Cryptographic Substitution Table Permutation for Side Channel Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cryptographic devices are vulnerable to side channel attacks, particularly when hackers monitor power consumption or timing signals during substitution operations in cryptographic algorithms, as these operations are relatively visible and targeted by hackers.
Innovation Solution
Implementing a method where a series of substitution operations includes a real set and multiple dummy sets based on different permutations of substitution tables, with the position of the real set selected randomly, to obscure the manipulation of the secret key and create a dissymmetry in side channel leakages.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If substitution operations are performed using standard cryptographic algorithms, then the cryptographic process functions correctly, but the device becomes vulnerable to side channel attacks due to the visibility of substitution operations
Solution Approach 1:
The patent creates dummy copies of substitution operations that mimic the real operation's timing and power consumption characteristics. These dummy operations use permuted substitution tables and random positioning to generate identical side channel signatures without revealing the actual secret key, thereby protecting against side channel attacks while maintaining cryptographic functionality
Solution Approach 2:
The patent introduces an intermediary layer of dummy substitution operations between the real cryptographic operation and the external observer. This intermediary layer absorbs the side channel information leakage by generating similar power consumption and timing patterns, preventing direct correlation between observed signals and the actual secret key
2Reliability
If dummy substitution operations are added to protect against side channel attacks, then security against side channel attacks improves, but the complexity of the cryptographic circuit increases
Solution Approach 1:
The patent designs a universal substitution operation module that can perform both real cryptographic substitutions and dummy protective substitutions using the same hardware circuitry. The module uses controllable multiplexers and random position selection to dynamically switch between real and dummy operations, eliminating the need for separate dedicated circuits for each type of operation and thereby reducing overall complexity
3Difficulty of detecting and measuring
If multiple dummy sets of substitution operations are performed, then the difficulty of correlating side channel signals with key values increases, but the execution time of the cryptographic process increases
Solution Approach 1:
The patent performs a limited number of dummy substitution operation sets (typically 1-3 dummy sets per real operation) rather than excessive redundancy. This partial action provides sufficient protection to obscure the real operation's signature while minimizing the time overhead, achieving an optimal balance between security enhancement and performance maintenance
Data Source
AI summary
The disclosure concerns implementing, by a cryptographic circuit, a set of substitution operations of a cryptographic process involving a plurality of substitution tables. For each set of substitution operations of the cryptographic process, a series of sets of substitution operations are performed. One set of the series is a real set of substitution operations corresponding to the set of substitution operations of the cryptographic process. One or more other sets are dummy sets of substitution operations, each dummy set being based on a different permutation of said substitution tables.


