Substitution Block With Ones-Complement Memory For Power Analysis Resistance
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Programmable logic circuits are vulnerable to power analysis attacks, which allow attackers to discover decryption keys by monitoring power consumption during decryption, compromising the security of encrypted design configurations.
Innovation Solution
Implementing a substitution block with a memory unit that stores both substitution values and their ones-complements, allowing concurrent reading and processing to maintain uniform power consumption, thereby masking key-dependent operations and resisting differential power analysis.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional decryption is implemented in programmable logic, then decryption functionality is achieved, but power consumption varies depending on the data being processed, making the device vulnerable to power analysis attacks
Solution Approach 1:
The patent changes the operational parameters of the decryption circuit by introducing dummy operations and balancing circuits that ensure the power consumption remains constant regardless of the actual data being processed. The circuit switches between real and dummy operations based on control signals, making the power profile uniform and uninformative to attackers.
Solution Approach 2:
The patent introduces intermediary elements such as dummy decryption circuits and balancing circuits that mediate between the actual decryption operation and the power consumption output. These intermediaries absorb or mask the variable power consumption characteristics, presenting a uniform power profile to external observers.
2Reliability
If decryption key is stored in nonvolatile memory, then decryption capability is maintained, but the device becomes vulnerable to attacks where attackers obtain the key through power analysis during decryption operations
Solution Approach 1:
The patent converts the harmful variable power consumption into a beneficial uniform power consumption pattern. By deliberately adding dummy operations and balancing circuits, the harmful information leakage is transformed into a uniform power profile that actively protects the decryption key while maintaining normal decryption functionality.
Solution Approach 2:
The patent applies preliminary anti-action by pre-configuring dummy decryption circuits and balancing mechanisms before any actual decryption occurs. These protective measures are always in place and activated concurrently with real decryption operations, preventing power analysis attacks from gaining information about the decryption key.
3Productivity
If substitution values are read from memory during decryption, then cryptographic processing is performed, but power consumption varies with each substitution value read, leaking information about the decryption key
Solution Approach 1:
The patent segments the decryption process into multiple parallel paths: one path processes the actual substitution values while another path processes dummy substitution values. By dividing the operation into separate segments that run concurrently, the power consumption of each segment becomes uniform and uninformative when observed individually or collectively.
Solution Approach 2:
The patent performs excessive action by executing both real and dummy substitution operations simultaneously. The dummy operations consume additional power but ensure that the total power consumption remains constant and uninformative, effectively masking the power characteristics of the necessary real substitution operations.
Data Source
AI summary
In one embodiment, a circuit arrangement for performing cryptographic operations is provided. The circuit includes a substitution block, a cryptographic circuit coupled to the substitution block, and a balancing circuit coupled to the substitution block. The substitution block includes a memory unit storing substitution values and ones-complement values that are corresponding ones-complements of the substitution values. The substitution block, responsive to a request to read a specified one of the substitution values, concurrently reads and outputs the specified substitution value and the corresponding ones-complement value. A power consumed in reading the specified substitution value is uniform with a power consumed in reading another one of the substitution values. The cryptographic circuit and the balancing circuit are configured to concurrently operate on each substitution value and the corresponding ones-complement value read from the memory, respectively.


