Secure Comparison Processing via Dynamic Parameter Masking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing secure comparison processing methods are vulnerable to 'side channel' attacks, such as electromagnetic leaks and power consumption variations, which can reveal secret data during authentication processes like PIN code verification, and previous solutions are either difficult to implement or easily detectable by attackers.

Innovation Solution

A secure comparative processing method where a processor executes parallel complementary operations on test data, adjusting execution parameters based on the input data, ensuring that variations in behavior are masked and indistinguishable from the comparison process, using a series of predefined basic operations repeated a specific number of times with varying execution parameters.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If symmetrical programs are implemented to minimize behavior differences during comparison, then security against side channel attacks is improved, but program complexity and difficulty of implementation increase significantly

Engineering Contradiction:
Improvesecurity against side channel attacksVSAvoidprogram complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies dynamics by making the execution parameters (number of iterations, operation sequences) variable rather than fixed. The program dynamically adjusts the number of comparative operations and complementary operations based on the comparison result, allowing asymmetric execution paths that still produce symmetric power consumption profiles. This resolves the contradiction by enabling security without requiring entirely symmetrical program structures.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes parameters such as the number of iterations, operation sequences, and timing characteristics to control power consumption patterns. By carefully selecting and adjusting these parameters, the system ensures that both successful and unsuccessful comparison paths consume similar amounts of power, achieving security without the need for complex symmetrical programming structures.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If random execution periods are generated during comparison or thereafter, then security against side channel attacks is improved, but the solution becomes easily detectable by attackers and imposes additional delays

Engineering Contradiction:
Improvesecurity against side channel attacksVSAvoidauthentication delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent uses periodic action by executing sequences of comparative operations and complementary operations in repeated cycles. The number of iterations is controlled to ensure that both successful and unsuccessful comparisons take approximately the same time, avoiding detectable delays while maintaining security. This structured periodic approach prevents timing attacks without requiring arbitrary random delays.

Inventive Principle:
Principle #19Periodic action

3Reliability

If multiple operations are executed in parallel during comparison, then resistance to side channel attacks is improved, but calculation overhead increases

Engineering Contradiction:
Improveresistance to side channel attacksVSAvoidcalculation overhead
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the comparison process into distinct phases: comparative operations phase and complementary operations phase. Each phase is executed in a controlled manner with specific iteration counts. This segmentation allows the system to achieve security through structured parallel execution without excessive overhead, as each segment serves a specific purpose and can be optimized independently.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The complementary operations serve multiple functions: they mask the comparison result, consume additional power in a controlled manner, and ensure that both successful and unsuccessful paths have similar execution characteristics. This multi-functionality reduces the need for separate security mechanisms, thereby reducing overall calculation overhead while maintaining security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10521586B2Secured comparative processing method
Publication Date: 2019.12.31 IDEMIA FRANCE SAS
  • US10521586B2 patent drawing
  • US10521586B2 patent drawing

AI summary

The invention relates to a secured comparative processing method of the type in which a processor of an electronic component compares a set of proof data received by the processor as an input with main secret data stored in said electronic component, characterised in that the processor executes, in parallel with the comparison with the secret data, a series of complementary operations on the set of proof data which generate on the electronic component a variation in behaviour which is a function of the proof data which the component receives as an input and which is added to the variation in behaviour linked to the comparison with the main secret data, the series of complementary operations including a series of base operations repeated K times, and the execution of said series being preceded by an adjustment of execution parameters of said series, the parameters including: the identifier of the series of base operations to be executed, the series of base operations being comprised within a set of predefined base operations, and the number K of executions of the set of base operations, the set of adjusted execution parameters being specific to the set of proof data received by the electronic component.