Binary Ring-LWE hardware with power side-channel countermeasures

Binary Ring-LWE hardware with power side-channel countermeasures
复制标题

具有电源侧信道对策的二进制 Ring-LWE 硬件

DOI:
10.23919/date.2018.8342207
复制
发表时间:
2018
期刊:
2018 Design, Automation & Test in Europe Conference & Exhibition (DATE)
影响因子:
--
通讯作者:
Mohit Tiwari
Mohit Tiwari
中科院分区:
--
文献类型:
--
作者:
Aydin Aysu;M. Orshansky;Mohit Tiwari

文献摘要

参考文献

被引文献

相似文献

我们描述了量子安全加密方案的第一个硬件实现,以及它的低成本功率侧通道对策。加密使用易于实现的带错误的二进制环学习(B-RLWE)问题,该问题具有可在硬件中高效生成的二进制错误。我们证明,由于二进制系数的性质,B-RLWE的直接实现对功率侧信道攻击,甚至对简单的功率分析都表现出脆弱性。我们通过冗余添加和内存更新来缓解此漏洞。为了进一步防止差分功率分析(DPA),我们利用B-RLWE的特定机会,基于中间状态的随机化和掩蔽门限解码来构建一种轻量级但有效的对抗措施。在SAKURA-G现场可编程门阵列板上,我们的方法与未保护设计相比,将DPA攻击所需的测量次数增加了40χ。我们的结果还量化了B-RLWE的旁信道安全性和硬件面积成本之间的权衡。
We describe the first hardware implementation of a quantum-secure encryption scheme along with its low-cost power side-channel countermeasures. The encryption uses an implementation-friendly Binary-Ring-Learning-with-Errors (B-RLWE) problem with binary errors that can be efficiently generated in hardware. We demonstrate that a direct implementation of B-RLWE exhibits vulnerability to power side-channel attacks, even to Simple Power Analysis, due to the nature of binary coefficients. We mitigate this vulnerability with a redundant addition and memory update. To further protect against Differential Power Analysis (DPA), we use a B-RLWE specific opportunity to construct a lightweight yet effective countermeasure based on randomization of intermediate states and masked threshold decoding. On a SAKURA-G FPGA board, we show that our method increases the required number of measurements for DPA attacks by 40 χ compared to unprotected design. Our results also quantify the trade-off between side-channel security and hardware area-cost of B-RLWE.
DOI: 10.13154/tches.v2018.i1.142-174
发表时间: 2018-02
期刊: IACR Cryptol. ePrint Arch.
影响因子: --
作者:
Tobias Oder;Tobias Schneider;T. Pöppelmann;Tim Güneysu
通讯作者: Tobias Oder;Tobias Schneider;T. Pöppelmann;Tim Güneysu