FPGA Implementation of ECC: Low-Cost Countermeasure against Horizontal Bus and Address-Bit SCA

Ievgen Kabin, Dan Kreiser, Zoya Dyka, Peter Langendöerfer · 2018

Designing tamper resistant implementation of cryptographic operations is a tricky and complex task. In this paper we discuss the addressing in hardware implementations, that has been reported as a significant problem in the past and explain by which means its impact can be significantly reduced. We use horizontal DPA and DEMA attacks to identify clock cycles that leak most. Then we describe two new designs in which the addressing is modified. The first one avoids recurring of the same data on the bus of the implementation and the second one realizes additionally a regular sequence of the addresses. We used an FPGA implementation to verify the effect of this approach and analysed power and electromagnetic traces. The number of clock cycles in which key candidates were extracted with a correctness of more than 90 per cent was reduced from 14 to zero attacking a power trace and from 21 to 5 attacking an electromagnetic trace for the latter design variant.

Read the paper · More papers on PaperTik