Power Balancing Circuit for FPGA Side-Channel Attack Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing side-channel attack countermeasures for cryptographic hardware are either algorithm-specific, incur high silicon area and power overheads, or are not synthesizable for field programmable gate arrays (FPGAs), leading to performance degradation and scalability issues.
Innovation Solution
A generic, low-overhead power balancing circuit using a time-to-digital converter (TDC) and a bank of ring oscillators that adjusts current consumption to maintain a constant supply current, making it difficult for attackers to detect changes and thus preventing side-channel attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If masking technique is used to protect AES-128, then side-channel attack protection is improved, but silicon area increases from 250,000 logic cells to 500,000 logic cells
Solution Approach 1:
The patent introduces a power balancing circuit as an intermediary component between the cryptographic core and the power supply. This circuit monitors the power consumption of the cryptographic operations and dynamically adjusts the power delivery to maintain constant power traces, thereby providing side-channel attack protection without requiring algorithm modifications or doubling the silicon area.
Solution Approach 2:
The patent changes the physical parameter of power consumption by dynamically adjusting the power delivery characteristics through the power balancing circuit. By monitoring power consumption parameters and modifying the power supply characteristics in real-time, the system achieves constant power traces without changing the cryptographic algorithm or doubling the hardware area.
2Reliability
If noise injection circuits are used for SCA protection, then side-channel attack protection is improved, but power overhead increases about ten times
Solution Approach 1:
The power balancing circuit performs self-service by automatically monitoring its own power consumption and dynamically adjusting the power delivery without requiring external intervention. The circuit uses its own power consumption data to control the power supply, eliminating the need for separate noise injection circuits and reducing power overhead by a factor of ten.
Solution Approach 2:
The patent implements a feedback mechanism where the power balancing circuit continuously monitors power consumption and adjusts power delivery accordingly. This closed-loop feedback system dynamically balances power consumption to maintain constant power traces, providing effective SCA protection without the excessive power overhead associated with noise injection circuits.
3Reliability
If WDDL is used for power balancing, then side-channel attack protection is improved, but area overhead doubles as compared to circuit without WDDL
Solution Approach 1:
The patent uses a power balancing circuit as an intermediary that sits between the cryptographic core and the power supply. This mediator dynamically adjusts power delivery based on real-time power consumption monitoring, achieving constant power traces without requiring the area-intensive WDDL technique or any modification to the cryptographic algorithm.
4Reliability
If existing DPA protection techniques are used, then side-channel attack protection is improved, but performance degradation occurs (reduction in throughput)
Solution Approach 1:
The power balancing circuit operates continuously in the background, dynamically adjusting power delivery without interrupting or slowing down cryptographic operations. The circuit maintains constant power traces throughout the entire operation, providing continuous protection without the performance degradation associated with other DPA protection techniques that require algorithm modifications.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
The solution provides greater than 10,000 times more protection against differential power and electromagnetic side-channel attacks with minimal area and power overhead, being synthesizable for FPGA implementation without performance penalties.
Implementation Method 1
a power balancing circuit including a bank of ring oscillators
Data Source
AI summary
An apparatus, system, and method for protecting a component from an observation attack are provided. A power balancing circuit configured to protect a cryptography component can include a ring oscillator electrically connected to a power supply, a time-to-digital converter (TDC) electrically connected to monitor an electrical parameter of the electrical power drawn by the cryptography component and provide data indicative of the electrical parameter, and a controller circuit configured to adjust a number of inverters of the ring oscillator drawing power from the power supply based on the data.


