Masking against Higher-Order Side Channel Analysis ?
Guillaume Fumaroli, Ange Martinelli, Emmanuel Prou, Matthieu Rivain · 2010
In the last decade, an eort has been made by the research community to nd ecient ways to thwart side channel analysis (SCA) against physical implementations of cryptographic algorithms. A com- mon countermeasure for implementations of block ciphers is Boolean masking which randomizes by the bitwise addition of one or several random value(s) to the variables to be protected. However, advanced techniques called higher-order SCA attacks exist that overcome such a countermeasure. These attacks are greatly favored by the very nature of Boolean masking. In this paper, we revisit the ane masking initially introduced by Von Willich in 2001 as an alternative to Boolean mask- ing. We show how to apply it to AES at the cost of a small timing overhead compared to Boolean masking. We then conduct an in-depth analysis pinpointing the leakage reduction implied by ane masking. Our results clearly show that the proposed scheme provides an excellent performance-security trade-o to protect AES against higher-order SCA.