Clock-Gated Encryption Using Randomized Functional Units

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

IoT devices are vulnerable to Side-Channel Attacks (SCA) that exploit physical characteristics to reveal secret keys, necessitating improved security measures to prevent information theft.

Innovation Solution

An encryption device utilizing a clock gating unit and random-number generator to randomly enable functional units, thereby disturbing power traces, and can be implemented without cryptography expertise, with the option to subdivide functional units for increased complexity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If functional units are kept simple and minimal, then device complexity and cost are reduced, but power trace complexity and security against SCA are insufficient

Engineering Contradiction:
Improvesecurity against side-channel attacksVSAvoidencryption device complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent changes the operational parameters of functional units by randomly enabling them during specific time periods. The controller generates enable signals that randomly activate functional units based on random numbers, transforming the static power consumption pattern into a dynamic, unpredictable pattern that resists power analysis attacks while keeping the hardware structure simple

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces dynamic behavior to functional units through random enabling and disabling during operation. Instead of functional units operating continuously or in fixed patterns, they are dynamically activated based on random numbers generated by the controller, creating variable power traces that prevent attackers from correlating power consumption with secret key operations

Inventive Principle:
Principle #15Dynamics

2Reliability

If random enabling of functional units is implemented, then power trace complexity increases and security improves, but device complexity and implementation difficulty increase

Engineering Contradiction:
Improvesecurity against power analysisVSAvoidimplementation ease without cryptography background
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a controller as an intermediary component that manages the random enabling of functional units. The controller generates random numbers and produces enable signals to activate functional units, separating the security function from the cryptographic operations. This intermediary approach allows simple functional units to achieve high security through coordinated control without requiring the functional units themselves to implement complex cryptographic protocols

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The functional units are designed to be self-sufficient and can operate independently when enabled. Each functional unit performs its designated cryptographic operation without needing to understand or implement the random enabling logic, as this is handled by the controller. This self-service approach allows functional units to remain simple while the system achieves high security through the coordinated action of the controller

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12413405B2Encryption device and encryption method with clock gating unit and random-number generator
Publication Date: 2025.09.09 NUVOTON
  • US12413405B2 patent drawing
  • US12413405B2 patent drawing
  • US12413405B2 patent drawing

AI summary

An encryption device is provided, which includes a controller, a random controller, a first functional unit, and a second functional unit. The controller generates a first enable signal and a second enable signal. When at least one of the first enable signal and the second enable signal is in a first logic level, the random controller generates a first random signal and a second random signal. The first functional unit performs the corresponding operation according to the first enable signal and the first random signal. The second functional unit performs the corresponding operation according to the second enable signal and the second random signal.