Non-Linear Cyclic Variable Clock Feistel Bridge-Inspired Countermeasure for Securing RISC-V Crypto-Core Against Power Attacks
Titu Mary Ignatius, Roy P. Paily · IEEE Transactions on Circuits and Systems I Regular Papers · 2025
With the increasing popularity of Internet of Things Edge (IoTe) devices, RISC-V emerges as the most suitable architecture for various applications. Since attackers have direct physical access to these IoTe devices, securing these RISC-V designs is of major concern. This research article first focuses on designing a low-power high-performance, RISC-V crypto-core for high security applications, which significantly enhances the efficiency of the AES encryption algorithm, but still susceptible to Power Analysis Attacks (PAA). A novel Non-Linear Cyclic Variable Clock Feistel Bridge-Inspired Countermeasure (NCVCFB) providing variation in both amplitude and temporal domains of signal was introduced to enhance AES security in RISC-V based IoTe devices, specially to address the vulnerability against PAA. The NCVCFB countermeasure employs the rolling architecture and will operate in tandem with each round of AES to obscure power consumption patterns. It will execute additional random number of rounds cyclically in the first and last round of AES, based on the randomly generated number. The newly designed, secured RISC-V achieved remarkably low area and power overheads of 1.05% and 1.23%, respectively, without affecting the maximum operating frequency. Nevertheless, the throughput was decreased due to variable clock count for different plaintext. The PAA was performed using the power traces captured from post-layout design on ASIC platform at UMC 65 nm technology node as well as on the experimental hardware setup employing a Side-channel Attack Security Evaluation Board (SASEBO). The resilience of the secured RISC-V architecture against PAA was tested by subjecting it to 2 Million traces, and none of the bytes got recovered. Thus, the NCVCFB secured RISC-V attained a Measurement To Disclose (MTD) >2M, Signal to Noise Ratio (SNR) <0.5, Mutual Information (MI) in the milli range, and Test Vector Leakage Assessment (TVLA) within +/−4.5 limits.