Side-Channel Protected Arithmetic Logic Unit

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cryptographic systems are vulnerable to side-channel attacks, such as differential power analysis (DPA), which can reveal sensitive information through patterns of power usage and operation timing.

Innovation Solution

A computer processing system and method that employs a multi-share system to protect against side-channel attacks. The system includes unprotected and protected hardware modules, with external and protected share inputs being processed through a multiplexor and arithmetic logic units (ALUs) to generate side-channel protected output shares.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If masking technique with data shares is used to protect against differential power analysis attacks, then security against side-channel attacks is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity against side-channel attacksVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies segmentation by dividing sensitive data into multiple shares (at least two shares) that are processed separately through protected hardware modules. Each share is isolated and processed independently, preventing attackers from analyzing power consumption patterns of the complete data. The segmentation of data into shares directly addresses the security vulnerability while the modular protected hardware module structure manages the resulting complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces protected hardware modules as intermediary components between the unprotected external environment and the sensitive cryptographic operations. These modules act as mediators that perform computations on shared data while protecting against power analysis attacks. The multiplexor serves as an intermediary that selectively routes either external share inputs or protected share inputs to the internal configurable hardware module, adding controlled complexity to achieve security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple shares are used in masking to enhance resilience against DPA attacks, then security effectiveness increases, but processing time increases

Engineering Contradiction:
Improveresilience against DPA attacksVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-processing external share inputs through protected hardware modules before they enter the main cryptographic computation. The multiplexor is configured to selectively transmit processed shares in advance, and the protected arithmetic logic unit performs preliminary computations on isolated shares. This preliminary processing on separated shares reduces the overall processing time compared to handling complete unshared data, while maintaining security.

Inventive Principle:
Principle #10Preliminary action

3Loss of information

If data is dispersed across multiple shares for masking, then information leakage is reduced, but computational overhead increases

Engineering Contradiction:
Improveinformation leakageVSAvoidcomputational overhead
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent applies merging by combining multiple processed share outputs from protected hardware modules into a final cryptographic result. The multiplexor merges selected share inputs, and the protected arithmetic logic unit combines isolated share computations. This merging of separated share processing paths achieves the security benefit of data dispersion while reducing computational overhead through efficient combination of intermediate results.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS12204643B1Computer processing system and method configured to perform side-channel countermeasures
Publication Date: 2025.01.21 PQSECURE TECHNOLOGIES LLC
  • US12204643B1 patent drawing
  • US12204643B1 patent drawing
  • US12204643B1 patent drawing

AI summary

This invention presents a computer processing system and method designed to execute cryptographic operations while providing selective protection against side-channel attacks. It comprises a configuration of unprotected and protected hardware modules, the latter of which is equipped with data isolators, and a protected arithmetic logic unit (ALU) for secure data processing. The system enhances cryptographic security by selectively transmitting and computing input shares to generate side-channel protected output shares, ensuring robust protection during cryptographic operations.