Lattice-Based Cryptography Coprocessor for Side-Channel Resistance
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cryptographic algorithms, such as CRYSTALS-Kyber, are vulnerable to first-order differential power analysis attacks, which can compromise the security of private keys by analyzing power consumption during key encapsulation and decapsulation operations.
Innovation Solution
A computer processing system with a specialized hardware architecture that includes a polynomial arithmetic unit, a sampling submodule, and an auxiliary submodule, all designed to perform lattice-based cryptographic primitives while resisting first-order side-channel attacks. This architecture minimizes performance and resource overhead while protecting against power analysis attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If software implementation of CRYSTALS-Kyber is protected against power analysis attacks, then security is improved, but performance overhead increases substantially
Solution Approach 1:
The patent replaces software-based protection mechanisms with a dedicated hardware accelerator that implements CRYSTALS-Kyber operations in hardware. This substitution eliminates the performance overhead associated with software-based side-channel protections while maintaining security, as the hardware architecture inherently resists power analysis attacks through its design (e.g., constant-time operations, masked registers, and controlled power consumption patterns).
Solution Approach 2:
The patent introduces a specialized coprocessor as an intermediary between the main processor and the cryptographic operations. This coprocessor handles the lattice-based computations in hardware, acting as a mediator that provides both security against power analysis and efficient performance. The coprocessor communicates with the main system through standardized interfaces, allowing secure key encapsulation without burdening the main processor with complex protection software.
2Reliability
If a protected specialized coprocessor is used, then high performance and security are achieved, but footprint increases
Solution Approach 1:
The patent segments the coprocessor into functional modules that handle specific aspects of the CRYSTALS-Kyber algorithm (e.g., polynomial arithmetic units, modular reduction units, sampling submodules). This segmentation allows for optimized resource utilization and reduces the overall footprint by enabling shared resources and avoiding redundancy. Each module is designed to perform its function with minimal overhead, contributing to a compact overall architecture.
Solution Approach 2:
The coprocessor is designed with multi-functional components that can perform various operations required by CRYSTALS-Kyber and potentially other lattice-based algorithms. For example, the polynomial arithmetic unit can perform multiplication, addition, and subtraction, while the sampling submodule handles different sampling operations. This universality reduces the footprint by avoiding dedicated hardware for each operation, as single units serve multiple purposes.
3Ease of manufacture
If hardware accelerators and microprocessor are used, then implementation simplicity is improved, but area overhead and clock cycles increase
Solution Approach 1:
The patent merges the cryptographic acceleration functions directly into a compact coprocessor unit that is tightly integrated with the main system. Rather than using separate hardware accelerators with extensive communication interfaces and memory systems, the coprocessor combines computation, data storage, and control functions in a unified architecture. This merging reduces area overhead by eliminating redundant components while maintaining implementation simplicity through a cohesive design.
Data Source
AI summary
A computer processing system configured to perform lattice-based cryptographic primitives with resistance to side-channel attacks with a computer processing architecture operably configured to perform at least one of key generation, key encapsulation, and key decapsulation and process security sensitive data, a sampling submodule performing hashing operations and centered binomial sampling routines, a polynomial arithmetic unit performing polynomial multiplication, polynomial addition, and polynomial subtraction by processing the security sensitive data that is divided into shares stored on a plurality of memory banks, an auxiliary submodule mathematical operations, a data interface unit operably configured to perform input and output operations and to input data and output data in shares, and de-serialize the input data into polynomial coefficients utilized by the polynomial arithmetic unit, and a controller submodule operably configured to sequence any operations needed to perform the at least one of key generation, key encapsulation, and key decapsulation.


