First-order DPA Vulnerability of Rijndael: Security and Area-delay Optimization Trade-off

Monjur Alam, Santosh Ghosh, Dipanwita Roy Chowdhury, Indranil SenGupta · 2013

Differential Power Analysis (DPA) attack for smart card, ASIC or micro controller based on crypto-systems have been demonstrated by several authors. Masking is a very well known approach as a DPA countermeasure. Due to cascading architecture of masked multiplier, the existing masking schemes increase timing and area complexity. Balanced masked architecture brings poor security guaranty. In this paper, we propose a masked multiplier which reduces path delay as compared to the existing ones in the literature. The proposed masked S-box has two level of area optimization. One is avoiding transformation cost and other is using masked bits in sharing mode. We explore security issues in the context of first-order and second-order DPA attacks. We have demonstrated that our approach indeed prevents the first order DPA attack of the Rijndael circuit implemented on FPGA. The proposed masked AES S-box is the most compact one (in terms of area and path delay) as well as secure in the context of first order DPA attack.

Read the paper · More papers on PaperTik