Sbox Multiplier Input Checks for SIFA Fault Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The Canright Sbox is susceptible to Statistical Ineffective Fault Analysis (SIFA) attacks, where an adversary can deduce sensitive internal values by introducing ineffective faults that do not alter the ciphertext, exploiting the final multiplier stage's zero-value bias.

Innovation Solution

A detection mechanism is implemented to monitor inputs to the final multiplier stage of the Sbox, checking for conditions that indicate a SIFA attack, and a duplicated SIFA detector circuit is used to protect against attacks targeting individual components, ensuring that ineffective faults are distinguished from effective faults.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If the Canright Sbox is implemented with a compact final multiplier stage, then resource efficiency is improved, but susceptibility to Statistical Ineffective Fault Analysis (SIFA) attacks worsens

Engineering Contradiction:
Improveresource efficiencyVSAvoidSIFA attack susceptibility
Core Design Contradiction:
Quantity of substanceVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by checking the input values to the final multiplier stage before the multiplication operation occurs. The detection circuit evaluates whether the input conditions could lead to an ineffective fault scenario, and if so, aborts the operation before the fault can be exploited. This prevents SIFA attacks by identifying vulnerable states in advance, while maintaining the compact Canright Sbox structure.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If check circuits are added to detect SIFA attacks, then security against SIFA attacks is improved, but device complexity worsens

Engineering Contradiction:
ImproveSIFA attack protectionVSAvoidcircuit complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by placing detection circuits only at specific critical locations within the Sbox - namely, monitoring the input values to the final multiplier stage. Rather than adding comprehensive checking throughout the entire circuit, the solution focuses resources on the specific point where SIFA attacks exploit the zero-value bias. This localized approach provides effective SIFA protection while minimizing the increase in overall device complexity.

Inventive Principle:
Principle #3Local quality

3Adaptability or versatility

If the Sbox processes all input combinations, then computational completeness is improved, but processing time for safe operations worsens due to additional checks

Engineering Contradiction:
Improveinput processing completenessVSAvoidprocessing time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent applies partial action by implementing selective checking rather than verifying all possible input combinations. The detection circuit performs a focused evaluation of specific conditions (whether input values could create ineffective fault scenarios) without requiring exhaustive validation of every computational path. This approach maintains computational completeness for legitimate operations while avoiding unnecessary time expenditure on comprehensive verification of all input combinations.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS12476786B2Statistical ineffective fault analysis protection of Sbox
Publication Date: 2025.11.18 NXP BV
  • US12476786B2 patent drawing
  • US12476786B2 patent drawing
  • US12476786B2 patent drawing

AI summary

A protection circuit for a Sbox, including: a first check circuit configured to determine if a most significant bit (MSB) part input into a first multiplier of the Sbox is zero; a second check circuit configured to determine if a CCn value input into the first multiplier and a second multiplier of the Sbox is zero; a third check circuit configured to determine if a least significant bit (LSB) part input into a first multiplier of the Sbox is zero; and a first Statistical Ineffective Fault Analysis (SIFA) logic circuit configured to produce a first output to indicate a SIFA attack when one of the following conditions is satisfied: both the MSB part and the LSB part are zero and the CCn value is not zero: or the CCn value is zero and either of the MSB part and LSB part are not zero.