Key Value-Dependent Exchange Randomization for Side-Channel Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for secure key exchange operations in public key cryptosystems like RSA and elliptic curve cryptography are vulnerable to side-channel attacks, which can reveal secret keys through power traces and Hamming weight analysis.

Innovation Solution

A method for combined key value-dependent exchange and randomization of input values is introduced, involving the determination of key shares, modification values, and intermediary values that depend on randomization values, to generate output values that obscure the exchange process and prevent Hamming weight matching.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If key-dependent exchange operation is performed to protect against side-channel attacks, then security against side-channel attacks is improved, but the exchange operation itself becomes vulnerable to power trace analysis and Hamming weight comparison attacks

Engineering Contradiction:
Improvesecurity against side-channel attacksVSAvoidvulnerability to power trace analysis and Hamming weight comparison
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces randomization values as intermediary elements that mediate between the key-dependent exchange operation and the observable outputs. These randomization values obscure the relationship between input values and exchanged values, preventing direct Hamming weight comparison while maintaining the security benefits of key-dependent exchange.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the parameters of the exchange operation by introducing randomization factors that modify the observable characteristics of the operation. By changing the Hamming weight distribution through randomization, the patent makes power trace analysis and Hamming weight comparison ineffective while preserving the key-dependent security property.

Inventive Principle:
Principle #35Parameter changes

2Productivity

If multiple words are processed to improve operational efficiency, then productivity is improved, but side-channel attacks become more efficient through accumulated power trace information

Engineering Contradiction:
Improveoperational efficiencyVSAvoidefficiency of side-channel attacks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The randomization values act as intermediaries that prevent the accumulation of useful information from power traces across multiple word processing operations. By introducing randomness at each operation, the patent ensures that even when multiple words are processed, the power trace analysis cannot accumulate sufficient information to compromise security.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If key-dependent exchange is implemented to obscure value processing, then security is improved, but device complexity increases due to additional operations and value management

Engineering Contradiction:
Improvesecurity through value obscuringVSAvoidcomplexity of exchange operation and value management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The randomization values serve as intermediary elements that simplify the overall value management complexity. Instead of managing multiple complex obfuscation mechanisms, the patent uses randomization values as a unified approach that handles both the exchange operation and the obscuring function, reducing the number of separate complex components needed.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20240163085A1Method for Combined Key Value-Dependent Exchange and Randomization of Two Input Values
Publication Date: 2024.05.16 INFINEON TECHNOLOGIES AG
  • US20240163085A1 patent drawing
  • US20240163085A1 patent drawing
  • US20240163085A1 patent drawing

AI summary

A method for a combined key value-dependent exchange and randomization of a first input value and a second input value comprises determining at least two shares of a key value, determining at least one modification value that depends on at least one of the first input value and the second input value, determining, for each share, an intermediary value which depends on the share and at least one of the at least one modification value, wherein at least one intermediary value further depends on a randomization value and arithmetically assembling the intermediary values to generate an output value for at least one of the first input value and the second input value.