IP Library Patent Application 11777186
Patent Application
App. No. 11/777,186

Masking and Additive Decomposition Techniques for Cryptographic Field Operations

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
11/777,186
Abstract

Masking and additive decomposition techniques are used to mask secret material used in field operations (e.g., point multiplication operations) performed by cryptographic processes (e.g., elliptic curve cryptographic processes). The masking and additive decomposition techniques help thwart “side-channel” attacks (e.g., power and electromagnetic analysis attacks).

Claims (71)

1 . A method comprising:

obtaining secret material;

obtaining a masking parameter; and

generating ciphertext or a digital signature using at least one field operation on the secret material, where the secret material and the masking parameter are combined and the field operation operates on the combination.

2 . The method of claim 1 , where the masking parameter is a random integer greater or equal to one.

3 . The method of claim 1 , where the masking parameter is generated by evaluating a function using one or more values.

4 . The method of claim 1 , where the secret material is a private key for an elliptic curve cryptographic process.

5 . The method of claim 1 , where the field operation is an elliptic curve point multiplication operation.

6 . The method of claim 5 , where the combination is given by k+a*n, where k is the secret material, a is the masking parameter and n is an order of an elliptic curve.

7 . The method of claim 1 , where the secret material is a random integer.

8 . The method of claim 1 , where the signature is generated in an elliptic curve digital signature process.

9 . The method of claim 1 , where the ciphertext is generated in an elliptic curve encryption or decryption process.

10 . A method, comprising:

representing a plaintext message as a point on an elliptic curve;

obtaining an exponent value;

obtaining a masking parameter;

obtaining an order of a prime cyclic subgroup of the elliptic curve; and

generating ciphertext from the point, the order, the exponent value and the masking parameter using at least one point multiplication operation, where the point multiplication operation uses the masking parameter to mask the exponent value, such that the exponent value can not be determined from an analysis of the operating environment of the cryptographic method.

11 . The method of claim 10 , wherein obtaining an exponent value further comprises:

randomly generating an integer value for the exponent value from a finite field of integer values.

12 . The method of claim 10 , where the point multiplication replaces the exponent value with a sum of the exponent value and a product of the masking parameter and the order.

13 . A method, comprising:

obtaining public domain parameters;

obtaining a masking parameter; and

generating ciphertext or a digital signature from the public domain parameters, the masking parameter and secret material.

14 . The method of claim 13 , where generating ciphertext or signature further comprises:

combining the masking parameter and secret material, such that the secret material is difficult to derive from observing an environment where the ciphertext or signature is generated.

15 . An apparatus comprising:

a random number generator configurable for generating a masking parameter; and

an encryption engine coupled to the random number generator and configurable for generating ciphertext or a signature using at least one field operation on secret material, where the secret material and the masking parameter are combined and the field operation operates on the combination.

16 . The apparatus of claim 15 , where the masking parameter is a random integer greater or equal to one.

17 . The apparatus of claim 15 , where the masking parameter is generated by evaluating a function using one or more values.

18 . The apparatus of claim 15 , where the secret material is a private key for an elliptic curve cryptographic process.

19 . The apparatus of claim 15 , where the field operation is an elliptic curve point multiplication operation.

20 . The apparatus of claim 19 , where the combination is given by k+a*n, where k is the secret material, a is the masking parameter and n an order of an elliptic curve.

21 . The apparatus of claim 15 , where the secret material is a random integer.

22 . The apparatus of claim 15 , where the digital signature is generated in an elliptic curve digital signature process.

23 . The apparatus of claim 15 , where the ciphertext is generated in an elliptic curve encryption process.

24 . The apparatus of claim 15 , where the apparatus is a smart card.

25 . An apparatus comprising:

a storage device for storing a masking parameter; and

an encryption engine coupled to the storage device and configurable for generating ciphertext or a signature using at least one field operation on secret material, where the secret material and the masking parameter are combined and the field operation operates on the combination.

26 . An apparatus comprising:

an interface configurable for receiving ciphertext or a signature; and

a decryption engine coupled to the interface and configurable for generating plaintext from the ciphertext or authenticating the signature using at least one field operation on secret material, where the ciphertext or signature was generated using secret material and a masking parameter that were combined in a field operation used in generating the ciphertext or signature.

27 . The apparatus of claim 26 , where the field operation is an elliptic curve point multiplication operation.

28 . The apparatus of claim 26 , where the digital signature is generated in an elliptic curve digital signature process.

29 . The apparatus of claim 26 , where the ciphertext is generated in an elliptic curve encryption process.

30 . A system comprising:

means for obtaining secret material;

means for obtaining a masking parameter; and

means for generating ciphertext or a signature using at least one field operation on the secret material, where the secret material and the masking parameter are combined and the field operation operates on the combination.

31 . A computer-readable medium having instructions stored thereon, which, when executed by a processor, causes the processor to perform operations, comprising:

obtaining secret material;

obtaining a masking parameter; and

generating ciphertext or a signature using at least one field operation on the secret material, where the secret material and the masking parameter are combined and the field operation operates on the combination.

32 . A method comprising:

obtaining secret material;

decomposing the secret material into two or more parts; and

generating ciphertext or a digital signature using at least one field addition operation on the two or more parts.

33 . The method of claim 32 , where the secret material is a private key for an elliptic curve cryptographic process.

34 . The method of claim 32 , where the field addition operation is an elliptic curve addition operation.

35 . The method of claim 32 , where the two parts, k 1 , k 2 , are combined to give k.A=k 1 .A+k 2 .A, where A is a point on an elliptic curve and k is an integer less than an order of the elliptic curve.

36 . The method of claim 35 , where the two parts, k 1 , k 2 , are combined to give k.A=(k 1 +a.N).A+k 2 .A, where a is a masking parameter and N is an order of the elliptic curve.

37 . The method of claim 32 , where the secret material is a random integer.

38 . The method of claim 32 , where the signature is generated in an elliptic curve digital signature process.

39 . The method of claim 32 , where the ciphertext is generated in an elliptic curve encryption or decryption process.

40 . A computer-readable medium having instructions stored thereon, which, when executed by a processor, causes the processor to perform operations comprising:

obtaining secret material;

decomposing the secret material into two or more parts; and

generating ciphertext or a digital signature using at least one field addition operation on the two or more parts.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 10, 2012
From: ATMEL ROUSSET S.A.S.
To: INSIDE SECURE
Reel/Frame 028522/0371 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 17, 2010
From: ATMEL CORPORATION
To: ATMEL ROUSSET S.A.S.
Reel/Frame 024097/0324 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 10, 2007
From: DUPAQUIS, VINCENT; DOUGUET, MICHEL
To: ATMEL CORPORATION
Reel/Frame 019678/0471 →