consumption increases
Solution Approach 1:
The patent changes the parameters of encryption operations by substituting real data and keys with dummy data and dummy keys in previously recorded operations. This creates variant encryption operations that maintain the same structural characteristics but differ in their computational parameters, thereby masking timing information without requiring additional hardware resources.
Solution Approach 2:
The patent creates dummy encryption operations that copy the structural and timing characteristics of real operations. By re-executing modified versions of previous operations with dummy inputs, the system generates masking timing profiles without requiring additional substitution boxes or increased hardware resources.
Data Source
AI summary
An apparatus, method, system and computer-readable medium are provided for preserving an encryption of data when confronted by an attack, such as a side channel analysis (SCA) attack based on a statistical analysis. In some embodiments, hardware, software, and/or firmware associated with an encryption calculation may be exercised or accessed during a background operation when an actual or real operation is not taking place. During the background operation, dummy values for data and one or more keys may be input to the hardware. A switching between the real operation and the background operation may take place seamlessly such that measurement of a physical characteristic associated with the hardware is indistinguishable in terms of when the real and background operations are active. In this manner, the secrecy of a key used in connection with the real operation may be preserved.


