Secret Can Be Public: Low-Memory AEAD Mode for High-Order Masking
Yusuke Naito, Yu Sasaki, Takeshi Sugawara
Abstract
We propose a new AEAD mode of operation for an efficient countermeasure against side-channel attacks. Our mode achieves the smallest memory with high-order masking, by minimizing the states that are duplicated in masking. An s-bit key-dependent state is necessary for achieving s-bit security, and the conventional schemes always protect the entire s bits with masking. We reduce the protected state size by introducing an unprotected state in the key-dependent state: we protect only a half and give another half to a side-channel adversary. Ensuring independence between the unprotected and protected states is the key technical challenge since mixing these states reveals the protected state to the adversary. We propose a new mode HOMA that achieves s-bit security using a tweakable block cipher with the s/2-bit block size. We also propose a new primitive for instantiating HOMA with s = 128 by extending the SKINNY tweakable block cipher to a 64-bit plaintext block, a 128-bit key, and a (256 + 3)-bit tweak. We make hardware performance evaluation by implementing HOMA with high-order masking for d ≤ 5. For any d > 0, HOMA outperforms the current state-of-the-art PFB Plus by reducing the circuit area larger than that of the entire S-box.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext e833ebe7-423f-4a03-b11a-77f5fc95e21eCited by top-tier papers1
Ask how each one uses itBuilds on2
Related papers
- Generalized Feistel Ciphers for Efficient Prime Field MaskingLorenzo Grassi, Loïc Masure, Pierrick Méaux, Thorben Moos et al.EUROCRYPT 2024 · 4 citations
- Secure Wire Shuffling in the Probing ModelJean-Sébastien Coron, Lorenzo SpignoliCRYPTO 2021 · 13 citations
- Shortest Path to Secured Hardware: Domain Oriented Masking with High-Level-SynthesisRajat Sadhukhan, Sayandeep Saha, Debdeep MukhopadhyayDAC 2021 · 8 citations
- Prouff and Rivain's Formal Security Proof of Masking, Revisited - Tight Bounds in the Noisy Leakage ModelLoïc Masure, François-Xavier StandaertCRYPTO 2023 · 10 citations
- A Thorough Evaluation of RAMBAMDaniel Lammers, Amir Moradi, Nicolai Müller, Aein Rezaei ShahmirzadiCCS 2023 · 1 citation
