Lower-Order Masking in Higher-Order Cryptographic Designs
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Higher-order countermeasures against advanced differential power analysis (DPA) attacks in cryptographic systems often require increased power consumption and resource expenditure, making them inefficient for non-critical portions of cryptographic algorithms that operate on public data.
Innovation Solution
Implementing lower-order masking techniques within a higher-order masked design by disabling cross-domain computations, specifically by zeroing out data shares and internal gates, to optimize power efficiency and performance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If higher-order masking countermeasures are implemented, then security against advanced DPA attacks is improved, but power consumption and resource usage increase
Solution Approach 1:
The patent applies different masking orders to different portions of the cryptographic algorithm based on their security requirements. Critical sections operating on secret data use higher-order masking (e.g., second-order), while non-critical sections operating on public data use lower-order or no masking. This local differentiation optimizes power consumption by avoiding unnecessary high-order countermeasures in sections where they are not required, while maintaining adequate security where needed.
2Reliability
If higher-order masking countermeasures are implemented, then security against advanced DPA attacks is improved, but resource expenditure increases
Solution Approach 1:
The patent implements masking order differentiation where critical cryptographic operations use higher-order masking and non-critical operations use lower-order masking. This reduces the quantity of computational resources required compared to applying uniform high-order masking throughout the entire algorithm, while maintaining security against DPA attacks for the critical sections.
3Reliability
If higher-order masking countermeasures are implemented, then security against advanced DPA attacks is improved, but system performance is reduced
Solution Approach 1:
The patent applies higher-order masking only to critical sections of the cryptographic algorithm that handle secret data, while allowing non-critical sections to operate with lower-order or no masking. This selective approach maintains security for vulnerable operations while preserving system performance by avoiding the overhead of high-order masking in sections where it provides no additional security benefit.
Data Source
AI summary
A computer processing system configured to effectuate lower-order masking in a higher-order masked design that includes a DOM Multiplication gate of order M operably configured to receive M+1 data shares for each of a plurality of variables and operably configured to perform a lower order masking of N. As used herein, M is greater than N, by disabling at least one cross-domain computation of the M+1 data shares between N+1 data shares and M−N data shares. To that end, the system and method of effectuating lower-ordered masking in a higher-order masked design beneficially by being operable to disable cross-domain computations to perform the lower-order masked operations.


