Hardware Masking for Side-Channel Attack Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current solutions for preventing side-channel attacks on computing platforms are limited in scalability, flexibility, and effectiveness, as they either require manual assembly inspection, enforce long development cycles, or lack protection against glitches and data serialization vulnerabilities.

Innovation Solution

A computing platform that incorporates a five-stage pipeline with a decoding stage, execution stage, memory stage, and write-back stage, featuring a protected register file using Boolean masking and additional ISA instructions to decorrelate energy consumption from cryptographic processing, and morphing program instructions to prevent side-channel information leakage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If software-level countermeasures are used to protect against side-channel attacks, then security protection is provided, but performance is low and development cycles are long

Engineering Contradiction:
Improvesecurity protectionVSAvoidperformance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent replaces software-level protection mechanisms with hardware-level countermeasures implemented in the computing platform's circuitry. The hardware automatically performs operations to prevent side-channel attacks without requiring software intervention, thereby improving performance while maintaining security protection.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The computing platform is designed to automatically protect itself against side-channel attacks through built-in hardware mechanisms. The system self-manages the security protections without external intervention or manual assembly inspection, reducing development cycles and improving performance.

Inventive Principle:
Principle #25Self-service

2Reliability

If manual assembly inspection is used to implement security countermeasures, then protection against side-channel attacks is achieved, but scalability is limited

Engineering Contradiction:
Improvesecurity protectionVSAvoidscalability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements universal hardware countermeasures that can protect multiple cryptographic operations and applications simultaneously. The computing platform's built-in mechanisms provide scalable protection across different workloads without requiring separate manual inspection for each case.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The automatic hardware-based protection eliminates the need for manual assembly inspection, enabling the system to scale to protect diverse cryptographic operations without proportional increases in development effort.

Inventive Principle:
Principle #25Self-service

3Reliability

If traditional cryptographic primitives are used, then mathematical security is provided, but resistance against side-channel attacks is insufficient

Engineering Contradiction:
Improvemathematical securityVSAvoidside-channel vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent merges traditional cryptographic primitives with hardware-based countermeasures in the computing platform. This combination maintains the mathematical security of the cryptographic algorithms while adding physical-layer protections against side-channel attacks through coordinated operations.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The hardware countermeasures act as an intermediary layer between the cryptographic operations and the physical environment. This intermediary prevents direct correlation between computational operations and measurable physical signals, thereby protecting against side-channel attacks while preserving mathematical security.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Adaptability or versatility

If spy applications are collocated on the same platform, then microarchitectural-based attacks can be executed, but the platform complexity increases

Engineering Contradiction:
Improveattack detection capabilityVSAvoidplatform complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent extracts and neutralizes the vulnerability to microarchitectural attacks by implementing hardware countermeasures that prevent spy applications from successfully executing side-channel attacks, rather than requiring complex detection and response mechanisms.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS20230318802A1A computing platform for preventing side channel attacks
Publication Date: 2023.10.05 POLITECNICO DI MILANO
  • US20230318802A1 patent drawing
  • US20230318802A1 patent drawing
  • US20230318802A1 patent drawing

AI summary

The present disclosure relates to a computing platform for preventing side channel attacks comprising a memory module configured for storing data of a computer program and program instructions; a pipeline having a plurality of stages, said plurality of stages being configurated for transferring electrical signal via a on-chip interconnect bus; a CPU configured for executing said computer program; said program instructions being decoded by one stage of said plurality of stages; each stage of said pipeline having at least one combinatorial module, said at least one combinatorial module having a plurality of data input and a plurality control input and at least a data output; each program instruction traveling from left to right through said pipeline, and within each stage can activate one or more or none of said at least one combinatorial module. The computing platform comprises a plurality digital logic means interconnected to each other’s and configured for generating random values or program data values, said plurality of digital logic means being in communication signal with said plurality of data input of said combinatorial module, so as when said program instruction enters one stage of said plurality of stages, all the combinatorial modules of said that stage that are not activated by the program instruction will have their input data fed with said random values and all the combinatorial modules of said that stage that are activated by said program instruction will have their unused data input fed with said random values and their used data inputs fed with said program data values.