Side-Channel Secure Cryptographic Apparatus Using Precomputed Lookup Tables
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for preventing side-channel attacks are inadequate, as they either fail to secure against all types of attacks or result in performance degradation and time delays during digital signature generation.
Innovation Solution
An apparatus and method that generate seed values, divide them into blocks, extract parameter values, and use these to create random numbers through exponentiation or scalar multiplication operations, enabling secure encryption and digital signature generation without direct exposure to physical information leakage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If related art methods for preventing side-channel attacks are applied, then security against side-channel attacks is improved, but computation time and processing speed deteriorate due to large amount of computation required
Solution Approach 1:
The patent applies preliminary action by pre-computing and storing exponentiation results in a lookup table during an offline phase. When a digital signature needs to be generated, the system retrieves pre-computed values from the table rather than performing real-time exponentiation operations. This shifts the computational burden to a preliminary stage, significantly reducing the time required during actual signature generation while maintaining security against side-channel attacks.
2Reliability
If exponentiation operations are performed for each bit in the exponent value, then cryptographic security is maintained, but power consumption increases and leaks information through side-channel attacks
Solution Approach 1:
The patent performs exponentiation operations in advance and stores the results in a lookup table. During actual cryptographic operations, pre-computed values are retrieved instead of performing new exponentiation. This eliminates real-time power consumption patterns that would otherwise leak information about the exponent bits, while cryptographic security is maintained through the use of pre-computed secure values.
Solution Approach 2:
The patent creates copies of exponentiation results and stores them in a lookup table. Instead of performing the same expensive exponentiation operation multiple times with different inputs, the system retrieves pre-computed copies from the table. This reduces power consumption during actual operations while maintaining the cryptographic properties of the original computations.
3Reliability
If related art side-channel protection methods are applied, then some side-channel attacks are prevented, but device complexity increases and performance degrades
Solution Approach 1:
The patent creates a lookup table that serves multiple cryptographic functions simultaneously. The same pre-computed exponentiation values can be used for different cryptographic operations and protocols. This multi-functional approach reduces device complexity compared to implementing separate protection mechanisms for each cryptographic operation, as a single lookup table provides universal protection against side-channel attacks across various operations.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
An apparatus (100) and method for performing operation being secure against side channel attack are provided. The apparatus and method generate values equal to values obtained through an exponentiation operation or a scalar multiplication operation of a point using values extracted from previously generated parameter candidate value sets and an operation secure against side-channel attack, thereby improving security against side-channel attack without degrading performance.