A 2455μm2 1.7Gbps Side-Channel Attack-Resistant Masked HMAC-SHA256 Accelerator in Intel 4 CMOS

Sachin Taneja, Vikram Suresh, Raghavan Kumar, Vivek K. De, Sanu K. Mathew · 2025

Hash-based message authentication codes (HMAC) employ shared secret keys and cryptographic hash functions to verify message authenticity and integrity, providing an energy-efficient alternative to compute-intensive public-key signature schemes [1]–[3]. Usage of secret key to compute initial state of the HMAC digest renders it vulnerable to power/electro-magnetic (EM) side-channel attacks (SCA) [3]–[7]. A typical attack employs adversary-controlled input message words$(W_{i})$to correlate measured traces with Hamming-distance (HD) power models of state registers in inner/outer SHA-256 hashes to recover the secret key$K$(Fig. 1). While HMAC attack strategies have been previously described [3], [4], [7], SCA countermeasures including noise-injection [5] and random masking [3], [4] have only been analytically explored without efficient circuit realizations or attack measurements.

Read the paper · More papers on PaperTik