Unified Data Processing Device for Secure Secret Data Handling
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data processing devices face challenges in implementing dummy calculations to protect against attacks, as they need to mimic real operations and storing dummy operation results introduces memory overhead, making it difficult to efficiently differentiate between real and dummy operations.
Innovation Solution
A data processing device that splits data words into shares, processes them in parallel using logic circuits, and uses remasking circuits to refresh shares, with an output circuit storing results based on a control sequence specifying real or dummy operations, allowing dummy operations to be indistinguishable from real ones in terms of memory access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If dummy calculations are introduced to protect against attacks, then security against fault attacks and side-channel analysis is improved, but device complexity and memory overhead increase due to needing separate dummy memory and additional control logic
Solution Approach 1:
The patent merges dummy operations and real operations into a single unified processing path. The same logic circuit processes both dummy and real data words through shared logic resources, eliminating the need for separate dummy memory and reducing device complexity while maintaining security against fault attacks and side-channel analysis
2Reliability
If dummy calculations are introduced to protect against attacks, then security against fault attacks and side-channel analysis is improved, but memory overhead increases due to storing dummy operation results
Solution Approach 1:
The patent merges the storage of dummy operation results with the storage of real operation results by using the same memory resources. The output circuit stores results in shared memory based on a control sequence, eliminating the need for separate dummy memory and reducing memory overhead while maintaining security
Solution Approach 2:
The memory resources are designed to serve multiple functions: storing both dummy and real operation results. The same memory circuitry is used for both purposes, with the output circuit dynamically selecting what to store based on the control sequence, thereby eliminating dedicated dummy memory and reducing overall memory overhead
3Reliability
If dummy operations are made indistinguishable from real operations, then security against side-channel analysis is improved, but difficulty in detecting faults in dummy operations increases
Solution Approach 1:
The patent incorporates feedback mechanisms where the output circuit monitors and verifies operations based on a control sequence. This feedback system allows the detection of faults in dummy operations while maintaining their indistinguishability from real operations, as the verification is performed through the same processing path without revealing whether an operation was dummy or real
Data Source
AI summary
According to various embodiments, a data processing device is described comprising a memory configured to store data words in the form of at least two respective shares, a logic circuit configured to receive the at least two shares of at least one of the data words and to process the shares to generate at least two shares of a result data word, a remasking circuit configured to receive at least two shares of at least one of the data words and refresh the shares and an output circuit configured to store the at least two shares of the result data word or to store the refreshed at least two shares depending on a control sequence specifying a sequence of real operations and dummy operations.


