Round-Interleaved Ciphering Circuit for Side Channel Attack Resistance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing hardware implementations of cryptosystems, such as AES, are susceptible to side channel attacks due to signal leakage, and current protection strategies often increase circuit complexity or degrade performance.

Innovation Solution

A method for concurrently executing two block cryptographic computations using a ciphering circuit, where processing rounds are alternated in a round-interleaved sequence, reducing dynamic leakage and improving resistance against first-order side channel analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If protection strategies are implemented to resist side channel attacks, then resistance against side channel analysis is improved, but circuit complexity increases and/or performance degrades

Engineering Contradiction:
Improveresistance against side channel attacksVSAvoidcircuit complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the cryptographic computation into multiple processing rounds that are executed in an interleaved sequence. By segmenting the computation timeline and alternating between rounds of different cryptographic operations, the system reduces signal leakage patterns that would otherwise expose side channel information, thereby improving security without requiring additional protective circuitry

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamic interleaving of processing rounds where the execution sequence is adjusted based on the specific cryptographic operations being performed. This dynamic scheduling approach allows the system to adapt the timing and sequence of operations to minimize signal leakage while maintaining computational efficiency, resolving the contradiction between security and performance

Inventive Principle:
Principle #15Dynamics

2Reliability

If protection strategies are implemented to resist side channel attacks, then resistance against side channel analysis is improved, but ciphering performance degrades

Engineering Contradiction:
Improveresistance against side channel attacksVSAvoidciphering performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent performs preliminary interleaving of processing rounds before the actual cryptographic computation begins. By pre-scheduling the sequence of operations and preparing the interleaved execution plan in advance, the system ensures that security measures are built into the computation structure itself, avoiding performance penalties that would arise from adding protective layers during execution

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent maintains continuous execution of cryptographic operations through interleaved processing rounds. Instead of completing one entire cryptographic operation before starting another, the system continuously executes multiple rounds in parallel, ensuring that useful computational action never stops while distributing the workload to prevent signal leakage patterns

Inventive Principle:
Principle #20Continuity of useful action

3Object-affected harmful factors

If concurrent execution with round interleaving is implemented, then signal leakage is reduced, but execution time may increase

Engineering Contradiction:
Improvesignal leakageVSAvoidexecution time
Core Design Contradiction:
Object-affected harmful factorsVSLoss of time

Solution Approach 1:

The patent introduces a temporal dimension to the execution of processing rounds by interleaving them in a round-robin fashion. Instead of executing operations sequentially in a single dimension, the system distributes operations across multiple time slices, reducing signal leakage in the temporal domain while maintaining overall execution efficiency through parallel processing capabilities

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS20250038950A1Methods, unit and device for concurrently executing first and second block cryptographic computations
Publication Date: 2025.01.30 NAGRAVISION SA
  • US20250038950A1 patent drawing
  • US20250038950A1 patent drawing
  • US20250038950A1 patent drawing

AI summary

A method for concurrently executing a first block cryptographic computation (60) and a second block cryptographic computation (61) using a ciphering circuit. The first block cryptographic computation includes computing a first output block (42) by executing a plurality of first processing rounds (70i, 78) based on a first input block (38, 64), and the second block cryptographic computation includes computing a second output block (43) by executing a plurality of second processing rounds (75j, 79) based on a second input block (39, 65). The method further includes alternatingly executing respective first and second processing rounds in a round-interleaved sequence.