EM and Power SCA-Resilient AES-256 Through >350× Current-Domain Signature Attenuation and Local Lower Metal Routing

EM and Power SCA-Resilient AES-256 Through >350× Current-Domain Signature Attenuation and Local Lower Metal Routing
复制标题

DOI:
10.1109/jssc.2020.3032975
复制
发表时间:
2021-01
影响因子:
5.4
通讯作者:
D. Das;Josef Danial;Anupam Golder;Nirmoy Modak;Shovan Maity;Baibhab Chatterjee;Dong-Hyun Seo;Muya Chang;Avinash L. Varna;H. Krishnamurthy;S. Mathew;Santosh K. Ghosh;A. Raychowdhury;Shreyas Sen
D. Das;Josef Danial;Anupam Golder;Nirmoy Modak;Shovan Maity;Baibhab Chatterjee;Dong-Hyun Seo;Muya Chang;Avinash L. Varna;H. Krishnamurthy;S. Mathew;Santosh K. Ghosh;A. Raychowdhury;Shreyas Sen
中科院分区:
工程技术1区
文献类型:
--
作者:
D. Das;Josef Danial;Anupam Golder;Nirmoy Modak;Shovan Maity;Baibhab Chatterjee;Dong-Hyun Seo;Muya Chang;Avinash L. Varna;H. Krishnamurthy;S. Mathew;Santosh K. Ghosh;A. Raychowdhury;Shreyas Sen

文献摘要

被引文献

相似文献

从数学角度看安全的加密算法,在物理基底上实施时,会泄露关键的“侧信道”信息,从而导致功耗和电磁(EM)分析攻击。电路级保护涉及基于开关电容、降压转换器或串联低压差(LDO)调节器的实现方式,每种方式都在功耗、面积或性能方面存在重大的权衡,并且到目前为止仅实现了1000万次最小泄露轨迹(MTD)。利用深度白盒模型,这项工作首次聚焦于电流域中的特征抑制,这使得MTD中的衰减平方(Attenuation²)增强,从而在功耗和电磁侧信道分析(SCA)抗扰性方面带来数量级的提升。通过结合电流域“特征衰减”(CDSA)以及局部较低层金属布线,加密电流中的关键相关信息在到达电源引脚之前被显著抑制。特别是,为了防止电磁从其源头(承载相关加密电流并充当天线的金属层)泄露,这项工作采用了嵌入加密知识产权(IP)的CDSA的较低层金属布线,以便在特征通过高层金属层(高层金属层辐射显著)连接到外部引脚之前被高度抑制。65纳米CMOS测试芯片包含受保护和未受保护的并行AES - 256实现,运行时钟频率为50兆赫兹。对受保护的CDSA - AES进行的测试向量泄露评估(TVLA)首次通过片上测量得以展示,结果表明高层金属层相较于低层金属布线泄露明显更多。对未受保护的实现进行的相关功耗和电磁分析(CPA/CEMA)攻击能够分别在8000次和12000次轨迹内提取出密钥,而受保护的CDSA - AES即使在进行了10亿次加密(针对功耗和电磁SCA,在时域和频域都进行了评估)之后也无法被破解,相较于具有可比功耗和面积开销的现有最先进的对策显示出100倍的提升。
Mathematically secure cryptographic algorithms, when implemented on a physical substrate, leak critical “side-channel” information, leading to power and electromagnetic (EM) analysis attacks. Circuit-level protections involve switched capacitor, buck converter, or series low-dropout (LDO) regulator-based implementations, each of which suffers from significant power, area, or performance tradeoffs and has only achieved a minimum traces to disclosure (MTD) of $10M$ till date. Utilizing an in-depth white-box model, this work, for the first time, focuses on signature suppression in the current domain, which provides an $Attenuation^{2}$ enhancement in MTD, leading to orders of magnitude improvement in both power and EM side-channel analysis (SCA) immunities. Using a combination of current-domain “signature attenuation” (CDSA) along with local lower level metal routing, the critical correlated information in the crypto current is significantly suppressed before it reaches the supply pin. Especially, to prevent the EM leakage from its source (metal layers carrying the correlated crypto current acting as antennas), this work embraces lower level metal routing of the CDSA embedding the crypto-IP so that the signature becomes highly suppressed before it passes through the higher metal layers (which radiates significantly) to connect to the external pin. The 65-nm CMOS test chip contains both protected and unprotected parallel AES-256 implementations, running at a clock frequency of 50 MHz. Test vector leakage assessment (TVLA) on the protected CDSA-AES, demonstrated with on-chip measurements for the first time, shows that the higher level metal layers leak significantly more compared with the lower level metal routing. Correlational power and EM analysis (CPA/CEMA) attacks on the unprotected implementation were able to extract the secret key within $8k$ and $12k$ traces, respectively, while the protected CDSA-AES could not be broken even after $1B$ encryptions for both power and EM SCA, evaluated both in the time and frequency domains, showing an improvement of $100\times $ over the prior state-of-the-art countermeasures with comparable power and area overheads.