Nonlinear LDO Cascades for Crypto Side-Channel Leakage Suppression

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional power regulator-based techniques provide insufficient resistance to side-channel attacks in the frequency-domain, as they induce linear transformations that can be easily exposed through methods like fast Fourier transform, failing to effectively boost the minimum traces to disclose (MTD) in cryptographic systems.

Innovation Solution

A cascaded implementation of a non-linear low-dropout regulator (NL-LDO) combined with cryptographic engines and arithmetic transformations, which randomizes control loop parameters and provides a wide-dynamic-range, high-bandwidth response to mask power consumption variations, achieving more than five orders of magnitude improvement in both time and frequency-domain MTD.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If non-linear low-dropout regulator with arithmetic transformations is implemented, then frequency-domain MTD is improved, but device complexity increases

Engineering Contradiction:
Improvefrequency-domain MTDVSAvoidregulator complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent merges the non-linear low-dropout regulator with the cryptographic engine into an integrated system. The power regulator and cryptographic operations are combined in a way that the non-linear power delivery characteristics are directly coupled with the arithmetic transformations, creating a unified SCA-resistant cryptographic system that reduces overall complexity.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The non-linear low-dropout regulator serves multiple functions: it provides standard voltage regulation, introduces non-linear transformations for SCA resistance, and works synergistically with arithmetic transformations in the cryptographic engine. This multi-functionality reduces the need for separate dedicated components.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Object-generated harmful factors

If non-linear low-dropout regulator is used, then power consumption masking is improved, but area overhead increases

Engineering Contradiction:
Improvepower consumption variationsVSAvoidcircuit area
Core Design Contradiction:
Object-generated harmful factorsVSArea of stationary object

Solution Approach 1:

The patent changes the operational parameters of the power regulator by introducing non-linear control characteristics. The non-linear error amplifier and non-linear transfer function modify how the regulator responds to load changes, effectively masking power consumption variations associated with cryptographic operations without requiring substantial area increases.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12047485B2Time and frequency domain side-channel leakage suppression using integrated voltage regulator cascaded with runtime crypto arithmetic transformations
Publication Date: 2024.07.23 INTEL CORP
  • US12047485B2 patent drawing
  • US12047485B2 patent drawing
  • US12047485B2 patent drawing

AI summary

Apparatus and method for resisting side-channel attacks on cryptographic engines are described herein. An apparatus embodiment includes a cryptographic block coupled to a non-linear low-dropout voltage regulator (NL-LDO). The NL-LDO includes a scalable power train to provide a variable load current to the cryptographic block, randomization circuitry to generate randomized values for setting a plurality of parameters, and a controller to adjust the variable load current provided to the cryptographic block based on the parameters and the current voltage of the cryptographic block. The controller to cause a decrease in the variable load current when the current voltage is above a high voltage threshold, an increase in the variable load current when the current voltage is below a low voltage threshold; and a maximization of the variable load current when the current voltage is below an undervoltage threshold. The cryptographic block may be implemented with arithmetic transformations.