IP Library › Granted Patent US 10,812,260
Granted Patent B2
US 10,812,260 · App. 15/862,817 · Granted Oct 20, 2020

Apparatus and method for performing operation being secure against side channel attack

Inventors: Kyu-Young Choi (Seoul, KR); Duk-Jae Moon (Seoul, KR); Hyo-Jin Yoon (Seoul, KR); Ji-Hoon Cho (Seoul, KR)
Assignee: SAMSUNG SDS CO., LTD.
H04L9/0869G06F7/723G06F7/725G06F21/755H04L9/003H04L9/0618H04L9/3247G06F1/03G06F2207/7219H04L9/3252H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,812,260
App. No.
15/862,817
Granted
Oct 20, 2020
Kind
B2
Abstract

An apparatus and method for performing operation being secure against side channel attack are provided. The apparatus and method generate values equal to values obtained through an exponentiation operation or a scalar multiplication operation of a point using values extracted from previously generated parameter candidate value sets and an operation secure against side-channel attack, thereby improving security against side-channel attack without degrading performance.

Claims (55)

1. An apparatus comprising:

a hardware processor configured to execute:

a seed value generator configured to generate a seed value;

a divider configured to divide the seed value into a plurality of divided blocks;

an extractor configured to extract a plurality of second parameter values from a second parameter candidate value set comprising a plurality of second parameter candidate values generated by using each of a plurality of first parameter candidate values, each of the plurality of second parameter values respectively corresponding to one of the plurality of divided blocks; and

a calculator configured to generate a random number based on the plurality of second parameter values,

wherein the hardware processor is further configured to encrypt data or generate a digital signature for the data based on the random number,

wherein each of the plurality of first parameter candidate values is a random value.

2. The apparatus of claim 1 , wherein each of the plurality of second parameter candidate values included in the second parameter candidate value set is generated by performing an exponentiation operation using a corresponding one of the plurality of first parameter candidate values as an exponent or by performing a scalar multiplication operation of a point using a corresponding one of the plurality of first parameter candidate values as a scalar multiplier.

3. The apparatus of claim 1 , wherein the extractor is further configured to extract the plurality of second parameter values respectively corresponding to bit strings in the plurality of divided blocks and positions of the divided blocks in the seed value, from the second parameter candidate value set.

4. The apparatus of claim 2 , wherein

the extractor comprises:

a first extractor configured to extract a plurality of first parameter values respectively corresponding to the plurality of divided blocks from a first parameter candidate value set including the plurality of first parameter candidate values used to generate the plurality of second parameter candidate values included in the second parameter candidate value set; and

a second extractor configured to extract the plurality of second parameter respectively corresponding to the plurality of divided blocks from the second parameter candidate value set,

wherein the calculator is further configured to generate a first random number based on the plurality of first parameter values and generate a second random number based on the plurality of second parameter values.

5. The apparatus of claim 4 , wherein

the first extractor is further configured to extract the plurality of first parameter values respectively corresponding to bit strings of the plurality of divided blocks and positions of the divided blocks in the seed value from the first parameter candidate value set, and

the second extractor is further configured to extract the plurality of second parameter values respectively corresponding to bit strings in the plurality of divided blocks and positions of the divided blocks in the seed value from the second parameter candidate value set.

6. The apparatus of claim 4 , wherein the calculator generates the first random number by adding the plurality of first parameter values to each other.

7. The apparatus of claim 4 , wherein the second random number is equal to a value obtainable by performing an exponentiation operation using the first random number as an exponent or by performing a scalar multiplication operation of a point using the first random number as a scalar multiplier and using the plurality of second parameter values.

8. The apparatus of claim 7 , wherein the hardware processor is further configured to encrypt the data or generate the digital signature for the data based on the first random number and the second random number.

9. The apparatus of claim 1 , wherein the seed value comprises a random bit string.

10. A method, comprising:

generating a seed value;

dividing the seed value into a plurality of divided blocks;

extracting a plurality of second parameter values from a second parameter candidate value set comprising a plurality of second parameter candidate values generated by using each of a plurality of first parameter candidate values, each of the plurality of second parameter values respectively corresponding to one of the plurality of divided blocks;

generating a random number based on the plurality of second parameter values; and

applying the random number to encrypt data or generate a digital signature for the data,

wherein each of the plurality of first parameter candidate values is a random value.

11. The method of claim 10 , wherein each of the plurality of second parameter candidate values included in the second parameter candidate value set is generated by performing an exponentiation operation using a corresponding one of the plurality of first parameter candidate values as an exponent or by performing a scalar multiplication operation of a point using a corresponding one of the plurality of first parameter candidate values as a scalar multiplier.

12. The method of claim 10 , wherein the extracting of the plurality of second parameter values extracts the plurality of second parameter values respectively corresponding to bit strings in the plurality of divided blocks and positions of the block in the seed value, from the second parameter candidate value set.

13. The method of claim 11 , wherein

the extracting of the plurality of second parameter values comprises:

extracting a plurality of first parameter values respectively corresponding to the plurality of divided blocks from a first parameter candidate value set including the plurality of first parameter candidate values used to generate the plurality of second parameter candidate values included in the second parameter candidate value set; and

extracting the plurality of second parameter values respectively corresponding to the plurality of divided blocks from the second parameter candidate value set, and

the generating of the random number comprises:

generating a first random number based on the plurality of first parameter values; and

generating a second random number based on the plurality of second parameter values.

14. The method of claim 13 , wherein

the extracting of the plurality of first parameter values extracts the plurality of first parameter values respectively corresponding to bit strings of the plurality of divided blocks and positions of the divided blocks in the seed value, from the first parameter candidate value set, and

the extracting of the plurality of second parameter values extracts the plurality of second parameter values respectively corresponding to bit strings in the plurality of divided blocks and positions of the divided blocks in the seed value, from the second parameter candidate value set.

15. The method of claim 13 , wherein the generating of the first random number generates the first random number by adding the plurality of first parameter values to each other.

16. The method of claim 13 , wherein the generating of the second random number generates the second random number equal to a value obtainable through an exponentiation operation using the first random number as an exponent or through a scalar multiplication of a point operation using the first random number as a scalar multiplier using the plurality of second parameter values.

17. The method of claim 16 , further comprising generating a digital signature using the first random number and the second random number.

18. The method of claim 10 , wherein the seed value comprises a random bit string.

19. A non-transitory computer readable medium having stored thereon a program for causing a computer to execute a method of claim 10 .

20. An apparatus comprising:

a hardware processor configured to execute:

receive a seed value;

divide the seed value into a plurality of blocks;

extract, for each of the plurality of blocks, a second parameter value from a second parameter candidate value set comprising a plurality of second parameter candidate values generated by using a plurality of first parameter candidate values, by using a number of the respective block and a value in the respective block as a first index; and

generate a random number based on the second parameter values for each of the plurality of blocks; and

apply the random number to encrypt data or generate a digital signature for the data based on the random number,

wherein each of the plurality of first parameter candidate values is a random value generated.

21. The apparatus of claim 20 , wherein a number of the second parameter candidate values included in the second parameter candidate value set changes according to a length of the seed value and a total number of the plurality of blocks.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 5, 2018
From: CHOI, KYU-YOUNG; MOON, DUK-JAE; YOON, HYO-JIN; CHO, JI-HOON
To: SAMSUNG SDS CO., LTD.
Reel/Frame 045012/0468 →
Priority Claims (1)
KR 10-2017-0055698 · Apr 28, 2017 · national
Continuity (1)
Related Publication 20180316499A1 · Nov 1, 2018
Cited By (1)
US 12,341,902