On Ciphers that Continuously Access the Non-Volatile Key

On Ciphers that Continuously Access the Non-Volatile Key
复制标题

DOI:
10.13154/tosc.v2016.i2.52-79
复制
发表时间:
2017-02
期刊:
IACR Trans. Symmetric Cryptol.
影响因子:
--
通讯作者:
Vasily Mikhalev;Frederik Armknecht;Christian Müller
Vasily Mikhalev;Frederik Armknecht;Christian Müller
中科院分区:
其他
文献类型:
--
作者:
Vasily Mikhalev;Frederik Armknecht;Christian Müller

文献摘要

被引文献

相似文献

由于越来越多的设备使用有限的资源,如有限的区域大小,功率或能量,社区已经开发了各种技术来设计轻量级密码。越来越多地讨论的一种方法是使用存储在设备上的非易失性存储器中的密码密钥,不仅用于寄存器的初始化,而且还用于加密/解密过程。最近的例子是Midori(Asiacrypt'15)和Sunday(FSE'15)。这一方面可以帮助节省资源,但也可以允许更强的密钥参与并因此允许更高的安全性。然而,到目前为止,公众对这种方法是否以及在多大程度上确实可行知之甚少。因此,没有很强的工程背景的密码学家面临的问题是,他们不能评估某些设计是否合理(从实用的角度来看),这阻碍了新设计的开发。在这项工作中,我们从实用的角度来探讨这一设计原则。在讨论了将密钥存储在非易失性存储器中的合理方法之后,以几种商业产品为例,重点讨论了将密钥存储在EEPROM中的情况。在这里,我们强调现有的限制,并得出一些设计,基于对它们的吞吐量的影响,更适合于从所有类型的非易失性存储器连续阅读密钥的方法。基于这些发现,我们改进了设计,提出了一个新的轻量级流密码,(i)具有显着小于几乎所有其他流密码的面积大小和(ii)可以有效地实现使用常见的非易失性存储器技术的SSTOM。因此,我们认为,我们的工作是使这种设计有更坚实的基础并就现实的设计展开进一步讨论的重要一步。
Due to the increased use of devices with restricted resources such as limited area size, power or energy, the community has developed various techniques for designing lightweight ciphers. One approach that is increasingly discussed is to use the cipher key that is stored on the device in non-volatile memory not only for the initialization of the registers but during the encryption/decryption process as well. Recent examples are the ciphers Midori (Asiacrypt’15) and Sprout (FSE’15). This may on the one hand help to save resources, but also may allow for a stronger key involvement and hence higher security. However, only little is publicly known so far if and to what extent this approach is indeed practical. Thus, cryptographers without strong engineering background face the problem that they cannot evaluate whether certain designs are reasonable (from a practical point of view) which hinders the development of new designs. In this work, we investigate this design principle from a practical point of view. After a discussion on reasonable approaches for storing a key in non-volatile memory, motivated by several commercial products we focus on the case that the key is stored in EEPROM. Here, we highlight existing constraints and derive that some designs, based on the impact on their throughput, are better suited for the approach of continuously reading the key from all types of non-volatile memory. Based on these findings, we improve the design of Sprout for proposing a new lightweight stream cipher that (i) has a significantly smaller area size than almost all other stream ciphers and (ii) can be efficiently realized using common non-volatile memory techniques. Hence, we see our work as an important step towards putting such designs on a more solid ground and to initiate further discussions on realistic designs.