US2020235910A1PendingUtilityA1

Lightweight mitigation against first-order probing side-channel attacks on block ciphers

Assignee: QUALCOMM INCPriority: Jan 11, 2017Filed: Apr 6, 2020Published: Jul 23, 2020
Est. expiryJan 11, 2037(~10.5 yrs left)· nominal 20-yr term from priority
H04L 9/003H04L 9/0625H04L 9/0631H04L 9/0618H04L 9/002H04L 9/14H04L 9/32
50
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Techniques for mitigating side-channel attacks on cryptographic algorithms are provided. An example method according to these techniques includes applying a block cipher algorithm to an input data to generate a cryptographic output, such that applying the block cipher to input data comprises modifying an output of a stage of the block cipher algorithm such that each output of the stage of the block cipher algorithm has a constant Hamming weight, and outputting the cryptographic output.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method for securing data, the method comprising:
 applying a block cipher algorithm to an input data to generate a cryptographic output, wherein applying the block cipher algorithm to the input data comprises modifying an output of a stage of the block cipher algorithm with a weight adjustment value such that each output of the stage of the block cipher algorithm has a constant Hamming weight; and   outputting the cryptographic output.   
     
     
         2 . The method of  claim 1 , wherein the stage of the block cipher algorithm is a diffusion stage of the block cipher algorithm. 
     
     
         3 . The method of  claim 2 , wherein the diffusion stage comprises a substitution round, and wherein modifying the output of the diffusion stage comprises modifying the output of the substitution round to have the constant Hamming weight. 
     
     
         4 . The method of  claim 1 , wherein the weight adjustment value comprises one or more bits of data that can be combined with an output of the stage of the block cipher algorithm such that the combined value has a Hamming weight equal to a predetermined constant value. 
     
     
         5 . The method of  claim 4 , wherein combining the weight adjustment value with the output of the stage of the block cipher algorithm comprises concatenating the one or more bits of data with the output of the stage of the block cipher algorithm. 
     
     
         6 . An apparatus comprising:
 means for applying a block cipher algorithm to an input data to generate a cryptographic output, wherein applying the block cipher algorithm to the input data comprises means for modifying an output of a stage of the block cipher algorithm with a weight adjustment value such that each output of the stage of the block cipher algorithm has a constant Hamming weight; and   means for outputting the cryptographic output.   
     
     
         7 . The apparatus of  claim 6 , wherein the stage of the block cipher algorithm is a diffusion stage of the block cipher algorithm. 
     
     
         8 . The apparatus of  claim 7 , wherein the diffusion stage comprises a substitution round, and wherein the means for modifying the output of the diffusion stage comprises means for modifying the output of the substitution round to have the constant Hamming weight. 
     
     
         9 . The apparatus of  claim 6 , wherein the weight adjustment value comprises one or more bits of data that can be combined with an output of the stage of the block cipher algorithm such that the combined value has a Hamming weight equal to a predetermined constant value. 
     
     
         10 . The apparatus of  claim 9 , wherein combining the weight adjustment value with the output of the stage of the block cipher algorithm comprises concatenating the one or more bits of data with the output of the stage of the block cipher algorithm. 
     
     
         11 . An apparatus comprising:
 a memory; and   a processor communicatively coupled to the memory, the processor configured to:
 apply a block cipher algorithm to an input data to generate a cryptographic output, wherein applying the block cipher algorithm to the input data comprises modifying an output of a stage of the block cipher algorithm with a weight adjustment value such that each output of the stage of the block cipher algorithm has a constant Hamming weight; and 
 output the cryptographic output. 
   
     
     
         12 . The apparatus of  claim 11 , wherein the stage of the block cipher algorithm is a diffusion stage of the block cipher algorithm. 
     
     
         13 . The apparatus of  claim 12 , wherein the diffusion stage comprises a substitution round, and wherein the processor is further configured to modify the output of the substitution round to have the constant Hamming weight. 
     
     
         14 . The apparatus of  claim 11 , wherein the weight adjustment value comprises one or more bits of data that can be combined with an output of the stage of the block cipher algorithm such that the combined value has a Hamming weight equal to a predetermined constant value. 
     
     
         15 . The apparatus of  claim 14 , wherein the processor is further configured to concatenate the one or more bits of data with the output of the stage of the block cipher algorithm. 
     
     
         16 . A non-transitory, computer-readable medium, having stored thereon computer-readable instructions for securing data, comprising instructions configured to cause a computing device to:
 apply a block cipher algorithm to an input data to generate a cryptographic output, wherein applying the block cipher algorithm to the input data comprises modifying an output of a stage of the block cipher algorithm with a weight adjustment value such that each output of the stage of the block cipher algorithm has a constant Hamming weight; and   output the cryptographic output.   
     
     
         17 . The non-transitory, computer-readable medium of  claim 16 , wherein the stage of the block cipher algorithm is a diffusion stage of the block cipher algorithm. 
     
     
         18 . The non-transitory, computer-readable medium of  claim 17 , wherein the diffusion stage comprises a substitution round, and wherein the instructions configured to cause the computing device to modify the output of the diffusion stage further comprise instructions configured to cause the computing device to modify the output of the substitution round to have the constant Hamming weight. 
     
     
         19 . The non-transitory, computer-readable medium of  claim 16 , wherein the weight adjustment value comprises one or more bits of data that can be combined with an output of the stage of the block cipher algorithm such that the combined value has a Hamming weight equal to a predetermined constant value. 
     
     
         20 . The non-transitory, computer-readable medium of  claim 19 , further comprising instructions configured to cause the computing device to configured to concatenate the one or more bits of data with the output of the stage of the block cipher algorithm.

Join the waitlist — get patent alerts

Track US2020235910A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.