Trade-Offs for S-boxes

Cryptographic Properties and Side-Channel Resilience

Conference Paper (2017)
Author(s)

Claude Carlet (Centre National de la Recherche Scientifique (CNRS))

Annelie Heuser (Centre National de la Recherche Scientifique (CNRS), INRIA/IRISA)

Stjepan Picek (TU Delft - Electrical Engineering, Mathematics and Computer Science, Massachusetts Institute of Technology, Centre National de la Recherche Scientifique (CNRS))

Research Group
Cyber Security
DOI related publication
https://doi.org/10.1007/978-3-319-61204-1_20 Final published version
More Info
expand_more
Publication Year
2017
Language
English
Research Group
Cyber Security
Pages (from-to)
393-414
Publisher
Springer
ISBN (print)
978-3-319-61203-4
ISBN (electronic)
978-3-319-61204-1
Event
Applied Cryptography and Network Security (2017-07-10 - 2017-07-12), Kanazawa, Japan
Page Views
210

Abstract

When discussing how to improve side-channel resilience of a cipher, an obvious direction is to use various masking or hiding countermeasures. However, such schemes come with a cost, e.g. an increase in the area and/or reduction of the speed. When considering lightweight cryptography and various constrained environments, the situation becomes even more difficult due to numerous implementation restrictions. However, some options are possible like using S-boxes that are easier to mask or (more on a fundamental level), using S-boxes that possess higher inherent side-channel resilience. In this paper we investigate what properties should an S-box possess in order to be more resilient against side-channel attacks. Moreover, we find certain connections between those properties and cryptographic properties like nonlinearity and differential uniformity. Finally, to strengthen our theoretical findings, we give an extensive experimental validation of our results.