IP Library › Granted Patent US 12,632,610
Granted Patent B2
US 12,632,610 · App. 18/039,890 · Granted May 19, 2026

Data-gating based masking

Inventor: Michael Hutter (Vienna, AT)
Assignee: Rambus Inc.
G06F21/755
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,632,610
App. No.
18/039,890
Granted
May 19, 2026
Kind
B2
Abstract

A bundled-data protocol can be used to synchronize the data flow in the mask shares. A random synchronization token is input and “bundled” with the combinatorial logic of a share. An additional output from the combinatorial logic is also provided such that when the original combinational output is exclusive OR'd (XOR'd) with the additional output yields the random synchronization token. When the XOR of the original and additional outputs, and the input synchronization token are equal, it indicates that the computation of the combinatorial logic is complete. Thus, the result of the comparison of the XOR of the original and additional outputs, and the input synchronization token may be used as a “done” or “enable” handshake signal to allow asynchronous gating elements (e.g., AND gates, asynchronous set-reset latches, and/or state-holding elements like the Muller C-element, etc.) to start and stop the flow of data in a mask share.

Claims (29)

1 . An integrated circuit, comprising:

first masked circuitry to compute a first masked output value from at least a first share value and a second share value;

second masked circuitry to compute a second masked output value from at least a randomized first token value, the first share value, and the second share value;

first regeneration circuitry to compute a first regenerated token value; and,

first enable signal circuitry to output a first enable signal based on the randomized first token value and the first regenerated token value.

2 . The integrated circuit of claim 1 , further comprising:

third masked circuitry to, in response to the first enable signal, compute a third masked output value from at least the first masked output value.

3 . The integrated circuit of claim 2 , further comprising:

fourth masked circuitry to, in response to the first enable signal, compute a fourth masked output value from at least the randomized first token value and the first masked output value.

4 . The integrated circuit of claim 3 , further comprising:

second regeneration circuitry to compute a second regenerated token value.

5 . The integrated circuit of claim 4 , further comprising:

second enable signal circuitry to output a second enable signal based on the randomized first token value and the second regenerated token value.

6 . The integrated circuit of claim 1 , wherein the first regeneration circuitry comprises an exclusive-OR function.

7 . The integrated circuit of claim 1 , wherein the first masked circuitry is included in a cryptographic operation.

8 . The integrated circuit of claim 1 , wherein the first masked circuitry implements a masked AND gate.

9 . A method, comprising:

generating a first output share of data gate based masking (DGM) circuitry based on a first input share value and a second input share value;

generating a second output share of the DGM circuitry based on a randomized first token value, the first input share value, and the second input share value;

generating a linearly processed first regenerated token value based on the first output share of the DGM circuitry and the second output share of the DGM circuitry; and,

outputting a first enable signal based on a linearly processed first token value and the linearly processed first regenerated token value.

10 . The method of claim 9 , further comprising:

in response to the first enable signal, generating a third output share of the DGM circuitry based on at least the first output share.

11 . The method of claim 10 , further comprising:

in response to the first enable signal, generating a fourth output share of the DGM circuitry base on at least the randomized first token value and the first output share.

12 . The method of claim 11 , further comprising:

generating a linearly processed second regenerated token value based on the third output share and the fourth output share.

13 . The method of claim 12 , further comprising:

outputting a second enable signal based on the linearly processed first token value and a linearly processed second regenerated token value.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 1, 2023
From: HUTTER, MICHAEL
To: RAMBUS INC.
Reel/Frame 063833/0035 →
Continuity (2)
Provisional Application 63124444 · Dec 11, 2020
Related Publication 20240045998A1 · Feb 8, 2024
References Cited (18)
US 6191683B1 · Nygaard, Jr. · 2001 [cited by applicant]
US 10712385B2 · Hutter et al. · 2020 [cited by applicant]
US 20060039179A1 · Luk et al. · 2006 [cited by applicant]
US 20060200514A1 · Fischer et al. · 2006 [cited by applicant]
US 20070018690A1 · Behrends et al. · 2007 [cited by applicant]
US 20150169904A1 · Leiserson et al. · 2015 [cited by applicant]
US 20190362104A1 · Leiserson · 2019 [cited by examiner]
US 20210097175A1 · Hoerder · 2021 [cited by applicant]
US 20220405428A1 · Leiserson · 2022 [cited by examiner]
EP Communication Pursuant to Rule 164(1) EPC, Partial Supplementary European Search Report with Mail Date Sep. 30, 2024 re: EP Appln. No. 21904127.4. 14 pages. [cited by applicant]
Kumar, Kundan et al., “Design of a differential power analysis resistant masked AES S-Box,” International Conference on Cryptology in India, Indocrypt 2007, LNCS 4859, Berlin, Heidelberg: Springer Berlin Heidelberg, 200… [cited by applicant]
Fischer, Wieland et al., “Masking at Gate Level in the Presence of Glitches”, Proceedings of the 7th International Conference on Cryptographic Hardware and Embedded Systems (CHES'05). Springer-Verlag, Berlin, Heidelberg… [cited by applicant]
Mangard, Stefan et al., “Pinpointing the Side-Channel Leakage of Masked AES Hardware Implementations *”, Proceedings of the 8th International Conference on Cryptographic Hardware and Embedded Systems (CHES'06). Springer… [cited by applicant]
Mangard, Stefan et al., “Side-Channel Leakage of Masked CMOS Gates*”, Proceedings of the 2005 International Conference on Topics in Cryptology (CT-RSA'05). Springer-Verlag, Berlin, Heidelberg, 2005, pp. 351-365, 15 page… [cited by applicant]
Marioka, Sumio et al., “An Optimized S-Box Circuit Architecture for Low Power AES Design”, Revised Papers from the 4th International Workshop on Cryptographic Hardware and Embedded Systems (CHES '02). Springer-Verlag, B… [cited by applicant]
Notification of Transmittal of the International Search Report and the Written Opinion of the International Searching Authority, or the Declaration with Mail Date Apr. 26, 2022 re: Int' Appin. No. PCT/US2021/061251. 19 … [cited by applicant]
Suzuki, Daisuke et al., “Random Switching Logic: A Countermeasure Against DPA Based on Transition Probability”, IACR Cryptology ePrint Archive. 2004, 346, 16 pages. [cited by applicant]
Zeng, Juanli et al., “Improvement on Masked S-box Hardware Implementation”, 2012 International Conference on Innovations in Information Technology (IIT), pp. 113-116, 5 pages. [cited by applicant]