A 4900- $mu$ m2 839-Mb/s Side-Channel Attack- Resistant AES-128 in 14-nm CMOS With Heterogeneous Sboxes, Linear Masked MixColumns, and Dual-Rail Key Addition

A 4900- $mu$ m2 839-Mb/s Side-Channel Attack- Resistant AES-128 in 14-nm CMOS With Heterogeneous Sboxes, Linear Masked MixColumns, and Dual-Rail Key Addition
复制标题

采用 14 nm CMOS 的 4900-$mu$ m2 839-Mb/s 侧通道抗攻击 AES-128,具有异构 Sbox、线性屏蔽混合列和双轨密钥添加

DOI:
--
复制
发表时间:
2020
影响因子:
5.4
通讯作者:
S. Mathew
S. Mathew
中科院分区:
工程技术1区
文献类型:
--
作者:
Raghavan Kumar;Vikram B. Suresh;Monodeep Kar;Sudhir K. Satpathy;M. Anders;Himanshu Kaul;A. Agarwal;S. Hsu;Gregory K. Chen;R. Krishnamurthy;V. De;S. Mathew

文献摘要

被引文献

相似文献

高级加密标准(AES)等加密电路容易受到相关功率分析(CPA)侧通道攻击(SCA),在SCA攻击中,敌方监视芯片提供电流签名或电磁(EM)发射,以解密嵌入密钥的值。本文介绍了一种全数字、全可综合的抗SCA 16-b系列AES-128硬件加速器,该加速器采用14 nm CMOS制,占地4900;lt;内嵌公式;<tex-ath notation=“LaTeX”>$MUX{m}^{2}$</tex-ath&>;/内嵌-公式&>。通过异类Sbox、线性掩码MixColumns和双轨AddRoundKey电路的随机化字节顺序洗牌实现:1)9.2;内联公式;;和lt;文本数学符号=“LaTeX”;$imes$</文本-数学&>;/行内-公式>与在14-nm中实现的未受保护的AES相比,当前签名与汉明距离(HD)/汉明重量(HW)功率模型之间的相关性更低;2)2.3<内嵌-公式&>;<$imes$</tex-ath&></内联公式>正确密钥猜测的相关比衰减;3)839-Mb/S加密吞吐量,总功耗为750 mV,25°C;4)在290 mV,25°C的能量最佳点测得的最高能效为390 Gbps/W,比无保护的AES引擎的开销高23%;5)<1%的性能影响与未受保护的AES;6)>1200<与未受保护的AES加速器相比,在最小痕迹泄露(MTD)方面有了改进,在1200万次加密后没有观察到成功的CPA攻击;以及7)>1100<inline-form>;改进功率和电磁时频域分析中的测试矢量泄漏评估(TVLA)度量。
Cryptographic circuits such as advanced encryption standard (AES) are vulnerable to correlation power analysis (CPA) side-channel attacks (SCAs), where an adversary monitors chip supply current signatures or electromagnetic (EM) emissions to decipher the value of embedded keys. This article describes an all-digital, fully synthesizable SCA-resistant 16-b serial AES-128 hardware accelerator fabricated in 14-nm CMOS, occupying 4900 <inline-formula> <tex-math notation="LaTeX">$mu ext{m}^{2}$ </tex-math></inline-formula>. Randomized byte-order shuffling through heterogeneous Sboxes, linear masked MixColumns, and dual-rail AddRoundKey circuits enable: 1) 9.2<inline-formula> <tex-math notation="LaTeX">$ imes $ </tex-math></inline-formula> lower correlation between current signatures and hamming distance (HD)/hamming weight (HW) power models compared to an unprotected AES implemented in 14-nm CMOS; 2) 2.3<inline-formula> <tex-math notation="LaTeX">$ imes $ </tex-math></inline-formula> attenuation of a correlation ratio for correct key guesses; 3) 839-Mb/s encryption throughput with 11-mW total power consumption measured at 750 mV, 25 °C; 4) peak energy efficiency of 390 Gbps/W measured at an energy optimal point of 290 mV, 25 °C, representing an overhead of 23% over the unprotected AES engine; 5) < 1% performance impact compared to unprotected AES; 6) >1200<inline-formula> <tex-math notation="LaTeX">$ imes $ </tex-math></inline-formula> improvement in minimum-traces-to-disclosure (MTD) over an unprotected AES accelerator, with no successful CPA attacks observed after 12M encryptions; and 7) >1100<inline-formula> <tex-math notation="LaTeX">${ imes }$ </tex-math></inline-formula> improvement in test vector leakage assessment (TVLA) metric in power and EM time- and frequency-domain analyses.