Patents by Inventor Ury KREIMER
Ury KREIMER has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).
-
Publication number: 20260149560Abstract: In a general aspect, a GHASH semiconductor intellectual property (IP) core can include circuitry for calculating a GHASH function. The IP core can be configured to calculate the GHASH function by calculating the following quantities: X 0 = 0 ; ? X i + 1 = H k ? X i + ? j = 0 k - 1 ? ? n = 0 m - 1 ? C ki + j ? h ijn , where ? for ? any ? i ? and ? j ; and ? ? n = 0 m - 1 ? h ijn = H j , where ? k > 1 ? and ? m > 1 .Type: ApplicationFiled: January 20, 2026Publication date: May 28, 2026Inventors: Ury Kreimer, Alexander Kesler, Yaacov Belenky, Vadim Bugaenko
-
Patent number: 12562885Abstract: In a general aspect, a GHASH semiconductor intellectual property (IP) core can include circuitry for calculating a GHASH function. The IP core can be configured to calculate the GHASH function by calculating the following quantities: X 0 = 0 ; X i + 1 = H k ? X i + ? j = 0 k - 1 ? ? n = 0 m - 1 ? C ki + j ? h ijn , where for any i and j; and ? n = 0 m - 1 ? h i ? j ? n = H j , where ? k > 1 ? and ? m > 1 .Type: GrantFiled: February 9, 2021Date of Patent: February 24, 2026Assignee: FORTIFYIQ, INC.Inventors: Ury Kreimer, Alexander Kesler, Yaacov Belenky, Vadim Bugaenko
-
Publication number: 20260005834Abstract: Techniques include replacing many of the functions used in finite-field-based arithmetic with lookup tables (LUTs) and combining such LUTs with redundancy-based protection. Advantageously, using LUTs makes it possible to dramatically decrease the redundancy level (e.g., from d=8 to d=3 or 4) and the power consumption and increase the maximal frequency, while preserving the same protection level, latency and performance. The improvement is applicable not only to AES, but also to other algorithms based on a finite field arithmetic, and in particular SM4, ARIA, and Camellia which use Sboxes very similar to or the same as the AES Sbox.Type: ApplicationFiled: August 4, 2025Publication date: January 1, 2026Inventors: Ury Kreimer, Yaacov Belenky, Alexander Kesler
-
Patent number: 12407490Abstract: Techniques include replacing many of the functions used in finite-field-based arithmetic with lookup tables (LUTs) and combining such LUTs with redundancy-based protection. Advantageously, using LUTs makes it possible to dramatically decrease the redundancy level (e.g., from d=8 to d=3 or 4) and the power consumption and increase the maximal frequency, while preserving the same protection level, latency and performance. The improvement is applicable not only to AES, but also to other algorithms based on a finite field arithmetic, and in particular SM4, ARIA, and Camellia which use Sboxes very similar to or the same as the AES Sbox.Type: GrantFiled: September 5, 2023Date of Patent: September 2, 2025Assignee: FortifyIQ, Inc.Inventors: Ury Kreimer, Yaacov Belenky, Alexander Kesler
-
Publication number: 20250258651Abstract: A method for performing modular multiplication of a first multiplicand and a second multiplicand in a cryptographic engine, the method including calculating an integer corresponding with an inverse of a modulus based on a number of bits in the modulus, a digit size of the modular multiplier and a fixed size coefficient. The method also includes calculating a result of the modular multiplication using a plurality of modular reduction coefficients determined using the integer and respective digits of the multiplicands, the result less than an upper size limit that is based on the size coefficient and the modulus. The method further includes determining a final result of the modular multiplication based on a difference between the result and the modulus. If the difference is less than zero, the result is the final result, and if the difference is greater than or equal to zero, the difference is the final result.Type: ApplicationFiled: February 10, 2025Publication date: August 14, 2025Inventors: Yaacov Belenky, Ury Kreimer, Valery Teper, Daria Ryzhkova, Alexander Kesler
-
Patent number: 12244685Abstract: In a general aspect, a method for testing vulnerability of a cryptographic function (CF) to a side-channel attack includes providing a plurality of input values to the function, where the CF, for each input value calculates a sum of the input value and a first value of the CF, and replaces a second value of the CF with the sum. The method further includes measuring a set of samples including a respective side-channel leakage sample for each input value. The method also includes iteratively performing a series of operations including splitting the set of samples into a plurality of subsets based on the input values, calculating a respective value for each subset based on samples of the subset, and comparing the respective values for different subsets to discover respective bit values of the first value and the second value from their least significant bits to most significant bits.Type: GrantFiled: February 23, 2023Date of Patent: March 4, 2025Assignee: FORTIFYIQ, INC.Inventors: Yaacov Belenky, Ury Kreimer, Alexander Kesler
-
Publication number: 20250015969Abstract: A method of improving performance of a data processor comprising: in a field of characteristic 2 computing XY by performing a series of: (i) multiplications of two different elements of the field; and (ii) raising an element of the field to a power Z wherein Z is a power of 2; wherein the number of multiplications (i) is at least two less than the number of ones (1s) in the binary representation of Y.Type: ApplicationFiled: September 17, 2024Publication date: January 9, 2025Inventors: Ury KREIMER, Alexander KESLER, Vadim BUGAENKO, Yaacov BELENKY
-
Patent number: 12132817Abstract: A method of improving performance of a data processor comprising: in a field of characteristic 2 computing XY by performing a series of: (i) multiplications of two different elements of the field; and (ii) raising an element of the field to a power Z wherein Z is a power of 2; wherein the number of multiplications (i) is at least two less than the number of ones (1s) in the binary representation of Y.Type: GrantFiled: July 11, 2022Date of Patent: October 29, 2024Assignee: FORTIFYIQ, INC.Inventors: Ury Kreimer, Alexander Kesler, Vadim Bugaenko, Yaacov Belenky
-
Patent number: 11995191Abstract: A method for testing an HMAC implementation for vulnerability to a side-channel attack can include mounting a template attack. The attack can include generating, based on first side-channel leakage information associated with execution of a hash function of the HMAC implementation, a plurality of template tables. Each template table can correspond, respectively, with a subset of bit positions of an internal state of the hash function. The attack can further include generating, based on second side-channel leakage information, a plurality of hypotheses for an internal state of an invocation of the hash function based on a secret key. The method can further include generating, using the hash function, respective hash values generated from each of the plurality of hypotheses and a message. The method can also include comparing each of the respective hash values with a hash value generated using the secret key to determine vulnerability of the HMAC implementation.Type: GrantFiled: August 11, 2021Date of Patent: May 28, 2024Assignee: FortifyIQ, Inc.Inventors: Yaacov Belenky, Ury Kreimer, Alexander Kesler
-
Publication number: 20240089086Abstract: Techniques include replacing many of the functions used in finite-field-based arithmetic with lookup tables (LUTs) and combining such LUTs with redundancy-based protection. Advantageously, using LUTs makes it possible to dramatically decrease the redundancy level (e.g., from d=8 to d=3 or 4) and the power consumption and increase the maximal frequency, while preserving the same protection level, latency and performance. The improvement is applicable not only to AES, but also to other algorithms based on a finite field arithmetic, and in particular SM4, ARIA, and Camellia which use Sboxes very similar to or the same as the AES Sbox.Type: ApplicationFiled: September 5, 2023Publication date: March 14, 2024Inventors: Ury Kreimer, Yaacov Belenky, Alexander Kesler
-
Publication number: 20230269065Abstract: In a general aspect, a method for testing vulnerability of a cryptographic function (CF) to a side-channel attack includes providing a plurality of input values to the function, where the CF, for each input value calculates a sum of the input value and a first value of the CF, and replaces a second value of the CF with the sum. The method further includes measuring a set of samples including a respective side-channel leakage sample for each input value. The method also includes iteratively performing a series of operations including splitting the set of samples into a plurality of subsets based on the input values, calculating a respective value for each subset based on samples of the subset, and comparing the respective values for different subsets to discover respective bit values of the first value and the second value from their least significant bits to most significant bits.Type: ApplicationFiled: February 23, 2023Publication date: August 24, 2023Inventors: Yaacov Belenky, Ury Kreimer, Alexander Kesler
-
Publication number: 20230077946Abstract: In a general aspect, a GHASH semiconductor intellectual property (IP) core can include circuitry for calculating a GHASH function. The IP core can be configured to calculate the GHASH function by calculating the following quantities: X 0 = 0 ; X i + 1 = H k X i + ? j = 0 k ? 1 ? n = 0 m ? 1 C k i + j h i j n , ? where for any i ? and j ; ? and ? n = 0 m ? 1 h i j n = H j , ? where k > 1 and m ? > 1.Type: ApplicationFiled: February 9, 2021Publication date: March 16, 2023Inventors: Ury Kreimer, Alexander KESLER, Yaacov BELENKY, Vadim BUGAENKO
-
Publication number: 20220414227Abstract: A method for testing an HMAC implementation for vulnerability to a side-channel attack can include mounting a template attack. The attack can include generating, based on first side-channel leakage information associated with execution of a hash function of the HMAC implementation, a plurality of template tables. Each template table can correspond, respectively, with a subset of bit positions of an internal state of the hash function. The attack can further include generating, based on second side-channel leakage information, a plurality of hypotheses for an internal state of an invocation of the hash function based on a secret key. The method can further include generating, using the hash function, respective hash values generated from each of the plurality of hypotheses and a message. The method can also include comparing each of the respective hash values with a hash value generated using the secret key to determine vulnerability of the HMAC implementation.Type: ApplicationFiled: August 11, 2021Publication date: December 29, 2022Inventors: Yaacov Belenky, Ury Kreimer, Alexander Kesler
-
Publication number: 20220360426Abstract: A method of improving performance of a data processor comprising: in a field of characteristic 2 computing XY by performing a series of: (i) multiplications of two different elements of the field; and (ii) raising an element of the field to a power Z wherein Z is a power of 2; wherein the number of multiplications (i) is at least two less than the number of ones (1s) in the binary representation of Y.Type: ApplicationFiled: July 11, 2022Publication date: November 10, 2022Inventors: Ury KREIMER, Alexander KESLER, Vadim BUGAENKO, Yaacov BELENKY
-
Patent number: 11418317Abstract: A semiconductor intellectual property (IP) core comprising a transformation engine designed and configured to represent each element of a field GF(28) using a polynomial of degree no higher than 7+d, where d>0 is a redundancy parameter. Also disclosed in the specification are several other IP cores and several different methods.Type: GrantFiled: January 16, 2020Date of Patent: August 16, 2022Assignee: FORTIFYIQ, INC.Inventors: Ury Kreimer, Alexander Kesler, Vadim Bugaenko, Yaacov Belenky
-
Patent number: 11323254Abstract: Device, system, and method of generating and handling cryptographic parameters. A first device and a second device store the same secret seed value, utilize the same deterministic pseudo-random number generation function, and utilize the same deterministic value modification function. The first device generates a candidate value, sequentially modifies its value, and performs primality testing until a confirmed prime number is found. The first device indicates to the second device, how many iterations of value modifications to perform in order to reach and thus re-generate therein the same already-confirmed prime number, without the need to perform any primality testing in the second device.Type: GrantFiled: April 25, 2019Date of Patent: May 3, 2022Assignee: ARM LIMITEDInventors: Ruvein Itskhak Levin, Ury Kreimer
-
Publication number: 20220045839Abstract: A semiconductor intellectual property (IP) core comprising a transformation engine designed and configured to represent each element of a field GF(28) using a polynomial of degree no higher than 7+d, where d>0 is a redundancy parameter. Also disclosed in the specification are several other IP cores and several different methods.Type: ApplicationFiled: January 16, 2020Publication date: February 10, 2022Inventors: Ury KREIMER, Alexander KESLER, Vadim BUGAENKO, Yaacov BELENKY
-
Patent number: 11190340Abstract: A method for creating unified, efficient hardware implementations for multiple symmetric ciphers is described. For a chosen set of two or more distinct types of symmetric ciphers, a unified substitution box (SBOX) is designed that can implement most of the operations in a single hardware block, with small hardware blocks added before and after the unified SBOX for unique operations of each distinct symmetric cipher. Optimization techniques can also be applied to the linear operations and SBOX operations for the chosen set, rather than individually for each symmetric cipher, of the two or more distinct types of symmetric ciphers.Type: GrantFiled: May 31, 2019Date of Patent: November 30, 2021Assignee: ARM LIMITEDInventors: Leonid Dorrendorf, Ruvein Itskhak Levin, Ury Kreimer
-
Publication number: 20210226783Abstract: Device, system, and method of generating and handling cryptographic parameters. A first device and a second device store the same secret seed value, utilize the same deterministic pseudo-random number generation function, and utilize the same deterministic value modification function. The first device generates a candidate value, sequentially modifies its value, and performs primality testing until a confirmed prime number is found. The first device indicates to the second device, how many iterations of value modifications to perform in order to reach and thus re-generate therein the same already-confirmed prime number, without the need to perform any primality testing in the second device.Type: ApplicationFiled: April 25, 2019Publication date: July 22, 2021Inventors: Ruvein Itskhak Levin, Ury Kreimer
-
Publication number: 20190372753Abstract: A method for creating unified, efficient hardware implementations for multiple symmetric ciphers is described. For a chosen set of two or more distinct types of symmetric ciphers, a unified substitution box (SBOX) is designed that can implement most of the operations in a single hardware block, with small hardware blocks added before and after the unified SBOX for unique operations of each distinct symmetric cipher. Optimization techniques can also be applied to the linear operations and SBOX operations for the chosen set, rather than individually for each symmetric cipher, of the two or more distinct types of symmetric ciphers.Type: ApplicationFiled: May 31, 2019Publication date: December 5, 2019Inventors: Leonid DORRENDORF, Ruvein Itskhak LEVIN, Ury KREIMER