Configurable Loop Shuffling via Instruction Set Extensions
Songqiao Cui, Josep Balasch · 2024
Hiding is a popular countermeasure against side-channel attacks. In software contexts, it typically involves adding time domain randomizations by shuffling the execution order of operations and/or by inserting dummy instructions. The combination of such countermeasures demands the presence of a random permutation algorithm, in addition to extra program flow control steps, leading to significant overheads in the software implementation. In this work, we improve the performance of such hiding countermeasures by designing a hardware engine capable of shuffling the execution order of software loops. Our engine can be easily integrated into a processor architecture and configured by means of custom instruction set extensions. We demonstrate this by prototyping and evaluating it on the CV32E40P RISC-V core (formerly RI5CY). For this particular platform, we additionally combine our engine with its native hardware loop feature and propose instructions capable of permuting memory access addresses at runtime. We validate the functional correctness of our design by targeting two algorithms explored in related works: the popular AES block cipher and the Number Theoretic Transform (NTT) found in several post-quantum cryptographic algorithms. For both designs, we benchmark the performance overheads of the resulting implementations and validate their increased security by means of practical experiments on an FPGA.