Randomized Multiplication Steps for Side Channel Attack Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current secure integrated circuits face challenges in protecting against auxiliary channel analysis, particularly in modular exponentiation operations, where existing methods like SPA, DPA, and CPA require numerous current consumption curves and are complex to implement, and are often countered by hardware countermeasures.

Innovation Solution

The integrated circuit employs a method that randomly or pseudo-randomly modifies the order of elementary multiplication steps during binary word multiplication operations, using a single current consumption curve to determine if operations are LIM(a, a) or LIM(a, m) by applying horizontal transverse statistical processing to consumption sub-curves.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional auxiliary channel analysis methods (SPA, DPA, CPA) are used to test integrated circuits, then measurement precision can be achieved, but device complexity and loss of time increase due to requiring numerous current consumption curves

Engineering Contradiction:
Improvemeasurement precisionVSAvoiddevice complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the current consumption curve into multiple sub-curves, each corresponding to specific elementary multiplication steps. By analyzing these segmented sub-curves horizontally rather than requiring multiple complete curves, the method achieves precise measurement of secret data while reducing the complexity of acquiring numerous full consumption curves.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent transitions from vertical analysis (comparing multiple complete consumption curves) to horizontal analysis (examining sub-curves within a single curve). This dimensional change allows precise extraction of information about secret exponent bits without requiring multiple complete measurements, thereby reducing device complexity and testing time.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Measurement precision

If traditional auxiliary channel analysis methods are used, then measurement precision can be achieved, but loss of time increases due to requiring numerous current consumption curves

Engineering Contradiction:
Improvemeasurement precisionVSAvoidloss of time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

By segmenting a single current consumption curve into informative sub-curves corresponding to specific multiplication operations, the method extracts precise measurements without requiring multiple complete curve acquisitions, thereby significantly reducing the time loss associated with traditional methods.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies partial action by focusing analysis only on the specific sub-curves that contain information about the secret exponent, rather than processing entire consumption curves. This selective approach achieves the necessary measurement precision while minimizing the time required for analysis.

Inventive Principle:
Principle #16Partial or excessive action

3Ease of operation

If multiplication operations are executed in fixed order, then ease of operation is maintained, but reliability decreases against auxiliary channel attacks

Engineering Contradiction:
Improveease of operationVSAvoidreliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces dynamic randomization of the multiplication operation order using a random permutation vector. This dynamic change in execution sequence protects against side-channel attacks that rely on fixed patterns, while the overall multiplication function remains unchanged, maintaining ease of operation at the functional level.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameter of operation sequence by applying a random permutation to the multiplication steps. This parameter transformation maintains the mathematical correctness of the multiplication while altering the temporal sequence, thereby protecting against auxiliary channel analysis without affecting the operational simplicity of the cryptographic function.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP2363975B1Integrated circuit protected against horizontal side channel attack
Publication Date: 2020.01.01 RAMBUS INC
  • EP2363975B1 patent drawingFigure 1~2
  • EP2363975B1 patent drawingFigure 3
  • EP2363975B1 patent drawingFigure 4~5B

AI summary

The circuit (CIC2) has a coprocessor (CP2) comprising a randomized multiplier (SMT2) for executing an operation of multiplication of two binary words in a set of elementary steps of multiplication of components of one of the binary words by components of the other binary word. The multiplier executes two successive multiplications of the binary words by modifying, in a random or pseudo-random manner, an order in which the elementary steps of multiplication of components of the former binary word by the components of the latter binary word are executed. Independent claims are also included for the following: (1) a device comprising integrated circuit (2) a method for protecting an integrated circuit against a side channel analysis.