Skip to main navigation Skip to search Skip to main content

A Side-Channel Analysis Resistant Description of the AES S-Box

  • ME Oswald
  • , S Mangard
  • , N Pramstaller
  • , V Rijmen

    Research output: Contribution to journalArticle (Academic Journal)peer-review

    250 Citations (Scopus)

    Abstract

    So far, efficient algorithmic countermeasures to secure the AES algorithm against (first-order) differential side-channel attacks have been very expensive to implement. In this article, we introduce a new masking countermeasure which is not only secure against first-order side-channel attacks, but which also leads to relatively small implementations compared to other masking schemes implemented in dedicated hardware. Our approach is based on shifting the computation of the finite field inversion in the AES S-box down to GF(4). In this field, the inversion is a linear operation and therefore it is easy to mask. Summarizing, the new masking scheme combines the concepts of multiplicative and additive masking in such a way that security against first-order side-channel attacks is maintained, and that small implementations in dedicated hardware can be achieved.
    Translated title of the contributionA Side-Channel Analysis Resistant Description of the AES S-Box
    Original languageEnglish
    Pages (from-to)413 - 423
    Number of pages11
    JournalLecture Notes in Computer Science
    DOIs
    Publication statusPublished - Feb 2005

    Bibliographical note

    Editors: Gilbert, H and Handschuh, H
    ISBN: 9783540265412
    Publisher: Springer
    Name and Venue of Conference: Fast Software Encryption: 12th International Workshop, FSE 2005, Paris, 21-23 February
    Conference Organiser: IACR

    Fingerprint

    Dive into the research topics of 'A Side-Channel Analysis Resistant Description of the AES S-Box'. Together they form a unique fingerprint.

    Cite this