Semiconductor Block Encryption for Side-Channel Resistance
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional techniques for improving tamper resistance against side-channel attacks in semiconductor devices increase operation time and are susceptible to power consumption analysis.
Innovation Solution
A semiconductor device that divides data into multiple pieces, applies specific processes like AddRoundKey to some of these pieces, and retains them differently across blocks to vary side-channel information, enhancing tamper resistance without increasing operation time.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If masking is applied to AES encryption to improve tamper resistance against side-channel attacks, then security is improved, but preprocessing is required which increases operation time
Solution Approach 1:
The data is divided into multiple pieces (first divisional data, second divisional data, etc.) and stored in different blocks. Different specific processes (e.g., AddRoundKey) are applied to different pieces, creating segmentation in both data structure and processing. This eliminates the need for preprocessing masking while maintaining security by ensuring that side-channel information varies across blocks.
Solution Approach 2:
The patent applies specific processes (such as AddRoundKey) to divisional data in advance before the main encryption operation. This preliminary action modifies the data in such a way that side-channel information becomes unpredictable, providing security without requiring separate preprocessing masking steps.
2Reliability
If conventional masking techniques are used to conceal power consumption, then side-channel attack resistance is improved, but the correlation between intermediate values and side-channel information can still be extracted through average waveform analysis
Solution Approach 1:
Different blocks of data are processed with different specific processes applied to different pieces of divisional data. This creates local variations in side-channel information across blocks, making it impossible to extract meaningful correlations through average waveform analysis. Each block has unique local characteristics that prevent global pattern recognition.
Solution Approach 2:
The patent introduces asymmetry by applying different treatments to different pieces of divisional data stored in different blocks. Instead of uniform masking, asymmetric processing ensures that side-channel information from different blocks cannot be combined or averaged to reveal secrets, as each block follows a different processing pattern.
3Reliability
If data is divided and different processes are applied to different pieces to vary side-channel information, then tamper resistance is improved, but device complexity increases
Solution Approach 1:
The division of data into pieces and their storage in different blocks provides a natural framework for applying different processes. This segmentation approach manages complexity by organizing the system into discrete, manageable units that can be processed independently, making the overall complex process more controllable and implementable.
Data Source
AI summary
In order to further improve tamper resistance to a side-channel attack while suppressing an increase in operation time in a semiconductor device, a semiconductor device includes: a dividing section configured to divide data into two or more pieces of divisional data; a block encryption executing section configured to apply, to only one or some of the two or more pieces of divisional data, a specific process included in a block encryption algorithm; and a data retaining section configured to retain, in respective blocks, the two or more pieces of divisional data to only one or some of which the specific process has been applied, so that pieces of side-channel information radiated differ from each other between at least some of the blocks.


