Hardware Security Simulation Using Galois Field Transformations

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for evaluating the resistance of hardware components to side channel attacks, such as differential power analysis and fault injection, require physical prototypes, which is inefficient and does not allow for pre-production security assessment.

Innovation Solution

A method that simulates power consumption and behavior of semiconductor chips at the design stage using a power consumption simulator and trace analyzer, incorporating Galois Field transformations and masking techniques to increase resistance to key extraction attacks, and associating checksums with cryptographic keys to enhance security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If physical prototypes are used for security testing, then accurate security evaluation is achieved, but development time and cost increase

Engineering Contradiction:
Improvesecurity evaluation accuracyVSAvoiddevelopment time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent creates virtual copies of the hardware design at the gate-level netlist stage, allowing security testing without physical prototypes. The simulator generates virtual power consumption traces and fault injection models that replicate actual hardware behavior, enabling accurate security evaluation during the design phase rather than requiring physical chips.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent performs security testing actions in advance during the design phase using virtual prototypes. By simulating side-channel attacks and fault injection attacks on the gate-level netlist before physical implementation, the system identifies and fixes security vulnerabilities early, avoiding the need for time-consuming post-production testing.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If comprehensive security testing is performed, then vulnerability detection improves, but testing complexity increases

Engineering Contradiction:
Improvevulnerability detection capabilityVSAvoidtesting system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the security testing process into separate functional modules: a gate-level netlist parser, a power consumption simulator, a fault injection simulator, and a vulnerability analyzer. Each module handles a specific aspect of security testing independently, making the overall complex testing process manageable and automatable through integrated scripts.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a virtual simulator as an intermediary between the hardware design and the security analysis. This simulator acts as a mediator that translates design specifications into testable models, generating virtual traces and fault scenarios without requiring direct interaction with physical hardware, thus simplifying the testing infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If masking techniques are applied to protect against side channel attacks, then security against key extraction improves, but processing efficiency decreases

Engineering Contradiction:
Improveresistance to key extraction attacksVSAvoidprocessing efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies masking techniques that modify operational parameters by introducing random masks into cryptographic operations. These masks are applied to intermediate values during encryption/decryption processes, transforming the power consumption traces to obscure correlations with secret keys. The simulator evaluates different masking implementations to find the optimal balance between security and performance.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20250015969A1Methods for protecting computer hardware from cyber threats
Publication Date: 2025.01.09 FORTIFYIQ INC
  • US20250015969A1 patent drawing
  • US20250015969A1 patent drawing
  • US20250015969A1 patent drawing

AI summary

A method of improving performance of a data processor comprising: in a field of characteristic 2 computing XY by performing a series of: (i) multiplications of two different elements of the field; and (ii) raising an element of the field to a power Z wherein Z is a power of 2; wherein the number of multiplications (i) is at least two less than the number of ones (1s) in the binary representation of Y.