Side-Channel Protected Arithmetic Logic Unit
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cryptographic systems are vulnerable to side-channel attacks, such as differential power analysis (DPA), which can reveal sensitive information through patterns of power usage and operation timing.
Innovation Solution
A computer processing system and method that employs a multi-share system to protect against side-channel attacks. The system includes unprotected and protected hardware modules, with external and protected share inputs being processed through a multiplexor and arithmetic logic units (ALUs) to generate side-channel protected output shares.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If masking technique with data shares is used to protect against differential power analysis attacks, then security against side-channel attacks is improved, but device complexity increases
Solution Approach 1:
The patent applies segmentation by dividing sensitive data into multiple shares (at least two shares) that are processed separately through protected hardware modules. Each share is isolated and processed independently, preventing attackers from analyzing power consumption patterns of the complete data. The segmentation of data into shares directly addresses the security vulnerability while the modular protected hardware module structure manages the resulting complexity.
Solution Approach 2:
The patent introduces protected hardware modules as intermediary components between the unprotected external environment and the sensitive cryptographic operations. These modules act as mediators that perform computations on shared data while protecting against power analysis attacks. The multiplexor serves as an intermediary that selectively routes either external share inputs or protected share inputs to the internal configurable hardware module, adding controlled complexity to achieve security.
2Reliability
If multiple shares are used in masking to enhance resilience against DPA attacks, then security effectiveness increases, but processing time increases
Solution Approach 1:
The patent applies preliminary action by pre-processing external share inputs through protected hardware modules before they enter the main cryptographic computation. The multiplexor is configured to selectively transmit processed shares in advance, and the protected arithmetic logic unit performs preliminary computations on isolated shares. This preliminary processing on separated shares reduces the overall processing time compared to handling complete unshared data, while maintaining security.
3Loss of information
If data is dispersed across multiple shares for masking, then information leakage is reduced, but computational overhead increases
Solution Approach 1:
The patent applies merging by combining multiple processed share outputs from protected hardware modules into a final cryptographic result. The multiplexor merges selected share inputs, and the protected arithmetic logic unit combines isolated share computations. This merging of separated share processing paths achieves the security benefit of data dispersion while reducing computational overhead through efficient combination of intermediate results.
Data Source
AI summary
This invention presents a computer processing system and method designed to execute cryptographic operations while providing selective protection against side-channel attacks. It comprises a configuration of unprotected and protected hardware modules, the latter of which is equipped with data isolators, and a protected arithmetic logic unit (ALU) for secure data processing. The system enhances cryptographic security by selectively transmitting and computing input shares to generate side-channel protected output shares, ensuring robust protection during cryptographic operations.


