Protection of cryptographic parameters used in cryptographic processing
A cipher instruction is executed that includes encrypting a confidential value. A power block sequencing value is obtained as input to the cipher instruction, and a mask value is generated using the encrypted confidential value and the power block sequencing value. A cipher operation is performed on at least a portion of a message specified by the cipher instruction using the mask value. The power block sequencing value is updated, based on performing the cipher operation of the at least the portion of the message, to provide an updated power block sequencing value to be used in re-execution of the cipher instruction based on the cipher instruction being interrupted. The updated power block sequencing value is to be provided as input to the cipher instruction based on the cipher instruction being re-executed to re-generate the mask value to be used in continuing the cipher operation of the message.
1 . A computer program product comprising:
a set of one or more computer-readable storage media; and
program instructions, collectively stored in the set of one or more computer-readable storage media, for causing at least one hardware computing device to perform computer operations including:
executing a cipher instruction, the executing the cipher instruction including:
encrypting a confidential value received as input to the cipher instruction, providing an encrypted confidential value;
obtaining as input to the cipher instruction a power block sequencing value, the power block sequencing value being a state value used in re-execution of the cipher instruction based on interruption of the cipher instruction;
generating a mask value using the encrypted confidential value and the power block sequencing value;
performing a cipher operation of at least a portion of a message specified by the cipher instruction, the cipher operation indicated by the cipher instruction, the performing the cipher operation using the mask value; and
updating the power block sequencing value, based on performing the cipher operation of the at least the portion of the message, providing an updated power block sequencing value, the updated power block sequencing value provided as input to the cipher instruction based on the cipher instruction being interrupted and re-executed, wherein based on re-executing the cipher instruction the mask value is re-generated and used in continuing the cipher operation of the message.
2 . The computer program product of claim 1 , wherein the mask value is transient and is re-generated on re-execution of the cipher instruction, and wherein the cipher operation is one operation of an encryption operation and a decryption operation.
3 . The computer program product of claim 1 , wherein the generating the mask value includes multiplying the encrypted confidential value and the power block sequencing value to generate the mask value.
4 . The computer program product of claim 1 , wherein the updating the power block sequencing value includes performing block-wise updates to the power block sequencing value based on performing the cipher operation on one or more message blocks of the message.
5 . The computer program product of claim 4 , wherein the executing the cipher instruction further includes performing block-wise updates to the mask value based on performing the cipher operation on the one or more message blocks of the message, wherein the power block sequencing value and the mask value are maintained in-step with one another.
6 . The computer program product of claim 1 , wherein the updating the power block sequencing value includes incrementally updating the power block sequencing value based on performing the cipher operation on a message block of the message, the message including a plurality of message blocks, and wherein the incrementally updating the power block sequencing value includes performing a multiplication operation on the power block sequencing value to incrementally update the power block sequencing value that is used to perform the cipher operation on a next message block of the plurality of message blocks.
7 . The computer program product of claim 6 , wherein the multiplication operation is performed over a Galois field 2 128 .
8 . The computer program product of claim 1 , wherein the computer operations further include:
interrupting execution of the cipher instruction, wherein the cipher operation of the message terminates prior to completion of the cipher operation of the message; and
re-executing the cipher instruction, the re-executing obtaining the updated power block sequencing value to resume the cipher operation of the message at a location in which the cipher operation of the message is interrupted.
9 . The computer program product of claim 8 , wherein the message includes a plurality of message blocks, and wherein the location in which the cipher operation of the message is interrupted is a message block of the plurality of message blocks of the message.
10 . The computer program product of claim 1 , wherein the obtaining as input to the cipher instruction the power block sequencing value includes obtaining the power block sequencing value from a parameter block used as input to the cipher instruction.
11 . A computer system comprising:
at least one hardware computing device;
a set of one or more computer-readable storage media; and
program instructions, collectively stored in the set of one or more computer-readable storage media, for causing the at least one hardware computing device to perform computer operations including:
executing a cipher instruction, the executing the cipher instruction including:
encrypting a confidential value received as input to the cipher instruction, providing an encrypted confidential value;
obtaining as input to the cipher instruction a power block sequencing value, the power block sequencing value being a state value used in re-execution of the cipher instruction based on interruption of the cipher instruction;
generating a mask value using the encrypted confidential value and the power block sequencing value;
performing a cipher operation of at least a portion of a message specified by the cipher instruction, the cipher operation indicated by the cipher instruction, the performing the cipher operation using the mask value; and
updating the power block sequencing value, based on performing the cipher operation of the at least the portion of the message, providing an updated power block sequencing value, the updated power block sequencing value provided as input to the cipher instruction based on the cipher instruction being interrupted and re-executed, wherein based on re-executing the cipher instruction the mask value is re-generated and used in continuing the cipher operation of the message.
12 . The computer system of claim 11 , wherein the updating the power block sequencing value includes performing block-wise updates to the power block sequencing value based on performing the cipher operation on one or more message blocks of the message.
13 . The computer system of claim 12 , wherein the executing the cipher instruction further includes performing block-wise updates to the mask value based on performing the cipher operation on the one or more message blocks of the message, wherein the power block sequencing value and the mask value are maintained in-step with one another.
14 . The computer system of claim 11 , wherein the updating the power block sequencing value includes incrementally updating the power block sequencing value based on performing the cipher operation on a message block of the message, the message including a plurality of message blocks, and wherein the incrementally updating the power block sequencing value includes performing a multiplication operation on the power block sequencing value to incrementally update the power block sequencing value that is used to perform the cipher operation on a next message block of the plurality of message blocks.
15 . The computer system of claim 11 , wherein the computer operations further include:
interrupting execution of the cipher instruction, wherein the cipher operation of the message terminates prior to completion of the cipher operation of the message; and
re-executing the cipher instruction, the re-executing obtaining the updated power block sequencing value to resume the cipher operation of the message at a location in which the cipher operation of the message is interrupted.
16 . A computer-implemented method comprising:
executing a cipher instruction on a hardware computing device, the executing the cipher instruction including:
encrypting a confidential value received as input to the cipher instruction, providing an encrypted confidential value;
obtaining as input to the cipher instruction a power block sequencing value the power block sequencing value being a state value used in re-execution of the cipher instruction based on interruption of the cipher instruction;
generating a mask value using the encrypted confidential value and the power block sequencing value;
performing a cipher operation of at least a portion of a message specified by the cipher instruction, the cipher operation indicated by the cipher instruction, the performing the cipher operation using the mask value; and
updating the power block sequencing value, based on performing the cipher operation of the at least the portion of the message, providing an updated power block sequencing value, the updated power block sequencing value provided as input to the cipher instruction based on the cipher instruction being interrupted and re-executed, wherein based on re-executing the cipher instruction the mask value is re-generated and used in continuing the cipher operation of the message.
17 . The computer-implemented method of claim 16 , wherein the updating the power block sequencing value includes performing block-wise updates to the power block sequencing value based on performing the cipher operation on one or more message blocks of the message.
18 . The computer-implemented method of claim 17 , wherein the executing the cipher instruction further includes performing block-wise updates to the mask value based on performing the cipher operation on the one or more message blocks of the message, wherein the power block sequencing value and the mask value are maintained in-step with one another.
19 . The computer-implemented method of claim 16 , wherein the updating the power block sequencing value includes incrementally updating the power block sequencing value based on performing the cipher operation on a message block of the message, the message including a plurality of message blocks, and wherein the incrementally updating the power block sequencing value includes performing a multiplication operation on the power block sequencing value to incrementally update the power block sequencing value that is used to perform the cipher operation on a next message block of the plurality of message blocks.
20 . The computer-implemented method of claim 16 , further including:
interrupting execution of the cipher instruction, wherein the cipher operation of the message terminates prior to completion of the cipher operation of the message; and
re-executing the cipher instruction, the re-executing obtaining the updated power block sequencing value to resume the cipher operation of the message at a location in which the cipher operation of the message is interrupted.
21 . A computer program product comprising:
a set of one or more computer-readable storage media; and
program instructions, collectively stored in the set of one or more computer-readable storage media, for causing at least one hardware computing device to perform computer operations including:
executing a cipher instruction, the executing the cipher instruction including:
encrypting a confidential value received as input to the cipher instruction, providing an encrypted confidential value;
obtaining as input to the cipher instruction a power block sequencing value, the power block sequencing value being a state value used in re-execution of the cipher instruction based on interruption of the cipher instruction;
generating a mask value using the encrypted confidential value and the power block sequencing value;
performing a cipher operation of at least a portion of a message specified by the cipher instruction, the cipher operation indicated by the cipher instruction, the performing the cipher operation using the mask value; and
updating the power block sequencing value, based on performing the cipher operation of the at least the portion of the message, providing an updated power block sequencing value, the updated power block sequencing value provided as input to the cipher instruction based on the cipher instruction being interrupted and re-executed; and
re-executing the cipher instruction based on execution of the cipher instruction being interrupted, the re-executing re-generating the mask value, obtaining the updated power block sequencing value and resuming the cipher operation of the message at a location in which the cipher operation of the message is interrupted, wherein the mask value is transient and is re-generated on re-execution of the cipher instruction.
22 . The computer program product of claim 21 , wherein the updating the power block sequencing value includes performing block-wise updates to the power block sequencing value based on performing the cipher operation on one or more message blocks of the message.
23 . The computer program product of claim 22 , wherein the executing the cipher instruction further includes performing block-wise updates to the mask value based on performing the cipher operation of the one or more message blocks of the message, wherein the power block sequencing value and the mask value are maintained in-step with one another.
24 . A computer-implemented method comprising:
executing a cipher instruction on a hardware computing device, the executing the cipher instruction including:
encrypting a confidential value received as input to the cipher instruction, providing an encrypted confidential value;
obtaining as input to the cipher instruction a power block sequencing value, the power block sequencing value being a state value used in re-execution of the cipher instruction based on interruption of the cipher instruction;
generating a mask value using the encrypted confidential value and the power block sequencing value;
performing a cipher operation of at least a portion of a message specified by the cipher instruction, the cipher operation indicated by the cipher instruction, the performing the cipher operation using the mask value; and
updating the power block sequencing value, based on performing the cipher operation of the at least the portion of the message, providing an updated power block sequencing value, the updated power block sequencing value provided as input to the cipher instruction based on the cipher instruction being interrupted and re-executed; and
re-executing the cipher instruction based on execution of the cipher instruction being interrupted, the re-executing re-generating the mask value, obtaining the updated power block sequencing value and resuming the cipher operation of the message at a location in which the cipher operation of the message is interrupted, wherein the mask value is transient and is re-generated on re-execution of the cipher instruction.
25 . The computer-implemented method of claim 24 , wherein the updating the power block sequencing value includes performing block-wise updates to the power block sequencing value based on performing the cipher operation on one or more message blocks of the message, and wherein the computer-implemented method further includes performing block-wise updates to the mask value based on performing the cipher operation on the one or more message blocks of the message, wherein the power block sequencing value and the mask value are maintained in-step with one another.