IP Library Granted Patent US 12,316,774
Granted Patent B2
US 12,316,774 · App. 17/960,734 · Granted May 27, 2025

Information leakage mitigation associated with elliptic curve operations

Inventor: Hoon Choi (Mountain View, CA)
Assignee: Lattice Semiconductor Corporation
H04L9/3252H04L9/0825H04L9/3066
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,316,774
App. No.
17/960,734
Granted
May 27, 2025
Kind
B2
Abstract

Various techniques are provided to implement information leakage mitigation associated with elliptic curve operations. In one example, a method includes generating second data based on first data. The first data is associated with a message. The second data is associated with a decoy message. The method further includes performing a first elliptic curve operation based on the first data. The method further includes performing a second elliptic curve operation based on the second data. The first elliptic curve operation and the second elliptic curve operation are performed in a random order. Related systems and devices are provided.

Claims (42)

1. A method comprising:

generating second data based on first data, wherein the first data is associated with a message, wherein the second data is associated with a first decoy message, wherein the first data comprises a private key and the message, and wherein the second data comprises a first decoy private key and the first decoy message;

generating third data based on the first data, wherein the third data comprises a second decoy private key and a second decoy message;

performing a first elliptic curve operation based on the first data;

performing a second elliptic curve operation based on the second data; and

performing a third elliptic curve operation based on the third data, wherein the first elliptic curve operation, the second elliptic curve operation, and the third elliptic curve operation are performed in a random order.

2. The method of claim 1 , further comprising generating one or more random numbers, wherein the random order to perform the first elliptic curve operation, the second elliptic curve operation, and the third elliptic curve operation is based on the one or more random numbers.

3. The method of claim 1 , wherein the generating the second data comprises deterministically deriving the second data from the first data.

4. The method of claim 3 , wherein the deterministically deriving comprises:

applying a hash function to the message to obtain the first decoy message; and/or

applying a hash function to the private key to obtain the first decoy private key.

5. The method of claim 3 , wherein the first elliptic curve operation comprises a first elliptic curve digital signature algorithm (ECDSA) signing operation to sign the message, and wherein the second elliptic curve operation comprises a second ECDSA signing operation to sign the first decoy message.

6. The method of claim 5 , wherein the first ECDSA signing operation comprises an elliptic curve multiplication of a nonce and an elliptic curve base point, wherein the first ECDSA signing operation is performed to obtain a signature, and wherein the signature is based on the message and the private key.

7. The method of claim 6 , wherein the second ECDSA signing operation comprises an elliptic curve multiplication of a decoy nonce and an elliptic curve base point, wherein the second ECDSA signing operation is performed to obtain a decoy signature, and wherein the decoy signature is based on the first decoy message and one of the first decoy private key or the private key.

8. The method of claim 1 , wherein the first elliptic curve operation comprises a first elliptic curve integrated encryption scheme (ECIES) decryption operation to decrypt encrypted data to obtain the message, and wherein the second elliptic curve operation comprises a second ECIES decryption operation to decrypt encrypted data to obtain the first decoy message.

9. The method of claim 8 , wherein the first data further comprises an ephemeral public key, wherein the second data further comprises a decoy ephemeral public key deterministically derived from the ephemeral public key, wherein the first ECIES decryption operation comprises an elliptic curve multiplication operation of the private key and the ephemeral public key, and wherein the second ECIES decryption operation comprises an elliptic curve multiplication operation of the decoy ephemeral public key and one of the private key or the first decoy private key.

10. The method of claim 1 , wherein the first data further comprises an ephemeral public key, wherein the second data further comprises a first decoy ephemeral public key, and wherein the third data further comprises a second decoy ephemeral public key.

11. A non-transitory machine readable storage medium including machine readable instructions which, when executed, cause one or more processors of a device to perform the method of claim 1 .

12. A system comprising:

one or more processors; and

a non-transitory machine-readable medium comprising instructions stored therein, which when executed by the one or more processors, cause the one or more processors to perform operations, wherein the operations comprise:

generating second data based on first data, wherein the generating comprises deterministically deriving the second data from the first data, wherein the first data is associated with a message, wherein the second data is associated with a decoy message, wherein the first data comprises a private key and the message,

wherein the second data comprises a decoy private key and the decoy message, and

wherein the deterministically deriving comprises:

applying a hash function to the message to obtain the decoy message;

and/or

applying a hash function to the private key to obtain the decoy private key;

performing a first elliptic curve operation based on the first data; and

performing a second elliptic curve operation based on the second data, wherein the first elliptic curve operation and the second elliptic curve operation are performed in a random order.

13. The system of claim 12 , wherein the operations further comprise generating a random number that indicates the random order to perform the first elliptic curve operation and the second elliptic curve operation.

14. The system of claim 12 , wherein the first elliptic curve operation comprises a first elliptic curve digital signature algorithm (ECDSA) signing operation performed to obtain a signature, wherein the signature is based on the message and the private key, wherein the second elliptic curve operation comprises a second ECDSA signing operation performed to obtain a decoy signature, and wherein the decoy signature is based on the decoy message and the decoy private key.

15. A system comprising:

one or more processors; and

a non-transitory machine-readable medium comprising instructions stored therein, which when executed by the one or more processors, cause the one or more processors to perform operations, wherein the operations comprise:

generating second data based on first data, wherein the first data is associated with a message, wherein the second data is associated with a decoy message, wherein the first data comprises a private key and an ephemeral public key, and wherein the second data comprises a decoy private key and a decoy ephemeral public key;

performing a first elliptic curve operation based on the first data, wherein the first elliptic curve operation comprises a first elliptic curve integrated encryption scheme (ECIES) decryption operation to decrypt encrypted data to obtain the message, wherein the first ECIES decryption operation comprises an elliptic curve multiplication operation of the private key and the ephemeral public key;

performing a second elliptic curve operation based on the second data, wherein the second elliptic curve operation comprises a second ECIES decryption operation to decrypt encrypted data to obtain the decoy message, wherein the second ECIES decryption operation comprises an elliptic curve multiplication operation of the decoy private key and the decoy ephemeral public key, and wherein the first elliptic curve operation and the second elliptic curve operation are performed in a random order.

16. The system of claim 15 , wherein the operations further comprise generating a random number that indicates the random order to perform the first elliptic curve operation and the second elliptic curve operation.

17. The system of claim 15 , wherein the operations further comprise:

generating third data based on the first data; and

performing a third elliptic curve operation based on the third data, wherein the first elliptic curve operation, the second elliptic curve operation, and the third elliptic curve operation are performed in a random order.

18. The system of claim 15 , wherein the decoy ephemeral public key is deterministically derived from the ephemeral public key.

Assignments (2)
SECURITY INTEREST Recorded Jul 2, 2026
From: LATTICE SEMICONDUCTOR CORPORATION
To: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS ADMINISTRATIVE AGENT
Reel/Frame 075892/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 1, 2024
From: CHOI, HOON
To: LATTICE SEMICONDUCTOR CORPORATION
Reel/Frame 068155/0789 →
Continuity (3)
Continuation PCTUS2021025834 · Apr 5, 2021
Provisional Application 63006010 · Apr 6, 2020
Related Publication 20230044442A1 · Feb 9, 2023
References Cited (14)
US 7418099B2 · Vanstone · 2008 [cited by examiner]
US 8472619B1 · Trimberger · 2013 [cited by applicant]
US 12113778B2 · Mulayin · 2024 [cited by examiner]
US 20110185177A1 · Spalka · 2011 [cited by examiner]
US 20120324242A1 · Kirsch · 2012 [cited by examiner]
US 20130269032A1 · Chasko et al. · 2013 [cited by applicant]
US 20150188713A1 · Rombouts et al. · 2015 [cited by applicant]
US 20170098089A1 · Stewart · 2017 [cited by examiner]
US 20190205507A1 · Antonatos · 2019 [cited by examiner]
US 20190245681A1 · Alwen · 2019 [cited by applicant]
US 20200028694A1 · Zaverucha · 2020 [cited by applicant]
US 20200314647A1 · Wang · 2020 [cited by examiner]
US 20210028946A1 · Scott · 2021 [cited by examiner]
US 20220248221A1 · Nix · 2022 [cited by examiner]