IP Library Granted Patent US 10,263,768
Granted Patent B2
US 10,263,768 · App. 15/354,016 · Granted Apr 16, 2019

Protection of a calculation against side-channel attacks

Inventor: Yannick Teglia (Belcodene, FR)
Assignee: STMicroelectronics (Rousset) SAS
H04L9/0618H04L9/002H04L9/003H04L9/0869H04L9/3066
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,263,768
App. No.
15/354,016
Granted
Apr 16, 2019
Kind
B2
Abstract

A method for protecting a ciphering algorithm executing looped operations on bits of a first quantity and on a first variable initialized by a second quantity, wherein, for each bit of the first quantity, a random number is added to the state of this bit to update a second variable maintained between two thresholds.

Claims (34)

1. A method, comprising:

executing, using a cryptographic circuit, a ciphering algorithm including executing looped operations on bits of a first quantity and on a first variable initialized by a second quantity; and

protecting, using the cryptographic circuit, the ciphering algorithm during execution of the looped operations, the protecting including, for each bit of the first quantity, updating a second variable maintained between two thresholds, wherein the updated second variable has a value which is a function of a random number and a state of the bit of the first quantity and the second variable represents a random-number drift introduced during executions of the looped operations.

2. The method of claim 1 wherein said second variable is used in one of plural operations performed for each bit of the first quantity.

3. The method of claim 1 wherein the random number is drawn for each bit of the first quantity.

4. The method of claim 1 , comprising, after updating the second variable for each bit of the first quantity, updating the first variable by a calculation taking into account said second variable and the second quantity.

5. The method of claim 1 wherein the second variable includes no more than 8 bits.

6. The method of claim 2 wherein said plural operations comprise an addition and a doubling, said second variable being taken into account during the addition.

7. The method of claim 6 wherein the executing includes multiplying a point of an elliptic curve by a scalar number, said scalar number representing the first quantity and said point representing the second quantity.

8. The method of claim 2 wherein said plural operations comprise a squaring and a multiplication, said second variable being taken into account in the multiplication.

9. The method of claim 8 wherein the executing includes performing a modular exponentiation of the second quantity, the first quantity representing an exponent of the modular exponentiation of the second quantity.

10. A device, comprising:

one or more memories; and

cryptographic circuitry, which, in operation:

executes a ciphering algorithm including executing looped operations on bits of a first quantity and on a first variable initialized by a second quantity; and

protects execution of the ciphering algorithm during execution of the looped operations, the protecting including, for each bit of the first quantity, maintaining a second variable between two thresholds during an execution of a looped operation, the maintained second variable having a value which is a function of a random number and a state of the bit of the first quantity, wherein the second variable represents a random-number drift introduced during executions of the looped operations.

11. The device of claim 10 wherein said second variable is used in one of plural operations performed for each bit of the first quantity.

12. The device of claim 11 wherein said plural operations comprise an addition and a doubling, said second variable being taken into account during the addition.

13. The device of claim 12 wherein the executing includes multiplying a point of an elliptic curve by a scalar number, said scalar number representing the first quantity and said point representing the second quantity.

14. The device of claim 11 wherein said plural operations comprise a squaring and a multiplication, said second variable being taken into account in the multiplication.

15. The device of claim 14 wherein the executing includes performing a modular exponentiation of the second quantity, the first quantity representing an exponent of the modular exponentiation of the second quantity.

16. A system, comprising:

one or more memories;

one or more processing circuits; and

cryptographic circuitry, which, in operation:

executes a ciphering algorithm including executing looped operations on bits of a first quantity and on a first variable initialized by a second quantity; and

protects execution of the ciphering algorithm during execution of the looped operations, the protecting including, for each bit of the first quantity, maintaining a second variable between two thresholds during an execution of a looped operation, the maintained second variable having a value which is a function of a random number and a state of the bit of the first quantity, wherein the second variable represents a random-number drift introduced during executions of the looped operations.

17. The system of claim 16 wherein one of the one or more processing circuits includes the cryptographic circuitry.

18. The system of claim 16 wherein the combining the random number and the state of the bit of the first quantity comprises subtracting the state of the bit of the first quantity from the random number.

19. The method of claim 1 wherein the combining the random number and the state of the bit of the first quantity comprises subtracting the state of the bit of the first quantity from the random number.

20. The device of claim 10 wherein the combining the random number and the state of the bit of the first quantity comprises subtracting the state of the bit of the first quantity from the random number.

21. The method of claim 1 wherein the ciphering algorithm is an encryption algorithm.

22. The device of claim 10 wherein the ciphering algorithm is an encryption algorithm.

23. The system of claim 16 wherein the ciphering algorithm is an encryption algorithm.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 10, 2023
From: STMICROELECTRONICS (ROUSSET) SAS
To: STMICROELECTRONICS INTERNATIONAL N.V.
Reel/Frame 063282/0118 →
Priority Claims (1)
FR 13 58271 · Aug 29, 2013 · national
Continuity (2)
Continuation 14470861 · Aug 27, 2014
Related Publication 20170070341A1 · Mar 9, 2017