IP Library Granted Patent US 12,488,089
Granted Patent B2
US 12,488,089 · App. 18/103,563 · Granted Dec 2, 2025

Trusted Execution Environment side-channel protection method

Inventor: Lukas Hänel (Valbonne, FR)
Assignee: Trustonic Limited
G06F21/53G06F9/5066G06F21/602
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,488,089
App. No.
18/103,563
Granted
Dec 2, 2025
Kind
B2
Abstract

A method for protecting a cryptographic operation on a device from a side-channel attack, the device comprising a processor operable to execute a rich execution environment (REE) and a trusted execution environment (TEE), the method comprising: receiving, at the TEE, a request to perform a cryptographic operation, wherein the cryptographic operation is divisible into a plurality of chunks; issuing, by the TEE, a command to control a characteristic of a core of the processor on which the TEE is to be executed on upon subsequent invocation of the TEE; verifying, by the TEE upon subsequent invocation of the TEE, that the characteristic of the core on which the TEE is executing on corresponds to the command; and responsive to a positive verification, performing, by the TEE, the cryptographic operation on one or more chunks of the plurality of chunks.

Claims (35)

1 . A method for protecting a cryptographic operation on a device from a side-channel attack, the device comprising a processor including processing circuitry configured to execute a rich execution environment (REE) and a trusted execution environment (TEE), the method comprising:

receiving, at the TEE, a request to perform a cryptographic operation, wherein the cryptographic operation is divisible into a plurality of chunks;

issuing, by the TEE, a command to control a characteristic of a core of the processor on which the TEE is to be executed on upon subsequent invocation of the TEE;

verifying, by the TEE upon subsequent invocation of the TEE, that the characteristic of the core on which the TEE is executing on corresponds to the command; and

responsive to a positive verification, performing, by the TEE, the cryptographic operation on one or more chunks of the plurality of chunks,

wherein the command instructs a clock frequency for the core on which the TEE is to be executed on upon subsequent invocation of the TEE, and

wherein the verification comprises measuring a duration of how long the cryptographic operation takes to complete for one or more chunks of the plurality of chunks and checking that the duration is consistent with the TEE executing at the clock frequency.

2 . The method of claim 1 , wherein upon receipt of the request the TEE divides the cryptographic operation into the plurality of chunks.

3 . The method of claim 1 , wherein the one or more chunks comprise two or more chunks and wherein responsive to a positive verification the cryptographic operation is iteratively performed on each chunk of the two or more chunks of the plurality of chunks.

4 . The method of claim 1 , wherein the one or more chunks are a predetermined number of chunks.

5 . The method of claim 1 , wherein subsequent to issuing the command, the TEE suspends execution of the cryptographic operation until subsequent invocation of the TEE.

6 . The method of claim 1 , wherein the processor is a multicore processor and wherein the command instructs that the TEE is to be executed on a specific core of the multicore processor upon subsequent execution of the TEE.

7 . The method of claim 6 , wherein the specific core is chosen at random.

8 . The method of claim 6 , wherein the multicore processor is a heterogeneous multicore processor comprising one or more lower performance cores and one or more higher performance cores and wherein the specific core is chosen to be one of the one or more higher performance cores.

9 . The method of claim 8 , wherein the verification comprises measuring a duration of how long the cryptographic operation takes to complete for one or more chunks of the plurality of chunks and checking that the duration is consistent with the TEE executing on a higher performance core.

10 . The method of claim 9 , wherein the duration is measured using a trusted time source.

11 . The method of claim 9 , wherein the duration is measured by the TEE scheduling two secure interrupts at a temporal separation corresponding to the duration length.

12 . The method of claim 1 , wherein the clock frequency is a minimum clock frequency.

13 . The method of claim 1 , further comprising, responsive to a negative verification, preventing cryptographic operations from being performed, and/or terminating the TEE.

14 . The method of claim 1 , wherein the verifying step is a first verifying step, the method further comprising:

a second verifying step, the second verifying step being performed by the TEE subsequent to the first verifying step and verifying that the characteristic of the core on which the TEE is executing on corresponds to the command; and

responsive to positive verification by the second verification step, performing, by the TEE, the cryptographic operation on one or more chunks of the plurality of chunks.

15 . The method of claim 1 , further comprising, responsive to a negative verification, modifying the cryptographic operation to include errors in its output.

16 . The method of claim 1 , wherein the issuing step is a first issuing step and the command is a first command, the method further comprising:

a second issuing step, the second issuing step being performed subsequent to the first issuing step and issuing a second command, wherein the second command commands a characteristic of the core on which the TEE is to be executed on upon subsequent invocation of the TEE which are different from those commanded by the first command.

17 . A non-transitory, computer-readable storage medium storing a computer program for controlling an electronic device to perform the method of claim 1 .

18 . A device comprising:

a processor including processing circuitry configured to execute a rich execution environment (REE) and a trusted execution environment (TEE);

data storage storing at least one computer program that when executed by the processor controls the processor to protect a cryptographic operation on the device from a side-channel attack by;

receiving, at the TEE, a request to perform a cryptographic operation, wherein the cryptographic operation is divisible into a plurality of chunks;

issuing, by the TEE, a command to control a characteristic of a core of the processor on which the TEE is to be executed on upon subsequent invocation of the TEE;

verifying, by the TEE upon subsequent invocation of the TEE, that the characteristic of the core on which the TEE is executing on corresponds to the command; and

responsive to a positive verification, performing, by the TEE, the cryptographic operation on one or more chunks of the plurality of chunks,

wherein the command instructs a clock frequency for the core on which the TEE is to be executed on upon subsequent invocation of the TEE, and

wherein the verification comprises measuring a duration of how long the cryptographic operation takes to complete for one or more chunks of the plurality of chunks and checking that the duration is consistent with the TEE executing at the clock frequency.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 20, 2026
From: TT SECURE PLATFORM LIMITED
To: QUALCOMM TECHNOLOGIES, INC.
Reel/Frame 075332/0723 →
CHANGE OF ASSIGNEE ADDRESS Recorded Apr 14, 2023
From: TRUSTONIC LIMITED
To: TRUSTONIC LIMITED
Reel/Frame 064025/0775 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 31, 2023
From: HÄNEL, LUKAS
To: TRUSTONIC LIMITED
Reel/Frame 062567/0931 →
Priority Claims (1)
GB 2201267 · Feb 1, 2022 · national
Continuity (1)
Related Publication 20230244781A1 · Aug 3, 2023
References Cited (22)
US 9177153B1 · Perrig · 2015 [cited by examiner]
US 9824225B1 · Polansky · 2017 [cited by examiner]
US 10372422B2 · Ono · 2019 [cited by examiner]
US 10802885B2 · Lee · 2020 [cited by examiner]
US 11392405B2 · Liu · 2022 [cited by examiner]
US 12212568B1 · Chandrashekar · 2025 [cited by examiner]
US 20190042747A1 · Sukhomlinov · 2019 [cited by examiner]
US 20190297084A1 · Li · 2019 [cited by examiner]
US 20200151305A1 · Lam · 2020 [cited by examiner]
US 20200226248A1 · Shamis · 2020 [cited by examiner]
US 20200366653A1 · Caceres · 2020 [cited by examiner]
US 20210044575A1 · Kong · 2021 [cited by examiner]
US 20210081575A1 · Saileshwar · 2021 [cited by examiner]
US 20210144170A1 · Ganapathy · 2021 [cited by examiner]
US 20210200882A1 · Maor · 2021 [cited by examiner]
US 20210365566A1 · Souissi · 2021 [cited by examiner]
US 20220075901A1 · Fanara · 2022 [cited by examiner]
US 20220129542A1 · Sun · 2022 [cited by examiner]
US 20220138286A1 · Zage · 2022 [cited by examiner]
US 20220188418A1 · Aschauer · 2022 [cited by examiner]
US 20230092152A1 · Shwartz · 2023 [cited by examiner]
US 20240095362A1 · Zhang · 2024 [cited by examiner]