Security Variable Scrambling for Side-Channel Attack Mitigation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for securing programmable logic devices against side-channel attacks are ineffective, as attackers can still determine the decryption key using statistical analysis of side-channel information such as power-supply fluctuations or electromagnetic emanations, despite encryption techniques like AES and challenge vector combinations.
Innovation Solution
The solution involves scrambling a critical variable with a challenge vector element, then further scrambling it with another element, limiting the number of challenge vectors it can be combined with, thereby hindering successful statistical side-channel analysis attacks by restricting the number of measurements an attacker can obtain.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If encryption techniques like AES and challenge vector combinations are used to secure programmable logic devices, then the confidentiality of configuration data is improved, but the device remains vulnerable to side-channel attacks where attackers can determine the decryption key using statistical analysis of power-supply fluctuations or electromagnetic emanations
Solution Approach 1:
The critical variable is segmented into multiple elements that are combined with challenge vectors in a limited sequence. Instead of allowing the critical variable to be combined with multiple different challenge vectors simultaneously, the patent divides the combination process into discrete segments where each element is combined sequentially, limiting the attacker's ability to perform statistical analysis across multiple combinations.
Solution Approach 2:
The patent introduces dynamic scrambling where the critical variable is repeatedly scrambled with elements of a challenge vector in a changing sequence. This dynamic process ensures that the same critical variable appears in different scrambled forms across different challenge vector combinations, making statistical analysis ineffective while maintaining encryption functionality.
2Reliability
If the critical variable is combined with multiple different challenge vectors to enhance security, then the encryption strength is improved, but the number of measurable side-channel signals increases, enabling successful statistical analysis attacks
Solution Approach 1:
The patent changes the parameters of the critical variable by scrambling it with different elements of the challenge vector. This parameter transformation ensures that the critical variable's effective value changes dynamically based on the challenge vector element being processed, thereby altering the side-channel signal characteristics and preventing attackers from correlating signals across multiple challenge vector combinations to recover the key.
3Loss of information
If proprietary configuration data is protected through encryption, then the confidentiality of intellectual property cores is improved, but side-channel measurements can still be used to mount active or passive attacks to determine the decryption key
Solution Approach 1:
The patent introduces scrambled versions of the critical variable as intermediaries between the original decryption key and the encryption/decryption process. These scrambled intermediaries are derived by combining the critical variable with challenge vector elements, and they perform the actual encryption operations. This intermediary layer obscures the relationship between the original key and the side-channel signals, making key extraction through statistical analysis significantly more difficult.
Data Source
AI summary
Methods and systems are provided for securing an integrated circuit device against various security attacks, such as side-channel attacks. By limiting the number of different challenge vectors that can be combined with a critical variable of an encryption operation, it becomes more difficult to create enough side channel measurements to successfully perform statistical side-channel analysis.


