Hardware Noise Vectors for Post-Quantum Key Pair Generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing lattice-based cryptographic methods face inefficiencies and vulnerabilities due to computationally expensive and susceptible noise vector generation processes, particularly in hardware and software platforms, which are prone to attacks and inefficient Gaussian sampling.

Innovation Solution

Directly obtain a noise vector from a hardware-implemented structure, such as a physical unclonable function (PUF), to generate a cryptographic key pair, ensuring a non-uniform distribution that enhances post-quantum security and resistance to attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If Gaussian sampling is used to generate noise vectors for lattice-based cryptography, then the cryptographic security is maintained, but the computational cost increases and the system becomes susceptible to timing attacks

Engineering Contradiction:
Improvecryptographic securityVSAvoidcomputational overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the noise vector generation process from traditional software-based Gaussian sampling and relocates it to a hardware-implemented structure. This hardware structure directly generates noise vectors with the required statistical properties, eliminating the need for computationally expensive Gaussian sampling algorithms while maintaining cryptographic security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent replaces the software-based Gaussian sampling mechanism with a hardware-implemented structure. This substitution eliminates the computational overhead and timing attack vulnerabilities associated with software implementations, as hardware provides deterministic, constant-time operation with the required statistical properties.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Adaptability or versatility

If software-based noise vector generation is used, then flexibility is maintained, but the system becomes prone to timing attacks and software vulnerabilities

Engineering Contradiction:
Improveimplementation flexibilityVSAvoidtiming attacks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent replaces software-based noise generation with a hardware-implemented structure. This substitution inherently protects against timing attacks because hardware operations execute in deterministic time, eliminating the timing variations that software-based approaches are susceptible to.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces a hardware-implemented structure as an intermediary between the cryptographic algorithm and the noise vector generation process. This hardware intermediary provides a secure, attack-resistant interface that generates noise vectors with the required statistical properties without exposing the system to software-based vulnerabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of manufacture

If uniform distribution is used for noise vectors, then implementation is simpler, but the cryptographic hardness of the LWE problem is reduced

Engineering Contradiction:
Improveimplementation simplicityVSAvoidcryptographic hardness
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent changes the distribution parameter of the noise vectors from uniform to a non-uniform distribution (such as discrete Gaussian or binomial distribution). This parameter change is achieved through the hardware-implemented structure, which directly generates samples from the required distribution without requiring complex software-based sampling algorithms, thus maintaining both cryptographic hardness and implementation simplicity.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP4629559A1Method and computing device for obtaining a cryptographic key pair
Publication Date: 2025.10.08 SIEMENS AG
  • EP4629559A1 patent drawingFigure 1~3
  • EP4629559A1 patent drawingFigure 4~5
  • EP4629559A1 patent drawingFigure 6

AI summary

The invention relates to a computer-implemented method for obtaining a cryptographic key pair (8,9) for use in a cryptographic method, the method comprising: randomly generating (S1) a private key (5, 8) of the cryptographic key pair (8,9); operating (S2) a hardware-implemented structure (4) using a randomly generated challenge (6) to obtain, in particular directly, a noise vector (7) from the hardware-implemented structure (4); and calculating (S3) a public key (9) of the cryptographic key pair (8,9) from the generated random private key (5, 8) using the noise vector (7) obtained from the hardware-implemented structure (4). The method advantageously offers a low-overhead, lightweight and hardened way of obtaining noise vectors 7 for use in calculating a public key of a PQ-secure cryptographic keypair. Also contemplated is a corresponding computing device and computer program product.