Secret Key Update Mechanism for Side-Channel Attack Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing information processing devices face challenges in effectively mitigating side-channel attacks without increasing hardware scale, particularly in systems like vehicle-mounted systems where frequent secret key updates are difficult to implement.

Innovation Solution

An information processing device with a storage unit for nonvolatile storage of a master secret key and order comparison information, and an update unit that compares request order information to authorize and update the secret key, performing decryption processing only once per update request to reduce the feasibility of side-channel attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If frequent secret key updates are implemented to counter side-channel attacks, then security against side-channel attacks is improved, but device complexity and operational difficulty increase

Engineering Contradiction:
Improvesecurity against side-channel attacksVSAvoidcomplexity of key update mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-storing order comparison information in nonvolatile memory before the actual key update operation. This allows the system to verify the legitimacy of update requests based on pre-established order information, eliminating the need for complex real-time verification mechanisms during key updates.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces order comparison information as an intermediary element between the key management system and the encryption processing system. This intermediary stores update order sequences and enables verification without requiring frequent or complex key updates, thus simplifying the overall system operation while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple decryption processing are performed for each update request to ensure security, then security against side-channel attacks is improved, but throughput overhead increases

Engineering Contradiction:
Improvesecurity against side-channel attacksVSAvoidthroughput overhead
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies partial action by performing decryption processing only once per update request, rather than multiple times. The system uses order comparison information to verify security, so a single decryption operation suffices to obtain the new key while maintaining security against side-channel attacks, thereby reducing throughput overhead.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If advanced side-channel attack countermeasures are implemented, then security is improved, but hardware scale increases

Engineering Contradiction:
Improvesecurity against side-channel attacksVSAvoidhardware scale
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces complex hardware-based side-channel attack countermeasures with a software-based key management mechanism. By using nonvolatile memory to store order comparison information and implementing verified key updates through software control, the system achieves security without requiring increased hardware scale or complex physical countermeasures.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS11546148B2Information processing device, information processing system, and method for controlling information processing device including comparing request order information and order comparison information
Publication Date: 2023.01.03 KK TOSHIBA
  • US11546148B2 patent drawing
  • US11546148B2 patent drawing
  • US11546148B2 patent drawing

AI summary

An information processing device updates its own secret key according to an update request including request order information, the information processing device being provided with: a storage unit that stores, in a nonvolatile manner, a master secret key, a secret key, and order comparison information that enables comparison of the request order of the update request; and an update unit that, in a case where the update request has been made, compares the request order information and the order comparison information, and in a case where it has been determined that the order of the update request is authorized, updates the order comparison information to information corresponding to the request order information before update processing of the secret key is performed by using the master secret key.