Lattice-Based Cryptography Masking Component Reuse

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Lattice-based cryptographic schemes require significant memory and computational resources for secure implementation on security controllers, which may not be feasible due to high memory requirements for large matrices and vectors, especially when protecting against side-channel attacks and potential quantum computer attacks.

Innovation Solution

A cryptographic processing device and method that reuse a masking component to reduce memory and computational overhead by precomputing row sums and using compressed shares for masked multiplication, allowing efficient lattice-based cryptography operations on resource-constrained devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If masking is applied to protect against side-channel attacks in lattice-based cryptography, then security is improved, but memory requirements increase significantly

Engineering Contradiction:
ImprovesecurityVSAvoidmemory requirements
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The secret first element is segmented into multiple components that are masked individually with the same masking component. This segmentation allows the masking to be applied component-wise, reducing the overall memory footprint compared to masking the entire element at once, while still providing protection against side-channel attacks.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A single masking component is reused across multiple components of the secret first element. This universal masking approach allows one masking component to serve multiple protection purposes simultaneously, reducing memory requirements compared to using separate masking components for each element, while maintaining security against side-channel attacks.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If large matrices and vectors are used in lattice-based cryptography, then cryptographic strength is improved, but device complexity increases

Engineering Contradiction:
Improvecryptographic strengthVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Row sums of the matrix are precomputed and stored before the actual cryptographic operation. This preliminary action reduces the computational complexity during the main operation, as the precomputed row sums can be directly used in the masked multiplication without requiring complex real-time computations, thereby reducing device complexity while maintaining cryptographic strength.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If masking is applied to protect secret elements, then security against side-channel attacks is improved, but computational overhead increases

Engineering Contradiction:
ImprovesecurityVSAvoidcomputational overhead
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The same masking component is reused for masking multiple components of the secret first element. This reuse reduces the number of masking operations required, thereby reducing computational overhead compared to using unique masking components for each element, while still providing comprehensive security against side-channel attacks.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The approach changes the parameter of masking from using multiple different masking components to using a single reused masking component. This parameter change reduces the number of cryptographic operations needed during execution, lowering computational overhead while maintaining the security properties through the reused mask.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11870901B2Cryptographic processing device and method for performing a lattice-based cryptography operation
Publication Date: 2024.01.09 INFINEON TECHNOLOGIES AG
  • US11870901B2 patent drawing
  • US11870901B2 patent drawing
  • US11870901B2 patent drawing

AI summary

According to various embodiments, a cryptographic processing device is described comprising a processor configured to determine a masking component, generate a masked version of a secret first element by masking multiple components of the secret first element with the masking component, determine a first share of the product of the secret first element and a second element by multiplying the second element with the masked version of the secret first element, determine a second share of the product of the secret first element and the second element by multiplying the second element with the difference of the secret first element and the masked version of the secret first element and continue with a lattice-based cryptography operation using the first share and the second share of the product.