IP Library › Granted Patent US 12,500,738
Granted Patent B2
US 12,500,738 · App. 17/948,017 · Granted Dec 16, 2025

Protection of cryptographic substitution-permutation networks from fault injection attacks

Inventors: Michael Alexander Hamburg (Laguna Beach, CA); Helena Handschuh (Palo Alto, CA); Mark Evan Marson (Carlsbad, CA); Winthrop John Wu (Pleasanton, CA)
Assignee: Cryptography Research, Inc.
H04L9/0631
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,500,738
App. No.
17/948,017
Granted
Dec 16, 2025
Kind
B2
Abstract

Aspects of the present disclosure involve a method and a system to perform the method to obtain a cryptographic output of a plurality of rounds of a cipher, by performing a plurality of modified rounds of the cipher, each of the modified rounds computing an unmasking transform, an operation of a respective round of the cipher, and a masking transform, the unmasking transform being an inverse of the masking transform of a previous round of the cipher.

Claims (53)

1 . A method to process an input into a substitution-permutation network (SPN) cipher, wherein the input into the SPN cipher comprises at least one of a plaintext input or a ciphertext input, the method comprising:

selecting a plurality of masking transforms, each masking transform of the plurality of masking transforms associated with a respective round of a plurality of rounds of the SPN cipher;

performing, by a processing device, a plurality of modified rounds of the SPN cipher, wherein each of the plurality of modified rounds computes a composite operation comprising:

an unmasking transform,

an operation of a respective round of the plurality of rounds of the SPN cipher, and

a masking transform,

wherein the unmasking transform comprises an inverse of the masking transform of a previous modified round of the plurality of modified rounds of the SPN cipher; and

obtaining an output of the SPN cipher using an output of a final modified round of the plurality of modified rounds, wherein the output of the SPN cipher comprises at least one of a ciphertext output or a plaintext output.

2 . The method of claim 1 , wherein the masking transform of the final modified round comprises an identity transform.

3 . The method of claim 1 , wherein the masking transform of a first modified round of the plurality of modified rounds is different from the masking transform of a second modified round of the plurality of modified rounds.

4 . The method of claim 1 , wherein an input into a second modified round of the plurality of modified rounds is based on i) an output of a first modified round of the plurality of modified rounds and ii) a key for the second modified round masked using the masking transform of the first modified round.

5 . The method of claim 1 , wherein the masking transform is a linear affine transform.

6 . The method of claim 5 , wherein the linear affine transform comprises a multiplication or division by an element of Galois Field GF (2 n ), wherein n is a number of bits of data input into each of the plurality of rounds of the cipher.

7 . A method to determine a ciphertext output of a substitution-permutation network (SPN) cipher, the method comprising:

masking, by a processing device, a plaintext input into the SPN cipher using a first masking matrix, wherein the first masking matrix comprises a first power of a base masking matrix;

performing a first composite operation that comprises:

a multiplication by an inverse of the first masking matrix,

an operation of a first round of a plurality of rounds of the SPN cipher, and

a multiplication by a second masking matrix, wherein the second masking matrix comprises a second power of the base masking matrix; and

obtaining the ciphertext output of the SPN cipher based on an output of the first composite operation.

8 . The method of claim 7 , wherein obtaining the ciphertext output based on the output of the first composite operation further comprises:

adding a key, obtained for a second round of a plurality of rounds of the cipher, to the output of the first composite operation to obtain an input into a second composite operation;

performing the second composite operation that comprises:

a multiplication by an inverse of the second masking matrix,

an operation of a second round of the plurality of rounds of the cipher, and

a multiplication by a third masking matrix different from the second masking matrix; and

obtaining the ciphertext output based on an output of the second composite operation.

9 . The method of claim 8 , wherein the key is masked by the second masking matrix.

10 . The method of claim 8 , wherein the key is masked by a key masking matrix, the method further comprising:

prior to performing the second composite operation, multiplying the input into the second composite operation by an inverse matrix of a product of the second masking matrix and the key masking matrix.

11 . The method of claim 8 , wherein adding the key is performed using an XOR addition.

12 . The method of claim 8 , wherein performing the first composite operation comprises adding a masking vector to an intermediate output of a portion of the first composite operation, and wherein the key is modified in view of the masking vector.

13 . The method of claim 8 , further comprising:

computing the second masking matrix using multiplication of the first masking matrix by a step matrix; and

computing the third masking matrix using multiplication of the second masking matrix by the step matrix.

14 . The method of claim 13 , further comprising:

performing a plurality of composite operations comprising the first composite operation and the second composite operation, wherein at least one of the plurality of composite operations comprises a multiplication by a masking matrix that is an inverse of the step matrix.

15 . The method of claim 7 , wherein an input into the first composite operation is masked by the first masking matrix.

16 . The method of claim 7 , wherein the first masking matrix was obtained during determination of a previous ciphertext output of the cipher, the previous ciphertext output of the cipher determined before the ciphertext output of the cipher.

17 . The method of claim 7 , further comprising computing a square of the first masking matrix.

18 . A system comprising:

a memory device; and

a processing device communicatively coupled to the memory device, wherein the processing device is configured to process an input into a substitution-permutation network (SPN) cipher, by performing operations comprising:

selecting a plurality of masking transforms, each masking transform of the plurality of masking transforms associated with a respective round of a plurality of rounds of the SPN cipher;

performing a plurality of modified rounds of the SPN cipher, wherein each of the plurality of modified rounds computes a composite operation comprising:

an unmasking transform,

an operation of a respective round of the plurality of rounds of the SPN cipher, and

a masking transform,

wherein the unmasking transform comprises an inverse of the masking transform of a previous modified round of the plurality of modified rounds of the cipher; and

obtaining an output of the SPN cipher using an output of a final modified round of the plurality of modified rounds, wherein the output of the SPN cipher comprises at least one of a ciphertext output or a plaintext output.

19 . The system of claim 18 , wherein the masking transform of the final modified round comprises an identity transform.

20 . The system of claim 18 , wherein the masking transform of a first modified round of the plurality of modified rounds is different from the masking transform of a second modified round of the plurality of modified rounds.

21 . The system of claim 18 , wherein an input into a second modified round of the plurality of modified rounds is based on i) an output of a first modified round of the plurality of modified rounds and ii) a key for the second modified round masked using the masking transform of the first modified round.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 20, 2022
From: HAMBURG, MICHAEL ALEXANDER; HANDSCHUH, HELENA; MARSON, MARK EVAN; WU, WINTHROP JOHN
To: CRYPTOGRAPHY RESEARCH, INC.
Reel/Frame 061156/0232 →
Continuity (2)
Provisional Application 63261396 · Sep 20, 2021
Related Publication 20230093306A1 · Mar 23, 2023
References Cited (10)
US 8565421B1 · Bhooma · 2013 [cited by applicant]
US 9509495B2 · Lee et al. · 2016 [cited by applicant]
US 9565018B2 · Farrugia et al. · 2017 [cited by applicant]
US 20080253557A1 · Dottax · 2008 [cited by examiner]
US 20140348323A1 · Chevallier-Mames · 2014 [cited by examiner]
US 20160269175A1 · Cammarota · 2016 [cited by examiner]
US 20180097618A1 · Kumar · 2018 [cited by examiner]
US 20190305930A1 · Bauer · 2019 [cited by applicant]
US 20210391977A1 · Reymond · 2021 [cited by examiner]
Chou et al. Title: “: A High Performance, Low Energy, Compact Masked 128-Bit AES in 22nm CMOS Technology”, Date: 2019; Published in: 2019 International Symposium on VLSI Design, Automation and Test (VLSI-DAT) (2019, pp.… [cited by examiner]