A Very Compact "Perfectly Masked" S-Box For Aes

ACNS'08: Proceedings of the 6th international conference on Applied cryptography and network security(2008)

引用 122|浏览11
暂无评分
摘要
Implementations of the Advanced Encryption Standard (AES), including hardware applications with limited resources (e.g., smart cards), may be vulnerable to "side-channel attacks" such as differential power analysis. One countermeasure against such attacks is adding a random mask to the data; this randomizes the statistics of the calculation at the cost of computing "mask corrections." The single nonlinear step in each AES round is the "S-box" (involving a Galois inversion), which incurs the majority of the cost for mask corrections. Oswald et al. [1] showed how the "tower field" representation allows maintaining an additive mask throughout the Galois inverse calculation. This work applies a similar masking strategy to the most compact (unmasked) S-box to date[2]. The result is the most compact masked S-box so far, with "perfect masking" (by the definition of Blomer[3]) giving suitable implementations immunity to first-order differential side-channel attacks.
更多
查看译文
关键词
AES,S-box,masking,DPA,composite Galois field
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要