Operation Shuffling with Multiple S-Boxes Against Power Analysis Attacks
Shota Kajiya, Hiroki Nishikawa, Kota Yoshida, Ittetsu Taniguchi, Takao Onoye · 2025
With the proliferation of IoT devices, hardware devices are exposed to side-channel attacks such as power analysis attacks. In particular, the SubBytes function of the Advanced Encryption Standard (AES) has been pointed out as a vulnerability, and countermeasures against it are required. One of common mitigation technique is shuffling, which randomizes the order in which transformations are performed using S-boxes. However, due to the characteristics of S-boxes, the number of combinations of the execution order is not sufficient, and the secret key can be easily revealed by increasing the power trace. In this study, we propose shuffling with multiple S-boxes in the SubBytes function. From the experiment, the number of secret keys revealed by CPA decreased from 16 to 0 compared to the no-countermeasure case and the existing method. In addition, when comparing the execution time of the proposed method with that of the no-countermeasure case, the proposed method increased the execution time by 0.6%.