Secret Value Estimation via Multivariate Leakage Statistical Modeling
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cryptographic systems are vulnerable to side-channel attacks, particularly those involving multivariate leakages and parametric models, where current estimation techniques are suboptimal and fail to effectively recover secret values, compromising security.
Innovation Solution
A secret value estimation device and method that determine estimates of secret values from multivariate leakage traces using a statistical distribution represented by parametric linear combinations of leakage model basis vectors, with a processing unit implementing an expectation maximization algorithm to jointly estimate unknown coefficients and secret keys, optimizing signal-to-noise ratio and security performance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If constant time execution and constant program flow techniques are used to counter side-channel attacks, then security against side-channel attacks is improved, but hardware resource consumption increases and practical implementation becomes infeasible
Solution Approach 1:
The patent introduces a statistical model as an intermediary between the cryptographic mechanism and the attacker. Instead of relying on constant time execution, the system uses a probabilistic leakage model to characterize side-channel information, allowing security analysis without modifying the actual execution timing or control flow of the cryptographic algorithm.
Solution Approach 2:
The patent replaces the mechanical approach of constant time execution with a statistical modeling approach. Rather than controlling physical execution characteristics, the system uses mathematical models to represent and analyze leakage traces, substituting physical constraint-based security with information-theoretic security through statistical characterization.
2Reliability
If randomization techniques such as secret splitting or masking schemes are used, then protection against single-instant physical leaked information is improved, but vulnerability to multiple leaked information attacks increases
Solution Approach 1:
The patent transitions from analyzing single-instant leakage to multi-instant leakage by adding the time dimension to the statistical model. The leakage model now characterizes traces across multiple time instants, allowing the system to detect and protect against attacks that exploit correlations between multiple leakage measurements rather than relying on single-instant randomization.
Solution Approach 2:
The patent implements a feedback mechanism where the statistical model continuously refines its characterization of leakage based on observed traces. The model adapts to the specific attack patterns and leakage characteristics, allowing the system to learn from multiple instances and improve its security assessment over time, thereby countering attacks that exploit repeated leakage patterns.
3Productivity
If existing estimation techniques are used for multivariate leakages, then processing speed is maintained, but accuracy of secret value recovery deteriorates
Solution Approach 1:
The patent changes the parameters of the statistical model to accurately capture multivariate leakage characteristics. By adjusting the model to account for correlations between multiple leakage traces and incorporating parametric models with unknown parameters, the system improves the accuracy of secret value recovery while maintaining efficient processing through optimized estimation algorithms.
Data Source
AI summary
A secret value estimation device is provided for determining an estimate of at least one secret value used by at least one cryptographic mechanism implemented in a cryptographic system from a statistical distribution of a set of multivariate leakage traces determined by a leakage traces statistical distribution unit. Each leakage trace being a vector comprises a plurality of random values, the number of said random values being an integer number superior or equal to 1, the statistical distribution being a function of parametric linear combinations of a set of leakage model basis vectors representing a multivariate leakage model, the number of basis vectors being an integer number superior or equal to 1, and the linear combinations being defined by a matrix of real values.


