IP Library Granted Patent US 9,722,778
Granted Patent B1
US 9,722,778 · App. 15/219,103 · Granted Aug 1, 2017

Security variable scrambling

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,722,778
App. No.
15/219,103
Granted
Aug 1, 2017
Kind
B1
Abstract

Methods and systems are provided for securing an integrated circuit device against various security attacks, such as side-channel attacks. By limiting the number of different challenge vectors that can be combined with a critical variable of an encryption operation, it becomes more difficult to create enough side channel measurements to successfully perform statistical side-channel analysis.

Claims (32)

1. A method for processing first and second data blocks based on a cryptographic operation, the method comprising:

decrypting, using decryption circuitry, the first data block based on a value of a critical variable used in the cryptographic operation;

after decrypting, using the decryption circuitry, the first data block, updating, using scrambling circuitry, a hash vector based on the second data block;

after updating, using the scrambling circuitry, the hash vector, scrambling, using the scrambling circuitry, the value of the critical variable based on an element of the hash vector to generate a scrambled value of the critical variable; and

decrypting, using the decryption circuitry, the second data block based on the scrambled value of the critical variable.

2. The method of claim 1 , comprising:

after decrypting, using the decryption circuitry, the second data block, scrambling, using the scrambling circuitry, the scrambled value of the critical variable based on a second element of the hash vector to generate another scrambled value of the critical variable; and

decrypting, using the decryption circuitry, a third data block based on the other scrambled value of the critical variable.

3. The method of claim 1 , wherein the critical variable is an encryption key or an intermediate state corresponding to the cryptographic operation.

4. The method of claim 1 , wherein scrambling, using the scrambling circuitry, the value of the critical variable comprises conditionally combining the value of the critical variable with a hidden mask variable, wherein the hidden mask variable is a function of a prior scrambled value of the critical variable.

5. The method of claim 4 , wherein the first data block and the second data block being processed comprises a configuration bitstream.

6. A system for processing data based on a cryptographic operation, the circuit comprising:

decryption circuitry that:

decrypts a first block of the data based at least in part on a value of a critical variable used in a cryptographic operation; and

decrypts a second block of data based at least in part on a scrambled value of the critical variable; and

scrambling circuitry that:

scrambles the value of the critical variable based at least in part on an element of a hash vector to generate the scrambled value of the critical variable by conditionally combining the value of the critical variable with a hidden mask variable, wherein the hidden mask variable is a function of a prior scrambled value of the critical variable.

7. The system of claim 6 , wherein the decryption circuitry comprises a decoder.

8. The system of claim 6 , wherein the decryption circuitry decrypts a third data block based at least in part on a second scrambled value of the critical variable.

9. The system of claim 8 , wherein the scrambling circuitry that scrambles the scrambled value of the critical variable based on a second element of the hash vector to generate the second scrambled value of the critical variable.

10. The system of claim 6 , wherein the critical variable comprises an encryption key or an intermediate state corresponding to the cryptographic operation.

11. The system of claim 6 , wherein the system is part of a programmable logic device.

12. A method for processing data based on a cryptographic operation, the method comprising:

decrypting, using decryption circuitry, a first data block based on a value of a critical variable used in the cryptographic operation;

decrypting, using the decryption circuitry, a second data block based on a first scrambled value of the critical variable;

after decrypting, using the decryption circuitry, the second data block, updating, using scrambling circuitry, a hash vector based on the third data block;

after updating, using the scrambling circuitry, the hash vector, scrambling, using the scrambling circuitry, the value of the critical variable based on an element of the hash vector to generate a second scrambled value of the critical variable; and

decrypting, using the decryption circuitry, a third data block based on the second scrambled value of the critical variable.

13. The method of claim 12 , comprising, after decrypting, using decryption circuitry, the first data block, scrambling, using the scrambling circuitry, the value of the critical variable based on an element of a hash vector to generate the first scrambled value of the critical variable.

14. The method of claim 13 , comprising, prior to scrambling, using the scrambling circuitry, the scrambled value of the critical variable, updating the hash vector based on the second data block.

15. The method of claim 13 , wherein scrambling, using the scrambling circuitry, the value of the critical variable comprises conditionally combining the value of the critical variable with a hidden mask variable, wherein the hidden mask variable is a function of a prior scrambled value of the critical variable.

16. The method of claim 12 , wherein scrambling, using the scrambling circuitry, the value of the critical variable comprises conditionally combining the value of the critical variable with a hidden mask variable, wherein the hidden mask variable is a function of a prior scrambled value of the critical variable.

Assignments (1)
SECURITY INTEREST Recorded Sep 12, 2025
From: ALTERA CORPORATION
To: BARCLAYS BANK PLC, AS COLLATERAL AGENT
Reel/Frame 073431/0309 →