Very High Order Masking: Efficient Implementation and Security Evaluation

Very High Order Masking: Efficient Implementation and Security Evaluation
复制标题

DOI:
10.1007/978-3-319-66787-4_30
复制
发表时间:
2017-09
期刊:
IACR Cryptol. ePrint Arch.
影响因子:
--
通讯作者:
Anthony Journault;François-Xavier Standaert
Anthony Journault;François-Xavier Standaert
中科院分区:
其他
文献类型:
--
作者:
Anthony Journault;François-Xavier Standaert

文献摘要

被引文献

相似文献

在本文中,我们研究的性能和安全性,最近专门用于并行实现的屏蔽算法在32位嵌入式软件平台,标准AES Rijndael和位片密码Fantomas。通过利用这些算法用于位片实现的优秀功能,我们首先扩展了Goudarzi和Rivain最近的速度记录(在Eurocrypt 2017上展示),并报告了具有32个份额的屏蔽实现的现实时间。然后,我们观察到,这样的实现提供的安全级别是不容易量化与当前的评估工具。因此,我们提出了一种新的“多模型”的评估方法,它利用不同的(或多或少抽象)的安全模型在文献中介绍。这种方法使我们能够以原则性的方式约束我们实现的安全级别,并根据充分理解的参数评估夸大安全性的风险。具体地说,它使我们得出结论,这些实现经受住了最坏情况下的对手与可证伪的假设下的测量。
In this paper, we study the performances and security of recent masking algorithms specialized to parallel implementations in a 32-bit embedded software platform, for the standard AES Rijndael and the bitslice cipherFantomas. By exploiting the excellent features of these algorithms for bitslice implementations, we first extend the recent speed records of Goudarzi and Rivain (presented at Eurocrypt 2017) and report realistic timings for masked implementations with 32 shares. We then observe that the security level provided by such implementations is uneasy to quantify with current evaluation tools. We therefore propose a new “multi-model” evaluation methodology which takes advantage of different (more or less abstract) security models introduced in the literature. This methodology allows us to both bound the security level of our implementations in a principled manner and to assess the risks of overstated security based on well understood parameters. Concretely, it leads us to conclude that these implementations withstand worst-case adversaries withmeasurements under falsifiable assumptions.