Syn-STELLAR: An EM/Power SCA-Resilient AES-256 With Synthesis-Friendly Signature Attenuation

Syn-STELLAR: An EM/Power SCA-Resilient AES-256 With Synthesis-Friendly Signature Attenuation
复制标题

DOI:
10.1109/jssc.2021.3113335
复制
发表时间:
2021-10
影响因子:
5.4
通讯作者:
A. Ghosh;D. Das;Josef Danial;V. De;Santosh K. Ghosh;Shreyas Sen
A. Ghosh;D. Das;Josef Danial;V. De;Santosh K. Ghosh;Shreyas Sen
中科院分区:
工程技术1区
文献类型:
--
作者:
A. Ghosh;D. Das;Josef Danial;V. De;Santosh K. Ghosh;Shreyas Sen

文献摘要

被引文献

相似文献

数学上安全的加密算法以相关功率和电磁(EM)信号的形式泄漏有意义的旁路信息,导致物理旁路分析(SCA)攻击。针对电源/EM SCA的电路级对策包括电流均衡器、IVR、非线性LDO、高达10M迹线的增强保护和电流域签名衰减(CDSA),以及与算术对策级联的随机NL-LDO实现了高达1B的保护。这项工作采用了模拟CDSA的概念,但使其易于在具有数字友好电流源、数字控制回路和数字出血路径的技术节点上进行扩展,将MTD从10M增加到2.5亿(使用单个数字对策,$25\x$改善)。环形振荡器(RO)用作渗漏路径以绕过依赖于加密的泄漏,起到局部负反馈(LNFB)的作用。此外,基于RO振荡频率,可以在启动、PVT或频率变化时调整AES节点电压。因此,RO充当数字签名衰减电路(DSAC)的集成LNFB和全局反馈。另一种电路技术,即时变传递函数(TVTF),消除了电流域均衡器(迄今最佳开关电容对抗)中的直流偏置要求,使其数字化,并利用基于开关帽的电路进行时域混淆,以实现更高的安全性。这项工作,即Syn-Stella:合成友好的签名衰减嵌入式加密与低级别金属布线,结合了DSAC和TVTF技术,实现了EM和POWER SCA的MTD>1.25B,比现有技术水平高出25%。65 nm CMOS测试芯片包含无保护和受保护(DSAC和DSAC-TVTF)并行AES-256实现。该实现是第一个综合友好型对策,它将两个模拟型强保护(签名衰减和开关电容电流均衡器)融合到一个数字友好解决方案中,并实现了1.25B MTD,其功率和面积开销与以前的电路级对策相当。
Mathematically secure cryptographic algorithms leak meaningful side-channel information in the form of correlated power and electromagnetic (EM) signals, leading to physical side-channel analysis (SCA) attacks. Circuit-level countermeasures against power/EM SCA include a current equalizer, IVR, non-linear LDOs, enhancing protection up to 10M traces, and current-domain signature attenuation (CDSA), and randomized NL-LDO cascaded with arithmetic countermeasures achieved protection up to >1B. This work embraces the concept of analog CDSA but makes it easily scalable over technology nodes with digital-friendly current sources, digital control loop, and digital bleed path to increase the MTD from 10M to 250M ( $25\times $ improvement, using a single digital countermeasure). Ring oscillator (RO) used as the bleed path to bypass encryption-dependent leakage acts as local negative feedback (LNFB). Besides, based on RO oscillation frequency, AES node voltage can be tuned at startup, PVT, or frequency variation. Thus, RO acts as integrated LNFB and global feedback for the digital signature attenuation circuit (DSAC). Another circuit technique, namely, the time-varying transfer function (TVTF), removes the requirement of dc bias in the current-domain equalizer (best switch capacitor-based countermeasure till date) to make it digital and utilizes switch cap-based circuit for time-domain obfuscation to achieve enhanced security. This work, namely, Syn-STELLAR: SYNthesis-friendly Signature aTtenuation Embedded crypto with Low-Level metAl Routing, combines both DSAC and TVTF techniques to achieve an MTD > 1.25B for both EM and power SCA, which is 25% higher than the existing state of the art. The 65-nm CMOS test chip contains unprotected and both the protected (DSAC and DSAC-TVTF) parallel AES-256 implementation. This implementation is the first synthesis-friendly countermeasure, which converges two analog-type strong protections (signature attenuation and switched cap current equalizer) in a digital-friendly solution and achieves > 1.25B MTD with power and area overheads comparable to previous circuit-level countermeasures.