计算机工程 ›› 2012, Vol. 38 ›› Issue (13): 108-111.doi: 10.3969/j.issn.1000-3428.2012.13.031

• 安全技术 • 上一篇    下一篇

抵御侧信道分析的AES双路径掩码方法

张翌维1,龚冰冰2a,刘烈恩2a,唐 有2b   

  1. (1. 国民技术股份有限公司,广东 深圳 518057;2. 深圳大学 a. 光电工程学院;b. 信息工程学院,广东 深圳 518060)
  • 收稿日期:2012-01-12 出版日期:2012-07-05 发布日期:2012-07-05
  • 作者简介:张翌维(1980-),男,工程师、博士,主研方向:安全芯片体系结构设计;龚冰冰、刘烈恩、唐 有,硕士研究生
  • 基金项目:
    国家发展和改革委员会信息安全专项基金资助项目([2010] 3044号)

AES Dual-path Masking Method for Resisting Side-channel Analysis

ZHANG Yi-wei 1, GONG Bing-bing 2a, LIU Lie-en 2a, TANG You 2b   

  1. (1. Nationz Technologies Inc., Shenzhen 518057, China; 2a. College of Optoelectronic Engineering; 2b. College of Information Engineering, Shenzhen University, Shenzhen 518060, China)
  • Received:2012-01-12 Online:2012-07-05 Published:2012-07-05

摘要: 为抵御功耗、电磁辐射等侧信道分析攻击,提出一种高级加密标准(AES)双路径掩码方法。采用2条数据路径,将随机数和随机S盒用于掩码操作,使一个加、解密轮次内的所有中间运算结果与AES算法的标准中间结果都不相同,且各中间结果的汉明重量随明文随机变化。实验结果表明,AES算法中间结果的汉明重量与该方法产生的能量特征之间的相关性被完全消除,可抵御各种侧信道分析攻击。

关键词: 侧信道分析, 高级加密标准算法, 差分功耗分析, 掩码方法, S盒, 时序折叠

Abstract: In order to resist the side-channel analysis as power and EM attack, a dual-path masking method is proposed for Advanced Encryption Standard(AES) algorithm implementation. Through two data paths, the random numbers and random S-boxes are used to mask operation, which makes all intermediate variables among the proposed AES scheme different from that of the standard method, and the Hamming distance corresponding to each intermediate variable changes with the plaintext. It is simple in structure, and conducive to software and hardware implementation. Experimental result shows the correlation between the intermediates of standard AES and the energy characteristics of proposed AES scheme are completely removed. Thus, the proposed method bears strong immunity to all known side-channel analysis.

Key words: side-channel analysis, Advanced Encryption Standard(AES) algorithm, Differential Power Analysis(DPA), masking method, S-box, timing folding

中图分类号: