Rotation-Invariant Cryptographic Circuit for Side-Channel Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cryptographic operations in security-related applications, such as smart cards and vehicle control devices, face challenges in being robust against side-channel attacks due to non-rotation invariant operations like bitwise shift and modular addition, which compromise the security of cryptographic keys.

Innovation Solution

A circuit and method are introduced that perform operations in a rotation-invariant manner by using a rotation parameter to generate a bit mask, allowing operands to remain in a rotated state throughout processing, ensuring that operations like shift and modular addition are invariant to rotation, thereby enhancing security against side-channel attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If cryptographic operations use non-rotation invariant operations like bitwise shift and modular addition, then processing efficiency is improved, but security against side-channel attacks deteriorates

Engineering Contradiction:
Improveprocessing efficiencyVSAvoidsecurity against side-channel attacks
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent changes the parameter of rotation invariance for cryptographic operations. By ensuring that operations remain valid under bit rotation, the system maintains security against side-channel attacks while preserving processing efficiency. This is achieved through rotation-invariant cryptographic algorithms and operations that do not reveal information about secret keys through power consumption patterns.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces random rotation values as intermediaries between the secret key and the cryptographic processing. These random rotation values mask the actual key material during processing, preventing attackers from correlating power consumption patterns with specific key bits, thus maintaining security while allowing efficient processing.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If random rotation is introduced into cryptographic processing, then security against side-channel attacks is improved, but operation correctness deteriorates due to non-rotation invariant operations

Engineering Contradiction:
Improvesecurity against side-channel attacksVSAvoidoperation correctness
Core Design Contradiction:
ReliabilityVSManufacturing precision

Solution Approach 1:

The patent changes the operational parameters to be rotation-invariant, meaning the operations produce correct results regardless of the rotation state of the input data. This allows random rotation to be applied for security purposes without compromising operation correctness, as the cryptographic algorithms are specifically designed to handle rotated inputs properly.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If operands are rotated before processing, then security is improved by distributing data across hardware paths, but operational complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidoperational complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements cryptographic operations that are universal in the sense that they function correctly regardless of the rotation state of their inputs. This multi-functionality allows the same hardware circuit to process both rotated and unrotated data correctly, eliminating the need for separate processing paths and reducing operational complexity while maintaining security benefits.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11755321B2Circuit and method for the rotation-invariant execution of one or more operations with at least one operand
Publication Date: 2023.09.12 INFINEON TECHNOLOGIES AG
  • US11755321B2 patent drawing
  • US11755321B2 patent drawing
  • US11755321B2 patent drawing

AI summary

A circuit includes a data input that is configured to receive a data word, the data word including at least one operand which is rotated by a number of bits given by a rotation parameter, a first control input that is configured to receive the rotation parameter, a second control input that is configured to receive an indication of an operation to be performed, a first subcircuit that is configured to generate an operation- and rotation-dependent bit mask from the rotation parameter and the indication of the operation to be performed, a second subcircuit which is configured to process the at least one operand as a function of the bit mask and the operation to be performed, wherein the operand and the operation result generated by the processing remain in the rotated state, and a data output which is configured to output the operation result.