An AES chip with DPA resistance using hardware-based random order execution

来源 :半导体学报 | 被引量 : 0次 | 上传用户:coolboywcp
下载到本地 , 更方便阅读
声明 : 本文档内容版权归属内容提供方 , 如果您对本文有版权争议 , 可与客服联系进行内容授权或下架
This paper presents an AES(advanced encryption standard) chip that combats differential power analysis (DPA) side-channel attack through hardware-based random order execution.Both decryption and encryption procedures of an AES are implemented on the chip.A fine-grained dataflow architecture is proposed,which dynamically exploits intrinsic byte-level independence in the algorithm.A novel circuit called an HMF(Hold-MatchFetch) unit is proposed for random control,which randomly sets execution orders for concurrent operations.The AES chip was manufactured in SMIC 0.18μm technology.The average energy for encrypting one group of plain texts(128 bits secrete keys) is 19 nJ.The core area is 0.43 mm~2.A sophisticated experimental setup was built to test the DPA resistance.Measurement-based experimental results show that one byte of a secret key cannot be disclosed from our chip under random mode after 64000 power traces were used in the DPA attack.Compared with the corresponding fixed order execution,the hardware based random order execution is improved by at least 21 times the DPA resistance. This paper presents an AES (advanced encryption standard) chip that combats differential power analysis (DPA) side-channel attack through hardware-based random order execution. But decryption and encryption procedures of an AES are implemented on the chip. A fine-grained dataflow architecture is proposed, which dynamically exploits intrinsic byte-level independence in the algorithm. A novel circuit called an HMF (Hold-MatchFetch) unit is proposed for random control, which randomly sets execution orders for concurrent operations. The AES chip was manufactured in SMIC 0.18 μm technology. Average energy for encrypting one group of plain texts (128 bits secrete keys) is 19 nJ. The core area is 0.43 mm ~ 2. A sophisticated experimental setup was built to test the DPA resistance. Measurement-based experimental results show that one byte of a secret key can not be disclosed from our chip under random mode after 64000 power traces were used in the DPA attack. Compared with the corresponding fixed order ex ecution, the hardware based random order execution is improved by at least 21 times the DPA resistance.
请下载后查看,本文暂不支持在线获取查看简介。 Please download to view, this article does not support online access to view profile.
丹麦国营铁路公司(DSB)宣布将从今年秋季开始启用一种新型的城市间列车。这种新的旅客列车称为 IC3,由兰德斯 Ascan Scandia 公司制造。大多数列车制造厂都是用钢和重型结构
报道了一种毛细管电泳分析中获得重复性分析结果的毛细管柱预处理方法。通过 采用有机溶剂的碱性溶液对毛细管柱进行预冲洗,可得到内壁均一的能产生稳定电渗流的毛 细管柱,实现
王凯,1982年8月18日生于湖北省武汉市,中国内地男演员,毕业于中央戏剧学院03级表演班。  2007年出演首部电视剧《虎穴》进入娱乐圈;2008年因出演《丑女无敌》中娘娘腔陈家明一角而走红;2011年主演电视剧《枪炮侯》;2012年主演电视剧《知青》并参演首部电影《我的狗狗我的爱》。2013年主演的电影《逆袭》入围第十六届上海国际电影节电影频道传媒大奖最佳影片奖;2014年参演古装权谋剧《琅琊
A red-emitting phosphor GdNbO4:Eu3+,Bi3+ was prepared by a high temperature solid-state reaction technique. The phosphor was characterized by X-ray diffraction
为进一步了解头颈部肿瘤浸润、血管生长及淋巴结转移的生物学 ,该文综述作者多年来实验研究结果及相关文献报告。癌最基本的特性是向周围组织浸润以及局部和远处转移。从原位
随着开放改革形势的发展,全国合资企业单位越来越多,但部分合资企业的领导不重视合资企业的情报工作. 认为,我们既然与外国人合资,就应当学习外国人的先进管理和技术,只要照