IP Library Granted Patent US 9,886,597
Granted Patent B2
US 9,886,597 · App. 14/770,797 · Granted Feb 6, 2018

Method for encoding data on a chip card by means of constant-weight codes

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,886,597
App. No.
14/770,797
Granted
Feb 6, 2018
Kind
B2
Abstract

The invention relates to a data-processing method that includes encoding a plurality of data of n bits into code words having a predefined constant Hamming weight, characterized in that said method also includes using ( 4000 ) encryption operations or arithmetic operations on the resulting code word(s) and also in that encoding each datum includes: decomposing ( 100 ) the datum into a plurality of m bit sequences to be encoded, m strictly being less than n; encoding ( 300 ) each bit sequence into a partial code word, each having a predefined Hamming weight, such that the sum of the Hamming weights of the partial code words are equal to the Hamming weights of the code word; and concatenating ( 300 ) the partial code words such as to produce the code word corresponding to the datum. The invention also relates to a data transmission method and to an electronic circuit configured to implement said methods.

Claims (29)

1. A data-processing method carried out in an electronic circuit in order to secure the electronic circuit against side channel attacks or detect attacks by injection of errors, comprising encoding a plurality of data (D) of n bits into code words (M) having a predefined constant Hamming weight,

further comprising encryption operations or arithmetical operations on the code word(s) obtained, and in that the encoding of each datum (D) comprises:

decomposition of the datum into a plurality of m sequences of bits (d 1 , . . . , d m ) to be coded, m being strictly less than n,

coding of each sequence of bits into a partial code word having each a predefined Hamming weight, such that a sum of the Hamming weights of the partial code words (m 1 , . . . , m m ) is equal to the Hamming weight of the code word (M), and concatenation of partial code words (m 1 , . . . , m m ) to obtain the code word (M) corresponding to the datum (D),

wherein the data (D) comprise 4 bits, each datum being decomposed into a first sequence of 3 bits, and a second sequence of one bit, the first sequence being coded in a partial code word of 5 bits size and of Hamming weight equal to 2 or 3, and the second sequence of one bit being coded in a partial code word of 2 bits size and Hamming weight equal to 1.

2. The data-processing processing method according to claim 1 , wherein the code word obtained has a size strictly less than 2n bits.

3. The data-processing processing method according to claim 1 , wherein the data (D) has a size n which is a power of 2 bits.

4. The data-processing processing method according to claim 1 , wherein the sequences of bits (d 1 , . . . , d m ) have a size which is a power of 2 bits.

5. The data-processing method according to claim 1 , the encoding being performed by a first processing unit, the method further comprising transmission to a second processing unit of at least one code word (M) obtained from the datum or data (D) and the encryption operations or the arithmetical operations being executed on said at least one code word (M) by the second processing unit.

6. The data-processing method according to claim 5 , further comprising verification, by the second processing unit, of a value of the Hamming weight of the received code word.

7. The data-processing method according to claim 1 , wherein the arithmetical operations or the encryption operations take carried out on at least one code word, and produces at output a result coded of the operation applied to the datum corresponding to the code word.

8. The data-processing method according to claim 1 , wherein the arithmetical operations or the encryption operations comprise linear operations applied to at least one code word, and said linear operations comprise:

generation of at least one table taking at least one partial code word at input, and producing at output the result of the operation applied to the partial code word(s),

decomposition of each code word on which the operation is performed into partial code words, and

calculation of the operation by application of partial code words to the tables, and concatenation of the results obtained.

9. The data-processing method according to claim 1 , wherein the arithmetical operations or the encryption operations are non-linear, wherein a non-linear operation comprises:

generation of at least one table taking at input at least one partial code word of at least one code word, and producing at output a coded result of the operation applied to at least one complete datum from which the partial code words are drawn,

decomposition of each code word on which the operation is performed into partial code words, and,

calculation of the operation by application of partial code words to the tables.

10. The data-processing method according to claim 1 , wherein encryption operations or arithmetical operations are processing steps of cryptographic algorithms, calculation algorithms of hashing functions, or integrity calculation algorithms adapted to receive said code words at input.

11. An electronic circuit comprising an encoding module comprising a processing unit adapted to encrypt data of n bits into code words having a predefined constant Hamming weight and for implementing on said code words encryption operations or arithmetical operations 1 ,

wherein the encryption of each datum (D) comprises:

decomposition of the datum into a plurality of m sequences of bits to be coded, m being strictly less than n,

coding of each sequence of bits into a partial code word having each a predefined Hamming weight, such that a sum of the Hamming weights of the partial code words is equal to the Hamming weight of the code word (M), and concatenation of the partial code words to obtain the code word (M) corresponding to the datum (D),

wherein the data (D) comprise 4 bits, each datum being decomposed into a first sequence of 3 bits, and a second sequence of one bit, the first sequence being coded in a partial code word of 5 bits size and of Hamming weight equal to 2 or 3, and the second sequence of one bit being coded in a partial code word of 2 bits size and Hamming weight equal to 1.

12. The electronic circuit according to claim 11 , wherein the encoding module further comprises data transmission means, and the circuit further comprises:

a decoding module comprising a processing unit adapted to decode a code word transmitted by a first module, and

an error signal generation module, adapted to generate an error signal when the Hamming weight of a code word transmitted by the first module is different to a predefined Hamming weight.

13. A smart card comprising an electronic circuit according to claim 11 .

Assignments (11)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 26, 2025
From: IDEMIA IDENTITY & SECURITY FRANCE
To: IDEMIA FRANCE
Reel/Frame 070632/0157 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ERRONEOUSLY NAMED PROPERTIES 14/366,087 AND 15/001,534 PREVIOUSLY RECORDED ON REEL 048039 FRAME 0605. ASSIGNOR(S) HEREBY CONFIRMS THE CHANGE OF NAME. Recorded Jan 17, 2024
From: MORPHO
To: SAFRAN IDENTITY & SECURITY
Reel/Frame 066343/0143 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ERRONEOUSLY NAMED PROPERTIES 14/366,087 AND 15/001,534 PREVIOUSLY RECORDED ON REEL 047529 FRAME 0948. ASSIGNOR(S) HEREBY CONFIRMS THE CHANGE OF NAME. Recorded Jan 17, 2024
From: SAFRAN IDENTITY & SECURITY
To: IDEMIA IDENTITY & SECURITY
Reel/Frame 066343/0232 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE ERRONEOUSLY NAME PROPERTIES/APPLICATION NUMBERS PREVIOUSLY RECORDED AT REEL: 055108 FRAME: 0009. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 17, 2024
From: SAFRAN IDENTITY & SECURITY
To: IDEMIA IDENTITY & SECURITY FRANCE
Reel/Frame 066365/0151 →
CORRECTIVE ASSIGNMENT TO CORRECT THE THE REMOVE PROPERTY NUMBER 15001534 PREVIOUSLY RECORDED AT REEL: 055314 FRAME: 0930. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 17, 2024
From: SAFRAN IDENTITY & SECURITY
To: IDEMIA IDENTITY & SECURITY FRANCE
Reel/Frame 066629/0638 →
CORRECTIVE ASSIGNMENT TO CORRECT THE APPLICATION NUMBER PREVIOUSLY RECORDED AT REEL: 055108 FRAME: 0009. ASSIGNOR(S) HEREBY CONFIRMS THE CHANGE OF NAME. Recorded Feb 17, 2021
From: SAFRAN IDENTITY AND SECURITY
To: IDEMIA IDENTITY & SECURITY FRANCE
Reel/Frame 055314/0930 →
CORRECTIVE ASSIGNMENT TO CORRECT THE THE RECEIVING PARTY DATA PREVIOUSLY RECORDED ON REEL 047529 FRAME 0948. ASSIGNOR(S) HEREBY CONFIRMS THE CHANGE OF NAME. Recorded Oct 29, 2020
From: SAFRAN IDENTITY AND SECURITY
To: IDEMIA IDENTITY & SECURITY FRANCE
Reel/Frame 055108/0009 →
CORRECTIVE ASSIGNMENT TO CORRECT THE CORRECT ASSIGNEE NAME PREVIOUSLY RECORDED AT REEL: 047529 FRAME: 0948. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 8, 2020
From: SAFRAN IDENTITY & SECURITY
To: IDEMIA IDENTITY & SECURITY FRANCE
Reel/Frame 051521/0307 →
CHANGE OF NAME Recorded Jan 9, 2019
From: MORPHO
To: SAFRAN IDENTITY & SECURITY
Reel/Frame 048039/0605 →
CHANGE OF NAME Recorded Aug 30, 2018
From: SAFRAN IDENTITY & SECURITY
To: IDEMIA IDENTITY & SECURITY
Reel/Frame 047529/0948 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 27, 2015
From: BRINGER, JULIEN; SERVANT, VICTOR
To: MORPHO
Reel/Frame 036438/0438 →