Abstract
Implementations of ARX ciphers are hoped to have some intrinsic side channel resilience owing to the specific choice of cipher components: Modular addition (A), rotation (R) and exclusive-or (X). Previous work has contributed to this understanding by developing theory regarding the side channel resilience of components (pioneered by the early works of Prouff) as well as some more recent practical investigations by Biryukov et al. that focused on lightweight cipher constructions. We add to this work by specifically studying ARX-boxes both mathematically as well as practically. Our results show that previous works' reliance on the simplistic assumption that intermediates independently leak (their Hamming weight) has led to the incorrect conclusion that the modular addition is necessarily the best target and that ARX constructions are therefore harder to attack in practice: We show that on an ARM M0, the best practical target is the exclusive or and attacks succeed with only tens of traces.
| Original language | English |
|---|---|
| Title of host publication | ACM International Conference on Computing Frontiers 2019, CF 2019 - Proceedings |
| Subtitle of host publication | April 30 - May 2, 2019, Alghero, Sardinia, Italy |
| Publisher | Association for Computing Machinery |
| Pages | 373-379 |
| Number of pages | 7 |
| ISBN (Electronic) | 9781450366854 |
| DOIs | |
| Publication status | Published - 30 Apr 2019 |
| Event | 16th ACM International Conference on Computing Frontiers, CF 2019 - Alghero, Sardinia, Italy Duration: 30 Apr 2019 → 2 May 2019 |
Conference
| Conference | 16th ACM International Conference on Computing Frontiers, CF 2019 |
|---|---|
| Country/Territory | Italy |
| City | Alghero, Sardinia |
| Period | 30/04/19 → 2/05/19 |
Keywords
- ARX
- Correlation Attack
- Side Channel
Fingerprint
Dive into the research topics of 'Examining the practical side channel resilience of arx-boxes'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver