Pre-calculated Cipher Authentication for Side-Channel Attack Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cryptographic systems, such as keyless entry/ignition systems, are vulnerable to side-channel attacks when an attacker has physical access, allowing them to recover sensitive information and reduce the strength of encryption algorithms, particularly through differential power analysis.

Innovation Solution

Executing cryptographic calculations in a secure environment to produce pre-calculated ciphers, which are stored and used for authentication requests and responses, ensuring that cryptographic operations are only performed after verifying a secure environment, thus preventing unauthorized access and side-channel attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If cryptographic calculations are performed in real-time during authentication, then authentication speed is improved, but vulnerability to side-channel attacks increases

Engineering Contradiction:
Improveauthentication speedVSAvoidside-channel attack vulnerability
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The patent pre-calculates cryptographic ciphers and stores them in a secure environment before authentication occurs. When authentication is needed, the pre-calculated ciphers are used instead of performing real-time cryptographic calculations, thus maintaining authentication speed while eliminating the vulnerability to side-channel attacks that would occur during real-time computation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary component - a secure element or trusted platform module - that performs the cryptographic calculations in a protected environment. This intermediary acts as a mediator between the authentication system and the external world, isolating the sensitive cryptographic operations from potential side-channel attacks while still enabling fast authentication through pre-computed values.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If cryptographic operations are performed externally without secure environment verification, then ease of operation is improved, but security against unauthorized access deteriorates

Engineering Contradiction:
Improveauthentication operation simplicityVSAvoidsecurity against unauthorized access
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs a preliminary verification to determine if the environment is secure before allowing cryptographic operations to proceed. This preliminary check ensures that pre-calculated ciphers are only used in authenticated, secure contexts, maintaining both ease of operation and security against unauthorized access.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements a feedback mechanism where the system continuously monitors and verifies the security context before executing authentication operations. Based on this feedback about the security environment, the system decides whether to proceed with authentication using pre-calculated ciphers or to reject the operation, thus maintaining security while enabling ease of operation when conditions are appropriate.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11018879B2Method and system for authentication with side-channel attack protection using pre-calculated ciphers
Publication Date: 2021.05.25 NXP BV
  • US11018879B2 patent drawing
  • US11018879B2 patent drawing
  • US11018879B2 patent drawing

AI summary

Embodiments of an authentication system and a method for authentication using ciphers are described. In the system and method, cryptographic calculations of an encryption algorithm are executed at a base station, in a determined secure environment, to produce a pre-calculated cipher for a subsequent authentication process. The pre-calculated cipher is then used to transmit an authentication request message from the base station and validation of an authentication response message for the subsequent authentication.