Software protection against differential fault analysis
An encryption module and method for performing an encryption/decryption process executes two cryptographic operations in parallel in multiple stages. The two cryptographic operations are executed such that different rounds of the two cryptographic operations are performed in parallel by the same instruction or the same finite state machine (FSM) state for hardware implementation.
1. A method for performing an encryption/decryption process, the method comprising:
executing multiple rounds of a first cryptographic operation of the encryption/decryption process on a first block of input data in multiple stages; and
executing multiple rounds of a second cryptographic operation of the encryption/decryption process on a second block of input data in the multiple stages,
wherein the first cryptographic operation on the first block of input data is performed in parallel with the second cryptographic operation on the second block of input data but with one of the first and second cryptographic operations being at least one round late with respect to the other operation such that different rounds of the first and second cryptographic operations are performed in parallel at a same time by one of a same instruction and a same finite state machine (FSM) state.
2. The method of claim 1 , wherein the first cryptographic operation on the first block of input data is performed in parallel with the second cryptographic operation on the second block of input data such that i round of the first cryptographic operation and i−1 round of the second cryptographic operation are performed at a same time_during at least one of the multiple stages.
3. The method of claim 2 , wherein the first cryptographic operation on the first block of input data is performed in parallel with the second cryptographic operation on the second block of input data such that a first round of the first cryptographic operation and none of the rounds of the second cryptographic operation are performed during a first stage of the multiple stages.
4. The method of claim 3 , wherein the first cryptographic operation on the first block of input data is performed in parallel with the second cryptographic operation on the second block of input data such that none of the rounds of the first cryptographic operation and the last round of the second cryptographic operation are performed during a final stage of the multiple stages.
5. The method of claim 1 , wherein the first and second blocks of input data are sixteen (16) bits.
6. The method of claim 1 , wherein the first and second blocks of input data are eight (8) bits.
7. The method of claim 1 , wherein each of the first and second cryptographic operations includes ten (10) rounds.
8. A non-transitory computer-readable storage medium containing program instructions for performing an encryption/decryption process, wherein execution of the program instructions by one or more processors of a computer system causes the one or more processors to perform steps comprising:
executing multiple rounds of a first cryptographic operation of the encryption/decryption process on a first block of input data in multiple stages; and
executing multiple rounds of a second cryptographic operation of the encryption/decryption process on a second block of input data in the multiple stages,
wherein the first cryptographic operation on the first block of input data is performed in parallel with the second cryptographic operation on the second block of input data but with one of the first and second cryptographic operations being at least one round late with respect to the other operation such that different rounds of the first and second cryptographic operations are performed in parallel at a same time by one of a same instruction and a same finite state machine (FSM) state.
9. The computer-readable storage medium of claim 8 , wherein the first cryptographic operation on the first block of input data is performed in parallel with the second cryptographic operation on the second block of input data such that i round of the first cryptographic operation and i−1 round of the second cryptographic operation are performed at a same time during at least one of the multiple stages.
10. The computer-readable storage medium of claim 9 , wherein the first cryptographic operation on the first block of input data is performed in parallel with the second cryptographic operation on the second block of input data such that a first round of the first cryptographic operation and none of the rounds of the second cryptographic operation are performed during a first stage of the multiple stages.
11. The computer-readable storage medium of claim 10 , wherein the first cryptographic operation on the first block of input data is performed in parallel with the second cryptographic operation on the second block of input data such that none of the rounds of the first cryptographic operation and the last round of the second cryptographic operation are performed during a final stage of the multiple stages.
12. The computer-readable storage medium of claim 8 , wherein the first and second blocks of input data are sixteen (16) bits.
13. The computer-readable storage medium of claim 8 , wherein the first and second blocks of input data are eight (8) bits.
14. The computer-readable storage medium of claim 8 , wherein each of the first and second cryptographic operations includes ten (10) rounds.
15. An apparatus comprising: memory;
a register;
a finite state machine (FSM); and an arithmetic logic unit,
wherein the arithmetic logic unit is configured to execute multiple rounds of a first cryptographic operation of the encryption/decryption process on a first block of input data in multiple stages and execute multiple rounds of a second cryptographic operation of the encryption/decryption process on a second block of input data in the multiple stages, and wherein the arithmetic logic unit is further configured so that the first cryptographic operation on the first block of input data is performed in parallel with the second cryptographic operation on the second block of input data but with one of the first and second cryptographic operations being at least one round late with respect to the other operation such that different rounds of the first and second cryptographic operations are performed in parallel at a same time by one of a same instruction and a same finite state machine (FSM) state.
16. The apparatus of claim 15 , wherein the arithmetic logic unit is configured so that the first cryptographic operation on the first block of input data is performed in parallel with the second cryptographic operation on the second block of input data such that i round of the first cryptographic operation and i−1 round of the second cryptographic operation are performed at a same time during at least one of the multiple stages.
17. The apparatus of claim 16 , wherein the arithmetic logic unit is configured so that the first cryptographic operation on the first block of input data is performed in parallel with the second cryptographic operation on the second block of input data such that a first round of the first cryptographic operation and none of the rounds of the second cryptographic operation are performed during a first stage of the multiple stages.
18. The apparatus of claim 17 , wherein the arithmetic logic unit is configured so that the first cryptographic operation on the first block of input data is performed in parallel with the second cryptographic operation on the second block of input data such that none of the rounds of the first cryptographic operation and the last round of the second cryptographic operation are performed during a final stage of the multiple stages.
19. The apparatus of claim 17 , wherein the first and second blocks of input data are sixteen (16) bits.
20. The apparatus of claim 17 , wherein each of the first and second cryptographic operations includes ten (10) rounds.