Security Processor Remainder Calculation Random Operand

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security processors face challenges in effectively preventing side channel attacks (SCAs) while minimizing power consumption and performance overhead, as existing defense techniques may not provide adequate protection against template attacks and power analysis attacks, and can result in increased circuit area and power consumption.

Innovation Solution

A security processor is designed with a random number generator and a modular calculator that generates a random operand by adding a random number to the input data, performing a remainder operation, which obscures the relationship between input data and leaked information, thereby reducing the risk of side channel attacks without significantly increasing power usage or chip area.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If defense techniques such as masking or hiding side channel information are implemented, then security against SCA is improved, but circuit area and power consumption increase

Engineering Contradiction:
Improvesecurity against side channel attackVSAvoidpower consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent changes the operational parameters by introducing random values dynamically during cryptographic operations. The random operand generator modifies the input operands by adding random values, and the random delay controller introduces variable timing delays. These parameter changes ensure that each operation consumes power in a randomized pattern, preventing attackers from correlating power consumption patterns with secret data while avoiding the need for extensive additional circuitry.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent implements dynamic behavior through the random operand generator and random delay controller. Instead of static masking schemes, the system dynamically generates random values during operation execution. The random delays are applied selectively based on operation types and secret data values, creating a dynamic power consumption profile that adapts to prevent template attacks without continuously operating at maximum power.

Inventive Principle:
Principle #15Dynamics

2Reliability

If defense techniques such as masking or hiding side channel information are implemented, then security against SCA is improved, but circuit area increases

Engineering Contradiction:
Improvesecurity against side channel attackVSAvoidcircuit area
Core Design Contradiction:
ReliabilityVSArea of stationary object

Solution Approach 1:

The patent achieves multi-functionality by integrating the random operand generation and random delay control within the existing cryptographic processor architecture. The random operand generator can serve multiple cryptographic operations (AES, DES, RSA, ECC), and the random delay controller manages timing for various operation types. This universal approach provides comprehensive SCA protection without requiring separate dedicated circuits for each cryptographic algorithm.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces intermediary components (random operand generator and random delay controller) that mediate between the input data and the cryptographic processing units. These intermediaries randomize the operational parameters without requiring fundamental changes to the core cryptographic algorithms, allowing existing secure computational logic to be protected against SCA with minimal additional circuit area.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If traditional remainder calculation is performed, then computational efficiency is maintained, but vulnerability to template attacks increases

Engineering Contradiction:
Improvecomputational efficiencyVSAvoidvulnerability to template attack
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies preliminary anti-action by randomizing the operands before they enter the remainder calculation operation. The random operand generator adds random values to the input operands prior to the division operation, and the random delay controller introduces timing variations. This preliminary randomization prevents attackers from establishing accurate templates of power consumption patterns for traditional remainder calculations, while the actual remainder operation itself remains efficient.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS11392725B2Security processor performing remainder calculation by using random number and operating method of the security processor
Publication Date: 2022.07.19 SAMSUNG ELECTRONICS CO LTD
  • US11392725B2 patent drawing
  • US11392725B2 patent drawing
  • US11392725B2 patent drawing

AI summary

Provided are a security processor for performing a remainder operation by using a random number and an operating method of the security processor. The security processor includes a random number generator configured to generate a first random number; a modular calculator configured to generate a first random operand based on first data and the first random number and generate output data through a remainder operation on the first random operand, wherein a result value of the remainder operation on the first input data is identical to a result value of the remainder operation on the first random operand.