Non-linear Share Encoding for Cryptographic DPA Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cryptographic data processing systems are vulnerable to external monitoring attacks, such as differential power analysis (DPA), due to the sequential appearance of shares representing secret values on communication buses or in memory, which can reveal protected information like encryption keys.
Innovation Solution
Implementing non-linear share encoding methods that ensure shares representing secret values are never simultaneously or sequentially present in un-encoded form in registers, memory, or on communication buses, using bijective encoding functions and decoding operations to protect against DPA attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If linear share encoding is used for cryptographic operations, then the implementation is simple and computationally efficient, but the system becomes vulnerable to differential power analysis attacks because shares appear sequentially in un-encoded form in memory and on communication buses
Solution Approach 1:
The patent applies non-linear encoding transformation to the shares, changing the mathematical representation from linear to non-linear form. This transformation modifies the parameters of the share encoding while maintaining the fundamental cryptographic functionality, thereby protecting against DPA attacks that exploit linear relationships in power consumption patterns
Solution Approach 2:
The patent introduces an encoding layer as an intermediary between the secret shares and their physical representation in memory and communication buses. This encoding mediator transforms the shares into a protected form that prevents direct observation of the underlying secret values through power analysis, while allowing legitimate cryptographic operations to proceed
2Object-affected harmful factors
If non-linear share encoding is implemented to protect against DPA attacks, then security against external monitoring is enhanced, but the computational complexity and implementation difficulty increase
Solution Approach 1:
The patent segments the cryptographic operation into distinct phases: encoding phase, computation phase, and decoding phase. By dividing the operation into these segments, the complex non-linear encoding is isolated to specific points in the computation, allowing the majority of the cryptographic logic to remain relatively simple while still achieving security benefits
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Systems and methods for performing cryptographic data processing operations employing non-linear share encoding for protecting from external monitoring attacks. An example method may comprise: receiving a plurality of shares representing a secret value employed in a cryptographic operation, wherein plurality of shares comprises a first share represented by an un-encoded form and a second share represented by an encoded form; producing a transformed form of the second share; and performing the cryptographic operation using the transformed form of the second share.