Files

Low-LatencyMaskedGadgetsRobustagainstPhysicalDefaultswithApplicationtoAscon.pdf
  • Open Access
  • Adobe PDF
  • 650.69 KB

Details

Authors
Abstract
Low-latency masked hardware implementations are known to be a difficultchallenge. On the one hand, the propagation of glitches can falsify their independenceassumption (that is required for security) and can only be stopped by registers. Thisimplies that glitch-robust masked AND gates (maintaining a constant number ofshares) require at least one cycle. On the other hand, Knichel and Moradi’s onlyknown single-cycle multiplication gadget that ensures (composable) security againstglitches for any number of shares requires additional care to maintain security againsttransition-based leakages. For example, it cannot be integrated in a single-cycle round-based architecture which is a natural choice for low-latency implementations. In thispaper, we therefore describe the first single-cycle masked multiplication gadget that istrivially composable and provides security against transitions and glitches, and proveits security in the robust probing model. We then analyze the interest of this newgadget for the secure implementation of the future lightweight cryptography standardAscon, which has good potential for low-latency. We show that it directly leadsto improvements for uniformly protected implementations (where all computationsare masked). We also show that it is can be handy for integration in so-calledleveled implementations (where only the key derivation and the tag generation aremasked, which provides integrity with leakage in encryption and decryption andconfidentiality with leakage in encryption only). Most importantly, we show thatit is very attractive for implementations that we denote as multi-target, which canalternate between uniformly protected and leveled implementations, without latencyoverheads and at limited cost. We complete these findings by evaluating differentprotected implementations of Ascon, clarifying its hardware design space.
Affiliations

Citations

Cassiers, G., Standaert, F.-X., & Verhamme, C. (2024). Low-Latency Masked Gadgets Robust againstPhysical Defaults with Application to Ascon. {IACR} Trans. Cryptogr. Hardw. Embed. Syst., 2024(3), 603-633. https://doi.org/10.46586/TCHES.V2024.I3.603-633 (Original work published 2024)