Non-Linear LDO Cascades for Crypto Side-Channel Suppression

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional power regulator-based techniques provide insufficient resistance against side-channel attacks in the frequency-domain, as they induce linear transformations that can be easily exposed through methods like fast Fourier transform, failing to effectively boost the minimum traces to disclose (MTD) in cryptographic devices.

Innovation Solution

A cascaded implementation of a non-linear low-dropout regulator (NL-LDO) and cryptographic engines augmented with arithmetic transformations, which randomizes control loop parameters and provides a wide-dynamic-range, high-bandwidth response to mask power consumption variations, achieving significant boosts in both time and frequency-domain MTD with minimal area overhead.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If linear transformations are used in power regulators, then device complexity is reduced, but frequency-domain security deteriorates

Engineering Contradiction:
Improveregulator complexityVSAvoidfrequency-domain MTD
Core Design Contradiction:
Device complexityVSMeasurement precision

Solution Approach 1:

The patent modifies the regulator's transfer function parameter from linear to non-linear, creating a system where the relationship between input and output power changes dynamically with operating conditions. This non-linear parameter change maintains relative device simplicity while dramatically improving frequency-domain security against side-channel attacks.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If non-linear LDO with arithmetic transformations is implemented, then frequency-domain MTD is improved, but device complexity increases

Engineering Contradiction:
Improvefrequency-domain MTDVSAvoidcircuit complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent merges the non-linear LDO power regulator with cryptographic arithmetic transformation blocks into an integrated circuit. This consolidation achieves frequency-domain MTD improvement through non-linear transformations while managing device complexity by integrating multiple functions into a unified structure rather than adding separate components.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The integrated circuit performs multiple functions: power regulation, cryptographic operations, and non-linear transformations for side-channel protection. This multi-functionality reduces overall system complexity by combining what would otherwise be separate components into a single universal block that handles all these tasks.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP4020114A1Time and frequency domain side-channel leakage suppression using integrated voltage regulator cascaded with runtime crypto arithmetic transformations
Publication Date: 2022.06.29 INTEL CORP
  • EP4020114A1 patent drawingFigure 1
  • EP4020114A1 patent drawingFigure 2
  • EP4020114A1 patent drawingFigure 3

AI summary

Apparatus and method for resisting side-channel attacks on cryptographic engines are described herein. An apparatus embodiment includes a cryptographic block coupled to a non-linear low-dropout voltage regulator (NL-LDO). The NL-LDO includes a scalable power train to provide a variable load current to the cryptographic block, randomization circuitry to generate randomized values for setting a plurality of parameters, and a controller to adjust the variable load current provided to the cryptographic block based on the parameters and the current voltage of the cryptographic block. The controller to cause a decrease in the variable load current when the current voltage is above a high voltage threshold, an increase in the variable load current when the current voltage is below a low voltage threshold; and a maximization of the variable load current when the current voltage is below an undervoltage threshold. The cryptographic block may be implemented with arithmetic transformations.