The Width-w NAF Method Provides Small Memory and Fast Elliptic Scalar Multiplications Secure against Side Channel Attacks
The Width-w NAF Method Provides Small Memory and Fast Elliptic Scalar Multiplications Secure against Side Channel Attacks
复制标题
DOI:
10.1007/3-540-36563-x_23
复制
发表时间:
2003-04
期刊:
影响因子:
--
通讯作者:
K. Okeya;T. Takagi
中科院分区:
文献类型:
--
作者:
K. Okeya;T. Takagi
The side channel attack (SCA) is a serious attack on wearable devices that have scarce computational resources. Cryptographic algorithms on them should be efficient using small memory — we have to make efforts to optimize the trade-off between efficiency and memory. In this paper we present efficient SCA-resistant scalar multiplications based on window method. Möller proposed an SPA-resistant window method based on 2w-ary window method, which replacesw-consecutive zeros to 1 plusw-consecutive 1 and it requires 2wpoints of table (or 2w-1+1 points if the signed 2w-ary is used). The most efficient window method with small memory is the width-wNAF, which requires 2w-2points of table. In this paper we convert the width-wNAF to an SPA-resistant addition chain. Indeed we generate a scalar sequence with the fixed pattern, e.g. 0..0x0..0x...0..0x, wherexis positive odd points < 2w. Thus the size of the table is 2w-1, which is optimal in the construction of the SPA-resistant chain based on width-wNAF. The table sizes of the proposed scheme are 6% to 50% smaller than those of Möller’s scheme forw= 2, 3, 4, 5, which are relevant choices in the sense of efficiency for 160-bit ECC.