An Efficient Implementation of SMS4 Cipher with Multiplicative Masking Resistant to Differential Power Analysis Attack
Yanhua Xu, Xuefei Bai, Li Guo · 2009
Since differential power analysis was introduced by Paul Kocher, many countermeasures have been proposed to protect implementations of cryptographic algorithms. Among them, the masking is an efficient method. SMS4 cipher was proved to be vulnerable to first-order DPA attacks, but there has been no countermeasure for it until now. In this paper, we focus on the security of SMS4 implementation, and present a secure implementation of SMS4 cipher with multiplicative masking. Moreover, composite field arithmetic, sharing and reusing hardware resources, and changing calculating orders are employed to produce a small SMS4 circuit. Using SMIC 0.18 mum CMOS technology, this design requires only about 25 k-gates of area to support both encryption and decryption with 200 Mbps throughput.