Switchable Current Sources for Side-Channel Attack Countermeasures
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current countermeasures against hardware side-channel attacks are algorithm-specific, require significant silicon-area and power overheads, and suffer from performance degradation, making them unsuitable for scalable protection against differential power analysis (DPA) in cryptographic operations, especially with the threat of quantum computing.
Innovation Solution
A generic, scalable countermeasure that integrates active Signal-to-Noise Ratio (SNR) reduction hardware with existing crypto cores, utilizing switchable current sources and capacitive elements to suppress power consumption variations, thereby isolating crypto cores from external power measurements and reducing electromagnetic emissions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional DPA protection technologies are implemented, then security against side-channel attacks is improved, but silicon-area overhead increases by at least 2x
Solution Approach 1:
The patent applies universality by creating a generic protection mechanism that works across multiple cryptographic algorithms and platforms. The current source circuitry provides DPA protection without being algorithm-specific, allowing the same hardware structure to protect various crypto operations without requiring separate protection circuits for each algorithm, thus avoiding the 2x silicon-area overhead of traditional approaches.
Solution Approach 2:
The patent introduces an intermediary current source circuit between the crypto core and the power supply. This intermediary component suppresses power consumption variations before they reach the external environment, enabling security protection without requiring extensive modifications to the crypto core itself or adding large amounts of protection hardware.
2Reliability
If traditional DPA protection technologies are implemented, then security against side-channel attacks is improved, but power overhead increases by at least 2x
Solution Approach 1:
The protection mechanism is designed to be universally applicable across different cryptographic operations and platforms. By using a generic current source circuitry that operates independently of specific algorithms, the system achieves security protection without requiring additional power consumption for algorithm-specific protection mechanisms, thereby avoiding the 2x power overhead.
Solution Approach 2:
The current source circuitry operates autonomously to suppress power variations without requiring external intervention or complex control mechanisms. The circuit automatically adjusts current delivery based on the crypto core's operational state, providing protection while minimizing additional power overhead compared to traditional protection methods.
3Reliability
If traditional DPA protection technologies are implemented, then security against side-channel attacks is improved, but performance degradation occurs
Solution Approach 1:
The current source circuit acts as an intermediary that decouples the security protection function from the cryptographic operations. By injecting current at the power supply stage rather than within the crypto core, the system provides DPA protection without interfering with crypto operation speed or requiring performance-adjusting mechanisms, thus avoiding performance degradation.
Solution Approach 2:
The patent segments the protection function from the computation function by placing current source circuitry at the power supply interface rather than integrating it within the crypto core. This segmentation allows secure power delivery without constraining the computational performance of the cryptographic operations, eliminating the trade-off between security and performance.
4Reliability
If algorithm-specific protection measures are used, then security for specific algorithms is improved, but scalability across different cryptographic modules is reduced
Solution Approach 1:
The patent implements universality by designing a protection mechanism that is independent of specific cryptographic algorithms. The current source circuitry provides generic DPA protection that can be applied to any crypto module regardless of the underlying algorithm, enabling seamless scalability across different cryptographic implementations without requiring algorithm-specific protection designs.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
This solution provides negligible silicon-area and power overheads, achieving 350x peak-to-peak current signal suppression, effectively protecting against DPA and other side-channel attacks without affecting crypto operation performance, and is applicable across various cryptographic algorithms.
Implementation Method 1
a capacitive element to support current levels
Implementation Method 2
utilizing switchable current sources and capacitive elements to suppress power consumption variations
Data Source
Figure 1A~1B
Figure 2A
Figure 2B
AI summary
Embodiments are directed to countermeasures against hardware side-channel attacks on cryptographic operations. An embodiment of an apparatus includes multiple crypto cores; and a current source including multiple current source blocks, the current source blocks including a respective current source block associated with each of the crypto cores, and wherein the current sources blocks are switchable to switch on a current source block associated with each active core of the multiple crypto cores and to switch off a current source associated with each inactive core of the multiple cryptographic cores.