IC Card Power Analysis Protection via Randomized Cryptographic Operations

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

IC cards are vulnerable to power analysis attacks, such as Simple Power Analysis (SPA) and Differential Power Analysis (DPA), which can compromise the secret key and sensitive data by analyzing power consumption patterns during cryptographic operations.

Innovation Solution

Introducing additional cryptographic operations with randomly generated secret parameters to obscure power consumption patterns, making it difficult for attackers to distinguish between genuine and additional operations, thereby increasing the difficulty of recovering the secret key.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Object-affected harmful factors

If cryptographic operations are executed with predictable timing, then power analysis attacks can easily detect and analyze the operations, but if randomizing delays are introduced to obscure timing patterns, then the execution time becomes abnormal and draws attention to potential secret key usage

Engineering Contradiction:
Improvevulnerability to power analysis attacksVSAvoidexecution time predictability
Core Design Contradiction:
Object-affected harmful factorsVSLoss of time

Solution Approach 1:

The patent introduces an intermediary mechanism (additional cryptographic operations with random parameters) that mediates between the need for secure execution and the need to maintain normal timing patterns. These intermediary operations absorb the randomizing effect without exposing the actual cryptographic operations involving the secret key, thus preventing timing-based power analysis attacks while maintaining execution predictability

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the parameters of cryptographic operations by introducing additional operations with random parameters (random keys, random plaintexts) that modify the power consumption profile without affecting the core cryptographic functionality. This parameter change obscures the timing patterns associated with secret key usage while maintaining the integrity of the original cryptographic operations

Inventive Principle:
Principle #35Parameter changes

2Object-affected harmful factors

If additional cryptographic operations are introduced to obscure power consumption patterns, then power analysis attacks become more difficult, but then the computational complexity and execution time increase

Engineering Contradiction:
Improvedetectability of cryptographic operationsVSAvoidcryptographic algorithm complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent applies partial action by introducing only the necessary additional cryptographic operations required to obscure power consumption patterns without implementing excessive redundancy. The randomizing operations are performed selectively to provide sufficient obfuscation while minimizing the increase in computational complexity and execution time

Inventive Principle:
Principle #16Partial or excessive action

3Measurement precision

If random parameters are used in additional cryptographic operations, then the correlation between power consumption and secret key usage is reduced, but then the number of operations to analyze increases for attackers

Engineering Contradiction:
Improvepower consumption analysis precisionVSAvoidnumber of cryptographic operations
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent converts the harmful effect of increased operational quantity into a benefit by using the additional operations as a shield. The increased number of operations with random parameters creates a larger dataset that dilutes the signal-to-noise ratio, making power analysis attacks less effective. The random parameters act as a protective layer that transforms the vulnerability of increased operational complexity into a security advantage

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Data Source

PatentUS8804949B2Method for protecting IC cards against power analysis attacks
Publication Date: 2014.08.12 STMICROELECTRONICS INT NV
  • US8804949B2 patent drawing
  • US8804949B2 patent drawing
  • US8804949B2 patent drawing

AI summary

A method for protecting data against power analysis attacks includes at least a first phase of executing a cryptographic operation for ciphering data in corresponding enciphered data through a secret key. The method includes at least a second phase of executing an additional cryptographic operation for ciphering additional data in corresponding enciphered additional data. An execution of the first and second phases is undistinguishable by the data power analysis attacks. Secret parameters are randomly generated and processed by the at least one second phase. The secret parameters include an additional secret key ERK for ciphering the additional data in the corresponding enciphered additional data.