Masked Gate Logic for Power Analysis Resistance
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cryptographic systems are vulnerable to side channel attacks such as power analysis, where attackers can extract secret keys by monitoring power consumption or electromagnetic emissions of cryptographic hardware devices, as existing countermeasures fail to effectively prevent inference of secret values.
Innovation Solution
Implementing gate-level masking techniques that divide secret data into shares and incorporate unpredictable data to prevent external power analysis, using masked gate logic structures with precharge mechanisms to balance signal probabilities and reduce propagation paths, thereby concealing secret keys from attackers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If gate-level masking techniques are implemented to prevent power analysis attacks, then security against side channel attacks is improved, but device complexity increases
Solution Approach 1:
The patent applies segmentation by dividing the secret data into multiple shares (e.g., d1, d2, d3) that are processed independently through different propagation paths. This segmentation ensures that no single path reveals the complete secret, thereby preventing power analysis attacks while maintaining the computational function through reconstructed output from multiple path results.
Solution Approach 2:
The patent implements local quality by creating different propagation paths with distinct characteristics (e.g., paths through gates G1-G4 versus G5-G8). Each path has unique local properties in terms of timing and power consumption patterns, which balances the overall power trace to mask the secret while preserving correct computation results through the majority vote or reconstruction mechanism.
2Reliability
If multiple propagation paths are created to mask secret data, then resistance to power analysis is improved, but the number of signal paths and potential glitches increases
Solution Approach 1:
The patent segments the computation into multiple independent propagation paths that process different shares of the secret data. This segmentation creates parallel signal paths (e.g., first path through G1-G4, second path through G5-G8) that independently compute partial results, which are then combined to produce the final output. The segmentation approach increases resistance to power analysis by distributing the computational workload across multiple paths with different power consumption patterns.
Solution Approach 2:
The patent applies preliminary action by pre-computing and storing intermediate results in memory elements (e.g., memory element 144) before the final computation. This preliminary storage of processed shares allows the system to maintain multiple propagation paths without immediately combining all results, thereby reducing the number of active signal paths at any given time and minimizing glitches while preserving the security benefits of multiple paths.
Data Source
AI summary
A method of and system for gate-level masking of secret data during a cryptographic process is described. A mask share is determined, wherein a first portion of the mask share includes a first number of zero-values and a second number of one-values, and a second portion of the mask share includes the first number of one-values and the second number of zero-values. Masked data values and the first portion of the mask share are input into a first portion of masked gate logic, and the masked data values and the second portion of the mask share are input into a second portion of the masked gate logic. A first output from the first portion of the masked gate logic and a second output from the second portion of the masked gate logic are identified, wherein either the first output or the second output is a zero-value.


