Randomized Multiplication Steps for Side Channel Attack Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current secure integrated circuits face challenges in protecting against auxiliary channel analysis, particularly in modular exponentiation operations, where existing methods like SPA, DPA, and CPA require numerous current consumption curves and are complex to implement, and are often countered by hardware countermeasures.
Innovation Solution
The integrated circuit employs a method that randomly or pseudo-randomly modifies the order of elementary multiplication steps during binary word multiplication operations, using a single current consumption curve to determine if operations are LIM(a, a) or LIM(a, m) by applying horizontal transverse statistical processing to consumption sub-curves.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional auxiliary channel analysis methods (SPA, DPA, CPA) are used to test integrated circuits, then measurement precision can be achieved, but device complexity and loss of time increase due to requiring numerous current consumption curves
Solution Approach 1:
The patent segments the current consumption curve into multiple sub-curves, each corresponding to specific elementary multiplication steps. By analyzing these segmented sub-curves horizontally rather than requiring multiple complete curves, the method achieves precise measurement of secret data while reducing the complexity of acquiring numerous full consumption curves.
Solution Approach 2:
The patent transitions from vertical analysis (comparing multiple complete consumption curves) to horizontal analysis (examining sub-curves within a single curve). This dimensional change allows precise extraction of information about secret exponent bits without requiring multiple complete measurements, thereby reducing device complexity and testing time.
2Measurement precision
If traditional auxiliary channel analysis methods are used, then measurement precision can be achieved, but loss of time increases due to requiring numerous current consumption curves
Solution Approach 1:
By segmenting a single current consumption curve into informative sub-curves corresponding to specific multiplication operations, the method extracts precise measurements without requiring multiple complete curve acquisitions, thereby significantly reducing the time loss associated with traditional methods.
Solution Approach 2:
The patent applies partial action by focusing analysis only on the specific sub-curves that contain information about the secret exponent, rather than processing entire consumption curves. This selective approach achieves the necessary measurement precision while minimizing the time required for analysis.
3Ease of operation
If multiplication operations are executed in fixed order, then ease of operation is maintained, but reliability decreases against auxiliary channel attacks
Solution Approach 1:
The patent introduces dynamic randomization of the multiplication operation order using a random permutation vector. This dynamic change in execution sequence protects against side-channel attacks that rely on fixed patterns, while the overall multiplication function remains unchanged, maintaining ease of operation at the functional level.
Solution Approach 2:
The patent changes the parameter of operation sequence by applying a random permutation to the multiplication steps. This parameter transformation maintains the mathematical correctness of the multiplication while altering the temporal sequence, thereby protecting against auxiliary channel analysis without affecting the operational simplicity of the cryptographic function.
Data Source
Figure 1~2
Figure 3
Figure 4~5B
AI summary
The circuit (CIC2) has a coprocessor (CP2) comprising a randomized multiplier (SMT2) for executing an operation of multiplication of two binary words in a set of elementary steps of multiplication of components of one of the binary words by components of the other binary word. The multiplier executes two successive multiplications of the binary words by modifying, in a random or pseudo-random manner, an order in which the elementary steps of multiplication of components of the former binary word by the components of the latter binary word are executed. Independent claims are also included for the following: (1) a device comprising integrated circuit (2) a method for protecting an integrated circuit against a side channel analysis.