Non-linear Share Encoding for Cryptographic DPA Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cryptographic data processing systems are vulnerable to external monitoring attacks, such as differential power analysis (DPA), due to the sequential appearance of shares representing secret values on communication buses or in memory, which can reveal protected information like encryption keys.

Innovation Solution

Implementing non-linear share encoding methods that ensure shares representing secret values are never simultaneously or sequentially present in un-encoded form in registers, memory, or on communication buses, using bijective encoding functions and decoding operations to protect against DPA attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If linear share encoding is used for cryptographic operations, then the implementation is simple and computationally efficient, but the system becomes vulnerable to differential power analysis attacks because shares appear sequentially in un-encoded form in memory and on communication buses

Engineering Contradiction:
Improveimplementation simplicityVSAvoidvulnerability to DPA attacks
Core Design Contradiction:
Ease of manufactureVSObject-affected harmful factors

Solution Approach 1:

The patent applies non-linear encoding transformation to the shares, changing the mathematical representation from linear to non-linear form. This transformation modifies the parameters of the share encoding while maintaining the fundamental cryptographic functionality, thereby protecting against DPA attacks that exploit linear relationships in power consumption patterns

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces an encoding layer as an intermediary between the secret shares and their physical representation in memory and communication buses. This encoding mediator transforms the shares into a protected form that prevents direct observation of the underlying secret values through power analysis, while allowing legitimate cryptographic operations to proceed

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If non-linear share encoding is implemented to protect against DPA attacks, then security against external monitoring is enhanced, but the computational complexity and implementation difficulty increase

Engineering Contradiction:
Improveprotection against DPA attacksVSAvoidimplementation complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent segments the cryptographic operation into distinct phases: encoding phase, computation phase, and decoding phase. By dividing the operation into these segments, the complex non-linear encoding is isolated to specific points in the computation, allowing the majority of the cryptographic logic to remain relatively simple while still achieving security benefits

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP3475825B1Cryptographic operations employing non-linear share encoding for protecting from external monitoring attacks
Publication Date: 2023.01.25 CRYPTOGRAPHY RESEARCH INC
  • EP3475825B1 patent drawingFigure 1
  • EP3475825B1 patent drawingFigure 2
  • EP3475825B1 patent drawingFigure 3

AI summary

Systems and methods for performing cryptographic data processing operations employing non-linear share encoding for protecting from external monitoring attacks. An example method may comprise: receiving a plurality of shares representing a secret value employed in a cryptographic operation, wherein plurality of shares comprises a first share represented by an un-encoded form and a second share represented by an encoded form; producing a transformed form of the second share; and performing the cryptographic operation using the transformed form of the second share.