Parallel Bit Mixers for Secure MAC and Hash Functions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing hash and message authentication code (MAC) functions are inflexible, slow, power-intensive, and vulnerable to side channel attacks, failing to meet the security and performance requirements of modern applications, particularly in fields like military aviation and commercial communications.

Innovation Solution

The development of a device and method using parallel bit mixers to generate coded data, which includes cryptographic hash and MAC functions, implemented in hardware to provide flexible security levels, reduced side channel leakage, and improved speed and power efficiency by utilizing diverse bit mixers with different subkeys and architectures, allowing for selectable security levels and efficient processing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing hash and MAC functions are implemented on a single programmable microprocessor, then device complexity is reduced, but side channel leakage increases and security is compromised

Engineering Contradiction:
Improvesecurity resistance to side channel attacksVSAvoidhardware structure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system divides the hash/MAC processing into multiple parallel bit mixer units (first bit mixer, second bit mixer, etc.), each handling different data blocks simultaneously. This segmentation into parallel independent units reduces side channel leakage by distributing the computational workload across multiple isolated processing paths.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The invention transitions from sequential single-processor execution to parallel multi-unit hardware architecture, adding spatial dimensionality to the processing system. Multiple bit mixers operate concurrently in parallel, transforming the time-sequential operation into space-parallel operation, which fundamentally changes the attack surface for side channel analysis.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Productivity

If existing hash and MAC functions are implemented in hardware, then speed and power efficiency improve, but flexibility and adaptability decrease

Engineering Contradiction:
Improveprocessing speedVSAvoidsecurity level selection flexibility
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The system incorporates selectable security levels through dynamic configuration options, allowing the hardware to adapt between different operational modes. The bit mixers can be configured with different parameters (n, m, r values) to provide varying security levels while maintaining hardware acceleration, making the system both fast and flexible.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The invention uses parameter-based configuration where different security levels are achieved by changing operational parameters (block size n, output size m, number of iterations r) rather than requiring different hardware architectures. This allows a single hardware implementation to provide multiple security levels through parameter adjustment.

Inventive Principle:
Principle #35Parameter changes

3Use of energy by moving object

If existing hash and MAC functions are implemented in hardware, then power consumption is reduced, but side channel leakage increases

Engineering Contradiction:
Improvepower consumptionVSAvoidside channel leakage
Core Design Contradiction:
Use of energy by moving objectVSObject-affected harmful factors

Solution Approach 1:

By segmenting the processing into multiple parallel bit mixer units, each unit processes smaller data blocks independently. This segmentation distributes the power consumption across multiple low-power units rather than one high-power unit, and simultaneously reduces side channel leakage by isolating the electromagnetic signatures of each unit.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The invention converts the potential harm of hardware implementation (side channel leakage) into a benefit by using parallelism to mask and distribute the leakage signals. The multiple parallel operations create overlapping electromagnetic signatures that are harder to analyze individually, turning the hardware's physical characteristics into a security feature rather than a vulnerability.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Data Source

PatentUS11283619B2Bit mixer based parallel MAC and hash functions
Publication Date: 2022.03.22 THE BOEING CO
  • US11283619B2 patent drawing
  • US11283619B2 patent drawing
  • US11283619B2 patent drawing

AI summary

A device for, and method of, generating coded data from input data are disclosed. The device includes: an input for receiving input data, where the input data includes a plurality of data blocks; a plurality of bit mixers coupled in parallel to the input, where each bit mixer is configured to receive at least one data block of the plurality of data blocks, where no bit mixer of the plurality of bit mixers is configured to receive a same data block of the plurality of data blocks as another of the bit mixers of the plurality of bit mixers, and where no two bit mixers of the plurality of bit mixers are configured to produce same output values for same input values; a combiner communicatively coupled in parallel to the plurality of bit mixers; and an output communicatively coupled to the combiner, the output configured to provide coded data.