Secure Processing Device Concealing Signature Keys via Dynamic Equation Selection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for generating RSA signatures are vulnerable to static and dynamic analysis, as the signature key generation equation remains fixed and split keys are consistently used, making it possible to specify the signature key.
Innovation Solution
A secure processing device that generates and executes a second secure operation procedure, using combined information and random number information, to conceal the confidential information, making it difficult to specify the signature key through static or dynamic analysis.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the signature key generation equation is permanently fixed and the same split keys are used, then the signature generation is simple and efficient, but the signature key can be specified by performing static analysis or dynamic analysis
Solution Approach 1:
The patent applies dynamics by making the signature key generation equation and split keys changeable rather than fixed. The control unit dynamically selects different signature key generation equations from a storage unit and generates different split keys for each signature generation operation, preventing unauthorized specification through analysis while maintaining operational simplicity.
Solution Approach 2:
The patent changes parameters by varying the signature key generation equations and split keys. The control unit changes the parameters (equations and keys) for each signature generation, making it impossible for unauthorized analysts to specify the signature key through static or dynamic analysis, thus improving security without significantly increasing complexity.
2Reliability
If different signature key generation equations and split keys are used each time, then the signature key cannot be specified through analysis, but the signature generation process becomes more complex
Solution Approach 1:
The system applies self-service by having the control unit automatically select signature key generation equations and generate split keys without external intervention. The storage unit stores multiple equations, and the control unit autonomously manages the selection and generation process, maintaining ease of operation while improving security against unauthorized analysis.
Solution Approach 2:
The patent applies preliminary action by pre-storing multiple signature key generation equations in the storage unit before signature generation begins. This preparation allows the control unit to quickly select and use different equations during operation, maintaining ease of use while preventing unauthorized specification through analysis.
3Productivity
If the signature key d is stored in memory or register, then the signature generation is efficient, but the signature key is at risk of being acquired in an unauthorized manner
Solution Approach 1:
The patent applies segmentation by dividing the signature key d into multiple split keys (d1, d2, d3) that are stored separately in memory or registers. The control unit combines these split keys using selected signature key generation equations to perform signature generation, maintaining efficiency while preventing unauthorized acquisition since individual split keys cannot reveal the complete signature key.
Data Source
AI summary
When performing secure processing using confidential information that needs to be confidential, the secure processing device according to the present invention prevents the confidential information from being exposed by an unauthorized analysis such as a memory dump. A signature generation device that provides a message M with a signature by using a signature key comprises: a split key storage unit that stores split secret keys obtained by splitting the signature key d into at least two, a signature key generation equation F for calculating the split secret keys to obtain the signature key d, and a signature generation equation; a signature key generation identical equation generation unit that generates a signature key generation identical equation G for obtaining the same result as the signature generation equation F, with use of an associative law, a distributive law, and a commutative law; a combined split key generation unit that generates a plurality of combined split keys that are each a result of calculating the split secret keys, and that are to be arguments for the signature key generation identical equation G; and a signature generation unit that provides the message with the signature, based on the signature key generation identical equation G and the split secret keys.


