Secret Key Update Mechanism for Side-Channel Attack Mitigation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing information processing devices face challenges in effectively mitigating side-channel attacks without increasing hardware scale, particularly in systems like vehicle-mounted systems where frequent secret key updates are difficult to implement.
Innovation Solution
An information processing device with a storage unit for nonvolatile storage of a master secret key and order comparison information, and an update unit that compares request order information to authorize and update the secret key, performing decryption processing only once per update request to reduce the feasibility of side-channel attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If frequent secret key updates are implemented to counter side-channel attacks, then security against side-channel attacks is improved, but device complexity and operational difficulty increase
Solution Approach 1:
The patent applies preliminary action by pre-storing order comparison information in nonvolatile memory before the actual key update operation. This allows the system to verify the legitimacy of update requests based on pre-established order information, eliminating the need for complex real-time verification mechanisms during key updates.
Solution Approach 2:
The patent introduces order comparison information as an intermediary element between the key management system and the encryption processing system. This intermediary stores update order sequences and enables verification without requiring frequent or complex key updates, thus simplifying the overall system operation while maintaining security.
2Reliability
If multiple decryption processing are performed for each update request to ensure security, then security against side-channel attacks is improved, but throughput overhead increases
Solution Approach 1:
The patent applies partial action by performing decryption processing only once per update request, rather than multiple times. The system uses order comparison information to verify security, so a single decryption operation suffices to obtain the new key while maintaining security against side-channel attacks, thereby reducing throughput overhead.
3Reliability
If advanced side-channel attack countermeasures are implemented, then security is improved, but hardware scale increases
Solution Approach 1:
The patent replaces complex hardware-based side-channel attack countermeasures with a software-based key management mechanism. By using nonvolatile memory to store order comparison information and implementing verified key updates through software control, the system achieves security without requiring increased hardware scale or complex physical countermeasures.
Data Source
AI summary
An information processing device updates its own secret key according to an update request including request order information, the information processing device being provided with: a storage unit that stores, in a nonvolatile manner, a master secret key, a secret key, and order comparison information that enables comparison of the request order of the update request; and an update unit that, in a case where the update request has been made, compares the request order information and the order comparison information, and in a case where it has been determined that the order of the update request is authorized, updates the order comparison information to information corresponding to the request order information before update processing of the secret key is performed by using the master secret key.


