• No results found

[PDF] Top 20 Threshold Implementations of all 3x3 and 4x4 S-boxes

Has 10000 "Threshold Implementations of all 3x3 and 4x4 S-boxes" found on our website. Below are the top 20 most common "Threshold Implementations of all 3x3 and 4x4 S-boxes".

Threshold  Implementations  of  all 3x3   and 4x4  S-boxes

Threshold Implementations of all 3x3 and 4x4 S-boxes

... for implementations to be provably resistant against first-order DPA with minimal assump- tions on the ...for all invertible 3×3, 4×4 S-boxes and the 6 × 4 DES ... See full document

25

Lightweight   and  Side-channel  Secure 4x4  S-Boxes  from  Cellular  Automata  Rules

Lightweight and Side-channel Secure 4x4 S-Boxes from Cellular Automata Rules

... low-cost threshold implementations (TI) - a provably secure strategy against side-channel ...4×4 S-Boxes, implemented via repeated iterations of simple cellular automata (CA) ...such ... See full document

24

Enabling 3-share  Threshold  Implementations  for  any 4-bit  S-box

Enabling 3-share Threshold Implementations for any 4-bit S-box

... 4-bit S-boxes are used in cryptographic algorithms due to their efficient hardware ...4-bit S- boxes, which fulfill certain cryptographic properties to resist linear and differ- ential ... See full document

17

Constructions  of  S-boxes  with  uniform  sharing

Constructions of S-boxes with uniform sharing

... secure implementations. One of the most popular ways is Threshold Implementations (TI) ...n-bit S-box is a permutation, its sharing with k shares is a permutation on GF (2 kn ... See full document

14

Affine  Equivalence   and  its  Application  to  Tightening  Threshold  Implementations

Affine Equivalence and its Application to Tightening Threshold Implementations

... At a first step, we decided to implement Algorithm 1 as a hardware circuit which searches for the affine triples in parallel to the encryption. The found affine triples are stored into a “First In, First Out” (FIFO) ... See full document

14

Shuffle   and  Mix:  On  the  Diffusion  of  Randomness  in  Threshold  Implementations  of  Keccak

Shuffle and Mix: On the Diffusion of Randomness in Threshold Implementations of Keccak

... Abstract. Threshold Implementations are well-known as a provably first- order secure Boolean masking scheme even in the presence of ...between S-boxes and prevent exploitable ... See full document

16

Constructing  TI-Friendly  Substitution  Boxes  using  Shift-Invariant  Permutations

Constructing TI-Friendly Substitution Boxes using Shift-Invariant Permutations

... One obstacle in threshold implementations is that there is no trivial efficient constructions for arbitrary cryptographic components. Take 3-share TI schemes for instance: in theory, any arbitrary quadratic ... See full document

27

Trade OFFS For Threshold Implementations Illustrated on AES
Syed Kareem Uddin & Imthiazunnisa Begum

Trade OFFS For Threshold Implementations Illustrated on AES Syed Kareem Uddin & Imthiazunnisa Begum

... operations: 1. a nonlinear byte substitution (Sub Bytes) by means of substitution tables (S-Boxes) or online computations; 2. a data shuffling phase (Shift Rows) operating on rows; 3. linear multiplication ... See full document

7

A High Performance VLSI Architecture for Threshold Implementations Illustrated on AES
K Anusha, M Suman Kumar, B Kedarnath & Dr S Sreenatha Reddy

A High Performance VLSI Architecture for Threshold Implementations Illustrated on AES K Anusha, M Suman Kumar, B Kedarnath & Dr S Sreenatha Reddy

... other S-boxes, re-masking may increase the amount of randomness ...per S-box calculation, which is a significant improvement over all previous ... See full document

9

Optimized  Threshold  Implementations:  Securing  Cryptographic  Accelerators  for  Low-Energy   and  Low-Latency  Applications

Optimized Threshold Implementations: Securing Cryptographic Accelerators for Low-Energy and Low-Latency Applications

... When we consider first-order attacker he can probe one share out of two at a given cycle, thus the reuse of randomness is not exploitable. For the case of second-order attacker he is able to get either a) 2 shares out of ... See full document

30

Several  Masked  Implementations  of  the  Boyar-Peralta  AES  S-Box

Several Masked Implementations of the Boyar-Peralta AES S-Box

... Abstract. Threshold implementation is a masking technique that pro- vides provable security for implementations of cryptographic algorithms against power analysis ...different threshold ... See full document

19

On 3-share  Threshold  Implementations  for 4-bit  S-boxes

On 3-share Threshold Implementations for 4-bit S-boxes

... address all of them) have been proposed during the last years, for example, to increase the SNR ratio [10], to balance the leakage of different values [9] or to break the link between the pro- cessed data and the ... See full document

16

Evolving  S-Boxes  with  Reduced  Differential  Power  Analysis  Susceptibility

Evolving S-Boxes with Reduced Differential Power Analysis Susceptibility

... The cycle crossover iteratively finds pairs of parental values by position to preserve bijectivity [OSH87]. These cycles consider both parents, so they differ from cycles found within a single permutation. This approach ... See full document

18

Large substitution boxes with efficient combinational implementations

Large substitution boxes with efficient combinational implementations

... Combinational implementations of the AES S-box have been well-studied for over a decade [65, 67, 53, 13, ...AES S-box from an area perspective requires only 32 AND and 83 XOR/XNOR ...AES S-box ... See full document

176

Key-Recovery  Attack  on  the  ASASA  Cryptosystem  with  Expanding  S-boxes

Key-Recovery Attack on the ASASA Cryptosystem with Expanding S-boxes

... polynomial-based S layers. The ASASA scheme with expanding S-boxes, on which we are focusing, involves S-boxes whose out- put is twice as big as their input; 32 perturbation polynomials ... See full document

17

Higher  Order  Side-Channel  Attacks  Resilient  S-boxes

Higher Order Side-Channel Attacks Resilient S-boxes

... generate S- boxes, we use genetic algorithms (GAs) since it represents a method that is easy to implement while being very efficient as reported in related ...obtain S-boxes with as high as ... See full document

6

Constrained  Search  for  a  Class  of  Good  S-Boxes  with  Improved  DPA  Resistivity

Constrained Search for a Class of Good S-Boxes with Improved DPA Resistivity

... of S-box F to DPA attacks. Also Prouff showed that S-boxes with very high nonlinearity and those which satisfy propagation criteria (PC) of higher order are more susceptible to DPA ...an ... See full document

19

On  Reverse-Engineering  S-Boxes  with  Hidden  Design  Criteria  or  Structure

On Reverse-Engineering S-Boxes with Hidden Design Criteria or Structure

... an S-Box can be leveraged for instance to improve the imple- mentation of a primitive using ...bits S-Boxes built from smaller 4 × 4 ones, since storing several 4 × 4 permutations as tables of 16 ... See full document

20

DYNAMIC Key-Depending S-boxes Inspired by Biological DNA

DYNAMIC Key-Depending S-boxes Inspired by Biological DNA

... and all its affine functions, or it is the distance between the function in question and the adjacent linear function [20, ...dynamic S-boxes using the proposed Column transcription method it appears ... See full document

6

Boosting  Higher-Order  Correlation  Attacks  by  Dimensionality  Reduction

Boosting Higher-Order Correlation Attacks by Dimensionality Reduction

... The covariance is computed for all key guesses K, where the wrong keys are plotted in grey and the correct key in red. Note that, as we target an XOR operation the maximum of the absolute value of the covariance ... See full document

20

Show all 10000 documents...