DocumentCode
2409199
Title
Masking the energy behavior of DES encryption [smart cards]
Author
Saputra, H. ; Vijaykrishnan, N. ; Kandemir, M. ; Irwin, M.J. ; Brooks, R. ; Kim, S. ; Zhang, W.
Author_Institution
Dept. of Comput. Sci. & Eng., Pennsylvania State Univ., University Park, PA, USA
fYear
2003
fDate
2003
Firstpage
84
Lastpage
89
Abstract
Smart cards are vulnerable to both invasive and non-invasive attacks. Specifically, non-invasive attacks using power and timing measurements to extract the cryptographic key has drawn a lot of negative publicity for smart card usage. The power measurement techniques rely on the data-dependent energy behavior of the underlying system. Further, power analysis can be used to identify the specific portions of the program being executed to induce timing glitches that may in turn help to bypass key checking. Thus, it is important to mask the energy consumption when executing the encryption algorithms. In this work, we augment the instruction set architecture of a simple five-stage pipelined smart card processor with secure instructions to mask the energy differences due to key-related data-dependent computations in DES encryption. The secure versions operate on the normal and complementary versions of the operands simultaneously to mask the energy variations due to value dependent operations. However, this incurs the penalty of increased overall energy consumption in the data-path components. Consequently, we employ secure versions of instructions only for critical operations; that is we use secure instructions selectively, as directed by an optimizing compiler. Using a cycle-accurate energy simulator, we demonstrate the effectiveness of this enhancement. Our approach achieves the energy masking of critical operations consuming 83% less energy as compared to existing approaches employing dual rail circuits.
Keywords
cryptography; instruction sets; logic design; logic simulation; microprocessor chips; optimising compilers; pipeline processing; smart cards; DES encryption energy behavior masking; cryptographic key extraction; data-dependent energy behavior; data-path component energy consumption; energy consumption masking; instruction set architecture; invasive attacks; key checking bypass; key-related data dependent computations; noninvasive attacks; optimizing compiler; pipelined smart card processor; power analysis attack; power measurements; secure instructions; selective secure instruction use; smart cards; timing glitches; timing measurements; Circuit simulation; Computer aided instruction; Computer architecture; Cryptography; Energy consumption; Optimizing compilers; Power measurement; Rails; Smart cards; Timing;
fLanguage
English
Publisher
ieee
Conference_Titel
Design, Automation and Test in Europe Conference and Exhibition, 2003
ISSN
1530-1591
Print_ISBN
0-7695-1870-2
Type
conf
DOI
10.1109/DATE.2003.1253591
Filename
1253591
Link To Document