IP Library Granted Patent US 12682045
Granted Patent B2
US 12682045 · App. 18/537,075 · Granted Jul 14, 2026

Fault-attack analysis device and method

Inventors: Kun-Yi Wu (Tainan City, TW); Yu-Shan Li (Tainan City, TW)
Assignee: Nuvoton Technology Corporation
G06F21/54G06F21/602G06F21/72
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12682045
App. No.
18/537,075
Granted
Jul 14, 2026
Kind
B2
Abstract

An embodiment of the invention provides a fault-attack analysis device. The first encoder performs a first encoding operation on the first output result corresponding to the normal round calculation to generate a first encoding result. The first decoder performs a first decoding operation on the first encoding result to generate a first decoding result. The second encoder performs a second encoding operation on the second output result corresponding to the redundant round calculation to generate a second encoding result. The second decoder performs a second decoding operation on the second encoding result to generate a second decoding result. The second encoding operation and the second decoding operation are based on binary field addition. The comparison circuit compares the first decoding result to the second decoding result to perform a fault-attack analysis.

Claims (13)

1 . A fault-attack analysis device, comprising: a controller, generating a control signal; an encryption and decryption circuit, coupled to the controller, and performing a first round calculation based on the control signal to generate a first output result and a second round calculation based on the control signal to generate a second output result; a first encoder, coupled to the encryption and decryption circuit, and performing a first encoding operation on the first output result from the encryption and decryption circuit to generate a first encoding result; a first decoder, coupled to the encryption and decryption circuit, and performing a first decoding operation on the first encoding result to generate a first decoding result; a second encoder, coupled to the encryption and decryption circuit, and performing a second encoding operation on the second output result from the encryption and decryption circuit to generate a second encoding result; a second decoder, coupled to the encryption and decryption circuit, and performing a second decoding operation on the second encoding result to generate a second decoding result, wherein the second encoding operation and the second decoding operation are based on a binary field addition; and a comparison circuit, coupled to the first decoder and the second decoder, and comparing the first decoding result and the second decoding result to perform a fault-attack analysis.

2 . The fault-attack analysis device of claim 1 , further comprising: a first storage circuit, coupled to the first encoder and the first decoder, and storing calculation result of each round of the first round calculation; and a second storage circuit, coupled to the second encoder and the second decoder, and storing calculation result of each round of the second round calculation.

3 . The fault-attack analysis device of claim 1 , wherein the encryption and decryption circuit further comprises: a first encryption and decryption circuit, coupled to the first encoder, the first decoder, the second encoder and the second decoder, performing the first round calculation based on the control signal to generate the first output result, and performing the second round calculation based on the control signal to generate the second output result.

4 . The fault-attack analysis device of claim 1 , wherein the encryption and decryption circuit further comprises: a first encryption and decryption circuit, coupled to the first encoder and the first decoder, and performing the first round calculation based on the control signal to generate the first output result; and a second encryption and decryption circuit, coupled to the second encoder and the second decoder, and performing the second round calculation based on the control signal to generate the second output result.

5 . The fault-attack analysis device of claim 1 , wherein the first encoding operation and the first decoding operation are different from the second encoding operation and the second decoding operation.

6 . The fault-attack analysis device of claim 1 , wherein the second encoder comprises a plurality of first Exclusive-OR gates and the second decoder comprises a plurality of second Exclusive-OR gates, wherein a number of the plurality of first Exclusive-OR gates is the same as a number of the second Exclusive-OR gates.

7 . A fault-attack analysis method, applied to a fault-attack analysis device, comprising: generating, by a controller of the fault-attack analysis device, a control signal; performing, by an encryption and decryption circuit of the fault-attack analysis device, a first round calculation based on the control signal to generate a first output result and a second round calculation based on the control signal to generate a second output result; performing, by a first encoder of the fault-attack analysis device, a first encoding operation to the first output result to generate a first encoding result; performing, by a first decoder of the fault-attack analysis device, a first decoding operation on the first encoding result to generate a first decoding result; performing, by a second encoder of the fault-attack analysis device, a second encoding operation on the second output result to generate a second encoding result; performing, by a second decoder of the fault-attack analysis device, a second decoding operation on the second encoding result to generate a second decoding result, wherein the second encoding operation and the second decoding operation are based on a binary field addition; and comparing, by a comparison circuit of the fault-attack analysis device, the first decoding result with the second decoding result to perform a fault-attack analysis.

8 . The fault-attack analysis method of claim 7 , further comprising: performing, by the encryption and decryption circuit, the first round calculation and the second round calculation according to an Advanced Encryption Standard (AES) algorithm.

9 . The fault-attack analysis method of claim 8 , further comprising:

dividing, by the second encoder, each output data of the second output result into a plurality of blocks;

configuring, by the second encoder, the blocks corresponding to each output data into different groups to generate a plurality of first variables; and

performing, by the second encoder, the second encoding operation on the plurality of first variables to generate the second encoding result,

wherein a number of the first variables is the same as a number of the output data.