Mode-Level vs. Implementation-Level Physical Security in Symmetric Cryptography - A Practical Guide Through the Leakage-Resistance Jungle
Davide Bellizia, Olivier Bronchain, Gaëtan Cassiers, Vincent Grosso, Chun Guo, Charles Momin, Olivier Pereira, Thomas Peters, François-Xavier Standaert
摘要
Triggered by the increasing deployment of embedded cryptographic devices (e.g., for the IoT), the design of authentication, encryption and authenticated encryption schemes enabling improved security against side-channel attacks has become an important research direction. Over the last decade, a number of modes of operation have been proposed and analyzed under different abstractions. In this paper, we investigate the practical consequences of these findings. For this purpose, we first translate the physical assumptions of leakage-resistance proofs into minimum security requirements for implementers. Thanks to this (heuristic) translation, we observe that (i) security against physical attacks can be viewed as a tradeoff between mode-level and implementationlevel protection mechanisms, and (ii) security requirements to guarantee confidentiality and integrity in front of leakage can be concretely different for the different parts of an implementation. We illustrate the first point by analyzing several modes of operation with gradually increased leakage-resistance. We illustrate the second point by exhibiting leveled implementations, where different parts of the investigated schemes have different security requirements against leakage, leading to performance improvements when high physical security is needed. We finally initiate a comparative discussion of the different solutions to instantiate the components of a leakage-resistant authenticated encryption scheme.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- Connecting Leakage-Resilient Secret Sharing to Practice: Scaling Trends and Physical Dependencies of Prime Field MaskingSebastian Faust, Loïc Masure, Elena Micheli, Maximilian Orlt 等EUROCRYPT 2024 · 被引用 8 次
- Generalized Feistel Ciphers for Efficient Prime Field MaskingLorenzo Grassi, Loïc Masure, Pierrick Méaux, Thorben Moos 等EUROCRYPT 2024 · 被引用 4 次
它引用的顶会 Paper2
- Strong Non-Interference and Type-Directed Higher-Order MaskingGilles Barthe, Sonia Belaïd, François Dupressoir, Pierre-Alain Fouque 等CCS 2016 · 被引用 302 次
- Tornado: Automatic Generation of Probing-Secure Masked Bitsliced ImplementationsSonia Belaïd, Pierre-Évariste Dagand, Darius Mercadier, Matthieu Rivain 等EUROCRYPT 2020 · 被引用 48 次
相关 Paper
- Prouff and Rivain's Formal Security Proof of Masking, Revisited - Tight Bounds in the Noisy Leakage ModelLoïc Masure, François-Xavier StandaertCRYPTO 2023 · 被引用 10 次
- Leakage and Tamper Resilient Permutation-Based CryptographyChristoph Dobraunig, Bart Mennink, Robert PrimasCCS 2022 · 被引用 7 次
- Effective and Efficient Masking with Low Noise Using Small-Mersenne-Prime CiphersLoïc Masure, Pierrick Méaux, Thorben Moos, François-Xavier StandaertEUROCRYPT 2023 · 被引用 20 次
- Leakage Resilient Value Comparison with Application to Message AuthenticationChristoph Dobraunig, Bart MenninkEUROCRYPT 2021 · 被引用 12 次
- Low-Latency Hardware Private CircuitsDavid Knichel, Amir MoradiCCS 2022 · 被引用 20 次
