Lune

CRYPTO2022Top-tier venue

Secret Can Be Public: Low-Memory AEAD Mode for High-Order Masking

Yusuke Naito, Yu Sasaki, Takeshi Sugawara

2022Year
13Citations
1Top-tier citations

Abstract

We propose a new AEAD mode of operation for an efficient countermeasure against side-channel attacks. Our mode achieves the smallest memory with high-order masking, by minimizing the states that are duplicated in masking. An s-bit key-dependent state is necessary for achieving s-bit security, and the conventional schemes always protect the entire s bits with masking. We reduce the protected state size by introducing an unprotected state in the key-dependent state: we protect only a half and give another half to a side-channel adversary. Ensuring independence between the unprotected and protected states is the key technical challenge since mixing these states reveals the protected state to the adversary. We propose a new mode HOMA that achieves s-bit security using a tweakable block cipher with the s/2-bit block size. We also propose a new primitive for instantiating HOMA with s = 128 by extending the SKINNY tweakable block cipher to a 64-bit plaintext block, a 128-bit key, and a (256 + 3)-bit tweak. We make hardware performance evaluation by implementing HOMA with high-order masking for d ≤ 5. For any d > 0, HOMA outperforms the current state-of-the-art PFB Plus by reducing the circuit area larger than that of the entire S-box.

Ask about this paper

Your agent reads all of it.

Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.

Questions to start from

Your agent calls

Luneget_paper_fulltext

Ask in Lune

Free to start. No credit card required.

lune papers fulltext e833ebe7-423f-4a03-b11a-77f5fc95e21e

Cited by top-tier papers1

Ask how each one uses it

Builds on2

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines