A DPA‐Resistant and Reconfigurable AES Cryptographic Engine Design and Implementation

Zhaoyi Niu, Zhaokang Peng, Nengyuan Sun, Zhiyuan Pan, Jinghe Wang, Jiafeng Cheng, Wenrui Liu, Jianghong Li, Kai Shi, Jiaqi Wang, Jiawei Zhang, Linhan Wang, Kangning Song, Weize Yu · International Journal of Circuit Theory and Applications · 2025

ABSTRACT In this paper, a reconfigurable advanced encryption standard (AES) cryptographic architecture is proposed for maximizing the throughput while minimizing the circuit area. The key expansions with respect to AES 128‐bit, AES 192‐bit, and AES 256‐bit are fused into a single module to reduce the circuit area overhead. By optimizing the AES encryption/decryption circuit with a 14‐stage pipeline, the whole cryptographic engine is able to make the three previous AES key lengths compatible. Furthermore, in order to resist against differential power analysis (DPA) attacks, two DPA attack countermeasures are embedded into the AES engine to randomize the critical power leakage. One countermeasure is randomly altering the number of pipelined stages with 14 or 16. The other countermeasure randomizes the mathematical operation pertaining to substitution boxes (S‐boxes). The results show that the proposed DPA‐resistant and reconfigurable (DRR) AES engine is capable of achieving a 128 Gbps throughput and with 98,131 m area, under the synthesis of TSMC 16‐nm process design kits (PDK). Additionally, even if 10 million plaintexts are enabled, the secret key of the DRR AES engine cannot be revealed by DPA attacks.

Read the paper · More papers on PaperTik