Enabling Microarchitectural Randomization in Serialized AES Implementations to Mitigate Side Channel Susceptibility

Enabling Microarchitectural Randomization in Serialized AES Implementations to Mitigate Side Channel Susceptibility
复制标题

在串行化 AES 实现中启用微架构随机化以减轻侧信道敏感性

DOI:
10.1109/isvlsi.2019.00064
复制
发表时间:
2019
期刊:
2019 IEEE Computer Society Annual Symposium on VLSI (ISVLSI)
影响因子:
--
通讯作者:
Daniel E. Holcomb
Daniel E. Holcomb
中科院分区:
--
文献类型:
--
作者:
S. Dhanuskodi;Daniel E. Holcomb

文献摘要

被引文献

相似文献

AES分组密码的高度串行化实现用于轻量级应用中,其中低面积和低功耗是主要关注点。这些轻量级设计的安全性在物联网时代的资源受限设备上变得越来越重要。AES算法不具有任何显著的已知密码分析弱点,但密钥通常可以通过使用侧信道信息泄漏或故障注入攻击实现弱点来提取。高度串行化的AES实现在每个周期中对数据的各个字节/字进行计算,这使得它们对侧通道密钥提取特别敏感,因为掩盖侧通道泄漏的总功耗更少。在这项工作中,我们提出了一个有效的AES微架构,随机化子轮操作,并减少对电源侧通道攻击的敏感性。我们提出的架构是兼容的,并补充,所有现有的电路级侧信道对策。我们设计了一个8位AES架构在商业16纳米FinFET技术,并观察到一个数量级的改善侧沟道保护的成本36%以上的面积和25%以上的能源每加密。测试芯片在10 MHz时的功耗为0.93pJ/bit。
Highly serialized implementations of the AES block cipher are used in lightweight applications where low area and low power are the primary concerns. Security of these lightweight designs becomes increasingly critical on resource-constrained devices in the Internet of Things era. The AES algorithm does not have any significant known cryptanalytic weaknesses, but keys can often be extracted by attacking implementation weaknesses using side channel information leakage or fault injection. Highly serialized AES implementations compute on individual bytes/words of data in each cycle which leaves them especially sensitive to side channel key extraction because there is less overall power consumption to obscure side channel leakages. In this work, we present an efficient AES microarchitecture that randomizes sub-round operations and reduces susceptibility to power side channel attacks. The architecture we propose is compatible with, and complementary to, all existing circuit-level side channel countermeasures. We design an 8-bit AES architecture in a commercial 16nm FinFET technology and observe an order of magnitude improvement in side channel protection at a cost of 36% more area and 25% more energy per encryption. Testchip measurement shows 0.93pJ/bit energy consumption at 10MHz.