Side Channel Attacks Database
|
|
|
|
|
|
A Very Compact Perfectly Masked S-Box for AES (corrected) |
 |
|
|
D. Canright, Lejla Batina, |
|
|
IACR 2009 |
|
| Abstract: |
|
Implementations of the Advanced Encryption Standard (AES), including hardware applications with limited resources (e.g., smart cards), may be vulnerable to side-channel attacks such as differential power analysis. One countermeasure against such attacks is adding a random mask to the data; this randomizes the statistics of the calculation at the cost of computing mask corrections. The single nonlinear step in each AES round is the S-box (involving a Galois inversion), which incurs the majority of the cost for mask corrections. Oswald et al. showed how the tower field representation allows maintaining an additive mask throughout the Galois inverse calculation. This work applies a similar masking strategy to the most compact (unmasked) S-box to date. The result is the most compact masked S-box so far, with perfect masking (by the definition of Blomer) giving suitable implementations immunity to first-order differential side-channel attacks. |
|
| Paper Available At: |
|
http://eprint.iacr.org/2009/011 |
|
|
|
|
|
|
|
|
|
|
|
|
Cited By: |
|
|
|
|
|
|
|
|
|
Sort: |
|
This paper has been referenced 0 times, showing 1-10 |
Page 1 of 0
|
|
|
|
|
|
|
|
|
|
|
|
| Comments About Paper |
|
|
|
|
| Post a Comment |
|
|
Enter the code shown:
|
| Name: |
|
| Email (optional) |
|
| Comment: |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| Direct any
comments, questions, omissions, criticizm here |
 |
|
|
|