Exploring RFC 7748 for Hardware Implementation: Curve25519 and Curve448 with Side-Channel Protection

Exploring RFC 7748 for Hardware Implementation: Curve25519 and Curve448 with Side-Channel Protection
复制标题

探索 RFC 7748 的硬件实现:具有侧通道保护的 Curve25519 和 Curve448

DOI:
--
复制
发表时间:
2018
期刊:
Journal of Hardware and Systems Security
影响因子:
--
通讯作者:
Tim Güneysu
Tim Güneysu
中科院分区:
--
文献类型:
--
作者:
Pascal Sasdrich;Tim Güneysu

文献摘要

被引文献

相似文献

最近对现代ECC中的操纵和后门的揭露引发了对现有方案的修订,并导致选择RFC 7748中提出的下一代TLS的两个新解决方案:Curve 25519和Curve 448。不幸的是,这两条曲线主要是针对软件实现而设计和优化的;它们在硬件中的实现和针对SCA的物理保护在设计阶段被忽略了。在这项工作中,我们证明了这两条曲线确实可以有效和安全地映射到现代FPGA的硬件结构,同时包括针对物理攻击的高级保护机制,并仍然提供高性能和吞吐量。特别是,我们的曲线25519架构提供了超过1 700点乘法每秒,仅使用1 006逻辑片(LS)和20个数字信号处理器(DSP)的中档Xilinx XC 7Z 020 FPGA。此外,我们的Curve 448架构仍然可以在224位的更高安全级别下实现每秒600次以上的操作,在同一设备上使用不超过1 985个LS和33个DSP。此外,我们对两种架构进行了实际的、基于测试的泄漏评估。更准确地说,我们分别研究了标量和基点可靠泄漏的检测,而我们的设计则结合了标量盲法和点随机化对策。最终,我们的研究结果证明,具有很高的信心,我们不能检测到任何标量和基点可靠的泄漏,即使在评估1 000 000功率测量。
Recent revelations on manipulations and back-doors in modern ECC have initiated the revision of existing schemes and led to the selection of two new solutions for next-generation TLS proposed in RFC 7748: Curve25519 and Curve448. Unfortunately, both curves were designed and optimized primarily for software implementations; their implementation in hardware and physical protection against SCA has been neglected during the design phase. In this work, we demonstrate that both curves can indeed be efficiently and securely mapped to hardware structures of modern FPGAs while including advanced protection mechanisms against physical attacks and still providing high performance and throughput. In particular, our Curve25519 architecture provides more than 1 700 point multiplications per second, using only 1 006 logic slices (LSs) and 20 digital signal processors (DSPs) of a mid-range Xilinx XC7Z020 FPGA. Furthermore, our Curve448 architecture still achieves more than 600 operations per second at a significantly higher security level of 224 bits, using not more than 1 985 LSs and 33 DSPs on the same device. In addition, we performed a practical, test-based leakage assessment for both architectures. More precisely, we investigated the detection of scalar- and base-point-dependable leakage individually while our designs were incorporated scalar blinding and point randomization countermeasures. Eventually, our findings prove with high confidence, that we cannot detect any scalar- and base-point-dependable leakage even after evaluating 1 000 000 power measurements.