Concealing Secrets in Embedded Processors Designs

Concealing Secrets in Embedded Processors Designs
复制标题

DOI:
10.1007/978-3-319-54669-8_6
复制
发表时间:
2016-11
期刊:
IACR Cryptol. ePrint Arch.
影响因子:
--
通讯作者:
Hannes Gross;Manuel Jelinek;S. Mangard;Thomas Unterluggauer;M. Werner
Hannes Gross;Manuel Jelinek;S. Mangard;Thomas Unterluggauer;M. Werner
中科院分区:
其他
文献类型:
--
作者:
Hannes Gross;Manuel Jelinek;S. Mangard;Thomas Unterluggauer;M. Werner

文献摘要

被引文献

相似文献

侧信道分析(SCA)攻击对嵌入式系统构成了严重威胁。到目前为止,掩蔽作为对抗SCA的对策的研究仅仅集中在加密算法上,并且已经针对特定的硬件或软件实现。然而,保护特定实现的缺点是在所使用的算法方面缺乏灵活性,不可能更新受保护的硬件实现,以及用于保护新算法的长开发周期。此外,加密算法通常只是对信息资产进行操作的嵌入式系统的一部分。因此,仅保护系统的这一部分对于大多数安全关键的嵌入式应用程序是不够的。在这项工作中,我们介绍了一种灵活的,SCA保护的处理器设计的基础上开源的V级RISC-V处理器。所介绍的处理器设计可以被合成以抵抗任意攻击顺序的SCA攻击。一旦合成,处理器保护安全敏感数据的计算免受侧信道泄漏。我们的方法的好处是:(1)灵活性和可更新性,(2)更快地开发SCA保护系统,(3)对软件开发人员的透明度,(4)任意SCA保护级别,(5)不仅保护加密算法,而且保护一般由处理敏感数据引起的泄漏。
Side-channel analysis (SCA) attacks pose a serious threat to embedded systems. So far, the research on masking as a countermeasure against SCA focuses merely on cryptographic algorithms, and has either been implemented for particular hardware or software implementations. However, the drawbacks of protecting specific implementations are the lack of flexibility in terms of used algorithms, the impossibility to update protected hardware implementations, and long development cycles for protecting new algorithms. Furthermore, cryptographic algorithms are usually just one part of an embedded system that operates on informational assets. Protecting only this part of a system is thus not sufficient for most security critical embedded applications.In this work, we introduce a flexible, SCA-protected processor design based on the open-source V-scale RISC-V processor. The introduced processor design can be synthesized to defeat SCA attacks of arbitrary attack order. Once synthesized, the processor protects the computation on security-sensitive data against side-channel leakage. The benefits of our approach are (1) flexibility and updatability, (2) faster development of SCA-protected systems, (3) transparency for software developers, (4) arbitrary SCA protection level, (5) protection not only for cryptographic algorithms, but against leakage in general caused by processing sensitive data.