A Side-Channel-Resistant Implementation of SABER

A Side-Channel-Resistant Implementation of SABER
复制标题

DOI:
10.1145/3429983
复制
发表时间:
2021-04
期刊:
ACM Journal on Emerging Technologies in Computing Systems (JETC)
影响因子:
--
通讯作者:
Michiel Van Beirendonck;Jan-Pieter D'Anvers;A. Karmakar;J. Balasch;I. Verbauwhede
Michiel Van Beirendonck;Jan-Pieter D'Anvers;A. Karmakar;J. Balasch;I. Verbauwhede
中科院分区:
其他
文献类型:
--
作者:
Michiel Van Beirendonck;Jan-Pieter D'Anvers;A. Karmakar;J. Balasch;I. Verbauwhede

文献摘要

被引文献

相似文献

候选的NIST后量子加密标准化在效率和理论安全性方面进行了广泛的研究,但对其侧信道安全性的研究在很大程度上缺乏。这对于它们的实际部署仍然是一个相当大的障碍,在实际部署中,侧信道安全性可能是一个关键需求。这项工作描述了Saber的一个抗侧信道实例,Saber是基于晶格的候选方案之一,使用掩蔽作为对抗措施。由于两种特定的设计选择:2次幂模和舍入学习的有限噪声采样,Saber被证明是非常有效的掩模。掩蔽基于格的密码系统的一个主要挑战是将位操作与算术掩蔽集成在一起,这需要算法在掩蔽表示之间安全地转换。所描述的设计包括一种新的基元,用于在算术份额上进行掩模逻辑移位,并将现有的掩模二项采样器用于Saber。给出了ARM Cortex-M4微控制器的实现,并对其侧通道电阻进行了实验验证。掩码实现的开销系数为2.5倍,明显低于之前报道的NewHope掩码变体的5.7倍。掩码解封装在Cortex-M4上需要少于3,000,000个周期,消耗的动态内存小于12kB,适合在嵌入式平台上部署。
The candidates for the NIST Post-Quantum Cryptography standardization have undergone extensive studies on efficiency and theoretical security, but research on their side-channel security is largely lacking. This remains a considerable obstacle for their real-world deployment, where side-channel security can be a critical requirement. This work describes a side-channel-resistant instance of Saber, one of the lattice-based candidates, using masking as a countermeasure. Saber proves to be very efficient to masking due to two specific design choices: power-of-two moduli and limited noise sampling of learning with rounding. A major challenge in masking lattice-based cryptosystems is the integration of bit-wise operations with arithmetic masking, requiring algorithms to securely convert between masked representations. The described design includes a novel primitive for masked logical shifting on arithmetic shares and adapts an existing masked binomial sampler for Saber. An implementation is provided for an ARM Cortex-M4 microcontroller, and its side-channel resistance is experimentally demonstrated. The masked implementation features a 2.5x overhead factor, significantly lower than the 5.7x previously reported for a masked variant of NewHope. Masked key decapsulation requires less than 3,000,000 cycles on the Cortex-M4 and consumes less than 12kB of dynamic memory, making it suitable for deployment in embedded platforms.