Higher order masking of the AES

  • Authors:
  • Kai Schramm;Christof Paar

  • Affiliations:
  • Horst Görtz Institute for IT Security (HGI), Ruhr University Bochum, Germany, Bochum, Germany;Horst Görtz Institute for IT Security (HGI), Ruhr University Bochum, Germany, Bochum, Germany

  • Venue:
  • CT-RSA'06 Proceedings of the 2006 The Cryptographers' Track at the RSA conference on Topics in Cryptology
  • Year:
  • 2006

Quantified Score

Hi-index 0.00

Visualization

Abstract

The development of masking schemes to secure AES implementations against side channel attacks is a topic of ongoing research. Many different approaches focus on the AES S-box and have been discussed in the previous years. Unfortunately, to our knowledge most of these countermeasures only address first-order DPA. In this article, we discuss the theoretical background of higher order DPA. We give the expected measurement costs an adversary has to deal with for different hardware models. Moreover, we present a masking scheme which protects an AES implementation against higher order DPA. We have implemented this masking scheme for various orders and present the corresponding performance details implementors will have to expect.