Side-channel Leakage Assessment Metrics: A Case Study of GIFT Block Ciphers

Side-channel Leakage Assessment Metrics: A Case Study of GIFT Block Ciphers
复制标题

DOI:
10.1109/isvlsi51109.2021.00051
复制
发表时间:
2021-07
期刊:
2021 IEEE Computer Society Annual Symposium on VLSI (ISVLSI)
影响因子:
--
通讯作者:
W. Unger;L. Babinkostova;Mike Borowczak;Robert Erbes
W. Unger;L. Babinkostova;Mike Borowczak;Robert Erbes
中科院分区:
其他
文献类型:
--
作者:
W. Unger;L. Babinkostova;Mike Borowczak;Robert Erbes

文献摘要

被引文献

相似文献

确定适当的安全级别并提供后续机制来实现它,是嵌入式计算设备最紧迫的问题之一。虽然存在一些可用于资源丰富的计算机系统的解决方案,但是将这些解决方案直接应用于资源受限的环境通常是不可行的。这种资源受限系统的基本问题是当前的密码算法利用显著的能量消耗和存储开销的事实。密码算法及其物理实现都影响密码系统对侧信道攻击的弹性。侧信道攻击表示利用泄漏来提取敏感信息(例如密钥)的过程。本文主要研究了基于功耗泄漏的相关功耗分析(CPA)边信道攻击。2016年,美国商务部国家标准与技术研究所(NIST)发起了新的加密算法提案的呼吁,以加强网络设备对网络攻击的加密防御,并保护这些无数设备创建的数据。这项工作评估了NIST候选方案PICCOLO、GIFT和PRESENT使用的S盒,以及几个在经典密码分析中表现出足够弱点的S盒变体,以便在对CPA攻击的弹性方面进行定量比较。三个著名的理论指标进行评估:透明度顺序(TO和RTO),非线性,和信号噪声比(SNR),旨在表征这些S盒对利用物理泄漏的对手的阻力。通过ChipWhisperer平台获得了对8位XMEGA进行攻击的实验结果,在所有评估的S盒中,发现带有PICCOLO S盒的GIFT 64最容易受到CPA的影响。结果表明,TO和RTO的变化不足以确保实际的CPA电阻,并且在具有相等非线性的S盒中,TO和SNR变量没有显著差异。
Determination of an adequate level of security and providing subsequent mechanisms to achieve it, is one of the most pressing problems regarding embedded computing devices. While there are some solutions available for resource-rich computer systems, direct application of these solutions to resource-constrained environments are often unfeasible. The fundamental problem for such resource-constrained systems is the fact that current cryptographic algorithms utilize significant energy consumption and storage overhead. Both the cryptographic algorithm and its physical implementation affect the resilience of a cryptosystem against side-channel attacks. A side-channel attack represents a process that exploits leakages in order to extract sensitive information such as the key. This paper focuses on Correlation Power Analysis (CPA) which is side-channel attack based on the power consumption leakage. In 2016 the U.S. Commerce Department’s National Institute of Standards and Technology (NIST) initiated the call for proposals of new cryptographic algorithms to strengthen the cryptographic defense of networked devices against cyberattacks and to protect the data created by those innumerable device. This work evaluates S-boxes used by NIST candidates PICCOLO, GIFT, and PRESENT, as well as several S-box variants that demonstrated sufficient weaknesses against classical cryptanalysis, for a quantitative comparison in terms of resiliency to CPA attack. Three well-known theoretical metrics are evaluated: transparency order (TO and RTO), non-linearity, and signal-to-noise (SNR) ratio, aiming to characterize the resistance of these S-boxes against adversaries exploiting physical leakages. Experimental results from attacks on an 8-bit XMEGA were obtained via the ChipWhisperer platform and of all the S-boxes evaluated, GIFT64 with a PICCOLO S-box was found to be the most susceptible to CPA. Results showed that variations in TO and RTO were not sufficient to ensure practical CPA resistance and that among S-boxes with equal non-linearity there were no significant differences in the TO and SNR variants.