A comprehensive analysis of performance and side-channel-leakage of AES SBOX implementations in embedded software

Ambuj Sinha, Zhimin Chen, Patrick R. Schaumont · 2010

The Advanced Encryption Standard is used in almost every new embedded application that needs a symmetric-key ci-pher. In such embedded applications, high-performance as well as resistance against implementation attacks is manda-tory. In this paper, we compare and contrast three different software implementations of AES. The first two are based on cryptographic lookup tables, while the third uses bit-slicing. We analyze the performance and side-channel resistance of each implementation on two different FPGA platforms, one based on a PowerPC processor, and the second based on a LEON-3 soft-core processor. Our measurements show that, on embedded platforms, a bit-sliced AES implementation does not always outperform a lookup-table based AES im-plementation. We also present a detailed analysis of the side-channel resistance and the source of side-channel leak-age, and show that our bit-sliced implementation has eight times more side-channel leakage than the lookup-table im-plementations. Hence, we conclude that a variation on the implementation style for embedded software implementation of AES will not only affect performance, but also embedded system security.

Read the paper · More papers on PaperTik