IP Library › Granted Patent US 12,375,263
Granted Patent B2
US 12,375,263 · App. 17/347,369 · Granted Jul 29, 2025

Protection of a cipher algorithm

Inventors: Guillaume Reymond (Luynes, FR); Thomas Sarno (Fuveau, FR)
Assignee: STMICROELECTRONICS (ROUSSET) SAS
H04L9/065H04L2209/046
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,375,263
App. No.
17/347,369
Granted
Jul 29, 2025
Kind
B2
Abstract

A cryptographic device includes hardware data processing circuitry and software data processing circuitry coupled to the hardware data processing circuitry. The device, in operation, executes a plurality of rounds of a symmetrical data cipher algorithm and protects the execution of the plurality of rounds of the symmetrical data cipher algorithm. The protecting includes executing data masking and unmasking operations using the hardware data processing circuitry, executing linear operations applied to data using the software data processing circuitry, executing linear operations applied to masks using the hardware data processing circuitry, and executing non-linear operations applied to data using one of the hardware data processing circuitry or the software data processing circuitry.

Claims (57)

1. A method, comprising:

executing a plurality of rounds of a symmetrical data cipher algorithm using an electronic device, the electronic device including hardware data processing circuitry and software data processing circuitry; and

protecting the execution of the plurality of rounds of the symmetrical data cipher algorithm against attacks during the execution of the plurality of rounds, the protecting including:

executing data masking and unmasking operations using the hardware data processing circuitry;

executing linear operations applied to data using the software data processing circuitry;

executing linear operations applied to masks using the hardware data processing circuitry; and

executing non-linear operations applied to data during rounds of the plurality of rounds using one of the hardware data processing circuitry or the software data processing circuitry, wherein each non-linear operation of the non-linear operations applied to data during a current round of the plurality of rounds is preceded in the current round by a mask refreshment operation implemented using one or more lookup tables.

2. The method of claim 1 , comprising:

applying a linear operation to a mask in parallel with application of a same linear operation to data.

3. The method according to claim 1 , wherein the symmetrical data cipher algorithm employs a data path and a key path, said data masking and unmasking operations, said linear operations applied to data, and said non-linear operations applied to data being operations of the data path.

4. The method according to claim 1 , wherein said data masking and unmasking operations comprise masking operations, unmasking operations, and mask refreshment operations.

5. The method of claim 4 , wherein each non-linear operation is followed by a mask refreshment operation.

6. The method according to claim 4 , wherein each non-linear operation is followed by a masking operation.

7. The method according to claim 4 , wherein each non-linear operation is preceded by an unmasking operation.

8. The method according to claim 1 , wherein each non-linear operation is followed by a masking or unmasking operation.

9. The method according to claim 1 , wherein each non-linear operation is preceded by a masking and unmasking operation.

10. The method according to claim 1 , comprising executing lookup table refreshment operations.

11. The method according to claim 1 , wherein non-linear operations executed by the hardware processing circuitry are executed using one or more lookup tables.

12. The method according to claim 1 , wherein the cipher algorithm is a block cypher algorithm or a stream cypher algorithm.

13. The method according to claim 1 , wherein data masking operations are executed using a logical addition function.

14. The method according to claim 1 , comprising:

in a first round of the plurality of rounds, initializing a lookup table of one or more lookup tables; and

in a second round of the plurality of rounds, refreshing the lookup table prior to performing a mask refreshment operation implemented using the lookup table.

15. A device, comprising:

hardware data processing circuitry; and

software data processing circuitry coupled to the hardware data processing circuitry, wherein the device, in operation:

executes a plurality of rounds of a symmetrical data cipher algorithm; and

protects the execution of the plurality of rounds of the symmetrical data cipher algorithm against attacks during the execution of the plurality of rounds, wherein the protecting includes:

executing data masking and unmasking operations using the hardware data processing circuitry;

executing linear operations applied to data using the software data processing circuitry;

executing linear operations applied to masks using the hardware data processing circuitry; and

executing non-linear operations applied to data during rounds of the plurality of rounds using one of the hardware data processing circuitry or the software data processing circuitry, wherein each non-linear operation of the non-linear operations applied to data during a current round of the plurality of rounds is preceded in the current round by a mask refreshment operation implemented using one or more lookup tables.

16. The device of claim 15 , wherein the protecting includes:

applying a linear operation to a mask in parallel with application of a same linear operation to data.

17. The device according to claim 15 , wherein the symmetrical data cipher algorithm employs a data path and a key path, said data masking and unmasking operations, said linear operations applied to data, and said non-linear operations applied to data being operations of the data path.

18. The device according to claim 15 , wherein said data masking and unmasking operations comprise masking operations, unmasking operations, and mask refreshment operations.

19. The device of claim 18 , wherein each non-linear operation is followed by a mask refreshment operation.

20. The device according to claim 18 , wherein each non-linear operation is preceded by an unmasking operation.

21. The device according to claim 18 , wherein said mask refreshment operations are implemented using one or more lookup tables.

22. The device according to claim 18 , wherein non-linear operations executed by the hardware processing circuitry are executed using one or more lookup tables.

23. A system, comprising:

an application processor; and

cryptographic circuitry coupled to the application processor and including hardware processing circuitry and software processing circuitry, wherein the cryptographic circuitry, in operation:

executes a plurality of rounds of a symmetrical data cipher algorithm; and

protects the execution of the plurality of rounds of the symmetrical data cipher algorithm against software attacks during the execution of the plurality of rounds, wherein the protecting includes:

executing data masking and unmasking operations using the hardware processing circuitry;

executing linear operations applied to data using the software processing circuitry;

executing linear operations applied to masks using the hardware processing circuitry; and

executing non-linear operations applied to data during rounds of the plurality of rounds using one of the hardware processing circuitry or the software processing circuitry, wherein each non-linear operation of the non-linear operations applied to data during a current round of the plurality of rounds is preceded in the current round by a mask refreshment operation implemented using one or more lookup tables.

24. The system of claim 23 , wherein the protecting includes:

applying a linear operation to a mask in parallel with application of a same linear operation to data.

25. The system according to claim 23 , wherein the symmetrical data cipher algorithm employs a data path and a key path, said data masking and unmasking operations, said linear operations applied to data, and said non-linear operations applied to data being operations of the data path.

26. The system according to claim 23 , wherein said data masking and unmasking operations comprise masking operations, unmasking operations, and mask refreshment operations.

27. The system according to claim 23 , wherein the hardware processing circuitry comprises one or more lookup tables.

28. The system according to claim 27 , wherein:

in a first round of the plurality of rounds, a lookup table of one or more lookup tables is initialized; and

in a second round of the plurality of rounds, the lookup table is refreshed prior to a mask refreshment operation implemented using the lookup table.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 29, 2021
From: REYMOND, GUILLAUME; SARNO, THOMAS
To: STMICROELECTRONICS (ROUSSET) SAS
Reel/Frame 056702/0050 →
Priority Claims (1)
FR 2006277 · Jun 16, 2020 · national
Continuity (1)
Related Publication 20210391977A1 · Dec 16, 2021
References Cited (11)
US 20130132706A1 · Trichina · 2013 [cited by examiner]
US 20150098564A1 · Chamley · 2015 [cited by examiner]
US 20160269175A1 · Cammarota · 2016 [cited by examiner]
US 20180089467A1 · Pedersen · 2018 [cited by examiner]
US 20180167196A1 · Cooper · 2018 [cited by examiner]
US 20190296898A1 · De Mulder · 2019 [cited by examiner]
US 20200322127A1 · Lozac'h · 2020 [cited by examiner]
CN 108369784A · 2018 [cited by applicant]
WO WO2004070510A2 · 2004 [cited by examiner]
Y. Wang and Y. Ha, “A Performance and Area Efficient ASIP for Higher-Order DPA-Resistant AES,” in IEEE Journal on Emerging and Selected Topics in Circuits and Systems, vol. 4, No. 2, pp. 190-202, Jun. 2014, doi: 10.1109… [cited by examiner]
Wang et al., “A Performance and Area Efficient ASIP for Higher-order DPA-resistant AES,” [cited by applicant]