Random Pre-Charging for Side-Channel Attack Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing electronic devices are vulnerable to side-channel attacks that exploit power consumption patterns, as current countermeasures are insufficient in preventing unauthorized access to secret information.

Innovation Solution

The implementation of a combinational logic circuit with protection circuitry that applies random data before sampling, ensuring a propagation delay that prevents sampling of random data by state-sampling components, thereby randomizing power consumption and enhancing security against side-channel attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If random data is applied to inputs before sampling to protect against side-channel attacks, then security level is improved, but there is a risk that random data may be sampled instead of functional data

Engineering Contradiction:
Improvesecurity levelVSAvoidsampling accuracy
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

Random data is applied to the combinational logic circuit inputs before the functional data is applied, allowing the random data to propagate through the circuit and be discarded before the functional data is sampled. This preliminary action creates a time window where random values are processed but not captured, protecting against side-channel attacks while ensuring functional data integrity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system dynamically switches between applying random data and functional data to the combinational logic circuit inputs based on timing control. The multiplexer dynamically selects between random data sources and functional data inputs, and the system adapts the timing of data application to ensure proper propagation and sampling windows are maintained.

Inventive Principle:
Principle #15Dynamics

2Reliability

If propagation delay is increased to ensure random data completes propagation before functional data is applied, then security is improved, but clock speed may be reduced

Engineering Contradiction:
ImprovesecurityVSAvoidclock speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The system applies random data for a duration that is sufficient to ensure complete propagation through all possible signal paths, even if this appears excessive. By ensuring the random data application window is longer than the maximum propagation delay, the system guarantees security without requiring clock cycle adjustments, as the random data is fully processed and discarded within the same clock cycle.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The combinational logic circuit naturally provides the required propagation delay through its inherent logic path delays. The system leverages the circuit's own propagation characteristics to determine the appropriate timing for switching between random and functional data, without requiring external delay elements or clock speed reduction. The circuit's intrinsic timing properties are used to self-regulate the security timing requirements.

Inventive Principle:
Principle #25Self-service

3Reliability

If hold-time margin is increased to accommodate random data propagation, then sampling reliability is improved, but device complexity increases

Engineering Contradiction:
Improvesampling reliabilityVSAvoidcircuit complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system combines the random data generation, multiplexing, and timing control functions into an integrated protection circuitry module. The hold-time margin requirement is merged with the existing clock timing structure, utilizing the same clock signal and control logic that already exists in the device, rather than introducing separate timing mechanisms.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The combinational logic circuit is designed to serve dual purposes: processing functional data for normal operation and processing random data for security protection. The same logic paths, flip-flops, and sampling mechanisms are used for both functional and security-related operations, eliminating the need for separate dedicated security circuitry and reducing overall device complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10878133B2Mitigation of side-channel attacks using small-overhead random pre-charging
Publication Date: 2020.12.29 NUVOTON
  • US10878133B2 patent drawing
  • US10878133B2 patent drawing
  • US10878133B2 patent drawing

AI summary

An electronic device includes a combinational logic circuit, one or more state-sampling components, and protection circuitry. The combinational logic circuit has one or more inputs and one or more outputs. The state-sampling components are configured to sample the outputs of the combinational logic circuit at successive clock cycles. The protection circuitry is configured to protect the combinational logic circuit by, per clock cycle, starting to apply random data to the inputs of the combinational logic circuit a given time duration before a sampling time of the state-sampling components for that clock cycle, and, after applying the random data, switching to apply functional data to the inputs of the combinational logic circuit, to be sampled by the state-sampling components. A propagation delay, over any signal path via the combinational logic circuit, is no less than the given time duration.