IP Library Patent Application 14056289
Patent Application
App. No. 14/056,289

SYSTEM AND METHOD FOR CRYPTOGRAPHIC PROCESSING IN A TIME WINDOW

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
14/056,289
Abstract

A method is disclosed for providing first data and a first secret key to a cipher processor for ciphering. The first data is ciphered in accordance with a first cipher process and the first secret key to provide output data. Before ciphering of the first data, extra data is inserted within the cipher processor for ciphering in accordance with at least a portion of said first cipher process. The extra data is inserted within a sequence of cipher processor operations for obfuscating the output data.

Claims (50)

1 . A method comprising:

providing first data and a first secret key to a cipher processor for ciphering;

said cipher processor ciphering the first data in accordance with a first cipher process and the first secret key to provide output data; and

before ciphering of the first data, inserting extra data within the cipher processor for ciphering in accordance with at least a portion of said first cipher process, said extra data inserted within a sequence of cipher processor operations for obfuscating said output data.

2 . A method according to claim 1 wherein the at least a portion of said first cipher process comprises inserting a plurality of guard rounds at one or more locations within the sequence of cipher processor operations to obfuscate an operation of the cipher processor from side-channel attack.

3 . A method according to claim 1 wherein the at least a portion of said first cipher process comprises inserting a plurality of guard rounds immediately before an initial round and immediately after a final round, the initial and final rounds processed in a similar fashion to other rounds.

4 . A method according to claim 2 wherein the at least a portion of said first cipher process comprises inserting a plurality of guard rounds similar to an initial round and a plurality of guard rounds similar to a final round to make it difficult to determine by way of side-channel attack when the initial and final rounds occurred.

5 . A method according to claim 1 wherein the at least a portion of said first cipher process is inserted within the sequence of cipher processor operations differently for different first data to make it difficult to determine the position of the at least a portion of the said first cipher process within the sequence of cipher processor operations by way of side-channel attack.

6 . A method according to claim 1 wherein the at least a portion of said first cipher process comprises dummy operations being executed solely to obfuscate operation of the cipher processor.

7 . A method according to claim 1 comprising:

providing a second secret key; and

providing second data to the cipher processor, the second data provided for being ciphered by the cipher processor,

wherein the at least a portion of said first cipher process comprises operations for performing the cipher with the second data and with the second secret key.

8 . A method according to claim 7 wherein cipher processor operations on the first data and cipher processor operations on the second data are interleaved one with another in a known fashion within the cipher processor and in an unknown fashion from outside the cipher processor

9 . A method according to claim 7 wherein cipher processor operations on the first data and cipher processor operations on the second data are interleaved one with another in a predetermined fashion within the cipher processor and in an unknown fashion from outside the cipher processor, the interleaving inconsistent.

10 . A method according to claim 1 wherein cipher processor operations on the first data and cipher processor operations on the second data are interleaved one with another in a known fashion within the cipher processor and in an unknown fashion from outside the cipher processor, the interleaving inconsistent between different first and second streams of data.

11 . A method for leak resistant ciphering comprising:

providing a first stream of data and an associated first secret key;

expanding the associated first secret key to form an associated first expanded secret key;

ciphering a plurality of guard rounds before processing the first data stream;

ciphering the first data stream in accordance with the associated first expanded secret key;

ciphering a plurality of guard rounds after processing the first data stream; and

providing the ciphered first stream of data at an output port.

12 . A method as defined in claim 11 wherein ciphering the plurality of guard rounds is in accordance with the first secret key.

13 . A method as defined in claim 11 wherein ciphering the plurality of guard rounds is in accordance with a second other secret key.

14 . A method as defined in claim 11 comprising:

providing M guard rounds in advance of performing processing of the first stream of data, where M is an integer greater than 0.

15 . A method as defined in claim 11 comprising providing P guard rounds after the processed first stream of data, where P is an integer greater than 0.

16 . A method as defined in claim 11 comprising:

providing a second other stream of data;

intermixing the first stream of data and the second other stream of data to provide an intermixed stream of data;

ciphering the second stream of data within the intermixed stream of data, wherein ciphering the first stream of data is also performed within the intermixed stream of data, to provide a ciphered intermixed stream of data; and

de-multiplexing the ciphered intermixed stream of data to remove the guard rounds therefrom to form a de-multiplexed ciphered first stream of data and ciphered second stream of data.

17 . A method as defined in claim 16 wherein the known number of guard rounds is a predetermined number of guard rounds.

18 . A method as defined in claim 16 comprising:

providing a predetermined number of guard rounds and final rounds at an end of the intermixed processed data streams.

19 . A method as defined in claim 16 comprising:

providing a known number of guard and final rounds at an end of the intermixed processed data streams.

20 . A method as defined in claim 16 wherein processing of the intermixed data streams is performed within a fixed window of time such that G pre +G post is equal to a constant, the fixed window filled with processing of the intermixed streams and the guard rounds.

21 . A method as defined in claim 16 comprising determining G pre by a scheduling system, G pre varying between different intermixed streams of data.

22 . A method according to claim 16 wherein the at least a portion of said first cipher processes comprises processing a plurality of guard rounds and wherein the guard rounds are inserted before the initial round and after the final round, the initial and final rounds processed in a similar fashion to other rounds.

23 . A method according to claim 16 wherein the at least a portion of said first cipher processes comprises processing a plurality of guard rounds and wherein the guard rounds are inserted before and after the initial round and before and after the final round, the initial and final rounds processed in a similar fashion to other rounds.

24 . A cipher processor comprising:

a key store for storing a first secret key;

a first data store for storing at least a portion of first data for ciphering thereof; and

a cipher processor for processing the first data in accordance with a first cipher process and the first secret key to provide output data therefrom, and for during processing of the first data inserting within the cipher processor at least a portion of the first data comprising at least a guard round for being processed thereby in accordance with a portion of a same cipher process, the at least a guard round inserted within a sequence of cipher processor operations for obfuscating operation thereof

25 . A cipher processor according to claim 24 wherein during use the at least a portion of the first data comprises a plurality of guard rounds and wherein the guard rounds are inserted at one or more locations within the sequence of cipher processor operations to obfuscate operation of the cipher processor from side-channel attack.

26 . A cipher processor according to claim 24 wherein during use the at least a portion of the first data comprises a plurality of guard rounds similar to an initial round and a plurality of guard rounds similar to a final round to make it difficult to determine by way of side-channel attack when the initial and final rounds occur.

27 . A cipher processor according to claim 24 wherein during use the at least a portion of the first data is disposed within the sequence differently for different first data to make it difficult to determine by way of side-channel attack when within the sequence of cipher processor operations the at least a portion of the first data are being inserted.

28 . A cipher processor according to claim 24 wherein the at least a portion of the first data comprises a plurality of guard rounds and wherein the guard rounds are inserted before the initial round and after the final round, the initial and final round processed in a similar fashion to the other rounds.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 8, 2015
From: ELLIPTIC TECHNOLOGIES INC.
To: SYNOPSYS INC.
Reel/Frame 036761/0474 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 17, 2013
From: HAMILTON, NEIL; BOURDON, FRAN?OIS; BORZA, MICHAEL
To: ELLIPTIC TECHNOLOGIES INC.
Reel/Frame 031426/0031 →