Unified Data Processing Device for Secure Secret Data Handling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data processing devices face challenges in implementing dummy calculations to protect against attacks, as they need to mimic real operations and storing dummy operation results introduces memory overhead, making it difficult to efficiently differentiate between real and dummy operations.

Innovation Solution

A data processing device that splits data words into shares, processes them in parallel using logic circuits, and uses remasking circuits to refresh shares, with an output circuit storing results based on a control sequence specifying real or dummy operations, allowing dummy operations to be indistinguishable from real ones in terms of memory access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If dummy calculations are introduced to protect against attacks, then security against fault attacks and side-channel analysis is improved, but device complexity and memory overhead increase due to needing separate dummy memory and additional control logic

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges dummy operations and real operations into a single unified processing path. The same logic circuit processes both dummy and real data words through shared logic resources, eliminating the need for separate dummy memory and reducing device complexity while maintaining security against fault attacks and side-channel analysis

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If dummy calculations are introduced to protect against attacks, then security against fault attacks and side-channel analysis is improved, but memory overhead increases due to storing dummy operation results

Engineering Contradiction:
ImprovesecurityVSAvoidmemory overhead
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent merges the storage of dummy operation results with the storage of real operation results by using the same memory resources. The output circuit stores results in shared memory based on a control sequence, eliminating the need for separate dummy memory and reducing memory overhead while maintaining security

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The memory resources are designed to serve multiple functions: storing both dummy and real operation results. The same memory circuitry is used for both purposes, with the output circuit dynamically selecting what to store based on the control sequence, thereby eliminating dedicated dummy memory and reducing overall memory overhead

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If dummy operations are made indistinguishable from real operations, then security against side-channel analysis is improved, but difficulty in detecting faults in dummy operations increases

Engineering Contradiction:
ImprovesecurityVSAvoidfault detection difficulty
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent incorporates feedback mechanisms where the output circuit monitors and verifies operations based on a control sequence. This feedback system allows the detection of faults in dummy operations while maintaining their indistinguishability from real operations, as the verification is performed through the same processing path without revealing whether an operation was dummy or real

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12169570B2Data processing device and method for processing secret data
Publication Date: 2024.12.17 INFINEON TECHNOLOGIES AG
  • US12169570B2 patent drawing
  • US12169570B2 patent drawing
  • US12169570B2 patent drawing

AI summary

According to various embodiments, a data processing device is described comprising a memory configured to store data words in the form of at least two respective shares, a logic circuit configured to receive the at least two shares of at least one of the data words and to process the shares to generate at least two shares of a result data word, a remasking circuit configured to receive at least two shares of at least one of the data words and refresh the shares and an output circuit configured to store the at least two shares of the result data word or to store the refreshed at least two shares depending on a control sequence specifying a sequence of real operations and dummy operations.