2019/11/25 by Keyvan Ramezanpour, Ramezanpour, Keyvan, Paul Ampadu +3
Computer Science · #Advanced Malware Detection Techniques #Cryptographic Implementations and Security #Cryptography and Security (cs.CR) #FOS: Computer and information sciences #Information Theory (cs.IT) #Physical Unclonable Functions (PUFs) and Hardware Security
paper · pdf · doi:10.48550/arxiv.1911.11278
openalex publication_date 2019/11/25 · openalex created_date 2025/10/10 · openalex updated_date 2026/07/28
While modern masking schemes provide provable security against passive\nside-channel analysis (SCA), such as power analysis, single faults can be\nemployed to recover the secret key of ciphers even in masked implementations.\nIn this paper, we propose random space masking (RS-Mask) as a countermeasure\nagainst both power analysis and statistical fault analysis (SFA) techniques. In\nthe RS-Mask scheme, the distribution of all sensitive variables, faulty and/or\ncorrect values is uniform, and it therefore protects the implementations\nagainst any SFA technique that exploits the distribution of intermediate\nvariables, including fault sensitivity analysis (FSA), statistical ineffective\nfault analysis (SIFA) and fault intensity map analysis (FIMA). We implement\nRS-Mask on AES, and show that a SIFA attack is not able to identify the correct\nkey. We additionally show that an FPGA implementation of AES, protected with\nRS-Mask, is resistant to power analysis SCA using Welch's t-test. The area of\nthe RS-Masked AES is about 3.5 times that of an unprotected AES implementation\nof similar architecture, and about 2 times that of a known FPGA SCA-resistant\nAES implementation. Finally, we introduce infective RS-Mask that provides\nsecurity against differential techniques, such as differential fault analysis\n(DFA) and differential fault intensity analysis (DFIA), with a slight increase\nin overhead.\n