Masked Cryptographic Co-Processor for Post-Quantum Side-Channel Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cryptographic systems face challenges in efficiently performing post-quantum cryptographic operations on low-resource embedded devices while ensuring resistance to attacks, particularly in the context of quantum computing threats, and there is a need for secure implementations that do not require large-scale redesign.

Innovation Solution

A cryptographic system-on-chip (SoC) is developed, comprising a cryptographic math unit and control unit, which performs discrete binary arithmetic and post-quantum cryptographic operations autonomously, with a security boundary that prevents access to secret data, and includes features like masking and side-channel security to protect against attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If post-quantum cryptographic functions are implemented on low-resource embedded devices, then quantum security is achieved, but resource consumption (processor cycles, power) increases significantly

Engineering Contradiction:
Improvequantum securityVSAvoidpower consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The cryptographic system is divided into a host device and a separate cryptographic device. The host device handles non-cryptographic operations while the cryptographic device专门 handles post-quantum cryptographic operations. This segmentation allows embedded devices to offload resource-intensive cryptographic computations to a dedicated cryptographic device, reducing power consumption and processor cycle usage on the embedded device while maintaining quantum security.

Inventive Principle:
Principle #1Segmentation

2Productivity

If post-quantum cryptographic operations are performed at high speed, then productivity is improved, but security against side-channel attacks may be compromised

Engineering Contradiction:
Improvecryptographic operation speedVSAvoidside-channel security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The cryptographic device acts as an intermediary between the host device and the cryptographic operations. It receives cryptographic operation requests from the host device, performs the operations in an isolated secure environment with dedicated security measures, and returns results to the host. This intermediary approach allows high-speed cryptographic operations to be performed securely without exposing the host device to side-channel vulnerabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If cryptographic operations are performed repeatedly at high speeds, then productivity increases, but resource consumption accumulates

Engineering Contradiction:
Improveencryption throughputVSAvoidprocessor cycles
Core Design Contradiction:
ProductivityVSQuantity of substance

Solution Approach 1:

The system segments cryptographic processing from general-purpose processing. The cryptographic device is dedicated exclusively to cryptographic operations, allowing it to optimize processor cycles for cryptographic functions. The host device can focus on application logic while the cryptographic device handles repeated encryption/decryption operations efficiently, reducing the cumulative processor cycle consumption on the embedded device.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12470376B2Cryptographic system for post-quantum cryptographic operations
Publication Date: 2025.11.11 PQSHIELD LTD
  • US12470376B2 patent drawing
  • US12470376B2 patent drawing
  • US12470376B2 patent drawing

AI summary

Certain examples described herein relate to at least a cryptographic system and a method of operating a cryptographic system. The cryptographic system may be implemented as a co-processor for performing post-quantum cryptographic functions. The cryptographic system has a set of bus interfaces for coupling to an external computing system, a cryptographic math unit and a control unit. The cryptographic math unit in certain examples is adapted to provide one or more masked modes of operation that secure the cryptographic operations against side-channel and non-invasive attacks. The method of operating a cryptographic system involves annotating secret data and tracking those annotations through one or more arithmetic operations.