Differential power analysis - resistant cryptographic processing
Abstract
Information leaked from smart cards and other tamper resistant cryptographic devices can be statistically analyzed to determine keys or other secret data. A data collection and analysis system is configured with an analog-to-digital converter connected to measure the device's consumption of electrical power, or some other property of the target device, that varies during the device's processing. As the target device performs cryptographic operations, data from the A/D converter are recorded for each cryptographic operation. The stored data are then processed using statistical analysis, yielding the entire key, or partial information about the key that can be used to accelerate a brute force search or other attack.
Claims
exact text as granted — not AI-modified1 - 7 . (canceled)
8 . A method for evaluating the security of a device, the method comprising:
connecting the device to an analog-to-digital converter; sending a plurality of commands to the device, wherein each command causes the device to process data using a key; recording a plurality of measurements of an attribute of the device by using the analog-to-digital converter; and determining whether information about the key is leaking from the device.
9 . The method of claim 8 , wherein sending a plurality of commands to the device comprises sending a plurality of command sequences, further wherein each command sequence causes the device to process data using the key.
10 . The method of claim 8 , wherein each command sent to the device causes the device to perform a cryptographic operation using the key.
11 . The method of claim 10 , wherein the cryptographic operation includes transforming with a block cipher.
12 . The method of claim 10 , wherein recording a plurality of measurements of an attribute is performed during processing of each cryptographic operation.
13 . The method of claim 8 , wherein determining whether information about the key is leaking from the device comprises statistically combining the recorded plurality of measurements.
14 . The method of claim 8 , wherein determining whether information about the key is leaking from the device comprises temporally aligning data points corresponding to a point of interest within the recorded plurality of measurements.
15 . The method of claim 8 , further comprising determining information about the key.
16 . The method of claim 15 , wherein the information about the key comprises values of a plurality of key bits.
17 . The method of claim 8 , wherein:
the analog-to-digital converter is configured to measure electromagnetic radiation; and recording a plurality of measurements of an attribute of the device by using the analog-to-digital converter comprises recording a plurality of measurements of electromagnetic radiation by using the analog-to-digital converter.
18 . The method of claim 8 , wherein:
the analog-to-digital converter is configured to measure variations in an amount of power consumed on an external power input to the device; and recording a plurality of measurements of an attribute of the device by using the analog-to-digital converter comprises recording a plurality of measurements of an amount of power consumed on the external power input to the device taken by the analog-to-digital converter.
19 . A system for evaluating the security of cryptographic hardware, the system comprising:
an analog-to-digital converter configured to connect to a device and measure an attribute related to operation of the device, the device comprising a key and a circuit configured to perform operations using the key; a data storage system configured to record a plurality of measurements of the attribute taken by the analog-to-digital converter; and a processor configured to determine whether information about the key is leaking from the device.
20 . The system of claim 19 , wherein the circuit is configured to perform cryptographic operations using the key.
21 . The system of claim 20 , wherein the cryptographic operations include transforming with a block cipher.
22 . The system of claim 20 , wherein the data storage system is configured to record a plurality of measurements of the attribute during processing of each cryptographic operation.
23 . The system of claim 19 , wherein the processor is configured to determine whether information about the key is leaking from the device by statistically combining the recorded plurality of measurements.
24 . The system of claim 19 , further comprising a data filtering system configured to temporally align data points corresponding to a point of interest within the recorded plurality of measurements.
25 . The system of claim 19 , wherein the processor is further configured to determine information about the key.
26 . The system of claim 19 , wherein:
the analog-to-digital converter is configured to measure electromagnetic radiation; and the data storage system is configured to record a plurality of measurements of electromagnetic radiation taken by the analog-to-digital converter.
27 . The system of claim 19 , wherein:
the analog-to-digital converter is configured to measure variations in an amount of power consumed on an external power input to the device; and the data storage system is configured to record a plurality of measurements of an amount of power consumed on the external power input to the device taken by the analog-to-digital converter.Join the waitlist — get patent alerts
Track US2017099134A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.