IP Library Granted Patent US 9,875,377
Granted Patent B2
US 9,875,377 · App. 14/661,862 · Granted Jan 23, 2018

Encryption device of a substitution-box type, and corresponding encryption method and computer program product

Inventor: Filippo Melzani (Burago di Molgora, IT)
Assignee: STMICROELECTRONICS S.R.L.
G06F21/72H04L9/002H04L9/0631H04L2209/046
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,875,377
App. No.
14/661,862
Granted
Jan 23, 2018
Kind
B2
Abstract

A device of the Substitution-Box (S-Box) type, which is suitable for operating in a symmetric-key encryption apparatus, in particular an AES (Advanced Encryption Standard) encryption apparatus, and includes at least one module configured for carrying out a non-linear operation in a finite field (GF(2 8 )) of an encryption method implemented by the above encryption apparatus, the module including at least one reprogrammable look-up table to, for example, implement countermeasures against side-channel attacks. When no countermeasures are employed, the tables may be set to fixed values, instead of being reprogrammable. The above module includes a plurality of composite look-up tables that implement the non-linear operation in a composite field of finite subfields (GF(2 4 ) 2 ; GF((2 2 ) 2 ) 2 ) deriving from the finite field (GF(2 8 )), each of the above composite look-up tables being smaller than a look-up table that is able to implement autonomously the non-linear operation in a finite field (GF(2 8 )).

Claims (74)

1. A device, comprising:

AES (Advanced Encryption Standard) circuitry, including:

non-linear operation circuitry configured to carry out a non-linear operation in a finite field of an AES process, said non-linear operation circuitry comprising a plurality of programmable registers configured to implement a plurality of composite look-up tables to perform said non-linear operation in a composite field of finite subfields deriving from said finite field, wherein the plurality of composite look-up tables are reprogrammable; and

linear operation circuitry configured to perform at least one linear operation of the AES process, wherein

each of said composite look-up tables has a size smaller than a size of a corresponding single look-up table to perform said non-linear operation in the finite field; and

said AES circuitry is configured to:

map elements of the finite field of the non-linear operation by decomposing the elements over the composite field of finite subfields using an isomorphism;

compute the non-linear operation in the composite field of finite subfields; and

map results of said computation over the field of the non-linear operation applying the inverse of the isomorphism used for the decomposition over the composite field of finite subfields.

2. The device of claim 1 wherein said non-linear operation is an operation of multiplicative inversion of a SubBytes operation of an AES encryption procedure.

3. The device of claim 1 , comprising at least one of:

set-top box circuitry; and

smart card circuitry.

4. The device of claim 1 wherein the AES circuitry comprises combinational logic and is configured to:

implement additions resulting from the decomposition using the combinational logic; and

implement remaining non-linear operations, resulting from said decomposition, using said composite look-up tables.

5. The device of claim 1 wherein the AES circuitry is configured to initialize a composite look-up table of the plurality of composite look-up tables by:

applying a first address-mask to an unmasked address, generating a masked address; and

applying a first data-mask to unmasked data, generating masked data.

6. The device of claim 5 wherein the AES circuitry is configured to reinitialize the composite look-up table by:

applying a logical combination of the first address-mask and a second address-mask to the masked address, generating an address corresponding to application of the second address-mask to the unmasked address; and

applying a logical combination of the first data-mask and a second data-mask to the masked data, generating data corresponding to application of the second data-mask to the unmasked data.

7. The device of claim 1 wherein the plurality of composite look-up tables comprise a plurality of flip-flops.

8. A method, comprising:

performing a non-linear operation of an Advanced Encryption Standard (AES) process in a finite field of the AES process using a plurality of programmable registers to implement a plurality of composite look-up tables to perform said non-linear operation in a composite field of finite subfields deriving from said finite field, wherein the plurality of programmable registers are reprogrammable; and

performing a linear operation circuitry of the AES process, wherein

each of said composite look-up tables has a size smaller than a size of a corresponding single look-up table to perform said non-linear operation in the finite field; and

the method includes:

mapping elements of the finite field of the non-linear operation by decomposing the elements over the composite field of finite subfields using an isomorphism;

computing the non-linear operation in the composite field of finite subfields; and

mapping results of said computation over the field of the non-linear operation, applying the inverse of the isomorphism used for the decomposition over the composite field of finite subfields.

9. The method of claim 8 wherein said non-linear operation is an operation of multiplicative inversion of a SubBytes operation of an AES encryption procedure.

10. The method of claim 8 , comprising at least one of:

controlling a set-top box based on a result of the AES process; and

controlling operation of a smart card based on the result of the AES process.

11. The method of claim 8 , comprising:

implementing additions resulting from the decomposition using combinational logic; and

implementing remaining non-linear operations, resulting from said decomposition, using said composite look-up tables.

12. The method of claim 8 , comprising initializing a composite look-up table of the plurality of composite look-up tables, the initializing including:

applying a first address-mask to an unmasked address, generating a masked address; and

applying a first data-mask to unmasked data, generating masked data.

13. The method of claim 12 wherein the initializing includes:

applying a logical combination of the first address-mask and a second address-mask to the masked address, generating an address corresponding to application of the second address-mask to the unmasked address; and

applying a logical combination of the first data-mask and a second data-mask to the masked data, generating data corresponding to application of the second data-mask to the unmasked data.

14. A non-transitory computer-readable medium having contents which configure a processing device to perform a method, the method comprising:

performing a non-linear operation of an Advanced Encryption Standard (AES) process in a finite field of the AES process using a plurality of programmable registers to implement a plurality of composite look-up tables to perform said non-linear operation in a composite field of finite subfields deriving from said finite field, wherein the plurality of programmable registers are reprogrammable; and

performing a linear operation circuitry of the AES process, wherein

each of said composite look-up tables has a size smaller than a size of a corresponding single look-up table to perform said non-linear operation in the finite field; and

the method includes:

mapping elements of the finite field of the non-linear operation by decomposing the elements over the composite field of finite subfields using an isomorphism;

computing the non-linear operation in the composite field of finite subfields; and

mapping results of said computation over the field of the non-linear operation, applying the inverse of the isomorphism used for the decomposition over the composite field of finite subfields.

15. The medium of claim 14 wherein the processing device is at least one of:

a set-top box; and

a smart card.

16. A system, comprising:

an interface configured to receive and output data; and

S-Box circuitry, including:

non-linear operation circuitry configured to carry out a non-linear operation in a finite field of an Advanced Encryption Standard (AES) process, said non-linear operation circuitry comprising a plurality of programmable registers configured to implement a plurality of composite look-up tables to perform said non-linear operation in a composite field of finite subfields deriving from said finite field, wherein the plurality of programmable registers are reprogrammable; and

linear operation circuitry configured to perform at least one linear operation of the AES process, wherein

each of said composite look-up tables has a size smaller than a size of a corresponding single look-up table to perform said non-linear operation in the finite field; and

said S-Box circuitry is configured to:

map elements of the finite field of the non-linear operation by decomposing the elements over the composite field of finite subfields using an isomorphism;

compute the non-linear operation in the composite field of finite subfields; and

map results of said computation over the field of the non-linear operation, applying the inverse of the isomorphism used for the decomposition over the composite field of finite subfields.

17. The system of claim 16 , comprising at least one of:

set-top box control circuitry configured to couple to the interface; and

smart card control circuitry configured to couple to the interface.

18. The system of claim 16 wherein the S-Box circuitry is configured to initialize a composite look-up table of the plurality of composite look-up tables by:

applying a first address-mask to an unmasked address, generating a masked address; and

applying a first data-mask to unmasked data, generating masked data.

19. The system of claim 18 wherein the S-Box circuitry is configured to reinitialize the composite look-up table by:

applying a logical combination of the first address-mask and a second address-mask to the masked address, generating an address corresponding to application of the second address-mask to the unmasked address; and

applying a logical combination of the first data-mask and a second data-mask to the masked data, generating data corresponding to application of the second data-mask to the unmasked data.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 1, 2022
From: STMICROELECTRONICS S.R.L.
To: STMICROELECTRONICS INTERNATIONAL N.V.
Reel/Frame 061828/0243 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 19, 2015
From: MELZANI, FILIPPO
To: STMICROELECTRONICS S.R.L.
Reel/Frame 035210/0333 →
Priority Claims (2)
IT TO2014A0267 · Mar 31, 2014 · national
IT TO2014A0268 · Mar 31, 2014 · national
Continuity (1)
Related Publication 20150278554A1 · Oct 1, 2015