Scrambling Module for Side Channel Attack Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security systems for chips, such as mobile phone chips, are vulnerable to side channel attacks due to the increasing effectiveness of attack algorithms, which can crack the chip key by analyzing power consumption information, leading to security breaches.

Innovation Solution

An attack prevention method and chip design that incorporates a scrambling module to generate power consumption and electromagnetic waves in synchronization with the cipher engine's operations, masking its normal power consumption and electromagnetic waves to prevent correct analysis during side channel attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple attack prevention algorithms are added in the cipher engine to defend against side channel attacks, then the security against side channel attacks is improved, but the power consumption and computational complexity increase

Engineering Contradiction:
Improvesecurity against side channel attacksVSAvoidpower consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent introduces a scrambling module as an intermediary component that generates random noise signals to mask the power consumption characteristics of the cipher engine. This mediator absorbs the harmful side channel information by adding random fluctuations to the power consumption profile, preventing attackers from extracting useful information while avoiding the need to modify the core cipher engine algorithms

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent converts the harmful power consumption variations that leak information into beneficial masking signals by using a scrambling module to generate random noise that correlates with the cipher engine's operation. The same power consumption fluctuations that attackers exploit are transformed into protective camouflage by adding controlled random variations that hide the underlying information patterns

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

2Reliability

If attack prevention algorithms are added to the cipher engine, then the security is improved, but the device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidcipher engine complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the security system into two independent parts: the original cipher engine that performs encryption/decryption operations and a separate scrambling module that provides attack prevention. This segmentation allows the cipher engine to remain simple and focused on its core function while the scrambling module handles the complexity of generating and applying masking signals, making the system easier to verify and maintain

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The scrambling module serves as an intermediary layer between the cipher engine and the external environment, absorbing the complexity of attack prevention mechanisms without requiring modifications to the cipher engine itself. This intermediary approach maintains the simplicity of the core cryptographic operations while providing robust security against side channel attacks

Inventive Principle:
Principle #24Intermediary (Mediator)

3Object-affected harmful factors

If a scrambling module is used to mask power consumption and electromagnetic waves, then the difficulty for side channel attacks is increased, but the power consumption increases due to the additional module

Engineering Contradiction:
Improveside channel attack resistanceVSAvoidpower consumption
Core Design Contradiction:
Object-affected harmful factorsVSUse of energy by moving object

Solution Approach 1:

The scrambling module is designed to use the cipher engine's own operational characteristics (clock signals, power consumption patterns) to generate its masking signals. By correlating the scrambling noise with the actual operation of the cipher engine, the system achieves effective masking using resources already present in the system, minimizing the need for additional power-consuming components

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent dynamically adjusts the parameters of the scrambling module based on the operational state of the cipher engine, such as changing the noise generation intensity or frequency characteristics according to the current cryptographic operation. This adaptive approach ensures adequate masking coverage while minimizing unnecessary power consumption during different operational phases

Inventive Principle:
Principle #35Parameter changes

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This approach significantly increases the difficulty for attackers to launch successful side channel attacks, enhancing the security of the chip by masking its power consumption and electromagnetic waves, thus preventing key cracking and improving overall security.

Implementation Method 1

the scrambling module generates power consumption and electromagnetic waves in synchronization with the cipher engine's operations, masking its normal power consumption and electromagnetic waves

Methodology Applied
Scientific EffectElectromagnetic radiation:

Data Source

PatentEP3316177B1Attack prevention method, apparatus and chip for cipher engine
Publication Date: 2021.02.03 HUAWEI TECH CO LTD
  • EP3316177B1 patent drawingFigure 1~2
  • EP3316177B1 patent drawingFigure 3~4
  • EP3316177B1 patent drawingFigure 5

AI summary

The present invention discloses an attack prevention method and apparatus for a cipher engine, and an attack prevention chip, so as to prevent a side channel attack on a chip, and improve security of the chip. The attack prevention method for a cipher engine provided in an embodiment of the present invention includes: obtaining a first running start condition configured for a cipher engine, where the cipher engine is disposed on a chip; configuring, according to the first running start condition, a second running start condition for a scrambling module disposed on the chip, where the second running start condition is used to enable the scrambling module to enter an operating state of generating power consumption and an electromagnetic wave in a process of starting, according to the first running start condition, the cipher engine to perform data encryption/decryption processing; controlling the scrambling module to start to run when the second running start condition is met, where the scrambling module generates the power consumption and the electromagnetic wave during running; and controlling the cipher engine to start when the first running start condition is met, so that the cipher engine starts to perform data encryption/decryption processing.