IP Library Granted Patent US 8,572,406
Granted Patent B2
US 8,572,406 · App. 12/750,953 · Granted Oct 29, 2013

Integrated circuit protected against horizontal side channel analysis

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,572,406
App. No.
12/750,953
Granted
Oct 29, 2013
Kind
B2
Abstract

An integrated circuit including a multiplication function configured to execute a multiplication operation of two binary words x and y including a plurality of basic multiplication steps of components xi of word x by components yj of word y is described. The multiplication function of the integrated circuit is configured to execute two successive multiplications by modifying, in a random or pseudo-random manner, an order in which the basic multiplication steps of components xi by components yj are executed.

Claims (24)

1. An integrated circuit comprising a multiplication function configured to execute a multiplication of at least two binary words x and y in a plurality of basic multiplication steps of components xi of word x by components yj of word y, i and j being iteration variables, wherein in at least some of the multiplication steps i does not equal j, and

wherein the multiplication function is further configured to execute two successive multiplications of binary words x and y by modifying, in a random or pseudo-random manner, an order in which the basic multiplication steps of components xi by components yj are executed.

2. The integrated circuit according to claim 1 , wherein the multiplication function is configured to modify, in a random or pseudo-random manner, the order in which the components xi are multiplied with the components yj without modifying one of the order in which the components yj are multiplied with the components xi, or the order in which the components yj are multiplied with the components xi.

3. The integrated circuit according to claim 1 , wherein the multiplication function is configured to modify, in a random or pseudo-random manner, both the order in which the components xi are multiplied with the components yj and the order in which the components yj are multiplied with the components xi.

4. The integrated circuit according to claim 1 , wherein the multiplication function includes a component configured to generate or receive a random or pseudo-random binary number, and configured to execute the plurality of basic multiplication steps of the components xi by the components yj, for at least one of the iteration variables i or j, according to an order determined by the random or pseudo-random binary number.

5. The integrated circuit according to claim 1 , wherein the multiplication function is also configured to randomize at least one of the components xi or yj by way of at least one random or pseudo-random word.

6. The integrated circuit according to claim 1 , wherein the multiplication function includes a first operating mode in which the iteration variables are incremented or decremented according to a constant order of multiplication of binary words to another, and a second operating mode wherein at least one of the iteration variables is incremented or decremented in a random or pseudo-random manner from one binary word multiplication to another.

7. The integrated circuit according to claim 1 , wherein the multiplication function is executed by a hardwired circuit controlled by a sequencer.

8. The integrated circuit according to claim 1 , further comprising a processing function of external data, the execution of which comprises at least one step of conditional branching to at least one first multiplication step of binary words by the multiplication function or a second multiplication step of binary words by the multiplication function, the conditional branching being a function of a private data of the integrated circuit.

9. The integrated circuit according to claim 8 , wherein the data processing function is a modular exponentiation function, the private data being an exponent of the modular exponentiation function.

10. The integrated circuit according to claim 8 , wherein the data processing function is a cryptographic function including a modular exponentiation function, the private data being an exponent of the modular exponentiation function forming a private key of the cryptographic function.

11. A device comprising an integrated circuit according to claim 1 , arranged on or embedded in a support.

12. A process for protecting against a side channel analysis of an integrated circuit configured to execute a multiplication operation of at least two binary words x and y and a plurality of basic multiplication steps of components xi of word x by components yj of word y, i and j being iteration variables, wherein in at least some of the multiplication steps i does not equal j, the process comprising:

modifying, in a random or pseudo-random manner, the order in which the integrated circuit executes basic multiplication steps of components xi by components yj, from one multiplication operation of binary words to another.

13. The process according to claim 12 , further comprising modifying, in a random or pseudo-random manner, the order in which the integrated circuit multiplies the components xi with the components yj, without modifying one of the order in which the components yj are multiplied with the components xi, or the order in which the components xi are multiplied with the components yj.

14. The process according to claim 12 , further comprising modifying, in a random or pseudo-random manner, both the order in which the integrated circuit multiplies the components xi with the components yj and the order in which the integrated circuit multiplies the components yj with the components xi.

15. The process according to claim 12 , further comprising:

generating a random or pseudo-random binary number within the integrated circuit; and

making the integrated circuit execute a plurality of basic multiplication steps of the components xi with the components yj according to an order determined by the random or pseudo-random binary number, for at least one of the iteration variables i or j.

16. The process according to claim 12 , further comprising randomizing at least one of the components xi or yj by way of at least one random or pseudo-random word.

17. The process according to claim 12 , applied to the protection of an integrated circuit comprising a processing function of an external data, the execution of which includes at least one step of conditional branching to at least a first multiplication step of binary words or at least a second multiplication step of binary words, the conditional branching being a function of a private data of the integrated circuit.

18. An integrated circuit comprising a multiplication function configured to execute a multiplication of at least two binary words x and y, wherein the multiplication function is configured to

divide words x and y into l components xi and yi of smaller size, with i=0, 1, . . . l−1, and j=0, 1, . . . l−1, i and j being iteration variables, and

execute a series of l 2 basic multiplication steps of components xi by components yj, wherein the multiplication function is further configured to execute the series of l 2 basic multiplication steps according to a random or pseudo-random order, by randomizing the iteration variable i or randomizing the iteration variable j, or randomizing both iteration variables i and j.

Assignments (8)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 3, 2020
From: RAMBUS INC.
To: CRYPTOGRAPHY RESEARCH, INC.
Reel/Frame 054539/0109 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 12, 2019
From: VERIMATRIX
To: RAMBUS INC.
Reel/Frame 051262/0413 →
PARTIAL RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL Recorded Nov 21, 2019
From: GLAS SAS, AS AGENT
To: INSIDE SECURE
Reel/Frame 051076/0306 →
CHANGE OF ADDRESS Recorded Oct 16, 2019
From: VERIMATRIX
To: VERIMATRIX
Reel/Frame 050733/0003 →
CHANGE OF NAME Recorded Oct 7, 2019
From: INSIDE SECURE
To: VERIMATRIX
Reel/Frame 050647/0428 →
SECURITY INTEREST Recorded Feb 27, 2019
From: INSIDE SECURE
To: GLAS SAS, AS SECURITY AGENT
Reel/Frame 048449/0887 →
CHANGE OF NAME Recorded Sep 5, 2012
From: INSIDE CONTACTLESS
To: INSIDE SECURE
Reel/Frame 028901/0685 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 18, 2010
From: FEIX, BENOIT; GAGNEROT, GEORGES; ROUSSELLET, MYLENE; VERNEUIL, VINCENT
To: INSIDE CONTACTLESS
Reel/Frame 024556/0722 →