Reconciling d+1 Masking in Hardware and Software

Reconciling d+1 Masking in Hardware and Software
复制标题

DOI:
10.1007/978-3-319-66787-4_6
复制
发表时间:
2017-09
期刊:
IACR Cryptol. ePrint Arch.
影响因子:
--
通讯作者:
Hannes Gross;S. Mangard
Hannes Gross;S. Mangard
中科院分区:
其他
文献类型:
--
作者:
Hannes Gross;S. Mangard

文献摘要

被引文献

相似文献

安全相关的自治设备数量不断增长,需要有效的机制来抵御低成本的侧信道分析(SCA)攻击。屏蔽在可调整的安全级别上提供了对SCA的高抵抗力。然而,高级别的SCA阻力与对新随机性的需求不断增加密切相关,这大大增加了实现成本。由于基于硬件的屏蔽方案比软件屏蔽方案有其他的安全要求,在过去的十年里,这两个领域的研究已经相当独立地进行。一个重要的实际差异是,最近公布的软件方案实现了较低的随机性足迹比硬件屏蔽方案。在这项工作中,我们将联合收割机现有的软件和硬件掩蔽计划到一个统一的掩蔽算法。我们演示了如何保护软件和硬件实现使用相同的掩蔽算法,并降低随机性成本比单独的计划。特别是对于硬件实现的随机性成本,在某些情况下可以减半的最先进的状态。理论上的考虑,以及实际的实施结果,然后用于与现有的计划从不同的角度和在不同的安全级别进行比较。
The continually growing number of security-related autonomous devices requires efficient mechanisms to counteract low-cost side-channel analysis (SCA) attacks. Masking provides high resistance against SCA at an adjustable level of security. A high level of SCA resistance, however, goes hand in hand with an increasing demand for fresh randomness which drastically increases the implementation costs. Since hardware based masking schemes have other security requirements than software masking schemes, the research in these two fields has been conducted quite independently over the last ten years. One important practical difference is that recently published software schemes achieve a lower randomness footprint than hardware masking schemes. In this work we combine existing software and hardware masking schemes into a unified masking algorithm. We demonstrate how to protect software and hardware implementations using the same masking algorithm, and for lower randomness costs than the separate schemes. Especially for hardware implementations the randomness costs can in some cases be halved over the state of the art. Theoretical considerations as well as practical implementation results are then used for a comparison with existing schemes from different perspectives and at different levels of security.