A Compact 1,257-Gbps/W Byte-Serial AES Accelerator for IoT Applications in 22 nm
Shutao Zhang, Malte Wabnitz, Tobias Gemmeke · 2023
Security is becoming even more critical for the digital society such as loT. Especially quantum computers pose serious threats to the currently deployed crypto-systems [1], which requires double key size for symmetric cryptographic algorithms to preserve security. As the de-facto standard block cipher, Advanced Encryption Standard (AES) acts as the mainstay to secure versatile applications like data communication and storage. Therefore, an even more compact and energy-efficient AES accelerator is in urgent demand for billions of miniaturized and battery-supplied devices in loT field considering quantum security. In contrast to the traditional 128-bit datapath designs, several byte-serial architectures have been proposed obtaining smaller area [2]–[7]. On one hand, single SBox is exploited for both data encryption and key expander for further area reduction [2]–[5]. However, significant redundant data movements result in large energy overhead, and additional cycles for ShiftRow lower the throughput [2]–[3]. The additional registers for the intermediate storage add to control complexity as well as power consumption [4]–[5]. The long latency (336/337 cycles per encryption) negatively impacts the hardware utilization and energy efficiency. On the other hand, double SBoxes boost the throughput with a corresponding area penalty [6]–[7]. Compared to the separate SBox for data encryption and key expander in [7], one of the two Sboxes is shared between data encryption and key expander in [6], which reduces the latency from 160 cycles/encryption to 113 but is still above the algorithmic lower bound of 100 cycles for 2 SBoxes. In this paper, the proposed AES accelerator reaches a throughput equivalent to the corresponding lower bound of 200 cycles/encryption using a single SBox at 100% utilization and achieves the lowest number of registers (32 bytes) for data storage. The redundant data movement is significantly reduced with efficient data structure while preserving high clock frequency. Through the multi-objective optimization, the proposed AES-128 encryption accelerator is well suited for embedded systems with tight area, throughput and energy constraints.