Secret Value Estimation via Multivariate Leakage Statistical Modeling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cryptographic systems are vulnerable to side-channel attacks, particularly those involving multivariate leakages and parametric models, where current estimation techniques are suboptimal and fail to effectively recover secret values, compromising security.

Innovation Solution

A secret value estimation device and method that determine estimates of secret values from multivariate leakage traces using a statistical distribution represented by parametric linear combinations of leakage model basis vectors, with a processing unit implementing an expectation maximization algorithm to jointly estimate unknown coefficients and secret keys, optimizing signal-to-noise ratio and security performance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If constant time execution and constant program flow techniques are used to counter side-channel attacks, then security against side-channel attacks is improved, but hardware resource consumption increases and practical implementation becomes infeasible

Engineering Contradiction:
Improvesecurity against side-channel attacksVSAvoidhardware resource consumption
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a statistical model as an intermediary between the cryptographic mechanism and the attacker. Instead of relying on constant time execution, the system uses a probabilistic leakage model to characterize side-channel information, allowing security analysis without modifying the actual execution timing or control flow of the cryptographic algorithm.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical approach of constant time execution with a statistical modeling approach. Rather than controlling physical execution characteristics, the system uses mathematical models to represent and analyze leakage traces, substituting physical constraint-based security with information-theoretic security through statistical characterization.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If randomization techniques such as secret splitting or masking schemes are used, then protection against single-instant physical leaked information is improved, but vulnerability to multiple leaked information attacks increases

Engineering Contradiction:
Improveprotection against single-instant leakageVSAvoidvulnerability to multi-instant attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent transitions from analyzing single-instant leakage to multi-instant leakage by adding the time dimension to the statistical model. The leakage model now characterizes traces across multiple time instants, allowing the system to detect and protect against attacks that exploit correlations between multiple leakage measurements rather than relying on single-instant randomization.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The patent implements a feedback mechanism where the statistical model continuously refines its characterization of leakage based on observed traces. The model adapts to the specific attack patterns and leakage characteristics, allowing the system to learn from multiple instances and improve its security assessment over time, thereby countering attacks that exploit repeated leakage patterns.

Inventive Principle:
Principle #23Feedback

3Productivity

If existing estimation techniques are used for multivariate leakages, then processing speed is maintained, but accuracy of secret value recovery deteriorates

Engineering Contradiction:
Improveprocessing speedVSAvoidaccuracy of secret value recovery
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The patent changes the parameters of the statistical model to accurately capture multivariate leakage characteristics. By adjusting the model to account for correlations between multiple leakage traces and incorporating parametric models with unknown parameters, the system improves the accuracy of secret value recovery while maintaining efficient processing through optimized estimation algorithms.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11210367B2Methods and devices for estimating secret values
Publication Date: 2021.12.28 INSTITUT MINES TELECOM TELECOM BRETAGNE
  • US11210367B2 patent drawing
  • US11210367B2 patent drawing
  • US11210367B2 patent drawing

AI summary

A secret value estimation device is provided for determining an estimate of at least one secret value used by at least one cryptographic mechanism implemented in a cryptographic system from a statistical distribution of a set of multivariate leakage traces determined by a leakage traces statistical distribution unit. Each leakage trace being a vector comprises a plurality of random values, the number of said random values being an integer number superior or equal to 1, the statistical distribution being a function of parametric linear combinations of a set of leakage model basis vectors representing a multivariate leakage model, the number of basis vectors being an integer number superior or equal to 1, and the linear combinations being defined by a matrix of real values.