Substitution Block With Ones-Complement Memory For Power Analysis Resistance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Programmable logic circuits are vulnerable to power analysis attacks, which allow attackers to discover decryption keys by monitoring power consumption during decryption, compromising the security of encrypted design configurations.

Innovation Solution

Implementing a substitution block with a memory unit that stores both substitution values and their ones-complements, allowing concurrent reading and processing to maintain uniform power consumption, thereby masking key-dependent operations and resisting differential power analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional decryption is implemented in programmable logic, then decryption functionality is achieved, but power consumption varies depending on the data being processed, making the device vulnerable to power analysis attacks

Engineering Contradiction:
ImprovesecurityVSAvoidpower consumption uniformity
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent changes the operational parameters of the decryption circuit by introducing dummy operations and balancing circuits that ensure the power consumption remains constant regardless of the actual data being processed. The circuit switches between real and dummy operations based on control signals, making the power profile uniform and uninformative to attackers.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces intermediary elements such as dummy decryption circuits and balancing circuits that mediate between the actual decryption operation and the power consumption output. These intermediaries absorb or mask the variable power consumption characteristics, presenting a uniform power profile to external observers.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If decryption key is stored in nonvolatile memory, then decryption capability is maintained, but the device becomes vulnerable to attacks where attackers obtain the key through power analysis during decryption operations

Engineering Contradiction:
Improvekey securityVSAvoidpower analysis vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent converts the harmful variable power consumption into a beneficial uniform power consumption pattern. By deliberately adding dummy operations and balancing circuits, the harmful information leakage is transformed into a uniform power profile that actively protects the decryption key while maintaining normal decryption functionality.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Solution Approach 2:

The patent applies preliminary anti-action by pre-configuring dummy decryption circuits and balancing mechanisms before any actual decryption occurs. These protective measures are always in place and activated concurrently with real decryption operations, preventing power analysis attacks from gaining information about the decryption key.

Inventive Principle:
Principle #9Preliminary anti-action

3Productivity

If substitution values are read from memory during decryption, then cryptographic processing is performed, but power consumption varies with each substitution value read, leaking information about the decryption key

Engineering Contradiction:
Improvedecryption speedVSAvoidinformation leakage
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the decryption process into multiple parallel paths: one path processes the actual substitution values while another path processes dummy substitution values. By dividing the operation into separate segments that run concurrently, the power consumption of each segment becomes uniform and uninformative when observed individually or collectively.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs excessive action by executing both real and dummy substitution operations simultaneously. The dummy operations consume additional power but ensure that the total power consumption remains constant and uninformative, effectively masking the power characteristics of the necessary real substitution operations.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS8583944B1Method and integrated circuit for secure encryption and decryption
Publication Date: 2013.11.12 XILINX INC
  • US8583944B1 patent drawing
  • US8583944B1 patent drawing
  • US8583944B1 patent drawing

AI summary

In one embodiment, a circuit arrangement for performing cryptographic operations is provided. The circuit includes a substitution block, a cryptographic circuit coupled to the substitution block, and a balancing circuit coupled to the substitution block. The substitution block includes a memory unit storing substitution values and ones-complement values that are corresponding ones-complements of the substitution values. The substitution block, responsive to a request to read a specified one of the substitution values, concurrently reads and outputs the specified substitution value and the corresponding ones-complement value. A power consumed in reading the specified substitution value is uniform with a power consumed in reading another one of the substitution values. The cryptographic circuit and the balancing circuit are configured to concurrently operate on each substitution value and the corresponding ones-complement value read from the memory, respectively.