IP Library Granted Patent US 8,705,731
Granted Patent B2
US 8,705,731 · App. 13/111,421 · Granted Apr 22, 2014

Selection of a lookup table with data masked with a combination of an additive and multiplicative mask

Inventor: Elena Vasilievna Trichina (Munich, DE)
Assignee: Spansion LLC
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,705,731
App. No.
13/111,421
Granted
Apr 22, 2014
Kind
B2
Abstract

Processing of masked data using multiple lookup tables (LUTs), or sub-tables, is described. For each input value, an appropriate sub-table provides an output value that is the result of a non-linear transformation (e.g., byte substitution) applied to the input value. An additive mask can be applied to the input data. A transformation can be applied to the masked input data to transform the additive mask into a multiplicative-additive mask. Selected bits of the masked input data and the bits in the additive component of the multiplicative-additive mask can be used in combination to select one of the sub-tables. An entry in the selected sub-table, corresponding to a transformed version of the input data, can then be identified.

Claims (27)

1. A data processing method comprising:

applying a transformation to randomly masked input data comprising input data that is masked with a random additive mask, wherein said transformation replaces said additive mask with a multiplicative-additive mask comprising an additive component;

using a first subset of said masked input data and said additive component of said multiplicative-additive mask in combination to select a lookup table (LUT) from a plurality of LUTs, wherein said LUT is selected using a swap operation in which indices of said LUTs are exchanged according to bit values of said additive mask; and

using a second subset of said masked input data to select an entry in said LUT corresponding to a transformed version of said input data.

2. The method of claim 1 wherein said plurality of LUTs are implemented in read only memory.

3. The method of claim 1 wherein said plurality of LUTs are implemented in hardware as synthesized logic.

4. The method of claim 1 wherein said masked input data is mapped to said LUT using a decoder that is controlled by bit values of said masked input data and by bit values of said additive component of said multiplicative-additive mask.

5. The method of claim 4 wherein said decoder comprises a cascade of two-to-two decoders, wherein said cascade comprises a two-to-two decoder comprising a de-multiplexer having two outputs, wherein both said outputs are provided as inputs to each of two multiplexers, and wherein both said multiplexers are controlled according to a value of a corresponding bit of said additive component of said multiplicative-additive mask.

6. The method of claim 4 wherein outputs of said decoder are provided as inputs to a cascade of multiplexers, wherein each of said multiplexers is controlled according to a value of a corresponding bit of said additive component of said multiplicative-additive mask.

7. A data processing method comprising:

masking an n-bit input value with a random additive mask to produce an n-bit masked input value;

replacing said additive mask with a multiplicative-additive mask comprising an additive component;

using the n/2 most significant bits of said masked input data and said additive component in combination to select a lookup table (LUT) from a plurality of LUTs, wherein said LUT is selected using a swap operation in which indices of said LUTs are exchanged according to bit values of said additive mask; and

using the n/2 least significant bits of said masked input data to select an entry in said LUT corresponding to a transformed version of said input data.

8. The method of claim 7 wherein there are 2 n/2 LUTs in said plurality of LUTs and wherein said additive mask comprises n/2 bits.

9. The method of claim 8 wherein said plurality of LUTs are implemented in read only memory.

10. The method of claim 7 wherein said plurality of LUTs are implemented in hardware as synthesized logic.

11. The method of claim 7 wherein said masked input value is mapped to said LUT using a decoder that is controlled by bit values of said most significant bits and by bit values of said additive component of said multiplicative-additive mask.

12. The method of claim 11 wherein said decoder comprises a cascade of two-to-two decoders, wherein said cascade comprises a two-to-two decoder comprising a de-multiplexer having two outputs, wherein both said outputs are provided as inputs to each of two multiplexers, and wherein both said multiplexers are controlled according to a value of a corresponding bit of said additive component of said multiplicative-additive mask.

13. The method of claim 11 wherein outputs of said decoder are provided as inputs to a cascade of multiplexers, wherein each of said multiplexers is controlled according to a value of a corresponding bit of said additive component of said multiplicative-additive mask.

14. A data processing system comprising:

a mask generator operable for generating a random mask that is applied to input data to generate masked input data and to transform said mask into a multiplicative-additive mask comprising an additive component; and

a decoder coupled to said mask generator and operable for selecting a lookup table (LUT) from a plurality of LUTs using a first subset of said masked input data and said additive component in combination, wherein said LUT is selected using a swap operation in which indices of said LUTs are exchanged according to bit values of said additive mask, said decoder also operable for selecting an entry in said LUT using a second subset of said masked input data, said entry corresponding to a transformed version of said input data.

15. The system of claim 14 wherein said LUT is implemented in read only memory.

16. The system of claim 14 wherein said LUT is implemented in hardware as synthesized logic.

17. The system of claim 14 wherein said decoder comprises a cascade of de-multiplexers and a cascade of multiplexers interleaved with said cascade of de-multiplexers, wherein said de-multiplexers include a de-multiplexer having two outputs, wherein both said outputs are provided as inputs to each of two multiplexers and wherein both of said two multiplexers are controlled according to a value of a corresponding bit of said additive component of said multiplicative-additive mask.

18. The system of claim 14 further comprising a cascade of multiplexers downstream of said decoder, wherein outputs of said decoder are provided as inputs to said multiplexers and wherein each of said multiplexers is controlled according to a value of a corresponding bit of said additive component of said multiplicative-additive mask.

Assignments (5)
MERGER Recorded Nov 14, 2025
From: CYPRESS SEMICONDUCTOR CORPORATION
To: INFINEON TECHNOLOGIES AMERICAS CORP.
Reel/Frame 073571/0456 →
RELEASE OF SECURITY INTEREST Recorded Mar 16, 2022
From: MUFG UNION BANK, N.A.
To: CYPRESS SEMICONDUCTOR CORPORATION; SPANSION LLC
Reel/Frame 059410/0438 →
CORRECTIVE ASSIGNMENT TO CORRECT THE 8647899 PREVIOUSLY RECORDED ON REEL 035240 FRAME 0429. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTERST. Recorded Nov 3, 2020
From: CYPRESS SEMICONDUCTOR CORPORATION; SPANSION LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 058002/0470 →
ASSIGNMENT AND ASSUMPTION OF SECURITY INTEREST IN INTELLECTUAL PROPERTY Recorded Oct 28, 2019
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: MUFG UNION BANK, N.A.
Reel/Frame 050896/0366 →
SECURITY INTEREST Recorded Mar 21, 2015
From: CYPRESS SEMICONDUCTOR CORPORATION; SPANSION LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 035240/0429 →
Continuity (2)
Continuation 11788264 · Apr 19, 2007
Related Publication 20110228928A1 · Sep 22, 2011