Vendor: Rambus, Inc. Category: Public Key

Fast Public Key Engine with DPA or with DPA and FIA

The SCA-resistant PKE-IP-85 family of Public Key Engine cores provide semiconductor manufacturers with superior public key crypto…

Overview

The SCA-resistant PKE-IP-85 family of Public Key Engine cores provide semiconductor manufacturers with superior public key cryptography acceleration. The cores are easily integrated into ASIC/SoC and FPGA devices, offer a high-level of resistance to Differential Power Analysis (DPA), and, optionally, offer detection of Fault Injection Attacks (FIA).

The PKE solution accelerates RSA operations with up to 8-Kbit key size and ECC operations up to 521-bit key size. The PKE natively accelerates Elliptic Curve Based Digital Signature sign, verify and key generation operations using NIST, Curve448, Curve25519, Brainpool and, optionally, SM2/SM2DSA curves.

How the PKE-IP-85 Public Key Engine Works

The DPA-resistant and FIA-resistant PKE solution is comprised of a big-integer hardware Math Unit, a hardware Command Generator, firmware and software driver components.

Functional interfaces of the PKE core include a 32-bit AHB interface, a 32-bit low-level command interface, and a context SRAM interface and scratch pad interface. A system host controller writes input data for a high-level public key-based cryptographic operation (such as RSA, ECC) into a dedicated SRAM and issues high-level commands to the Command Generator. The PKE can also accelerate to a lower level by making direct calls to the Math Unit that accesses keys and data stored in a dedicated SRAM while performing its operations. The PKE firmware provides the required blinded key shares to the hardware core.

The cores are extensively side-channel validated using Test Vector Leakage Assessment methodology and show no leakage beyond 1 million operations. This results in a core that is protected against side-channel attacks beyond 10 million operations. The FIA-resistant core detects faults that are injected by lasers or EM pulses, for example.

Key features

  • RSA Laboratories PKCS #1 v2.1: RSA Cryptography Standard (no PKCS padding)
  • NIST FIPS 186-4 and FIPS 186-5 (primitives in support of) Digital Signature Standard
  • RFC5639 Elliptic Curve Cryptography (ECC) Brainpool Standard Curves and Curve Generation
  • RFC7748 Elliptic Curves for Security
  • RFC8032 Edwards-Curve Digital Signature Algorithm (EdDSA with Curve25519 and Curve448)
  • GB/T 32918.2-2016 SM2DSA (in versions with optional SM2 support)
  • SCA Test Vector Leakage Assessment shows no leakage beyond 1 million operations
  • FIA-resistant core detects faults that are injected by lasers or EM pulses Enhanced Flexibility
  • Can be used stand alone or integrated into higher function security cores
  • Offered as DPA-protected PKE-IP-85-DPA or as DPA+FIA-protected PKE-IP-85-DPA-FIA or as Common Criteria EAL 4+ PKE-IP-85-DPA-FIA-CC
  • Supports ASIC, SoC and FPGA implementations

Block Diagram

What’s Included?

  • Complete Documentation
    • Integration guides
    • Reference manual
    • Application developer guide
  • RTL and FW Package
    • Verilog RTL for synthesis and simulation
    • Standard EDA tool flow scripts and support files
    • Verification test bench and test vectors
  • SW Package
    • DPA Software Library for PKE Development Kit, including examples

Specifications

Identity

Part Number
PKE-IP-85-DPA(-FIA)
Vendor
Rambus, Inc.
Type
Silicon IP

Files

Note: some files may require an NDA depending on provider policy.

Provider

HQ: USA

Learn more about Public Key IP core

Bringing IPsec into the Quantum Safe Era

Over the next five years, all security protocols and public key cryptography will undergo a comprehensive overhaul to ensure quantum safety. This represents the most significant change in these domains since the advent of public key cryptography.

Google, Quantum Attacks, and ECDSA: Why There’s No Need to Panic and Why Preparation Matters Now

Over the past several weeks, we’ve seen growing discussion across the industry about Google’s latest publications on quantum computing and cryptography. In some corners, those discussions have quickly escalated into claims that widely deployed elliptic curve cryptography (ECC), including ECDSA, is on the verge of collapse. Customers are understandably asking questions: Has ECDSA been broken? Are today’s systems suddenly at risk? Do migration timelines need to change?

Side-Channel Attacks On Post-Quantum Cryptography

Device security requires designers to secure their algorithms, not only against direct attacks on the input and output, but also against side-channel attacks. This requirement is especially notable for cryptographic algorithms, since they have a regular, well-understood structure, and the secrets they process often give access to much more information.

Frequently asked questions about Public-Key Cryptography IP cores

What is Fast Public Key Engine with DPA or with DPA and FIA?

Fast Public Key Engine with DPA or with DPA and FIA is a Public Key IP core from Rambus, Inc. listed on Semi IP Hub.

How should engineers evaluate this Public Key?

Engineers should review the overview, key features, supported foundries and nodes, maturity, deliverables, and provider information before shortlisting this Public Key IP.

Can this semiconductor IP be compared with similar products?

Yes. Buyers can compare this product with similar semiconductor IP cores or IP families based on category, provider, process options, and structured technical specifications.

×
Semiconductor IP