Side-channel attack resistant ROM-based AES S-Box

Craig Teegarden, M. Bhargava, K. Mai
{"title":"Side-channel attack resistant ROM-based AES S-Box","authors":"Craig Teegarden, M. Bhargava, K. Mai","doi":"10.1109/HST.2010.5513101","DOIUrl":null,"url":null,"abstract":"In the AES algorithm, the Substitution Box (S-Box) often dominates the area and delay of implementations. The S-Box performs a byte-wise substitution on the data based on an established code book, and most AES algorithm implementations use a large complex logic block consisting mainly of XORs to implement the S-Box. Direct implementation of the S-Box with a look-up table (LUT) has been eschewed due to difficulty in pipelining the structure, hence restricting the throughput. However, we present a custom ROM-based S-Box implementation that can achieve comparable throughput to logic-based implementations, yet is smaller in both area and power. Additionally, the symmetrical nature of the ROM is well suited towards achieving data-independent power dissipation, which is key in defending against power analysis side-channel attacks. We present both power-analysis hardened and unhardened ROM-based S-Box designs which significantly outperform logic-based designs in area, power, performance, and power-analysis resistance.","PeriodicalId":6367,"journal":{"name":"2010 IEEE International Symposium on Hardware-Oriented Security and Trust (HOST)","volume":"55 1","pages":"124-129"},"PeriodicalIF":0.0000,"publicationDate":"2010-06-13","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"14","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2010 IEEE International Symposium on Hardware-Oriented Security and Trust (HOST)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/HST.2010.5513101","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 14

Abstract

In the AES algorithm, the Substitution Box (S-Box) often dominates the area and delay of implementations. The S-Box performs a byte-wise substitution on the data based on an established code book, and most AES algorithm implementations use a large complex logic block consisting mainly of XORs to implement the S-Box. Direct implementation of the S-Box with a look-up table (LUT) has been eschewed due to difficulty in pipelining the structure, hence restricting the throughput. However, we present a custom ROM-based S-Box implementation that can achieve comparable throughput to logic-based implementations, yet is smaller in both area and power. Additionally, the symmetrical nature of the ROM is well suited towards achieving data-independent power dissipation, which is key in defending against power analysis side-channel attacks. We present both power-analysis hardened and unhardened ROM-based S-Box designs which significantly outperform logic-based designs in area, power, performance, and power-analysis resistance.
基于rom的抗侧信道攻击AES S-Box
在AES算法中,替换盒(S-Box)往往占据着实现的面积和延迟。S-Box基于已建立的代码本对数据执行逐字节替换,并且大多数AES算法实现使用主要由xor组成的大型复杂逻辑块来实现S-Box。使用查找表(LUT)直接实现S-Box已被避免,因为难以将结构流水线化,因此限制了吞吐量。然而,我们提出了一个定制的基于rom的S-Box实现,它可以实现与基于逻辑的实现相当的吞吐量,但在面积和功耗方面都更小。此外,ROM的对称特性非常适合实现与数据无关的功耗,这是防御功率分析侧信道攻击的关键。我们提出了强化和未强化的基于rom的S-Box设计,它们在面积、功耗、性能和功耗分析阻力方面都明显优于基于逻辑的设计。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信